Determine if an admin opened up a users mailbox

With Exchange 2003 you would see event ID's whenever an admin (or another user with mailbox permissions) opened up another users mailbox (e.g. added their mailbox to their Outlook profile).
I'm currently trying to use the EAC to create a mailbox audit log search. After filling in the Start date, End date, leaving the "Search these mailboxes" field blank to go through all the mailboxes on our system, and selecting "All non-owners",
I'm not getting any results. I was under the impression the logging for this type of search was on by default.
Thanks for any feedback,
Dan

I'm not sure that it is enabled.
I researched this a while ago and shared my findings in a blog post:
http://davidmtechblog.blogspot.com/2013/07/exchange-2010-security-auditing.html
It looks like you are using Exchange 2013, since you mention "EAC", even though this is in the "Exchange 2010" section of the forum.
Regardless, at the end of my blog post, there are references to auditing in O365; the interface should be the same for on-premises Exchange 2013.
Please mark as helpful if you find my contribution useful or as an answer if it does answer your question. That will encourage me - and others - to take time out to help you.

Similar Messages

  • How to determine which file descriptor opened my driver?

    Suppose a user process opens my driver twice. How does open() determine which file descriptor opened the device? In Linux, the kernel will pass a pointer to a structure which represents the open file descriptor. However, Solaris only passes the device number to open(), so I can only determine my device was opened, but not which file. I need this information because my driver needs to keep track of all file descriptors opened for the device.
    Thanks!
    -Darren

    I'm still at a loss why you need to know the file descriptor value (unless the app is sufficiently spaghettied that it has to query the driver to figure out what it opened with what). It's like asking what filename was used to open the device (which you can't get either). Since Solaris is based on a Streams framework, it would be bad to have drivers to even think it has a direct mapping into user space. It would be the same in asking (using /bin/sh):
    prog3 4>&1 3>&1 2>&1 | prog2 | prog1
    and you want to know from prog1 what descriptor prog3 wrote to. I don't see how linux even does this properly, since any given file open can have multiple file descriptors (via dup).

  • Resetting the Admin password in single user mode

    Ok, my friend bought an old Imac from someone she went to school with with OS 10.4.2 on it. It works fine except that she can not install any programs because there is an admin password that she does not know. She asked the person she bought it from, he says he doesn't even remember setting a password. Normaly with this issue id just pop in the install disk and reset it from there, except neither of them have the install disk, and my install disk is to current for the machine. Does anyone know how I can reset the admin acount using single user mode commands? I can do it on my Mac Book pro but it doesn't seem to work the same way on 10.4. Please help!
    EDIT: It is a Power PC G3 if that helps.
    Message was edited by: CartooNxHerO

    CartooNxHerO wrote:
    Ok, so I used the advice from the third link you gave me but i'm still in single user mode trying to figure out how to delete the users home folders.
    Message was edited by: CartooNxHerO
    You do not need to delete "the users home folders". Nor do you need to delete the netinfo database. Here are two proceedures:
    Change Password
    Mac OS X:
    Changing or resetting an account password via GUI:
    Resetting a user's password
    Resetting the original administrator account password
    http://docs.info.apple.com/article.html?artnum=106156
    You do not have a CD/DVD
    Changing password from single user mode:
    You can also change the administrator's password from single user mode or create a new administrator account.
    You need to get into single use mode for steps one and two that are listed below.
    This page will tell you how to get into single user mode.
    http://support.apple.com/kb/HT1492
    Basically, you hold down the command-s key then powering on your machine. The command key has a little apple symbol on the lower left. It is between the alt/option key and the space bar. On a PC keyboard, it will be the windows key, I think.
    1) You can change the password on an account. ( Do you know Unix. You are in a Unix single user console. ) The setup commands you need should be listed on the screen. For Mac OS 10.4.11, the commands are:
    # Type the follow two instructions to access the startup disk in read/write:
    /sbin/fsck -fy
    /sbin/mount -uw /
    # Start up some utility processes that are needed.
    sh /etc/rc
    # You will probably need to press the return key once the system stops typing.
    # To find out the users on the system type, use the list command. The l is a lower case L:
    ls /Users
    # One of these accounts will be the administrator.
    # Pick one of the users which I'll call a-user-name and type it in this command:
    passwd a-user-name
    # and enter the new user password. You need six characters.
    # You will need to enter your password twice. Your typing will not show up on the screen just
    # press enter when you complete the typing.
    # For cryptic information on these commands try:
    man ls
    man passwd
    The root account isn't enabled by default. I am not sure if changing the password on root will enable it.
    2) Get the Mac to set up an additional administrative account. You can then change the password on your old account.
    Start with your computer power off. Hold down command-s. Power on your computer.
    Type in the following:
    The first two commands will depend on your release of Mac OS X. Look at what is typed out in the console to determine the exact format.
    # Type the follow two instructions to access the startup disk in read/write. Press return after each command.
    /sbin/fsck -fy
    /sbin/mount -uw /
    cd /var/db
    pwd
    #List all files. The l is a lower case L.
    ls -a
    #The move command acts as a rename command in this format.
    mv -i .applesetupdone .applesetupdone.old
    reboot
    Once you've done that the computer reboots and it's like the first time you used the machine. Your old accounts are all safe. From there you just change all other account passwords in the account preferences!!
    Limnos adds detailed explainations:
    http://discussions.apple.com/message.jspa?messageID=8441597#8441597
    The above the idea came from a post by JoseAranda at September 9, 2006 3:48 AM
    http://www.askdavetaylor.com/howdo_i_reset_my_mac_os_x_admin_rootpassword.html
    You will need to scroll down to see this post. Search for applesetupdone
    Or see:
    http://superpixel.ch/articles/running-setup-assistant-again/
    Once you have a new administrative account, you can change the password of your old administrative account
    blue apple > System Preferences > Accounts

  • Photoshop elements does not open, says "gathering user info...."

    photoshop elements does not open, says "gathering user info...."

    Hi,
    Please try couple of probable solutions as mentioned below:
    Solution 1:
    1. Close Elements.
    2. Launch the Photoshop Elements Welcome Screen and hold down ctrl + alt + shift as you click Editor.
    3. Continue to hold the keys until you see a message box asking if you want to delete Photoshop Elements settings file; click Yes. Elements will open with default preferences.
    Solution 2: In case any network printer is attached try to launch without network or printer uninstall or make different printer as default.
    Solution 3: Try launching with anti-virus off or removing PSE from conflicting list.
    Solution 4:
    On the drive on which you have installed PSE,on my machine it is on C:
    Go  to C:\Program Files\Adobe\Photoshop Elements  9\Locales\<locale>\Plug-Ins\Import-Exportand you will find twain  plug-in. Remove that plug-in from that location and copy it somewhere  else.
    Now launch PSE and check if it works.
    Solution 5: Try with admin account or right click and select run as admin. or try directly from .exe
    For related post for Twain please see this:http://forums.adobe.com/message/2954743#2954743
    Thanks,
    Garry

  • Exchange 2013 Give domain Admin access to all users inbox

    In the old 2007 exchange server we had domain admin access to everyones mailbox so we could open anyones email box using outlook client.
    But in 2013 exchange the mailbox delegation does not give us the option to add a "group" to the full access area, old allows to add a "user" who has a mailbox setup in exchange. I see there is Exchange Server group listed under Full Access
    , but it does not work added our domain Admin user to that group rebooted exchange and the test machine but did not work.
    Only option that works to allow mounting of xyz users mailbox via abc admin user is to actually add that abc admin user to the xyz mailbox under mailbox delegation > Full Access.
    Is  there a work around this, so we can simply have a group ABCD with user ABC or DEF etc. etc. so they can access everyones mailbox instead of going in and changing all users mailbox delegation one by one for the new user etc. ?

    Have you tried using the Exchange Management Shell?
    Get-Mailbox | Add-MailboxPermission -User Name_of_Group -AccessRights FullAccess -InheritanceType All
    Ed Crowley MVP "There are seldom good technological solutions to behavioral problems."
    I did i tried get-mailboxpermission and other than NT Authority and the end user the Deny was set to True for all inheritance rights. I tried your command, added user to the group i wanted under Enterprise OU in AD and restarted transport on exchange and
    logged in on the test machine again.
    Still no go, the user I am trying to add when using get-mailboxpermission shows up as Denied for fullaccess so is that overriding the group permissions ?
    RunspaceId      : 2xxxxxxx0
    AccessRights    : {FullAccess}
    Deny            : True
    InheritanceType : All
    User            : domain\abc
    Identity        : domain/Users/xyzuser
    IsInherited     : False
    IsValid         : True
    ObjectState     : Unchanged
    And for the group i just added with the above abc user inside it:
    RunspaceId      : 2xxxxxxxxx0
    AccessRights    : {FullAccess}
    Deny            : False
    InheritanceType : All
    User            : domain\newgroupadded
    Identity        : domain/Users/xyzuser
    IsInherited     : False
    IsValid         : True
    ObjectState     : Unchanged
    So is the users deny is causing this ? Not really sure why ABC domain admin/enterprise admin is the only one listed as no deny, there are other mailbox users that do not show up, I am assuming I have to create a new user a domain local user and that might
    work ? I wanted the Domain/Enterprise Manager/admin to have access so we would not have to keep toggling between users just to access someones inbox.
    Also further down the list of mailboxpermission i see the user abc (the user i want to add to the group to have access) is listed with Full access and Deny flag is set to False instead of True.
    So have two entries for user abc one with deny flag set to true and one with deny flag to false.
    AccessRights    : {FullAccess, DeleteItem, ReadPermission, ChangePermission, ChangeOwner}
    Deny            : False
    InheritanceType : All

