Solved

exch 2010 management access

Posted on 2011-03-24
4
459 Views
Last Modified: 2012-08-14
In exchange 2003, Tech support would make changes to Exch 2003 users mailboxes through AD... Now that we just started using exch 2010, mailbox attributes are no longer availalbe in the users AD account.. Do the Tech support admins need to have access to the Exch 2010 MMC to edit users mailboxes?  Any best practive advice is welcome.
0
Comment
Question by:DEFclub
  • 2
  • 2
4 Comments
 
LVL 38

Expert Comment

by:Adam Brown
ID: 35211841
They will need to have access to the Exchange 2010 Master Console or Shell. You can control what level of access they have by using management roles. http://technet.microsoft.com/en-us/library/dd298183.aspx has some in depth information on the new Role Based Access Control system for Exchange 2010. If you don't want to have to deal with managing roles like that, you can utilize the built in Exchange Security Groups that are installed into AD with Exchange. For instance, adding users to the Recipient Administrators group will allow them to perform a number of mailbox oriented tasks.

One of the advantages of this system is that when a user with limited administrative access opens the Exchange Management Console, only the tasks that they have access to will be presented to them. From the Exchange Management Shell, they will only be able to use the Powershell cmdlets assigned to the management role that they are a member of.
0
 

Author Comment

by:DEFclub
ID: 35211990
Yes, I’m familiar with the management rolls... I guess Im just realizing that Microsoft removed exchange administration from AD and it solely resides in the Exchange MMC or PS... Any idea what their philosophy was for making that decision?
0
 
LVL 38

Accepted Solution

by:
Adam Brown earned 500 total points
ID: 35212081
There were a couple of reasons. Removing it from AD allows for split administration, where AD admins can only view and modify AD objects and functions and Exchange admins can only manage Mailboxes. In the default installation, this partitioning of managerial functions doesn't exist, but Exchange can be installed in a way that allows for much better separation of duties. This is a requirement laid out by many modern security accreditation systems. To be more specific, separation of duties is the requirement that each employee have only enough access to view and modify objects within the scope of their jobs. This prevents an AD admin from, say, configuring an Email user so that all a user's email is forwarded to the admin. It also prevents an Exchange admin from modifying a user or resetting passwords. This could be done with the old system, but the presentation and management of it is much more intuitive with separate interfaces for the two functions.

Another is my own opinion of things, in that the old way of doing it really wasn't very intuitive. Specifically, you managed the Exchange environment in the Exchange Console and the Users in AD. It makes much more sense to have all Exchange administrative tasks available in the same location. I very clearly remember my first run in with Exchange and being horribly confused that I couldn't manage the user's email addresses and such in the Exchange console. There are probably many other reasons as well.
0
 

Author Closing Comment

by:DEFclub
ID: 35216798
Thanks for taking the time to explain!
0

Join & Write a Comment

Synchronize a new Active Directory domain with an existing Office 365 tenant
Learn to move / copy / export exchange contacts to iPhone without using any software. Also see the issues in configuration of exchange with iPhone to migrate contacts.
In this video we show how to create a Contact in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Contact ta…
how to add IIS SMTP to handle application/Scanner relays into office 365.

747 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now