Users who were initially in a thread continue to see thread(in the preview board) after they have been removed, but if double click on it, it shows th

  • Thread starter Thread starter Déh
  • Start date Start date
D

Déh

Guest
Users who were initially in a thread continue to see thread(in the preview board) after they have been removed, but if double click on it, it shows they are not authorized to see it


Scenario:

User A - Created the email

User B - Cced on the email

User C - CCed on the email, but removed later (this user continues to see the preview of the emails)

Brief explanation:

There is an email with a few replies to it. User A,B and C are all in this thread.

User A decides to create a meeting from these emails. User A clicks on Meeting in the Home Tab > Respond section > Meeting (CTRL+Alt+R). When the meeting pops up user A removes user C and keeps/invites user B only to the meeting.

The problem:

Outlook on user C organizes the emails with same subject in a "Conversation".
When User C expands the conversation, it lists the meetings that user C has been removed from and can read the notes of the meetings as a preview. If User C double clicks on this email listed it shows the user isn't authorized to open this object. The meetings doesn't show on user C calendar as well. So, in a nutshell, the problem is that user C may be able to read sensitive information from meetings that he/she hasn't been invited to participate.

In reality, this scenario with user C happens with multiple users that have been removed from the thread. I didn't find any permission issues on Exchange. User C doesn't have access to user A mailbox. What should be the next steps?


Thanks for your assistance!

Continue reading...
 
Back
Top