Exchange Security Risk Auditor (ESRA)
ESRA audits and updates Mailbox and public folder permissions in Exchange. It can be used for ad-hoc housekeeping or for regular scheduled audit activities.
How does it work?
ESRA audits and updates Mailbox and public folder permissions in Exchange. As staff move departments or roles, and system configurations change over time, errors or omissions can creep in to email permissions. Inappropriate access to mailboxes or public folders can lead to intentional or unintentional breaches of confidential information, or even the accidental deletion of public folders, wiping out a department’s work.
ESRA enforces access policy and rights and prevents security breaches by automating otherwise time-consuming and regularly required housekeeping tasks.
ESRA can be used by the Exchange Administrator or Security Officer.
MSD2D, a resource for the Microsoft Exchange community, announced that C2C Exchange Security Risk Auditor (ESRA) was selected as the 2005 winner in the Exchange Security category of the MSD2D People’s Choice Awards.
Benefits
Exchange Security Risk Auditor (ESRA) provides an easy-to-use application for finding, auditing and changing folder and mailbox permissions.
The objective of ESRA is to enhance the security of your Exchange System, by giving your Administrator the ability to review and change permissions quickly and accurately.
ESRA enables an automated audit of all permissions associated with an Exchange mailbox or public folder, and performs relevant changes.
Regain Control
ESRA should be used both for
- Routine systems maintenance eg when a user leaves the organisation, all their permissions are changed.
- Regular security audits.


