DL management

Glenn Maxwell 10,146 Reputation points
2023-04-01T00:40:54.4166667+00:00

Hi All

I have Distributions groups and mail enabled security groups in exchange online. lets say i have DLs by name

DL1@contoso.com and user1@contoso.com is the owner of the DL.

DL2@contoso.com and user2@contoso.com is the owner of the DL.

user1 from OWA can manage the DL membership as well user1 can delete the DL. I want to control Few DLs. i.e user1 who is the owner of the DL1 can manage membership but should not delete the DL.

in the same way user2 can manage the membership but should not delete the DL2. how do i control this. Only for few DLs i want to go with this approach please guide me.

Microsoft Exchange Online
Microsoft Exchange Online Management
Microsoft Exchange Online Management
Microsoft Exchange Online: A Microsoft email and calendaring hosted service.Management: The act or process of organizing, handling, directing or controlling something.
4,190 questions
Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,356 questions
Microsoft Exchange Hybrid Management
Microsoft Exchange Hybrid Management
Microsoft Exchange: Microsoft messaging and collaboration software.Hybrid Management: Organizing, handling, directing or controlling hybrid deployments.
1,895 questions
{count} votes

Accepted answer
  1. Jarvis Sun-MSFT 10,091 Reputation points Microsoft Vendor
    2023-04-10T08:28:24.3366667+00:00

    Hi @Glenn Maxwell ,  

    After my experiment, it was possible to create a custom RBAC role to restrict DL owners' permission to delete DL, here is my testing process:  

    1.  Create the new Role Assignment Policy called DG-Management: User's image

    1. We need to remove the Remove-DistributionGroup cmdlet: User's image

     

    1. Checking to see the current Management Role Entries, note the Remove cmdlets are gone: User's image

     

    1. Assign the DG-management role with my testuser:  User's image
    2. Check the result, after creating a new group we can find there is no Delete option in Distribution groups.  User's image

    Detailed information and steps please refer to: Allow Users To Manage Distribution Groups Without Creating New Ones

    Please Note: Since the web site is not hosted by Microsoft, the link may change without notice. Microsoft does not guarantee the accuracy of this information.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".  Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


1 additional answer

Sort by: Most helpful
  1. Glenn Maxwell 10,146 Reputation points
    2023-04-02T04:52:20.8166667+00:00

    My ask is DL owners should not be able to delete DLs from OWA.(Is it possible to create a policy for few DLS)

    0 comments No comments