Service account permissions

Installation user account

The user account used to perform the installation must be:

  • A member of the domain.
  • Assigned appropriate send-as and receive-as permissions on mail server.
  • Not a domain administrator (highly recommended)
  • A local administrator on the AMS server.

User account to run AMS services

An Active Directory user account is required to run all AMS service processes on servers running AMS components. This user must have a number of special permissions pre-configured on the account.

User requirements:

  • User must be a member of the domain in which the Aurea Messaging Solutions server is installed.
  • User has a Microsoft Exchange mailbox.
  • User must be a member of the local administrator group on the Aurea Messaging Solutions server, and preferably not a domain administrator. To do this, on the Aurea Messaging Solutions server launch the Local Users and Groups applet (Start > Run > lusrmgr.msc) and add the user to Groups > Administrators.
  • In Microsoft Exchange 2010 and higher, the user account must also be a member of the Organization Management and Recipient Management security groups. For more information refer to Add Members to a Role Group.
  • The user must be assigned a Microsoft Exchange management scope role that has access to all mailboxes (impersonation rights). For more information on how to create the management scope role, refer to Microsoft Exchange management scope role.

Setting Impersonation rights

An Active Directory Service Account refers to an Active Directory user account under which all AMS service processes run. This user account must be created on the AMS server.

This Active Directory Service Account user must be a member of:

  • The domain in which the AMS server is installed
  • A local administrator group on the AMS server

To ensure product reliability and performance, it is our recommendation that the Active Directory Service Account used be dedicated to AMS and not shared with any other applications.

The account must be assigned a Microsoft Exchange management scope role that has access to all mailboxes (impersonation rights).

This management scope role is utilized by SyncManager to access the list of Microsoft Exchange mailbox names and synchronize them with the data center. It is also used by RecoveryManager to restore emails that were sent or received during an email outage, back into their Exchange mailboxes.