Chat now with support
Chat with Support

Security Explorer 9.8 - Release Notes

Permission requirements to manage Microsoft Exchange in Security Explorer

For more details on configuring user impersonation, see Configuring Exchange Impersonation in Exchange 2010.
1
In the Navigation pane, expand Role Based Access Control | Roles | ApplicationImpersonation | Assignments.
2
Select Assignments, and select File | New.
4
Select RecipientRelativeWriteScope and choose Organization from the list.
5
Click OK and restart Security Explorer.

Restrictions with mailbox management

Only a user who is a Domain Administrator and Exchange Administrator has no restrictions for mailbox management in Security Explorer. If a user uses Run As to start Security Explorer and that user does not have enough privileges and enters valid Alternative Credentials (Domain User, Exchange Administrator, Local Administrator, Has Mailbox, Has Impersonation), there are some restrictions with mailbox management in Security Explorer.

Exchange 2007

Domain Administrator

Exchange Organization Administrator

Windows® Authentication

Valid Alternative Credential

No restrictions

Domain User

Exchange Organization Administrator

Windows Authentication

Valid Alternative Credential

Cannot create, delete, and manage distribution groups.

Cannot manage Active Directory® permissions for mailboxes and public folders (View-only mode).

Domain User

Windows Authentication

Cannot connect to Exchange.

Domain User

Valid Alternative Credential

Cannot create, delete, and manage security and distribution groups (except dynamic distribution groups).

Cannot manage Active Directory permissions for mailboxes and public folders (View-only mode).

Exchange 2010

Domain Administrator

Member of Organization Management

Windows® Authentication

Valid Alternative Credential

No restrictions

Domain User

Member of Organization Management

Windows Authentication

Valid Alternative Credential

Cannot create, delete and manage distribution groups.

Cannot manage Active Directory® permissions for mailboxes and public folders (View-only mode).

Domain User

Windows Authentication

Cannot connect to Exchange.

Domain User

Valid Alternative Credential

Cannot create, delete, and manage security and distribution groups (except dynamic distribution groups).

Cannot create mail-enabled public folders.

Cannot manage Active Directory permissions for mailboxes and public folders (View-only mode).

Related Documents

The document was helpful.

Select Rating

I easily found the information I needed.

Select Rating