Solved

Exchnage 2010 Administrative access and rights control

Posted on 2013-01-18
7
187 Views
Last Modified: 2014-08-16
hello all,
I have 2x Exchange DAG's within the same organisation in different AD sites.

We have a DAG in the UK consisting of 2x physical mailbox servers and 2x virtual CAS/HT boxes.
We have the same setup in the USA.

The USA has it's own small junior IT team. I wan't to give certain access privileges without the USA junior admins being able to do anything on the UK servers.

So far, I have used RBAC's to create helpdesk roles and the like. However, I need to give the USA admins the ability to manage their own databases only (not the UK ones). This is to carry out actions such as;

- Active/move a DB copy on a server whilst suspending it on another mbx host. take a server offline for maintenance whilst keeping all DB's up on the USA DAG.


How can I increase the USA admins Exchange access ensuring, that they cannot do anything on the UK- London DAG?
thanks, regards
0
Comment
Question by:UBB
  • 2
  • 2
7 Comments
 
LVL 42

Assisted Solution

by:Amit
Amit earned 175 total points
ID: 38794109
I don't see any such restriction option, as DB resides at Org level, and if you are giving Org level permission, it give rights at highest level.
0
 
LVL 52

Expert Comment

by:Manpreet SIngh Khatra
ID: 38794276
I second Amit as its a single level access and maybe what you can try out is give Object level access using ADISIEDIT

- Rancy
0
 

Author Comment

by:UBB
ID: 38795073
hello,
appreciate the feedback. Rancy, are you able to give me a few more details re ADSIEdit?

I don't realy like messing with that unless I know exactly what I am after and where to look.

What container should I be connecting to in ADSI to find this 'key'?
Which object is it I should be looking at?
What values should I be changing in Adsi?
thanks.
0
 
LVL 52

Accepted Solution

by:
Manpreet SIngh Khatra earned 175 total points
ID: 38795150
In ADSIEDIT you have to browse to the Servers container and on the properties of the specific Server object go to Security Tab and give the account Full control and wait

- Rancy
0
 

Author Comment

by:UBB
ID: 38798277
thanks
i will try that this week and get back.. probably wont be till wed/thurs.
regards
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This process describes the steps required to Import and Export data from and to .pst files using Exchange 2010. We can use these steps to export data from a user to a .pst file, import data back to the same or a different user, or even import data t…
With User Account Control (UAC) enabled in Windows 7, one needs to open an elevated Command Prompt in order to run scripts under administrative privileges. Although the elevated Command Prompt accomplishes the task, the question How to run as script…
In this video we show how to create a Contact in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Contact ta…
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…

860 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question