Exchange 2019 Custome Admin Roles

Shafaqat Ali 1 Reputation point
2024-01-31T12:33:17.5966667+00:00

Dear Experts, I have a very unique requirements. If anybody can help me to do it. Our Environment is single AD Single Domain, with 2 Exchange Servers. We have 4 domains configured in Exchange Server. Now we need to create the admin who can create and see just a users for the domain he is assigned to. What I mean is that if we give access of domain1.com to the *** Email address is removed for privacy *** then he must be able to do all the Admin tasks for that domain. But he will not be able to access any other domains users and tasks. I have played with the roles but I couldn't get the job done. Can anyone help me for this kind of configuration. Thanks. Ali.

Exchange | Exchange Server | Management
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Kael Yao 37,751 Reputation points Moderator
    2024-02-01T01:37:32.4033333+00:00

    Hi @Shafaqat Ali,

    Now we need to create the admin who can create and see just a users for the domain he is assigned to

    If in Active Directory you have four separate organization units for each of these domains, in Exchange you can refer to the following documentation to create a custom scope to only allow the admin to be able to manage one specific organization unit:

    Understanding management role scopes

    However, to my knowledge it may not be possible to restrict admins from seeing other domains' users, but they will have no permission to manage these users.

    Below is an example:

    1.create a custom scope to only allow writing to the domain1 OU 01

    2.create a role group and select this scope, add Mail Recipient creation role to allow creating mailboxes, add an admin to this group 02

    3.when this admin tries to create a mailbox in other OU than the domain1 OU, he gets an error that this is out of his write scope 03


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".  Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


  2. Shafaqat Ali 1 Reputation point
    2024-02-05T04:49:37.9366667+00:00

    I couldn't check it now. I will check on weekend and will confirm you. Thanks, Ali.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.