Inherited Permissions and Exchange 2003

Posted on 2003-11-26
Last Modified: 2011-09-20
We upgraded from Win2k Domain Exch5.5 to Win2k3 Domain Exch2003.  Now I understand that the security and stuff is controlled from Active Directory Users and Computers (ADUC) now.  But I am experiencing a problem.

With Exch5.5 we could (locally on the mail server) open any users mailbox by changing the mailbox properties on the local outlook icon.  However with our new stuff we get 'access denied you do not have permission' even though we are logged in as a domain admin (=exchange admin).  

Looking in ADUC Exchange Advanced tab Mailbox Rights, advanced settings there is a deny line for 'Full Mailbox Access' for Domain admins, enterprise admins, Exchange domain servers  and Administrator.  IT's inheriting from someplace but I cannot figure out where.  There is no 'allow inheritance' checkbox to remove the inheritance like there is on file and folder permissions.

What gives?

Question by:wokwon
  • 4
  • 3
LVL 26

Expert Comment

ID: 9829521
If u go to ur ESM mailbox store properties psge\security can u give urself or admins full control including send as ans recieve as?

Author Comment

ID: 9829560
Well I *could* give send as and recieve as if i remove the inherititence from the mailbox store.  Will this allow 'Full Control' for admins to be applied for all mailboxes?  I don't want to be able to send as, I want to be able to open the mailbox in outlook from the server like I used to be able to in Exch5.5

Thanks for your suggestion.
LVL 26

Accepted Solution

Vahik earned 150 total points
ID: 9829561
Listen what the heck i am talking about.There should be an allow permission box so just check it.In 2000 and later that is by design and u should either enable it on individual basis or u go and give urself
full permission on the mailbox store.I misstook allow inheritance with allow permision box.
Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

LVL 26

Expert Comment

ID: 9829566
Just go to the specific users properties page \mailbox right and give urself allow full mailbox permission and u will be able to do what u want to do.

Author Comment

ID: 9829572
Bingo!  You are my hero.
LVL 26

Expert Comment

ID: 9829585
wokwon in order for u to have full mailbox right to any mailbox store
u must give urself send as and recive as permission on that store.In certain situations u may need to have that right like when u want to use exmerge to export all the users from a certain mailbox store.anyways thanks and goodluck.

Author Comment

ID: 9829593
"Just go to the specific users properties page \mailbox right and give urself allow full mailbox permission and u will be able to do what u want to do. " 

My problem was that the specific users properties page was inheriting from somewhere and I didn't know where.  As you said, it inherits from the information store.  In hindsight, that seems perfectly logical but previously had me stumped.

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Setup different mail flow for a few users - Exchange 2016. 3 24
Exchange 2010 DAG 18 60
Exchange 2013 not searching 9 35
.cer Exchange Certificate 2013 issue. 2 26
Local Continuous Replication is a cost effective and quick way of backing up Exchange server data. The following article describes the steps required to configure Local Continuous Replication. Also, the article tells you how to restore from a backup…
Learn to move / copy / export exchange contacts to iPhone without using any software. Also see the issues in configuration of exchange with iPhone to migrate contacts.
In this video we show how to create a Distribution Group in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >>…
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…

930 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now