Ureader.com  
Microsoft software help and Community
   home   |   control panel login   |   archive   |  
 
Exchange
2000.active.directory
2000.admin
2000.announcements
2000.app.conversion
2000.applications
2000.clients
2000.clustering
2000.connectivity
2000.development
2000.documentation
2000.general
2000.information.store
2000.interop
2000.kms
2000.misc
2000.protocols
2000.realtime.collabo.
2000.setup
2000.transport
2000.win2000
admin
application.conversion
applications
clients
clustering
connectivity
design
development
misc
mobility
setup
tools
  
 
date: Mon, 7 Jul 2008 16:41:02 -0700,    group: microsoft.public.exchange.admin        back       


Delegate "Change Permissions" right for mailboxes via ADSIEDIT   
We have a very locked down environment - any permission which is delegated is 
done using the minimum rights required. For example we never use the delegate 
control wizard when assigning rights to change passwords / unlock accounts 
etc in AD. We use individual groups called "change password" and "unlock 
accounts" and permission these groups with the exact right required.

We need to allow an AD security group the ability to change the permissions 
on all users mailboxes. If we open a users account in AD and open the 
mailbox, we can add this group here and assign the "change permissions" 
right. However we need to do this across the organization. So in adsiedit, at 
this location:

configuration->services->company->administrative groups->exchange 
administrative group -> servers

We have permissioned the cluster nodes with a security group assigning the 
"change permissions" right. lets call this group "Modify exchange 2007 
mailbox permissions"

We can see this permission propogate to all users mailboxes, so when opening 
any mailbox we can see "Modify exchange 2007 mailbox permissions" group with 
the "change permissions" right (inherited). 

However any member of "Modify exchange 2007 mailbox permissions" cannot 
change mailbox permissions, we get an access is denied error. 

If I roll back this change via adsiedit, and then open an individual mailbox 
(as an exchange admin) and add in the group "Modify exchange 2007 mailbox 
permissions" with the "change permissions" right, any member of "Modify 
exchange 2007 mailbox permissions" can now change permissions!

so when its permissioned directly it will work, but when its inherited it 
doesnt. 

Any ideas?
date: Mon, 7 Jul 2008 16:41:02 -0700   author:   DJH

Google
 
Web ureader.com


    COPYRIGHT 2007, YARDI TECHNOLOGY LIMITED, ALL RIGHT RESERVE  |   contact us