Author Information Company: Docusnap AG Created by: Jones Adam Created on: 2/17/2012 12:00:00 AM Company: Docusnap AG Domain docusnap.internal Group Name Members Description Last Changed Email Group Scope Created on Account Operators Members can administer domain user and group accounts 8/3/2010 9:48:05 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/2/2010 1:22:35 PM Administrators Administrator, Domain Admins, dsdemo_admin, Enterprise Admins Administrators have complete and unrestricted access to the computer/domain 12/13/2010 9:18:41 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/2/2010 1:21:29 PM Allowed RODC Password Replication Group Members in this group can have their passwords replicated to all read-only domain controllers in the domain 8/2/2010 3:59:48 PM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/2/2010 1:22:36 PM Backup Operators Backup Operators can override security restrictions for the sole purpose of backing up or restoring files 8/3/2010 9:48:05 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/2/2010 1:21:29 PM Cert Publishers Members of this group are permitted to publish certificates to the directory 8/2/2010 3:59:48 PM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/2/2010 1:22:35 PM Certificate Service DCOM Access Members of this group are allowed to connect to Certification Authorities in the enterprise 8/2/2010 3:59:48 PM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/2/2010 1:21:29 PM Cryptographic Operators Members are authorized to perform cryptographic operations. 8/2/2010 3:59:48 PM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/2/2010 1:21:29 PM d_accounting u_accounting 11/29/2010 10:49:37 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 11/23/2010 7:17:13 PM d_assets accounting u_assets accounting 11/29/2010 10:49:37 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 11/23/2010 7:17:25 PM d_controlling u_controlling 11/29/2010 10:49:37 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 11/23/2010 7:17:36 PM d_finances u_finances 11/29/2010 10:49:37 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 11/23/2010 7:17:51 PM d_general u_general 11/29/2010 10:50:04 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 11/23/2010 7:26:37 PM d_it u_it 11/29/2010 10:50:04 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 11/23/2010 7:18:01 PM d_logistic u_logistic 11/29/2010 10:50:21 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 11/23/2010 7:18:16 PM d_management u_management 11/29/2010 10:50:04 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 11/23/2010 7:18:28 PM d_payroll accounting u_payroll accounting 11/29/2010 10:49:37 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 11/23/2010 7:18:39 PM d_personnel department u_personnel department 11/29/2010 10:50:04 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 11/23/2010 7:18:53 PM d_procurement u_procurement 11/29/2010 10:50:21 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 11/23/2010 7:19:08 PM d_shipping u_shipping 11/29/2010 10:50:21 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 11/23/2010 7:19:21 PM d_warehouse u_warehouse 11/29/2010 10:50:21 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 11/23/2010 7:19:32 PM Delegated Setup Members of this management role group have permissions to install and uninstall Exchange on provisioned servers. This role group shouldn't be deleted. 8/3/2010 6:48:32 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/3/2010 6:43:30 AM Denied RODC Password Replication Group Cert Publishers, Domain Admins, Domain Controllers, Enterprise Admins, Group Policy Creator Owners, krbtgt, Read-only Domain Controllers, Schema Admins Members in this group cannot have their passwords replicated to any read-only domain controllers in the domain 8/2/2010 3:59:48 PM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/2/2010 1:22:36 PM DHCP Administrators Members who have administrative access to the DHCP Service 8/2/2010 4:00:27 PM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/2/2010 3:22:07 PM DHCP Users Members who have view-only access to the DHCP service 8/2/2010 4:00:27 PM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/2/2010 3:22:07 PM Discovery Management Members of this management role group can perform searches of mailboxes in the Exchange organization for data that meets specific criteria. 8/3/2010 6:48:32 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/3/2010 6:43:30 AM Distributed COM Users Members are allowed to launch, activate and use Distributed COM objects on this machine. 8/2/2010 3:59:48 PM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/2/2010 1:21:29 PM DnsAdmins DNS Administrators Group 8/2/2010 4:00:26 PM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/2/2010 1:23:15 PM DnsUpdateProxy DNS clients who are permitted to perform dynamic updates on behalf of some other clients (such as DHCP servers). 8/2/2010 4:00:26 PM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/2/2010 1:23:15 PM Domain Admins Administrator, dsdemo_admin Designated administrators of the domain 12/13/2010 9:18:41 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/2/2010 1:22:35 PM Domain Computers All workstations and servers joined to the domain 8/2/2010 3:59:48 PM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/2/2010 1:22:35 PM Domain Controllers All domain controllers in the domain 8/3/2010 9:48:05 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/2/2010 1:22:35 PM Domain Guests Guest All domain guests 8/2/2010 3:59:48 PM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/2/2010 1:22:35 PM Domain Users Harrison Barber, Katie Swift, Leon V. Bryant, boston1, beamer01, london1, Max Gordon, Nathan Young, Sophie Coates, Tom Brown, Zara Pearce, Abigail Knight, Alex Stevenson, Charlotte L. Sanders, Elliot Roberts, Administrator, DiscoverySearchMailbox {D919BA05-46A6-415f-80AD-7E09334BB852}, DOCUSNAP$, dsdemo_admin, dsdemo_user, FederatedEmail.4c1f4d8b-8179-4148-93bf-00a95fa1e042, krbtgt, SystemMailbox{1f05a927-24b4-463e-90d0-ec07aeef603f}, SystemMailbox{e0dc1c29-89c3-4034-b678-e6c29d823ed9} All domain users 8/2/2010 3:59:48 PM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/2/2010 1:22:35 PM Enterprise Admins Administrator, dsdemo_admin Designated administrators of the enterprise 12/13/2010 9:18:41 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/2/2010 1:22:35 PM Enterprise Read-only Domain Controllers Members of this group are Read-Only Domain Controllers in the enterprise 8/2/2010 3:59:48 PM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/2/2010 1:22:36 PM Event Log Readers Members of this group can read event logs from local machine 8/2/2010 3:59:48 PM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/2/2010 1:21:29 PM Exchange All Hosted Organizations This group contains all the Exchange Hosted Organization Mailboxes groups. It is used for applying Password Setting Objects to all hosted mailboxes. This group should not be deleted. 8/3/2010 6:48:32 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/3/2010 6:43:31 AM Exchange Install Domain Servers SBEX0001 This group is used during Exchange setup and is not intended to be used for other purposes. 8/3/2010 1:24:27 PM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/3/2010 6:44:12 AM Exchange Servers SBEX0001, Exchange Install Domain Servers This group contains all the Exchange servers. This group should not be deleted. 8/3/2010 1:24:27 PM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/3/2010 6:43:31 AM Exchange Trusted Subsystem SBEX0001 This group contains Exchange servers that run Exchange cmdlets on behalf of users via Management service. Its members will have permission to read and modify all Exchange configuration, as well as user accounts and groups. This group should not be deleted. 8/3/2010 1:24:27 PM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/3/2010 6:43:31 AM Exchange Windows Permissions Exchange Trusted Subsystem This group contains Exchange servers that run Exchange cmdlets on behalf of users via Management service. Its members will have permission to read and modify all Windows accounts and groups. This group should not be deleted. 8/3/2010 6:48:32 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/3/2010 6:43:31 AM ExchangeLegacyInterop This group is for interoperability with Exchange 2003 servers within the same forest. This group should not be deleted. 8/3/2010 6:48:32 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/3/2010 6:43:31 AM g_accounting Tom Brown, Zara Pearce 11/29/2010 10:49:37 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 11/23/2010 7:14:34 PM g_assets accounting Nathan Young 11/29/2010 10:49:37 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 11/23/2010 7:12:40 PM g_controlling Sophie Coates, Alex Stevenson 5/20/2011 11:36:34 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 11/23/2010 7:14:27 PM g_finances g_accounting, g_assets accounting, g_controlling, g_payroll accounting 11/29/2010 10:49:37 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 11/23/2010 7:12:50 PM g_general g_it, g_management, g_personnel department, g_finances, g_logistic 11/29/2010 10:50:04 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 11/23/2010 7:26:23 PM g_it Leon V. Bryant 11/29/2010 10:50:04 