General discussion
June 26, 2003 at 04:17 AM
fimos

Exchange2k – trusting Administrators

by fimos . Updated 23 years, 2 months ago

Hi All,

I have a client with an exchange2k environment, they would like to separate the executives or at least gain some reasonable assurance that
IT isn’t/can’t read executive email. Exchange2k is configured by default to disallow administrator ‘read’ access to other person’s mailboxes but this is easily changed. My thoughts are to put some sort of watch/trigger on the event logs on events such as an Administrator accounts accessing executive email. I suppose the easy answer is that we have to trust our Adminstrators, but, in this case I feel that the client will not buy into that level of trust.

I am looking for opinions for this problem?

On a similar note, what sort of ‘key’ events would you guys consider red flags for malicious activity e.g. (repeated login failures)?

This discussion is locked

All Comments