Home > Microsoft Exchange Tips > Exchange Server Administration Tips > Exchange admins: Is it time to rethink your email address policy?
Exchange Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

EXCHANGE SERVER ADMINISTRATION TIPS

Exchange admins: Is it time to rethink your email address policy?


Brien Posey, Contributor
07.08.2009
Rating: -2.67- (out of 5)


Exchange Server tips, tutorials and expert advice
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


Most Exchange Server administrators may not spend a lot of time thinking about email address policies. In fact, once Exchange is up and running, you probably won't touch the policy again unless a corporate merger or similar event forces you to change company email addresses. But the email address policy may affect your organization's overall security more than you originally thought.

Although more advanced authentication mechanisms are available, most users still authenticate by using a traditional username and password combination. If a hacker can figure out a username, he has one-half of the information needed to log in as a legitimate user.

The problem is that email addresses often have some correlation to usernames. For example, my email address is Brien@brienposey.com. It's easy to guess that my logon name is Brien. Therefore, it's a good idea to change my email address to a different format than one that includes my logon name.

Modifying a user's email address policy will change his email addresses. If your email address policy was created using Exchange Server 2003, you'll have to use either System Manager to perform the modification or you'll need to upgrade the policy using the Set-EmailAddressPolicy command.

Modifying your Exchange email address policy

You can modify your email address policy by opening the Exchange Management Console and selecting the Hub Transport container from the Organization Configuration section. Next, select the Email Address Policies tab, select your email address policy and click Edit.

The email address policy is comprised of a single text string that dictates the format of the email address. You can use Microsoft's pre-canned address or you can create a custom SMTP address. If your goal is to improve security, I recommend creating a custom SMTP address, which can only be done via the Exchange Management Shell.

To create a custom SMTP email address policy, create a text string that consists of hard-coded text blocks and different variables. A list of the available variables are show in Table 1.

Variable Function
%G First name
%I Middle initial
%S Last name
%D Display name
%M Exchange alias
%<x>S The first X letters of the user's last name. For example %2S would represent the first two letters of the user's last name.
%<x>G The first X letters of the user's first name. For example, %3G would represent the first three letters of the user's first name.

Table 1. Available variables for creating a custom SMTP email address policy.

Although you can see which variables are available, you may still be a bit unclear on how to use them. Here's an example:

First name: Brien
Middle initial: M
Last name: Posey
Display name: Brien Posey
Domain: Contoso.com

Table 2 shows what the email address looks like based on various email address policy strings.

String Resulting email address
%G.%S Brien.Posey@contoso.com
%1G%S BPosey@contoso.com
%G%I%S BrienMPosey@contoso.com
%G%1S BrienP@contoso.com

Table 2. Samples of various email address policy strings.

About the author: Brien M. Posey, MCSE, is a five-time recipient of Microsoft's Most Valuable Professional award for his work with Exchange Server, Windows Server, Internet Information Services (IIS), and File Systems and Storage. Brien has served as CIO for a nationwide chain of hospitals and was once responsible for the Department of Information Management at Fort Knox. As a freelance technical writer, Brien has written for Microsoft, TechTarget, CNET, ZDNet, MSD2D, Relevant Technologies and other technology companies. You can visit Brien's personal website at www.brienposey.com.

Do you have comments on this tip? Let us know.

Please let others know how useful this tip was via the rating scale below. Do you know a helpful Exchange Server, Microsoft Outlook or SharePoint tip, timesaver or workaround? Email the editors to talk about writing for SearchExchange.com.

Rate this Tip
To rate tips, you must be a member of SearchExchange.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Exchange Server Administration Tips
Remove Exchange 2003 objects from AD to install Exchange 2010
Is your Exchange 2007 hub transport server healthy?
Avoid Outlook 2007 performance issues during repairs
Developing an Exchange 2007 server role DR plan
How DSAccess service improves Exchange Server 2007 reliability
An introduction to the Exchange Remote Connectivity Analyzer tool
Monitor Exchange 2007 with disk- and RPC-related counters
DPM 2007 replica inconsistencies in Exchange databases
Track Exchange 2007 mailbox server health using database counters
Digging deeper into Exchange Server 2010

Email Policy Management
Changing email address formats in Exchange Server 2003
Configuring the default recipient policy in an Exchange 2003 environment
Microsoft Exchange Server email archiving tutorial
Setting up email disclaimers and signatures in Exchange Server
Use the OWA Admin tool to 'segment' Outlook Web Access 2003 features
Why are .PST files a security threat to Exchange Server mailboxes?
Customizing Outlook Web Access (OWA) in Exchange Server 2007
Managing Microsoft Outlook search folder functionality
Moving mobile user mailboxes from Exchange 2003 to Exchange 2007
How to set up Exchange 2007 message classifications

Microsoft Exchange Server Mailbox Management
Delivering email between Exchange server test and production domains
Microsoft Outlook error message: 'Mailbox Size Limit exceeded'
Restoring user accounts and mailbox links in Active Directory
Problems receiving email from outside a Exchange Server 2003 domain
Best practices for moving mailboxes in Exchange Server
Exchange Server 2003 collects email from only specific POP3 domains
Troubleshoot 'System Attendant' error messages in OWA
Relocating Outlook email messages on a hosted Exchange 2007 server
Restore contacts from an Exchange public folder
Performing advanced search queries in Microsoft Outlook 2007

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
email bankruptcy  (SearchExchange.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Email Server Solutions: Exchange 2007, Exchange 2003, Exchange 2000, SharePoint
HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersIT Downloads
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2004 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts