CA Identity Manager: Why do Microsoft Exchange service accounts require Administrative privileges on all mailbox servers
Article ID: 77520
CA Identity ManagerCA Identity GovernanceCA Identity Portal
Why does the service account that connects Identity Manager to an AD/Exchange endpoint in agentless mode need to have local administrator privileges on all mailbox servers?
Release: Component: IDMGR
The AD/Exchange connector uses the Windows Remote Management Tools to manage objects on the endpoint. These tools require administrative rights as part of their permissions. Without the rights, the service account cannot use WinRMT and therefore cannot manage the mailboxes.