Setup
...
Configure User Onboarding
Minimum Permissions required to Manage AD Contacts
7 min
the activate orchestrator (job) service, service account will need the following permissions in exchange and on the ou(s) where contacts reside within active directory permissions required create and update grant to activate orchestrator service account see recommendation below grant in on premise exchange rights recipient management role grant on ou and all descendant objects rights list contents read all properties write all properties read permissions delete grant to activate orchestrator service account grant on ou and all descendant objects rights read write create all child objects delete all child objects recommendation to grant these permissions it is recommended to create a group in an ou that only the activate orchestrator service account can write to see kb minimum permissions required for the services manager module for the rights required on the ou assign rights listed above to the group create a service that adds users to the group ensure that a team with appropriate training to understand the access being requested are approvers for the service order the service for the orchestrator service account notes if possible, remove permissions for users other than the activate orchestrator service account to manage objects in the ou(s)