« Upcoming Book On Windows Workflow Foundation Development Using EmpowerID | Main | Welcome to the Identity Management Blog! »
Friday
Oct022009

Microsoft Exchange 2010 Drops ACLs for RBAC

Microsoft recently announced that the soon to be released Exchange 2010 was moving to an entirely Role-Based Access Control model. This represents a major change from the split permissions ACL model used in previous versions and one that is sure to be welcomed by security professionals everywhere. From what I've read so far, it looks like a complete swap out of the administrative delegation model from granting ACLs for attributes on objects moving instead to controlling "Operations" which represent PowerShell commandlets that perform specific human identifiable tasks. The ACLs model was cited by the Exchange team as a leading source of support calls and a major area of frustration for administrators.

Interestingly enough, the Exchange 2010 RBAC model maps on an almost one-to-one level with EmpowerID's implementation of RBAC at the technical role or "Management Role" level. These are the roles defined per type of Resource (mailbox, user, group, web page, etc...) to provide consistency for delegation of management tasks and also for reporting who has access to what. In EmpowerID, our "Operations" are workflow shapes that can, like Exchange, be PowerShell commandlets or almost anything else: custom code, web service calls, SSH calls, etc...

We are in complete agreement with the Exchange teams assesment of the lack of viability of ACL-based permissions management and are looking forward to seeing how AD moves down this path in future releases of the Windows Server platform. Given that Windows Server 2008 R2 includes a large number of PowerShell commandlets for AD administration, using these as the basis for AD management "Operations" an RBAC management model seems like a natural next step.

 Read more about our take on Exchange's move to RBAC

PrintView Printer Friendly Version

EmailEmail Article to Friend

References (1)

References allow you to track sources for this article, as well as articles that were written in response to this article.

Reader Comments (4)

http://vkatalogah.ru/ - ������������ ����������� � ���������

February 4, 2010 | Unregistered CommenterBickpaike

blog.identitymanagement.com, how do you do it?

March 8, 2010 | Unregistered CommenterMarcy

Annd this is the reason I love blog.identitymanagement.com. Inisghtful posts.


http://mishandlevideos.blogspot.com/2010/03/dependently-hunt.html

March 11, 2010 | Unregistered CommenterSantos

Interesting post, would be good to know how far this new entirely "Role-Based Access Control mode" would be advantageous in real life situations. For now am still keeping my email hosting accounts...

April 16, 2010 | Unregistered CommenterEmail Hosting

PostPost a New Comment

Enter your information below to add a new comment.

My response is on my own website »
Author Email (optional):
Author URL (optional):
Post:
 
Some HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong>