Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


March 11, 2008

How can I prevent users from using Microsoft Office Outlook’s delegation feature?

RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

Untitled Document

Executive Summary:
Prevent users from using Microsoft Office Outlook’s delegation feature.

Q: How can I prevent users from using Microsoft Office Outlook’s delegation feature?

A: In a standard Exchange Server organization, users can grant other employees delegate access to their mailbox or folders. This practice typically occurs when a manager grants access to an assistant, or when an employee goes on vacation and delegates mailbox access to a co-worker. However, delegation is often performed incorrectly—and sometimes even inadvertently—which can unintentionally expose information to the wrong personnel. Although I don’t know of a method for completely preventing Outlook delegation in an Exchange environment, you can prevent users from using delegation by removing access to this feature in the UI.

After an Exchange account is configured, you can add delegation functionality in Outlook as an Exchange Client Extension. To access the delegation feature, select Options from the Tools menu. Select the Delegates tab, as Figure 1 shows. The Exchange extension for this tab is called dlgsetp.dll. The file dlgsetp.ecf, which describes dlgsetp.dll, tells Outlook how to load the .dll file for Exchange Client Extensions. You can configure the UI to tell Outlook not to load this add-in. In Microsoft Office Outlook 2007, select Trust Center from the Tools menu, and click Add-ins on the left-hand menu. At the bottom of the window, select the add-ins you want to manage (i.e., Exchange Client Extensions), as Figure 2 shows, and click Go. In the Add-In Manager window that opens, which Figure 3 shows, you can clear the Delegate Access check box to remove the Delegates tab from Outlook’s UI. However, users can simply navigate back to this option and reenable it.

A solution is to delete or rename the file dlgsetp.ecf to prevent the extension from loading into Outlook. I typically rename the file from dlgsetp.ecf to dlgsetp.ecf.bak. In Outlook 2007, this file is located in \Program Files\Microsoft Office\Office12\ADDINS. The location is similar in previous versions of Outlook; for example, in Microsoft Office Outlook 2003, the path is \Program Files\Microsoft Office\Office11\ADDINS. Renaming this file doesn’t cause Outlook to fail and doesn’t even generate an error message; the action simply prevents the Delegates tab from loading. The Delegates tab isn’t visible because the Exchange Client Extension isn’t able to load into Outlook. You might need to restart Outlook for the change to take effect.

From an enterprise perspective, you might want to use a logon script or another centrally managed solution with access to the file system to rename the file dlgsetp.ecf. Keep in mind that installing patches or service packs might apply a new dlgsetp.ecf file, thereby restoring the Delegates tab. You’d then need to rename the file again.

Although this solution is a bit of a hack, it might be worthwhile in your organization. Preventing users from using Outlook’s delegation feature is often easier than dealing with the ramifications of incorrect or inappropriate delegation.

End of Article



Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
Microsoft: Save Money ... By Paying for Software

Microsoft this week adopted an interesting tactic in its long-running battle with open source software: Businesses looking to save money over the long haul should simply pay for software instead of moving to free, open source solutions. The rationale? ...

PsExec

This freeware utility lets you execute processes on a remote system and redirect output to the local system. ...

Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...


Security Whitepapers The Impact of Messaging and Web Threats

Why SaaS is the Right Solution for Log Management

Protecting (You and) Your Data with Exchange Server 2007

Related Events Storage Consolidation for Your Microsoft Applications: Reducing Cost and Complexity

How IE7 & The New Extended Validation SSL Certificates Impact Your Site

The Myths & Truths of Email Management with SharePoint

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing