keyongtech


  keyongtech > exchange.* > exchange.admin > 07/2008

 #1  
07-07-08, 09:31 PM
William Holmes
Hello,

Logged in as a user that is a member of Exchange Organization Administrators
as Well as the Exchange Public Folder Administrators I receive the following
error when attempting to add Send As permissions to a user. In a default
exchange installation shouldn't it be possible to grant these rights as a
member of the Exchange Organiztion Administrators?

Thanks

Bill

Summary: 1 item(s). 0 succeeded, 1 failed.
Elapsed time: 00:00:00


MyDomain\mytestuser
Failed

Error:
Active Directory operation failed on mydomain.com This error is not
retriable. Additional information: Access is denied.
Active directory response: 00000005: SecErr: DSID-03151E04, problem 4003
(INSUFF_ACCESS_RIGHTS), data 0




The user has insufficient access rights.

Exchange Management Shell command attempted:
Add-ADPermission -Identity 'CN=myPublicFolder,CN=Microsoft Exchange System
Objects,DC=mydomain,DC=com' -User 'MYDOMAIN\mytestuser' -ExtendedRights
'Send-as'

Elapsed Time: 00:00:00
 #2  
07-08-08, 02:38 AM
Rich Matheisen [MVP]
On Mon, 7 Jul 2008 16:31:42 -0400, "William Holmes"
<wtholmes> wrote:

>Logged in as a user that is a member of Exchange Organization Administrators
>as Well as the Exchange Public Folder Administrators I receive the following
>error when attempting to add Send As permissions to a user. In a default
>exchange installation shouldn't it be possible to grant these rights as a
>member of the Exchange Organiztion Administrators?


That depends on the AD object you're trying to modify. Blocked
inheritence, membership in a prvileged group (like Domain Admins),
etc. trump the inherited rights your user may have on the objects.
 #3  
07-08-08, 04:09 PM
William Holmes
Hello,

I am aware of these issues. To clarify this is what I am asking.

If I install a new active directory forest followed by Exchange, create a
non-privileged user and then add that user to the Exchange Organization
Administrators. Will this user be able to add send-As privileges to to user,
group, and public folder objects in the Exchange Organization? I am asking
this question in context of a default configuration.

Thanks

Bill



"Rich Matheisen [MVP]" <richnews> wrote in message
news:fu7r
[..]
 #4  
07-09-08, 02:10 AM
Rich Matheisen [MVP]
On Tue, 8 Jul 2008 11:09:57 -0400, "William Holmes"
<wtholmes> wrote:

>I am aware of these issues. To clarify this is what I am asking.
>
>If I install a new active directory forest followed by Exchange, create a
>non-privileged user and then add that user to the Exchange Organization
>Administrators. Will this user be able to add send-As privileges to to user,
>group, and public folder objects in the Exchange Organization? I am asking
>this question in context of a default configuration.


That's pretty much the same as your original post -- with a few
qualifications. The answer is still the same. What you have permission
to modify depends on the rights you have on the AD object.

If you're dealing with an AD User object and inheritence on the object
isn't blocked you'll usually have permission to modify the AD User.

Is it safe to assume that this new forest has only one domain, or that
the AD object you're trying to modify is in a domain that's be prepped
for use by Exchange?

The error you're getting says that your user lacks the necesssary
permission. That permission should be inherited. I'm not sure that
Exchange admins have permissions to modify the property the "Send-As"
permission.
Similar Threads
sendas group permissions 2007

i have a distrib group that contains some local contacts, these contacts need to be able to sendas the group address. i added in ADUC each user in advanced security and...

Blackberry SendAs Permissions

Environment: Exchange Server 2003 SP1, BES 4.1.3 and AD structure. I am looking at Microsoft KB907434 And am wondering if the workaround mentioned will work on Exchange...

SendAs Permissions Issue

Hi Guys, Listen I got a big problem, my client is running windows 2000 Server with Exchange 2000 installed. A few weeks ago the (IS) got corrupted, lucky we had backups and...

Removing SendAs/ReceiveAs permissions from Domain Admins

Is there a way I can prevent Domain Admins from being able to send mail as other people? I can remove the sendas/reeceiveas permissions at the organization level in...

SendAs/ReceiveAs permissions

I'm running a Windows 2003 AD forest with Exchange 2003. Is there a way to prevent Domain Admins from being able to send mail as other people, i.e. remove the SendAs...


All times are GMT. The time now is 11:21 PM. | Privacy Policy