How to Monitor Non-Owner Mailbox Access

1. Introduction

Shared mailboxes are a great way for a specific group of people to perform certain tasks from a common account. However, having shared mailboxes introduces a high risk of security incidents. With non-owners having privileged rights to access shared mailboxes, there’s always a chance that they might wrongly handle emails with sensitive information.

Whether it is done accidentally or maliciously, a message could be deleted, sent to a wrong recipient, or moved to another location and any of these situations may result in data loss or leaks. To avoid any security incidents, it is highly recommended that users regularly monitor non-owner access to shared mailboxes.

2. Mailbox Access Auditing

There are many situations where employees may need to give other people access to their mailboxes, examples include the case of an employee with a personal assistant or teams of people that might use shared mailboxes to communicate better. Whatever the reason, it’s important that proper auditing is maintained on shared mailboxes to avoid unwanted changes going unnoticed. This, however, can be a complex and time-consuming task without a proper solution in place.

3. The Lepide Solution

Using the Lepide Data Security Platform, you can audit mailboxes based on specific user access and instantly get alerts and receive regular reports showing you who, what, when and where a specific mailbox was accessed and what actions were taken.

3.1 The Mailbox Accessed by Non-Owners Report

The Mailbox Accessed by Non Owners Report identifies mailboxes that have been accessed by somebody other than the mailbox owner, and the actions that were taken.

This report is available for both Exchange Server and Exchange Online.

3.2 Prerequisites

You will need to have installed the following components:

For Exchange Online, Non-Owner mailbox auditing is enabled automatically when the component is installed.

For Exchange Server, Non-Owner mailbox auditing can be enabled either during installation of the component or after installation via Properties, Advanced Domain Configuration. For more information, please refer to the Configure Mailbox Access Auditing Guide.

3.3 Running the Report

Click the User Behavior & Analytics icon

The report is found in the tree structure on the left-hand side:

For Exchange Server:

  • Expand the Active Directory name

  • Expand Exchange Modification Reports

  • Expand Auditing

  • Expand All Mailbox Access Reports

  • Click on Mailbox Accessed by Non Owners

Text

Description automatically generated
Exchange Server Folder Structure

For Exchange Online:

  • Expand Exchange Online

  • Expand Auditing

  • Expand All Mailbox Access Reports

  • Click on Mailbox Accessed by Non Owners

Graphical user interface, text

Description automatically generated
Exchange Online File Structure

The Mailbox Accessed by Non Owners screen is displayed:

Graphical user interface, application

Description automatically generated
Mailbox Accessed by Non Owners Report

The example above is an Exchange Online Report but the Exchange Server Report works in the same way.

  • From the top of the screen, click Today

The following dialog box is displayed:

Graphical user interface, text, application

Description automatically generated
When Filter

  • Select a date range and click OK

You will return to the Mailbox Accessed by Non Owners screen

  • Click on Operation

The following dialog box is displayed:

Graphical user interface, text, application

Description automatically generated
Operation Filter
  • Change the Filter Criteria to Not EqualTo

  • Check FolderBind

  • FolderBind will show every time the mailbox is accessed so it is better to filter this out to reduce unnecessary data being retrieved by the report.

  • Click OK

  • Click Generate Report


Graphical user interface, application, table, Excel

Description automatically generated
The Generated Report

The Report is displayed and shows who performed the action, the owner of the mailbox the action was performed on, what was done, when it was done and more detail what the activity was.

3.4 Creating an Alert

You may want to create an alert for non owner mailbox access so you are notified as soon as a particular event occurs. For example you may want to be notified if a message is moved to deleted items by a particular user.

An alert can be created from the Exchange Server Non Owner Mailbox Report within the Lepide Data Security Platform as follows:

  • Right click on the Mailbox Accessed by Non Owners Report

A menu is displayed:

Graphical user interface, application

Description automatically generated
Report Menu
  • Choose Set Alert

A Wizard will start, and the Select Reports dialog box is displayed:

Graphical user interface, text, application, email

Description automatically generated
Select Report(s)

Ensure that the report on which you want to set an alert is checked. In this case, it is the Mailbox Accessed by Non Owners report.

  • Click Next

The Set Filter(s) dialog box is displayed:

Graphical user interface, application

Description automatically generated
Set Filter(s)

On the left of the dialog box, you can see the report you are working on which in this case is Mailbox Accessed by Non Owner.

There are options to change the settings for Action Performed by, Action Performed on and Operation. The default setting for all these options is All.

The threshold alert options can be customized as follows:

Threshold Alert:

Check this box to switch threshold alerting on

Send alert only if event occurs:

Change the number of times the event occurs, the time value and time-period here

  • Click Next

The Alert Settings dialog box is displayed:

Graphical user interface, text, application, email

Description automatically generated
Alert Settings

This dialog box allows you to set up responses to occur when an alert has been triggered and displays any existing responses which have been set up. You can also change the Alert Type.

  • To create a new response to an alert, click the Add button.

Graphical user interface, application

Description automatically generated
Add Alert Action

The Add Alert Action dialog box is displayed:

  • Click the Select Action drop down arrow to see a list of actions available:

Graphical user interface, application

Description automatically generated
Add Alert Action Options

The Alert Actions are as follows:

  • Send Email Alert

  • Show in LiveFeed

  • Send Alert to App

  • Execute Script

The configuration of each of these actions is explained in the following section: https://www.lepide.com/knowledgebase/?page_id=3972464652&slug=configuring-threat-models-and-real-time-alerts