Solved

Don't have permission to open users accounts on second exchange server

Posted on 2006-11-23
6
221 Views
Last Modified: 2010-03-06
I seem to be experiencing a frustrating issue. I am running a site with around 50 users. We are in the process of migrating and splitting users across both exchange servers. The Master exchange server is a Exchange 2000 server on Windows 2000 server. The second (new) server is an Exchange 2003 on a 20003 server.

I have just migrated myself and a few other test accounts across to the new exchange server. The problem is I can't seem to be able to open other users accounts (in outlook - File, Open, Other Users Folders) that have been migrated to the new server. Everyones accounts on the old server are fine and accessible but not on the new server. My own folder is fine (on x23k).

I have checked the Permissions under Exchange System Manager, Administrative Groups, Site Name, Servers, server #2 and it mirrors the master server in regards to security settings.

I have also checked under Mailbox Store as well and as far as I can see I should have access. I am also a member of the Enterprise and domain admin groups.

Any ideas or leads?

Paul

0
Comment
Question by:dusty_nz
  • 3
  • 2
6 Comments
 
LVL 104

Accepted Solution

by:
Sembee earned 250 total points
ID: 18005366
That is by design.
Administrators are denied access by default. Deny overrides allow.

As far as I am concerned there is no reason why administrators need access to all mailboxes and it isn't a permission that I want to have. I do not have that permission on any of the sites that I manage.

If you want to grant that permission then you will have to set it specifically on the server.

http://support.microsoft.com/default.aspx?kbid=821897

However I stress again that this permission is not required for the day to day administrator of an Exchange server if the server has been setup correctly.

Simon.
0
 
LVL 10

Expert Comment

by:MATTHEW_L
ID: 18015128
Is there somthing imperticular that you are looking to acheive by having access to other users folders?  Like Simon said this isnt something that is usually done and is designed that way by default.  I also do not have permission to read anything in any of the mailboxes that I manage.  There are other ways of acheiving most objectives without these settings.
0
 

Author Comment

by:dusty_nz
ID: 18015808
The reason is that I am often asked to set Out of office, Search peoples email accounts (When they are away and need to find accomodation name etc) and archiving of old users accounts.

Nothing covert but certainly makes everything a lot easier.

Paul
0
Top 6 Sources for Identifying Threat Actor TTPs

Understanding your enemy is essential. These six sources will help you identify the most popular threat actor tactics, techniques, and procedures (TTPs).

 
LVL 10

Expert Comment

by:MATTHEW_L
ID: 18015812
Well then follow article SemBee sent and you should be ready to go.
0
 
LVL 104

Expert Comment

by:Sembee
ID: 18016048
If when I get those requests, I will grant myself the required permission on demand, do what is required then remove the permission. Then I cannot be accused of accessing something that I don't need to.

Ex-user accounts are different, and the permissions on those don't really come in to same category. Although again I will grant permissions on demand.

Simon.
0
 
LVL 10

Expert Comment

by:MATTHEW_L
ID: 18016056
What I have done for ex-user accounts is either use exmerge to a pst or reset the password on the account.
0

Featured Post

Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

Join & Write a Comment

"Migrate" an SMTP relay receive connector to a new server using info from an old server.
Marketers need statistics and metrics like everybody else needs oxygen. In this article we explain how to enable marketing campaign statistics for Microsoft Exchange mail.
In this video we show how to create a User Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Mailb…
To show how to generate a certificate request in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Servers >> Certificates…

747 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now