BlackBerry Forums Support Community               

Closed Thread
 
LinkBack Thread Tools
Old 07-08-2008, 03:41 PM   #1 (permalink)
New Member
 
Join Date: Jul 2008
Model: 8830
PIN: N/A
Carrier: Verizon
Posts: 3
Post Thanks: 0
Thanked 0 Times in 0 Posts
Default Besadmin Account

Please Login to Remove!

I am trying to get the skinny on the behavior of the besadmin account and when and why it accesses users accounts on the Exchange Server, but I cannot seem to find anything out there.

We have logging turned on and we see the besadmin account access the user accounts with 1009 and 1016 Event ID's in the Exchange Application event logs and I see it send as users which I know is normal by design behavior. But I want to make sure it is in FACT the besadmin account accessing the email accounts and say not an administrative user who knows the besadmin login credentials.

Can anyone point me in the right direction? Any help on this would be GREAT!!!!
Offline  
Old 07-08-2008, 05:02 PM   #2 (permalink)
Talking BlackBerry Encyclopedia
 
Join Date: Oct 2007
Model: 8830
PIN: N/A
Carrier: Sprint, Alltel
Posts: 262
Post Thanks: 0
Thanked 0 Times in 0 Posts
Default

change the credentials and see if you still have the same activity. Or, you might get lucky and the possible offender might start asking why the password doesn't work any longer.

edit:
I'm adding that there is no good reason for anyone to need to log in as BesAdmin except for installing or upgrading since you can grant Administrative rights to anyone and they can use BB Manager.

Last edited by scott_perry : 07-08-2008 at 05:04 PM.
Offline  
Old 07-08-2008, 05:04 PM   #3 (permalink)
BlackBerry Extraordinaire
 
CO_BBTechie's Avatar
 
Join Date: Jul 2007
Location: Denver
Model: 8310
Carrier: AT&T
Posts: 2,044
Post Thanks: 0
Thanked 0 Times in 0 Posts
Default

Have you checked other logs on the server? It should indicate which IP number the request is coming from.
__________________
Treat your password like your toothbrush. Don't let anybody else use it, and get a new one every six months.
Clifford Stoll
Offline  
Old 07-08-2008, 10:48 PM   #4 (permalink)
New Member
 
Join Date: Jul 2008
Model: 8830
PIN: N/A
Carrier: Verizon
Posts: 3
Post Thanks: 0
Thanked 0 Times in 0 Posts
Default

Basically what I am seeing is the besadmin account may not touch say my account for 4 or 5 days, THEN all of a sudden I will see it access my account (and other managers) 3 or 4 times in one day. Let me add that when I do finally see it access my exchange account at no time that it accessed my account did I do a manual sync, access my calendar or do anything to my blackberry other than possibly unlock it (which I know has NO bearing on my exchange account.....).

As for IP's the only way to really track the IP access is to sync it up with the domain controller that the person logs into, but there is always a bit of a lag between when they log in and when they access something.

But here is the catch, you can "impersonate" another user when logging into an exchange server or someone's mail account. I will not go into the details, but you can log into your workstation as one user then access a mail account and show up as a TOTALLY different user in the logs and as long as you are an admin there is no audit trail.

Microsoft in their infinite wisdom figures that if you have admin priv that you belong there and there is NO audit trail to really track the activities of someone with admin priv other than 3rd party apps (I have been on the phone with MS for hours asking them if they really were serious about that statement and went thru both level 1 and level 2 of the exchange, active directory and security teams on this matter).
Offline  
Old 07-08-2008, 10:55 PM   #5 (permalink)
CrackBerry Addict
 
ashworth's Avatar
 
Join Date: Jun 2006
Location: Ontario, Canada
Model: 9000
OS: 4.6
Carrier: Rogers
Posts: 625
Post Thanks: 0
Thanked 0 Times in 0 Posts
Default

You also have access to the BES logs so if you do have any questionable emails that you want to know if it was sent by the BESAdmin account then grep out the MAGT log for that day around the time the email was send/recv.
__________________
Cheers,
Ash


My BlackBerry GPS Golf Application | Mileage Calculator
Offline  
Old 07-08-2008, 11:22 PM   #6 (permalink)
New Member
 
Join Date: Jul 2008
Model: 8830
PIN: N/A
Carrier: Verizon
Posts: 3
Post Thanks: 0
Thanked 0 Times in 0 Posts
Default

Thank you for the reply, but I am not so much worried about emails being sent but about access to actual email accounts by admins with the besadmin credentials.

But that is good info to know about if that ever happens, Thank You!!

Last edited by eslaptyback : 07-08-2008 at 11:30 PM.
Offline  
Closed Thread


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On





Copyright 2004-2014 BlackBerryForums.com.
The names RIM and BlackBerry are registered Trademarks of BlackBerry Inc.