Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
dede79
Contributor

IA collector - events from shared mailboxes

Hello,

I discovered that having a shared mailbox in addition to the personal one is resulting in permanent access role updates on the client.

If I close outlook I only see the logged in user.

Checkpoint says its by design - but actually installing MUH agent on thousends of clients is not a nice solution or me.

Has anybody seen this issue before? It really gets problematic if the username of the shared mailbox has no rules for internet access - when role is updated the user using this pc can not access the web.

Since it looks like a real windows login event I so no options for exclude filters.

 

Gateways are R81 - collector 81.040

 

Thanks

0 Kudos
4 Replies
the_rock
Legend
Legend

I also believe thats by design. Log out events would never be logged, as Microsoft would never log those in the first place, only log-in ones.

0 Kudos
PhoneBoy
Admin
Admin

This is expected behavior when you effectively have multiple identities on one PC, which is what I presume is happening as a result of this shared mailbox.
Not sure even MUH would necessarily solve this.
What about when you access the shared mailbox using Outlook Web Access (instead of using Outlook)?

0 Kudos
dede79
Contributor

I suppose then we will not have that issue. So it is a microsoft thing that thei create an login event just for a mailbox access? Strange that I see it the first time  - doing IA nearly from begining on.

0 Kudos
PhoneBoy
Admin
Admin

I assume so, yes
It’s possible it’s a behavior change in Outlook if this started only recently.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events