Solved

Create Accounts and Mailboxes only

Posted on 2010-11-18
2
649 Views
Last Modified: 2012-05-10
Windows 2003 / Exchange 2003 environment.  Need to figure out if there is a way to allow our Help Desk the ability to create account and mailbox only.  We do not want them to have the ability to read everyone's emails, delete accounts.  Is this possible?  Not sure what permissions are required.
0
Comment
Question by:ajruiz
2 Comments
 
LVL 23

Expert Comment

by:Stelian Stan
ID: 34166478
Select your Users OU or the specific OU you have the users > Right click on that OU > Delegate Control > Add all the users you want to give them permissions to create User Account > Check (Create, delete, and manage user accounts) > Next and Finish
0
 
LVL 12

Accepted Solution

by:
Rant32 earned 500 total points
ID: 34167356
Use the Delegate Control wizard to assign at least the 'Create user' common task to the Helpdesk group.

The Helpdesk group should also be a View Only Exchange Administrator. They need to be able to list the AGs and servers in the organization to assign the mailbox server. Use the Exchange Administrator to delegate View Only Administrator rights at the Organization or the Administrative Group, depending on the scope.

If your helpdesk uses AD Users & Computers to create accounts, then the Exchange management tools should be installed on the computer they run it on. These tools are not compatible with Outlook and should ideally not be installed on the same computer (I believe you even have to un-install Outlook to install the Exchange management tools and Outlook will nag about it afterwards).
0

Featured Post

Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
This script can help you clean up your user profile database by comparing profiles to Active Directory users in a particular OU, and removing the profiles that don't match.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…

813 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now