question

Sop-3080 avatar image
0 Votes"
Sop-3080 asked LucasLiu-MSFT commented

Is possibly to apply " Email Address policies" on a Distribution or Security group?

Hello,

I'm trying to find some sort of documentation to see if its possibly to apply " Email Address policies" on a Distribution or Security group?


Thanks,

office-exchange-server-mailflow
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

AndyDavid avatar image
0 Votes"
AndyDavid answered AndyDavid edited

image.png (23.2 KiB)
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Sop-3080 avatar image
0 Votes"
Sop-3080 answered ZhengqiLou-MSFT commented

Thanks but when i try to access the security group that i created in AD i can't find it in EAC...what am I doing wrong? I know i can select all the users but I just want to apply the policy to a specific Security Group that I created in AD. Thanks for your help.

· 2
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Is it mail-enabled?

0 Votes 0 ·

Hi @Safs-3080 ,

The security group you created in AD is not mail-enabled.
For example, the SG is a security group I created with EAC while SG2 was created in AD.
90080-image.png
The SG2 has no mailbox attributes, neither mail address nor database path.
But it could also be a member of the admin role group:
90181-image.png

Note: SG & SG3 are universal security groups but SG2 was a global security group. SG2 couldn't be a member of the admin role group.

Best regards,
Lou

0 Votes 0 ·
image.png (44.0 KiB)
image.png (17.2 KiB)
Sop-3080 avatar image
0 Votes"
Sop-3080 answered AndyDavid commented

Thanks for help but can you clarify your last statement.

"If this is a security only group, then no, since Email Address Policies would not be valid in that case"

Are you saying that applying email address policy to a security group is not possible? Am I reading it correctly? If I'm not mistaken you had mentioned in your initial response to my question that it was possible to apply email address policy to a security/distribution group?

· 3
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Only if its a mail-enabled security group, yes.

0 Votes 0 ·

anonymous userDavid thanks for the help... do you know of any documentation that stats that we can only apply an email address policy to a "mail-enabled" security/distribution group.

0 Votes 0 ·

By definition, Email Address policies only apply to mail-enabled objects. An email address policy would not be valid if its not mail-enabled since there is no email address associated with the object

https://docs.microsoft.com/en-us/exchange/email-addresses-and-address-books/email-address-policies/email-address-policies?view=exchserver-2019

Email address policies define the rules that create email addresses for recipients in your Exchange organization



.



0 Votes 0 ·
ZhengqiLou-MSFT avatar image
0 Votes"
ZhengqiLou-MSFT answered ZhengqiLou-MSFT edited

Hi @Safs-3080 ,

As Andy said, it is a yes:
For a mail enabled security group:
90115-image.png

Email options for mail-enabled security groups

For a distribution group:
90107-image.png

Email options for distribution groups

The mail-enabled security group, you could consider it as a distribution group but could be a member of admin role groups to give them permission.
90143-image.png

Regards,
Lou


If the response is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


image.png (55.3 KiB)
image.png (14.6 KiB)
image.png (17.1 KiB)
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Sop-3080 avatar image
0 Votes"
Sop-3080 answered LucasLiu-MSFT commented

anonymous userDavid

Ok, so I just created a Mail-enabled security group in EAC, named it Emailaddresstest2. Added a user as the owner, added a user a member.

Verified that I'm able to view the security group in AD but when i try to create and Email Policy and Specify the types: I select mail enabled groups and select "Add a rule" and try to find and locate that group that i created, I can't find it.

· 3
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Make sure its a universal group.

0 Votes 0 ·

Hi @Safs-3080 ,
Agree with Andy.
And if you want to apply this email address policy to the specific group, you could run the following command to set the customattribute1 for this group, then add the rule in email address policy.

 Set-DistributionGroup -Identity <> -CustomAttribute1 <>

91671-7.png



If the response is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.





0 Votes 0 ·
7.png (17.3 KiB)

Hi @Safs-3080 ,
I am writing here to confirm with you how thing going now?



If the response is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


0 Votes 0 ·