Solved

Exchange 2010 account @iphone is getting emails even after password change

Posted on 2016-10-11
8
49 Views
Last Modified: 2016-10-12
I have a SBS 2011 box with pre installed Exchange 2010 Version 14.3 (Build 123.4)
Users are receiving emails at iPhone. I noticed a strange thing; even after changing password of windows logon account, users can still receive & send emails at iPhone even without updating the new password in the iPhone exchange account settings.

iPhone asked the new password after restarting the server only.

Is it the genuine procedure or is the server got compromised? If its a policy, where to find & modify the policy.

Thanks for reading the concern.
0
Comment
Question by:Akash Bansal
  • 4
  • 4
8 Comments
 
LVL 57

Accepted Solution

by:
Cliff Galiher earned 500 total points
ID: 41839544
Perfectly normal. Authentication issues a token for a length of time and that token os still valid after a password change. You won't have to re-auth until the token expires. You really don't want to mess with this behavior. It has ramifications well beyond exchange.
1
 
LVL 2

Author Comment

by:Akash Bansal
ID: 41839547
What is the token age normally? Worried if my server is compromised or not.
0
 
LVL 57

Assisted Solution

by:Cliff Galiher
Cliff Galiher earned 500 total points
ID: 41839552
Several hours. Is there a reason you think the server is compromised?
1
What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

 
LVL 2

Author Comment

by:Akash Bansal
ID: 41839554
Thanks.
User having admin privilege  reported a suspicious attachment he opened.
I submitted it to Avira; now it is added to the virus definition.


https://analysis.avira.com/en/status?uniqueid=5v1rPZISYhnBq1FR0vdkSVqFDNqYZtDA&incidentid=2099562

A few months back one of my friend lost money as his google mail password was hacked & hacker successfully diverted some expected payments to his account. The friend click almost the same type of link in pdf file & innocently entered his password to the phishing link.
0
 
LVL 57

Expert Comment

by:Cliff Galiher
ID: 41839712
Well, as a general rule, admins should have separate admin accounts. For example, I may have an account called "cliff" that is a standard user that has an exchange mailbox and is a standard user, and "admin-cliff" that does *not* have an exchange mailbox and is used for admin tasks.  Admin accounts are further secured with 2FAband/or all external access blocked. That way admin credentials would never be leaked how you described.
1
 
LVL 2

Author Comment

by:Akash Bansal
ID: 41840168
Yes! You are correct, I would advice my friends to make separate admin accounts.
What is 2FAband?
0
 
LVL 57

Expert Comment

by:Cliff Galiher
ID: 41840952
Typo. 2FA and/or.
1
 
LVL 2

Author Comment

by:Akash Bansal
ID: 41841401
As google mail has an option to sign out from all devices. So after changing the password of gmail, we click on "sign out all other web sessions", I guess this ensure that all other devices are forced logout.

How can we do it with on premises exchange 2010/2013 or 2016 users sessions.
0

Featured Post

Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Scam emails are a huge burden for many businesses. Spotting one is not always easy. Follow our tips to identify if an email you receive is a scam.
Read this checklist to learn more about the 15 things you should never include in an email signature.
In this Micro Video tutorial you will learn the basics about Database Availability Groups and How to configure one using a live Exchange Server Environment. The video tutorial explains the basics of the Exchange server Database Availability grou…
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question