Help desk cannot assign retention policies to new mailboxes

I am running Exchange 2010 SP1.  I would like to give my help desk the ability to create new mailboxes.  When a new mailbox is created, we select the option to assign a Retention policy to it.  I added the help desk members to the "Recipient
Management" group.  They can now create new mailboxes but they get an access denied error when they select a retention policy to be assigned to it.  As a member of the "Organization Management" group, I am able to assign retention policies to new
mailboxes.
With the RBAC editor, I created a custom management role group called "Mailbox Management" based on the "Recipient Management" group and added the "Retention Management" role to the group.  I believe this will give them the permissions to apply retention
policies to new mailboxes but it also gives them the permissions to create/modify/delete retention policies themselves.  I only want to give them the rights to add mailboxes to retention policies. 
I assume I need to create a custom management role and assign this new role to my new management role group but can someone tell me the minimum role entries I need for my help desk to be able to assign rentention policies during the mailbox creation
wizard process?
Steve

Hi Steve,
Due to you post the issue in a wrong type, and we changed the type to give you a suggestion.
Please refer to below information:
http://technet.microsoft.com/en-us/library/dd638205.aspx 
The permissions required to configure messaging policy and compliance vary depending on the procedure being performed or the cmdlet you want to run. For more information about messaging policy and compliance, see
Messaging Policy and Compliance, refer to above article you could find out what permissions you need to perform the procedure or run the cmdlet, then you coudl create a roleassignment
for the customized role group.
Regards!
Gavin
TechNet Community Support

Similar Messages

  • Please help!  Cannot access TC backups on new hard drive with Lion!

    I know this seems like a generic posting, and believe me that I have searched through countless posts to find the situation most similar to mine.  To start, the basic story (I am pretty computer illiterate, so excuse the lack of terminology):
    -My computer was working slow, beach balling, etc. two weeks ago - took to Apple Genius Bar for help and they suggested need for new hard drive. I already had a hard drive crash in January, but since I have had a Time Capsule running Time Machine since September 2009, I hooked it right up and restored from a backup with no issue... so I wasn't worried about this.  I waited to make sure that I had the most recent backup (and needed to use my computer for law school for a couple days), so I turned it in a day later immediately after a complete incremental backup via TM on my TC. 
    -Got my computer back from the Apple "depot" with new hard drive and hard drive cable.
    -Had an extremely hard time getting my TC to link to my computer and via AppleCare phone help, realized that Apple had given me back my computer with Leopard, and they said that I needed to go back to the store to get a Lion reinstall since the backups had been done in Lion.
    -Went back to Apple store, reinstalled Lion... they told me there would be no issue once I got home and hooked up to TC.  Connected to TC via ethernet and went through "set up" procedure as if it was new computer - could never get past the "Select the Disk" page.  Either it was beach-balling or just sitting there, and I couldn't click continue or anything.
    -Called AppleCare again, they said to try it through Migration Assistant instead of Set Up... again, could not connect to TC.  They said it was too complicated to do over the phone and sent me back to the store...
    -By now, I am on vacation and spent 5, yes FIVE, hours at another store trying to migrate the data to no avail.  I obviously don't know everything they tried, but I know they tried installing each operating system since Leopard, going through set up and migration assistant, and doing a disk repair of the TC.  None of this worked.  Every single time my TC connects and you can see the title of the drive ("Data") and the two separate backups ("emilysmac" was my old computer and "emilysmacbookpro" was the dummy one we tried to make).  Emilysmacbookpro was accessible with no data on it, but once we clicked on emilysmac it just said "connecting" forever and never did anything.
    Basically:
    -300GB of my TC shows that it has been used, so I know something is there. 
    -I can also pull up the data on another computer, and it shows files dated from September 2009 up to the date I last updated, but they do not look how they used to - they are "Unix Executable" files and cannot open through Time Machine.
    I have a really hard time thinking that my TC AND my computer hard drive failed at the same time - which is actually what Apple suggested to me.  Is there anything that anyone knows that will help?!  I am desperate here!  This TC had backups of all my music, pictures and law school work over the past 2.5 years.  Any help would be much appreciated!

    PS I have also looked through Pondini's site, but I am not sure if I am missing something since I don't totally understand all of it.  Thanks again!

