Artisan Mailbox Manager Security Features
ArtiSan implements a very sophisticated security scheme to control access to the archive
content based on a dynamic view of the relevant permissions in relation to the archive content
and the Exchange server. In general, if a user can see or could have seen an item in an Exchange
mailbox then they are granted access to the archive copy. This is irrespective of whether this is due
to delegated access or simply that the item was in their own mailbox.
When a user attempts to access a message in the archive irrespective of how that request is made,
ArtiSan checks the identity of the user attempting to make the access against its internal
record of whether a copy of the mail was located in that user's mailbox. If so, the item
is returned. However, if the mail originated from another user's mailbox, ArtiSan checks the current
permissions associate with the Exchange mailbox store and mailbox folder to see whether the
user is a delegated user of the mailbox folder and, if so, will return the message content. If none
of these cases are true, then the system will deny the user access to the content.
The system is dynamic because the system uses the current settings for checking delegated access
and so will dynamically track changes performed by users in the Exchange. By tracking Exchange
and Active Directory permissions, the system simplifies the task of securing the
company mail system.
ArtiSan also maintains a notion of the "ArtiSan Reviewers" group, which is a group added to the
ADS that is allowed to search across all mail in the archive and to access any content. The purpose
of this account is to allow support of searches by company information officers for the purposes of
compliance.
ArtiSan is typically deployed using NTFS storage and permission checking is end to end in the
system. However, it also supports the use of non-permissioned storage, enforcing the permissions
checks within the ArtiSan software. ArtiSan also installs an indexing filter that is specifically
designed to enforce security of searches so that search results do not include content that the end
user is not permissioned for even where the underlying content is located on network attached storage. The
filter also deals with some internationalisation issues arising from the standard EML filter supplied by
Microsoft with the Indexing Service.
|