?
Solved

Running ExMerge on an Exchange Server that is a DC

Posted on 2010-09-13
7
Medium Priority
?
507 Views
Last Modified: 2012-06-21
So I have a Catch 22 here... I need to run Exmerge to get a copy of some mailboxes but my Exchange 2003 server is a DC. I created a special user and delegated control as you are supposed to do but it still doesn't work because the user has to be a member of the Local Admin group which we all know does not exist on a DC. But if I use an account that is a member of Domain Admins or Enterprise Admins there is an explicit DENY permission.

Is my only option to change the permissions on the store and remove the DENY for the Domain Admins? I really hate to do that...

0
Comment
Question by:EGSAdmin
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
7 Comments
 
LVL 32

Accepted Solution

by:
endital1097 earned 2000 total points
ID: 33667691
add that user with receive-as and send-as permission to the mailbox store within exchange system manager
an explicit allow overrides the deny granted to domain admins
0
 
LVL 34

Expert Comment

by:Shreedhar Ette
ID: 33667743
Hi,

Refer this article:
http://support.microsoft.com/kb/292509

Hope this helps,
Shree
0
 
LVL 28

Expert Comment

by:sunnyc7
ID: 33668096
can you get the exmerge log from
c:\program files\exchsrvr\bin

or the location you are running exmerge from.

that may provide clues.

thanks
0
Office 365 Training for IT Pros

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

 

Author Comment

by:EGSAdmin
ID: 33668562
Ok, I thought the Deny always took precidence, I did not relaize there wasa difference if the permission was inherited. I will try the chage tomorrow and see if that works.

Is there any way to get the user I created per the above KB article to work? This would not be an issue accept the Exchange Server is running as a DC also so it is not a local admin on the exchange server...
0
 
LVL 32

Expert Comment

by:endital1097
ID: 33668566
exchange is different here where the explicit allow will override the deny
you just need to assign the permission at the database level
0
 
LVL 17

Expert Comment

by:lucid8
ID: 33671182
Advice above is correct on user for ExMerge, however, if that fails, check out http://www.lucid8.com/product/digiscope.asp 
Troy
0
 

Author Comment

by:EGSAdmin
ID: 33672933
OK, so I got it to work by just giving an Member of Domain Admins an Explicit Allow... Even though when you change the permissions it says that the deny will take precedence...
New-Bitmap-Image.bmp
0

Featured Post

Veeam Task Manager for Hyper-V

Task Manager for Hyper-V provides critical information that allows you to monitor Hyper-V performance by displaying real-time views of CPU and memory at the individual VM-level, so you can quickly identify which VMs are using host resources.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

As tax season makes its return, so does the increase in cyber crime and tax refund phishing that comes with it
This article provides a convenient collection of links to Microsoft provided Security Patches for operating systems that have reached their End of Life support cycle. Included operating systems covered by this article are Windows XP,  Windows Server…
In this video we show how to create a Resource Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: Navigate to the Recipients >> Resources tab.: "Recipients" is our default selection …
The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager
Suggested Courses
Course of the Month12 days, 18 hours left to enroll

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question