Microsoft Exchange Inventory

The comprehensive and always up-to-date inventory of the Exchange infrastructure provides a solid basis for well-founded decisions.

Permissions

Exchange server rights required:

  • Local administrator on the Exchange server (s) (PsExec connection)
  • View-Only Organization Management/Organization Management
    • NetBIOS spelling
    • UPN spelling

Active Directory rights required:

  • Read access to the configuration partition
  • By default, only domain administrators own this
  • ADSI Editor
    • Configuration
    • cn=Configuration...
      • cn=Services
      • cn=Microsoft Exchange
      • cn=domain
      • cn=Administrative Groups
      • cn=Exchange Administrative Group...
      • cn=Servers

Requirements

  • Inventory via script is possible
  • Transparent firewall configuration
  • PsExec.exe (Microsoft Sysinternals Tool) can be executed
  • PsExec can be blocked by a virus scanner

Supported systems

  • Microsoft Exchange Server 2007 (.NET >= 4.8)
  • Microsoft Exchange Server 2010 (.NET >= 4.8)
  • Microsoft Exchange Server 2013 (.NET >= 4.8)
  • Microsoft Exchange Server 2016 (.NET >= 4.8)
  • Microsoft Exchange Server 2019 (.NET >= 4.8)

Logs used

Protokoll

Port

NetBIOS Name Service, NetBIOS Datagram Service

137, 138

UDP

DCE endpoint solution, NetBIOS Session Service, Microsoft-DS Active Directory, Windows shares (CIFS)

135, 139, 445

TCP

Dynamic high range port (WMI only)

1024 - 65535

TCP/UDP