Solved

Problem with Exchange View-Only Administrator role.

Posted on 2010-08-16
5
438 Views
Last Modified: 2012-05-10
I am working on an environment of Exchange Shell 2007 in a domain. Users of the domain are controlled by Active Directory(AD). I have created a user "test" on the AD. This user is just member of "Domain Users" and not any other group. When i am trying to execute cmdlets like "get-group", "get-mailbox" from this user, it is executing perfectly, even after the fact that "test" user is not member of "Exchange View-Only Administrators".
According to the Microsoft documentation, the account you use must be delegated the "Exchange View-Only Administrator role".

I have used this, as a check in the Installer of the software, to verify that the user has Exchange View-Only Administrator role.

Can anybody help me to find out the reason why this is happening?
0
Comment
Question by:vickytaurus
  • 2
  • 2
5 Comments
 
LVL 32

Accepted Solution

by:
endital1097 earned 500 total points
ID: 33444857
your users are "Authenticated Users" and by default have the ability to read Active Directory, and therefore in Exchange 2007 these cmdlets should work

a mailbox is simply a user object that is mailbox-enabled or has attributes modified to enable it for mail

users also can see groups within AD

0
 

Author Comment

by:vickytaurus
ID: 33444988
Thanks endital1097,

If this is the reason, then is there a way i can remove a user from "Authenticated Users" so that i can test the case of failure(cmdlets  not executing)?

Thanks a lot for your response.
0
 
LVL 5

Expert Comment

by:Blake_1
ID: 33445114
You cannot remove someone from Authenticated Users if they have a domain user account.  You could try running the commands from a local user account on the server and observe the behaviour, this would be equivalent to not being a member of Auth Users.

As indicated, all users have access to read the majority of Active Directory.
0
 
LVL 32

Expert Comment

by:endital1097
ID: 33445151
if you want to verify, try a different cmdlet like get-mailboxdatabase
0
 

Author Closing Comment

by:vickytaurus
ID: 33445665
Thanks endital1097 for your solution. I am exploring with the guidelines provided by you. For now it seems that issues is resolved.
Thanks again.
0

Featured Post

Better Security Awareness With Threat Intelligence

See how one of the leading financial services organizations uses Recorded Future as part of a holistic threat intelligence program to promote security awareness and proactively and efficiently identify threats.

Join & Write a Comment

"Migrate" an SMTP relay receive connector to a new server using info from an old server.
This process describes the steps required to Import and Export data from and to .pst files using Exchange 2010. We can use these steps to export data from a user to a .pst file, import data back to the same or a different user, or even import data t…
In this Micro Video tutorial you will learn the basics about Database Availability Groups and How to configure one using a live Exchange Server Environment. The video tutorial explains the basics of the Exchange server Database Availability grou…
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…

747 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now