Solved

Create custom RBAC roles in Exchange 2010

Posted on 2013-11-11
1
358 Views
Last Modified: 2013-11-27
I have a domain admin user that I would like to designate to have the ability to mailbox enable a user in Exchange, choose which database the mailbox will go to, and the ability to modify SMTP addresses and Exchange custom attributes.  

I have assigned this user the Help Desk management role group, which shows as having the assigned roles of User Options and View-Only Recipients.  

I have also created a custom role group and assigned the roles of Mail Recipient Creation and Mail Recipients roles to this user.

I have installed the Exchange Management Console on the users computer, however when I go to verify the proper privileges, it appears that the user has many more privileges than the ones I have assigned, including, and most concerning the ability to Remove mailboxes from the EMC with the rights assigned.

Where is this allowed privilege being applied, and how can I check? Also, how can I remove or modify my privileges so it only includes the abilities I mentioned in the first sentence.

My primary goal is to make sure the user does not have the ability to remove or delete existing mailboxes.

Thank you in advance.
0
Comment
Question by:fireguy1125
1 Comment
 
LVL 63

Accepted Solution

by:
Simon Butler (Sembee) earned 500 total points
ID: 39641225
If they are a domain admin then they probably have more permissions that you expect. Most permissive wins, that means if a user is a member of a group that has higher permissions, that is what permissions they get. You need to look at the permission structure and probably remove their domain admin rights.

Simon.
0

Featured Post

Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Lotus Notes – formerly IBM Notes – is an email client application, while IBM Domino (earlier Lotus Domino) is an email server. The client possesses a set of features that are even more advanced as compared to that of Outlook. Likewise, IBM Domino is…
Read this checklist to learn more about the 15 things you should never include in an email signature.
In this video we show how to create a Resource Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: Navigate to the Recipients >> Resources tab.: "Recipients" is our default selection …
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…

680 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question