Solved

Exchange store permissions?

Posted on 2007-11-17
4
195 Views
Last Modified: 2010-04-21
I have an exchange server that I have full exchange admin rights on. I can do things like Exmerges and reconnect mailboxes exc.

There is another group in Active directory whos members need to manage that groups poeple.

I'm going to create a storage group with those groups users only and let that group manage it.

How can I do this and let them run Exmerge, Exchange Tasks, Mail Enable poeple and stuff while giving them the least permissions to do this job?

I was thinking of just applying permissions to that storage group or store? for that group and give sendas/receiveas permissions?

I beleive they also need to be local admins in order to successfully do an Exmerge and export PST's or whatever? In that case can they be local account operators or something very minimal that won't allow them to bang up the actual server or do things outside of ESM?


0
Comment
Question by:snyderkv
  • 2
  • 2
4 Comments
 
LVL 12

Accepted Solution

by:
Network_Data_Support earned 500 total points
Comment Utility
The account that is used to run the ExMerge utility must have the Send As permission and the Receive As permission on the mailbox store that the ExMerge utility will be used on. By default, the following permissions are assigned when you install Exchange:
•      In Exchange 2000, built-in administrator accounts and built-in administrative groups inherit the Deny permission for both the Send As and the Receive As permissions.
•      In Exchange 2003, built-in administrator accounts and built-in administrative groups inherit the Allow permission together with the Deny permission for the Send As permission and for the Receive As permission.

Note Some permissions take precedence over others. Typically, the Deny permission overrides the Allow permission. However, inherited Deny permissions do not prevent access to an object if the object has an explicit Allow permission entry. Explicit permissions take precedence over inherited permissions, even inherited Deny permissions.
To use the ExMerge utility without being restricted by these inherited permissions, it is recommended that you create a new security group, add members to the group, and then grant permissions to the security group on the Exchange mailbox store. In Exchange 2003, you must use a security group to override inherited Send As permissions and Receive As permissions. In Exchange 2000, you can apply explicit permissions to an individual account to override inherited Send As and Receive As permissions. However, we recommend that you use a security group to apply permissions in both versions of Exchange.
0
 

Author Closing Comment

by:snyderkv
Comment Utility
Thanks great answer

Please tell me if you also need to be a local admin?
0
 

Author Comment

by:snyderkv
Comment Utility
Great writeup.

Also please let me know if they also have to be a local admin on that exchange server
0
 
LVL 12

Expert Comment

by:Network_Data_Support
Comment Utility
i dont think so, exmerge is userly set up with a new account created in AD and only member of domain users if i remember shouldnt be a member of domain admins so in that case dont need to be a local administrator
0

Featured Post

IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

Utilizing an array to gracefully append to a list of EmailAddresses
This process describes the steps required to Import and Export data from and to .pst files using Exchange 2010. We can use these steps to export data from a user to a .pst file, import data back to the same or a different user, or even import data t…
In this video we show how to create an email address policy in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Mail Flow…
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now