[Last Call] Learn about multicloud storage options and how to improve your company's cloud strategy. Register Now

x
?
Solved

Exchange 2010 account @iphone is getting emails even after password change

Posted on 2016-10-11
8
Medium Priority
?
70 Views
Last Modified: 2016-10-12
I have a SBS 2011 box with pre installed Exchange 2010 Version 14.3 (Build 123.4)
Users are receiving emails at iPhone. I noticed a strange thing; even after changing password of windows logon account, users can still receive & send emails at iPhone even without updating the new password in the iPhone exchange account settings.

iPhone asked the new password after restarting the server only.

Is it the genuine procedure or is the server got compromised? If its a policy, where to find & modify the policy.

Thanks for reading the concern.
0
Comment
Question by:Akash Bansal
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 4
8 Comments
 
LVL 59

Accepted Solution

by:
Cliff Galiher earned 2000 total points
ID: 41839544
Perfectly normal. Authentication issues a token for a length of time and that token os still valid after a password change. You won't have to re-auth until the token expires. You really don't want to mess with this behavior. It has ramifications well beyond exchange.
1
 
LVL 2

Author Comment

by:Akash Bansal
ID: 41839547
What is the token age normally? Worried if my server is compromised or not.
0
 
LVL 59

Assisted Solution

by:Cliff Galiher
Cliff Galiher earned 2000 total points
ID: 41839552
Several hours. Is there a reason you think the server is compromised?
1
Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

 
LVL 2

Author Comment

by:Akash Bansal
ID: 41839554
Thanks.
User having admin privilege  reported a suspicious attachment he opened.
I submitted it to Avira; now it is added to the virus definition.


https://analysis.avira.com/en/status?uniqueid=5v1rPZISYhnBq1FR0vdkSVqFDNqYZtDA&incidentid=2099562

A few months back one of my friend lost money as his google mail password was hacked & hacker successfully diverted some expected payments to his account. The friend click almost the same type of link in pdf file & innocently entered his password to the phishing link.
0
 
LVL 59

Expert Comment

by:Cliff Galiher
ID: 41839712
Well, as a general rule, admins should have separate admin accounts. For example, I may have an account called "cliff" that is a standard user that has an exchange mailbox and is a standard user, and "admin-cliff" that does *not* have an exchange mailbox and is used for admin tasks.  Admin accounts are further secured with 2FAband/or all external access blocked. That way admin credentials would never be leaked how you described.
1
 
LVL 2

Author Comment

by:Akash Bansal
ID: 41840168
Yes! You are correct, I would advice my friends to make separate admin accounts.
What is 2FAband?
0
 
LVL 59

Expert Comment

by:Cliff Galiher
ID: 41840952
Typo. 2FA and/or.
1
 
LVL 2

Author Comment

by:Akash Bansal
ID: 41841401
As google mail has an option to sign out from all devices. So after changing the password of gmail, we click on "sign out all other web sessions", I guess this ensure that all other devices are forced logout.

How can we do it with on premises exchange 2010/2013 or 2016 users sessions.
0

Featured Post

Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

How to deal with a specific error when using the Enable-RemoteMailbox cmdlet to create a mailbox in the cloud-based service, for an existing user in an on-premises Active Directory.
Want to know how to use Exchange Server Eseutil command? Go through this article as it gives you the know-how.
In this Micro Video tutorial you will learn the basics about Database Availability Groups and How to configure one using a live Exchange Server Environment. The video tutorial explains the basics of the Exchange server Database Availability grou…
This video demonstrates how to sync Microsoft Exchange Public Folders with smartphones using CodeTwo Exchange Sync and Exchange ActiveSync. To learn more about CodeTwo Exchange Sync and download the free trial, go to: http://www.codetwo.com/excha…
Suggested Courses

650 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question