Solved

Problem with Exchange View-Only Administrator role.

Posted on 2010-08-16
5
445 Views
Last Modified: 2012-05-10
I am working on an environment of Exchange Shell 2007 in a domain. Users of the domain are controlled by Active Directory(AD). I have created a user "test" on the AD. This user is just member of "Domain Users" and not any other group. When i am trying to execute cmdlets like "get-group", "get-mailbox" from this user, it is executing perfectly, even after the fact that "test" user is not member of "Exchange View-Only Administrators".
According to the Microsoft documentation, the account you use must be delegated the "Exchange View-Only Administrator role".

I have used this, as a check in the Installer of the software, to verify that the user has Exchange View-Only Administrator role.

Can anybody help me to find out the reason why this is happening?
0
Comment
Question by:vickytaurus
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
5 Comments
 
LVL 32

Accepted Solution

by:
endital1097 earned 500 total points
ID: 33444857
your users are "Authenticated Users" and by default have the ability to read Active Directory, and therefore in Exchange 2007 these cmdlets should work

a mailbox is simply a user object that is mailbox-enabled or has attributes modified to enable it for mail

users also can see groups within AD

0
 

Author Comment

by:vickytaurus
ID: 33444988
Thanks endital1097,

If this is the reason, then is there a way i can remove a user from "Authenticated Users" so that i can test the case of failure(cmdlets  not executing)?

Thanks a lot for your response.
0
 
LVL 5

Expert Comment

by:Blake_1
ID: 33445114
You cannot remove someone from Authenticated Users if they have a domain user account.  You could try running the commands from a local user account on the server and observe the behaviour, this would be equivalent to not being a member of Auth Users.

As indicated, all users have access to read the majority of Active Directory.
0
 
LVL 32

Expert Comment

by:endital1097
ID: 33445151
if you want to verify, try a different cmdlet like get-mailboxdatabase
0
 

Author Closing Comment

by:vickytaurus
ID: 33445665
Thanks endital1097 for your solution. I am exploring with the guidelines provided by you. For now it seems that issues is resolved.
Thanks again.
0

Featured Post

Creating Instructional Tutorials  

For Any Use & On Any Platform

Contextual Guidance at the moment of need helps your employees/users adopt software o& achieve even the most complex tasks instantly. Boost knowledge retention, software adoption & employee engagement with easy solution.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Lotus Notes – formerly IBM Notes – is an email client application, while IBM Domino (earlier Lotus Domino) is an email server. The client possesses a set of features that are even more advanced as compared to that of Outlook. Likewise, IBM Domino is…
In-place Upgrading Dirsync to Azure AD Connect
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…
Suggested Courses

623 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question