  • One application won't open for one user

    We are doing a rollout of Macbook Pros to a group of people. We have used migration assistant for 20 computers. One application will not open for one user on each of the computers. The applicaiton will open for users that are added, but not the admin user that the application was originally installed. We have tried uninstalling and reinstalling the application with the same results. The one user can not log in. The permissions look right for all files.

    How about clarifying some things for me? Does each machine have a different admin user? What user installed the application that won't open (you say there is only one?) How many users on each machine - one or many? How many admin users are there? How many users are Standard or Managed users? What user "can not log in?" Is this on one machine or all machines? Which is the application that won't open, where is it installed, what are the permissions for the application, what are the permissions for the folder in which it's installed?
    Are these computers on a network or operating standalone or does each person in the group have their own separate machine?
    From where did you migrate for these 20 computers and why did you use Migration Assistant? MA is not the correct tool for doing a multi-system configuration. This is usually done using a net-based installation from a machine running OS X Server or from an XServe or by creating a standard system DVD and installing via ASR.

  • Hi, I hope someone can help.... When I open a new user account, which I want to set parental control on, the screen keeps freezing once the account is open. The wee rainbow circle appears and I can't do anything. Does anyone know how to fix this? Thanks

    Hi, I hope someone can help.... When I open a new user account, which I want to set parental control on, the screen keeps freezing once the account is open. The wee rainbow circle appears and I can't do anything. Does anyone know how to fix this? Thanks

    Could be many things, we should start with this...
    "Try Disk Utility
    1. Insert the Mac OS X Install disc, then restart the computer while holding the C key.
    2. When your computer finishes starting up from the disc, choose Disk Utility from the Installer menu at the top of the screen. (In Mac OS X 10.4 or later, you must select your language first.)
    Important: Do not click Continue in the first screen of the Installer. If you do, you must restart from the disc again to access Disk Utility.
    3. Click the First Aid tab.
    4. Select your Mac OS X volume.
    5. Click Repair. Disk Utility checks and repairs the disk."
    http://docs.info.apple.com/article.html?artnum=106214
    Then try a Safe Boot, (holding Shift key down at bootup), run Disk Utility in Applications>Utilities, then highlight your drive, click on Repair Permissions, reboot when it completes.
    (Safe boot may stay on the gray radian for a long time, let it go, it's trying to repair the Hard Drive.)
    Report any errors it found for Disk Repair, don't need the ones for Permissions Repair.
    Try it again & see if anything changed, but have Activity Monitor open & Show All Processes & sorted on CPU%, also have Console open if we can... maybe not when switching, but we'll see.
    Does this happen if you just try to create a new admin user???

  • Server allows overwriting files that are open by other users.

    We're having a problem with Snow Leopard Server not warning a user when they attempt to overwrite a file that is open by another user.
    Running Snow Leopard Server 10.6.8 on an Xserve with an Xserve RAID. Have about 25-30 Mac clients, running 10.6.8 or 10.7.3. Users running Adobe CS5.5
    Here's the scenario:
    User edits a file in InDesign, then saves a PDF of that file to the server. The user's supervisor reviews the file, and perhaps adds comments to it, but not necessarily.
    The user edits the ID file again, and saves a new PDF over the old one. When we were running Server 10.4.x, the user would have been warned that the PDF file was open by another user, and would have been prevented from saving. Under SL Server, no warning takes place, and the file is overwritten.
    At this point, a couple of things can happen.
    1: The new file is written, and the changes can be seen by the user. The supervisor's computer does not see the new version of the file. Quicklook and opening the file into Acrobat 10 will still show the old file. Disconnecting and reconnecting fixes this.
    2: The new file is written, but it is corrupted, and not openable by either party. If neither one opens the file right away, this could go unnoticed.
    I've tested this scenario between two Lion machines, and the "file-open" warning occurs like it should.
    Is there a setting in SL Server that I need to look at, or is this a bug?
    Our short-term fix is to have the user always save to a new filename. This can work, but it's cumbersome.

