1. Introduction
Shared mailboxes are a great way for a specific group of people to perform certain tasks from a common account. However, having shared mailboxes introduces a high risk of security incidents. With non-owners having privileged rights to access shared mailboxes, there’s always a chance that they might wrongly handle emails with sensitive information.
Whether it is done accidentally or maliciously, a message could be deleted, sent to a wrong recipient, or moved to another location and any of these situations may result in data loss or leaks. To avoid any security incidents, it is highly recommended that users regularly monitor non-owner access to shared mailboxes.
2. Mailbox Access Auditing
There are many situations where employees may need to give other people access to their mailboxes, examples include the case of an employee with a personal assistant or teams of people that might use shared mailboxes to communicate better. Whatever the reason, it’s important that proper auditing is maintained on shared mailboxes to avoid unwanted changes going unnoticed. This, however, can be a complex and time-consuming task without a proper solution in place.
3. The Lepide Solution
Using the Lepide Data Security Platform, you can audit mailboxes based on specific user access and instantly get alerts and receive regular reports showing you who, what, when and where a specific mailbox was accessed and what actions were taken.
3.1 The Mailbox Accessed by Non-Owners Report
The Mailbox Accessed by Non Owners Report identifies mailboxes that have been accessed by somebody other than the mailbox owner, and the actions that were taken.
This report is available for both Exchange Server and Exchange Online.
3.2 Prerequisites
You will need to have installed the following components:
For Exchange Server, you will need an Active Directory component. For information on how to install and configure this, please refer to the following section: https://lepide.atlassian.net/wiki/spaces/LEPKB/folder/3829596166?atlOrigin=eyJpIjoiYjllMzI1MWExNWIwNDFiMjhlMDBhNGIyZTA1YWEwNGQiLCJwIjoiYyJ9
For Exchange Online, you will need an Exchange Online component. For information on how to install and configure this, please refer to the following section: https://lepide.atlassian.net/wiki/spaces/LEPKB/folder/3854499852?atlOrigin=eyJpIjoiNzdiMWQ5NDI4ZGEzNGMyMDkxNGMxYzQ2ZmI0YjVmNTYiLCJwIjoiYyJ9
For Exchange Online, Non-Owner mailbox auditing is enabled automatically when the component is installed.
For Exchange Server, Non-Owner mailbox auditing can be enabled either during installation of the component or after installation via Properties, Advanced Domain Configuration. For more information, please refer to the Configure Mailbox Access Auditing Guide.
3.3 Running the Report
Click the User Behavior & Analytics icon
The report is found in the tree structure on the left-hand side:
For Exchange Server:
Expand the Active Directory name
Expand Exchange Modification Reports
Expand Auditing
Expand All Mailbox Access Reports
Click on Mailbox Accessed by Non Owners
For Exchange Online:
Expand Exchange Online
Expand Auditing
Expand All Mailbox Access Reports
Click on Mailbox Accessed by Non Owners
The Mailbox Accessed by Non Owners screen is displayed:
The example above is an Exchange Online Report but the Exchange Server Report works in the same way.
From the top of the screen, click Today
The following dialog box is displayed:
Select a date range and click OK
You will return to the Mailbox Accessed by Non Owners screen
Click on Operation
The following dialog box is displayed:
Change the Filter Criteria to Not EqualTo
Check FolderBind
FolderBind will show every time the mailbox is accessed so it is better to filter this out to reduce unnecessary data being retrieved by the report.
Click OK
Click Generate Report
The Report is displayed and shows who performed the action, the owner of the mailbox the action was performed on, what was done, when it was done and more detail what the activity was.
3.4 Creating an Alert
You may want to create an alert for non owner mailbox access so you are notified as soon as a particular event occurs. For example you may want to be notified if a message is moved to deleted items by a particular user.
An alert can be created from the Exchange Server Non Owner Mailbox Report within the Lepide Data Security Platform as follows:
Right click on the Mailbox Accessed by Non Owners Report
A menu is displayed:
Choose Set Alert
A Wizard will start, and the Select Reports dialog box is displayed:
Ensure that the report on which you want to set an alert is checked. In this case, it is the Mailbox Accessed by Non Owners report.
Click Next
The Set Filter(s) dialog box is displayed:
On the left of the dialog box, you can see the report you are working on which in this case is Mailbox Accessed by Non Owner.
There are options to change the settings for Action Performed by, Action Performed on and Operation. The default setting for all these options is All.
The threshold alert options can be customized as follows:
Threshold Alert: | Check this box to switch threshold alerting on |
Send alert only if event occurs: | Change the number of times the event occurs, the time value and time-period here |
Click Next
The Alert Settings dialog box is displayed:
This dialog box allows you to set up responses to occur when an alert has been triggered and displays any existing responses which have been set up. You can also change the Alert Type.
To create a new response to an alert, click the Add button.
The Add Alert Action dialog box is displayed:
Click the Select Action drop down arrow to see a list of actions available:
The Alert Actions are as follows:
Send Email Alert
Show in LiveFeed
Send Alert to App
Execute Script
The configuration of each of these actions is explained in the following section: https://www.lepide.com/knowledgebase/?page_id=3972464652&slug=configuring-threat-models-and-real-time-alerts
