Solved

Minimum rights required in Active Directory

Posted on 2009-05-14
3
582 Views
Last Modified: 2012-05-07
Hello all,

I'm trying to figure out the minimum required rights a help desk worker should have to be able to move users and create new mailboxes. Thanks!
0
Comment
Question by:hmcnasty
3 Comments
 
LVL 57

Accepted Solution

by:
Mike Kline earned 250 total points
Comment Utility
What other tasks would they be doing with user accounts?
There is a builtin-group called account operators (that may be to much power though)
http://technet.microsoft.com/en-us/library/cc756898.aspx
Account Operators
Members of this group can create, modify, and delete accounts for users, groups, and computers located in the Users or Computers containers and organizational units in the domain, except the Domain Controllers organizational unit. Members of this group do not have permission to modify the Administrators or the Domain Admins groups, nor do they have permission to modify the accounts for members of those groups. Members of this group can log on locally to domain controllers in the domain and shut them down. Because this group has significant power in the domain, add users with caution.
We have about 20 people in our help desk.  Two of them do account maintenance and they are in this group.  
Thanks
Mike
0
 
LVL 22

Assisted Solution

by:Paka
Paka earned 250 total points
Comment Utility
Configuring a user or helpdesk to manage user accounts and mailboxes can be done but it's a moderately difficult task.  In short, you will need to create a group such as "HelpDeskGroup" and delegate Exchange View Only Adminstrator rights to it (don't let the name concern you) using ESM.  Next, you will need to delegate the appropriate rights to that group - this is the tough part and is detailed in the link below.  Lastly, add the individual Help Desk accounts to the HelpDeskGroup.

Here's a link detailing the appropriate rights needed for mailbox delegation:
http://groups.google.com/group/microsoft.public.exchange.admin/browse_thread/thread/89170c9c159e81f3
0
 

Author Comment

by:hmcnasty
Comment Utility
Thanks guys, this has been very helpful.
0

Featured Post

Top 6 Sources for Identifying Threat Actor TTPs

Understanding your enemy is essential. These six sources will help you identify the most popular threat actor tactics, techniques, and procedures (TTPs).

Join & Write a Comment

I know all systems administrator at some time or another has had to create a script to copy file from a server share to a desktop. Well now there is an easy way to do this in Group Policy. Using Group policy preferences is not hard. The first thing …
Installing a printer using group policy preferences is not that hard let’s take a look at it. First lets open up your group policy console and edit the policy you want to add it to. I recommend creating a new policy for each printer makes it a l…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

5 Experts available now in Live!

Get 1:1 Help Now