  • Help, I cannot print letters, etc. from new HP printer

    Help, I do not know what else to do, was on phone for long time yesterday trying to find a solutiuon. Printer does not work with computer, etc.

    Jlin ,
    Welcome to the HP Community Forum.
    With whom did you speak on the phone?
    Did you contact HP Technical Support?
    Contact HP – USA - Phone Assistance
    List of
    HP tech support/ Customer Service Phone Numbers – Some English Speaking Countries
    ==================================================​======================
    What kind of HP Printer do you have -- What is the model number? 
    Your printer should have its own Website Support Pages -- the instructions below will help you find the Support Website and help you install the printer software.
    In general, you should first install the Full Feature Software for the printer onto your computer:
    Install Full Feature Software – Printer
    The installation of the printer software may allow you to print from the computer to your printer.
    If you provide more information, someone may be able to provide suggestions.  Please include what you have done thus far to try and resolve the problems you are facing.
    Click the Kudos Thumbs-Up to show you appreciate the help.
    Click Accept as Solution when the Answer provides a Fix or Workaround!
    I am pleased to provide assistance on behalf of HP. I do not work for HP. 
    Kind Regards,
    Dragon-Fur

  • Retention Policies without Recreation of mailboxes

    Greetings,
    i'm wondering if it's possible to create Retention Policy and with these tags:
    Delete and Allow Recovery after 3 years
    Move to archive after 1 year
    without recreation of whole mailbox.
    Because I've several Databases with around 200 Mailboxes.
    Imagine how much bandwidth and time would it take to download new mailbox from server.
    For example in three years one mailbox has around 3GB.
    I tried applying this and it recreated all mailboxes, whole network went down because of download.
    Thank you.

    If I understood you correctly: it is possible to apply non-default retention policies to existing mailboxes,
    http://technet.microsoft.com/en-us/library/dd298052(v=exchg.150).aspx
    If I misunderstood you, please correct me. Hope it helps.
    Robert Mandziarz | IT Administrator:
    CodeTwo
    If this post helps resolve your issue, please click the "Mark as Answer" or "Helpful" button at the top of this message. By marking a post as Answered, or Helpful you help others find the answer
    faster.

  • Custom Retention policies for default folders in Outlook

    Hello,
    The following are the steps I've taken to create a retention policy for a user.Exchange 2013, outlook 2013
    The problem is that even if I create a retention tag for a default folder, I cannot implement it. I've gotten retention tags for user created folders to work, but not the default folders.
    Login to microsoft 365 as exchange Administrator
    Click Admin > Exchange
    Click ‘Compliance Management’ on left side
    Click ‘Retention Tags’
    Create desired retention tag by folder (choose default folder or user created folder)
    Save each tag as it is created
    Click ‘Retention Policies’
    Click ‘New’ to create a new policy
    Add desired tags to policy and click save
    To apply Retention Policy click ‘Recipients’ on left side
    Click ‘mail boxes’
    12. 
    Select user and click edit > mailbox features
    13. 
     Select desired retention policy
    14. 
    Save
    Using this method I created a retention tag to delete mail in the junk mail folder after 14 days. I added the 14 day junk mail retention tag to a retention policy and applied
    it to a user. But whenever I look at the junk mail folder it shows that the email will be deleted in 30 days --- not 14.
    What am I doing wrong?

    Hi,
    We can try to use managed folders to specify retention settings for default folders such as Inbox, Deleted Items, and Sent Items. See:
    http://technet.microsoft.com/en-us/library/ee364744(v=exchg.141).aspx
    Also check this:
    http://blogs.technet.com/b/theexchangeguy/archive/2012/06/04/retention-polices-and-tags-101.aspx
    Since this question is more related to Exchange server, it's better to post your question to Exchange forum:
    http://social.technet.microsoft.com/Forums/en-US/category/exchangeserver/ 
    The reason why we recommend posting appropriately is you will get the most qualified pool of respondents,
    and other partners who read the forums regularly can either share their knowledge or learn from your interaction with us.
    Thank you for your understanding.
    Best Regards,
    Steve Fan
    TechNet Community Support

  • Cannot Assign Archive and Retention Policies in Outlook 2010

    We are having problems figuring out how we enable Archiving and Retention tags in Outlook.  We have a new Exchange 2010 server with an Enterprise license key. We have run Microsoft Office professional plus 2010 on all of our clients (licensed through
    our volume license service agreement). We have configured an Archive mailbox store and assigned accounts to use that store. The archive mailbox appears in the users Outlook, but they cannot assign policies to folders or items. The ribbon does not show the
    option. I can see that it is configured to be part of the ribbon (when customizing the ribbon), but the option is not available to the user to actually select. I see user tags assigned to the user in Exchange, so I am at a loss as to where else to look for
    the problem.
    I see lots of documentation that says this is a licensing problem, but I am running the right components and think I have the right licensing. Is there a trouble shooting document or things I can check to make sure I have everything the way I need it to
    be?

