Problem with Exchange View-Only Administrator role.

I am working on an environment of Exchange Shell 2007 in a domain. Users of the domain are controlled by Active Directory(AD). I have created a user "test" on the AD. This user is just member of "Domain Users" and not any other group. When i am trying to execute cmdlets like "get-group", "get-mailbox" from this user, it is executing perfectly, even after the fact that "test" user is not member of "Exchange View-Only Administrators".
According to the Microsoft documentation, the account you use must be delegated the "Exchange View-Only Administrator role".

I have used this, as a check in the Installer of the software, to verify that the user has Exchange View-Only Administrator role.

Can anybody help me to find out the reason why this is happening?
vickytaurusAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

endital1097Commented:
your users are "Authenticated Users" and by default have the ability to read Active Directory, and therefore in Exchange 2007 these cmdlets should work

a mailbox is simply a user object that is mailbox-enabled or has attributes modified to enable it for mail

users also can see groups within AD

0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
vickytaurusAuthor Commented:
Thanks endital1097,

If this is the reason, then is there a way i can remove a user from "Authenticated Users" so that i can test the case of failure(cmdlets  not executing)?

Thanks a lot for your response.
0
Blake_1Commented:
You cannot remove someone from Authenticated Users if they have a domain user account.  You could try running the commands from a local user account on the server and observe the behaviour, this would be equivalent to not being a member of Auth Users.

As indicated, all users have access to read the majority of Active Directory.
0
endital1097Commented:
if you want to verify, try a different cmdlet like get-mailboxdatabase
0
vickytaurusAuthor Commented:
Thanks endital1097 for your solution. I am exploring with the guidelines provided by you. For now it seems that issues is resolved.
Thanks again.
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Exchange

From novice to tech pro — start learning today.