Send As Permissions Exchange 2007

I posted a question previously about this and the solution worked, however it isn't really a solution at this time.  I'm trying to grant John permissions to send as (send on behalf) of sales in Exchange 2007.  I have given the following command in the EMC as well as in the gui to give Send as permissions and Send on Behalf of.

Add-ADPermission "sales" -User "john" -Extendedrights "Send As"

The way I am having John send as sales is to put in the From line in Outlook.  He then receives the Exchange Delivery notification that he doesn't have permission when attempting to send as sales.  The only way I can get it to work is if I recreate the Outlook profile.  Unfortunately this isn't an option with this user.

Is there something else I can do? It's been over 24 hours so I know the changes have replicated.
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Is Sales a user defined in AD or in Exchange? In other words does it have it's own mailbox/username? If not I do not believe you can do this, because you cant send as if the as is a contact or alternate SMTP address.
wakebrdr77Author Commented:
It has its own AD account and mailbox.  This can be done as I already have other users set up to send as Sales.  I had to recreate their Outlook profile in order for it to work though. I don't want to have to do that this time.  It should be more simple than this.
Send As and Grand Send on behalf is different.  In your case, you should configure as a ditribution group and configure john to send on behalf.  

Set-DistributionGroup "Sales" -GrantSendOnBehalfTo "John","Marc","Peter"

GrantSendOnBehalfTo is a multi-valued properties.  You must have all users when you set the properties.  You could not run the following for example :

Set-DistributionGroup "Distribution Group Name" -GrantSendOnBehalfTo "John"
Set-DistributionGroup "Distribution Group Name" -GrantSendOnBehalfTo "Marc"
Set-DistributionGroup "Distribution Group Name" -GrantSendOnBehalfTo "Peter"

Only Peter would have the permission to send on behalf.

Now if you want to set SendAs use this command

Add-AdPermission "Sales" -user -AccessRights extendedright -ExtendedRights "send as"

Note: “Send as” as precedence over “Send on behalf” if you configure both.
Making Bulk Changes to Active Directory

Watch this video to see how easy it is to make mass changes to Active Directory from an external text file without using complicated scripts.

wakebrdr77Author Commented:
Thanks for the clarification martingagnon. I know I don't want to use Send on Behalf as I do not want the recipient to know the true sender.

The command Add-AdPermission "Sales" -user -AccessRights extendedright -ExtendedRights "send as" has already been set for John.

He is still receiving the nondeliverable message.
Verify that the permission have been applied correctly by running the following command:

Get-AdPermission "Sales" -User

Note : Instead of Sales, you may have to enter the full name domain/OU/Sales

It should return something like :
User                : domain\john
Identity            : domain/OU/Sales
Deny                : False
AccessRights        : {ExtendedRight}
ExtendedRights      : {Send-As}
IsInherited         : False
Properties          :
ChildObjectTypes    :
InheritedObjectType :
InheritanceType     : All

If it returns nothing, it means no permissions has been set for this user.
wakebrdr77Author Commented:
I have exactly that as you showed above, so it appears the permissions have been set.
Has the user logged off and logged back on to get his new security token?  If not, make sure he reboots completely the computer he is using to send as using Outlook.
wakebrdr77Author Commented:
No, he hasn't, but that probably won't happen until he leaves for the day.  I'll update this again tomorrow. Thanks for your help so far.
The Send As permission is not granted until after replication has occurred. Replication times depend on your Microsoft Exchange and network configuration. To grant the permission immediately, stop and then restart the Microsoft Exchange Information Store service.
Be aware that you cannot send e-mail messages on behalf of a mailbox if the mailbox is hidden from address lists. When sending a message, Exchange requires that an e-mail address is resolved in the From field. In the case where a message is sent on behalf of a mailbox that is hidden from address lists, the SMTP address is interpreted as an address that is not from your organization (known as a foreign address) and is rejected.  

So make sure you select the address from the global address list.  If the user has created a contact named in his personnal contact, the recipient resolver may try to send as this smtp address.  By selecting, you are sure to use the correct object.
wakebrdr77Author Commented:
The address is available in the global address book.  Also, it's been 3 days for replication and the user still can't send as.  I guess I'm going to have to recreate the profile.
How about you copy his profile with a new name?  That would be quicker than creating from scratch a new profile.  Also, what version is the Microsoft Outlook Client?
wakebrdr77Author Commented:
I'm just going to recreate it, I know that it works that way.  It's Outlook 2007. Thanks for your help.
Shreedhar EtteCommented:

Refer this article:

and search for "Granting Send As Permission"

Hope this helps,

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today

From novice to tech pro — start learning today.