    We found our own answer on this. Not sure why, but we had to use powershell to start the Managed Folder Assistant for the user name we had configured:
    Start-ManagedFolderAssistant -identity <username>
    My guess is that if we had waited long enough this would have resolved itself.

  • When I want to organise my bookmarks most of the options are greyed out and cannot be used including create new folder! Help

    '''''''''bold text'''''''''
    When i want to organise my bookmarks most of the options on the organise bookmarks menu are greyed out and cannot be used - including create new folder etc. Help please.

    Make sure you are not in the Private Browsing Mode:
    File > Private Browsing is UNCHECKED.

  • I actually need help but cannot find the answer. Please.......Lately when open a new tab it does not open with a blank page. I don't want to set my homepage as

    I actually need help but cannot find the answer.
    Please.......Lately when open a new tab it does not open with a blank page. I don't want to set my homepage as blank as when I first open Firefox, it automatically loads my hotmail page. But then if I open other pages I don't get a blank page. Help, please?
    Thank you.
    ''[Personal information removed by moderator. Please read [[Forum and chat rules and guidelines]], thanks.]''

    hello, please refer to [[New Tab Page – show, hide and customize top sites]] in order to switch the feature off.

  • I have a 3rd generation iPod and I cannot download or install any new apps. This started a few weeks ago.   I have plenty of space, it's very frustrating not to be able to get any apps! Please help?

    Please help,  I cannot get any apps free or bought, I am able to update just fine and, I can use the apps I already have with no problem.  But to be able to install an app. ie, new game recommended by app I already own, is impossible. A few weeks now I have been unable to get any new apps.  Why is this occuring and can there be something I can do to fox this without upgrading to 4.0.   

    Try resetting the device.
    Hold the On/Off Sleep/Wake button and the Home button down at the same time for at least ten seconds, until the Apple logo appears.

