trace logon from disabled user account?

D

Dylan

I have two accounts that are disabled. In the event viewer (app log) I
get event ID 1022 logon failure to first storage group\mailbox
store... So obviously someone is trying to log into a disabled
exchange account. The question is how can I trace maybe by IP address
where it is coming from to correct the problem. Or maybe there is
another solution? Please advise.
 
B

Brian Desmond [MVP]

Dylan-

Most likely the disabled accounts are receiving mail. This will cause the
issue. You need to pull up the Exchange Permissions and grant the SELF
account Associated External Account permissions on the mailbox. You can do
this from the user's Exchange ADvanced tab in AD U & C

--
--
Brian Desmond
Windows Server MVP
(e-mail address removed)12.il.us

Http://www.briandesmond.com
 
D

Dylan

Thanks Brian,
I followed your reccommendation for account #1 which I believe might
fix the problem. However account #2 doesn't have an exchange mailbox,
which is the wierd thing. I contine to get the logon error ever hour.
Could it be a program running somewhere on the network trying to logon
to an account without a exchange mailbox, and if so how can we trace
it and shut it down? Thanks for your help.
 
D

Dylan

Thanks Brian,
I followed your reccommendation for account #1 which I believe might
fix the problem. However account #2 doesn't have an exchange mailbox,
which is the wierd thing. I contine to get the logon error ever hour.
Could it be a program running somewhere on the network trying to logon
to an account without a exchange mailbox, and if so how can we trace
it and shut it down? Thanks for your help.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top