BlackBerry Forums Support Community
              

Closed Thread
 
Thread Tools
Old 04-04-2011, 06:05 AM   #21
CanuckBB
BlackBerry Extraordinaire
 
CanuckBB's Avatar
 
Join Date: Feb 2006
Location: YYZ
Model: 9900
Carrier: Rogers
Posts: 1,183
Default Re: Former employee can still access corporate mail via BlackBerry?

Please Login to Remove!

To the best of my recollection, mail sent to a disabled account will bounce.

I assume that the account is automatically disbled by IMS. You need to run a report daily on disabled accounts to make sure all other IT related functions for that account are disabled.

Fully automated termination procedures are generally bad.
Offline  
Old 04-04-2011, 06:58 AM   #22
fadmin
BlackBerry Extraordinaire
 
Join Date: Mar 2007
Model: Z10
OS: 10.1.0.19
Carrier: Fido
Posts: 1,068
Default Re: Former employee can still access corporate mail via BlackBerry?

But not sure how is this blackberry issue? If user account in AD is disabled that does not disable exchange mailbox. And that is on purpose done, so mgmt may check from time to time to see if there is business related msgs that needs attn. If you disable mailbox then it will stop mail coming to a BB. Think of this as mail forwarding only done by BES that does it more secure, but it is nothing but mail forwarding. If you had it enabled on the server to forward mail to internal or external emai, then disabling AD acct and not mailbox will continue to work to any account and not just blackberry.
I agree it would be nice to have bes ad integration but this is not BES issue but rather exchange issue.

BBlunk, with your setup I am more concerned that you guys allow personal equipment to connect to a network but provide them with sim? What is the point of that? Not sure in what kind of business you are in but that is huge no no. In any case this should not be too expensive to fix, as I assume that when calculate support cost per user you budgeted that at some point IT dep. would need to do removal of the user as well.
Offline  
Old 04-04-2011, 08:42 AM   #23
BBLunk
New Member
 
Join Date: Apr 2011
Model: N/A
PIN: N/A
Carrier: Several
Posts: 4
Default Re: Former employee can still access corporate mail via BlackBerry?

@NJBlackBerry: You're right, no consensus has been reached in this thread. I meant to say that the general consensus in our organization is that disabling AD accounts does not prevent BB mail access and is therefore a gaping hole for us. I've not seen anything yet to contradict that opinion. Nico's tests appear to support this opinion, but unfortunately in a Notes environment, not Exchange.

@freakinvibe: The problem, as I understand it, is that the BES using an Active Directory service account for its MAPI calls to the Exchange server. The user's AD account isn't referenced whatsoever. This makes sense, because the BB doesn't authenticate to the BES using AD credentials, so the BES can't impersonate the user in the MAPI calls. The status of User AD accounts seems to have no bearing whatsoever on BB/BES mail sync. This, coupled with us not disabling BES accounts and/or forcing users to surrender their BBs, has left us exposed. It would be awesome if BES would check that AD user accounts are enabled before allowing mail sync, but I can't find anything to suggest that it does.

@CanuckBB: I agree with fadmin... Disabling the AD account does not prevent mail being sent to the associated mailbox, unless you're running Exchange 2003 without the hotfix described in Microsoft KB 903158.

@fadmin: Apologies... We don't actually allow individuals to use their own BB's with a corporate SIM. I was trying to simplify my initial post. I thought it might derail the conversation if I explained that we actually allow some corporate users to keep their corporate BBs when the leave the organization (shock, horror).

I know it's a big ask, but is anyone in a position to run the test below and post the results?

1. Create a test user account in Active Directory and a corresponding mailbox in MS Exchange
2. Create a BES account for the test user
3. Activate a BB for access to the Mailbox of the test user
4. Send/receive mail via BB to confirm it functions
5. Disable the test user account (and wait for AD replication)
6. Attempt to access mail via PC, OWA, iPhone, Android or Windows Phone to confirm that access is denied.
7. Send/receive mail via BB to confirm that access is still allowed

Optionally:
8. Switch SIM in BB. New SIM must also have BES data plan.
9. Send/receive mail via BB to confirm that access is still allowed without reactivation.

Regards,
Lunk
Offline  
Old 04-04-2011, 08:50 AM   #24
fadmin
BlackBerry Extraordinaire
 
Join Date: Mar 2007
Model: Z10
OS: 10.1.0.19
Carrier: Fido
Posts: 1,068
Default Re: Former employee can still access corporate mail via BlackBerry?

Ways described in 6. will not work as it does ask for user credentials to authanticate before it lets you in.
7. will work as (simplified) BESAdmin does it for a user. Removing BESAdmin from users mailbox permission will do the same thing, disable redirection.
Offline  
Old 04-04-2011, 09:24 PM   #25
Nico57
Thumbs Must Hurt
 
Join Date: Aug 2007
Location: Courbevoie, France
Model: SGS3
OS: CM 10.2
Carrier: SFR
Posts: 59
Default Re: Former employee can still access corporate mail via BlackBerry?

Quote:
Originally Posted by NJBlackBerry View Post
I don't agree with that "consensus" (and didn't see it posted anywhere). I believe if the account is disabled in AD, the e-mail to the BB is also disabled.
Instead of believing, just try it.

E-mail access is only one part of the problem anyway.
To me, network access through MDS_CS is actually a much bigger issue.

A user whose AD/Domino account has been terminated, but whose BES account has not been taken care of, still has direct access to the corporate network and can virtually do a lot of bad things.
__________________
400 BB users | BES 4.1.7 | Traveler 9.0 | Domino 8.5
Offline  
Old 04-08-2011, 07:05 AM   #26
CanuckBB
BlackBerry Extraordinaire
 
CanuckBB's Avatar
 
Join Date: Feb 2006
Location: YYZ
Model: 9900
Carrier: Rogers
Posts: 1,183
Default Re: Former employee can still access corporate mail via BlackBerry?

In the end, you need to make sure IT is notified of employee terminations.
Offline  
Closed Thread



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads for: Former employee can still access corporate mail via BlackBerry?
Thread Thread Starter Forum Replies Last Post
Knowledge Sharing - Perform basic troubleshooting steps for Novell GroupWise noname BES Admin Corner 1 01-12-2010 07:33 AM
Initialize problem with BES and GroupeWise dupere BES Admin Corner 2 07-02-2008 02:09 PM
New to BES admin , need help with messages. bigwig BES Admin Corner 5 10-17-2007 10:59 AM
First post thought I'd make it helpful mazzel General 8100 Series Discussion - Pearl 1 05-30-2007 03:45 PM
The Hosted BES FAQ - Cheap BES/MDS - Wireless Outlook sync! Mark Rejhon BlackBerry Network 81 03-29-2007 05:29 AM


Pyle 5.2-Channel Hi-Fi Bluetooth Stereo Amplifier PT694BT 1000 Watt picture

Pyle 5.2-Channel Hi-Fi Bluetooth Stereo Amplifier PT694BT 1000 Watt

$139.95



KEYENCE LR-TB5000CL Laser Sensor with Built-in Amplifier picture

KEYENCE LR-TB5000CL Laser Sensor with Built-in Amplifier

$289.99



Portable Voice Amplifier, Towevine Rechargeable Microphone Speaker picture

Portable Voice Amplifier, Towevine Rechargeable Microphone Speaker

$14.99



FANUC A06B-6093-H151 K.  Servo Amplifier Unit 50/60Hz.    5.1A 1PH.  3.2A 3PH  picture

FANUC A06B-6093-H151 K. Servo Amplifier Unit 50/60Hz. 5.1A 1PH. 3.2A 3PH

$375.00



Biamp Tesira AMP-450BP AVB/TSN Enabled 4 Channel Amplifier w/ PoE+ (G155) picture

Biamp Tesira AMP-450BP AVB/TSN Enabled 4 Channel Amplifier w/ PoE+ (G155)

$250.00



Honeywell Ultraviolet Flame Amplifier RM7890 A 1015 picture

Honeywell Ultraviolet Flame Amplifier RM7890 A 1015

$199.99







Copyright © 2004-2016 BlackBerryForums.com.
The names RIM © and BlackBerry © are registered Trademarks of BlackBerry Inc.