  • NEW 9I RMAN: BACKUP OPTIMIZATION AND RETENTION POLICIES

    제품 : RMAN
    작성날짜 : 2004-05-20
    NEW 9I RMAN: BACKUP OPTIMIZATION AND RETENTION POLICIES
    =======================================================
    오라클 9i RMAN 에서는 백업을 보다 효율적으로 할 수 있는 기능을 보강 했다.
    지금 소개할 "Retention Policies" 기능을 통해서 보다 효율적인 RMAN 백업
    전략을 세울 수 있다.
    1. 백업 화일 최적화 방법 (Backup File Optimization)
    백업 화일 최적화란 백업에 소요되는 공간을 최소화 하는 전략이다. RMAN
    백업시에 같은 정보 (dbid, checkpoint, and resetlogs data 등등) 를 가지고 있는
    화일이 이미 존재하는 백업 셋 내부에 있는지 체크하게 된다. 만일 같은 화일이
    이미 백업 되어 있다면 BACK UP 명령은 해당 화일에 대해서는 백업을 하지 않게
    된다.
    이때 같은 화일이라고 판단하는 기준은 다음과 같다.
    * Datafile: 같은 DBID, checkpoint SCN, resetlogs SCN 과 time. 데이타 화일은
    반드시정상적으로 offline 되었거나, read-only 이거나, 또는 정상적 으로 close
    되어야 함.
    * Archived redo log: 같은 thread, sequence number, 그리고 같은 Resetlogs
    SCN 과 time.
    * Backup Set: 같은 Backup Set recid 와 stamp.
    RMAN 이 백업을 수행하다가 위와 같은 조건의 화일이 이미 존재함을 확인하면
    이것은 건너뛰게 될 화일의 대상이다. 하지만 이때 바로 Skip 을 결정하지 않고
    정해진 Retention Policies 를 조사 한후에 Skip 여부를 결정 하게 된다.
    만일 백업 명령에 DELETE INPUT option 이 사용되면 RMAN 은 백업이 Skip
    되어도 화일을 지우게 된다.
    RMAN 은 모든 화일에 대한 백업이 Skip 되어도 에러메시지나 경고를 보내지
    않는다.
    그러나 만일 데이터 화일에 대한 백업이 recovery policy window 보다 오래
    된 것 이면 RMAN 은 새로운 백업 화일을 만들기 위해서 화일을 백업 하게 된다.
    Note:
    자체적인 expirations policy 를 가지고 있는 media manager 를 사용할 경우에는
    이런 백업 최적화 정책을 사용하는 것에 신중을 기해야 한다.
    백업 최적화 를 사용하기 위해서는 CONFIGURE 명령을 사용한다. CONFIGURE
    명령은 명령 수행 이후에 이루어지는 모든 백업에 대해 적용이 된다.
    예:
    CONFIGURE BACKUP OPTIMIZATION ON; # default 는 OFF
    2. Backup Optimization에 Retention Policies 적용 하기
    Retention Policy 로 백업 최적화를 조절 할 수 있다. 그러나 retention policy를
    사용하지 않기 위해서는 'CONFIGURE RETENTION POLICY TO NONE' 을
    이용해서 명시적으로 retention policy를 사용하지 않는다고 해야 한다. 디폴트로
    REDUNDANCY = 1 이 적용 된다.
         a. Recovery Window 를 이용한 Backup Optimization
    만일 백업 최적화가 enable 되어 있고 Recovery Window 가 retention policy
    적용을 위해서 셋업 되어 있으면 RMAN 은 항상 가장 최근의 백업이 Recovery
    Window 보다 오래된 데이터 화일을 백업한다.
    예를 들면 다음과 같은 조건에서
    o Today is February 21.
    o The recovery window is 7 days.
    o The most recent backup of tablespace tbs2 to tape is January 3.
    o Tablespace tbs2 is read-only.
    2월 21일에 tbs2 테이블 스페이스를 테이프로 백업을 하라는 명령을 내리면,
    RMAN 은 이 화일이 1월3일 이후에 변경 사항이 없는데도 불구 하고 백업을 하게
    된다. 이로써 RMAN 은 최근 7일 동안에 최소한 한번의 백업이 있어야 된다는
    조건을 지키게 된다.
    이러한 작동 방식은 media manager 가 오래된 테잎을 제거 해도 되도록 한다.
    그렇지 않다면, media manager 는 1월 3일의 백업을 무한정 가지고 있게 된다.
    2월 21일에 tbs2 테이블 스페이스의 보다 최근의 백업을 만듦으로 써, RMAN 은
    media manager 가 1월 3일에 백업 했던 테입을 지워도 되도록 한다.
         b. Redundancy 를 이용한 Backup Optimization
    Retention policy 로 Redundancy 를 채택 한 경우에 RMAN 은 Redundancy
    에 1을 더한 갯수를 초과하는 오프라인 또는 읽기 전용 화일의 백업을 건너뛴다.
    이때 'CONFIGURE RETENTION POLICY TO REDUNDANCY n' 명령어로
    Redundancy의 갯수를 정한다.
    아래와 같은 백업 최적화 명령을 내린 경우를 예로 든다:
    CONFIGURE BACKUP OPTIMIZATION ON;
    CONFIGURE RETENTION POLICY TO REDUNDANCY 2;
    아카이브 테이블스페이스를 한번도 백업을 받은적이 없고 다음의 작업을 1주일
    동안 한다고 하자.
    Day Action Result Redundant Backup
    Monday Take tablespace archive offline clean.
    Tuesday Run BACKUP DATABASE. The archive tablespace is backed up.
    Wednesday Run BACKUP DATABASE. The archive tablespace is backed up.
    Thursday Run BACKUP DATABASE. The archive tablespace is backed up. Tuesday backup.
    Friday Run BACKUP DATABASE. n/a Tuesday backup.
    Saturday Run BACKUP DATABASE. n/a Tuesday backup.
    Sunday Run DELETE OBSOLETE. The Tuesday backup is deleted.
    Monday Run BACKUP DATABASE. The archive tablespace is backed up. Wednesday backup.
    화요일, 수요일, 그리고 목요일의 백업은 아카이브 테이블 스페이스를 복사 해서
    3개의 백업이 반드시 존재 해야 한다는 조건을 충촉 시킨다. (1+Redundancy)
    금요일과 토요일에는 백업 최적화 조건에 의해서 아카이브 테이블 스페이스를
    복사하지 않게 된다.
    RMAN 은 일요일에는 유효기간이 지난 백업 화일을 지우게 된다. 따라서 화요일에
    만든 백업은 삭제 된다. 월요일의 전체 백업은 3개의 백업이 존재 해야 한다는 조건
    때문에 아카이브 테이블 스페이스를 또 다시 백업하게 된다. 이런 방식으로 백업
    사이클이 진행 된다.
    3. RETENTION POLICY NONE vs. DEFAULT
    주의 사항:
    'CONFIGURE RETENTION POLICY TO NONE' 과 'CONFIGURE RETENTION
    POLICY TO DEFAULT' 는 그 의미가 같지 않다. 전자는 RETENTION POLICY
    자체가 존재 하지 않는다는 의미 이며 백업은 expire 되지 않으며 'DELETE
    OBSOLETE' 명령은 사용 할 수 없게 된다. 후자는 디폴트 RETENTION POLICY
    (REDUNDANCY 1) 를 사용하게 된다는 의미 이다.
    'DELETE OBSOLETE' 명령은 RETENTION POLICY 기준으로 expire 된 백업을
    제거 하라는 명령이다.
    보다 자세한 내용은 Oracle9i Recovery Manager User's Guide and
    Reference의 Backup Optimization 부분을 참고 하시기 바랍니다.
    --------------THE END----------------------------------------------

