We have set up a restrictive organization model and are looking to have our helpdesk perform "Allow" for individual users/devices that are blocked by default. What would be best way to delegate the allow?
From this article: (http://technet.microsoft.com/enus/library/dd638131.aspx) it looks as though organization manament and server management is required for "Exchange ActiveSync security settings". We don't however want to make a tier1, tier2 helpdesk a member of those role groups. So we would ideally want to add the specific role entries to one of the roles assigned to our tier2 group for example.
Any help on identifying those role entries would be much apprecieated.
Thank you,
Aaron Luna