Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


May 10, 2007

A Cautionary Tale about Mailbox Administration


RSS
Subscribe to Windows IT Pro | See More Exchange Server and Outlook Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

Storytelling is a venerable human trait. Instead of swapping hunting stories around a primitive campfire, IT professionals tend to exchange their war stories at trade shows or via email. Recently, a customer told me a story that I think highlights some interesting aspects of day-to-day Exchange Server management.

First, you need to know the players. Alice was a senior Help desk technician. Bob was her boss. Carol was a senior executive, and Dave was a junior Help desk tech.

One day, for some reason known only to herself, Alice composed, and then sent, a profanity-laden rant to Carol and copied several other managers. Alice realized her mistake fairly quickly and contacted Dave. She asked him to delete the offending email message from Carol's Inbox. Here's where things get interesting.

As directed, Dave used the service account for the backup software to log on to Carol's mailbox and remove the offending email message. Unfortunately, Carol had already seen the message and replied to it, as had several of the other addressees. Dave subsequently deleted the message from the other addressees' mailboxes as well, but it was too late. The cat was out of the bag.

Bob was out of town while this transpired. When he returned, he had to deal with an angry Carol, a fearful Dave, and Alice, who had tried to cover her tracks by trimming her 8GB mailbox down to a few hundred megabytes. After an investigation, which didn't take long given the blatant nature of Alice's misconduct, Alice was fired, Dave received a reprimand, and Bob took a lot of antacids.

What's interesting about this case? If the story were only about poor self-control on the part of a frustrated email sender, it wouldn't be worth retelling; we've all been there at one time or another. However, this story points out some things you should evaluate in your own environment:

  • If you use a service account that has access to multiple mailboxes, you should guard it and audit its use. If a junior technician has the password, there's no telling who else might have it or what they might be doing with it. Better still, consider using Microsoft Volume Shadow Copy Service (VSS)-based solutions that don't require access to individual mailboxes.
  • Dave should have known better than to accept a request to tamper with someone's mailbox, even though Alice was senior to him. Do your junior employees have clear guidelines for what they can and can't do to other users' mailboxes? Does your management culture back up those guidelines with support for people who refuse to violate them?
  • Carol was rightly suspicious after the offending message disappeared from her mailbox. If senior executives at your organization ever have reason to doubt the integrity of your messaging system or its administrators, it will be difficult for you to restore credibility.
  • Alice's sudden purging of her mailbox was suspicious, too. Naturally, Bob wanted to know what might have been deleted, so he restored the mailbox database to a recovery storage group and copied its contents for inspection. An alternate solution would have been to use a tool that can directly mount mailboxes from a dismounted .edb file, but in this case the built-in tools served their purpose.
  • Because this organization was using Exchange Server 2003, they didn't have an effective way to do cross-mailbox searches without using a third-party product. This made the investigation into Alice's deeds a bit more complicated; if she had been involved in other wrongdoing, the inability to find content might have been more of a problem.

As Shakespeare said, all's well that ends well, and in this story justice was served. This kind of thing happens more often than you would think, and it makes sense to be prepared so that if it happens in your organization you'll be able to resolve the problem quickly, fairly, and accurately.

End of Article



Reader Comments
What tools are available to directly mount an edb file? This would be an ideal solution for those that take SAN snapshots, eliminating the time and effort of using recovery storage groups.

pwtrnut May 10, 2007 (Article Rating: )


Yes, please...what tools can read mailboxes directly from an EDB?

And also, what tools can do cross-mailbox searches?

tscalzott May 10, 2007 (Article Rating: )


There are several tools that can directly mount EDBs: Ontrack PowerControls, AppAssure Replay, and Quest Recovery Manager for Exchange are the first ones that come immediately to mind.

As for cross-mailbox searches, normally that's a feature provided by archiving systems, whether you host them (Zantaz, Symantec Enterprise Vault, Quest Archive Manager) or use a hosted service (MessageOne EMS, Microsoft EHS Archiving, Fortiva). Lots to choose from :)

paulrobichaux May 10, 2007 (Article Rating: )


Ontrack Powercontrols is awesome. We used it to restore mailboxes that were deleted by a hacker break-in. Saved us having to have duplicate hardware to restore the whole edb, not to mention the interruption of service for unaffected mailboxes. I am a big fan.

mberli1 May 10, 2007 (Article Rating: )


Thanks for the recommendations...we will definitely look @ Ontrack, AppAssure and Quest. If anyone has pros/cons for a 1 Exchange 2k3 server/500+ mailbox shop, let me know. Thanks Paul.

pwtrnut May 11, 2007 (Article Rating: )


You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
No Jobs, No Excitement at Apple's Last Macworld Keynote

Apple CEO Steve Jobs made the right move in skipping out on his company's last appearance at Macworld: In a Tuesday keynote address at the conference, Apple had no interesting new products to sell, opting instead to spend mind-numbing amounts of time on ...

Where is Microsoft NetMeeting in Windows XP?

...

Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...


Related Articles Professional Development for Exchange and Outlook Pros

Exchange Server and Outlook Whitepapers Protecting (You and) Your Data with Exchange Server 2007

StoreVault SnapManagers for Microsoft Exchange and SQL Server

Related Events Storage Consolidation for Your Microsoft Applications: Reducing Cost and Complexity

How IE7 & The New Extended Validation SSL Certificates Impact Your Site

Top 10 Email Security Challenges and Solutions

Check out our list of Free Email Newsletters!

Exchange Server and Outlook eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

The Expert's Guide for Exchange 2003: Preparing for, Moving to, and Supporting Exchange Server 2003

Related Exchange Server and Outlook Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.

Exchange & Outlook UPDATE eNewsletter
News, strategies, products, and developments in Exchange Server and Outlook messaging.

Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2009 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing