Carbonite Support > FAQ: What is Exchange Imperson...

FAQ: What is Exchange Impersonation?

Summary:

What is Exchange Impersonation?

This article applies to:

Carbonite Plans Products Platforms
Power and Ultimate (Not sure?) Carbonite Safe Server Backup (Not sure?) Windows

Solution:

Exchange Impersonation is a right that can be granted to an account on an Exchange server. Impersonation is ideal for applications, such as Carbonite Safe Server Backup, that connect to local Exchange servers or Exchange Online. It allows a single service account to access any number of other mailboxes.

A detailed overview of the Exchange Impersonation right can be found in this article in the Microsoft knowledge Base. The article gives great detail about the Exchange Impersonation right.

Are there any security concerns?

Exchange Impersonation is a built-in, native right within Exchange which only works via the Exchange Web Services (EWS) API. Only applications that use the EWS API can utilize Exchange Impersonation.

However, Impersonation is an Administrator-level right and should be treated with care. You should work with your Exchange administrator to ensure that the service accounts that you use are created with the permissions and access that meet the security requirements of your organization.

How does CSSB use Exchange Impersonation?

The Exchange Local Mailbox and Exchange Online Mailbox backup types in CSSB require that the user specify an administrator account that has the Exchange Impersonation right. The user can choose any account, or even create a new one, so long as the account meets the requirements laid out in the CSSB User Guide. Please refer to this Knowledge Base article for the requirements for Local Exchange Mailbox backups and Exchange Online.

Exchange Impersonation allows the chosen administrator account to access other mailboxes on the server using the Exchange Web Services API. CSSB only accesses other mailboxes for backup and restore purposes. For example, CSSB is able to use Impersonation to copy data from mailboxes during a backup without needing a separate login for each.

Feedback