Active Directory credentials prerequisites
The credentials that are used to collect Active Directory data must have the following permissions:
- Read permissions on all the Active Directory user, group and contact objects
Note: Specifying the Active Directory collection credentials is optional if the Data Engine service credentials that you specified during installation have read permissions on the Active Directory user objects.
Prerequisites to collect Exchange Configuration and Mailbox Content
Any credentials that are used to collect Exchange configuration, mailbox properties and mailbox content through PowerShell and Active Directory must be a member of the View-Only Organization Management role group and Public Folder Management Group or the Organization Management Group. If you wish to run the Mailbox Content Collection the account needs to have Application Impersonation Rights.
• How to set Exchange impersonation for Exchange 2013:
• How to set Exchange impersonation for Exchange 2010:a
• How to set Exchange impersonation for Exchange 2007:
• How to set impersonation for Office 365:
Prerequisites to collect Exchange Tracking Logs
For Exchange, the credentials that are used to collect message traffic and DLP incident data from the Exchange message tracking logs must have the following permissions:
• have access rights to the share that contains the Exchange message tracking logs
• be a member of the View-Only Organization Management security group and Public Folder Management or Organization Management.
You can gather Exchange message tracking logs from any of the following locations:
• Directly from tracking log folders on each Exchange server
• From user-created file shares on each Exchange server, such as \\ServerName\MessageTracking
• From any file share that contains up-to-date Exchange tracking log copies. Original log files and
compressed zip files are supported in the share.
Note: By default, the tracking log folder is located as follows:
• Exchange 2007
\\ServerName\c$\Program Files\Microsoft\Exchange Server\TransportRoles\Logs\MessageTracking
• Exchange 2010
\\ServerName\c$\Program Files\Microsoft\Exchange Server\V14\TransportRoles\Logs\MessageTracking
• Exchange 2013
\\ServerName\c$\Program Files\Microsoft\Exchange Server\V15\TransportRoles\Logs\MessageTracking
Permissions needed for Exchange Public Folders
When you configure an Exchange public folders data source, you can select whether you want to collect data
from legacy public folders (Exchange 2007, Exchange 2010) or new (Exchange 2013, Exchange 2016) public
folders.
For Exchange 2007, ensure that the Microsoft Exchange Server 2007 Management Tools are installed.
For Exchange 2010, Exchange 2013, or Exchange 2016 the credentials that you specify to collect public folder data using remote PowerShell must:
• Be a member of the Exchange View-Only Administrator role.
• Have remote PowerShell access enabled.
Permissions needed for Exchange IIS logs (ActiveSync)
When you configure an Exchange IIS logs data source, you specify two sets of credentials:
• credentials for the LDAP connection to Active Directory
• credentials for collecting the IIS log files from the Exchange CAS (Client Access Services)
Credentials to collect data through LDAP
The credentials that are used to collect device and user information through LDAP from Active Directory must
have the following Active Directory permissions:
• Read permission on User objects.
• Read permission on the msExchMailboxGuid property of all User objects
Usually, these read permissions are available to members of the Authenticated Users group. Consequently, you
only need to be an authenticated user of the domain or of another domain that is trusted by the domain.
Credentials to collect the IIS log files
The credentials that are used to collect information from the IIS log files on the Exchange Client Access Server
(CAS) must have the following permissions:
• Local Administrators rights on all Exchange CAS servers
The Local Administrators rights are required to access to the IIS logs through an administrative volume share,
such as C$.
As an alternative to providing Local Administrators rights, you could create a non-administrative share for the
IIS log folder. You could then grant read access to the credentials to the IIS log files through the share.
Permissions needed for Exchange Online hybrid mailbox configuration
The credentials that you specify to collect Exchange Online mailbox configuration data (including statistics,
permissions, and mobile devices) using remote PowerShell must:
• Be a member of the Exchange View-Only Organization Management role in the Exchange Online tenant.
• Have PowerShell access enabled.
To collect mailbox recipient “send as” permissions, the credentials must also:
• Be a member of the Recipient Management role group in the Exchange Online tenant.
The credentials that are used to collect Active Directory user data must have the following permissions:
• Read permissions on all the Active Directory user objects.
Office 365 Native
Permissions needed for Exchange Online (Office 365 Native) user configuration
The credentials that you specify to collect Exchange Online user configuration data using remote PowerShell
must:
• Be a member of the Exchange View-Only Organization Management role in the Exchange Online tenant.
• Have PowerShell access enabled.
Permissions needed for Exchange Online (Office 365 Native) mailbox content data
The credentials that you specify to collect Exchange Online mailbox content data using EWS must:
• Have Exchange impersonation permissions for all of the target mailboxes.(KB Article 145879)
• Have Exchange Web Services (EWS) access enabled.
• Be a member of the Exchange View-Only Organization Management role in the Exchange Online tenant.
• Have PowerShell access enabled.
Permissions needed for Exchange Online (Office 365 Native) mailbox configuration
The credentials that you specify to collect Exchange Online mailbox configuration data (including statistics,
permissions, and mobile devices) using remote PowerShell must:
• Be a member of the Exchange View-Only Organization Management role in the Exchange Online tenant.
• Have PowerShell access enabled.
To collect mailbox recipient “send as” permissions, the credentials must also:
• Be a member of the Recipient Management role group in the Exchange Online tenant.
Lync/Skype for Business credential permissions
Permissions to collect Lync/Skype for Business session and conference details
The account that is used to collect Lync/Skype for Business conference and peer-to-peer session data must have the following database role memberships in the Lync/Skype for Business CDR SQL databases:
• db_datareader
Permissions to collect Lync/Skype for Business QoE data
The account that is used to collect Lync QoE data must have the following database role memberships in the
Lync QoE SQL database:
• db_datareader
Permissions for the Lync/Skype for Business configuration data source
The account you specify for a Skype for Business/Lync configuration data source is used to collect the user,
server, and pool configuration data from the Skype for Business/Lync servers. The account must have the
CsViewOnlyAdministrator RBAC (role-based access control) role in the Skype for Business/Lync organization.
The easiest method to assign this role is to add the user to the CS View-Only Administrators build-in security
group.
Permissions needed to collect Cisco data
Note: Cisco is supported only if Active Directory is present and Cisco end-users are synchronized to Active Directory users using the SAM account name.
Permissions needed for Cisco configuration
You specify the credentials that are used to collect user data from Active Directory and the credentials used to
collect end-user data from the Cisco Unified Communications Manager (CUCM) server.
• The credential that is used to collect Active Directory (LDAP) user data must have read permissions on all
the Active Directory user, group and contact objects.
• The credential that is used to collect Cisco end-user data (including phone number and SAM account)
must have read permissions on the Cisco Unified Communications Manager server. The credential must
be a member of user group Standard AXL API Access.
There are different methods that Active Directory (LDAP) can be integrated with Cisco. UC Analytics requires
that the SAM account name be used to synchronize the Cisco end-users and Active Directory users.
Permissions needed for Cisco CDR logs
• You must specify a credential to access the Cisco server to collect Cisco configuration for the specified
Cisco Unified Communications Manager (CUCM). The credential must be a member of user group
Standard AXL API Access.
• To access the directories that contain the CDR logs, you can enter specific Windows credentials or you
can use the credential that is specified for the Data Engine service. The credential used to access the
Cisco CDR logs must have read rights on all the file shares on which you have stored the log files.