Custom Management Scope permission issue

Mikhail Firsov 1,876 Reputation points
2020-10-14T09:22:21.693+00:00

Hello,

Please excuse me for partially the same question as was posted here, but I'd like to illustrate the whole configuration process and find out what (if) was done wrong.

The theory - Create a custom management scope for In-Place eDiscovery searches

The practice:

32274-test12-2.png

32303-test13.png

Checking:
32129-test14.png

Testing:
32284-test15.png

Please note that since the eDiscovery/in-hold tab does appear on Bail's ECP the Test_Discovery_Manager role group assignment has worked correctly.

What's wrong with the scope permissions?

Thank you in advance,
Michael

Microsoft Exchange Online Management
Microsoft Exchange Online Management
Microsoft Exchange Online: A Microsoft email and calendaring hosted service.Management: The act or process of organizing, handling, directing or controlling something.
4,166 questions
Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,335 questions
Microsoft Exchange Hybrid Management
Microsoft Exchange Hybrid Management
Microsoft Exchange: Microsoft messaging and collaboration software.Hybrid Management: Organizing, handling, directing or controlling hybrid deployments.
1,875 questions
0 comments No comments
{count} votes

Accepted answer
  1. Kael Yao-MSFT 37,491 Reputation points Microsoft Vendor
    2020-10-15T06:51:31.137+00:00

    @Mikhail Firsov
    Hi,Michael.
    I noticed that you mentioned you are using Exchange 2019 in the former post.
    And I tested in my lab (both in Exchange 2019 CU2 and Exchange 2016 CU13) and got the same result.
    32418-screenshot-01.png
    The problem may be resulted from the distribution group not being resolved correctly into the mailbox addresses of members in this group.
    As the error message statued "You don't have sufficient permissions to search the mailbox..."(while actually it's a distribution group) and accroding to this article from Exchange Team Blog.
    32498-screenshot-02.png

    I suppose that it may be a bug.
    As a workaround,you can try manually selecting all specific mailboxes in the distribution group instead of selecting the distribution group directly.
    In my test,the search can complete without the permission error.


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

3 additional answers

Sort by: Most helpful
  1. Mikhail Firsov 1,876 Reputation points
    2020-10-15T07:58:18.177+00:00

    Hi KaelYao-MSFT,

    Before creating new searches I always check whether the -Filter is working: (I just did not post it):
    32601-test16.png

    ... I assumed that if the -Filter in Get-Recipient is working then - theoretically - the -RecipientRestrictionFilter in the NewScope cmdlet should also work. Since the search does succeed for a mailbox (not a group!) that is part of the custom scope the assumption was correct. And you right: changing the group to a user mailbox from that group leads to the search creating successfully:
    32611-test17.png

    32612-test18.png

    Furthermore, I did see somewhere on technet the article discribing the issue (a bug?) with resolving distribution groups - as far as I see it's exactly the same problem. I just don't remeber that the article contained something like "this issue will be fixed in ...".

    I also think this is the bug and administrators must know that this would not work:
    32549-test19.png

    Thank you very much for your help!

    Regards,
    Michael Firsov


  2. Mikhail Firsov 1,876 Reputation points
    2020-10-15T08:05:50.75+00:00

    P.S. I find it rather serious bug because it's easy to select several users instead of the group name in the test environment but in real networks distribution groups may contain hundreds or thousands members!

    0 comments No comments

  3. Mikhail Firsov 1,876 Reputation points
    2020-10-15T14:03:48.73+00:00

    Thank you, KaelYao-MSFT!

    0 comments No comments