[Last Call] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

Can't move mailbox to Exchange 2010 from Exchange 2007

Posted on 2010-09-07
8
Medium Priority
?
652 Views
Last Modified: 2012-05-10
I have full DomainAdmin rights, but I'm unable to move or create a mailbox on my new Exchange 2010 server.  I've tried running the Full Access command with the Shell, but I still don't have the right permissions.
0
Comment
Question by:gharveyz28
  • 4
  • 2
  • 2
8 Comments
 
LVL 4

Expert Comment

by:PcGod718
ID: 33621793
i believe there is a diff between a domain admin and an exchange admin.  a couple of years ago, MS decided to flip a few security settings..   try making a user that is NOT a domain admin but IS an exchange enterprise server admin (either that or enterprise admin)  i forget which specifically is it..
0
 
LVL 3

Author Comment

by:gharveyz28
ID: 33621918
Sorry I'm a member of the following groups:

Domain Admins
Domain Users
Enterprise Admins
Exchange Organization Administrators
Organization Management
Recipient Management
Schema Admins
Server Management

Am I missing a group or should I remove a group?
0
 
LVL 1

Expert Comment

by:JoeBelliveau
ID: 33622139
Create a test user on the domain, set the password to a complex string and give the user just exchange org and public folder org admin rights, use said user while logged into the server and the on server exchange maagement console to try and create a mailbox.

Im betting you have a fundamental issue and it's not rights.

Run the Best practices analyzer from the toolbox as well if the second user account does not work.

I'd also add exchange reciepient admin to your rights group

0
Creating Active Directory Users from a Text File

If your organization has a need to mass-create AD user accounts, watch this video to see how its done without the need for scripting or other unnecessary complexities.

 
LVL 4

Expert Comment

by:PcGod718
ID: 33622497
ugh, i hate not being around a faster system....
anyhoo.. if memory serves, theres a conflict now if you are a member of DOMAIN ADMINS and EXCHADMIN

i dont see that u listed EXCHADMIN, so im going to assume thats the group you need to be in to make the changes.

i think the procedure these days is to have a domain admins group and exchadmins and they are inherently separated.  there is some reg hack i think that lets you be a member of both.

so i would create a NEW user, called MAILADMIN, do NOT add them to Domain Admins, but DO add them to EXCHADMIN, see if that new user can do the mail stuff for you.
0
 
LVL 3

Author Comment

by:gharveyz28
ID: 33622895
Still an issue....
0
 
LVL 1

Expert Comment

by:JoeBelliveau
ID: 33623304
gharveyz28 can you show me the output of when you try and move the mailbox from the wizard ?

I have seen to many times in PS where people typo.

Is it a permissions denied message or a failure to find the box ?

Output please.
0
 
LVL 3

Author Comment

by:gharveyz28
ID: 33629054
Here is the error from the Local Move Request Wizard on the Exchange 2010 Server. (trying to move mailbox from 2007 to 2010).

Error:
Active Directory operation failed on Zeus.xxxx.xxxx.net. This error is not retriable. Additional information: Insufficient access rights to perform the operation.
Active directory response: 00002098: SecErr: DSID-03150E8A, problem 4003 (INSUFF_ACCESS_RIGHTS), data 0


The user has insufficient access rights.
Click here for help... http://technet.microsoft.com/en-US/library/ms.exch.err.default(EXCHG.140).aspx?v=14.1.218.11&t=exchgf1&e=ms.exch.err.Ex6AE46B

Exchange Management Shell command attempted:
'xxxx.xxxx.net/CORP/ITS/Systems/Gxxx - Domain Admin account' | New-MoveRequest -TargetDatabase 'San Jose'

Elapsed Time: 00:00:11
0
 
LVL 3

Accepted Solution

by:
gharveyz28 earned 0 total points
ID: 33632047
Solved it.

I removed myself from every Exchange Group except:

Exchange Organization Administrators
Organization Administrators
Server Management

I guess I was a member of a group with more restrictive permissions.
0

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Stellar Exchange Toolkit: this 5 in 1 toolkit comes loaded with mega-software tool. Here’s an introduction to tools’ usage and advantages:
Eseutil Hard Recovery is part of exchange tool and ensures Exchange mailbox data recovery when mailbox gets corrupt due to some problem on Exchange server.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…
Suggested Courses

830 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question