Authorisation Manager help

Jon_S's picture

I'm wanting to give our helpdesk team access to do 2 things, export archives to PST and change permissions to Exchange Archives (for when people have left and the AD account no longer exists).

I think I've got the export permissions sorted, but I can't find a way to give permissions to only change the permissions and not be able to delete the entire archive. Is there any way to do it?

Thanks

RahulG's picture

you can try creating role

you can try creating role defination in the authorization manger and add all the task which you want the user's should be authorized to perform as per your need
you can simply right click on the role defination and select new role defination .

If this response answers your concern, please mark it as a "solution"

Jon_S's picture

The problem is there is no

The problem is there is no operations that exclusively give access to change permissions or delete archives. There is only administer and manage permissions which covers both.

I found that I could use the below Operations:
{DIR} Can administer Enterprise Vault
{DIR} Can manage archives
Can manage Exchange Mailbox Archives
Can perform  Export Archive

That way they can only browse to the Top level where they can select Export or Modify Archive from the common tasks page, but it takes forever to to bring up the list of archives with Modify Archive so it's not really usable.