Custom Search

Thursday, April 10, 2008

Creating Security or Distribution Groups on Exchange

a
Using the following steps, administrators can create security or distribution groups:
a
1. Open Active Directory User and Computers. Right-click in the container where you want to create a new group, select New, and then select Group.
2. As shown in Figure 3.3, the New Object-Group dialog box will appear. In the Group Name field, type up to a 64 character name for the new group. The first 20 characters will be automatically inserted for the Pre-Windows 2000 group name and must be unique for the domain. If needed, you can type a unique name into this field.
aa

a
3. Select a group type of either Domain local, global, or universal (available only in native mode). The recommended scope type is universal; if you are unsure about which scope to use, choose universal.
4. Select Security or Distribution for your group type and click Next.
5. If the Exchange is set up properly, the Create an Exchange Email Address option will be available. Make sure that the box is checked and that the correct Alias name for the email address is displayed. (By default, the alias name is set to the group name.) If an Exchange email address isn't needed, uncheck this option.
6. Click Next and then click Finish, creating the group. If creation of an email address was selected, SMTP and X.400 email addresses will be automatically created.
a
After the group is created, administrators can change additional group properties, such as adding members to the group, setting message size-restriction limits, adding or removing email addresses, or limiting which users can send messages to the group.
a
Creating Query-Based Distribution Groups
a
Query-based distribution groups do not have a scope that is domain local, global, or universal. Their membership can contain users and groups from other domains or forests or members of the local domain. Their scope is determined by the container associated with the group when it is created. For example, if the container associated with the group is pandoranetworks.com, the query filter is applied to all recipients in the domain. If a filter is applied to a specific organization unit (OU) in a domain, the filter applies to all recipients in the container and those in any containers below.
a
The beauty of query-based distribution groups is that less time is spent managing group membership. In most organizations, people move around the company to different roles, departments, or eventually leave the company. Instead of specifying static user memberships, query-based distribution groups minimize the amount of time spent adding or removing users from groups by allowing LDAP queries to dynamically build membership in the distribution group. The group membership is created on-the-fly. An LDAP query is run every time an email is sent to this dynamic distribution list. Thus, using query-based distribution groups can dramatically reduce the administrative costs.
a
Because groups are used to manage email distribution and permissions, remember to create groups that will contain similar types of users. Typically, administrators create groups for users who work in the same departments and need access to similar network resources, users who have similar roles in an organization (executives, directors, engineers, and so on), or for users on specific company projects. Using the following steps, administrators can create query-based distribution groups:
a
1. Open Active Directory User and Computers. Right-click in the container where you want to create anew group, select New, and then select Query-Based Distribution Group.
2. As shown in Figure 3.4, the New Object-Query-based Distribution Group dialog box will appear. Type in a group name and, if required, a different alias for the group. Otherwise, the group name will be automatically inserted for the Exchange alias and will be used to set the group email address.
a

a
3. The container in which the group is created defines the scope of the LDAP query. This means the query filter will apply to all recipients of the container selected and below the specified container. Choose one of the preconfigured filters; otherwise, select the Customize Filter option and click Customize. The Find Exchange Recipients dialog box, as shown in Figure 3.5, appears.
a

a
4. Use the following tabs to configure additional parameters:
aa
● General Used to select the recipient types in the group.
● Storage Used to limit the mailbox to a specific server or mailbox store.
● Advanced Used to create combinations of fields, operators, and search criteria.
aa
5. When you're finished selecting criteria, click OK to return to the wizard. Click Next and then click Finish to create the group. As with other groups, if creation of an email address was selected, SMTP and X.400 email addresses will be automatically created.
aa
Again, after the group is created, administrators can manage additional group properties, such as adding members to the group, setting message size-restriction limits, changing, adding, or removing email addresses, limiting which users can send messages to the group, adding an expansion server, or configuring out-of-office options and nondelivery settings. Many settings can be configured; explore the ones that best fit your organi zation.
aa
Renaming and Deleting Groups
aa
Renaming and deleting groups each has a different effect on the security identifier (SID); object values are used to identify, handle, and track permissions independently of group names. When a group is renamed, the group is given a new label. Changing the name does not affect the SID, Exchange alias, or email addresses associates with the group. The group can be renamed in ADUC in two easy steps:
aa
1. Right-click the group name and then select Rename. Type in the new group name and press Enter.
2. When the Rename Group dialog box appears, press Tab and type in a new pre-Windows 2000 group name; then click OK to complete the group rename.
aa
Deleting a group removes it permanently from Active Directory. In theory, after a group is deleted, a group with the same name cannot be created with the same permissions of the original group. Group names can be reused, but because the SID of the new group name will not match the SID of the original group name, the permission settings must be manually re-created. Deleting a group is accomplished by highlighting the appropriate group, right-clicking, and selecting Delete or pressing the Delete key.
aa
Summary
aa
In an Exchange organization, administrators spend a great deal of time dealing with users, contacts, and groups. The administration tools are very similar to those of Exchange 2000 and require very little additional training to get started. The administration tools include new features, such as drag-and-drop capability, an enhanced interface, and updated versions of the administration tools. Although Active Directory Users and Computers is used for the majority of administrative tasks in Exchange 2003, the Exchange Task Wizard is also useful for basic configuration, setup, and administration on Exchange mailboxes, such as deleting, moving, and merging. Query-based distribution groups use LDAP queries to minimize group additions, deletions, and changes that normally absorb a lot of time for administrators.

Delicious Save to del.icio.us