Solved

Make "Username" "owner" of all groups in Exchange Admin Center for Exchange 2013?

Posted on 2016-09-29
10
58 Views
Last Modified: 2016-10-03
We have a large number of groups, both distribution and security, we'd like to make a certain admin account the owner of all the groups so that any and all changes can be made without error.  Is there a way to do this at once in EAC?
0
Comment
Question by:Daniel Checksum
  • 5
  • 5
10 Comments
 
LVL 15

Assisted Solution

by:Todd Nelson
Todd Nelson earned 500 total points
ID: 41822647
Owner?  There is no "owner" assigned to groups in Exchange.

As long as the "certain admin account" is a member of Organization Management they are able to make changes to all groups.
0
 
LVL 1

Author Comment

by:Daniel Checksum
ID: 41822651
OK, I guess I should go ahead and clarify here.  Logging in to EAC as "Administrator" (THE domain administrator) and attempting to add a user, getting "You don't have sufficient permissions.  This operation can only be performed by a manager of the group." -- We were going to make Administrator the owner of every single group so if/when we log on as Administrator we're not given this error.

The current workaround is to add the user in the ADUC group AND THEN add in EAC.
0
 
LVL 15

Assisted Solution

by:Todd Nelson
Todd Nelson earned 500 total points
ID: 41822655
What AD groups is the "administrator" a member of?  The only one that matters for Exchange to be able to do most all things in Exchange is Organization Management.
0
Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 
LVL 1

Author Comment

by:Daniel Checksum
ID: 41822657
It's a member in quite a few groups, not to list them all, but, at least:  "Exchange Organization Administrators, Exchange Recipient Administrators, Exchange Servers, Exchange View-Only Administrators"
0
 
LVL 15

Assisted Solution

by:Todd Nelson
Todd Nelson earned 500 total points
ID: 41822662
I would recommend adding the administrator as a member of Organization Management.  Try it out, make sure AD replication completes, and then perform the same task.

Let me know.
0
 
LVL 1

Author Comment

by:Daniel Checksum
ID: 41822672
It's actually already there, showed up when I tried to add it with the error "this user is already a member..."

I actually just tried to add Administrator as the owner of the group and got the same exact error about not having permission.
0
 
LVL 15

Accepted Solution

by:
Todd Nelson earned 500 total points
ID: 41822685
Hmmm.  Okay.  This should do it...

Take an accounting of your current permissions.  This command will export a list of all distros and their existing managers to a CSV file...

Get-DistributionGroup | Select-Object Name,ManagedBy | Export-Csv C:\DistroManagers.csv -NoType

Open in new window


This command will set Administrator as the manager of an individual distro...

Set-DistributionGroup -Identity "GrouName" -ManagedBy "Administrator" -BypassSecurityGroupManagerCheck

Open in new window


This command will set Administrator as the manager of all distros...

Get-DistributionGroup | Set-DistributionGroup -ManagedBy "Administrator" -BypassSecurityGroupManagerCheck

Open in new window


Hope that helps.
0
 
LVL 1

Author Comment

by:Daniel Checksum
ID: 41826792
Update:  Just got back from the weekend and have a few more pressing projects now.  Will get back to you with results when I have more time.
0
 
LVL 1

Author Closing Comment

by:Daniel Checksum
ID: 41826867
Thanks, Todd.  Coworker applied the commands and all appears to be working.  Fantastic job, sir.
0
 
LVL 15

Expert Comment

by:Todd Nelson
ID: 41826873
You are most welcome.
0

Featured Post

Free Tool: Postgres Monitoring System

A PHP and Perl based system to collect and display usage statistics from PostgreSQL databases.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

MS Outlook is a world-class email client application that is mainly used for e-communication globally.  In this article, we will discuss the basic idea about MS Outlook, its advanced features, and types of MS Outlook File formats.
This script can help you clean up your user profile database by comparing profiles to Active Directory users in a particular OU, and removing the profiles that don't match.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…

829 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question