Urgently need help with Exchange 2000 / Active Directory security issue

From: Sw (swilliams_at_cromwells.co.uk)
Date: 12/30/04


Date: 30 Dec 2004 05:52:04 -0800

We recently had what appears to be someone logging onto the Exchange
2000 server and setting any mail sent to two domain users to be also
forwarded to an external recipient (Contact) that I had set up
previously. This is the second time this has happened in 6 months, and
meant the user whose Contact address this was, was getting mail
destined for these 2 users- obviously a big security risk. Is there ANY
way of finding out which domain user might have made the changes to the
Active Directory objects for these users? Neither previously had any
forwarding set up in Delivery Options.

There doesn't seem to be anything in Event Viewer for this kind of
change, and I can't see any way at all how Active Directory would
choose to set up forwarding to an external recipient in this way.
Furthermore this is the second time this has occurred and there appear
to be patterns (personnel-wise) linking the two events. I'm almost
completely certain that this is deliberate. I have been tasked with
finding out who has done this as quickly as possible.

I've set auditing in Active Directory but for Exchange options I think
you need to set it within Exchange System Manager- but can't seem to
see where auditing for this option is set.

This is extremely urgent, so any help anyone can give me would be much
appreciated! Please reply to the thread or email me
- swilliams at cromwells.co.uk. Thanks for your assistance.



Relevant Pages

  • Re: SBS 2008 Teething issues:
    ... In SBS 2008, you need to create the contacts for mail forwarding in Exchange Management Console. ... The key to keep in mind with SBS 2008 is that a lot of things that we're used to doing from Active Directory are now done from Exchange. ...
    (microsoft.public.windows.server.sbs)
  • Exchange 2K forwarding to external- need to know who has set this up on AD users - V. urgent!!!
    ... 2000 server and setting any mail sent to two domain users to be also ... Active Directory objects for these users? ... There doesn't seem to be anything in Event Viewer for this kind of ... choose to set up forwarding to an external recipient in this way. ...
    (microsoft.public.exchange.admin)
  • Someone has meddled with Active Directory users (has set email forwarding to external account)- how
    ... 2000 server and setting any mail sent to two domain users to be also ... Active Directory objects for these users? ... There doesn't seem to be anything in Event Viewer for this kind of ... choose to set up forwarding to an external recipient in this way. ...
    (microsoft.public.exchange2000.misc)
  • Someone has meddled with email forwarding for 2 Active Directory users- how can I find out who?
    ... 2000 server and setting any mail sent to two domain users to be also ... Active Directory objects for these users? ... There doesn't seem to be anything in Event Viewer for this kind of ... choose to set up forwarding to an external recipient in this way. ...
    (microsoft.public.security)
  • Re: Exchange 2003 Server Email Forwarding
    ... Create a Contact in Active Directory and set the e'Mail address ... In Exchange General Delivery Options enter the Contact ... you created and select to deliver to both forwarding address ... > In linux it was done by updating /etc/alias ...
    (microsoft.public.windows.server.sbs)