Consider the following scenario:
- In a Microsoft Exchange Server 2010 environment, you create a scoped management role assignment which assigns the Active Directory Permissions or Mail Recipients roles.
- You assign the role assignment to a role assignee.
- The role assignee tries to run the Add-ADPermission command against a mailbox that is outside of the role assignment scope.
This issue occurs because there is no Role Based Access Control (RBAC) scope verification when Exchange Server 2010 runs the Add-ADPermission command.
Microsoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section.
For more information about Role Based Access Control, visit the following Microsoft website:Add-ADPermission command, visit the following Microsoft website:Active Directory Permissions role, visit the following Microsoft website:
Article ID: 2514766 - Last Review: Aug 26, 2011 - Revision: 1