Permissions for Zimbra service accounts
Is this sufficient permissions or overkill?
'Zimbra' account will be used for F/B and GAL Interaction.
'Zmigrator' account will be used for migration functions(mapi profile, mailbox access).
1. Create ‘zimbra’ and ‘zmigrator” domain accounts
2. Grant to the ‘zmigrator’ account – Full Access to all Exchange mailboxes and be part of the Domain Administrators Group.
3. Grant to the ‘zimbra’ account – ‘Local Administrator’ on the each Exchange Mail and Hub Transport server(s).
4. Ensure that this Service Account 'ONXCOM\Zimbra' can update Exchange Free-Busy folder by issuing this Powershell command on the Exchange server.
[PS] C:\> add-publicfolderclientpermission -identity
"\NON_IPM_SUBTREE\SCHEDULE+ FREE BUSY\EX:/o=ONXCOM/ou=Exchange Administrative Group (FYDIBOHF23SPDLT)" –user Zimbra – accessrights owner