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 11/23/2010 7:12:21 PM g_logistic g_procurement, g_shipping, g_warehouse, Abigail Knight 11/29/2010 10:50:21 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 11/23/2010 7:11:27 PM g_management Katie Swift 11/29/2010 10:50:04 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 11/23/2010 7:12:15 PM g_payroll accounting Max Gordon 11/29/2010 10:49:37 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 11/23/2010 7:12:29 PM g_personnel department Harrison Barber 11/29/2010 10:50:04 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 11/23/2010 7:12:06 PM g_procurement Alex Stevenson 11/29/2010 10:50:21 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 11/23/2010 7:11:37 PM g_shipping Elliot Roberts 11/29/2010 10:50:21 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 11/23/2010 7:11:53 PM g_warehouse Charlotte L. Sanders 11/29/2010 10:50:21 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 11/23/2010 7:11:45 PM Group Policy Creator Owners Administrator, dsdemo_admin Members in this group can modify group policy for the domain 12/13/2010 9:18:41 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/2/2010 1:22:35 PM Guests Domain Guests, Guest Guests have the same access as members of the Users group by default, except for the Guest account which is further restricted 8/2/2010 3:59:48 PM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/2/2010 1:21:29 PM Help Desk Members of this management role group can view and manage the configuration for individual recipients and view recipients in an Exchange organization. Members of this role group can only manage the configuration each user can manage on his or her own mailbox. Additional permissions can be added by assigning additional management roles to this role group. 8/3/2010 6:48:32 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/3/2010 6:43:30 AM Hygiene Management Members of this management role group can manage Exchange anti-spam features and grant permissions for antivirus products to integrate with Exchange. 8/3/2010 6:48:32 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/3/2010 6:43:30 AM IIS_IUSRS S-1-5-17 Built-in group used by Internet Information Services. 8/2/2010 3:59:48 PM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/2/2010 1:21:29 PM Incoming Forest Trust Builders Members of this group can create incoming, one-way trusts to this forest 8/2/2010 3:59:48 PM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/2/2010 1:22:35 PM Network Configuration Operators Members in this group can have some administrative privileges to manage configuration of networking features 8/2/2010 3:59:48 PM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/2/2010 1:21:29 PM Organization Management Administrator, dsdemo_admin Members of this management role group have permissions to manage Exchange objects and their properties in the Exchange organization. Members can also delegate role groups and management roles in the organization. This role group shouldn't be deleted. 12/13/2010 9:18:41 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/3/2010 6:43:30 AM Performance Log Users Members of this group may schedule logging of performance counters, enable trace providers, and collect event traces both locally and via remote access to this computer 8/2/2010 3:59:48 PM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/2/2010 1:21:29 PM Performance Monitor Users Members of this group can access performance counter data locally and remotely 8/2/2010 3:59:48 PM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/2/2010 1:21:29 PM Pre-Windows 2000 Compatible Access S-1-5-11 A backward compatibility group which allows read access on all users and groups in the domain 8/2/2010 3:59:48 PM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/2/2010 1:22:35 PM Print Operators Members can administer domain printers 8/3/2010 9:48:05 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/2/2010 1:21:29 PM Public Folder Management Members of this management role group can manage public folders. Members can create and delete public folders and<forcewidth> 8/3/2010 6:48:32 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/3/2010 6:43:30 AM manage public folder settings such as replicas, quotas, age limits, and permissions as well as mail-enable and mail-disable public folders. RAS and IAS Servers Servers in this group can access remote access properties of users 8/2/2010 3:59:48 PM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/2/2010 1:22:35 PM Read-only Domain Controllers Members of this group are Read-Only Domain Controllers in the domain 8/3/2010 9:48:05 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/2/2010 1:22:36 PM Recipient Management Members of this management role group have rights to create, manage, and remove Exchange recipient objects in the Exchange organization. 