Remove-mailbox requires permissions above what documentation states
The page: http://technet.microsoft.com/en-us/library/aa995948.aspx claims that
"To run the Remove-Mailbox cmdlet,the account you use must be delegated the following:
* Exchange Recipient Administrator role * Account Operator role for the applicable Active Directory containers"
My tests show this to be incorrect. When a user with these permissions attempts this action, an error message occurs like the following:
'WARNING: Failed to commit the change on object"de5f83f1-c268-4dbd-9e6b-63b42fbed228" because access is denied.'
If the user is added to the Domain Admins group in AD then the error will not occur.
This is of importance to me because I would like to allownon-priveleged (non-administrator) users to manage the recipients on my exchange server. So far I added these non-priveleged users to the Exchange Recipient Administrator group and used the delegation of control wizard to give them "Create, Delete and Manage Accounts" and "Reset User Passwords and Force change at next logon" rights over OU containing the mailbox users and this works for everything except removing mailboxes. I tried adding them to the Account Operator group for test purposes but that did not solve the above problem.
Does anyone know why the official documentation appears to be wrong?
Regards,John
June 14th, 2007 11:57am