    We're having a problem with Snow Leopard Server not warning a user when they attempt to overwrite a file that is open by another user.
    Running Snow Leopard Server 10.6.8 on an Xserve with an Xserve RAID. Have about 25-30 Mac clients, running 10.6.8 or 10.7.3. Users running Adobe CS5.5
    Here's the scenario:
    User edits a file in InDesign, then saves a PDF of that file to the server. The user's supervisor reviews the file, and perhaps adds comments to it, but not necessarily.
    The user edits the ID file again, and saves a new PDF over the old one. When we were running Server 10.4.x, the user would have been warned that the PDF file was open by another user, and would have been prevented from saving. Under SL Server, no warning takes place, and the file is overwritten.
    At this point, a couple of things can happen.
    1: The new file is written, and the changes can be seen by the user. The supervisor's computer does not see the new version of the file. Quicklook and opening the file into Acrobat 10 will still show the old file. Disconnecting and reconnecting fixes this.
    2: The new file is written, but it is corrupted, and not openable by either party. If neither one opens the file right away, this could go unnoticed.
    I've tested this scenario between two Lion machines, and the "file-open" warning occurs like it should.
    Is there a setting in SL Server that I need to look at, or is this a bug?
    Our short-term fix is to have the user always save to a new filename. This can work, but it's cumbersome.

  • Multiple iTunes open in multiple 'user accounts'- at the same time

    We have three people in our family, each with their own iPod/iphone, we sync our iPod/iphone on the same computer but in different ‘user accounts’ in xp.
    Now the problem is ; only one iTunes program can run at a time, so if one person is downloading a podcast and another logs into their user account then they can’t open iTunes because it is open in another user account already.
    There must be a way to run multiple iTunes at the same time in different user accounts?
    Anyone?
    I’m running XP on an i7 machine

    Welcome to AD!
    Sadly, there is not a way to do this.
    http://support.apple.com/kb/TS1969?viewlocale=en_US

  • Stale data error: OA page opened by different users

    Hi,
    An OA Page which is basically use to query order details and update certain custom tables based on the order details has been developed.
    The first page which is a search page perfoms the search based on the "Custom Name", "Order Status" --> Bith LOV fields
    When this page is opened by multiple users we get a "Stale Data" error.
    Kindly help to resolve this issue.
    Thanks.

    Hi ,
    Please check root AM that you have created the variable in Custom Properties (RETENTION_LEVEL ,MANAGE_STATE)
    Thanks
    Pratap

  • Not able to open active directory user and computer in windows server 2008r2

    Hi All techies,
    i would like to know one issue which i am facing mostly, i have created 5 virtual machine all with window server2008r2 and one windows 7 on vm-ware now when ever i start my virtual machines everything going rite but when i try to open active directory user/
    computer or domain and trust i get a following error "data from active directory user and computers is not available from dc(null) bcoz unspecified error" even when i chk in events log its give me no help, and after 15-30 min everything works good
    Please let me know the cause of it and really appreciate it .
    Thanks
    Atul

    You need to ensure that
    1. group policy that says "wait for network before logon" is applied to all computers including servers and workstations is applied
    2. DNS record exists for all DCs in DNS
    3. If there are multiple Domain Controllers in Forests, then they point them as secondary DNS server. This way they will be able to resolve IPs if local DNS server service takes time to start.
    As Chris mentioned, you need to start all DCs first, give a time of 5 minutes and then start member servers and workstations for successful logon.
    - Sarvesh Goel - Enterprise Messaging Administrator

  • Excel 2010 - Can't Save File Becasue It's Opened By Another User

    Hi All,
    I'm using excel 2010, I can create an excel doc, update it, save it on the network, then close it. Then go out of the folder its saved in, go back in and open the file but it flags up as read only as its 'opened by another user'.
    I can confirm 100% that no one else has this file open.
    This affects multiple users, I have a feeling this may be caused by an update but don't have anything solid to back that theory up.
    All users who have this problem are running windows 7 Pro machines, all domain joined.
    Can anyone offer any suggestions?

    Hi,
    Please try the following methods:
    Methods1:
    Turn off the Details Pane shown at the bottom of Windows Explorer.  Go to Organize -> Layout -> Details Pane.  That fixes the first problem.
    Turn off “Show pop-up description for folder and desktop items”  Click on Tools -> Folder Options.  In the box that opens up, click on the View tab.  Scroll down the list to “Show pop-up description for folder and desktop items” and clear
    the checkbox and then click OK.  This fixes the second problem.
    Turn off Preview Pane.  Go to Organize -> Layout -> Preview Pane. This fixes number 3. 
    Methods2:
    Add the following registry keys:
    Key: HKEY_CLASSES_ROOT\CLSID\{993BE281-6695-4BA5-8A2A-7AACBFAAB69E}
    Name: EnableShareDenyNone
    Type: REG_DWORD
    Value: 1
    Key: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{993BE281-6695-4BA5-8A2A-7AACBFAAB69E}   
    Name: EnableShareDenyNone
    Type: REG_DWORD
    Value: 1
    For more detail information, please refer to the following links:
    http://blogs.technet.com/b/the_microsoft_excel_support_team_blog/archive/2012/05/14/the-definitive-locked-file-post.aspx
    http://support.microsoft.com/kb/942146/en-us
    Regards,
    George Zhao
    TechNet Community Support

  • Safari only opens under 1 user,question mark appears over icon in dock...please help,i am clueless

    as title says safari opens under wifes user name,it was not in her dock we found it in trash and "put back",then icon appeared on her desk top we put it in her dock,now its in dock and desk top,and other usres cannot open safari,get question mark over icon in dock,we are clueless as u can probably tell any help appreciated

    ralphfromronkonkoma wrote:
    we found it in trash and "put back",then icon appeared on her desk top we put it in her dock,now its in dock and desk top,and other usres cannot open safari
    If you found Safari in the Trash it was probably the Safari.app itself. Icons on the Dock do not go into Trash. They drag off and "Poof".
    That means that the app, itself is on your Desktop. Choose it and Get Info (command-i). Does it say, "Safari.app"? Drag it back into /Applications folder. Then drag your icon off the Dock and create a new one by dragging Safari.app to the Dock. It will create an alias which is all the Dock icons are.
    The question mark means an alias has lost the path to the application. Have your other users drag it off the Dock and drag it from the applications folder to create a new alias on the Dock.

  • Unable to save document - Read Only or Open by another user error occurs when PDF is opened from Windows Explorer

    Adobe Pro XI  - using Windows 7 Pro OS
    When a PDF document is opened from Windows Explorer, and pages are added, deleted, notations made, any type of changes, it cannot be saved until Windows Explorer is fully closed.  If you try to save the document, you receive the following error - "The document could not be saved.  The file may be read-only, or another user may have it opened.  Please save the document with a different name or in a differnt folder. "   I have confirmed the document is not read only, it is not open by another user, and it is not open multiple times.  Once you fully close Windows Explorer, and try to save the document, it saves without a problem.
    Are there settings in either Adobe Pro XI or Windows that will allow you to save documents without closing Windows Explorer first?
    Thank you for any assistance you can provide.  This error is a frustration since I open all my documents through Windows Explorer.

    [discussion moved to Creating, Editing & Exporting PDFs forum]

  • Need MBAM 2.5 Helpdesk and selfservice sites to open for authenticated users with no password prompt

    I Need MBAM 2.5 Helpdesk and self service sites to open for authenticated users with no password prompt. I just cant seem to get this to work. The account used in the application pool has its SPN registered and delegation set. I can use that account to login
    to the sites but am prompted for a password. That said anyone I add into the helpdesk users group cannot negotiate the sites. Only the account I have set in the application pool can. I want domain authenticated users that have been added to the MBAM Help Desk
    Users group to negotiate the site with NO password challenge at all.
    tconners

    This generally means that your SPN is not set up correctly.  Let's say the web server you installed the SSP on is lance.contoso.com and your app pool creds are corp\lance.  You should set an SPN similar to setspn -s http/lance.contoso.com
    corp\lance.  In your browser, you should now be able to access the SSP without prompts.  However, if you still get prompted, generally that means that your local intranet zone in IE does not have an entry for *.contoso.com.  Since you are entering
    an FQDN in your browser, IE interprets the "." to mean "on the internet" which breaks Kerberos authentication.  By adding *.contoso.com to your local intranet zone, you are telling it that lance.contoso.com is on the intranet, so use
    Kerberos.
    I can confirm, that I have exact configuration and I always get the password promt for the very first time. We have 2 server (1xIIS and 1xSQL) infrastructure in production with SPN set like it should and I get the password prompt.

Maybe you are looking for