The Add-ADPermission cmdlet grants permissions to an Active Directory object, for example, modifying an access control entry (ACE) on a server object.
To run the Add-ADPermission cmdlet, the account you use must be delegated the following:
-
Exchange Recipient Administrator role
-
Account Operator role for the applicable Active Directory containers
For more information about permissions, delegating roles, and the rights that are required to administer Exchange Server 2007, see Permission Considerations.
For more information about extended rights, see Permissions.