Solved

organisation management 2013

Posted on 2015-02-17
2
52 Views
Last Modified: 2015-02-25
In relation to the group/role "organisation  management" in exch2013, what permissions does this give the user, and what types of user typically require this permission? Or put another way, what could a malicious user do to your exchange environment if they got hold of an account with organisation management permissions.

I am reviewing security permissions and noticed generally the whole IT section (25+ employees) have been added organisation permissions - but I need to determine if this is common, or if you have only a few trusted users with organisation management permissions - and if so for what tasks do they require such access.
0
Comment
Question by:pma111
2 Comments
 
LVL 53

Assisted Solution

by:Will Szymkowski
Will Szymkowski earned 250 total points
ID: 40614323
Org Management, is the top level administrative Group for Exchange 2013 (think of it as a domain admin account for an AD Domain). Users/Group that are associated with this built-in group have access to perform any administrative task in your Exchange Organization. If you have Users that are not Exchange Admins in your environment I would not have them part of this group.

Take a look at the technet below which explains Org Management Group in more detail.
https://technet.microsoft.com/en-us/library/dd335087%28v=exchg.150%29.aspx

Will.
0
 
LVL 24

Accepted Solution

by:
VB ITS earned 250 total points
ID: 40614381
I am reviewing security permissions and noticed generally the whole IT section (25+ employees) have been added organisation permissions
That's way too many people. As Will has outlined above, the Organization Management group has almost complete access to your Exchange environment so only add the users that need to be in this group. For all others I would look at creating some custom RBAC roles and applying only the required access to these roles.

Start off here first to get a better understanding of the RBAC model in Exchange: https://technet.microsoft.com/en-us/library/dd298183(v=exchg.150).aspx

This article walks you through the process of creating a custom RBAC role group and adding specific permissions to this group so as to limit what users can do. Note that this is a four-part article: http://www.msexchange.org/articles-tutorials/exchange-server-2013/management-administration/rbac-made-easy-part1.html
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
This article explains in simple steps how to renew expiring Exchange Server Internal Transport Certificate.
The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager
This video demonstrates how to sync Microsoft Exchange Public Folders with smartphones using CodeTwo Exchange Sync and Exchange ActiveSync. To learn more about CodeTwo Exchange Sync and download the free trial, go to: http://www.codetwo.com/excha…

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now