How to remove DeleteItem permission on exchange mailbox

Hi Experts, I've run an exchange powershell command to give me a listing of AccessRights for mailboxes on an Exchange 2010 server.

There are 2 users who have a listing for DeleteItem acccess from AD users who are disabled and who no longer have email boxes.

How can I remove those accesses, either through the command console or exchange powershell?

This is the powershell command I ran from this site

Get-Mailbox | Get-MailboxPermission | where {$_.user.tostring() -ne "NT AUTHORITY\SELF" -and $_.IsInherited -eq $false} | Select Identity,User,@{Name='Access Rights';Expression={[string]::join(', ', $_.AccessRights)}} | Export-Csv -NoTypeInformation mailboxpermissions.cs
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Henrik JohanssonSystems engineerCommented:
The following should work to loop through the result and remove the permissions. Remove -WhatIf parameter to execute it instead of emulate what should happen.

Get-Mailbox | Get-MailboxPermission | where {$_.user.tostring() -ne "NT AUTHORITY\SELF" -and $_.IsInherited -eq $false} | % {$Id=$_.Identity; $u=$_.User; $p=$_.AccessRights; Remove-MailboxPermission $Id -User $User -AccessRights $p -WhatIf }

Open in new window

ChiITAuthor Commented:
Hi Henrik, where do I put the users account ID and also how does it know to only delete the DeleteItem permission?
Henrik JohanssonSystems engineerCommented:
You specify the criteria In the where-clause between { ... }.

If you want to revoke all DeleteItem delegations from the mailboxes:
{ $_.isinherited -eq $False  -And $_.AccessRights -eq 'DeleteItem'

Open in new window

If you want to revoke the delegation for a single user with the delegated access right fomr the mailboxes.
{$_.isInherited -eq $False -And $_.User -eq 'USER TO REVOKE' -And $_.AccessRights -eq 'DeleteItem'}

Open in new window

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today

From novice to tech pro — start learning today.