Unable to Grant Domain Local Groups Full Access Permission to a Exchange 2010 Mailbox using the GUI

John Doe is a user in your Active Directory environment (Windows Server 2008 R2 Forest Function Level) with a mailbox on the email server (Exchange Server 2010 with SP2):

dl-gui1.png

You want to grant a domain local group named “Test Group” the full access permission to John Doe’s mailbox:

dl-gui2.png

You attempt to grant this permission by selecting “Manage Full Access Permission” from the Exchange 2010 Management Console:

dl-gui31.png

When you click add and search for the group, it doesn’t appear:

dl-gui4.png

PowerShell to the Rescue! The only way I’ve figured out how to accomplish this (work-around for this issue) is to use the “Exchange Management Shell” (PowerShell). In this scenario, use the following PowerShell script:

Add-MailboxPermission -Identity "John Doe" -User "Test Group" -AccessRights "FullAccess"

Even though the syntax uses the parameter name “-User”, you can specify a group name.

dl-gui5.png

The full access permission for John Doe’s mailbox is now assigned to the “Test Group”:

dl-gui6.png

µ