Where to Find Event log for Exchange Send as permission set
Hi,
I am using Exchange 2007 with windows 2008 server in two two domain controller with trust relation ship....
My mail server exists on antoher domain and user are on other domain controller.... I want to check some event logs for exchange...
in my exchange (HUB & CAS )server i have set permission to another user with manage full access permission (user exists on another domain with i have trust)
Now i want to see event logs regarding this change on server ..
Please tell me that where i can find log for this particular action
On mail server (Hub & CAS)
On Mail server (Mail Box server)
On Domain Controller (Mail server exists on)
On Domain Controller (User ID exists on)
Kindly help me to sort out this issue where i can find & how can i serach for ..
Thanks
Vijay Kr Jangir
May 7th, 2010 2:35pm
Hi,
These logs are only available on DCs. All users’ permission data are stored in Active Directory. When setting permission to another user with manage full access permission,
exchange server will connect to DC and then access Active Directory to modify the corresponding objects. If you successful changing the permission, a Success Audit event log will be generated in DC. The event is located under “Event Viewer\Security”.
The log is like this:
==============================================
Event Type:
Success Audit
Event Source:
Security
Event Category:
Directory Service Access
Event ID:
566
Date: 5/11/2010
Time: 3:51:42 PM
User: XXXX\XXXXXX
Computer: XXXXXX
Description:
Object Operation:
Object Server: DS
Operation Type: Object Access
Object Type: groupPolicyContainer
Object Name: CN={6AC1786C-016F-11D2-945F-00C04fB984F9},CN=Policies,CN=System,DC=genli,DC=lab
Handle ID: -
Primary User Name: XXXXX$
Primary Domain: GENLI
Primary Logon ID: (0x0,0x3E7)
Client User Name: administrator
Client Domain: GENLI
Client Logon ID: (0x0,0x8D9F1)
Accesses:
Write Property
Properties:
Write Property
Default property set
versionNumber
groupPolicyContainer
Additional Info:
Additional Info2:
Access Mask: 0x20
==========================================
You can use Event ID 566 to filter.
Free Windows Admin Tool Kit Click here and download it now
May 11th, 2010 12:53pm