Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win


Problem moving mailbox 'You do not have permission to log on'

Posted on 2006-11-14
Medium Priority
Last Modified: 2008-01-09
I moved a test mailbox from one exchange 2K server to another and now I am having problems opening the new mailbox. I can open the mailbox with outlook if I login as the owner of the mailbox, but what I am unable to do (but was before the move) is login as a domain admin and open that same mailbox. The error I get when I try to open the mail box is 'you do not have permission to log on'. But the domain admin account I am using has full access to the mailbox in question.

Is this behavior typical, and shouldn't I be able to access the mailbox if I am logged in as an admin with mailbox rights?

Thanks is Advance
Question by:gbarcalow
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
LVL 39

Accepted Solution

redseatechnologies earned 1000 total points
ID: 17941991
Hi gbarcalow,

This is somewhat typical (my Exchange 2000 knowledge is fading fast).

I know Exchange 2003 is like this, and vaguely remember 2000 to be the same;

If you want full admin access, follow this -> http://www.petri.co.il/grant_full_mailbox_rights_on_exchange_2000_2003.htm

Just reading that article again, it states that 2000 was also this way by default

Hope that helps,


Author Comment

ID: 17942167
Well that was interesting. Why would the access for domain admins be granted by default on the original server?

Assisted Solution

lollygagr earned 200 total points
ID: 17942174
Only one caveat about the article referenced above - the first two procedures will work great, but the third one (applying perms at the server level) has a big "gotcha".  It will work at first, but as you make moves and changes to mailboxes and stores, you will find that the inherited rights will mysteriously stop working on a growing number of mailboxes.  This is due to the fact that Exchange stores aren't Active Directory objects and don't inherit rights in the same way as accounts, groups, etc.  The only way to apply these rights and be sure new/moved mailboxes will inherit them consistently to work is to do it at the store level.

I found this one out the hard way a while back. :-)
LVL 39

Expert Comment

ID: 17942279
Someone would have made the changes initially on the existing server, which is why it was working, but now doesnt

By default, domain admins are explicitly denied access to users folders


Expert Comment

ID: 17944340
Actually that's a good example of the difference between Exchange permissions and Active Directory permissions.  The rule in AD is that deny entries in the ACL trump all other permissions.  The rule for Exchange objects like stores and mailboxes is that deny USUALLY trumps, EXCEPT when the deny is inherited and the allow permissions are explicitly defined at a lower level.  Active Directory and Exchange have to play in the same sandbox, but they don't play by the same rules.

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Know the reasons and solutions to move/import EDB to New Exchange Server. Also, find out how to recover an Exchange .edb file and to restore the file back.
Want to know how to use Exchange Server Eseutil command? Go through this article as it gives you the know-how.
In this video we show how to create an Address List in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Organization >> Ad…
In this video we show how to create an Accepted Domain in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Mail Flow >> Ac…
Suggested Courses

650 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question