Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chriss Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Certain groups have "Send as" permission by default

Status
Not open for further replies.

PScottC

MIS
Mar 16, 2003
1,285
US
I just performed a clean install of Windows Server 2003 with Exchange 2003 on a new test domain. I have been examining the ACE's on default and new user object that I am creating in the directory and I'm finding that the following groups have the "Send As" permission:

Administrators
Domain Admins
Enterprise Admins
Account Operators

As user accounts are created, these groups are given "Full" access to the object. The rights are not inherited.

It seems to me that this constitutes a security risk. I do not want users in any of those groups, especially Account Operators, to be able to "Send as". This allows anyone who is a member of these groups to masquerade as someone else through email. It would be better for me to specifically delegate this permission.

I've checked several domains and this permission structure seems to be ubiquitous.

Comments?

PSC

Governments and corporations need people like you and me. We are samurai. The keyboard cowboys. And all those other people out there who have no idea what's going on are the cattle. Mooo! --Mr. The Plague, from the movie "Hackers
 
I performed some more testing on this tonight. I found that only members of the Domain Admins and Enterprise Admins groups can actually perform a "Send As" action. The other groups listed above are given an access denied error message.

This makes me feel significantly better, but I still wonder why the permission structure was set up this way...

PSC

Governments and corporations need people like you and me. We are samurai. The keyboard cowboys. And all those other people out there who have no idea what's going on are the cattle. Mooo! --Mr. The Plague, from the movie "Hackers
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top