Setup
Distribution Lists
Minimum Permissions Required to Manage Distribution Lists
13 min
the activate orchestrator (job) service, service account will need the following permissions in exchange and on the ou(s) where distribution lists reside permissions required create, update, and add user on premise exchange grant to activate orchestrator service account see recommendation below grant in on premise exchange rights organization management role or, the security group creation and membership role a role group may have to be created to grant it, it is normally granted to the organization management role group without this we get; “a parameter cannot be found that matches parameter name 'type'” grant on ou and all descendant objects rights list contents read all properties write all properties read permissions cloud only dls azure grant to activate microsoft 365 admin account this can be the synchronised activate orchestrator service account, or a new, entra id only account created grant in exchange online rights membership in the security group creation and membership role a role group will have to be created to grant it, security group creation and membership is normally granted to the organization management role group a link to a guide on managing role groups can be found below without this we get; “a parameter cannot be found that matches parameter name 'type'” delete on premise active directory grant to activate orchestrator service account grant on ou and all descendant objects rights delete group objects cloud only dls azure grant to activate microsoft 365 admin account grant in exchange online rights membership in the security group creation and membership role recommendation to grant permissions it is recommended to create a group to assign rights to on premise exchange create a group in an ou that only the activate orchestrator service account can write to see kb minimum permissions required for the services manager module for the rights required on the ou for activate to manage group membership hybrid exchange create a mail enabled security group in an ou that is synchronised to azure ad see kb minimum permissions required for the services manager module for the rights required on the ou for activate to manage group membership cloud only create a mail enabled universal group in azure ad assign rights listed above to the group create a service that adds users to the group ensure that a team with appropriate training to understand the access being requested are approvers for the service order the service for the orchestrator service account notes if possible, remove permissions for users other than the activate orchestrator service account to manage objects in the ou(s) a guide to creating a role group to grant the security group creation and membership role can be found at https //learn microsoft com/en us/exchange/permissions exo/role groups