Re: have to add user to local admin group

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



I don't know the exact permissions you need but you are heading the right
direction by giving the user permissions to either the information store or
the database level. You do not need to give them send as/receive as
permissions because if you recall these are denied to domain admins and
enterprise admins but they can admin mailboxes.

Nue
"skip" <skip@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:FC76B74D-EFAC-437F-A06E-23D5EB149D82@xxxxxxxxxxxxxxxx
>I did delegate to the user "Exchange view only" and the user has full
>rights
> to the OU. The user can create user accounts in the OU and delete
> accounts,
> but the user cannot create user accounts or contacts in the OU that have
> an
> email address. The only way i got this to work was to add the user to the
> local admin group on the Exchange/DC/GC server. It seems that i need to
> grant
> this user elevated permissions in ESM to either the mailbox store or the
> server node. I really dont like giving more rights then are absoluelty
> necessary, and it looks like i may have to give the send as and recieve as
> rights to this user.
>
> "Nuevo" wrote:
>
>> I don't believe you are correct. In order to fully Administer an Exchange
>> server you do need to be a local admin but for your purpose you need only
>> make then a View Only Administrator and then grant any additional
>> Exchange
>> rights explicitly.
>>
>> Nue
>> "skip" <skip@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
>> news:C2B4A018-C470-44AE-9D4B-135A14D498C5@xxxxxxxxxxxxxxxx
>> > Hi all
>> >
>> > I am running Exchange 2003 sp2 on windows 2003 sp1. Everything is
>> > isntalled
>> > on one server, AD and Exchange are on a single server. I am faced with
>> > a
>> > troubling problem. I need to give rights to a user so they can add
>> > email
>> > enabled contacts into an OU. I have given the use the delegated perms
>> > to
>> > do
>> > this, and they can add user to this OU no problem. I have also
>> > installed
>> > the
>> > Exchange admin tools and 2003 admins tools on the users machine. In
>> > order
>> > for
>> > the user to create contacts with an email address in the OU, I have to
>> > add
>> > this user to the local administrator group on the Exchange/DC server,
>> > and
>> > i
>> > really really dont want to do this. What alternatives do i have with
>> > this?
>> >
>> > Many thanks for a possible solution
>>
>>
>>


.



Relevant Pages

  • RE: How to query exchange on sbs2003 for outlook delegates
    ... Exchange 2003 Server to get the Outlook delegates list in SBS 2003 network. ... Check both "Check permissions on default folders" and "Extract ... Microsoft is providing this information as a convenience to you. ...
    (microsoft.public.windows.server.sbs)
  • Re: Unable to add mailbox
    ... This is a regular exchange 2003 install, and no, I have not lately done a dr ... december, and another backup dc in Feb (which was the old mail server, but I ... Authenticated User has Read and Special Permissions, the under advanced, the ... make sure that box is checked on the user's account as well. ...
    (microsoft.public.exchange.admin)
  • Re: Forestprep wont run
    ... Im assuming you meant subnet in Sites and Services. ... Its still saying i have to be an Exchange Full Administrator. ... Exchange server, and is it a global catalog server? ... Admin member even though exchange dont exist but in schema now:( ...
    (microsoft.public.exchange.setup)
  • Re: Exchange Server Security
    ... Permissions will inherit to the server object from level above my server ... Exchange server, All servers in the Admin Group, or All servers in the ORG. ... when I look at the security tab ...
    (microsoft.public.exchange2000.general)
  • RE: NTFS Folder Permissions
    ... | Can anyone tell me what permissions I need to set on the Exchsvrv ... | and my EDB and LOG directories in order for exchange 2003 to operate? ... | Operators", but when I browse to the Exchsvrv ... | I get a "Server Operators is not recognised" message. ...
    (microsoft.public.exchange.admin)