Hi All,
I have a client with an exchange2k environment, they would like to separate the executives or at least gain some reasonable assurance that
IT isn’t/can’t read executive email. Exchange2k is configured by default to disallow administrator ‘read’ access to other person’s mailboxes but this is easily changed. My thoughts are to put some sort of watch/trigger on the event logs on events such as an Administrator accounts accessing executive email. I suppose the easy answer is that we have to trust our Adminstrators, but, in this case I feel that the client will not buy into that level of trust.
I am looking for opinions for this problem?
On a similar note, what sort of ‘key’ events would you guys consider red flags for malicious activity e.g. (repeated login failures)?