Exchange Manager

Unifying Active Directory and Exchange Management with Workflow and Role-Based Access Control

Unified Management for Exchange and Active Directory

EmpowerID Exchange Manager automates and simplifies the complex process of provisioning, managing and auditing Microsoft Exchange mailboxes and contacts.

As the first and only solution built on a workflow and role-based access control platform, Exchange Manager delivers rapid ROI with the industry's most flexible and easy-to-use Microsoft Exchange mailbox management solution. Prior to Exchange 2007, administrators could use the extensions provided by Exchange to manage users and mailboxes from a single interface — the Active Directory Users and Computers console. With the advent of Exchange 2007, however, those extensions have been removed, forcing administrators to use different tools to accomplish the same tasks. Exchange Manager restores that capability, providing the much needed reunification of Active Directory and Exchange Management into a single console with a robust Role-Based Access Control security model that does not require granting or managing native Active Directory permissions.

Exchange Manager performs four critical security functions:

Role-Based Delegated Administration

Exchange Manager extends far beyond simple Exchange mailbox create, edit and delete functions — it provides dozens of workflows, as well as the workflow building blocks for customization, covering all aspects of Exchange mailbox management. The workflows perform the functions of the native Exchange management tools while adding granular delegation, workflow approvals, built-in activity reporting, naming convention enforcement, and task automation. Exchange Manager also offers full support for all Microsoft PowerShell management tasks for Exchange in easy-to-use graphical workflow shapes.

EmpowerID's powerful role-based delegation and administrative model closely matches the one found in Microsoft’s Exchange 2010, but is more expansive with an ability to manage all aspects of Active Directory and other types of managed directories and applications. Exchange Manager eliminates the need to delegate and manage the complex permissions in Active Directory and Exchange that technical and business users need to perform mailbox management tasks. Exchange Manager provides easy to use Web and WPF interfaces that drive powerful and customizable workflow processes.

The EmpowerID role model also extends beyond Exchange 2010's technical roles by creating business roles that reflect both job functions and organizational structure. For example, a change in job status or position as defined by an authoritative source, such as a corporate HR system, can trigger an automatic revision to a user's ability to perform Exchange management tasks.

User Self-Service

In addition to delegated administration, Exchange Manager opens up the ability to allow users to perform common tasks via self-service workflow processes. End users can be securely granted the right to perform a variety of actions based on their role, with requests exceeding their level of delegated ability being routed for approval. Common tasks include requesting resource mailboxes and increases in mailbox quotas, enabling mailbox features like ActiveSync, or requesting permissions for shared mailboxes. Exchange Manager delivers rapid cost savings by enabling workflow-based self-service to securely automate the management of a full range of Exchange resources.

Resource Forest and Cloud Support

Exchange Manager manages even the most complex Exchange environments, including those where Exchange resides in separate Active Directory Forests — even off-premise instances. A common model for B2B mail hosting is the Exchange Resource Forest. In this configuration, the Exchange Mailbox infrastructure is separated into an Active Directory forest that is distinct from the various user account forests. This complex scenario provides additional security benefits, but requires complex directory provisioning and synchronization between forests. Exchange Manager easily accommodates this and other complex scenarios by leveraging the metadirectory and sync services to manage the mailbox user accounts as a unit and to keep them synchronized. Provisioning, attribute flow, mailbox permissions enforcement, and de-provisioning are all handled in a unified and auditable manner with role-based security.

Detailed Exchange Inventory and Environment Reporting

Exchange Manager creates enhanced security with visibility, reporting and logging capabilities. Exchange Manager inventories your Exchange organizations and automatically discovers and monitors these systems for changes. This information is stored in the metadirectory and provides rich reporting of all aspects of Exchange mailboxes within your organization and the changes that occur to them. All management of Exchange mailboxes performed through EmpowerID includes a rich audit trail of activity that assists in meeting key requirements of corporate governance and compliance initiatives. Exchange Manager tells you what privileges a user has, when and why they were granted, and who approved them.

Why Exchange Manager

Few Active Directory management tools provide in-depth Exchange Management functionality and none provide all of the functionality contained in Exchange Manager. Exchange Manager delivers a complete solution that you won't outgrow. It offers:

  • A unified console - a single management console allowing full management of Exchange mailboxes in the same interface for managing users, groups, SharePoint sites, etc...
  • Deleted mailbox restoration - restore disconnected or deleted mailboxes while retaining all settings
  • Extensive and customizable workflow capabilities - its Microsoft Windows Workflow Foundation-based architecture allows complete customization of existing processes or creation of new processes to meet any business need
  • A PowerShell automation platform - its has the ability to utilize any PowerShell cmdlet as a protected operation in a workflow with granular delegation, approval routing and built-in audit logging
  • A powerful metadirectory - its metadirectory engine inventories and continuously monitors Active Directory for Exchange mailbox changes
  • A superior user experience - its flexible user interface options include web, Silverlight, and a rich WPF client.
  • Powerful Role-Based Access Control - its enterprise proven Role-Based Access Control model provides granular delegation and reporting of who has access to what