This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Active Roles 7.1 Send As Permission

Attempting to allow Help Desk people to use Active Roles Console (i.e. MMC, or fat client) to set "Send As" (not send on behalf) permission on user's mailbox.  I've been googling, or going through a few ARS blogs, and product documentation but unable to find supportive information.  I must be looking at the wrong place...can anyone shed some lights on how to do that?  There are some old blog on using native security, some scripts, editing edvsaSendAs (or something like that)...but they aren't definitive to me, perhaps I am not technical enough to understand ... Any help is greatly appreciated.  I am particularly interested to find out if there is an built-in access template that will allow that...and then, where in the MMC I can access that "send as" information.

Again, much appreciated for any help..

Parents
  • I see in my ARS v7.1.2

    #1. Delegation(Send As) – (seems like) available in ARS WI only: User | Exchange Properties | Delegation(Send As) separate tab
    #2. Full Mailbox Access – in both ARS MMC and WI: User | Exchange Advanced

    Change History shows when you change it, in both cases ACL on resource "Mailbox" is changed:

    #1. Delegation(Send As) – (seems like) available in ARS WI only: User | Exchange Properties | Delegation(Send As) separate tab
    nTSecurityDescriptor (nTSecurityDescriptor) 'O:DAG:DAD:AI(A;;LCRPLORC;;;PS)(A;;RC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;AO)(A;;C … 'D:AI(A;;LCRPLORC;;;PS)(A;;RC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;AO)(A;;CCDCLCSWR …
    Exchange ActiveSync Mailbox Policy DN (edsva-MsExch-ProtocolSettings-ActiveSync-PolicyDN) Default (dsgsoft.com/Configuration/Services/Microsoft Exchange/DSGsoft Org/Mobile Mailbox Policies) Default (dsgsoft.com/Configuration/Services/Microsoft Exchange/DSGsoft Org/Mobile Mailbox Policies)
    edsvaSendAsTrustees (edsvaSendAsTrustees) S-1-5-10 S-1-5-10; Mon Orange (dsgsoft.com/QUEST/Inactive)

    #2. Full Mailbox Access – in both ARS MMC and WI: User | Exchange Advanced
    edsaMailboxSecurityDescriptor (edsaMailboxSecurityDescriptor) <not set> 'D:(A;CI;CCRC;;;PS)(A;CI;CCSD;;;S-1-5-21-2924937001-1541418760-4277144972-1453)'
Reply
  • I see in my ARS v7.1.2

    #1. Delegation(Send As) – (seems like) available in ARS WI only: User | Exchange Properties | Delegation(Send As) separate tab
    #2. Full Mailbox Access – in both ARS MMC and WI: User | Exchange Advanced

    Change History shows when you change it, in both cases ACL on resource "Mailbox" is changed:

    #1. Delegation(Send As) – (seems like) available in ARS WI only: User | Exchange Properties | Delegation(Send As) separate tab
    nTSecurityDescriptor (nTSecurityDescriptor) 'O:DAG:DAD:AI(A;;LCRPLORC;;;PS)(A;;RC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;AO)(A;;C … 'D:AI(A;;LCRPLORC;;;PS)(A;;RC;;;AU)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;AO)(A;;CCDCLCSWR …
    Exchange ActiveSync Mailbox Policy DN (edsva-MsExch-ProtocolSettings-ActiveSync-PolicyDN) Default (dsgsoft.com/Configuration/Services/Microsoft Exchange/DSGsoft Org/Mobile Mailbox Policies) Default (dsgsoft.com/Configuration/Services/Microsoft Exchange/DSGsoft Org/Mobile Mailbox Policies)
    edsvaSendAsTrustees (edsvaSendAsTrustees) S-1-5-10 S-1-5-10; Mon Orange (dsgsoft.com/QUEST/Inactive)

    #2. Full Mailbox Access – in both ARS MMC and WI: User | Exchange Advanced
    edsaMailboxSecurityDescriptor (edsaMailboxSecurityDescriptor) <not set> 'D:(A;CI;CCRC;;;PS)(A;CI;CCSD;;;S-1-5-21-2924937001-1541418760-4277144972-1453)'
Children
No Data