Solved

New Exchagne 2010 server can't see AD users to create new mailbox's

Posted on 2013-12-17
6
375 Views
Last Modified: 2014-01-08
This seems like a very strange issue.  OK, I have Exchange 2010 SP1 on Server 2008. Two DC both Server 2008.  

When I go to add mailbox's via Exchange console, I search for AD users and only the users I created within the past 5 days show up.  I even created a test account prior to this question and it shows up.  However, all of the original users do not show up.  Keep in mind, the test account I created is in the same OU as all of the other accounts.  

I am also getting MSExchange ADAccess warnings on all of the existing users...

Process w3wp.exe () (PID=4364). Recipient object CN=user,OU=Phone Team,OU=Employees,DC=domain,DC=com read from server-Server.domain.com failed validation and will be excluded from the result set.  Set event logging level for Validation category to Expert to get additional events about each failure.

Please assist me with this one.  I am lost!
0
Comment
Question by:sXmont1j6
6 Comments
 
LVL 56

Expert Comment

by:Cliff Galiher
ID: 39725382
First guess is that at one time someone went and changed the permissions on one of your AD subtrees and had the permissions propogate to all child objects. Those objects, if the permissions were set wrong, would be unreadable by Exchange. New objects would, of course, get default permissions and work fine.

Compare the permissions on two objects, one that works, and one that doesn't, and find out where they got changed.
0
 

Author Comment

by:sXmont1j6
ID: 39725657
I am sorry, I don't know what you mean, permissions on the user objects?  I am not clear on what you want me to compare.
0
 
LVL 35

Expert Comment

by:Mahesh
ID: 39725952
What Exchange role permissions you have on account used for creating mailboxes?
Check below article for role assignment
http://blog.pluralsight.com/exchange-2010-role-based-access-control
Try creating new user with recipient management \ organization management permissions and check if he is able see all users in AD
Also you need to add above id to local administrators group on exchange server

If above works, then you can compare permissions of old ID with new one.

Mahesh
0
Do email signature updates give you a headache?

Are you constantly making changes to email signatures? Are the images not formatting how you want them to? Want high-quality HTML signatures on all devices, including on mobiles and Macs? Then, let Exclaimer solve all your email signature problems today.

 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 39729358
First - Exchange 2010 SP1 is very old and no longer supported. The first thing I would do is upgrade to Exchange 2010 Sp3 and the latest rollup so that you are on a supported platform.

If the users are all in the same OU, then in the properties of the OU reset the inheritance, to include the child objects. As already pointed out, this probably does not include the Exchange system objects. It could also be that inheritance is disabled on those objects and you need to enable it.

Simon.
0
 

Accepted Solution

by:
sXmont1j6 earned 0 total points
ID: 39754266
The problem was that I was on a hosted platform and AD already saw that the accounts had mailboxes.  I had to disable them and then re-add the accounts in Exchange.
0
 

Author Closing Comment

by:sXmont1j6
ID: 39764678
The problem was that I was on a hosted platform and AD already saw that the accounts had mailboxes.  I had to disable them and then re-add the accounts in Exchange.
0

Featured Post

Zoho SalesIQ

Hassle-free live chat software re-imagined for business growth. 2 users, always free.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This process describes the steps required to Import and Export data from and to .pst files using Exchange 2010. We can use these steps to export data from a user to a .pst file, import data back to the same or a different user, or even import data t…
Following basic email etiquette rules will help you write a professional email and achieve a good, lasting impression with your contacts.
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now