Reviewer Permissions needed for Delegate Folder access t o be viewed in Archive Explorer(AE)

Article:TECH71838  |  Created: 2009-01-24  |  Updated: 2009-01-02  |  Article URL http://www.symantec.com/docs/TECH71838
Article Type
Technical Solution

Product(s)

Environment

Problem



Reviewer Permissions needed for Delegate Folder access t o be viewed in Archive Explorer(AE)

Solution



When a user assigns Delegate Permissions from within Outlook to give another user access to certain folders all will work well as long as the correct Enterprise Vault(EV) Policy option is set and the EV Permission are synced for that mailbox. This will allow the viewing of the archived messages by the Delegate User but when viewed via AE a error will occur.

If the Desktop Policy is set(in version 8.0) or the Mailbox Policy(in version 7.5 and below) to sync Folder Level Permission then EV will sync permissions exactly as they are within outlook. The permissions set through delegation to the given folder are synchronized into Enterprise Vault, so if a user connects to the "Other Users Folder" within outlook, they will be able to open these archived items. However if the delegate user uses archive explorer to view the archived items a error will be displayed stating that access was denied listing the users folders. This is due to the fact that the root of the mailbox has a deny permission against everyone but the owner. If you right click the properties of "Mailbox - user name" and go to Properties, and then permissions, you will notice that the two permissions listed are Default and Anonymous, both set to none. If a delegated user attempts to open the mailbox through the Email Accounts -> Advanced options, you will get an error stating that access was denied listing the users folders.

Solution:
A workaround to this is to give 'Reviewer Rights" on the root of the Mailbox as this is a 'Folder List" access only and does not give Write or Read permissions.

On the root of the users mailbox to go to Properties and then permissions, add the delegated user and give the user "Reviewer" rights. This will now allow the archive to be shown in archive explorer, and will only list the folders given permissions to through Folder Permissions or delegate control.

As previously stated this is expected behavior and is by design since Archive Explorer is design is to only show archives where we have access to the root folders of the mailbox.
 


Legacy ID



327097


Article URL http://www.symantec.com/docs/TECH71838


Terms of use for this information are found in Legal Notices