8/3/2010 6:48:32 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/3/2010 6:43:30 AM Records Management Members of this management role group can configure compliance features such as retention policy tags, message classifications, transport rules, and more. 8/3/2010 6:48:32 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/3/2010 6:43:30 AM Remote Desktop Users Members in this group are granted the right to logon remotely 8/2/2010 3:59:48 PM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/2/2010 1:21:29 PM Replicator Supports file replication in a domain 8/3/2010 9:48:05 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/2/2010 1:21:29 PM Schema Admins Administrator, dsdemo_admin Designated administrators of the schema 12/13/2010 9:18:41 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/2/2010 1:22:35 PM Server Management Members of this management role group have permissions to manage all Exchange servers within the Exchange organization, but members don't have permissions to perform operations that have global impact in the Exchange organization. 8/3/2010 6:48:32 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/3/2010 6:43:30 AM Server Operators Members can administer domain servers 8/3/2010 9:48:05 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/2/2010 1:22:35 PM Terminal Server License Servers SLTS0001 Members of this group can update user accounts in Active Directory with information about license issuance, for the purpose of tracking and reporting TS Per User CAL usage 8/25/2010 6:59:52 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/2/2010 1:22:35 PM u_accounting g_accounting 11/29/2010 10:49:37 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 11/23/2010 7:14:51 PM u_assets accounting g_assets accounting 11/29/2010 10:49:37 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 11/23/2010 7:15:06 PM u_controlling g_controlling 11/29/2010 10:49:37 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 11/23/2010 7:15:19 PM u_finances g_finances 11/29/2010 10:49:37 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 11/23/2010 7:15:30 PM u_general g_general 11/29/2010 10:50:04 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 11/23/2010 7:26:31 PM u_it g_it 11/29/2010 10:50:04 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 11/23/2010 7:15:41 PM u_logistic g_logistic 11/29/2010 10:50:21 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 11/23/2010 7:15:51 PM u_management g_management 11/29/2010 10:50:04 AM System Group, Global Group, Domain Local Group, Universal<forcewidth> 11/23/2010 7:15:59 PM Group, Security Group u_payroll accounting g_payroll accounting 11/29/2010 10:49:37 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 11/23/2010 7:16:22 PM u_personnel department g_personnel department 11/29/2010 10:50:04 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 11/23/2010 7:16:35 PM u_procurement g_procurement 11/29/2010 10:50:21 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 11/23/2010 7:16:46 PM u_shipping g_shipping 11/29/2010 10:50:21 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 11/23/2010 7:16:54 PM u_warehouse g_warehouse 11/29/2010 10:50:21 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 11/23/2010 7:17:04 PM UM Management Members of this management role group can manage Unified Messaging organization, server, and recipient configuration. 8/3/2010 6:48:32 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/3/2010 6:43:30 AM Users S-1-5-11, S-1-5-4, Domain Users Users are prevented from making accidental or intentional system-wide changes and can run most applications 8/2/2010 3:59:48 PM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/2/2010 1:21:29 PM View-Only Organization Management Members of this management role group can view recipient and configuration objects and their properties in the Exchange organization. 8/3/2010 6:48:32 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/3/2010 6:43:30 AM Windows Authorization Access Group S-1-5-9, Exchange Servers Members of this group have access to the computed tokenGroupsGlobalAndUniversal attribute on User objects 8/3/2010 6:48:32 AM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/2/2010 1:22:35 PM WINS Users Members who have view-only access to the WINS Server 8/2/2010 7:38:30 PM System Group, Global Group, Domain Local Group, Universal Group, Security Group 8/2/2010 7:38:30 PM