<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Minimum permissions necessary to access mailbox data</title><link>http://blogs.technet.com/exchange/archive/2006/01/25/418099.aspx</link><description>I was asked the following question recently: What are the minimum permissions necessary I need to grant a user in order for that user to be able to access the data in another user’s mailbox? Automatically I referenced following article 821897 that states</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>calendar permission</title><link>http://blogs.technet.com/exchange/archive/2006/01/25/418099.aspx#418126</link><pubDate>Thu, 26 Jan 2006 09:54:53 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:418126</guid><dc:creator>zhai </dc:creator><description>Hi Charlotte &lt;br&gt;Really enjoyed your post  , I am encountering some difficulties with Exchange permission in my company and wondered if you could give  me some advise  .&lt;br&gt;We are a big Telco company located in the middle east .&lt;br&gt;Currently we are giving our telemarketing guys access to our door to door sales person's outlooks so they can look at there calendar and set up appointment for them.&lt;br&gt;&lt;br&gt;The system guys are giving the telemarketing permission thought the sales person AD user witch mean the telemarketing are getting Full mailbox access.&lt;br&gt;We had complaints from the sales about telemarketing viewing  their mail .&lt;br&gt;So we want to give the telemarketing access only to their calendar ( as it should be)   is there a way to do that centrally from the AD ?&lt;br&gt;( I know I can do it from every sales person outlook but I prefer to do from a central location ) .&lt;br&gt;&lt;br&gt;Thanks in advance&lt;br&gt;&lt;br&gt;zhai&lt;br&gt;&lt;br&gt;</description></item><item><title>re: Minimum permissions necessary to access mailbox data</title><link>http://blogs.technet.com/exchange/archive/2006/01/25/418099.aspx#418166</link><pubDate>Thu, 26 Jan 2006 20:48:56 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:418166</guid><dc:creator>Charlotte Raymundo</dc:creator><description>Zhai,&lt;br&gt;&lt;br&gt;Unfortunately granting permissions on specific Outlook folders can not be set in AD.  That said, here is a post that will help you to set this using CDO code:&lt;br&gt;&lt;br&gt;&lt;a rel="nofollow" target="_new" href="http://gsexdev.blogspot.com/2005/05/changing-default-permissions-on.html"&gt;http://gsexdev.blogspot.com/2005/05/changing-default-permissions-on.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;Hope this helps!</description></item><item><title>dscflush</title><link>http://blogs.technet.com/exchange/archive/2006/01/25/418099.aspx#418199</link><pubDate>Fri, 27 Jan 2006 06:28:38 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:418199</guid><dc:creator>Luke Notley</dc:creator><description>What ever happened to that great utility dscflush for Exchange 2003? doesn't seem to work on Exchange 2003 servers I've tried it on.&lt;br&gt;&lt;br&gt;Luke</description></item><item><title>re: Minimum permissions necessary to access mailbox data</title><link>http://blogs.technet.com/exchange/archive/2006/01/25/418099.aspx#418482</link><pubDate>Wed, 01 Feb 2006 03:54:02 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:418482</guid><dc:creator>Robert Hupf</dc:creator><description>We are having a problem where we are granting a user in one domain Send As rights to a mailbox in another domain (same forest) and the permission keeps &amp;quot;disappearing&amp;quot;.  I have tried it with different users and the same thing happens.  We are on Exchange 2003 SP1.</description></item><item><title>re: Minimum permissions necessary to access mailbox data</title><link>http://blogs.technet.com/exchange/archive/2006/01/25/418099.aspx#418489</link><pubDate>Wed, 01 Feb 2006 05:06:18 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:418489</guid><dc:creator>Exchange</dc:creator><description>Robert,&lt;br/&gt;&lt;br/&gt;Check this article - we see this relatively often in PSS:&lt;br/&gt;&lt;br/&gt;Delegated permissions are not available and inheritance is automatically disabled&lt;br/&gt;&lt;a rel="nofollow" target="_new" href="http://support.microsoft.com/?id=817433"&gt;http://support.microsoft.com/?id=817433&lt;/a&gt;</description></item><item><title>re: Minimum permissions necessary to access calandar information</title><link>http://blogs.technet.com/exchange/archive/2006/01/25/418099.aspx#418944</link><pubDate>Tue, 07 Feb 2006 19:39:34 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:418944</guid><dc:creator>Manju</dc:creator><description>Hi,&lt;br /&gt;I'm Manju. I have a Question on the same.