Article ID: 313807 - Last Review: February 27, 2007 - Revision: 3.2 XADM: Enhancing the Security of Exchange 2000 for the Exchange Domain Servers GroupThis article was previously published under Q313807 On This PageSUMMARY
This article describes how to obtain and use a script that restricts access to the Exchange Domain Servers groups across a forest. A default Exchange installation creates an Exchange Domain Servers group for each domain within the forest. This group contains the computer accounts for each Exchange server within a given domain. These groups are granted access to all Exchange public folder and mailbox stores in the forest. Customers may want to restrict access to mailbox stores to only the local server that hosts the stores. MORE INFORMATION
To further enhance the security model of Exchange, a script is available from the Microsoft Download Center that restricts access to the Exchange Domain Servers groups across the forest. The following file is available for download from the Microsoft Download Center: Collapse this image ![]() 119591
(http://support.microsoft.com/kb/119591/EN-US/
)
How to Obtain Microsoft Support Files from Online Services
Microsoft scanned this file for viruses. Microsoft used the most current virus-detection software that was available on the date that the file was posted. The file is stored on security-enhanced servers that help to prevent any unauthorized changes to the file.
Script UsageThe script must be run for each Exchange server in the organization and the script requires the distinguished name of the Exchange server, for example:
cscript edslock.vbs "CN=Mail1,CN=Servers,CN=America AG,CN=Administrative Groups,CN=Microsoft, CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=America,DC=microsoft,DC=com
The script performs the following actions:
Script Deployment GuidelinesThe script can be run on any server in the forest and does not have to be copied locally to each Exchange server. The account that runs the script must have full write access to the configuration naming context. Microsoft recommends that the Exchange Full Administrator perform this function because Exchange Administrators and Domain Administrators do not have these permissions.If you restore an information store from a backup tape to a different server, you must run the script again to reset the permissions on the store. EDSlock Q313807 UpdatesTo verify that the patch has been installed on the computer, confirm that the following registry key has been created on the server:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Updates\Exchange Server 2000\SP2\Q313807
To verify the individual files, use the date/time and version information provided in the following registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Updates\Exchange Server 2000\SP2\Q313807\filelist
File Installation:The script (EDSlock.vbs) is installed in the following directory:
%WinDir%\System32\Q313807
The script is not run as part of the installation process.
| Article Translations
|
Back to the top

