Hello and welcome to CertForums.co.uk, here we host free active certification forums with links to the best free resources for Microsoft's MCSA MCSE MCDBA Cisco's CCNA CCDA and CCNP, and CompTIA's A+ Network+ i-NET+ and Security+ certifications in the UK. If you wish to post or use other advanced features you will need to register first. Registration is absolutely free and takes only a few minutes to complete so sign up today!

If you have any problems with the registration process or your account login, please contact support

Go Back   CertForums > Computing Support Forums > Software
Home Forums Register Search Today's Posts Mark Forums Read

Restricting access on Exchange folders

Post New ThreadReply
 
Thread Tools Display Modes
  #1  
Old 15-May-2008, 03:13 PM
Leehaa's Avatar
Leehaa Leehaa is offline
Longterm Member
Posts: 994
Points: 726 Leehaa has over 500 pointsLeehaa has over 500 pointsLeehaa has over 500 pointsLeehaa has over 500 pointsLeehaa has over 500 pointsLeehaa has over 500 pointsLeehaa has over 500 points
Power: 20
None
Join Date: 07 Jul 2006
Age: 28
Certifications: MCP, MCDST, 70-270
WIP: 70-290
Restricting access on Exchange folders

We have a user who needs access to one of the email folders on our exchange server.
He also needs to be able to share his calendar with users on our domain.

He is external to the company and, should literally just be able to access the one folder, be blocked from all public folders.
Also, he has a MAC.

We figure that the best way would be to create him an internet email account on our exchange server (please tell if you can think of any other set-up) so that he can login to that and access the relevant folder...

What I'm not sure of is how to lock it down so that he is only able to view the relevant folder, and none of the others in the public folders (which I think all people need full access to by default)

Anyone got any ideas? Would it by some kind of GPO in AD, or would it be more simple than that?

He he...I know what exam I'm going to be studying for next, rather than 290!

Thanks in advance!


You need to step outside for the sun to shine down on you! (by me - lol)

Last edited by Leehaa : 15-May-2008 at 03:18 PM.
 
Reply With Quote
  #2  
Old 15-May-2008, 03:44 PM
kevicho kevicho is offline
Valued Member
Posts: 226
Points: 817 kevicho has over 500 pointskevicho has over 500 pointskevicho has over 500 pointskevicho has over 500 pointskevicho has over 500 pointskevicho has over 500 pointskevicho has over 500 points
Power: 11
None
Join Date: 07 Feb 2008
Location: Rotherham, UK
Age: 28
Certifications: MCSA (A+/N+/270/290/291), HND
WIP: CCNA
Quote:
Originally Posted by Leehaa View Post
We have a user who needs access to one of the email folders on our exchange server.
He also needs to be able to share his calendar with users on our domain.

He is external to the company and, should literally just be able to access the one folder, be blocked from all public folders.
Also, he has a MAC.

We figure that the best way would be to create him an internet email account on our exchange server (please tell if you can think of any other set-up) so that he can login to that and access the relevant folder...

What I'm not sure of is how to lock it down so that he is only able to view the relevant folder, and none of the others in the public folders (which I think all people need full access to by default)

Anyone got any ideas? Would it by some kind of GPO in AD, or would it be more simple than that?

He he...I know what exam I'm going to be studying for next, rather than 290!

Thanks in advance!
His access is via OWA (outlook web access) id imagine.

The public folders should just be a case of checking the permissions, the 2 to look for are default and anonymous.
If they are set correctly (ie the "folder visible" box unticked) then he would need to be specifically added for him to view and then on to amending/deleting stuff.

The calender thing, 2 things you could do, one open his account in outlook (as the main account, not a subfulder in someone elses account), and go into tools, options, delegates, then add the relevant people to what is needed, they in turn use the file - open other users folder to view it.

Or you could create him a public calender for him, then set permissions as appropriate.

Remember you can do all this in a normal outlook profile before trying it in OWA.

I personally would just get someone to forward all relevant emails to him, much easier for me and my department ;)


Last edited by kevicho : 15-May-2008 at 03:47 PM.
 
