give admins rights to mailboxes whose accounts are in a specific OU
Hello, I have a need to give some limited mail admin capabilities to some of our IT staff. Basically, I want them to be able to do things like modify mailbox permissions, change email addresses, and set forwarding settings, but only for users in the OU that they are designated to manage. can some one point me towards a list of AD attributes or other permissions settings that would relate to exchange mailboxes so I can build a policy that will suit my organizations needs? thanks Christiaan
September 28th, 2009 10:25pm
HI,Per my knowledge Forwarding settings, change email address actually are saved in user ad objects. You can give permissions to change attribute for the users. Use ADSIedit.msc to delegate permissions.Hope this helpsregards
Chinthaka Shameera | MCITP: EA | MCSE: M |
http://howtoexchange.wordpress.com/
Free Windows Admin Tool Kit Click here and download it now
September 29th, 2009 5:01am
It is nicelydocumented in couple of TechNet articles to split the permissions as per your own organizational permission model...
Planning and Implementing a Split Permissions Model
http://technet.microsoft.com/en-us/library/bb232100.aspx
Split Permissions Model Reference
http://technet.microsoft.com/en-us/library/bb430782.aspxAmit Tank | MVP Exchange Server | MCITP: EMA | MCSA: M | http://ExchangeShare.WordPress.com
September 29th, 2009 6:14am
One thing to keep in mind that the new permissions model in Exchange 2010 called Role Based Access Control (RBAC) allows you to define OU scopes within its own permissions model so you don't have to do what is listed in that article. <3 RBAC!MVP | MCITP: Enterprise Messaging Administrator | MCTS: OCS + Voice Specialization | http://www.shudnow.net
Free Windows Admin Tool Kit Click here and download it now
September 29th, 2009 6:53am
One thing to keep in mind that the new permissions model in Exchange 2010 called Role Based Access Control (RBAC) allows you to define OU scopes within its own permissions model so you don't have to do what is listed in that article. <3 RBAC!
MVP | MCITP: Enterprise Messaging Administrator | MCTS: OCS + Voice Specialization | http://www.shudnow.net
Absolutely agree!Amit Tank | MVP Exchange Server | MCITP: EMA | MCSA: M | http://ExchangeShare.WordPress.com
September 29th, 2009 7:22am
Here is one nice article by Bharat Suneja. I guess this will suits your reqs http://exchangepedia.com/blog/2008/02/how-to-delegate-recipient.html Vinod
|CCNA|MCSE 2003 +Messaging|MCTS|ITIL V3|
Free Windows Admin Tool Kit Click here and download it now
September 29th, 2009 1:55pm