msCCare
asked on
ACL Inheritance on Exchange 2003 Servers
We are in the process of transitioning from Exchange 2003 to 2010 and are having a permissions issue. So far, we have installed 2 CAS/HUB servers into the organization and the temporary routing groups have been automatically created. The problem is, our 2003 servers do not inherit permissions from above (for an unknown reason) and the new permissions for groups "Exchange Servers" and "Exchange Trusted Subsystem" are not present on any 2003 server.
We are afraid of just clicking the inherit permissions checkbox fearful that something will stop working. My question...is there a tool out there that will allow us to easily compare ACL permissions between parent and child? I was able to use dsacls to export but that is going to take a lot of sifting through. Or would it just be easier to add the new 2010 groups to each server node? I do see "Exchange Trusted Subsystem" has Full Permission and "Exchange Servers" have read and extended rights. Are there any other permissions to note?
We are afraid of just clicking the inherit permissions checkbox fearful that something will stop working. My question...is there a tool out there that will allow us to easily compare ACL permissions between parent and child? I was able to use dsacls to export but that is going to take a lot of sifting through. Or would it just be easier to add the new 2010 groups to each server node? I do see "Exchange Trusted Subsystem" has Full Permission and "Exchange Servers" have read and extended rights. Are there any other permissions to note?
ASKER
Thanks, that is a great document, but the issue still remains that we have permission issues on our 2003 server objects. We already ran all prerequisites, schema updates, and installed 2 CAS/HUB servers. Apparently, the Exchange 2010 install does not check for these permissions prior to installing.
You can use tool called dumpsec or user powershell command
get-acl -path x:\folderName\files.txt | FL AccessToString
To get the acl on the folder or file
get-acl -path x:\folderName\files.txt | FL AccessToString
To get the acl on the folder or file
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
Resolved on own
ASKER
Resolved on own
https://www.experts-exchange.com/Software/Server_Software/Email_Servers/Exchange/A_2881-Migrate-Small-Business-Server-2003-to-Exchange-2010-and-Windows-2008-R2.html
Read it all, mainly from section 6 for exchange and make sure you followed ALL the right steps