Reply With Quote
  #3  
Old 15-May-2008, 04:06 PM
Leehaa's Avatar
Leehaa Leehaa is offline
Longterm Member
Posts: 994
Points: 726 Leehaa has over 500 pointsLeehaa has over 500 pointsLeehaa has over 500 pointsLeehaa has over 500 pointsLeehaa has over 500 pointsLeehaa has over 500 pointsLeehaa has over 500 points
Power: 20
None
Join Date: 07 Jul 2006
Age: 28
Certifications: MCP, MCDST, 70-270
WIP: 70-290
Quote:
Originally Posted by kevicho View Post
His access is via OWA (outlook web access) id imagine
Yes - sorry!

Quote:
Originally Posted by kevicho View Post
The public folders should just be a case of checking the permissions, the 2 to look for are default and anonymous.
If they are set correctly (ie the "folder visible" box unticked) then he would need to be specifically added for him to view and then on to amending/deleting stuff
This is where it gets complicated - they are all visible as standard. For specific reasons ...i'm not sure the exact reasons (first week in the job), it needs to be left that all folders are visible (in terms of default and annonymous), but then access is restricted as appropriate...

(Just edited that - hope it makes a bit more sense!)


You need to step outside for the sun to shine down on you! (by me - lol)

Last edited by Leehaa : 15-May-2008 at 04:16 PM.
 
Reply With Quote
  #4  
Old 15-May-2008, 06:13 PM
NightWalker's Avatar
NightWalker NightWalker is offline
Longterm Member
Posts: 715
Points: 679 NightWalker has over 500 pointsNightWalker has over 500 pointsNightWalker has over 500 pointsNightWalker has over 500 pointsNightWalker has over 500 pointsNightWalker has over 500 points
Power: 19
None
Join Date: 04 Apr 2005
Location: Devon, UK
Age: 29
Certifications: A+, Network+, MCP, MCSA:M 2003
WIP: Active Directory 70-294
Quote:
Originally Posted by Leehaa View Post
Yes - sorry!



This is where it gets complicated - they are all visible as standard. For specific reasons ...i'm not sure the exact reasons (first week in the job), it needs to be left that all folders are visible (in terms of default and annonymous), but then access is restricted as appropriate...

(Just edited that - hope it makes a bit more sense!)
You could make a replica of the public folder on another exchange server (in another routing group) and set the permissions for him on that replica, locking it all down and leave the original copy and permissions intact for internal users to use.


A+, Network+, MCP, MCSA:Messaging 2003, (70-270, 70-284, 70-290, 70-291, 70-293).
Microsoft Course 2576.

CPU: C2D E6600 @ 3.2 Ghz
HSF: Zalman CNPS9500A-LED
Mobo: Asus P5K Premium-Black Pearl
Ram: Corsair XMS2 2x1GB DDR2-675MHz
GPU: Asus EN8600GT DX10
HD: OS = 1xWD1600YS
HD: Data = 3xWD1600JS RAID5
PSU: Hiper Type-R 530W
Case: Thermaltake VC3000BWS
Display: Samsung SyncMaster 2232BW
 
Reply With Quote
  #5  
Old 15-May-2008, 07:17 PM
Leehaa's Avatar
Leehaa Leehaa is offline
Longterm Member
Posts: 994
Points: 726 Leehaa has over 500 pointsLeehaa has over 500 pointsLeehaa has over 500 pointsLeehaa has over 500 pointsLeehaa has over 500 pointsLeehaa has over 500 pointsLeehaa has over 500 points
Power: 20
None
Join Date: 07 Jul 2006
Age: 28
Certifications: MCP, MCDST, 70-270
WIP: 70-290
Quote:
Originally Posted by NightWalker View Post
You could make a replica of the public folder on another exchange server (in another routing group) and set the permissions for him on that replica, locking it all down and leave the original copy and permissions intact for internal users to use.

Good idea thanks! Quite a lot to do for just one person, but having done a bit of research i'm not sure how else to get around it...


You need to step outside for the sun to shine down on you! (by me - lol)
 
Reply With Quote
  #6  
Old 15-May-2008, 07:25 PM
NightWalker's Avatar
NightWalker NightWalker is offline
Longterm Member
Posts: 715
Points: 679 NightWalker has over 500 pointsNightWalker has over 500 pointsNightWalker has over 500 pointsNightWalker has over 500 pointsNightWalker has over 500 pointsNightWalker has over 500 points
Power: 19
None
Join Date: 04 Apr 2005
Location: Devon, UK
Age: 29
Certifications: A+, Network+, MCP, MCSA:M 2003
WIP: Active Directory 70-294
Quote:
Originally Posted by Leehaa View Post
Good idea thanks! Quite a lot to do for just one person, but having done a bit of research i'm not sure how else to get around it...
Is the folder content static? if it is you could make a folder in the guys mailbox and copy in the data.


