Re: public folder permissions: 5.5 vs. 2003



Believe me - I would love to go to native mode - but cannot when we still
have 8 other sites to migrate before we can complete and go to native mode.
Its taken years to get to this point, and the decision is out of my hands.
Corporate beauracracy and all.

For just about each DL list we do have a Security group. In my example of
"secretaries" we do have both the DL list and the security group.

I tried going into AD and adding the group by doing the CRTL while accessing
client permissions in exchange system manager. But this did not take effect
and once that is done, you cannot go back to the normal MAPI permissions.

How do you apply the client access to security groups and still utilize the
MAPI permissions?


"Bharat Suneja" <bharatsuneja@xxxxxxxxxxx> wrote in message
news:%23DiNk2kvFHA.3400@xxxxxxxxxxxxxxxxxxxxxxx
> In Exchange 2000/2003, you cannot assign PF permissions to Distribution
> Groups because these are not Security Principals.
>
> - If you want, you can convert the Distribution Groups to Security Groups
> and assign permissions to those.
> - Or you can create separate Security Groups and make users members, then
> assign permissions to the new security groups.
> - One reason it's good to have native mode AD domain - during migration
DLs
> can be converted to Universal Security Groups, which can't be done in
mixed
> mode.
> --
> Bharat Suneja
> MCSE, MCT
> --------------------------------
>
> "grlgeek" <no@xxxxxxxxx> wrote in message
> news:dLGdnYwXOuEuK63eRVn-iw@xxxxxxxxxxxxxx
> > In Exchange 5.5 you can grant client access permissions to a public
folder
> > by distribution lists.
> >
> > Example:
> > In Exchange 5.5: Secretaries is a position that has a high turnover
rate.
> > A distribution list called "secretaries" is created and the employees
are
> > added and removed to the DL as they come and go in their employment. A
> > public folder is created to store the forms and templates the
secretaries
> > use, and the client access permissions on that folder is set to the
> > distribution list "Secretaries" as reviewers so they can have access to
> > the
> > folder and its contents. This format is more administratively
friendly,
> > as
> > the exchange admin only has to add the user account to the secretaries
DL
> > and the permissions take effect.
> >
> > In Exchange 2003: We migrate the public folders from 5.5 to 2003. But
> > because this is a 10 site organization and only 2 of the sites have
> > migrated. Under 2003 it seems that the client access permissions that
> > are
> > set based on DL no longer apply and we have to set it on the individual.
> >
> > This means when a new secretary is added the account gets created, user
is
> > added to the Secretaries DL list for the email group, and then added to
> > every Public Folder they need access to. (and whatever security groups
> > for
> > AD they get as well, which usually there is a corresponding security
> > group.)
> >
> > There has to be an easier way! But we have to work in the mixed mode
> > environment for quite a while as there are still 8 other sites in the
> > organization/domain that still need to migrate.
> >
> > Any advice would be appreciated.
> >
> >
>
>


.



Relevant Pages

  • Re: Cant delegate/share to a group - Addendum
    ... > Computers tree includes users and security groups, ... > Distribution Group shows the Security Group type grayed out with no way to ... > events occurred when I tried to delegate to distribution groups before I ... > switched to native mode and still occur after the switch when I try to use ...
    (microsoft.public.exchange2000.general)
  • Re: Cant delegate/share to a group - Addendum
    ... > Computers tree includes users and security groups, ... > Distribution Group shows the Security Group type grayed out with no way to ... > events occurred when I tried to delegate to distribution groups before I ... > switched to native mode and still occur after the switch when I try to use ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: restrict delegated admins to create computer accounts in AD
    ... The way to do this is to create security groups and give ... appropriate local groups will be able to prestage computer accounts in their ... -- Create Computer Objects ... To access these permissions, use the advanced DACL editor on the OU you wish ...
    (microsoft.public.windows.server.active_directory)
  • Re: AD distribution and security group usage
    ... What do you mean by assign permissions to DL's in Exchange? ... is the admin staff have set security groups, mainly for file access, and have ... Know the last time that distribution groups were being used/are being ...
    (microsoft.public.win2000.active_directory)
  • Re: Public Folder Permission
    ... You can only use Microsoft Windows 2000 Universal Security Groups ... (UDGs) ... to a client permission, ... can't switch AD to native mode yet, quick resolution is to populate PF ...
    (microsoft.public.exchange.admin)