Hello, I recently discovered that any user on my current network can send on behalf of any other user. This is a big security risk and no such permissions have been set that I can find to allow this.
This may be a stupid question, but I hope your domain users are not members of the domain or exchange admins groups? I'd definitely check group membership
Good question, but no they are not members of the Domain or Exchange admins. I will review group membership. I wasn't the one who originally setup the server so there are probably some memberships or groups that I am not aware of yet.
Looks like the account in question was a member of the Domain Admins security group. I didn't realize, and still don't understand, how that was giving him permission to send on behalf of any user in the domain. I will have to do a bit more research to find out if that is the way 2K Server sets things up.
It's related to mailbox perms. In ADUC, User Properties, Exchange Advanced, you'll see Mailbox Rights. Domain Admins, by default, have Delete, Read, Change, Take Ownership, (Deny Full Mailbox Access).
Always a good reason to *strictly limit* membership of Domain Admins....
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.