[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now


Problem moving mailbox 'You do not have permission to log on'

Posted on 2006-11-14
Medium Priority
Last Modified: 2008-01-09
I moved a test mailbox from one exchange 2K server to another and now I am having problems opening the new mailbox. I can open the mailbox with outlook if I login as the owner of the mailbox, but what I am unable to do (but was before the move) is login as a domain admin and open that same mailbox. The error I get when I try to open the mail box is 'you do not have permission to log on'. But the domain admin account I am using has full access to the mailbox in question.

Is this behavior typical, and shouldn't I be able to access the mailbox if I am logged in as an admin with mailbox rights?

Thanks is Advance
Question by:gbarcalow
  • 2
  • 2
LVL 39

Accepted Solution

redseatechnologies earned 1000 total points
ID: 17941991
Hi gbarcalow,

This is somewhat typical (my Exchange 2000 knowledge is fading fast).

I know Exchange 2003 is like this, and vaguely remember 2000 to be the same;

If you want full admin access, follow this -> http://www.petri.co.il/grant_full_mailbox_rights_on_exchange_2000_2003.htm

Just reading that article again, it states that 2000 was also this way by default

Hope that helps,


Author Comment

ID: 17942167
Well that was interesting. Why would the access for domain admins be granted by default on the original server?

Assisted Solution

lollygagr earned 200 total points
ID: 17942174
Only one caveat about the article referenced above - the first two procedures will work great, but the third one (applying perms at the server level) has a big "gotcha".  It will work at first, but as you make moves and changes to mailboxes and stores, you will find that the inherited rights will mysteriously stop working on a growing number of mailboxes.  This is due to the fact that Exchange stores aren't Active Directory objects and don't inherit rights in the same way as accounts, groups, etc.  The only way to apply these rights and be sure new/moved mailboxes will inherit them consistently to work is to do it at the store level.

I found this one out the hard way a while back. :-)
LVL 39

Expert Comment

ID: 17942279
Someone would have made the changes initially on the existing server, which is why it was working, but now doesnt

By default, domain admins are explicitly denied access to users folders


Expert Comment

ID: 17944340
Actually that's a good example of the difference between Exchange permissions and Active Directory permissions.  The rule in AD is that deny entries in the ACL trump all other permissions.  The rule for Exchange objects like stores and mailboxes is that deny USUALLY trumps, EXCEPT when the deny is inherited and the allow permissions are explicitly defined at a lower level.  Active Directory and Exchange have to play in the same sandbox, but they don't play by the same rules.

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The main intent of this article is to make you aware of ‘Exchange fail to mount’ error, its effects, causes, and solution.
If something goes wrong with Exchange, your IT resources are in trouble.All Exchange server migration processes are not designed to be identical and though migrating email from on-premises Exchange mailbox to Cloud’s Office 365 is relatively simple…
In this video we show how to create an email address policy in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Mail Flow…
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…
Suggested Courses
Course of the Month19 days, 13 hours left to enroll

873 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question