Solved

Problem with Exchange View-Only Administrator role.

Posted on 2010-08-16
5
442 Views
Last Modified: 2012-05-10
I am working on an environment of Exchange Shell 2007 in a domain. Users of the domain are controlled by Active Directory(AD). I have created a user "test" on the AD. This user is just member of "Domain Users" and not any other group. When i am trying to execute cmdlets like "get-group", "get-mailbox" from this user, it is executing perfectly, even after the fact that "test" user is not member of "Exchange View-Only Administrators".
According to the Microsoft documentation, the account you use must be delegated the "Exchange View-Only Administrator role".

I have used this, as a check in the Installer of the software, to verify that the user has Exchange View-Only Administrator role.

Can anybody help me to find out the reason why this is happening?
0
Comment
Question by:vickytaurus
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
5 Comments
 
LVL 32

Accepted Solution

by:
endital1097 earned 500 total points
ID: 33444857
your users are "Authenticated Users" and by default have the ability to read Active Directory, and therefore in Exchange 2007 these cmdlets should work

a mailbox is simply a user object that is mailbox-enabled or has attributes modified to enable it for mail

users also can see groups within AD

0
 

Author Comment

by:vickytaurus
ID: 33444988
Thanks endital1097,

If this is the reason, then is there a way i can remove a user from "Authenticated Users" so that i can test the case of failure(cmdlets  not executing)?

Thanks a lot for your response.
0
 
LVL 5

Expert Comment

by:Blake_1
ID: 33445114
You cannot remove someone from Authenticated Users if they have a domain user account.  You could try running the commands from a local user account on the server and observe the behaviour, this would be equivalent to not being a member of Auth Users.

As indicated, all users have access to read the majority of Active Directory.
0
 
LVL 32

Expert Comment

by:endital1097
ID: 33445151
if you want to verify, try a different cmdlet like get-mailboxdatabase
0
 

Author Closing Comment

by:vickytaurus
ID: 33445665
Thanks endital1097 for your solution. I am exploring with the guidelines provided by you. For now it seems that issues is resolved.
Thanks again.
0

Featured Post

Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Utilizing an array to gracefully append to a list of EmailAddresses
This article aims to explain the working of CircularLogArchiver. This tool was designed to solve the buildup of log file in cases where systems do not support circular logging or where circular logging is not enabled
In this video we show how to create an email address policy in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Mail Flow…
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…

756 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question