Set Permissions for Distribution Lists

Applies To: Windows Server 2008

You can use this procedure to set permissions for distribution lists in Active Directory Domain Services. Set permissions for distribution lists to regulate access to the distribution lists. Distribution lists are essentially distribution group objects in Active Directory Domain Services. They can contain explicit references only to destinations published in Active Directory Domain Services; that is, to public queues, queue aliases, and other distribution lists, but not to private and URL-named queues. Queue aliases are published in Active Directory Domain Services and can point to any queue, including private and URL-named queues. Thus, queue aliases pointing to private and URL-named queues can be included in a distribution list.

Membership in <Domain>\Domain Users, or equivalent, is the minimum required to complete this procedure.

To set permissions for distribution lists in Active Directory Domain Services

  1. Click Start, click All Programs, click Administrative Tools, and then click Active Directory Users and Computers.

  2. On the View menu, click Users, Groups, and Computers as containers.

  3. On the View menu, click Advanced Features.

  4. To grant permissions for a distribution list, in the console tree, right-click the applicable distribution list (group) and then click Properties.

    Where?

    • Active Directory Users and Computers/*YourDomain/*Users/YourDistributionList(Group)
  5. On the Security page, set permissions for the object specified in Step 4, as needed:

    • To grant permissions for this object to a group or user appearing under Group or user names, select the applicable group or user, and then in Permissions for GroupOrUser, select the check boxes in the Allow column following the names of the applicable permissions.

    • To deny a group or user permissions for this object, select the applicable group or user in Group or user names, and then select the check boxes in the Deny column following the names of the applicable permissions.

  6. To add a new group or user for access, click Add. In the Select Users, Computers, or Groups dialog box, click Object Types, select the Group and/or Users check box as appropriate, clear the remaining check boxes, and click OK. In Enter the object name to select, type the name of a group or user or the names of several groups or users separated by semicolons, and then click OK. Or, click Advanced to search for groups or users, enter the applicable parameters, click Find Now, select the group or user, click OK, and then click OK again. Then, select the group or user you just added and select the applicable check boxes as needed.

Additional considerations

  • Message Queuing distribution lists are distribution group objects in Active Directory Domain Services.

Important

Distribution lists are not created or managed with Message Queuing tools or APIs. For best security practice, consider carefully the permissions granted to distribution list objects.

Additional references