Home > Microsoft Exchange Tips > Exchange Server Administration Tips > Security best practices dos and don'ts, part 2
Exchange Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

EXCHANGE SERVER ADMINISTRATION TIPS

Security best practices dos and don'ts, part 2


Brien M. Posey, SearchExchange.com Contributor
06.16.2004
Rating: -3.75- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Yesterday, I talked about three best practices for Exchange security: Not exposing a Server containing mailboxes to the outside world, using a two-tier approach for virus protection and keeping Exchange up to date.

Today I am going to focus on two other equally important best practices.

As I mentioned in part one, a recent SearchExchange.com poll found that 52% of respondents spend between 25% to 50% of their work time on security-related issues. Another 23% said that they spend more than 50% of their day on security-related challenges.

While it is challenging to ensure your Exchange Server is protected from various security threats, there are some steps you can take to avoid them.

Best Practice #4: Do plan for disaster

You probably back up Exchange every night, but have you ever tested your backups?

When I worked for the Department of Defense, we didn't know that our Exchange database was slightly corrupt. The database was in good enough condition that Exchange was able to run for quite some time, but the corruption caused Exchange to crash. We didn't realize that we had been backing up corrupt data each night for the last two months. Since the data was corrupt, we were unable to mount the database after the restore operation was completed. Since our backups were invalid, we had to repair the existing database. We eventually got the database to mount, but lost a lot of data during the repair.

In all fairness, Exchange has improved a lot since then. Even so, there are still a lot of people running Exchange 5.5, which is the same version of Exchange that we had the problem with. Our problem could have been much less severe had we occasionally restored our backups onto a test server to validate them. At the first sign of trouble, we could have begun repairing the databases rather than waiting for the problem to become so bad that the system crashed.

Best Practice #5: Do take advantage of Intelligent Message Filter

One of the biggest risks to Exchange security is spam. Spam often carries viruses, Trojans, spyware or links to malicious content. The problem is that good Exchange level antispam software has traditionally been expensive. Recently, though, Microsoft has released the Intelligent Message Filter as a free add-on for users of Exchange Server 2003.

The Intelligent Message Filter is an enterprise level, antispam application based on Microsoft's experience with Hotmail and MSN. Microsoft has produced about half a million different criteria to determine whether or not a message is spam or legitimate e-mail.

If you work in a small company that currently has no spam protection, then downloading and installing the Intelligent Message Filter is a no-brainer. You can get it here. If, on the other hand, you already have antispam software and are happy with its performance, then you might want to evaluate the Intelligent Message Filter on a test server prior to deploying it in a production environment.


Brien M. Posey, MCSE, is a Microsoft Most Valuable Professional for his work with Windows 2000 Server and IIS. Brien has served as the CIO for a nationwide chain of hospitals and was once in charge of IT security for Fort Knox. As a freelance technical writer, he has written for Microsoft, CNET, ZDNet, TechTarget, MSD2D, Relevant Technologies and other technology companies. You can visit his personal Web site at http://www.brienposey.com.

Do you have a useful Exchange tip to share? Submit it to our monthly tip contest and you could win a prize and a spot in our Hall of Fame.

Rate this Tip
To rate tips, you must be a member of SearchExchange.com.
Register now to start rating these tips. Log in if you are already a member.


Submit a Tip




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Exchange Server Administration Tips
Top 10 Microsoft Exchange Server tips of 2008
Database changes that enhance Exchange Server 2007 fault tolerance
How continuous replication methods affect Exchange 2007 log shipping
Analyzing Exchange ActiveSync data from .CSV report files
How to run Exchange Management Shell cmdlets in Exchange Server 2007
Eliminate .PST file use for secure email retention in Exchange 2007
Exchange Server 2007 log shipping and continuous replication
Benefits of backing up Exchange Server with Microsoft's DPM 2007
Exchange Server 2007 replication and database transaction basics
Microsoft Exchange Server 2003 database recovery methods

Microsoft Exchange Server Transaction Log Files
How continuous replication methods affect Exchange 2007 log shipping
Exchange Server 2007 log shipping and continuous replication
Benefits of backing up Exchange Server with Microsoft's DPM 2007
Can a deleted transaction log be restored in Exchange Server 2003?
Why are Exchange Server MDBDATA log files important?
Automating Exchange Server 2003 log file cleanup
Tame your Exchange Server transaction logs
Exchange Server Standard Maintenance Checklist
How to move Exchange Server transaction logs and databases to a new hard drive
How to manually (and safely) purge Exchange Server transaction logs

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Email Server Solutions: Exchange 2007, Exchange 2003, Exchange 2000, SharePoint
HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersIT Downloads
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2004 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts