Solved

Can't move mailbox to Exchange 2010 from Exchange 2007

Posted on 2010-09-07
8
648 Views
Last Modified: 2012-05-10
I have full DomainAdmin rights, but I'm unable to move or create a mailbox on my new Exchange 2010 server.  I've tried running the Full Access command with the Shell, but I still don't have the right permissions.
0
Comment
Question by:gharveyz28
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 2
  • 2
8 Comments
 
LVL 4

Expert Comment

by:PcGod718
ID: 33621793
i believe there is a diff between a domain admin and an exchange admin.  a couple of years ago, MS decided to flip a few security settings..   try making a user that is NOT a domain admin but IS an exchange enterprise server admin (either that or enterprise admin)  i forget which specifically is it..
0
 
LVL 3

Author Comment

by:gharveyz28
ID: 33621918
Sorry I'm a member of the following groups:

Domain Admins
Domain Users
Enterprise Admins
Exchange Organization Administrators
Organization Management
Recipient Management
Schema Admins
Server Management

Am I missing a group or should I remove a group?
0
 
LVL 1

Expert Comment

by:JoeBelliveau
ID: 33622139
Create a test user on the domain, set the password to a complex string and give the user just exchange org and public folder org admin rights, use said user while logged into the server and the on server exchange maagement console to try and create a mailbox.

Im betting you have a fundamental issue and it's not rights.

Run the Best practices analyzer from the toolbox as well if the second user account does not work.

I'd also add exchange reciepient admin to your rights group

0
NEW Veeam Agent for Microsoft Windows

Backup and recover physical and cloud-based servers and workstations, as well as endpoint devices that belong to remote users. Avoid downtime and data loss quickly and easily for Windows-based physical or public cloud-based workloads!

 
LVL 4

Expert Comment

by:PcGod718
ID: 33622497
ugh, i hate not being around a faster system....
anyhoo.. if memory serves, theres a conflict now if you are a member of DOMAIN ADMINS and EXCHADMIN

i dont see that u listed EXCHADMIN, so im going to assume thats the group you need to be in to make the changes.

i think the procedure these days is to have a domain admins group and exchadmins and they are inherently separated.  there is some reg hack i think that lets you be a member of both.

so i would create a NEW user, called MAILADMIN, do NOT add them to Domain Admins, but DO add them to EXCHADMIN, see if that new user can do the mail stuff for you.
0
 
LVL 3

Author Comment

by:gharveyz28
ID: 33622895
Still an issue....
0
 
LVL 1

Expert Comment

by:JoeBelliveau
ID: 33623304
gharveyz28 can you show me the output of when you try and move the mailbox from the wizard ?

I have seen to many times in PS where people typo.

Is it a permissions denied message or a failure to find the box ?

Output please.
0
 
LVL 3

Author Comment

by:gharveyz28
ID: 33629054
Here is the error from the Local Move Request Wizard on the Exchange 2010 Server. (trying to move mailbox from 2007 to 2010).

Error:
Active Directory operation failed on Zeus.xxxx.xxxx.net. This error is not retriable. Additional information: Insufficient access rights to perform the operation.
Active directory response: 00002098: SecErr: DSID-03150E8A, problem 4003 (INSUFF_ACCESS_RIGHTS), data 0


The user has insufficient access rights.
Click here for help... http://technet.microsoft.com/en-US/library/ms.exch.err.default(EXCHG.140).aspx?v=14.1.218.11&t=exchgf1&e=ms.exch.err.Ex6AE46B

Exchange Management Shell command attempted:
'xxxx.xxxx.net/CORP/ITS/Systems/Gxxx - Domain Admin account' | New-MoveRequest -TargetDatabase 'San Jose'

Elapsed Time: 00:00:11
0
 
LVL 3

Accepted Solution

by:
gharveyz28 earned 0 total points
ID: 33632047
Solved it.

I removed myself from every Exchange Group except:

Exchange Organization Administrators
Organization Administrators
Server Management

I guess I was a member of a group with more restrictive permissions.
0

Featured Post

Office 365 Training for IT Pros

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I was prompted to write this article after the recent World-Wide Ransomware outbreak. For years now, System Administrators around the world have used the excuse of "Waiting a Bit" before applying Security Patch Updates. This type of reasoning to me …
Sometimes clients can lose connectivity with the Lotus Notes Domino Server, but there's not always an obvious answer as to why it happens.   Read this article to follow one of the first experiences I had with Lotus Notes on a client's machine, my…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…

717 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question