&lt;br /&gt;&lt;br /&gt;If any user wants to access calendar information of other users, what is the normal procedure?&lt;br /&gt;&lt;br /&gt;Do we need to grant full mailbox permissions at mailbox level and any role required at client.</description></item><item><title>re: Minimum permissions necessary to access mailbox data</title><link>http://blogs.technet.com/exchange/archive/2006/01/25/418099.aspx#418957</link><pubDate>Tue, 07 Feb 2006 21:47:49 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:418957</guid><dc:creator>Charlotte Raymundo</dc:creator><description>Manju,&lt;br /&gt;&lt;br /&gt;To grant another user access to a second user's calendar you can either grant MAPI permissions on the second user's calendar or grant permissions on that user object in the Active Directory. &lt;br /&gt;&lt;br /&gt;If you want to just share the calendar you will grant access from Outlook client. &amp;nbsp;Here is the article with the steps:&lt;br /&gt;&lt;br /&gt;290824	How to open another user's calendar or another folder in Outlook 2002&lt;br /&gt;&lt;a rel="nofollow" target="_new" href="http://support.microsoft.com/default.aspx?scid=kb;EN-US;290824"&gt;http://support.microsoft.com/default.aspx?scid=kb;EN-US;290824&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;If you want to grant permissions to access the calendar from the Active Directory side you will grant permissions on the second user's user object under &amp;quot;mailbox rights&amp;quot; (steps listed above). &amp;nbsp;&lt;br /&gt;&lt;br /&gt;The user being granted the permissions at the Active Directory level will need the full mailbox access and with that right the user will be able to access all folders in the second user's mailbox, not just the calendar. &amp;nbsp;There is no way to specify the specific mailbox items the permissions are applied to at this level.&lt;br /&gt;&lt;br /&gt;Hope this answers your question!&lt;br /&gt;</description></item><item><title>re: Minimum permissions necessary to access mailbox data</title><link>http://blogs.technet.com/exchange/archive/2006/01/25/418099.aspx#419696</link><pubDate>Thu, 16 Feb 2006 10:22:52 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:419696</guid><dc:creator>Igor</dc:creator><description>Hi Charlotte,&lt;br&gt;great article.&lt;br&gt;I have one question: &lt;br&gt;often we want give to user read permissions for another user mailbox (not only for specific folders, but for whole mailbox).&lt;br&gt;When we define &amp;quot;Read permissions&amp;quot; in Exchange advanced-&amp;gt;Mailbox rights properties of the user it's doesn't work - user cannot open another user mailbox. However it is work if we give to user full mailbox access.&lt;br&gt;But we want to give only read access...&lt;br&gt;Any suggestions?&lt;br&gt;Currently we use PFDAVAdmin tool for give read permissions for whole mailbox, but we really want to do it with ActiveDirectory.&lt;br&gt;P.S. we use Exchange 2003 sp1 servers on windows 2003.</description></item><item><title>re: Minimum permissions necessary to access mailbox data</title><link>http://blogs.technet.com/exchange/archive/2006/01/25/418099.aspx#419847</link><pubDate>Fri, 17 Feb 2006 21:11:38 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:419847</guid><dc:creator>Charlotte Raymundo</dc:creator><description>Igor,&lt;br&gt;&lt;br&gt;Granting permissions to allow users just the read permissions (even on the entire mailbox) has to be done at the MAPI level in Outlook. &lt;br&gt;&lt;br&gt;The Full Mailbox Access right is the only one availble in the Active Directory. &amp;nbsp;As you mentioned this gives the user more rights then just the read access. &amp;nbsp;Unfortunately there is no way to break this down into specific permissions (read, write ...) in the Active directory.&lt;br&gt;&lt;br&gt;With that said, you could grant these MAPI level permissions using CDO referenced in this blog:&lt;br&gt;&lt;a rel="nofollow" target="_new" href="http://gsexdev.blogspot.com/2005/05/changing-default-permissions-on.html"&gt;http://gsexdev.blogspot.com/2005/05/changing-default-permissions-on.html&lt;/a&gt; &lt;br&gt;&lt;br&gt;Hope that helps!&lt;br&gt;</description></item><item><title>re: Minimum permissions necessary to access mailbox data</title><link>http://blogs.technet.com/exchange/archive/2006/01/25/418099.aspx#419923</link><pubDate>Sun, 19 Feb 2006 11:14:40 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:419923</guid><dc:creator>Igor</dc:creator><description>Hi Charlotte, &lt;br&gt;thanks for the answer.&lt;br&gt;Will be nice if Microsoft will remove &amp;quot;Read permissions&amp;quot; string in Exchange advanced-&amp;gt;Mailbox rights properties or at least need to describe this behaviour in help/KB article.&lt;br&gt;Thanks, Igor &lt;br&gt;</description></item><item><title>re: Minimum permissions necessary to access mailbox data</title><link>http://blogs.technet.com/exchange/archive/2006/01/25/418099.aspx#420112</link><pubDate>Tue, 21 Feb 2006 18:36:03 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:420112</guid><dc:creator>Charlotte Raymundo</dc:creator><description>Igor,&lt;br&gt;&lt;br&gt;I can certainly understand the confusion as it is not well documented. &amp;nbsp;The permissions in the mailbox rights section falls under more administrator type roles. &amp;nbsp;The read permissions right is just that; this permission provides the ability for the user to read the permissions of the mailbox. &amp;nbsp;&lt;br&gt;&lt;br&gt;Regards,&lt;br&gt;Charlotte</description></item><item><title>re: Minimum permissions necessary to access mailbox data</title><link>http://blogs.technet.com/exchange/archive/2006/01/25/418099.aspx#420202</link><pubDate>Wed, 22 Feb 2006 13:45:17 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:420202</guid><dc:creator>PermanentMarker</dc:creator><description>why not make it a MMC exchange task&lt;br&gt;- share this mailbox, with user(s)&lt;br&gt;- share a folder of this mailbox&lt;br&gt;&lt;br&gt;then have next steps like&lt;br&gt; readonly access&lt;br&gt; read and delete access&lt;br&gt; create /delete own items xx&lt;br&gt; full mailbox access xx&lt;br&gt;&lt;br&gt;and in a xx &amp;gt; next step&lt;br&gt; send as&lt;br&gt;&lt;br&gt;perhaps more easy to some users, ehmm exchange admins &lt;br&gt;&lt;br&gt;&lt;br&gt;Altough i think that users should share their mailboxes themself, from a legal standpoint.</description></item><item><title>HOWTO: Configure Exchange Event Service on Exchange 2003 with minimum permissions</title><link>http://blogs.technet.com/exchange/archive/2006/01/25/418099.aspx#421451</link><pubDate>Wed, 08 Mar 2006 07:43:09 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:421451</guid><dc:creator>The CDOs and CDONTS of Messaging Development</dc:creator><description>We have received several support calls in the past months relating to migrating Exchange Event Service Scripts from Exchange 5.5 to Exchange 2003. &amp;nbsp;Because it isn’t straightforward or documented (to my knowledge), I came up with this information to help</description></item><item><title>re: Minimum permissions necessary to access mailbox data</title><link>http://blogs.technet.com/exchange/archive/2006/01/25/418099.aspx#426266</link><pubDate>Tue, 25 Apr 2006 18:02:16 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:426266</guid><dc:creator>Diego </dc:creator><description>Let's suppose the access was already given. If you give access to a group and somebody sends an e-mail to our Global List criticizing &amp;nbsp;the company. How to know who send the e-mail?</description></item><item><title>HOWTO: Configure Exchange Event Service on Exchange 2003 with minimum permissions</title><link>http://blogs.technet.com/exchange/archive/2006/01/25/418099.aspx#3190622</link><pubDate>Fri, 23 Jan 2009 07:26:48 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3190622</guid><dc:creator>mstehle: The CDOs and CDONTS of Messaging Development</dc:creator><description>&lt;p&gt;We have received several support calls in the past months relating to migrating Exchange Event Service Scripts from Exchange 5.5 to Exchange 2003. Because it isn’t straightforward or documented (to my knowledge), I came up with this information to help&lt;/p&gt;
</description></item></channel></rss>