how to grant the following from our servers?

cmdolcet
cmdolcet used Ask the Experts™
on
I have a vendor that has asked the following from us:
An account with rights to access all mailbox in exchange? and access to the DNS for our company.

What would be the best way of giving this to them. Our domain controller and our exchange are on 2 different VM's.

Thanks in advance.
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Edward PamiasTeam Lead RRS Desk
Top Expert 2016

Commented:
If this is a trusted Vendor, get them VPN access with a keyfob(secure ID) to access your systems. The secure ID will require them to create a pin so not just anyone can access your network, if this is at all possible. If not I would wait for another expert to chime in.
Adam BrownSenior Systems Admin
Top Expert 2010

Commented:
Personally, I'd be asking why they need that level of access. What service is the vendor providing? Also, do they need to have this for stuff they have to do manually, or do they just need to have a service account with this level of access? We need a little more information to properly answer the question.
Tom CieslikIT Engineer
Distinguished Expert 2017

Commented:
If you trust him you can create another VM with Windows 7 / 8 / 10
Create user for hime and add this user to Domain admins group.

Enable Audit on domain to know all changes and give him RDP or VPN access to this VM station.

On VM station you can install Microsoft Remote Desktop Manager and configure access to both servers , Exchange and DC

I'm not understand why he need access to all mailboxes, you need to discuss this with your Boss, since some company information, specially his can be classified.
If your boss will be OK with this then you need to give this new user full success permission to all mailboxes in EAC or using power shell

You can do this by adding user to Organization Manager group

Add-RoleGroupMember "Organization Management" -Member "<account name>"

then

Get-Mailbox -ResultSize unlimited -Filter {(RecipientTypeDetails -eq 'UserMailbox') -and (Alias -ne 'Admin')} | Add-MailboxPermission -User admin@example.com -AccessRights fullaccess -InheritanceType all -AutoMapping:$false
Ensure you’re charging the right price for your IT

Do you wonder if your IT business is truly profitable or if you should raise your prices? Learn how to calculate your overhead burden using our free interactive tool and use it to determine the right price for your IT services. Start calculating Now!

Author

Commented:
We are trying to migrate out Exchange server 2010 mailbox, public folder and other things to Office 365 Pro. Currently we host our exchange and house all our mailboxes.

If that makes sense.
Tom CieslikIT Engineer
Distinguished Expert 2017

Commented:
So My advise is adequate

Author

Commented:
So Tom if I follow the above correctly....

I would first need to get a connection either an RDP or a VPN to each VM server ( We have a domain and an exchange). Second I would need to configure a user account with Domain admin rights?  In my logic correct?

Would I create the server in the active directory or use the wizards in the SERVER 2012 application?

Thanks,
Tom CieslikIT Engineer
Distinguished Expert 2017

Commented:
Would I create the server in the active directory or use the wizards in the SERVER 2012 application?

Regular new VM installation would be enough.
You can delete this workstation after all will be done if you don't going to need it.

After you setup new VM workstation with new account install Microsoft Remote Desktop Manager and add this servers you want to give him access to. Test connections.

https://www.microsoft.com/en-us/download/details.aspx?id=44989


You don;t need to create VPN if you don;t want to. Just enable (reroute) RDP on your firewall to this new virtual machine

Author

Commented:
OK so I noticed the VM servers I wanted to give the RDP access to is not created. How can I create an RDP for him to log in to both servers?

Thanks
Tom CieslikIT Engineer
Distinguished Expert 2017

Commented:
I have a filling you're not reading my comments.
I just explained you everything.
You can't give access to 2 machines in same time from outside because only one rule can be created on firewall.
You can change port for RDP to one server but it's a lot more complicated.

So best solution is give him RDP access to one of workstation in your domain then setup RDP using MRDM to servers he need. If you don;t have spare workstation you can install Virtual Workstation on your Virtual server and setup it for him. I did explained this in my previous posts.

Author

Commented:
OK how do I give him access?

How to I create an RDP IP outside address is there was never one created before?

I am just not following you.

Sorry!
Edward PamiasTeam Lead RRS Desk
Top Expert 2016

Commented:
Watch this video it helps you setup up what you want for a home PC but its the same principal.

http://www.appdataworks.com/allow-remote-desktop-connections-from-outside-your-network/
Tom CieslikIT Engineer
Distinguished Expert 2017

Commented:
You need to create rule on your company firewall to forward port 3389 to internal IP (workstation or VM)
It's very simple.

Author

Commented:
Tom,

This rule that I need to create...... We have a Soniwall firewall device TZ 215  to be exact. However I know our other VM have outside IP address created for them? Where does that get done?
Distinguished Expert 2018

Commented:
You can use the Public Server Wizard to open up a port (most user friendly way to go about it). The question is whether you want to open port 3389 or use a different port.

Author

Commented:
Where is the Public Server Wizard located? When you say open port 3389 what are the best practices should that port be open or should another port be open?

also when I have an outside line, should I just then go ahead and create a user in my active directly for him to use?
Tom CieslikIT Engineer
Distinguished Expert 2017

Commented:
Wizard is on the top of this screen after log on
Capture.JPG
Distinguished Expert 2018

Commented:
If you really wanted to know the best practice involving RDP, it would actually be to use the Remote Gateway and other services. But for how you actually have it set up, the most ideal things to do would be to have two factor authentication using a product like Duo or AuthLite.

Author

Commented:
OK sorry....
for the long delay. would I setup my RDP access through my Sonicwall firewall?
Tom CieslikIT Engineer
Distinguished Expert 2017

Commented:
No, wizard will help you open RDP ports and forward protocols to Host you want to give access to.
You can define host before wizard or do it as a part of wizard :)
Distinguished Expert 2018

Commented:
It's two pieces: The server has to be configured to allow RDP connections, and the Sonicwall has to be configured to forward the ports necessary for the RDP connection to the correct server(s).

Author

Commented:
OK, the server is already configured to let RDP through we type in an IP address to access certain PC. So do I need to configure another rule in the SonicWall to connect to another device?
Distinguished Expert 2018

Commented:
Correct. That's where the Public Server Wizard comes into play, to assist you with port forwarding and NAT rules.
Tom CieslikIT Engineer
Distinguished Expert 2017

Commented:
Like I said before, you can't configure multiple connection using same protocol and same port number to multiple devices.
If you want to connect to multiple devices from outside then you must configure VPN connection first then connect by local IP address.

Author

Commented:
OK... I was able to rout it through the Sonic walls Firewall and get access from the outside.

However If I wanted to create a specific user in my AD that would only be allow to remote into a static IP address how would I be able to configure this?
IT Engineer
Distinguished Expert 2017
Commented:
Navigate to your Active Directory Users and Computers
Go to section BuildIn
Open Remote Desktop Users group and add your new created username.

Capture.JPG
On machine you want to give access to you must go to  System Properties
Remote tab
Select Allow connections from computers running any version of Remote Desktop

Then click on Select Users button
Add
And select your Remote Desktop Users group.

Capture.JPG
All other users not going to be able to connect using RDP, only members of this group

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial