An RBAC role assignee can unexpectedly change a DAG that is outside the management role group scope in an Exchange Server 2010 environment

Article ID: 2720017 - View products that this article applies to.
Expand all | Collapse all

Symptoms

Consider the following scenario:
  • You have some database availability groups (DAGs) in a Microsoft Exchange Server 2010 environment.
  • You create a management role assignment in the environment.
  • You assign management roles to a role assignee.
  • You define the scope of the role assignment to a member mailbox server in a DAG.
  • The role assignee tries to make some changes to another DAG that is outside the scope of the management role group by using one of the following cmdlets:
    • New-DatabaseAvailabilityGroup
    • Set-DatabaseAvailabilityGroup
    • Remove-DatabaseAvailabilityGroup
    • Stop-DatabaseAvailabilityGroup
    • Start-DatabaseAvailabilityGroup
In this scenario, the role assignee can unexpectedly change the DAG successfully.

Cause

This issue occurs because there is no Role Based Access Control (RBAC) scope validation when Exchange Server 2010 runs *-DatabaseAvailabilityGroup cmdlets.

Resolution

To resolve this issue, install the following update rollup:
2785908 Description of Update Rollup 5 version 2 for Exchange Server 2010 Service Pack 2

Status

Microsoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section.

More information

For more information about management role scopes, go to the following Microsoft website:
Understanding management role scopes
For more information about the New-DatabaseAvailabilityGroup cmdlet, go to the following Microsoft website:
General information about the New-DatabaseAvailabilityGroup cmdlet
For more information about the Set-DatabaseAvailabilityGroup cmdlet, go to the following Microsoft website:
General information about the Set-DatabaseAvailabilityGroup cmdlet
For more information about the Remove-DatabaseAvailabilityGroup cmdlet, go to the following Microsoft website:
General information about the Remove-DatabaseAvailabilityGroup cmdlet
For more information about the Stop-DatabaseAvailabilityGroupcmdlet, go to the following Microsoft website: 
General information about the Stop-DatabaseAvailabilityGroup cmdlet
For more information about the Start-DatabaseAvailabilityGroup cmdlet, go to the following Microsoft website:
General information about the Start-DatabaseAvailabilityGroup cmdlet
Note This is a "FAST PUBLISH" article created directly from within the Microsoft support organization. The information contained herein is provided as-is in response to emerging issues. As a result of the speed in making it available, the materials may include typographical errors and may be revised at any time without notice. See Terms of Use for other considerations.

Properties

Article ID: 2720017 - Last Review: December 14, 2012 - Revision: 3.0
Applies to
  • Microsoft Exchange Server 2010 Service Pack 1
  • Microsoft Exchange Server 2010 Service Pack 2
Keywords: 
kbqfe kbfix kbexpertiseinter kbsurveynew KB2720017

Give Feedback

 

Contact us for more help

Contact us for more help
Connect with Answer Desk for expert help.
Get more support from smallbusiness.support.microsoft.com