Exchange 2007, anyone can send as to anyone
Hi,
today i found out that ANY user can send as ANY user from Global Address list without setting any permissions on Send As permissions tab. I found an article http://social.technet.microsoft.com/Forums/en-US/exchange2010/thread/df365e57-80b0-4d60-890d-72c36742b072/.
I checked the solution, but I didn't found a unkown user GUID, only the account SELF has the Send as permission <not inherited> and Everyone only has the "change password" permission. My user isn't member of an administators account
How can I disable the send as permission for all users, please help, Thanks
my configuration, Exchange 2007 Version 08.02.0176.002, Windows Server 2003x64 latest patches from November 2010
December 22nd, 2010 9:15am
The behaviour you are seeing isn't standard. There also isn't a single answer to the question, because something has obviously been changed on the domain for this behaviour to occur.
You need to go through the domain and look for what does have Send As permissions. Groups are the usual cause.
You will need to look in ADUC as well as the Exchange Management console.
Don't forget that after making a permission change, Exchange caches permissions for up to 2 hours, so don't expect the change to be effective immediately if you are testing things.
Was this is a migration from Exchange 2003?
Simon.Simon Butler, Exchange MVP
Blog |
Exchange Resources
Free Windows Admin Tool Kit Click here and download it now
December 22nd, 2010 11:25am
Run ExBPA in permission check mode please.
http://www.microsoft.com/downloads/en/details.aspx?FamilyID=dbab201f-4bee-4943-ac22-e2ddbd258df3&displaylang=en
Regards, Pushkal MishrA
December 22nd, 2010 12:23pm
Run ExBPA in permission check mode please.
http://www.microsoft.com/downloads/en/details.aspx?FamilyID=dbab201f-4bee-4943-ac22-e2ddbd258df3&displaylang=en
Regards, Pushkal MishrA
Free Windows Admin Tool Kit Click here and download it now
December 22nd, 2010 8:18pm
Hi,
In Exchange 2007, if a delegate account also has Full Mailbox Access permission to a mailbox, the delegate user can send as the mailbox owner without having the Send
As permission specified. So please check whether the user who has the Full Mailbox Access permission to a mailbox also is a delegate account.
And here is a document for you.
Understanding Send As Behavior in Exchange 2007:
http://technet.microsoft.com/en-us/library/dd421860(EXCHG.80).aspx
Best regards,
SerenaPlease remember to click Mark as Answer on the post that helps you, and to click Unmark as Answer if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.
December 24th, 2010 3:50am
Hi,
thanks for reply. I checked all your tips and I have a solution.
Some time ago I delegate some permissions (create, modify user account etc) in AD to a group. This group had the send as permission in ADUC. I changed the setting and was waiting, and now it works correctly.
Thanks, and happy new year
Free Windows Admin Tool Kit Click here and download it now
December 27th, 2010 9:21am
Hi,
Thanks for sharing.
Best regards,
Serena
Please remember to click Mark as Answer on the post that helps you, and to click Unmark as Answer if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.
December 27th, 2010 8:34pm