Re: Deny account admins rights to change mailbox permissions

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



I would be very surprised if View-Only Administrator role grants the right
to change permissions on mailboxes. I suspect that your administrators are
in a group that otherwise has rights to do this. You should review the
groups that they're in and see if any have rights on the mailbox store,
server, or administrtive group.

See this link:
http://www.microsoft.com/technet/prodtechnol/exchange/guides/E2k3ADPerm/07316e16-0daa-4604-91e5-b0cf4ed6ac6c.mspx?mfr=true
--
Ed Crowley
MVP - Exchange
"Protecting the world from PSTs and brick backups!"

"G" <gwaltman@xxxxxxx> wrote in message
news:1158704506.740164.107820@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
I need to give admins the rights to add and create Exchange accounts
using the ADUC tool, but I also need to deny them the rights to go in
and change the users mailbox permissions (User Properties\Exchange
Advanced\Mailbox Rights) and gain access to their email accounts.

I have already delegated accounts admins rights to the users OU giving
them some basic rights to create users accounts. When I delegate
Exchange View only admin rights, they are allowed to create mailboxes,
but it also allows them the rights to change the security settings for
the users mailbox (User Properties\Exchange Advanced\Mailbox Rights)
and allows them to add their ID's permissions to view and read the
users mailbox. I have tried to deny the rights to change permissions
at the OU level as well as the exchange level, but this does not help.
Any help would be greatly appreciated.

Thanks,
Gary Waltman
NCU



.



Relevant Pages

  • Re: Read only permission to a users mail box via Active Directory
    ... your recovery server and grant rights to the person who needs to peruse the ... Sometimes administrators need access to a users mailbox without ... If permissions are given via outlook the user can find ... In the past I gave the administrator Full mailbox ...
    (microsoft.public.exchange.admin)
  • Re: Exchange 2003 - Delegated Mailbox permissions admin
    ... What permissions do I need to be able to modify a user object's mailbox ... For an Exchange Administrator to properly modify a user or inetOrgPerson ... object's mailbox rights by means of the Mailbox Rights button on the ... Exchange Advanced tab of the Active Directory Users and Computers snap-in, ...
    (microsoft.public.exchange.admin)
  • Re: SEND AS Permissions - Exchange 2007 Serious Issue
    ... Look for places where the administrator or a group of administrators has been conferred rights, such as at the organization, administrative group, server, or mailbox store level and revoke the rights. ... I have a user GARY BROWN and his Mailbox Email ...
    (microsoft.public.exchange.admin)
  • RE: Which permission can open users mailbox?
    ... admin or administrator rights in your domain then grant that user full ... mailbox access rights using AD users and computers on a machine with the ... management console and on that particular mailbox you can grant full mailbox ... The domain admin part is the problem as there are security updates for e2k3 ...
    (microsoft.public.exchange.admin)
  • Re: msExchMailboxSecurityDescriptor and inherited rights
    ... account in order for things to work correctly. ... This guide is for Exchange 2003, and lists what rights are necessary to ... modify mailbox rights for an object. ... 'Change Permissions' right, and these rights are inherited throughout the ...
    (microsoft.public.exchange.development)