Article ID: 328753 - Last Review: February 28, 2007 - Revision: 1.5 XADM: Do Not Assign Mailboxes to Administrative Accounts
This article was previously published under Q328753 SUMMARY
Do not assign mailboxes to users or groups that are members of the following Microsoft Active Directory directory service security groups:
MORE INFORMATION
By not assigning mailboxes to accounts with administrative permissions, you avoid security issues related to "elevation of privilege" attacks. For example, in an elevation of privilege attack, a security hole exists in which Group X is made a member of the Domain Administrators group, and access control lists (ACLs) exist on Group X that permit Group Y to modify Group X. In this situation, members of Group Y can make themselves members of Group X and so become a member of the Domain Administrators group. To help guard against such security issues, the Administrator account and accounts that are members of these security groups are not permitted to inherit permissions. On the Security tab of the group or account's properties page, you can see that the Allow inheritable permissions from parent to propagate to this object check box is not selected. Moreover, if you click to select this check box, a Microsoft Windows 2000 system task soon clears it automatically. Clearing the check box is a function of Windows 2000 intended to prevent hackers from playing with security and inappropriately increasing their permissions to the level of administrator. As a side effect of this inheritance setting, if you do try to use a mailbox assigned to an administrative account, you may not be able to log on to or resolve the mailbox. Also, in Exchange System Manager, although the Administrator account can have an Exchange 2000 alias and an Exchange 2000 mailbox, it does not have e-mail addresses. The Recipient Update Service, which updates the e-mail addresses and several other attributes, does not have the authority to update objects if the Allow inheritable permissions from parent to propagate to this object check box is not selected. For additional information, click the article numbers below to view the articles in the Microsoft Knowledge Base: 268754
(http://support.microsoft.com/kb/268754/EN-US/
)
XADM: How to Assign Users or Groups Full Access to Other User Mailboxes
236168
(http://support.microsoft.com/kb/236168/EN-US/
)
XADM: Administrator Able to Change Permissions for Mailbox without Permissions Admin. Right
| Other Resources Other Support Sites
CommunityGet Help NowArticle Translations
|






Windows Live
Facebook
Twitter
Linkedin
Digg it
Yahoo
Delicious
StumbleUpon
Yammer
Reddit
Technorati
FriendFeed
Email
Back to the top
