Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

Exchange 2010 account @iphone is getting emails even after password change

Posted on 2016-10-11
8
54 Views
Last Modified: 2016-10-12
I have a SBS 2011 box with pre installed Exchange 2010 Version 14.3 (Build 123.4)
Users are receiving emails at iPhone. I noticed a strange thing; even after changing password of windows logon account, users can still receive & send emails at iPhone even without updating the new password in the iPhone exchange account settings.

iPhone asked the new password after restarting the server only.

Is it the genuine procedure or is the server got compromised? If its a policy, where to find & modify the policy.

Thanks for reading the concern.
0
Comment
Question by:Akash Bansal
  • 4
  • 4
8 Comments
 
LVL 57

Accepted Solution

by:
Cliff Galiher earned 500 total points
ID: 41839544
Perfectly normal. Authentication issues a token for a length of time and that token os still valid after a password change. You won't have to re-auth until the token expires. You really don't want to mess with this behavior. It has ramifications well beyond exchange.
1
 
LVL 2

Author Comment

by:Akash Bansal
ID: 41839547
What is the token age normally? Worried if my server is compromised or not.
0
 
LVL 57

Assisted Solution

by:Cliff Galiher
Cliff Galiher earned 500 total points
ID: 41839552
Several hours. Is there a reason you think the server is compromised?
1
NFR key for Veeam Backup for Microsoft Office 365

Veeam is happy to provide a free NFR license (for 1 year, up to 10 users). This license allows for the non‑production use of Veeam Backup for Microsoft Office 365 in your home lab without any feature limitations.

 
LVL 2

Author Comment

by:Akash Bansal
ID: 41839554
Thanks.
User having admin privilege  reported a suspicious attachment he opened.
I submitted it to Avira; now it is added to the virus definition.


https://analysis.avira.com/en/status?uniqueid=5v1rPZISYhnBq1FR0vdkSVqFDNqYZtDA&incidentid=2099562

A few months back one of my friend lost money as his google mail password was hacked & hacker successfully diverted some expected payments to his account. The friend click almost the same type of link in pdf file & innocently entered his password to the phishing link.
0
 
LVL 57

Expert Comment

by:Cliff Galiher
ID: 41839712
Well, as a general rule, admins should have separate admin accounts. For example, I may have an account called "cliff" that is a standard user that has an exchange mailbox and is a standard user, and "admin-cliff" that does *not* have an exchange mailbox and is used for admin tasks.  Admin accounts are further secured with 2FAband/or all external access blocked. That way admin credentials would never be leaked how you described.
1
 
LVL 2

Author Comment

by:Akash Bansal
ID: 41840168
Yes! You are correct, I would advice my friends to make separate admin accounts.
What is 2FAband?
0
 
LVL 57

Expert Comment

by:Cliff Galiher
ID: 41840952
Typo. 2FA and/or.
1
 
LVL 2

Author Comment

by:Akash Bansal
ID: 41841401
As google mail has an option to sign out from all devices. So after changing the password of gmail, we click on "sign out all other web sessions", I guess this ensure that all other devices are forced logout.

How can we do it with on premises exchange 2010/2013 or 2016 users sessions.
0

Featured Post

Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Many people use more than one email account and so it becomes difficult for them to manage them when they use separate accounts,  so, in this article, I have shared an easy way to add Other Mail Accounts in your Google Inbox. It helps to combine all…
When you have clients or friends from around the world, it becomes a challenge to arrange a meeting or effectively manage your time. This is where Outlook's capability to show 2 time zones in one calendar comes in handy.
In this video we show how to create an Address List in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Organization >> Ad…
In this video we show how to create an email address policy in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Mail Flow…

856 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question