trace logon from disabled user account?

  • Thread starter Thread starter Dylan
  • Start date Start date
D

Dylan

I have two accounts that are disabled. In the event viewer (app log) I
get event ID 1022 logon failure to first storage group\mailbox
store... So obviously someone is trying to log into a disabled
exchange account. The question is how can I trace maybe by IP address
where it is coming from to correct the problem. Or maybe there is
another solution? Please advise.
 
Dylan-

Most likely the disabled accounts are receiving mail. This will cause the
issue. You need to pull up the Exchange Permissions and grant the SELF
account Associated External Account permissions on the mailbox. You can do
this from the user's Exchange ADvanced tab in AD U & C

--
--
Brian Desmond
Windows Server MVP
(e-mail address removed)12.il.us

Http://www.briandesmond.com
 
Thanks Brian,
I followed your reccommendation for account #1 which I believe might
fix the problem. However account #2 doesn't have an exchange mailbox,
which is the wierd thing. I contine to get the logon error ever hour.
Could it be a program running somewhere on the network trying to logon
to an account without a exchange mailbox, and if so how can we trace
it and shut it down? Thanks for your help.
 
Thanks Brian,
I followed your reccommendation for account #1 which I believe might
fix the problem. However account #2 doesn't have an exchange mailbox,
which is the wierd thing. I contine to get the logon error ever hour.
Could it be a program running somewhere on the network trying to logon
to an account without a exchange mailbox, and if so how can we trace
it and shut it down? Thanks for your help.
 
Back
Top