DOCUMENT:Q259575 06-AUG-2002 [exchange] TITLE :XADM: How to Determine Which User Deleted an Exchange Recipient PRODUCT :Microsoft Exchange PROD/VER::5.5 OPER/SYS: KEYWORDS:kberrmsg exc55 ====================================================================== ------------------------------------------------------------------------------- The information in this article applies to: - Microsoft Exchange Server, version 5.5 ------------------------------------------------------------------------------- SUMMARY ======= This article describes how to use Diagnostics Logging to determine which Administrator account deleted an Exchange Server recipient. MORE INFORMATION ================ In a typical production Exchange Server environment, many individuals and groups may have Administrator permissions to an Exchange Server site. In some cases, recipients may be accidentally or purposely deleted when you use the Microsoft Exchange Server Administrator program or the Directory Import feature. To determine when the recipient was deleted, and which Administrator account deleted the recipient, set the Diagnostics Logging level on the MSExchangeDS\Security object to Maximum: 1. Start the Administrator program, expand the Site\Configuration\Servers container, and then click a server. 2. On the File menu, click Properties. 3. Click the Diagnostics Logging tab. 4. In the Services section, click MSExchangeDS. 5. In the Category section, click Security. 6. In the Logging Level section, click Maximum, and then click OK. Use this procedure on every server in the site. If you use the Administrator program on one server to change the Diagnostics Logging level, the diagnostic information is not logged until the changes are replicated to the other servers in the site. NOTE: If Diagnostics Logging for the Security object is not enabled on every server in the site, a user who has Administrator permissions is able to establish a connection to a server that does not have the Diagnostics Logging level set to Maximum, and delete a mailbox without being detected. When the Diagnostics Logging level for the Security object is set to Maximum, if a mailbox is deleted on the server, an event similar to the following event is logged: ***BEGIN*** Date: Event: 1053 Time: