{"id":238,"date":"2010-10-24T22:44:31","date_gmt":"2010-10-24T20:44:31","guid":{"rendered":"http:\/\/marwin.e-blog.cz\/?p=238"},"modified":"2011-05-18T12:54:26","modified_gmt":"2011-05-18T10:54:26","slug":"exchange-2007-storage-group-permissions-for-regional-admins","status":"publish","type":"post","link":"https:\/\/svobodma.cz\/?p=238","title":{"rendered":"Exchange 2007 &#8211; How set permissions for Regional Admins (create, delete mailbox, distribution group.). Manage only their regional storage groups"},"content":{"rendered":"<p>When you need add permissions to regional admin , who will be able to create and delete mailboxes , distrubution groups&#8230; only for their Regional Storage Groups ( mailbox databases ) you can use powershell or you can do that over ADSIEDIT tool.Do that over powershell  is not too easy for starter with EMS. I used ADSIEDIT tool and now I will show you what you will need to add appropriate permissions for regional admin.<\/p>\n<p>Over ADSIEDIT \ud83d\ude42 jup<\/p>\n<p>this is path in ADSIEDIT in my Domain.<\/p>\n<p>so start &#8222;run.exe&#8220; and writte adsiedit.msc , enter  :)( it is include in standard tools from install cd Server 2003,  Server 2008 include system  )<\/p>\n<p><em><strong>choose <\/strong><\/em><\/p>\n<p><strong><em>configuration\/cn=services\/cn=microsoft exchange\/cn=&#8220;name of your exchange org.&#8220; \/cn=Administration groups\/cn=exchange administration group(FYDIBOHF23SPDLT)\/cn=servers\/cn=&#8220;name of your exch. server&#8220;\/cn=information store\/&#8220;names of your storage groups&#8220;<\/em><\/strong><\/p>\n<p>for example , In my organization I have Storage groups <strong>SGRegionPR, SGRegionBR , SGRegionOS ,<\/strong><\/p>\n<ul>\n<li>I will add <strong><span style=\"text-decoration: underline;\">Full permissions( it will be depend on your choose )<\/span><\/strong> for security group  &#8222;<em><strong>exadminbr<\/strong><\/em>&#8220;  which will be manage Exchange in Region-BR on Storage Group  &#8222;<strong>SGRegionBR<\/strong>&#8220; <em>Enough will be &#8211; &#8222;<\/em><strong><em>access  recipient  update services&#8220; , &#8222;administer information store&#8220;,&#8220;read&#8220;, &#8222;list content&#8220; <span style=\"font-weight: normal;\">to be able to  create , delete mailbox<\/span>. (not move)<\/em><\/strong><\/li>\n<li>I adjusted  <strong>deny all permission<\/strong> for &#8222;<strong><em>exadminbr<\/em><\/strong>&#8220; group on other Storage Groups because I do not want to regional admin from BR  will be able to see other Storage groups and their details.<\/li>\n<\/ul>\n<ul>\n<li>I adjusted  permission &#8222;<strong>administer information store<\/strong>&#8220; for &#8222;<strong><em>exadminbr<\/em><\/strong>&#8220; group on <strong>cn=exchange administration group(FYDIBOHF23SPDLT)<span style=\"color: #99ccff;\"> do you know what does it mean ?<\/span><\/strong><strong><span style=\"color: #99ccff;\"> :)- -E <\/span><span style=\"font-weight: normal;\"><span style=\"color: #99ccff;\">f<\/span><\/span><span style=\"color: #99ccff;\">, X<\/span><\/strong><span style=\"color: #99ccff;\">-y<\/span><strong><span style=\"color: #99ccff;\"> ,C<\/span><\/strong><span style=\"color: #99ccff;\">-d<\/span><strong><span style=\"color: #99ccff;\"> ,H<\/span><\/strong><span style=\"color: #99ccff;\">-i<\/span><strong><span style=\"color: #99ccff;\"> , A<\/span><\/strong><span style=\"color: #99ccff;\">-b<\/span><strong><span style=\"color: #99ccff;\"> , N<\/span><\/strong><span style=\"color: #99ccff;\">-o<\/span><strong><span style=\"color: #99ccff;\"> ,G<\/span><\/strong><span style=\"color: #99ccff;\">-h<\/span><strong><span style=\"color: #99ccff;\"> , E<\/span><\/strong><span style=\"color: #99ccff;\">-f<\/span><strong><span style=\"color: #99ccff;\"> ,12, R<\/span><\/strong><span style=\"color: #99ccff;\">-s<\/span><strong><span style=\"color: #99ccff;\">,O<\/span><\/strong><span style=\"color: #99ccff;\">-p<\/span><strong><span style=\"color: #99ccff;\"> ,C<\/span><\/strong><span style=\"color: #99ccff;\">-d<\/span><strong><span style=\"color: #99ccff;\"> , K<\/span><\/strong><span style=\"color: #99ccff;\">-l<\/span><strong><span style=\"color: #99ccff;\"> , S<\/span><\/strong><span style=\"color: #99ccff;\">-t =<\/span><strong><span style=\"color: #99ccff;\"> EXCHANGE12ROCKS \ud83d\ude42 funny<\/span><\/strong><\/li>\n<\/ul>\n<p>You do not have to delegate this permissions on child objects ! In security tab do not use <span style=\"text-decoration: underline;\">advance button<\/span>, but only add group &#8222;<strong><em>exadminbr&#8220; <\/em><\/strong>and mark <strong>&#8222;administer information store&#8220;<\/strong><strong> <\/strong>permission.<\/p>\n<ul>\n<li>I adjusted permission &#8220; <strong>access  recipient  update services<\/strong>&#8220; for &#8222;<strong><em>exadminbr&#8220; <span style=\"font-style: normal;\"><span style=\"font-weight: normal;\">group<\/span><\/span><\/em><\/strong> on <strong>cn=exchange administration group(FYDIBOHF23SPDLT)<\/strong> or you can add perm. on <strong>cn=servers<\/strong> , use advance button in security tab for add permission and delegate permissions on child objects<\/li>\n<\/ul>\n<ul>\n<li>I adjusted  permission  &#8222;<strong>list content<\/strong> &#8220; for &#8222;<strong><em>exadminbr&#8220; <\/em><\/strong>on <strong>cn=&#8220;name of your exchange org&#8220; <\/strong>, use advance button in security tab for add permission and delegate permission on child objects<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>When you need add permissions to regional admin , who will be able to create and delete mailboxes , distrubution groups&#8230; only for their Regional Storage Groups ( mailbox databases ) you can use powershell or you can do that &hellip; <a href=\"https:\/\/svobodma.cz\/?p=238\">Cel\u00fd p\u0159\u00edsp\u011bvek <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[],"class_list":["post-238","post","type-post","status-publish","format-standard","hentry","category-exchange-server"],"_links":{"self":[{"href":"https:\/\/svobodma.cz\/index.php?rest_route=\/wp\/v2\/posts\/238","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/svobodma.cz\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/svobodma.cz\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/svobodma.cz\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/svobodma.cz\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=238"}],"version-history":[{"count":33,"href":"https:\/\/svobodma.cz\/index.php?rest_route=\/wp\/v2\/posts\/238\/revisions"}],"predecessor-version":[{"id":246,"href":"https:\/\/svobodma.cz\/index.php?rest_route=\/wp\/v2\/posts\/238\/revisions\/246"}],"wp:attachment":[{"href":"https:\/\/svobodma.cz\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=238"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/svobodma.cz\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=238"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/svobodma.cz\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=238"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}