Microsoft KB Archive/328753

= XADM: Do Not Assign Mailboxes to Administrative Accounts =

Article ID: 328753

Article Last Modified on 2/28/2007

-

APPLIES TO


 * Microsoft Exchange 2000 Server Standard Edition

-



This article was previously published under Q328753



SUMMARY
Do not assign mailboxes to users or groups that are members of the following Microsoft Active Directory directory service security groups:
 * Administrators
 * Schema administrators
 * Domain administrators
 * Enterprise administrators

Additionally, do not use the user or group account to perform common user tasks, such as accessing a mailbox. It is not a best practice to assign mailboxes to accounts that have administrative permissions.



MORE INFORMATION
By not assigning mailboxes to accounts with administrative permissions, you avoid security issues related to &quot;elevation of privilege&quot; attacks. For example, in an elevation of privilege attack, a security hole exists in which Group X is made a member of the Domain Administrators group, and access control lists (ACLs) exist on Group X that permit Group Y to modify Group X. In this situation, members of Group Y can make themselves members of Group X and so become a member of the Domain Administrators group.

To help guard against such security issues, the Administrator account and accounts that are members of these security groups are not permitted to inherit permissions. On the Security tab of the group or account's properties page, you can see that the Allow inheritable permissions from parent to propagate to this object check box is not selected. Moreover, if you click to select this check box, a Microsoft Windows 2000 system task soon clears it automatically. Clearing the check box is a function of Windows 2000 intended to prevent hackers from playing with security and inappropriately increasing their permissions to the level of administrator.

As a side effect of this inheritance setting, if you do try to use a mailbox assigned to an administrative account, you may not be able to log on to or resolve the mailbox. Also, in Exchange System Manager, although the Administrator account can have an Exchange 2000 alias and an Exchange 2000 mailbox, it does not have e-mail addresses. The Recipient Update Service, which updates the e-mail addresses and several other attributes, does not have the authority to update objects if the Allow inheritable permissions from parent to propagate to this object check box is not selected.

For additional information, click the article numbers below to view the articles in the Microsoft Knowledge Base:

268754 XADM: How to Assign Users or Groups Full Access to Other User Mailboxes

236168 XADM: Administrator Able to Change Permissions for Mailbox without Permissions Admin. Right

Keywords: kbinfo KB328753

-

[mailto:TECHNET@MICROSOFT.COM Send feedback to Microsoft]

© Microsoft Corporation. All rights reserved.