Re: Can user storage limit settings be applied over an Exch system



Ed:
I think you are going to need to deny this at the OU level. You could
disable it user-by-user, but that would be time consuming. I don't have
ADUC right here in front of me, so I don't remember the exact procedures,
but you need to deny permissions to specific attributes. Be careful about
denying permissions, though, because you could deny yourself permissions to
Write to those attributes, too.

Here are the attribute names:
mDBOverHardQuotaLimit

mDBOverQuotaLimit

mDBStorageQuota




--
Jim McBee
- MostlyExchange Blog: http://mostlyexchange.blogspot.com
- Exchange FAQ: http://www.swinc.com/resources/exchange/




"ed@lehigh" <ed@xxxxxxxxxx> wrote in message
news:CC5A54DA-918A-4E45-BE20-757BDB2D1455@xxxxxxxxxxxxxxxx
> Hi Jim,
>
> Thanks for the quick response. I took a look at the advanced security
> settings (effective permissions) to locate the setting to disable write
> for
> "deleted item retention" - use mailbox store defaults with no luck. Also
> to
> disable the mailbox size change from occurring.
>
> Can you help with the specific permission name and location to set this
> (if
> different)?
>
> We don't want to allow local IT to override a company standard on deleted
> items retention and mailbox sizes.
>
> Thanks in advance,
>
> Ed
>
>
> "Jim McBee (MVP)" wrote:
>
>> Ed:
>> Yes, individual settings on a user account will override the Exchange
>> System policies. It might be an hour or so before you notice the changes
>> take effect due to caching and replication, though. The only
>> permissions
>> you need to set this is the permissions to manage the user account. No
>> Exchange permissions are necessary. However, you could set custom
>> permissions on the user account objects so that your OU admins cannot
>> change
>> a user's limits.
>>
>> --
>> Jim McBee
>> - MostlyExchange Blog: http://mostlyexchange.blogspot.com
>> - Exchange FAQ: http://www.swinc.com/resources/exchange/
>>
>> "ed@lehigh" <ed@xxxxxxxxxx> wrote in message
>> news:0F058D3C-7BB1-40DE-9CC0-F32128D4927E@xxxxxxxxxxxxxxxx
>> > In ADUC with the Exchange extensions, under the Exchange general tab,
>> > you
>> > can
>> > override the mailbox store defaults for individual users. It accepts
>> > the
>> > change.
>> >
>> > However, does this really get applied since the system policy (based on
>> > storage group) defines these settings?
>> >
>> > Is this dependent on permissions at all? Example - If the account
>> > making
>> > the changes in ADUC is a full exchange admin at the admin group level,
>> > does
>> > it then override the system policy? Whereas if the account does not
>> > have
>> > the
>> > above, the screen shows the change, but it is not in effect?
>> >
>> > I am looking at 2 scenarios:
>> >
>> > - changing the max mailbox size
>> > - changing the deleted items retention setting.
>> >
>> > Finally - if it is a bug (shows the changes are applied but are not),
>> > is
>> > there a fix to the MMC interface?
>> >
>> > Thanks in advance for your help.
>> >
>> > Ed
>>
>>
>>


.



Relevant Pages

  • RE: Exmerge errors
    ... To do this open regedit on the system you are administering Exchange ... A Deny does overrule an allow IF they are both inherited. ... An explicite allow at the store level will over-ride the inherited Deny. ... I cannot see where or how to override these permissions. ...
    (microsoft.public.exchange.admin)
  • Re: Messed up Administrator permissions
    ... Actually Exchange does an explicit Deny to all members of Domain Admins. ... Create a different account for doing ExMerge and grant it permissions on the ... server or on the mailbox store object. ...
    (microsoft.public.exchange.admin)
  • Re: Can user storage limit settings be applied over an Exch system pol
    ... individual settings on a user account will override the Exchange ... you need to set this is the permissions to manage the user account. ...
    (microsoft.public.exchange2000.admin)
  • RE: Delegate Exchange Permission
    ... I actualy gave the Helpdesk staff create & manage user account on certain ... on Exchange side I gave him exchange view-only and the following custom ... Generic Read access right (includes Read Permissions, List Contents, List ...
    (microsoft.public.exchange.admin)
  • Re: Send As permissions set on all users, need to remove!
    ... I have also installed MS06-029 security fix, twice, and the build still ... As far as where I checked the permissions: AD in the default users OU ... Exchange Server with deny send as permissions, I then added all of the ...
    (microsoft.public.exchange.admin)