SOLVED

Grant Access to All Mailboxes in Exchange 2016

%3CLINGO-SUB%20id%3D%22lingo-sub-2329204%22%20slang%3D%22en-US%22%3EGrant%20Access%20to%20All%20Mailboxes%20in%20Exchange%202016%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2329204%22%20slang%3D%22en-US%22%3E%3CP%3EI%20have%20inherited%20an%20Exchange%202016%20infra%20and%20I%20have%20a%20requirement%20for%20the%20following%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CUL%3E%3CLI%3E%3CP%3EGrant%20an%20Active%20Directory%20group%20read%20access%20to%20all%20mailboxes%20(new%20and%20existing)%3C%2FP%3E%3C%2FLI%3E%3CLI%3E%3CP%3EGrant%20an%20Active%20Directory%20group%20full%20access%20to%20all%20mailboxes%20(new%20and%20existing)%3C%2FP%3E%3C%2FLI%3E%3C%2FUL%3E%3CP%3EThe%20idea%20is%20this%20is%20a%20one%20off%20config%20so%20new%20mailboxes%20don't%20require%20anything%20to%20be%20done%20to%20them%20once%20created%20and%20inherit%20this%20permission.%20How%20can%20I%20accomplish%20this%3F%20is%20this%20setup%20with%20Exchange%20or%20Active%20Directory.%20Any%20guidance%20would%20be%20much%20appreciated.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2329204%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EExchange%20Server%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2329973%22%20slang%3D%22en-US%22%3ERe%3A%20Grant%20Access%20to%20All%20Mailboxes%20in%20Exchange%202016%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2329973%22%20slang%3D%22en-US%22%3EGrant%20permissions%20on%20the%20Database%20level.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2333248%22%20slang%3D%22en-US%22%3ERe%3A%20Grant%20Access%20to%20All%20Mailboxes%20in%20Exchange%202016%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2333248%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F58%22%20target%3D%22_blank%22%3E%40Vasil%20Michev%3C%2FA%3E%26nbsp%3BAh!%20So%20this%20is%20actually%20done%20by%20setting%20a%20permission%20on%20the%20EX%20DB%20object%20in%20ADDS%20using%20%3CSTRONG%3ESet-ADPermission%3C%2FSTRONG%3E%20CMDLET%20%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

I have inherited an Exchange 2016 infra and I have a requirement for the following:

 

  • Grant an Active Directory group read access to all mailboxes (new and existing)

  • Grant an Active Directory group full access to all mailboxes (new and existing)

The idea is this is a one off config so new mailboxes don't require anything to be done to them once created and inherit this permission. How can I accomplish this? is this setup with Exchange or Active Directory. Any guidance would be much appreciated.

2 Replies
best response confirmed by shocko (Occasional Contributor)
Solution
Grant permissions on the Database level.

@Vasil Michev Ah! So this is actually done by setting a permission on the EX DB object in ADDS using Set-ADPermission CMDLET ?