Can't move mailboxes from Exchange 2003 to 2010

I am currently working on a network that has 2 domains within the forest.  I recently implemented an Exchange 2010 server to replace the Exchange 2003 server.  These servers hold the mailboxes for users on both domains.  
I was able to move the mailboxes from 2003 to 2010 for all the users on the main domain.  However, when I attempt to move the mailboxes from the sub-domain, I get the following error:
Active directory failed on server1.  additional information: insufficient access rights to perform this operation:
Active directory response: 00002098: SecErr: DSID-03150A48. problem 4003 (INSUFF_ACCESS_RIGHTS). Data 0
the user has insufficient access rights

This occurs whether I am logged into the Exchange 2010 server as the administrator of the top domain or as the administrator of the sub domain.

What rights do I need to assign and to which administrator user?
CybertronnhAsked:
Who is Participating?
 
AkhaterCommented:
you need to run setup.com /preparedomain:fqdnofsubdomain
0
 
Paul MacDonaldDirector, Information SystemsCommented:
Make sure the user accounts in AD are set to inherit permissions.
0
 
Manpreet SIngh KhatraSolutions Architect, Project LeadCommented:
What credentails are used to move ?
Does the Admin or whatever creds used for Sub-domain have appropriate rights on Exchange and Users to perform the move ?

- Rancy
0
Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 
CybertronnhAuthor Commented:
I saw the article about setting the user's security properties to inherit permissions and on the mailbox I am experimenting with I have "include inheritable permissions from this object's parert" checked.  Still I am unable to move this mailbox
0
 
AkhaterCommented:
u need to prepare the domain run setup.com /preparedomain:fqdnofsubdomain
0
 
kj_syenceCommented:
Wait,

Did you check the box that said to allow inheritable permissions or was it already checked? If you just checked it then replication will have to take place before this setting will take effect. try forcing replication between all of your DC's if possible and restart the information store service in one location where a mailbox resides then try to move the mailbox again.
0
 
CybertronnhAuthor Commented:
I did the setup /perparedomain:fqdn and I was able to move the first mailbox.  I will update this question after I have moved the remaining maiboxes.  Thank you AKHater!
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.