Resource Forest, Exchange 2007 and Public Folder Permissions
Hello everyone :-)Im having problems understanding how to give permissions to a Public Folder in a Resource Forest to a user in the User Forest. Its all simple and clear when it comes down to mailbox access and permissions but Im totally lost when it comes to PFs. Both PFDAVAdmin and EMS seems only willing to find users in my Resource Forest and not my User Forest.What makes me a bit afraid is that Ive in my hours with Google have found my problem asked in various forums but getting no reply.Clearly this must be something that is easily solved (if you know how ;-))Cheers / Jesper Bernle
September 30th, 2009 5:29pm

Hi Jesper,It would be nice if you could explain what type of permissions you are trying to give on the PF. This will vary per version of exchange too. I presume you are running Exchange 2003. If that is true you can go to properties of public folder in public folder tree and the Permissions Tab. Normally, You can use the Directry Rights button to assign permissions like Send As.To do this. I would recommend you going by groups because its easier way to manage the permissions and keep your ACEs tidy. You can ask the other side administrator (the other forest) to create a security group and add the users into it who need permissions on the PF and then add that security group to the Directory Rights of the PF. I hope that helps.Milind Naphade | MCTS:M | http://www.msexchangegeek.com
Free Windows Admin Tool Kit Click here and download it now
September 30th, 2009 7:30pm

Okay, my bad. I think I should read between the lines. I didnt notice the subject of this thread. You can still use the PF management console on your Exchange 2007 server or the PS with command Add-ADPermission "Marketing Department" -User "otherforest.com\Kim" -Extendedrights "Send As" see http://technet.microsoft.com/en-us/library/bb676518.aspxMilind Naphade | MCTS:M | http://www.msexchangegeek.com
September 30th, 2009 7:42pm

same way you can grant client permissions too Add-PublicFolderClientPermission -Identity "\Marketing\West Coast" -AccessRights PublishingEditor -User Contoso.com\Kim How to Add Permissions for Client Users to Access Public Folder Content Vinod |CCNA|MCSE 2003 +Messaging|MCTS|ITIL V3|
Free Windows Admin Tool Kit Click here and download it now
October 1st, 2009 4:43pm

Nope - It doesnt like when I try to specify my User Forest under the -User. This was the first thing I tried myself but no success.Cheers / Jesper Bernle
October 1st, 2009 5:20pm

what error message you get when to try to perform this task?Vinod |CCNA|MCSE 2003 +Messaging|MCTS|ITIL V3|
Free Windows Admin Tool Kit Click here and download it now
October 1st, 2009 5:23pm

"The specified public folder user "resourceforest.com\User" does not exist. A valid public folder user should be a mail-enabled user, mailbox or distribution group."Cheers / Jesper Bernle
October 1st, 2009 5:27pm

Does "USER" has a linked mailbox on the exchange 2007 server in the resource forest.????Vinod |CCNA|MCSE 2003 +Messaging|MCTS|ITIL V3|
Free Windows Admin Tool Kit Click here and download it now
October 1st, 2009 5:36pm

Yes he/she has.BTW - Thank you very much for wanting to help me out :-)Cheers / Jesper Bernle
October 2nd, 2009 9:16am

I was talking to an MS employee a few months ago about Outlook being able to access another Outlook folder or act as a delegate for another Outlook user in a different forest. The reply was the following and may help you out: "The magic sauce for Outlook and Exchange to allow a "cross-forest sync'ed mailbox-enabled contact" to access a folder or act as delegate includes: (a) legacyExchangeDN (b) msExchMasterAccountSid - after this Exchange is agnostic, but Outlook wants (c) msExchRecipientDisplayType to have bit 2 set, e.g. a value of -1073741818 works and finally (d) msExchRecipientTypeDetails set to 32768." MVP | MCSE:M | MCITP: Enterprise Messaging Administrator | MCTS: OCS + Voice Specialization | http://www.shudnow.net
Free Windows Admin Tool Kit Click here and download it now
October 3rd, 2009 4:15am

Yes - and it´s good news. I managed to get it solved by some good old AGLP (or rather AGDLP). ;-)Thank you all for your interest and efforts in this issue and for the curious people in the audience a more step-by-step instruction of the solution is on my blog.Cheers / Jesper Bernle
October 7th, 2009 11:40pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics