Management role types are the foundation of all management roles. Types define the implicit scopes defined on all management roles of a specified role type and also act as a logical grouping of related roles. All management roles derived from the parent built-in management role have the same role type. Refer to the Management role hierarchy figure earlier in this topic for an illustration of this relationship. Management role types also represent the maximum set of cmdlets and their parameters that can be added to a role associated with a role type.
The following table lists all of the administrative management role types in Exchange 2010 and whether the configuration that's permitted by the role type is applied across the whole Exchange organization or only to an individual server. For more information about each of the management roles associated with these role types, including a description of each role, who may benefit from being assigned the role, and other information, see Built-in Management Roles.
|
Management role type
|
Built-in management role
|
Description
|
Organization or server
|
|---|
|
ActiveDirectoryPermissions
|
Active Directory Permissions Role
|
This role type is associated with roles that enable administrators to configure Active Directory permissions in an organization. Some features that use Active Directory permissions or an access control list (ACL) include transport Receive and Send connectors, and Send As and send on behalf permissions for mailboxes.
Note:
Permissions set directly on Active Directory objects may not be enforced through RBAC.
|
Organization
|
|
AddressLists
|
Address Lists Role
|
This role type is associated with roles that enable administrators to manage address lists, the global address list (GAL), and offline address lists in an organization.
|
Organization
|
|
ApplicationImpersonation
|
ApplicationImpersonation Role
|
This role type is associated with roles that enable applications to impersonate users in an organization to perform tasks on behalf of the user.
|
Organization
|
|
AuditLogs
|
Audit Logs Role
|
This role type is associated with roles that enable administrators to manage the administrator audit logging configuration in an organization.
|
Organization
|
|
CmdletExtensionAgents
|
Cmdlet Extension Agents Role
|
This role type is associated with roles that enable administrators to manage cmdlet extension agents in an organization.
|
Organization
|
|
DatabaseAvailabilityGroups
|
Database Availability Groups Role
|
This role type is associated with roles that enable administrators to manage database availability groups (DAGs) in an organization. Administrators assigned this role either directly or indirectly are the highest level administrators responsible for the high availability configuration in an organization.
|
Organization
|
|
DatabaseCopies
|
Database Copies Role
|
This role type is associated with roles that enable administrators to manage database copies on individual servers.
|
Server
|
|
Databases
|
Databases Role
|
This role type is associated with roles that enable administrators to create, manage, mount, and dismount mailbox and public folder databases on individual servers.
|
Server
|
|
DisasterRecovery
|
Disaster Recovery Role
|
This role type is associated with roles that enable administrators to restore mailboxes and DAGs in an organization.
|
Organization
|
|
DistributionGroups
|
Distribution Groups Role
|
This role type is associated with roles that enable administrators to create and manage distribution groups and distribution group members in an organization.
|
Organization
|
|
EdgeSubscriptions
|
Edge Subscriptions Role
|
This role type is associated with roles that enable administrators to manage edge synchronization and subscription configuration between Edge Transport servers and Hub Transport servers in an organization.
|
Organization
|
|
EmailAddressPolicies
|
E-Mail Address Policies Role
|
This role type is associated with roles that enable administrators to manage e-mail address policies in an organization.
|
Organization
|
|
ExchangeConnectors
|
Exchange Connectors Role
|
This role type is associated with roles that enable administrators to manage connectors that aren't Send and Receive connectors in an organization. These connectors include routing group connectors and delivery agent connectors.
|
Organization
|
|
ExchangeServerCertificates
|
Exchange Server Certificates Role
|
This role type is associated with roles that enable administrators to create, import, export, and manage Exchange server certificates on individual servers.
|
Server
|
|
ExchangeServers
|
Exchange Servers Role
|
This role type is associated with roles that enable administrators to manage Exchange server configuration on individual servers.
|
Server
|
|
ExchangeVirtualDirectories
|
Exchange Virtual Directories Role
|
This role type is associated with roles that enable administrators to manage Microsoft Office Outlook Web App, Microsoft ActiveSync, offline address book (OAB), Autodiscover, Windows PowerShell, and Web administration interface virtual directories on individual servers.
|
Server
|
|
FederatedSharing
|
Federated Sharing Role
|
This role type is associated with roles that enable administrators to manage cross-forest and cross-organization sharing in an organization.
|
Organization
|
|
InformationRightsManagement
|
Information Rights Management Role
|
This role type is associated with roles that enable administrators to manage the Information Rights Management (IRM) features of Exchange in an organization.
|
Organization
|
|
Journaling
|
Journaling Role
|
This role type is associated with roles that enable administrators to manage journaling configuration in an organization.
|
Organization
|
|
LegalHold
|
Legal Hold Role
|
This role type is associated with roles that enable administrators to configure whether data within a mailbox should be retained for litigation purposes in an organization.
|
Organization
|
|
MailboxImportExport
|
Mailbox Import Export Role
|
This role type is associated with roles that enable administrators to import and export mailbox content and to purge unwanted content from a mailbox.
|
Organization
|
|
MailboxSearch
|
Mailbox Search Role
|
This role type is associated with roles that enable administrators to search the content of one or more mailboxes in an organization.
|
Organization
|
|
MailEnabledPublicFolders
|
Mail Enabled Public Folders Role
|
This role type is associated with roles that enable administrators to configure whether individual public folders are mail-enabled or mail-disabled in an organization.
