Tech or Treat! Write an article about your scariest tech disaster to win gadgets!Learn more

x
?
Solved

exch 2010 management access

Posted on 2011-03-24
4
Medium Priority
?
511 Views
Last Modified: 2012-08-14
In exchange 2003, Tech support would make changes to Exch 2003 users mailboxes through AD... Now that we just started using exch 2010, mailbox attributes are no longer availalbe in the users AD account.. Do the Tech support admins need to have access to the Exch 2010 MMC to edit users mailboxes?  Any best practive advice is welcome.
0
Comment
Question by:DEFclub
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 43

Expert Comment

by:Adam Brown
ID: 35211841
They will need to have access to the Exchange 2010 Master Console or Shell. You can control what level of access they have by using management roles. http://technet.microsoft.com/en-us/library/dd298183.aspx has some in depth information on the new Role Based Access Control system for Exchange 2010. If you don't want to have to deal with managing roles like that, you can utilize the built in Exchange Security Groups that are installed into AD with Exchange. For instance, adding users to the Recipient Administrators group will allow them to perform a number of mailbox oriented tasks.

One of the advantages of this system is that when a user with limited administrative access opens the Exchange Management Console, only the tasks that they have access to will be presented to them. From the Exchange Management Shell, they will only be able to use the Powershell cmdlets assigned to the management role that they are a member of.
0
 

Author Comment

by:DEFclub
ID: 35211990
Yes, I’m familiar with the management rolls... I guess Im just realizing that Microsoft removed exchange administration from AD and it solely resides in the Exchange MMC or PS... Any idea what their philosophy was for making that decision?
0
 
LVL 43

Accepted Solution

by:
Adam Brown earned 2000 total points
ID: 35212081
There were a couple of reasons. Removing it from AD allows for split administration, where AD admins can only view and modify AD objects and functions and Exchange admins can only manage Mailboxes. In the default installation, this partitioning of managerial functions doesn't exist, but Exchange can be installed in a way that allows for much better separation of duties. This is a requirement laid out by many modern security accreditation systems. To be more specific, separation of duties is the requirement that each employee have only enough access to view and modify objects within the scope of their jobs. This prevents an AD admin from, say, configuring an Email user so that all a user's email is forwarded to the admin. It also prevents an Exchange admin from modifying a user or resetting passwords. This could be done with the old system, but the presentation and management of it is much more intuitive with separate interfaces for the two functions.

Another is my own opinion of things, in that the old way of doing it really wasn't very intuitive. Specifically, you managed the Exchange environment in the Exchange Console and the Users in AD. It makes much more sense to have all Exchange administrative tasks available in the same location. I very clearly remember my first run in with Exchange and being horribly confused that I couldn't manage the user's email addresses and such in the Exchange console. There are probably many other reasons as well.
0
 

Author Closing Comment

by:DEFclub
ID: 35216798
Thanks for taking the time to explain!
0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A bad practice commonly found during an account life cycle is to set its password to an initial, insecure password. The Password Reset Tool was developed to make the password reset process easier and more secure.
It’s time for spooky stories and consuming way too much sugar, including the many treats we’ve whipped for you in the world of tech. Check it out!
This video discusses moving either the default database or any database to a new volume.
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an antispam), the admini…
Suggested Courses

647 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question