Link to home
Start Free TrialLog in
Avatar of David McMorris
David McMorrisFlag for United Kingdom of Great Britain and Northern Ireland

asked on

Exchange Management Scope and Role Issue

Hi,


I have a user who needs to be a admin delegate for a number of shared mailboxes.

I have created a management scope using the following command - 


New-ManagementScope "FCR_CC_MGMT" -RecipientRestrictionFilter {Customattribute1 -Eq "FCR_ACCESS"}


I have given the custom attribute FCR_ACCESS to the required shared mailboxes this user needs to administrate.


I have then created an admin role within Exchange Online and then changed the write scope to FCR_CC_MGMT. I have also added the user as a member and set the role to only Mail Recipients.


I have then given the user Exchange Administrator access role in Office 365. When the user logs into Exchange Online console. They are able to modify other mailboxes outside of the write scope? Is there something i am doing wrong? I have checked and the user doesn't have any other roles within Office 365 apart from Exchange admin. 


Thanks,


Avatar of Vasil Michev (MVP)
Vasil Michev (MVP)
Flag of Bulgaria image

Why are you granting the Exchange Administrator role? This is an unscoped assignment, thus will apply to all mailboxes, so what you're seeing is by design.
If you absolutely need to grant Exchange admin role, creating an exclusive management scope should work instead: https://docs.microsoft.com/en-us/exchange/understanding-exclusive-scopes-exchange-2013-help
Avatar of David McMorris

ASKER

Hi Vasil,

I see now, so i need to use the Exclusive switch on the management scope command?

Then the user can only modify the intended mailboxes.

This is for power users who regularly need to make changes to delegation access to departmental shared mailboxes. They were previously trying to do it via OWA which wasn't working. I will try what you have suggested. thanks 
You can simply not assign the Exchange admin role. If you create a role assignment for the Mail recipients role, scoped to the filter you already created, the user will not be able to modify any other mailbox.
So the user doesn't need the exchange admin role to access the Exchange management console?
ASKER CERTIFIED SOLUTION
Avatar of Vasil Michev (MVP)
Vasil Michev (MVP)
Flag of Bulgaria image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial