Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations TouchToneTommy on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Firm Mailbox Permissions

Status
Not open for further replies.

lizdunn

IS-IT--Management
Jul 12, 2000
42
US
I am trying to set up a "public" mailbox that is accessible to all users in the domain. The purpose of this mailbox is to file emails pertaining to client matters. The way we have it set up is to create the mailbox, create a folder in the mailbox called "clients," under the clients folder create subfolders A-Z, and in each subfolder, create sub subfolders for each client that begins with that letter. This was set up on our public folders but because you can't search subfolders in the public folders, and restoring a deleted item is such a big deal, we decided to try a public mailbox. My question (finally) is this: HOw do I set the permissions on this mailbox to give everyone rights to do just about anything (create new folders and subfolders, move items into folders) except delete items?

thanks.
 
There are a few ways you can do this.

One way is to create the shared mailbox, create yourself a profile to log in to it (assuming you have granted your account rights to open it), then rightclick the mailbox root folder (Outlook Today), select Properties, click the permissions tab, make sure the Default name is selected in the top window, change the Role to Owner, then modify the Delete options to None (this will change the role to Custom).

You will then need to repeat these permissions changes to any subfolder that already exists inside the mailbox (like Inbox) that you want this population to be able to open and create within.

Anyone by default can then add the mailbox to their profile by modifying their Exchange Server service (Proterties, Advanced, Add, and add the mailbox name in).

Whilst you're setting up the permissions, you might like to create a DL with an appropriate name, add it to the Name box, and give it an Owner role on the mailbox - people in this DL would then have Delete rights over items in the mailbox, useful for cleaning up the items that people will inevitably create in error over time.

 
It is better to give permissions on from a mailbox point of view, rather that folder access. This is mainly from an adminstration point of view. Through exchange administrator, go to the mailbox properties and then to permissions. You then add the domain account everyone or domain users to have permissions to the mailbox. This way, any subfolders created under this mailbox will automatically have the same permissions.
 
Thanks for the info. I tried setting these permissions and noticed that while items within folders cannot be deleted, folders themselves can be, regardless of the permissions set! this is also true in the public folders. Is this how it's supposed to work?

The permissions we have set on the public folders is: Default - None; Firm - Custom (can create, but not edit or delete any); and a specified domain user as owner. Also, when folders are created by a user in the public folder, they automatically become the owner, which again defeats our purpose. I periodically have to push down the permission set on the exhange manager for the public folders.

Am I missing something?

Thanks.
 
lizdunn, in your original post, you say explicitly say want people to not be able to delete items (you didn't say not delete items and subfolders). To stop them deleting subfolders, have you tried removing the Folder Owner tick from the Role?

mayh3m, whilst I agree with your general point (that it is better to permissions mailboxes from Admin rather than the individual folder via Outlook, where possible), if you read the requirement carefully you'll see that Admin permissions aren't suitable. This grants User rights on the mailbox, this gives full read, write and delete access to everything in the mailbox!
 
How do I remove the Folder Owner tick from the Role?
 
As described in the 1st paragraph of my first response to you. When you get to the bit about changing the delete option, the folder tick boxes are just above this, folder owner is the top of the three tickboxes.
 
got it. Works pretty well, except, whoever creates a folder automatically becomes the owner, and can delete whatever they want. Any way to push down permissions as on public folders?

Thanks for all your help.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top