A+, Network+, MCP, MCSA:Messaging 2003, (70-270, 70-284, 70-290, 70-291, 70-293).
Microsoft Course 2576.

CPU: C2D E6600 @ 3.2 Ghz
HSF: Zalman CNPS9500A-LED
Mobo: Asus P5K Premium-Black Pearl
Ram: Corsair XMS2 2x1GB DDR2-675MHz
GPU: Asus EN8600GT DX10
HD: OS = 1xWD1600YS
HD: Data = 3xWD1600JS RAID5
PSU: Hiper Type-R 530W
Case: Thermaltake VC3000BWS
Display: Samsung SyncMaster 2232BW
 
Reply With Quote
  #7  
Old 15-May-2008, 07:29 PM
Leehaa's Avatar
Leehaa Leehaa is offline
Longterm Member
Posts: 994
Points: 726 Leehaa has over 500 pointsLeehaa has over 500 pointsLeehaa has over 500 pointsLeehaa has over 500 pointsLeehaa has over 500 pointsLeehaa has over 500 pointsLeehaa has over 500 points
Power: 20
None
Join Date: 07 Jul 2006
Age: 28
Certifications: MCP, MCDST, 70-270
WIP: 70-290
Quote:
Originally Posted by NightWalker View Post
Is the folder content static? if it is you could make a folder in the guys mailbox and copy in the data.
Unfortunately not. Shared between 3 or 4 people with a lot of data being moved around...


You need to step outside for the sun to shine down on you! (by me - lol)
 
Reply With Quote
  #8  
Old 16-May-2008, 09:53 PM
nugget's Avatar
nugget nugget is offline
Junior toady
Posts: 5,732
Points: 877 nugget has over 500 pointsnugget has over 500 pointsnugget has over 500 pointsnugget has over 500 pointsnugget has over 500 pointsnugget has over 500 pointsnugget has over 500 points
Power: 75
Join Date: 22 Jul 2003
Location: Switzerland
Certifications: A+ Network+ MCP's 270, 290 MCDST
WIP: MCSA 2003
If you're using public folders I take it you have Exchange 2003?

I don't know anything about 2003 but a little about 2007.

The way I'd do it is to create another group in AD and put him in it. Give his public folder the appropriate access permissions through this new group, and then add his group to all the other folders with deny permissions.

This is of course quite a lot of work if you have a lot of users with public folders, but you might be able to script it.


My little place.

Das hier ist euer Erbe, Doch wenn’s euch nicht gefällt
Dann werdet bessere Menschen, Und ihr kriegt ’ne bessere Welt
[Entfache dieses Feuer by the Böhse Onkelz]

My new PC
CPU: Intel Core 2 Quad QX9450
Graphics: Asus EN8800GTS 512MB
Mainboard: Asus R.O.G. Maximus Extreme
PSU: Be Quiet Dark Power BQT P7 - PRO-650W
RAM: 4GB OCZ Platinum XTC, DDR3-1333
 
Reply With Quote
Post New ThreadReply Spread this thread: Submit this thread to digg Submit this thread to del.icio.us


Go Back   CertForums > Computing Support Forums > Software


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Exchange 2007 and Backup Exec nugget Software 13 14-Dec-2007 11:24 PM
Learning Exchange 2007 ManicMonkey Exchange Exams 6 06-Dec-2007 07:40 AM
Exchange Management Shell Tips of the Day Mitzs Networking 0 30-Sep-2007 08:17 PM
Exchange Resource Mailboxes Jellyman_4eva Exchange Exams 5 24-Jul-2007 09:26 PM
Exchange 2007 and journaling to public folders Meltin Exchange Exams 3 15-May-2007 01:15 PM


All times are GMT. The time now is 09:04 PM.

Powered by vBulletin® Version 3.6.10
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
CertForums.co.uk (C) copyright 2003-2007 All Rights Reserved. Content published on CertForums.co.uk requires permission for reprint.
Hosted by Lunarpages