|
Permissions listed in this section are applied to objects contained in the Exchange configuration container or its children. The configuration container’s AD path is cn=Microsoft Exchange, cn=Services, cn=Configuration, dc=domain.
Account | Allow | Deny | Inherit | Right | On Property |
---|---|---|---|---|---|
During ForestPrep phase | |||||
Authenticated Users |
| ACTRL_DS_LIST | ACTRL_DS_READ_PROP | |||
Designated admin account |
|
| DS_AM_FULL_CONTROL | ||
During server install | |||||
Exchange Domain Servers |
|
| STANDARD_RIGHTS_READ | ACTRL_DS_READ_PROP | ACTRL_DS_LIST | ||
During ADC setup | |||||
Exchange Services |
|
| DS_AM_FULL_CONTROL |
Account | Allow | Deny | Inherit | Right | On Property |
---|---|---|---|---|---|
During server install | |||||
Exchange Domain Servers |
|
| DS_AM_FULL_CONTROL |
Account | Allow | Deny | Inherit | Right | On Property/ Applies To |
---|---|---|---|---|---|
During ForestPrep phase | |||||
Authenticated Users |
| ACTRL_DS_LIST_OBJECT | ACTRL_DS_READ_PROP | |||
Designated admin account |
|
| Send-As | ||
Designated admin account |
|
| Receive-As | ||
During server install | |||||
“Enterprise Admins” |
|
| Send-As | ||
“Enterprise Admins” |
|
| Receive-As | ||
“Domain Admins” of root domain |
|
| Send-As | ||
“Domain Admins” of root domain |
|
| Receive-As | ||
Everyone |
|
| ms-Exch-Create-Top-Level- Public-Folder | ||
Everyone |
|
| ms-Exch-Create-Public- Folder | ||
Everyone |
|
| ms-Exch-Store-Create- Named-Properties | ||
Everyone |
|
| STANDARD_RIGHTS_READ | ACTRL_DS_READ_PROP | ACTRL_DS_LIST | ACTRL_LIST_OBJECT | Applies to object class: msExchPrivateMDB | |
Everyone |
|
| STANDARD_RIGHTS_READ | ACTRL_DS_READ_PROP | ACTRL_DS_LIST | ACTRL_LIST_OBJECT | Applies to object class: msExchPublicMDB | |
Everyone |
|
| STANDARD_RIGHTS_READ | ACTRL_DS_READ_PROP | ACTRL_DS_LIST | ACTRL_LIST_OBJECT | Applies to object class: mTA | |
Exchange Domain Servers |
|
| DS_AM_CONTROL_ACCESS | ||
Exchange Domain Servers |
|
| ACTRL_DS_CREATE_CHILD | ||
Exchange Domain Servers |
|
| ACTRL_DS_WRITE_PROP | Public- Information | |
Exchange Domain Servers |
|
| ACTRL_DS_WRITE_PROP | Personal- Information (property set) | |
Exchange Domain Servers |
|
| DS_AM_FULL_CONTROL | Applies to object class: siteAddressing | |
When enabling an SRS (ACE is removed when SRS is disabled) | |||||
MACHINE$ |
|
| ACTRL_DS_LIST_OBJECT | ACTRL_DS_CREATE_CHILD| ACTRL_DS_DELETE_CHILD |
Account | Allow | Deny | Inherit | Right | On Property |
---|---|---|---|---|---|
During server install | |||||
Authenticated Users |
|
| ACTRL_DS_LIST |
Account | Allow | Deny | Inherit | Right | On Property |
---|---|---|---|---|---|
During server install | |||||
Authenticated Users |
|
| STANDARD_RIGHTS_READ | ACTRL_DS_READ_PROP | ACTRL_DS_LIST |
Account | Allow | Deny | Inherit | Right | On Property |
---|---|---|---|---|---|
During server install | |||||
Exchange Domain Servers |
|
| DS_AM_FULL_CONTROL |
Account | Allow | Deny | Inherit | Right | On Property |
---|---|---|---|---|---|
During server install (set on attribute msExchPFDefaultAdminACL) | |||||
Authenticated Users |
|
| Ms-Exch-Create-Public- Folder |
Account | Allow | Deny | Inherit | Right | On Property |
---|---|---|---|---|---|
During server install (set on attribute msExchPFDefaultAdminACL) | |||||
Authenticated Users |
|
| Ms-Exch-Create-Public-Folder |
Account | Allow | Deny | Inherit | Right | On Property |
---|---|---|---|---|---|
During KMS install | |||||
MACHINE$ |
|
| DS_AM_FULL_CONTROL | ||
Authenticated Users |
|
| STANDARD_RIGHTS_READ | ACTRL_DS_READ_PROP |
Account | Allow | Deny | Inherit | Right | On Property |
---|---|---|---|---|---|
During server install | |||||
Exchange Domain Servers |
|
| DS_AM_FULL_CONTROL |
|