Solved

Can't Manage Full Access Permission on Mailbox Exchange 2007

Posted on 2014-02-10
4
1,467 Views
Last Modified: 2014-02-10
When trying to grant myself full access to a users mailbox I get the following error:

Warning:
The ACL for the object "CN=username,CN=OU,DC=Domain,DC=Domain" is not in canonical order (Deny/Allow/Inherited) and will be ignored.

Exchange Management Shell command completed:
Add-MailboxPermits -Identity  'CN=username,CN=OU,DC=Domain,DC=Domain' -User 'MyUsername' -AccessRights 'FullAccess'

Does anyone know how to resolve this?
0
Comment
Question by:Shawn
  • 2
  • 2
4 Comments
 
LVL 35

Accepted Solution

by:
Joseph Daly earned 245 total points
ID: 39847910
This looks wrong to me. Are you using the console or shell?

'CN=username,CN=OU,DC=Domain,DC=Domain

Distinguished name should look like below.

CN=George\, Curious,OU=container,OU=Test,DC=domain,DC=com
0
 
LVL 53

Expert Comment

by:Will Szymkowski
ID: 39847911
This is probably a permission inheritance issue. Open ADSIEdit, select "default naming context" navigate to the location above and right click select properties and check to ensure that the permissions are inherited from the parent folder.

Will.
0
 
LVL 35

Expert Comment

by:Joseph Daly
ID: 39847917
Assuming your distinguished name path above is correct this should be the correct form.

'CN=username,OU=OU,DC=Domain,DC=Domain
0
 
LVL 53

Expert Comment

by:Will Szymkowski
ID: 39847923
Read the post to fast, it is due to wrong format CN=username,OU=OUname,DC=domain,DC=com

Will.
0

Featured Post

Announcing the Most Valuable Experts of 2016

MVEs are more concerned with the satisfaction of those they help than with the considerable points they can earn. They are the types of people you feel privileged to call colleagues. Join us in honoring this amazing group of Experts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Background Information Recently I have fixed file server permission issues for one of my client. The client has 1800 users and one Windows Server 2008 R2 domain joined file server with 12 TB of data, 250+ shared folders and the folder structure i…
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an antispam), the admini…

685 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question