    Hi,
    Backup optimisation = +- do not copy empty space.
    So, when you issue your BACKUP statement, it backs up the datafile. dot. nothing more.
    In order to achieve what you're testing, look into TFM for BACKUP INCREMENTAL LEVEL x .
    Regards,
    Yoann.

  • Help Desk Assign permission on mailboxes script

    Exchange sp3
    Outlook 2010 sp1
    I've come up with a script to give to the help desk that will save me from having to do lots of remedial work. The script gives the full access permission and send-as on a mailbox.
    This script works but for some reason I cannot get the input window to appear on my screen
    Here it is.
    [void][System.Reflection.Assembly]::LoadWithPartialName('Microsoft.VisualBasic')
    $Identity = Read-Host "= [Microsoft.VisualBasic.Interaction]::InputBox("Enter the name of the Mailbox", "Username")"
    $user = read-Host "Enter the name that will have full access rights"
    $AccessRights = read-host [Microsoft.VisualBasic.Interaction]::InputBox("Enter the name that will have full access rights", "Name")
    $ExtendedRights = Read-Host [Microsoft.VisualBasic.Interaction]::InputBox ("Enter the Extended Rights")
    [System.Reflection.Assembly]::LoadWithPartialName(“System.Windows.Forms”)
    [system.Windows.Forms.MessageBox]::show("$Identity $user", "MyTitle")
    Add-MailboxPermission -Identity $Identity -User $user -AccessRights $AccessRights
    Add-ADPermission -Identity (Get-Mailbox $Identity).DistinguishedName -User $user  -ExtendedRights $ExtendedRights
    Help please,
    alexis

    The following worked for me
    [void][System.Reflection.Assembly]::LoadWithPartialName('Microsoft.VisualBasic')
    #$Identity = Read-Host "= [Microsoft.VisualBasic.Interaction]::InputBox("Enter the name of the Mailbox", "Username")"
    $Identity = [Microsoft.VisualBasic.Interaction]::InputBox("Enter the name of the Mailbox", "Username")
    #$user = read-Host "Enter the name that will have full access rights"
    $user = [Microsoft.VisualBasic.Interaction]::InputBox("Enter the name that will have full access rights", "Name")
    #$AccessRights = read-host [Microsoft.VisualBasic.Interaction]::InputBox ("Enter the name that will have full access rights", "Name")
    $AccessRights = [Microsoft.VisualBasic.Interaction]::InputBox("Enter the permissions", "Name")
    #$ExtendedRights = Read-Host [Microsoft.VisualBasic.Interaction]::InputBox ("Enter the Extended Rights")
    $ExtendedRights = [Microsoft.VisualBasic.Interaction]::InputBox("Enter the Extended Rights")
    [System.Reflection.Assembly]::LoadWithPartialName(“System.Windows.Forms”)
    [system.Windows.Forms.MessageBox]::show("$Identity $user","MyTitle")
    Add-MailboxPermission -Identity $Identity -User $user -AccessRights $AccessRights
    Add-ADPermission -Identity (Get-Mailbox $Identity).DistinguishedName -User $user  -ExtendedRights $ExtendedRights

