Delegating Exchange Administrative Control for Cisco Unity 5.0(1)+
Permissions Wizard grants a few Exchange permissions
automatically. For more information, see Permissions
Granted By the Cisco Unity Permissions Wizard.
However, you need to manually grant additional
permissions to two Active Directory accounts. The permissions you grant depend on the
versions of Exchange in which mailboxes will be homed:
Version of Exchange in Which Mailboxes Are Homed
|
Active Directory Account
|
Permissions to Grant
|
Exchange 2000 or Exchange 2003, with or without Exchange 2007
|
Cisco Unity installation
|
Delegate Exchange Administrator administrative control
|
Cisco Unity directory services
|
Delegate Exchange Administrator administrative control if you want to
create Cisco Unity subscribers by using the Cisco Unity Administrator.
Delegate Exchange View Only Administrator administrative control if you
want to create Cisco Unity subscribers only by importing accounts from Active Directory.
|
Exchange 2007 only
|
Cisco Unity installation
|
Delegate Exchange Organization Administrator administrative control
|
Cisco Unity directory services
|
Delegate Exchange Organization Administrator admininistrative control
|
Exchange 2010, with or without Exchange 2003 or Exchange 2007
|
Cisco Unity installation
|
Add the account to the Organization Management role group. If mailboxes
are also homed in Exchange 2003 and/or Exchange 2007, delegate the applicable administrative
control listed above.
|
Cisco Unity directory services
|
Add the account to the Organization Management role group. If mailboxes
are also homed in Exchange 2003 and/or Exchange 2007, delegate the applicable administrative
control listed above.
|
If any mailboxes are homed in
Exchange 2000 or Exchange 2003, you can delegate control either at the Exchange
organization level or at the administrative group level. However, for ease of
maintenance, we encourage you to delegate control at the organization level.
If you want to use Digital Networking and if you want to
delegate control at the administrative group level, then for all administrative
groups in which Cisco Unity subscriber mailboxes will be homed, you must:
- Delegate
Exchange Administrator control to the installation account for every Cisco
Unity server.
- Delegate
Exchange Administrator or Exchange View Only Administrator control to the
directory service account for every Cisco Unity server.
Otherwise, Digital Networking is not supported.
Using Cisco Unity Bridge Networking, AMIS Networking, or VPIM
Networking is supported only when:
- The
Active Directory forest includes at least one Exchange 2000 or Exchange
2003 server, on which the Cisco Unity Voice Connector for Microsoft
Exchange can be installed. A Voice Connector for Exchange 2007 is
currently not available.
- You
delegate control to the installation and directory services accounts at
the organization level.
Do the applicable procedure:
To Delegate Control When Mailboxes Are Homed in Exchange
2000 or Exchange 2003, with or without Exchange 2007
- If
you are delegating control at the Exchange organization level, log on to
the Cisco Unity server by using an account that is an Exchange Full
Administrator.
If you are delegating control at the Exchange administrative group level,
log on to the Cisco Unity server by using an account that has the
permissions that are required to delegate control to accounts for the
desired administrative group.
If you are configuring failover, log on to the primary server.
- On
the Cisco Unity server, on the Windows Start menu, click Programs >
Microsoft Exchange > System Manager.
- In
the left pane of the Exchange System Manager MMC, right-click either the
organization name at the top of the tree control or the name of an
administrative group in which Cisco Unity subscriber mailboxes will be
homed, and click Delegate Control.
- In
the Welcome to the Exchange Administration Delegation Wizard, click Next.
- In
the Users or Groups dialog box, click Add.
- In
the Delegate Control dialog box, click Browse.
- In
the Select Users, Computers, or Groups dialog box, in the Look In list,
click the name of the domain in which the installation account was
created.
- In
the list of users, computers, and groups, double-click the name of the
installation account.
The Delegate Control dialog box reappears. The account you selected
appears in the Group (Recommended) or User box.
- In
the Role list, click Exchange Administrator.
- Click
OK to close the Delegate Control dialog box.
- In
the left pane of the Exchange System Manager MMC, right-click either the
organization name at the top of the tree control or the name of the same
administrative group that you chose in Step 3, and click Delegate
Control.
- In
the Welcome to the Exchange Administration Delegation Wizard, click Next.
- In
the Users or Groups dialog box, click Add.
- In
the Delegate Control dialog box, click Browse.
- In
the Select Users, Computers, or Groups dialog box, in the Look In list,
click the name of the domain in which the directory services account was
created.
- In
the list of users, computers, and groups, double-click the name of the
directory services account.
The Delegate Control dialog box reappears. The account you selected
appears in the Group (Recommended) or User box.
- In the Role list, click the applicable option:
Exchange Administrator
|
If you want to create Cisco Unity subscribers by using the
Cisco Unity Administrator.
|
Exchange View Only Administrator
|
If you do not want to create Cisco Unity subscribers by using
the Cisco Unity Administrator (meaning that you will create Cisco Unity
subscribers only by importing accounts from Active Directory).
|
- Click
OK to close the Delegate Control dialog box.
- If
you are delegating control at the administrative group level, repeat Step
3 through Step 18 for each administrative group in which Cisco Unity
subscriber mailboxes will be homed.
- Click
Next.
- Click
Finish.
- Close
the Exchange System Manager MMC.
To Delegate Control When All Mailboxes Are Homed in
Exchange 2007
- Log
on to an Exchange 2007 server by using an account that is an Exchange
Organization Administrator.
- On
the Windows Start menu, click Programs > Microsoft Exchange Server
2007 > Exchange Management Console.
- In
the console tree, right-click Organization Configuration, and click
Add Exchange Administrator.
- On
the Add Exchange Administrator page of the wizard, click Browse.
- In
the Select User or Groups to Delegate dialog box, choose the installation
account, and click OK.
- Back
on the Add Exchange Administrator page, click Exchange Organization
Administrator Role.
- Click
Add.
- On
the Completion page, click Finish.
- In
the console tree, right-click Organization Configuration, and click
Add Exchange Administrator.
- On
the Add Exchange Administrator page of the wizard, click Browse.
- In
the Select User or Groups to Delegate dialog box, choose the directory
services account, and click OK.
- Back
on the Add Exchange Administrator page, click Exchange Organization
Administrator Role.
- Click
Add.
- On
the Completion page, click Finish.
- Close
the Exchange Management Console.
To Add the Installation and Directory Services Accounts to the
Organization Management Role Group When Mailboxes Are Homed in Exchange 2010
- On the
Windows Start menu, click Programs > Microsoft Exchange 2010 > Exchange
Management Console.
- In the
left pane, expand Microsoft Exchange On-Premises <servername>.
-
Click Toolbox.
- In the
right pane, double-click Role Based Access Control (RBAC) User Editor.
- Log on to
Outlook Web App.
- In the right
pane, click the Administrator Roles tab.
- Double-click
Organization Management.
- In the
Organization Management window, click Add, and follow the on-screen prompts
to assign the Organization Management role to the installation account.
- Repeat Step 8 to
assign the Organization Management role to the directory services account.
- Click Save.
Revision History
1.0.0, Initial version.
1.1.0, Updated for Cisco Unity 4.0(3)
1.2.0, Updated for Cisco Unity 4.1(1)
1.3.0, Updated for Cisco Unity 4.2(1)
1.4.0, Updated for Cisco Unity 5.0(1)
1.5.0, Updated for Cisco Unity 8.0(3)
© 2010 Cisco Systems, Inc. -- Company Confidential