Delegate Object Creation when Full Exchange Admin Permission already applied

David Jenkins 946 Reputation points
2020-09-11T12:59:24.407+00:00

So I have a task of restricting Exchange Administrators access to certain OUs. We have a Forest and the accounts reside in a sub domain to the forest root. In sub domains Admins have full control. In the Forest Root they need access to create contacts only.

For the Exchange settings they have the permissions needed to create all their tasks in the sub domain but it means they have the permissions in the root domain as well since we use the Exchange Groups built in.

Using AD Delegation I've Denied User Objects Full Control access for the Domain and it doesn't appear to block account creation. If I deny read access to an OU they can't see it.

How would I go about restricting User account creation? What am I missing?

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,101 questions
Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,440 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Thameur-BOURBITA 32,621 Reputation points
    2020-09-13T22:07:58.057+00:00

    Hi,

    Did you try create a group in root domain , set delegation for this group then add admin account from child domain?

    The group scope in root domain must be local to accept members from another domain.

    Please if this reply help you to fix your issue mark it as answer

    0 comments No comments

  2. Hannah Xiong 6,241 Reputation points
    2020-09-14T03:24:22.063+00:00

    Hello,

    Thank you so much for posting here.

    We mainly focus on the AD issue since we are not professional with exchange issue. In AD, if we would like to restrict user account creation for certain user, we could try the below.

    1, Create the new OU and then add the specific user accounts to the OU.
    2, Right click the OU and choose "Properties", then choose "Security" tab.
    3, Select Advances button. For example:

    24362-111.png

    4, Select the ADD button

    24363-112.png

    5, Then, from the list with the permissions entries, add the users or groups you do not want them to create the user account.
    In the Type checkbox, select: Deny
    In the Applies to dropdown box select: This Object and all descendant objects

    6, Click "Clear all" and then check "Create User objects". For example:

    24364-113.png

    7, When the user tried to create the user account, Access is denied was shown. For example:

    24372-114.png

    Hope the information is helpful. We could kindly have a recheck whether it is helpful to solve our issue. For any question, please feel free to contact us.

    Best regards,
    Hannah Xiong

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments