Granting Read Access to Target Active Directory Domain
Granting Read Access to Active Directory Domain
To grant this permission to an account, complete the following steps:
- In the Active Directory Users and Computers snap-in, right-click the domain name, and then click Properties.
- On the Security tab, click Add and select the account.
- Select the account, and then check the Allow box for the Read permission in the Permissions box.
- Click the Advanced button. In the Advanced Security Settings dialog box, select the account you specified on step 2, and click Edit.
- In the Permission Entry dialog box, select This object and all descendant (child) objects from the Apply to drop-down list.
- Close the dialog boxes by clicking OK.
Granting Read Permission for Microsoft Exchange Container
To grant this permission to an account, complete the following steps:
- From the Start menu, select Run. In the Run dialog box, type ADSIEdit.msc. Click OK.
-
In the ADSIEdit snap-in, open the CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=<…>,DC=<…> container.
- Right-click the Microsoft Exchange container and select Properties.
- In the Properties dialog box, click the Security tab.
- On the Security tab, click Add and select the account to which you wish to assign permissions.
- Select the account name, and then enable the Allow option for the Read permission in the Permissions box.
- Click the Advanced button. In the Advanced Security Settings dialog box, select the account you specified on step 5 and click Edit.
- In the Permission Entry dialog box, select This object and all child (descendant) objects from the Apply onto drop-down list.
-
Close the dialog boxes by clicking OK.
Granting Move Mailboxes Management Role
To grant the Move Mailboxes management role to the <User> (in our example, LA\JohnSmith), run the following cmdlet in Exchange Management Shell:
New-ManagementRoleAssignment -Role "Move Mailboxes" -User LA\JohnSmith
Granting Mail Recipients Management Role
To grant the Mail Recipients management role to the <User> (in our example, LA\JohnSmith), run the following cmdlet in Exchange Management Shell:
New-ManagementRoleAssignment -Role "Mail Recipients" -User LA\JohnSmith