Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Copy exchnage database permissions with ADSIEdit

Posted on 2011-02-21
4
Medium Priority
?
1,054 Views
Last Modified: 2012-05-11
After creating a new mailstore in exchange 2010 I would normally use ADSI Edit to add the permissions for the BES and the backup software account manually.

Is there  a way to copy the permissions from the existing mailstore to the new one with out having to manually open it in adsi-edit?
0
Comment
Question by:BMI-IT
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 58

Expert Comment

by:tigermatt
ID: 34943024
>> Is there  a way to copy the permissions from the existing mailstore to the new one with out having to manually open it in adsi-edit?

No way to "copy" permissions like you describe, but an alternative would be to set the necessary permissions "higher" in the tree - at the organization level - so the BES and backup software can always access any mail store you create.

I also would not recommend you use ADSIEdit for this procedure. Everything can be achieved using the Exchange Management Shell, and that environment is MUCH safer for this purpose.

I would also, as a best practice, use a security group, grant the permissions to the group and then put the BES and backup service user accounts into that group.

I don't know what permissions you want these application service users to have, but here's how to grant them full control at both levels:

At the Mailbox Database level:
Get-MailboxDatabase "DB NAME" | Add-ADPermission -User DOMAIN\MyUserOrGroupName -AccessRights FullControl

Open in new window

At the Organization level:
Get-OrganizationConfig | Add-ADPermission -User DOMAIN\MyUserOrGroupName -AccessRights FullControl

Open in new window

Those examples show how to grant full control - DO NOT give full control if your applications don't need it. If you set the permissions at the organization level, that IS very high in the AD structure, so be sure to document that modification too.

-Matt
0
 

Author Comment

by:BMI-IT
ID: 34943065
Ahh I see,  for the Besadmin account I need to add Send As, Receive As, and Administer Information Store for the new mailstore I created
0
 
LVL 58

Accepted Solution

by:
tigermatt earned 500 total points
ID: 34943210

If you want to grant that at the mailbox store level, the following command will do the trick:

Get-MailboxDatabase "DB NAME" | Add-ADPermission -user DOMAIN\BESAdmin -ExtendedRight Send-As,Receive-As,ms-Exch-Store-Admin

Open in new window


-Matt
0
 

Author Comment

by:BMI-IT
ID: 34943228
That did the trick  thank you :)
0

Featured Post

Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The main intent of this article is to make you aware of ‘Exchange fail to mount’ error, its effects, causes, and solution.
If something goes wrong with Exchange, your IT resources are in trouble.All Exchange server migration processes are not designed to be identical and though migrating email from on-premises Exchange mailbox to Cloud’s Office 365 is relatively simple…
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…
In this Micro Video tutorial you will learn the basics about Database Availability Groups and How to configure one using a live Exchange Server Environment. The video tutorial explains the basics of the Exchange server Database Availability grou…

609 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question