CA Identity Manager: Why do Microsoft Exchange service accounts require Administrative privileges on all mailbox servers

Document ID : KB000077520
Last Modified Date : 20/04/2018
Show Technical Document Details
Question:
Why does the service account that connects Identity Manager to an AD/Exchange endpoint in agentless mode need to have local administrator privileges on all mailbox servers?
Answer:
The AD/Exchange connector uses the Windows Remote Management Tools to manage objects on the endpoint. These tools require administrative rights as part of their permissions. Without the rights, the service account cannot use WinRMT and therefore cannot manage the mailboxes.