jbreg
asked on
Can't Open the Mailbox of a Recently Enabled User (Error: -2147221231)
I have a user in our exchange 2003 / wserver 2003 environment who was disabled for the past few days, but who has an exchange mailbox. Today, someone needed access to his mailbox. I thought that simply re-enabling the account, and telling the user to go to open --> other user's folder in Outlook would do it (the user has privaledges to do this), but instead they get the error "Unable to display the folder. The information store could not be opened"
On the exchange machine, 2 errors are logged in event log:
Event ID 1022, Logon Failure on database "First Storage Group\Mailbox Store (Name)" - Windows 2000 account ECOURIERUK\user; mailbox /o=XXX/ou=First Administrative Group/cn=Recipients/cn=use r.
Error: -2147221231
and
Disabled user /o=Name/ou=First Administrative Group/cn=Recipients/cn=use r does not have a master account SID. Please use Active Directory MMC to set an active account as this user's master account.
Now, I looked these up and tried the fix that was suggested which was to open the user's account in AD and go to exchange advanced and ensure the self account was the "associated external account". There was nothing with this priv, so I assigned it to SELF. Then, I even went to ESM and set RUS to rebuild. Granted I haven't waited toolong, but I still get the same error messages in the event log, and I still can't logon to this user's mailbox.
Help!
On the exchange machine, 2 errors are logged in event log:
Event ID 1022, Logon Failure on database "First Storage Group\Mailbox Store (Name)" - Windows 2000 account ECOURIERUK\user; mailbox /o=XXX/ou=First Administrative Group/cn=Recipients/cn=use
Error: -2147221231
and
Disabled user /o=Name/ou=First Administrative Group/cn=Recipients/cn=use
Now, I looked these up and tried the fix that was suggested which was to open the user's account in AD and go to exchange advanced and ensure the self account was the "associated external account". There was nothing with this priv, so I assigned it to SELF. Then, I even went to ESM and set RUS to rebuild. Granted I haven't waited toolong, but I still get the same error messages in the event log, and I still can't logon to this user's mailbox.
Help!
run mailbox cleanup agent and reconnec the mailbox
ASKER
Now things are a little stranger. Without doing anything (just waiting) I can now log on to the user's mailbox from outlook web access.
But, when I try and go to open--> other user's folder in outlook it says "Unable to display the folder. The inbox coudl not be found"
Should I still run mailbox cleanup agent and recconect? Could you give a more step-by-step on this?
But, when I try and go to open--> other user's folder in outlook it says "Unable to display the folder. The inbox coudl not be found"
Should I still run mailbox cleanup agent and recconect? Could you give a more step-by-step on this?
yes trying running mailbox cleanup agent..see the results whether its giving a any errors i.e. red cross on the mail box or not..if yes just simply reconnect the mailbox with the user name.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
Ok guys,
1. I have run the mailbox cleanup agent, no red cross or other errors. There is no option to reconnect (greyed out) as it seems to be properly connected.
2. When I try and open the mailbox from Outlook I still get an error "Unable to display the folder. The inbox folder could not be found"
3. I am able to acess the folder fine via OWA.
4. The account is enabled and SELF has priv of:
-read permissions
-full mailbox access
-associated external account
In sum, the problem is that despite following all the steps outlined, I can access the mbox from the web, but not by opening it in my Oultook. I have full mailbox access permissions to this user's mailbox.
What else could be wrong?
1. I have run the mailbox cleanup agent, no red cross or other errors. There is no option to reconnect (greyed out) as it seems to be properly connected.
2. When I try and open the mailbox from Outlook I still get an error "Unable to display the folder. The inbox folder could not be found"
3. I am able to acess the folder fine via OWA.
4. The account is enabled and SELF has priv of:
-read permissions
-full mailbox access
-associated external account
In sum, the problem is that despite following all the steps outlined, I can access the mbox from the web, but not by opening it in my Oultook. I have full mailbox access permissions to this user's mailbox.
What else could be wrong?
Exchange Full Administrators do not have the right to open any mailbox found on any server within the Exchange organization.
http://www.petri.co.il/grant_full_mailbox_rights_on_exchange_2000_2003.htm
http://www.petri.co.il/self_permission_on_exchange_mailboxes.htm
You enabled the account and associated external account to SELF account
You have to follow one out of the 2 options
1. Allow AEA, where you will not enable the account, or
2. Renable the account and grant the SELF account FMA
Cheers !!
http://www.petri.co.il/grant_full_mailbox_rights_on_exchange_2000_2003.htm
http://www.petri.co.il/self_permission_on_exchange_mailboxes.htm
You enabled the account and associated external account to SELF account
You have to follow one out of the 2 options
1. Allow AEA, where you will not enable the account, or
2. Renable the account and grant the SELF account FMA
Cheers !!
ASKER
No, mate, you don't understand, I have explicitly already given myself full control over all mailboxes on that server. There should not be any problem. The problem does not appear to be with permissions but rather something else.
This is an interesting one, because I just realised that the problem is that I get the same error with ANY user's mailbox I try to open via outlook:
If, from outlook 2003, I go to open --> other user's folder, then select the user and inbox (or anything else for that matter) I get
"Unable to display the folder. The <foldername> folder could not be found" (ie the calendar, inbox, or whatever I try to open.
Any ideas?
This is an interesting one, because I just realised that the problem is that I get the same error with ANY user's mailbox I try to open via outlook:
If, from outlook 2003, I go to open --> other user's folder, then select the user and inbox (or anything else for that matter) I get
"Unable to display the folder. The <foldername> folder could not be found" (ie the calendar, inbox, or whatever I try to open.
Any ideas?
u as an admin have full mailbox rights on the mailbox store PLUS allow send as and allow
recieve as permission and still cant open other users mailbox???? this is starnge...
why dont u run forstprep and domain prep again...and see if that would help u...
recieve as permission and still cant open other users mailbox???? this is starnge...
why dont u run forstprep and domain prep again...and see if that would help u...
This can happen if your account is missing the msExchMailboxSecurityDescr iptor attribute. Open ADSIEdit and find your account, open properties, and find this attribute. If you see nothing in the box this is not it and you can ignore the rest of this. But if you see <not set> then this is probably your issue. The only way to repopulate this is with CDOEXM, your best bet is using a tool like ADModify (http://www.admodify.net) to set this. On one of the Exchange tabs in the tool, there should be a check box called "set msExchMailboxSecurityDescr iptor".
ASKER
I eventually got it to work by creating an AD group, giving that group full access to the exchange store, and making myself a member. I suspect the reason it did not work before that is because I was a member of groups (exchange admins and domain admins) which are explicitly barred from having read access to mailboxes.
http://support.microsoft.com/?kbid=262054
Worked for me...
However I'll award points for the help and pointing me in the right direction.
http://support.microsoft.com/?kbid=262054
Worked for me...
However I'll award points for the help and pointing me in the right direction.