[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now


Exchange 2007 security distribution groups

Posted on 2011-04-21
Medium Priority
Last Modified: 2012-05-11
Hi Experts,

I have a questions regarding file permissions of folders and linking this with a distribution group using Exchange 2007.

We currently have a shared area where staff saves files to. Problem is over time its become a mess and we are planning on ditching this and creating a new shared area with is more permissions based.

I want to change this new folder so only certain groups of users are able to save work on this share. What would also be useful is if that same group could also be used as a distribution group for email on Outlook.

I wanted to ask what advantages and disadvantages are there for using 'mail enabled universal security groups' in Exchange 2007 which I think will allow me to use a group as a distribution list in Outlook as well as a AD security group to provide permissions for folders.

Would I be better of creating 2 groups with same name, one which will be a mail enabled distribution group for use with exchange and then create a normal security group in AD which would be used to lock down persmissions on files and folders.

The first option sounds great but I am thinking what effect would this have if we ever decided to remove exchange or upgrade exchange, what effect would this have with the folder permissions? I am guessing they will disappear if we ever removed exchange  as it seems the mail enabled groups are heavily linked with Exchange.

If you guys could give me your opinons on this that would be great. The first option would be better as it will save me creating duplicate groups and manually adding in members and it also means 1 group to manage for each department and team.

Question by:RobKanj
  • 3
LVL 31

Expert Comment

ID: 35441647
Use the first option, there are no disadvantages. It is much easier to admin than 2 groups
LVL 31

Accepted Solution

MegaNuk3 earned 2000 total points
ID: 35441677
Even if you were to remove exchange the group would still work as a security group and provide access to shares, folders and files.

Don't make every DG a security group though as they consume more space in AD. Create or change DGs into security groups as you need them.

Author Closing Comment

ID: 35442257
superb - thanks MegaNuke
LVL 31

Expert Comment

ID: 35442301
Thanks for the points.

Also note, that exchange will also convert DGs into SGs if they have been used in exchange to grant permissions e.g. Assigning a DG Public Folder permissions from Outlook

Featured Post

Restore individual SQL databases with ease

Veeam Explorer for Microsoft SQL Server delivers an easy-to-use, wizard-driven interface for restoring your databases from a backup. No expert SQL background required. Web interface provides a complete view of all available SQL databases to simplify the recovery of lost database

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

With so many activities to perform, Exchange administrators are always busy in organizations. If everything, including Exchange Servers, Outlook clients, and Office 365 accounts work without any issues, they can sit and relax. But unfortunately, it…
Steps to fix “Unable to mount database. (hr=0x80004005, ec=1108)”.
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
Suggested Courses

873 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question