Share all details about your problem, including any error messages you may have received.
*I have requirement to set forwarding rights for a helpdesk team, where they can set forwarding onbehalf. I have granted “IdentityAdministrator” capability for the user, and they can be able to set forwarding for others using Identities->Identity Warehouse. But when trying via Manage Access->ManageAccounts and clicking on forwarding option getting error as “*The logged in user is not authorized to update the forwarding preference of the selected user”
In “IdentityAdministrator” capability, i can see the “SetIdentityForwarding” SPRights is part of it.
Why forwarding is not working from the manage account?
can you Exact go to the QuickLink Population (Dynamic Scope) tied to the “Manage Accounts” QuickLink, and add/expand its population definition so it includes the identities the helpdesk team needs to set forwarding for (or assign the helpdesk capability to a Dynamic Scope whose population covers those users). Once the target identities fall within that authorized population, the forwarding option in Manage Accounts will work — the SPRight alone isn’t sufficient for that entry point.
All configurations are already in place, the quick link population is configured with membership as “IdentityAdministrator” capability and enabled “Manage Accounts” quicklink and helpdesk team assigned with “IdentityAdministrator” capability.
And the users with capability can view the forwarding options as well.
@Sampath_Kumar , Good catch! It looks like the Manage Accounts forwarding endpoint also requires the Edit Identity QuickLink authorization in addition to SetIdentityForwarding.