  • HT1420 looking at the 'help' to work out how to authorise new computer so can play songs, the instructions say - open itunes - go to store tab -locate 'authorise computer'- I cannot find the 'authorise computer' part !

    looking at the 'help' to work out how to authorise new computer so can play songs, the instructions say - open itunes - go to store tab -locate 'authorise computer'- I cannot find the 'authorise computer' part !

    You are looking at the drop-down menus at the top of iTunes e.g. on a Mac :
    If you are on iTunes 11 on Windows then press Alt-S and the Store menu should appear at the top.

  • Contact your help desk with this information: cannot create connection file "CitrixID"

    Has anyone overcome an issue with logging in to a Citrix server and getting the following message: Contact your help desk with this information: cannot create connection file “CitrixID”? I can log on, but once logged in, the apps available to me will not launch.  All worked fine before I upgraded to OS X Mavericks. I do a lot of foreign travel and Citrix kept me connected to the office. Unfortunately, our IT team aren't really "Mac Guys" so they are just as perplexed as I am. I have deleted and deleted Citrix Receiver several times as posts on other sites recommended, but to no avail.

    There are some discussions on the citrix forum that may help if you haven't already seen them. Here are two and there are likely more:
    http://discussions.citrix.com/topic/325359-reciever-117-cannot-write-connection- file-usersnamelibraryapplication-supportcitrix-receivermodules/
    http://discussions.citrix.com/topic/302900-reciever-1143-cannot-write-connection -file-userschristinalibraryapplication-supportcitrix-receivermodules-error-numbe r-30/

  • I need help whenever I want to install a new application I receive a message that I cannot be connected to I tunes store although I am connected to the Internet Help

    I need help whenever I want to install a new application I receive a message that I cannot be connected to I tunes store although I am connected to the Internet Help

    Click here and follow the instructions to change the iTunes Store country.
    (85848)

  • I updated my iphone and restored, now it is not being activated as this cannot be done anywhere in India. the help desk at a store asked me to restore it but there isn't any restore button now!

    I updated my iphone and restored, now it is not being activated as this cannot be done anywhere in India. the help desk at a store asked me to restore it but there isn't any restore button now!

    A compatible SIM card would be from AT&T and would not work in India.  It sounds as if your iPhone was hacked to unlock it and when you updated it, the hack was removed, thus relocking it to AT&T.

Maybe you are looking for

  • IMac as display?

    hey every1... i got a question concerning my iMac...i am thinking about buying a second mac (maybe power mac or the new macbook) i have seen that u can connect a screen to the new macbook so i am wondering if in any case it is possible to connect the

  • Syntax error on include of Function Module (user exit)  EXIT_SAPLRSAP_002

    When I do a syntax check in the a routine within inlude ZXRSAU02 of FM EXIT_SAPLRSAP_002, I get an error.  This object has been in production so I must be doing the syntax check incorrectly. The error is 'Field i_t_data is unknown. It is neither in o

  • Dynamically resize inline poup size

    Hi All, I'm using the latest build of Jdev and I have a inline popup within my taskflow which has a page with inputListOfValues. In my calling page, on the command button I'm setting the window size of the called popup to windowHeight="180" windowWid

  • Iweb beginner (with a capital B)

    Hi guys, I've had my iMac for a couple of yrs now, and I'm a bit of a musician, and have just finished a load of songs on GB. It's taken a long time to learn how to do it, and they sound good. I'd like to make a wee website for myself now, and pop my

  • Very Slow lan speed at WRT54G v8

    Hello folks, I'm very sorry to bring this issue to you, but I've checked all the information avaliable at the forum and was not able to solve my problem. Here it is: I have in my house total of 4 devices: 2- PC (P4 2.0 Gh 1 gb RAM) running Windows XP