Enterprise Vault.cloud™ Archive Administration Help
- Getting started with Archive Administration
- Archive Overview
- My Config
- About Office 365 mailbox delegation permissions synchronization
- About Provisioning
- About Managed Tags
- About Account Management
- Archive Collectors
- About Box File Archiving
- About Salesforce Chatter Archiving
- About Lync On-Premises Archiving
- About Bloomberg Archiving
- Role Management
- Policy Management
- Classification
- Import Data
- Authentication Management
- AD FS Configuration Guide
- Retention Management
- Continuity Management
- Reporting and Notifications
- Personal.cloud Deployment for IBM Notes
- Archive Administration Updates in Previous Releases
- Archive Administration Known Issues
Effects of synchronized mailbox delegation permissions
The effects of synchronized mailbox delegation permissions depend on whether the permissions are granted to a user or to a mail-enabled security group.
Table: Effects of synchronized delegation permissions granted to a user describes the effects when the permissions are granted to a user.
Table: Effects of synchronized delegation permissions granted to a user
Mailbox delegation permission | Effect of the synchronized permission in Personal.cloud |
---|---|
Full Access | The user can read the account's archived items in Personal.cloud. Note: This access is not granted if the user belongs to a group that has a synchronized Deny Full Access permission. |
Deny Full Access * | The user cannot read the account's archived items in Personal.cloud. |
Send As | No effect at this release. |
Send on Behalf | No effect at this release. |
* Deny Full Access permission can only be set from PowerShell.
Table: Effects of synchronized delegation permissions granted to a mail-enabled security group describes the effects when the permissions are granted to a mail-enabled security group.
Table: Effects of synchronized delegation permissions granted to a mail-enabled security group
Mailbox delegation permission | Effect of the synchronized permission in Personal.cloud |
---|---|
Full Access | Users who are members of the group can read the account's archived items in Personal.cloud. Note: This access is not granted if the user has a synchronized Deny Full Access permission. |
Deny Full Access* | Users who are members of the group cannot read the account's archived items in Personal.cloud. |
Send As | No effect at this release. |
Send on Behalf | No effect at this release. |
* Deny Full Access permission can only be set from PowerShell.
Note that if Enterprise Vault.cloud synchronizes conflicting delegation permissions, precedence is given to deny permissions. This behavior matches Microsoft's handling of conflicting delegation permissions with regard to mailbox access.
Consider this example scenario of a mailbox to which the Office 365 administrator has assigned a number of delegation permissions.
Figure: Example: An Office 365 mailbox with delegation permissions set for users and mail-enabled security groups
In this example, the Office 365 administrator has granted the following delegate access to the mailbox:
User A and members of Group 1 have been given Full Access permission.
User B and members of Group 2 have been given Deny Full Access permission.
Assuming that Office 365 Sync has synchronized all of these delegation permissions, then User A and members of Group 1 can access the mailbox archive.
Note that this access is subject to the precedence of any deny delegation permissions. For example if User A is a member of Group 2, then User A cannot access the mailbox archive because Group 2's Deny Access delegation permission overrides User A's Full Access permission.