Note the following information when using the App Agent Exchange Admin Configuration tool:
- To protect a stand-alone Exchange Server or Exchange DAG with the Microsoft application agent, you must configure an account with the required privileges. The App Agent Exchange Admin Configuration tool simplifies configuring security group memberships by ensuring that users have all the required Active Directory security group memberships and PowerShell management roles.
- To use the App Agent Exchange Admin Configuration tool, you must be logged in with domain administrator permissions. You can use an existing non-administrative user to run the App Agent Exchange Admin Configuration tool. However, this action is only possible if you select Skip Active Directory Authentication and configure the user on each Exchange Server node. This option skips the Active Directory authentication and authorization operations for the user. It only sets the user as the Microsoft application agent Exchange user account in the registry for backup and recovery operations.
- The Microsoft application agent uses the user account that is set in the registry by the App Agent Exchange Admin Configuration tool to perform backups and database- or granular-level recovery.
- To create a Microsoft application agent Exchange administrator account, the App Agent Exchange Admin Configuration tool performs the following steps:
- Creates an Active Directory user account
- Creates the custom Exchange security group Dell App Agent Exchange Admin Roles
- (Optional) Allows selecting Assign Organization Management rights
Members of the Organization Management role group have permissions to manage Exchange objects and their properties in the Exchange organization. Members can also delegate role groups and management roles in the organization.
Note: If you select Assign Organization Management rights, the Microsoft application agent adds the user to the Organization Management group. The tool does not create the Dell App Agent Exchange Admin Roles security group. If you do not select this option and do not select the Skip Active Directory Authentication option, the Microsoft Application Agent creates an Active Directory security group Dell App Agent Exchange Admin Roles and adds the user to that group.
Figure 3. App Agent Exchange Admin Configuration tool
- Permissions that the Exchange Admin Configuration tool configures:
- Security group memberships on the Microsoft application agent client host:
Local Administrator
- Security group memberships on Domain Controller:
Remote Desktop Users
- Exchange Security Group memberships:
Exchange Servers
Dell App Agent Exchange Admin Roles, which include:
- Exchange Roles
- Database Copies
- Databases
- Disaster Recovery
- Mailbox Import Export
- Mail Recipient Creation
- Mail Recipients
- View-Only Configuration