You can use the New-DistributionGroup cmdlet to create new Active Directory group objects of the following types:
-
Mail-enabled universal security group
-
Universal distribution group
Distribution groups are used to consolidate groups of recipients into a single point of contact for e-mail messages. Distribution groups can't be used to assign permissions to network resources in the Active Directory directory service.
To run the New-DistributionGroup cmdlet, the account you use must be delegated the following:
-
Exchange Recipient Administrator role
-
Account Operator role for the applicable Active Directory containers
For more information about permissions, delegating roles, and the rights that are required to administer Exchange Server 2007, see Permission Considerations.