Microsoft Exchange Inventory

The comprehensive and always up-to-date inventory of the Exchange infrastructure provides a solid basis for well-founded decisions.

Benefits of Exchange Inventory with Docusnap

Exchange inventory with Docusnap offers IT administrators and IT managers significant practical benefits in daily operations. By automating and agentless inventory of Microsoft Exchange servers, Docusnap ensures that all relevant configuration data and authorizations are precisely recorded without the need for manual intervention. This enables a comprehensive and always up-to-date inventory of the Exchange infrastructure, which forms a solid basis for well-founded decisions.

With Docusnap, IT administrators can generate detailed and automatically generated reports on the configuration of Exchange servers, access rights to mailboxes, mailbox folders, and public folders. These reports are not only visually appealing, but can also be individually customized and can be exported to Microsoft Visio, for example. The graphical presentation of the send connectors and other configuration details makes it easier to understand complex relationships within the Exchange infrastructure.

The data obtained through Exchange inventory is essential for various tasks such as security-related checks and the optimization of access rights. Docusnap analyses Exchange server data using the standard LDAP protocol and stores it in a structured way in the Configuration Management Database (CMDB). This enables centralized administration and rapid evaluation of information, which significantly increases efficiency and security in the IT department.

In addition to Exchange inventory, Docusnap also supports the inventory of other systems and services, such as hardware, installed software, network configurations, and certificates. This gives IT administrators a holistic overview of the entire IT infrastructure, which significantly simplifies administration and maintenance.

Permissions

Exchange server rights required:

  • Local administrator on the Exchange server (s) (PsExec connection)
  • View-Only Organization Management/Organization Management
    • NetBIOS spelling
    • UPN spelling

Active Directory rights required:

  • Read access to the configuration partition
  • By default, only domain administrators own this
  • ADSI Editor
    • Configuration
    • cn=Configuration...
      • cn=Services
      • cn=Microsoft Exchange
      • cn=domain
      • cn=Administrative Groups
      • cn=Exchange Administrative Group...
      • cn=Servers

Requirements

  • Inventory via script is possible
  • Transparent firewall configuration
  • PsExec.exe (Microsoft Sysinternals Tool) can be executed
  • PsExec can be blocked by a virus scanner

Supported systems

  • Microsoft Exchange Server 2007 (.NET >= 4.8)
  • Microsoft Exchange Server 2010 (.NET >= 4.8)
  • Microsoft Exchange Server 2013 (.NET >= 4.8)
  • Microsoft Exchange Server 2016 (.NET >= 4.8)
  • Microsoft Exchange Server 2019 (.NET >= 4.8)

Logs used

Protokoll

Port

NetBIOS Name Service, NetBIOS Datagram Service

137, 138

UDP

DCE endpoint solution, NetBIOS Session Service, Microsoft-DS Active Directory, Windows shares (CIFS)

135, 139, 445

TCP

Dynamic high range port (WMI only)

1024 - 65535

TCP/UDP