Run a Lightweight Directory Access Protocol (LDAP) query to locate which user accounts have the ANONYMOUS LOGON group set as their associated external accounts. To do this, follow these steps:
1. | Click Start, click Run, type Ldp.exe, and then click OK. |
2. | Click Connection, and then click Connect. |
3. | Type the name of a global catalog in the Server box, type 3268 in the Port box, and then click OK. |
4. | Click Connection, and then click Bind. |
5. | Type the administrator name, the password, and the domain name. Then, click OK. |
6. | On the Browse menu, click Search. |
7. | In the Filter box, type (&(|(msExchMasterAccountSid=\01\01\00\00\00\00\00\05\07\00\00\00)(objectSID=\01\01\00\00\00\00\00\05\07\00\00\00))(!(objectClass=foreignSecurityPrincipal))), and then click Run. |
The query should return zero entries. If the query returns any entries, follow these steps:
1. | Use the Active Directory Users and Computers snap-in to open the user's properties. |
2. | On the Exchange Advanced tab, click Mailbox Rights. |
3. | Locate the ANONYMOUS LOGON group, and then click to clear the Associated external account check box. Then, click OK.
Important If the Associated external account check box is not selected for the ANONYMOUS LOGON group, click to select the Associated external account check box, and then click OK. Then, go to step 1 to restart this procedure. |
If the account is disabled, specify another account as the associated external account. You can use the
SELF group if you are not sure which account to specify.