This role type enables you to manage the e-mail properties of public folders only. It doesn't enable you to manage properties of public folders that aren't e-mail properties. To manage properties of public folders that aren't e-mail properties, you need to be assigned a role associated with the PublicFolders role type.
|
Organization
|
|
MailRecipientCreation
|
Mail Recipient Creation Role
|
This role type is associated with roles that enable administrators to create mailboxes, mail users, mail contacts, distribution groups, and dynamic distribution groups in an organization. Roles associated with this role type can be combined with roles associated with the MailRecipients role type to enable the creation and management of recipients.
This role type doesn't enable you to mail-enable public folders. To mail-enable public folders, you must be assigned a role associated with the MailEnabledPublicFolders role type.
If your organization maintains a split permissions model where recipient creation is performed by a different group from the group that performs recipient management, assign the MailRecipientCreation role to the group that performs recipient creation, and the MailRecipients role to the group that performs recipient management.
|
Organization
|
|
MailRecipients
|
Mail Recipients Role
|
This role type is associated with roles that enable administrators to manage existing mailboxes, mail users, mail contacts, distribution groups, and dynamic distribution groups in an organization. Roles associated with this role type can't create these recipients but can be combined with roles associated with the MailRecipientCreation role type to enable the creation and management of recipients.
This role type doesn't enable you to manage mail-enabled public folders or distribution groups. To manage mail-enabled public folders, you must be assigned a role associated with the MailEnabledPublicFolders role type. To manage distribution groups, you must be assigned a role associated with the DistributionGroups role type.
If your organization maintains a split permissions model where recipient creation is performed by a different group from the group that performs recipient management, assign the MailRecipientCreation role to the group that performs recipient creation, and the MailRecipients role to the group that performs recipient management.
|
Organization
|
|
MailTips
|
Mail Tips Role
|
This role type is associated with roles that enable administrators to manage MailTips in an organization.
|
Organization
|
|
MessageTracking
|
Message Tracking Role
|
This role type is associated with roles that enable administrators to track messages in an organization.
|
Organization
|
|
Migration
|
Migration Role
|
This role type is associated with roles that enable administrators to migrate mailboxes and mailbox content into or out of a server.
|
Server
|
|
Monitoring
|
Monitoring Role
|
This role type is associated with roles that enable administrators to monitor the Microsoft Exchange services and component availability in an organization. In addition to administrators, roles associated with this role type can be used with the service account used by monitoring applications to collect information about the state of Exchange servers.
|
Organization
|
|
MoveMailboxes
|
Move Mailboxes Role
|
This role type is associated with roles that enable administrators to move mailboxes between servers in an organization and between servers in the local organization and another organization.
|
Organization
|
|
OrganizationClientAccess
|
Organization Client Access Role
|
This role type is associated with roles that enable administrators to manage Client Access server settings in an organization.
|
Organization
|
|
OrganizationConfiguration
|
Organization Configuration Role
|
This role type is associated with roles that enable administrators to manage organization-wide settings in an organization. Organization configuration that can be controlled with this role type include the following and more:
-
Whether MailTips are enabled or disabled for the organization.
-
The URL for the managed folder home page.
-
The Microsoft Exchange recipient SMTP address and alternate e-mail addresses.
-
The resource mailbox property schema configuration.
-
The Help URLs for the Exchange Management Console and Outlook Web App.
This role type doesn't include the permissions included in the OrganizationClientAccess or OrganizationTransportSettings role types.
|
Organization
|
|
OrganizationTransportSettings
|
Organization Transport Settings Role
|
This role type is associated with roles that enable administrators to manage organization-wide transport settings, such as system messages, site configuration, and other organization-wide transport settings in an organization.
This role doesn't enable you to create or manage transport Receive or Send connectors, queues, hygiene, agents, remote and accepted domains, or rules. To create or manage each of the transport features, you must be assigned roles associated with the following role types:
-
Receive connectors
ReceiveConnectors
-
Send connectors
SendConnectors
-
Transport queues
TransportQueues
-
Transport hygiene
TransportHygiene
-
Transport agents
TransportAgents
-
Remote and accepted domains
RemoteAndAcceptedDomains
-
Transport rules
TransportRules
|
Organization
|
|
POP3AndIMAP4Protocols
|
POP3 and IMAP4 Protocols Role
|
This role type is associated with roles that enable administrators to manage POP3 and IMAP4 configuration, such as authentication and connection settings, on individual servers.
|
Server
|
|
PublicFolderReplication
|
Public Folder Replication Role
|
This role type is associated with roles that enable administrators to start and stop public folder replication in an organization.
|
Organization
|
|
PublicFolders
|
Public Folders Role
|
This role type is associated with roles that enable administrators to manage public folders in an organization.
