Solved

Minimum rights required in Active Directory

Posted on 2009-05-14
3
628 Views
Last Modified: 2012-05-07
Hello all,

I'm trying to figure out the minimum required rights a help desk worker should have to be able to move users and create new mailboxes. Thanks!
0
Comment
Question by:hmcnasty
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 57

Accepted Solution

by:
Mike Kline earned 250 total points
ID: 24387784
What other tasks would they be doing with user accounts?
There is a builtin-group called account operators (that may be to much power though)
http://technet.microsoft.com/en-us/library/cc756898.aspx
Account Operators
Members of this group can create, modify, and delete accounts for users, groups, and computers located in the Users or Computers containers and organizational units in the domain, except the Domain Controllers organizational unit. Members of this group do not have permission to modify the Administrators or the Domain Admins groups, nor do they have permission to modify the accounts for members of those groups. Members of this group can log on locally to domain controllers in the domain and shut them down. Because this group has significant power in the domain, add users with caution.
We have about 20 people in our help desk.  Two of them do account maintenance and they are in this group.  
Thanks
Mike
0
 
LVL 22

Assisted Solution

by:Paka
Paka earned 250 total points
ID: 24393913
Configuring a user or helpdesk to manage user accounts and mailboxes can be done but it's a moderately difficult task.  In short, you will need to create a group such as "HelpDeskGroup" and delegate Exchange View Only Adminstrator rights to it (don't let the name concern you) using ESM.  Next, you will need to delegate the appropriate rights to that group - this is the tough part and is detailed in the link below.  Lastly, add the individual Help Desk accounts to the HelpDeskGroup.

Here's a link detailing the appropriate rights needed for mailbox delegation:
http://groups.google.com/group/microsoft.public.exchange.admin/browse_thread/thread/89170c9c159e81f3
0
 

Author Comment

by:hmcnasty
ID: 24424296
Thanks guys, this has been very helpful.
0

Featured Post

Enroll in June's Course of the Month

June’s Course of the Month is now available! Experts Exchange’s Premium Members, Team Accounts, and Qualified Experts have access to a complimentary course each month as part of their membership—an extra way to sharpen your skills and increase training.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
Uncontrolled local administrators groups within any organization pose a huge security risk. Because these groups are locally managed it becomes difficult to audit and maintain them.
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

691 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question