?
Solved

Can't move mailbox to Exchange 2010 from Exchange 2007

Posted on 2010-09-07
8
Medium Priority
?
649 Views
Last Modified: 2012-05-10
I have full DomainAdmin rights, but I'm unable to move or create a mailbox on my new Exchange 2010 server.  I've tried running the Full Access command with the Shell, but I still don't have the right permissions.
0
Comment
Question by:gharveyz28
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 2
  • 2
8 Comments
 
LVL 4

Expert Comment

by:PcGod718
ID: 33621793
i believe there is a diff between a domain admin and an exchange admin.  a couple of years ago, MS decided to flip a few security settings..   try making a user that is NOT a domain admin but IS an exchange enterprise server admin (either that or enterprise admin)  i forget which specifically is it..
0
 
LVL 3

Author Comment

by:gharveyz28
ID: 33621918
Sorry I'm a member of the following groups:

Domain Admins
Domain Users
Enterprise Admins
Exchange Organization Administrators
Organization Management
Recipient Management
Schema Admins
Server Management

Am I missing a group or should I remove a group?
0
 
LVL 1

Expert Comment

by:JoeBelliveau
ID: 33622139
Create a test user on the domain, set the password to a complex string and give the user just exchange org and public folder org admin rights, use said user while logged into the server and the on server exchange maagement console to try and create a mailbox.

Im betting you have a fundamental issue and it's not rights.

Run the Best practices analyzer from the toolbox as well if the second user account does not work.

I'd also add exchange reciepient admin to your rights group

0
Get real performance insights from real users

Key features:
- Total Pages Views and Load times
- Top Pages Viewed and Load Times
- Real Time Site Page Build Performance
- Users’ Browser and Platform Performance
- Geographic User Breakdown
- And more

 
LVL 4

Expert Comment

by:PcGod718
ID: 33622497
ugh, i hate not being around a faster system....
anyhoo.. if memory serves, theres a conflict now if you are a member of DOMAIN ADMINS and EXCHADMIN

i dont see that u listed EXCHADMIN, so im going to assume thats the group you need to be in to make the changes.

i think the procedure these days is to have a domain admins group and exchadmins and they are inherently separated.  there is some reg hack i think that lets you be a member of both.

so i would create a NEW user, called MAILADMIN, do NOT add them to Domain Admins, but DO add them to EXCHADMIN, see if that new user can do the mail stuff for you.
0
 
LVL 3

Author Comment

by:gharveyz28
ID: 33622895
Still an issue....
0
 
LVL 1

Expert Comment

by:JoeBelliveau
ID: 33623304
gharveyz28 can you show me the output of when you try and move the mailbox from the wizard ?

I have seen to many times in PS where people typo.

Is it a permissions denied message or a failure to find the box ?

Output please.
0
 
LVL 3

Author Comment

by:gharveyz28
ID: 33629054
Here is the error from the Local Move Request Wizard on the Exchange 2010 Server. (trying to move mailbox from 2007 to 2010).

Error:
Active Directory operation failed on Zeus.xxxx.xxxx.net. This error is not retriable. Additional information: Insufficient access rights to perform the operation.
Active directory response: 00002098: SecErr: DSID-03150E8A, problem 4003 (INSUFF_ACCESS_RIGHTS), data 0


The user has insufficient access rights.
Click here for help... http://technet.microsoft.com/en-US/library/ms.exch.err.default(EXCHG.140).aspx?v=14.1.218.11&t=exchgf1&e=ms.exch.err.Ex6AE46B

Exchange Management Shell command attempted:
'xxxx.xxxx.net/CORP/ITS/Systems/Gxxx - Domain Admin account' | New-MoveRequest -TargetDatabase 'San Jose'

Elapsed Time: 00:00:11
0
 
LVL 3

Accepted Solution

by:
gharveyz28 earned 0 total points
ID: 33632047
Solved it.

I removed myself from every Exchange Group except:

Exchange Organization Administrators
Organization Administrators
Server Management

I guess I was a member of a group with more restrictive permissions.
0

Featured Post

VIDEO: THE CONCERTO CLOUD FOR HEALTHCARE

Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you troubleshoot Outlook for clients, you may want to know a bit more about the OST file before doing your next job. IMAP can cause a lot of drama if removed in the accounts without backing up.
There are times when we need to generate a report on the inbox rules, where users have set up forwarding externally in their mailbox. In this article, I will be sharing a script I wrote to generate the report in CSV format.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
Suggested Courses

765 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question