This role type doesn't enable you to manage whether public folders are mail-enabled or manage public folder replication. To mail-enable or disable a public folder, you must be assigned a role associated with the MailEnabledPublicFolders role type. To configure public folder replication, you must be assigned a role associated with the PublicFolderReplication role type.
|
Organization
|
|
ReceiveConnectors
|
Receive Connectors Role
|
This role type is associated with roles that enable administrators to manage transport Receive connector configuration, such as size limits on an individual server.
|
Server
|
|
RecipientPolicies
|
Recipient Policies Role
|
This role type is associated with roles that enable administrators to manage recipient policies, such as provisioning policies, in an organization.
|
Organization
|
|
RemoteAndAcceptedDomains
|
Remote and Accepted Domains Role
|
This role type is associated with roles that enable administrators to manage remote and accepted domains in an organization.
|
Organization
|
|
RetentionManagement
|
Retention Management Role
|
This role type is associated with roles that enable administrators to manage retention policies in an organization.
|
Organization
|
|
RoleManagement
|
Role Management Role
|
This role type is associated with roles that enable administrators to manage management role groups, role assignment policies, management roles, role entries, assignments, and scopes in an organization.
Users assigned roles associated with this role type can override the role group managed by property, configure any role group, and add or remove members to or from any role group.
|
Organization
|
|
SecurityGroupCreationAndMembership
|
Security Group Creation and Membership Role
|
This role type is associated with roles that enable administrators to create and manage USGs and their memberships in an organization.
If your organization maintains a split permissions model where USG creation and management is performed by a different group from the group that manages Exchange servers, assign roles associated with this role type to that group.
|
Organization
|
|
SendConnectors
|
Send Connectors Role
|
This role type is associated with roles that enable administrators to manage transport Send connectors in an organization.
|
Organization
|
|
SupportDiagnostics
|
Support Diagnostics Role
|
This role type is associated with roles that enable administrators to perform advanced diagnostics under the direction of Microsoft support services in an organization.
Caution:
Roles associated with this role type grant permissions to cmdlets and scripts that should only be used under the direction of Microsoft Customer Service and Support.
|
Organization
|
|
TransportAgents
|
Transport Agents Role
|
This role type is associated with roles that enable administrators to manage transport agents in an organization.
|
Organization
|
|
TransportHygiene
|
Transport Hygiene Role
|
This role type is associated with roles that enable administrators to manage antivirus and anti-spam features in an organization.
|
Organization
|
|
TransportQueues
|
Transport Queues Role
|
This role type is associated with roles that enable administrators to manage transport queues on an individual server.
|
Server
|
|
TransportRules
|
Transport Rules Role
|
This role type is associated with roles that enable administrators to manage transport rules in an organization.
|
Organization
|
|
UMMailboxes
|
UM Mailboxes Role
|
This role type is associated with roles that enable administrators to manage the Unified Messaging (UM) configuration of mailboxes and other recipients in an organization.
|
Organization
|
|
UMPrompts
|
UM Prompts Role
|
This role type is associated with roles that enable administrators to create and manage custom UM voice prompts in an organization.
|
Organization
|
|
UnifiedMessaging
|
Unified Messaging Role
|
This role type is associated with roles that enable administrators to manage Unified Messaging servers in an organization.
This role doesn't enable you to manage UM-specific mailbox configuration or UM prompts. To manage UM-specific mailbox configuration, use roles associated with the UMMailboxes role type. To manage UM prompts, use the roles associated with the UMPrompts role type.
|
Organization
|
|
UnScopedRoleManagement
|
Unscoped Role Management Role
|
This role type is associated with roles that enable administrators to create and manage unscoped top-level management roles in an organization.
|
Organization
|
|
UserOptions
|
User Options Role
|
This role type is associated with roles that enable administrators to view the Outlook Web App options of a user in an organization. Roles associated with this role type can be used to help a user with diagnosing problems with his or her configuration.
|
Organization
|
|
ViewOnlyAuditLogs
|
View-Only Audit Logs Role
|
This role type is associated with roles that enable administrators to search the administrator audit log in an organization.
|
Organization
|
|
ViewOnlyConfiguration
|
View-Only Configuration Role
|
This role type is associated with roles that enable administrators to view all of the non-recipient Exchange configuration settings in an organization. Examples of configuration that are viewable are server configuration, transport configuration, database configuration, and organization-wide configuration.
Roles associated with this role type can be combined with roles associated with the ViewOnlyRecipients role type to create a role that can view every object in an organization.
|
Organization
|
|
ViewOnlyRecipients
|
View-Only Recipients Role
|
This role type is associated with roles that enable administrators to view the configuration of recipients, such as mailboxes, mail users, mail contacts, distribution groups, and dynamic distribution groups.
Roles associated with this role type can be combined with roles associated with the ViewOnlyConfiguration role type to create a role that can view every object in the organization.
|
Organization
|
The following table lists all of the user-focused management role types and their associated built-in management roles in Exchange 2010.