Solved

Inherited Permissions and Exchange 2003

Posted on 2003-11-26
7
963 Views
Last Modified: 2011-09-20
We upgraded from Win2k Domain Exch5.5 to Win2k3 Domain Exch2003.  Now I understand that the security and stuff is controlled from Active Directory Users and Computers (ADUC) now.  But I am experiencing a problem.

With Exch5.5 we could (locally on the mail server) open any users mailbox by changing the mailbox properties on the local outlook icon.  However with our new stuff we get 'access denied you do not have permission' even though we are logged in as a domain admin (=exchange admin).  

Looking in ADUC Exchange Advanced tab Mailbox Rights, advanced settings there is a deny line for 'Full Mailbox Access' for Domain admins, enterprise admins, Exchange domain servers  and Administrator.  IT's inheriting from someplace but I cannot figure out where.  There is no 'allow inheritance' checkbox to remove the inheritance like there is on file and folder permissions.

What gives?

0
Comment
Question by:wokwon
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
7 Comments
 
LVL 26

Expert Comment

by:Vahik
ID: 9829521
If u go to ur ESM mailbox store properties psge\security can u give urself or admins full control including send as ans recieve as?
0
 

Author Comment

by:wokwon
ID: 9829560
Well I *could* give send as and recieve as if i remove the inherititence from the mailbox store.  Will this allow 'Full Control' for admins to be applied for all mailboxes?  I don't want to be able to send as, I want to be able to open the mailbox in outlook from the server like I used to be able to in Exch5.5

Thanks for your suggestion.
0
 
LVL 26

Accepted Solution

by:
Vahik earned 150 total points
ID: 9829561
Listen what the heck i am talking about.There should be an allow permission box so just check it.In 2000 and later that is by design and u should either enable it on individual basis or u go and give urself
full permission on the mailbox store.I misstook allow inheritance with allow permision box.
0
Office 365 Training for Admins - 7 Day Trial

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

 
LVL 26

Expert Comment

by:Vahik
ID: 9829566
Just go to the specific users properties page \mailbox right and give urself allow full mailbox permission and u will be able to do what u want to do.
0
 

Author Comment

by:wokwon
ID: 9829572
Bingo!  You are my hero.
0
 
LVL 26

Expert Comment

by:Vahik
ID: 9829585
wokwon in order for u to have full mailbox right to any mailbox store
u must give urself send as and recive as permission on that store.In certain situations u may need to have that right like when u want to use exmerge to export all the users from a certain mailbox store.anyways thanks and goodluck.
0
 

Author Comment

by:wokwon
ID: 9829593
"Just go to the specific users properties page \mailbox right and give urself allow full mailbox permission and u will be able to do what u want to do. " 

My problem was that the specific users properties page was inheriting from somewhere and I didn't know where.  As you said, it inherits from the information store.  In hindsight, that seems perfectly logical but previously had me stumped.
0

Featured Post

Office 365 Training for Admins - 7 Day Trial

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article aims to explain the working of CircularLogArchiver. This tool was designed to solve the buildup of log file in cases where systems do not support circular logging or where circular logging is not enabled
Unified and professional email signatures help maintain a consistent company brand image to the outside world. This article shows how to create an email signature in Exchange Server 2010 using a transport rule and how to overcome native limitations …
This video discusses moving either the default database or any database to a new volume.
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…

729 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question