Link to home
Start Free TrialLog in
Avatar of jbreg
jbreg

asked on

Can't Open the Mailbox of a Recently Enabled User (Error: -2147221231)

I have a user in our exchange 2003 / wserver 2003 environment who was disabled for the past few days, but who has an exchange mailbox. Today, someone needed access to his mailbox. I thought that simply re-enabling the account, and telling the user to go to open --> other user's folder in Outlook would do it (the user has privaledges to do this), but instead they get the error "Unable to display the folder. The information store could not be opened"

On the exchange machine, 2 errors are logged in event log:

Event ID 1022, Logon Failure on database "First Storage Group\Mailbox Store (Name)" - Windows 2000 account ECOURIERUK\user; mailbox /o=XXX/ou=First Administrative Group/cn=Recipients/cn=user.
Error: -2147221231

and

Disabled user /o=Name/ou=First Administrative Group/cn=Recipients/cn=user does not have a master account SID. Please use Active Directory MMC to set an active account as this user's master account.

Now, I looked these up and tried the fix that was suggested which was to open the user's account in AD and go to exchange advanced and ensure the self account was the "associated external account". There was nothing with this priv, so I assigned it to SELF. Then, I even went to ESM and set RUS to rebuild. Granted I haven't waited toolong, but I still get the same error messages in the event log, and I still can't logon to this user's mailbox.

Help!
Avatar of virag
virag
Flag of India image

run mailbox cleanup agent and reconnec the mailbox
Avatar of jbreg
jbreg

ASKER

Now things are a little stranger. Without doing anything (just waiting) I can now log on to the user's mailbox from outlook web access.

But, when I try and go to open--> other user's folder in outlook it says "Unable to display the folder. The inbox coudl not be found"

Should I still run mailbox cleanup agent and recconect? Could you give a more step-by-step on this?
yes trying running mailbox cleanup agent..see the results whether its giving a any errors i.e. red cross on the mail box or not..if yes just simply reconnect the mailbox with the user name.

ASKER CERTIFIED SOLUTION
Avatar of ikm7176
ikm7176
Flag of Saudi Arabia image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of jbreg

ASKER

Ok guys,

1. I have run the mailbox cleanup agent, no red cross or other errors. There is no option to reconnect (greyed out) as it seems to be properly connected.
2. When I try and open the mailbox from Outlook I still get an error "Unable to display the folder. The inbox folder could not be found"
3. I am able to acess the folder fine via OWA.

4. The account is enabled and SELF has priv of:
-read permissions
-full mailbox access
-associated external account

In sum, the problem is that despite following all the steps outlined, I can access the mbox from the web, but not by opening it in my Oultook. I have full mailbox access permissions to this user's mailbox.

What else could be wrong?
Exchange Full Administrators do not have the right to open any mailbox found on any server within the Exchange organization.

http://www.petri.co.il/grant_full_mailbox_rights_on_exchange_2000_2003.htm
http://www.petri.co.il/self_permission_on_exchange_mailboxes.htm

You enabled the account and associated external account to SELF account

You have to follow one out of the 2 options  

1. Allow AEA, where you will not enable the account, or
2. Renable the account and grant the SELF account FMA

Cheers !!
Avatar of jbreg

ASKER

No, mate, you don't understand, I have explicitly already given myself full control over all mailboxes on that server. There should not be any problem. The problem does not appear to be with permissions but rather something else.

This is an interesting one, because I just realised that the problem is that I get the same error with ANY user's mailbox I try to open via outlook:

If, from outlook 2003, I go to open --> other user's folder, then select the user and inbox (or anything else for that matter) I get

"Unable to display the folder. The <foldername> folder could not be found" (ie the calendar, inbox, or whatever I try to open.

Any ideas?
u as an admin have full mailbox rights on the mailbox store PLUS allow send as and allow
recieve as permission and still cant open other users mailbox???? this is starnge...
why dont u run forstprep and domain prep again...and see if that would help u...
This can happen if your account is missing the msExchMailboxSecurityDescriptor attribute.  Open ADSIEdit and find your account, open properties, and find this attribute.  If you see nothing in the box this is not it and you can ignore the rest of this.  But if you see <not set> then this is probably your issue.  The only way to repopulate this is with CDOEXM, your best bet is using a tool like ADModify (http://www.admodify.net) to set this.  On one of the Exchange tabs in the tool, there should be a check box called "set msExchMailboxSecurityDescriptor".
Avatar of jbreg

ASKER

I eventually got it to work by creating an AD group, giving that group full access to the exchange store, and making myself a member. I suspect the reason it did not work before that is because I was a member of groups (exchange admins and domain admins) which are explicitly barred from having read access to mailboxes.

http://support.microsoft.com/?kbid=262054

Worked for me...

However I'll award points for the help and pointing me in the right direction.