Announcement

Collapse
No announcement yet.

Exchange 2003 users able to edit other user's calendar without permissions

Collapse
X
  • Filter
  • Time
  • Show
Clear All
new posts

  • Exchange 2003 users able to edit other user's calendar without permissions

    Hello dear Petri members,

    Our Exchange 2003 server is currently giving users the permission to edit other user's calendars in Outlook 2010. For example:
    User 1 can create appointments in any other user's calendar without sending an request for acceptance first. I for example currently can edit my bosses calendar without my boss has ever given me permission for that kind of action.
    I have checked the Exchange permissions on the calendar's in question and see nothing out of order there.
    How should i proceed in troubleshooting this kind of problem?
    Thanks in advance for any replies and i will keep this forum updated on the progress in solving this issue.

  • #2
    Re: Exchange 2003 users able to edit other user's calendar without permissions

    Can you open the entire mailbox as well if you try?
    cheers
    Andy

    Please read this before you post:


    Quis custodiet ipsos custodes?

    Comment


    • #3
      Re: Exchange 2003 users able to edit other user's calendar without permissions

      I have tried and the answer is yes i can open my bosses mailbox for example. Looks like an horrible security incident here.

      Comment


      • #4
        Re: Exchange 2003 users able to edit other user's calendar without permissions

        In Exchange System Manager i saw that the group Authenticated Users had Full Control permissions on the Server object. Deleted the group and waiting for the permissions to have effect, also checked the permissions on the mailbox store and storage group. Nothing out of order there. Hopefully deleting the server permissions for that group helped in solving this problem.

        Comment


        • #5
          Re: Exchange 2003 users able to edit other user's calendar without permissions

          Changing this permission had effect on the active permissions. User's are not able to open eachother's mailbox or make an appointment in another user's calendar. Case solved!

          Comment

          Working...
          X