Groups > Microsoft > Rights Management Services > RE: RMS and Exchange Admin




RMS and Exchange Admin

RMS and Exchange Admin
Wed, 19 Mar 2008 11:02:31 +020
Hi everyone,

In a large organisation across multiple regions, we have regional exchange 
administrators in place.  When deploying RMS templates, some regions are 
concerned that exchange admins will be able to access their mailbox and 
therefore sensitive RMS protected emails.

My assumption is that so long as the exchange Admins are not part of the AD 
group associated with the template, they may be able to access a users 
mailbox, but NOT the RMS protected mail?

Interestingly we did some testing using the built in <do not forward> 
permissions in outlook and Admins were not able to access RMS protected 
mail.  However when we tested this using an internal <Confidential> 
template, they were able to access this, but perhaps because they were also 
part of the group <Everyone>.

Would this be correct?

Regards,
Neil 
Post Reply
RE: RMS and Exchange Admin
Thu, 20 Mar 2008 09:29:01 -070
Hi,

Yes that's correct. Administrators are part of the anyone group.
If you protect an email for a particular group, adminstrators won't be able 
to open the documents.

However, there is a super user group in RMS. Members of this group could 
open and see all encrypted documents.

Olivier

"Neil Van Der Merwe" wrote:

> Hi everyone,
> 
> In a large organisation across multiple regions, we have regional exchange

> administrators in place.  When deploying RMS templates, some regions are 
> concerned that exchange admins will be able to access their mailbox and 
> therefore sensitive RMS protected emails.
> 
> My assumption is that so long as the exchange Admins are not part of the AD

> group associated with the template, they may be able to access a users 
> mailbox, but NOT the RMS protected mail?
> 
> Interestingly we did some testing using the built in <do not forward>

> permissions in outlook and Admins were not able to access RMS protected 
> mail.  However when we tested this using an internal <Confidential> 
> template, they were able to access this, but perhaps because they were also

> part of the group <Everyone>.
> 
> Would this be correct?
> 
> Regards,
> Neil 
Post Reply
about | contact