Restricting email flow within a group within an organization

Posted on 2014-12-31
Last Modified: 2015-01-14
We have a client that has an in house exchange 2010 server.

The customer requests a small group of users to have the ability to email one another within said group without being able to email anyone else within the organization nor outside of the organization. Nor will they be able to receive email from outside of the small group within the organization, nor be able to receive email from the outside.

I have been able to restrict mail flow to within the organization, but not quite sure how to select the specified users from within the organization.

Any tips and advice on this would be helpful. An odd request indeed, but it is for students within a private school.
Question by:BlackJack11
  • 4
  • 3
  • 3
  • +1

Expert Comment

ID: 40525768
First, create two distribution groups.  One that has the small group in it, and one that has everyone else.

In Exchange Management Console, expand Organization Configuration and click on Hub Transport.
Then click on the Transport Rules Tab.

Right click in the transport rules tab and select New Transport Rule.
Call it Prevent Users from Sending to Small Group and click Next
Select "From a member of a distribution list" and "sent to a member of a distribution list".

In the bottom half, click on "distribution list" next to "From a member of a distribution list" and add one of the distribution groups you created.  Then click on the other "distribution list" next to "and sent to a member of" and select the other distribution list.  Click Next.

Then choose "delete the message without notifying anyone" or something else, such as "send rejection message to sender with enhanced status code".  If you select "send rejection..." then configure the message and code in the bottom half of the dialog box.  Click next.

You can put in some exceptions if you want.

Then repeat this but reverse the groups, so now the from group is the group that was the to group and vice versa.

That will handle blocking mail sent internally between the groups.  As new employees are hired, they need to be put into one of the two groups.

Then, you need to create two more rules as you did above, but under the conditions select "from users that are inside or outside the organization" and select "Outside the Organization" and "sent to a member of a distribution list".  Configure the distribution list to be the small group distribution list you created.  CLick next.

select the action you want as before, delete without notifying, or send rejection.  click next. Add exceptions if you want. click next and new.

Then create one more rule, this one you'll reverse the conditions again.  You'll select "From a member of a distribution list" and "to users that are inside or outside the organization, or partners" and you'll select your small group again, and select "Outside the organization", then select the action (rejection or deleted), exceptions, and you're done.

So you need four rules.  One to stop the big group from sending to the small group, one to keep the small group from sending to the big group, one to stop outside people from sending to the small group, and one to stop the small group from sending to outside people.

And you need to make sure the distribution groups are kept up to date.
LVL 31

Accepted Solution

Gareth Gudger earned 500 total points
ID: 40525776
You can do a couple of things.
First to stop them from receiving messages but from a select few people, you can do Message Delivery Restrictions on the user account itself. To block outside users you can check Require that all senders are authenticated. Or, in your case, to restrict it to just a few inside users, select, Only Senders in the following list. Then click Add to pick who you want to be allowed to send. You can also add a distribution group here rather than adding each individual mailbox. So if you have a Students distro, you can just add that. See the screenshot below.

To prevent sending you will need to create a Transport Rule. It could look something like this. I sent a rule that any message from my distribution group (again could be a Students distro) is prevented from being sent, unless it is sent to another member of that same distro. See the screenshot below.


Author Comment

ID: 40525777
Logically makes sense; I didn't think of 2 distribution groups. Thank you for the quick response!
U.S. Department of Agriculture and Acronis Access

With the new era of mobile computing, smartphones and tablets, wireless communications and cloud services, the USDA sought to take advantage of a mobilized workforce and the blurring lines between personal and corporate computing resources.

LVL 31

Expert Comment

by:Gareth Gudger
ID: 40525781
You can do it with one distro. See my screenshot above.

Expert Comment

by:Jessie Gill, CISSP
ID: 40525788
You could create a transport rule, that will block the mail leaving the organization from the restricted users or the restricted users from receiving the mails externally, also make one for internal emails if need to.

Expert Comment

ID: 40525809
Gareth Gudger has a good point.  With 1 group and two transport rules (rather than use restrictions in one case and a transport in another, I'd go with two transport rules to keep it consistent).

So one rule, as GG says, deletes if from Small Group except if to Small Group.  The second deletes if to Small Group except if from Small Group.

Then any emails the small group sends gets deleted (inside or outside) unless it's to someone in the small group.  Any emails sent to the small group (inside or outside) likewise get deleted unless from the small group.

And then you only have one distribution group to maintain.  

In any case, GG's solution is simpler than mine.

Author Comment

ID: 40525821
One distribution group with "to" and "from" restrictions.


Author Comment

ID: 40525854
Mail flow restrictions from certain users and transport rule sending to members in the distribution group.

Happy New Years!
LVL 31

Expert Comment

by:Gareth Gudger
ID: 40525899
Everything working now BlackJack?

Expert Comment

ID: 40525901
Blackjack11, the rule you posted a screenshot for will always let mail through to or from a member of TestDG.  

Message comes through from outside to TestDG member.  Rule applies *except* if the message is to a member of TestDG, so it goes through.

Message sent from TestDG member to any internal or external address.  Rule applies *except* if the message is from a member of TestDG, so it also goes through.

Author Comment

ID: 40525902
Work will be done at a later date, just making sure there was a way to do it.

Thank you for the follow-up.

Featured Post

Announcing the Most Valuable Experts of 2016

MVEs are more concerned with the satisfaction of those they help than with the considerable points they can earn. They are the types of people you feel privileged to call colleagues. Join us in honoring this amazing group of Experts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Are external E-mails being sent to distribution groups? 6 39
Exchange 2016 install absolute nightmare 10 33
Exchange Certificate 5 32
This article aims to explain the working of CircularLogArchiver. This tool was designed to solve the buildup of log file in cases where systems do not support circular logging or where circular logging is not enabled
As tax season makes its return, so does the increase in cyber crime and tax refund phishing that comes with it
This video demonstrates how to sync Microsoft Exchange Public Folders with smartphones using CodeTwo Exchange Sync and Exchange ActiveSync. To learn more about CodeTwo Exchange Sync and download the free trial, go to:…
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…

813 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now