|
| RMS and Exchange Admin |
 |
Wed, 19 Mar 2008 11:02:31 +020 |
Hi everyone,
In a large organisation across multiple regions, we have regional exchange
administrators in place. When deploying RMS templates, some regions are
concerned that exchange admins will be able to access their mailbox and
therefore sensitive RMS protected emails.
My assumption is that so long as the exchange Admins are not part of the AD
group associated with the template, they may be able to access a users
mailbox, but NOT the RMS protected mail?
Interestingly we did some testing using the built in <do not forward>
permissions in outlook and Admins were not able to access RMS protected
mail. However when we tested this using an internal <Confidential>
template, they were able to access this, but perhaps because they were also
part of the group <Everyone>.
Would this be correct?
Regards,
Neil
|
| Post Reply
|
| RE: RMS and Exchange Admin |
 |
Thu, 20 Mar 2008 09:29:01 -070 |
Hi,
Yes that's correct. Administrators are part of the anyone group.
If you protect an email for a particular group, adminstrators won't be able
to open the documents.
However, there is a super user group in RMS. Members of this group could
open and see all encrypted documents.
Olivier
"Neil Van Der Merwe" wrote:
> Hi everyone,
>
> In a large organisation across multiple regions, we have regional exchange
> administrators in place. When deploying RMS templates, some regions are
> concerned that exchange admins will be able to access their mailbox and
> therefore sensitive RMS protected emails.
>
> My assumption is that so long as the exchange Admins are not part of the AD
> group associated with the template, they may be able to access a users
> mailbox, but NOT the RMS protected mail?
>
> Interestingly we did some testing using the built in <do not forward>
> permissions in outlook and Admins were not able to access RMS protected
> mail. However when we tested this using an internal <Confidential>
> template, they were able to access this, but perhaps because they were also
> part of the group <Everyone>.
>
> Would this be correct?
>
> Regards,
> Neil
|
| Post Reply
|
|
|
|
|
|
|
|
|
|