0 votes

Our adaxes service account is able to create the mailbox when running our create user business rule, but cannot change any settings like disable OWA.

What level of security will it need?

by (50 points)

1 Answer

0 votes
by (273k points)
selected by
Best answer

Hello,

To manage mailboxes in Exchange Online, it is recommended to assign the Exchange administrator role to the account used to register your Microsoft 365 tenant in Adaxes.

In case of Exchange on-premises, you need to grant corresponding permissions to the account whose credentials are specified for a managed domain. For information on how to check/change the account, have a look at the following help article: https://www.adaxes.com/help/ChangeManagedDomainServiceAccount. It is recommended to assign the account to the Organization Management role group. It provides administrative access to an entire Exchange organization and can perform almost any task.

If, for some reason, you do not want to provide the account administrative access to your Exchange organization, you need to assign the account to the following role groups in Exchange:

For more details, see Understanding Management Roles.

Related questions

0 votes
0 answers

Over the last day or so we have been seeing this pop up under the exchange header in adaxes portal. cmdlet Get-CASMailbox is not present in the role definition of the current user

asked Jul 3, 2023 by Jeff.Briand (60 points)
0 votes
1 answer

Can I manage the user that is user by Adaxes to connect to Active Directory with Privilege Access Management (PAM)? Since this user can change user's password, ... would like to manage this user so that PAM can change/rotate the password periodically

asked Nov 18, 2021 by fachmi (170 points)
0 votes
1 answer

When copying a group, the message appears even though the group does not yet exist. "The specified group already exists, (Server: adc.de:636)"

asked Oct 12, 2021 by Johann Ihnen (170 points)
0 votes
1 answer

Hi, I need to create a number of mail user accounts via Adaxes and a lot of these accounts have & in the displayname/email address etc (I know, I know ... failed so I can troubleshoot it better. I have tried $context.logmessage($_.Exception.Message) Thanks

asked May 9 by typod (50 points)
3,374 questions
3,073 answers
7,817 comments
545,382 users