cancel
Showing results for 
Search instead for 
Did you mean: 

Permissions - users able to view Vaults even though they don't have permissions

mstawchansky
Level 4
I'm using Enterprise Vault 8 SP3. I have a very similar issue to this one.

https://www-secure.symantec.com/connect/forums/user-able-see-all-vaults-has-no-permissions

I am able to clear permissions off the Vaults using EVPM and ZAP. This clears all permissions and everything looks good. Once the syncronize task runs again though, permissions are back to the incorrect way ( some users can view ALOT of vaults). The Vaults that are visible show only their own permissions on the permissions property tab and in the PermissionsBrowser. I've also disabled Inheritance and Permision sync in all my Mailbox archiving policies...but they are still being synced somehow ( and the Exchange Mailboxes themselves operate correctly. I.E. User A can see User B's Vault , but User A cannot see User B's Exchange Mailbox.

Any help?
1 ACCEPTED SOLUTION

Accepted Solutions

TonySterling
Moderator
Moderator
Partner    VIP    Accredited Certified
Is there anything unusual in AD on the Exchange Tab of the properties page for the users that show up?

this might help, http://seer.entsupport.symantec.com/docs/310881.htm

View solution in original post

4 REPLIES 4

JesusWept3
Level 6
Partner Accredited Certified
is it syncing folder permissions?
also these users that can see otherr people, are they members of exchange admins or backup groups etc?
https://www.linkedin.com/in/alex-allen-turl-07370146

mstawchansky
Level 4
Yes, the affected users are able to browse everything in the Vaults from Inbox down.

No additional permissions groups, some are contractors with only the Authenticated Users group members.

TonySterling
Moderator
Moderator
Partner    VIP    Accredited Certified
Is there anything unusual in AD on the Exchange Tab of the properties page for the users that show up?

this might help, http://seer.entsupport.symantec.com/docs/310881.htm

JesusWept3
Level 6
Partner Accredited Certified
What i would also suggest doing is getting a user and seeing if they can open the users mailbox in outlook or the \inbox in outlook itself
because if that is the case, then you have a bigger problem tied to Exchange and AD (which i believe you have any way)
https://www.linkedin.com/in/alex-allen-turl-07370146