RE: audit deleted public folders

  • From: "Michael B. Smith" <michael@xxxxxxxxxx>
  • To: "[ExchangeList]" <exchangelist@xxxxxxxxxxxxx>
  • Date: Thu, 26 Jan 2006 12:34:12 -0500

Exchange Server 2003 service pack 2 adds functionality to meet this
need. 

 

For earlier versions of Exchange, see

 

http://support.microsoft.com/kb/884863/

 

There might be third party stuff that does what you want, but I'm not
aware of it.

 

 

________________________________

From: Tom Kern [mailto:tpkern@xxxxxxxxx] 
Sent: Thursday, January 26, 2006 10:07 AM
To: [ExchangeList]
Subject: [exchangelist] audit deleted public folders

 

http://www.MSExchange.org/ 

I'm running exchange 2k post sp3 rollup.

I have "Directory Access" auditing enabled on the domain controllers ou.

 

This morning someone deleted a mail enabled public folder and the only
event i get is this-

Event Type: Success Audit
Event Source: Security
Event Category: Directory Service Access 
Event ID: 565
Date:  1/26/2006
Time:  8:08:10 AM
User:  OPANDCO\EXNYC03$
Computer: OPNYC10
Description: 
Object Open:
  Object Server: DS
  Object Type: publicFolder
  Object Name: %{ececd715-14da-44bb-919b-0bf8ac8d07ca}
  New Handle ID: 0
  Operation ID: {0,2476766380}
  Process ID: 304
  Primary User Name: OPNYC10$ 
  Primary Domain: OPANDCO
  Primary Logon ID: (0x0,0x3E7)
  Client User Name: EXNYC03$
  Client Domain: OPANDCO
  Client Logon ID: (0x0,0x93421897)
  Accesses  DELETE 
   
  Privileges  -

 Properties:

 

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp .

 

OPNYC10 is the dc the delete took place on and EXNYC03 is the exchange
server hosting this folder.

However by reading the event, it looks like the Exchange server deleted
the folder.

I know thats not right.

Is it that someone deleted the mapi folder through Outlook and then
Exchange cleaned up the folder object from AD?

If so, how can I audit the mapi public folder deletions?

 

Thanks a lot

------------------------------------------------------ List Archives:
http://www.webelists.com/cgi/lyris.pl?enter=exchangelist Exchange
Newsletters: http://www.msexchange.org/pages/newsletter.asp
------------------------------------------------------ Visit
TechGenix.com for more information about our other sites:
http://www.techgenix.com
------------------------------------------------------ You are currently
subscribed to this MSExchange.org Discussion List as: michael@xxxxxxxxxx
To unsubscribe visit
http://www.webelists.com/cgi/lyris.pl?enter=exchangelist Report abuse to
info@xxxxxxxxxxxxxx

Other related posts: