University of Wisconsin Extended Campus is now Wisconsin Online Collaboratives! This name reflects the partnerships of the 13 universities within the Universities of Wisconsin–our state's premier system of public higher education. Through these partnerships we will continue to support online degrees, certificates and courses–along with support services to you.

Capstone Projects

How to Properly Administrate Mailbox Permissions in a Multi-Forest Active Directory – Exchange Architecture

Program: Applied Computing Bachelor's
Host Company: QBE Insurance Inc.
Location: Sydney / London / Sun Prairie, Wisconsin (remote)
Student: Trent Schnell

QBE has a complex Active Directory Exchange environment. We have a resource AD forests that replicate accounts and groups to ExchangeForest.com. QBE’s On-Prem Exchange instance exists in ExchangeForest.com. Exchange stores mailbox permissions (FullAccess, Send on Behalf, and SendAs) in attributes on a mailbox’s Active Directory account. FullAccess and Send on Behalf are stored in the mailbox account’s msExchMailboxSecurityDescriptor AD attribute. SendAs is stored in the mailbox account’s Active Directory Advanced Security Permissions. The Outlook client reaches out to an Exchange Server using Security Identifiers (SID). Because there are replica groups and accounts, it’s important that the correct groups are granted mailbox access. Otherwise, Outlook and Exchange will incorrectly query Active Directory and will return access denied. The replica of the group in the Exchange Forest must be granted access to the mailbox. The original group in the resource forest must not.