I trying to track down a user who is logging on as different user to send anonymous messages.
Scenerio:
I have a domain user account that about 15 people know the password to. someone logged on using this account and sent a message to someone in a different department. because of the content of the message I'm 100% certain that it's an internal user; not someone spoofing.
Is there a way to track down what computer (IP address) was used to log on as this user?
The incident happened a couple of days ago so I'm hoping I still track down the user. I'm using exchange server 2003.
Scenerio:
I have a domain user account that about 15 people know the password to. someone logged on using this account and sent a message to someone in a different department. because of the content of the message I'm 100% certain that it's an internal user; not someone spoofing.
Is there a way to track down what computer (IP address) was used to log on as this user?
The incident happened a couple of days ago so I'm hoping I still track down the user. I'm using exchange server 2003.