Re: Local Admin on Domain Controller?

From: Ben Winzenz [Exchange MVP] (ben_winzenz_at_NOSPAMdotmessageonedotcom)
Date: 03/22/05

  • Next message: toby one: "System volume information"
    Date: Tue, 22 Mar 2005 15:41:08 -0600
    
    

    Be careful - you are confusing separate sets of permissions.

    Delegating Full Exchange Admin control to *any* account regardless of
    whether it is a domain admin will force an inherited deny to log on to all
    mailboxes. You need to make sure that you are separating the permissions.
    Delegating control implies (or should) administrative control (i.e. make
    changes to mailbox settings, add connectors, etc. etc.). However, starting
    with Exchange 2000, it no longer implies full access to all mailboxes.

    If you want the domain admin to have full access to all mailboxes, then you
    need to also grant it Send As/Receive As permissions on the Mailbox Store.
    This equates to Full Mailbox Access. In order to do this, you will have to
    either modify the inherited deny to force an explicit allow on the mailbox
    store, or you will have to remove the inherited deny (often inherited from
    the Organization).

    -- 
    Ben Winzenz
    Exchange MVP
    "you know who maybe" <nguser2u@spamnotAOL.com> wrote in message 
    news:113ujiktnaf8q48@news.supernews.com...
    > thanks, but he is a Domain Admin. I know that's how it's supposed to work, 
    > but Exchange doesn't care: it wants a local admin.
    >
    > So far this is the only drawback I've found to running Exchange on a 
    > domain controller: Delegate Control will add the user as a Full Exchange 
    > Admin but it just doesn't work. The account cannot access any mailbox with 
    > full access, as he can on an exchange server that is not a DC.
    >
    >
    > "PD" <nomail@mail.com> wrote in message 
    > news:CRH%d.42913$hs5.3576979@phobos.telenet-ops.be...
    >>A domain controller doesn't have any local users.
    >> If you make your user a member of the domain admins group, then he should 
    >> have all the necessary permissions...
    >>
    >> "you know who maybe" <nguser2u@spamnotAOL.com> wrote in message 
    >> news:113uhpbtbs4hnb0@news.supernews.com...
    >>> I've fighting a number of issues related to permissions which require 
    >>> the user to be a member of the local admin group on the exchange server, 
    >>> but in this case the exchange server is a domain controller.
    >>>
    >>> Any ideas on what to do here?
    >>>
    >>> Thanks!
    >>>
    >>>
    >>
    >>
    >
    > 
    

  • Next message: toby one: "System volume information"

    Relevant Pages

    • Re: Error code 80070005 at "GetMailboxTable" call...
      ... It should work with exchange view only admin. ... from this link what I felt is Exchnage View only permissions should be ... enough to connect to stores. ... domain admin privileges) and Exchange server name. ...
      (microsoft.public.exchange.applications)
    • Re: Correctly setting Permissions on exchange mailbox rights
      ... The critical issue is Everyone Full Control. ... is being inherited from by using Exchange System Manager. ... reevaluate what permissions your Domain and Enterprise Admins have. ... associated external account) ...
      (microsoft.public.exchange.admin)
    • RE: Domain admin mailbox rights on Exchange 2003
      ... "Exchange Admins" are denied permissions by default, ... Domain admin mailbox rights on Exchange 2003 ...
      (Focus-Microsoft)
    • RE: Recommended Permissions for Application Folder / share
      ... normally we can configure NTFS permissions and the Sharing ... Domain Admin: Full Control ... SBS Folder Operators: Full Control ... Domain Admin Full Control ...
      (microsoft.public.windows.server.sbs)
    • Exmerge errors
      ... Trying to get a backup of mailboxes on Exchange 2003. ... is or I wouldn't get email) and you have correct permissions to log on. ... Exchange Admin, Domain Admin and Admin ... I did download the Exmerge for Exchange 2003. ...
      (microsoft.public.exchange.admin)