2.5. Preparing an Active Directory Domain for Exchange
Problem
You want to prepare an Active Directory domain for the installation of an Exchange server.
Solution
Using a graphical user interface
Log in with a domain account that is a member of the
DomainAdminsandAdministrators(if running from a member server) groups.Start Exchange Setup from the product CD.
Select Exchange Deployment Tools.
Select DomainPrep and click Next.
Accept the license agreement and, if prompted, enter your product key.
On the Component Selection page, be sure that the Action is set to DomainPrep. If it is not, select DomainPrep from the drop-down list, then click Next.
Allow the process to finish.
Discussion
Like forestprep, domainprep is normally a one-time operation performed before Exchange is installed. It performs several necessary actions:
It creates the
ExchangeDomainServersglobal security group in the Users container. This security-sensitive group will eventually contain all of the Exchange servers in the domain and is required for the Recipient Update Service (RUS) to work because the RUS runs as a child of the System Attendant, which runs in the LocalSystem context. For the RUS to touch directory objects, this group must exist and the local machine account must be in it. However, adding an ordinary account to this group gives that account full access to Exchange 2000 mailbox data. For that reason, Exchange Server 2003 adds an explicit deny ACE on the Servers container for this group. To accomplish ...