|
If someone does access a mailbox and they are not the primary NT account, then a 1016 event will be created in the application log. See this Microsoft article for more information: How to monitor mailbox access by auditing or by viewing Mailbox Resources in Exchange Server.
You might also want to check out this tip: Establishing mailbox audit trails on Exchange Server.
Do you have comments on this Ask the Expert Q&A? Let us know.
Related information from SearchExchange.com:
Expert Advice: Who has full mailbox access?
15 tips in 15 minutes: Managing recipients and distribution lists
Reference Center: Permissions and authentication
|