Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations bkrike on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

SOBO Sending of Behalf Of

Status
Not open for further replies.

clancyfan

IS-IT--Management
May 12, 2004
67
CA
Hello, I recently discovered that any user on my current network can send on behalf of any other user. This is a big security risk and no such permissions have been set that I can find to allow this.

Running Exchange 2000 on Windows 2000 Server.
 
This may be a stupid question, but I hope your domain users are not members of the domain or exchange admins groups? I'd definitely check group membership
 
Good question, but no they are not members of the Domain or Exchange admins. I will review group membership. I wasn't the one who originally setup the server so there are probably some memberships or groups that I am not aware of yet.
 
Looks like the account in question was a member of the Domain Admins security group. I didn't realize, and still don't understand, how that was giving him permission to send on behalf of any user in the domain. I will have to do a bit more research to find out if that is the way 2K Server sets things up.

 
Exactly.

It's related to mailbox perms. In ADUC, User Properties, Exchange Advanced, you'll see Mailbox Rights. Domain Admins, by default, have Delete, Read, Change, Take Ownership, (Deny Full Mailbox Access).

Always a good reason to *strictly limit* membership of Domain Admins....
 
In my ADUC, user properties I don't have an exchange advanced. Only exchange general and exchange tasks.

??
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top