Solved

Exchange 2010 SP3, remote users unable to open shared mailboxes

Posted on 2014-10-06
9
451 Views
Last Modified: 2014-10-13
This weekend we had a scheduled power outage, so I shutdown all the servers at my site including the Exchange box.  Today users from a remote location who open a couple shared mailboxes that are hosted from my site are unable to do so.

I have verified those users are in the correct security group, that security groups is listed with Full Access to these two mailboxes.  Local users have no trouble opening the mailboxes in question.

I've checked the Event logs on both servers and am seeing nothing with regards to these two mailboxes, or the users trying to access them.

As a test I gave an Admin at the remote site Full Access to a totally different mailbox hosted here.. Outlook could not find that user.  What's more, the test admin in the remote site CAN see the test mailbox listed in the GAL.
0
Comment
Question by:Ben Hart
  • 6
  • 3
9 Comments
 
LVL 5

Expert Comment

by:Abdul Khadja Alaoudine
ID: 40363748
It looks to me it could be DNS issue. Test mailbox could be listed in the GAL because Outlook may have Offline Address Book cached.

From remote site see if you can ping / nslookup to Exchange servers and DCs.
0
 
LVL 14

Author Comment

by:Ben Hart
ID: 40363964
Test admin can ping my Exch server and the two DC's which are both GC's as well.  Ive also tried removing and re-adding the permissions which did not help.
0
 
LVL 5

Expert Comment

by:Abdul Khadja Alaoudine
ID: 40364058
What's the error message? Would you be able to provide screenshot?
0
Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

 
LVL 14

Author Comment

by:Ben Hart
ID: 40364308
The set of folders cannot be opened.  Exchange is not available, etc


sounds just like a network issue, but with pings and nslookups completing successfully from those desktops it can't be network related.  I found out two other users who have main mailboxes on that server but are also remotely opening the problematic mailboxes are doing so without issue.
0
 
LVL 5

Accepted Solution

by:
Abdul Khadja Alaoudine earned 500 total points
ID: 40365369
Do the following:

1. Remove full access to those users for the shared mailboxes
2. Run below PS command and disable Automapping

Add-MailboxPermission -Identity <shared mailbox> -User '<user needs access>' -AccessRight FullAccess -InheritanceType All -Automapping $false

See for more info - http://technet.microsoft.com/en-gb/library/hh529943(v=exchg.141).aspx

3. Open Outlook on users' PC who need access. In Outlook click on File --> Account Settings --> Account Settings --> Change --> More Settings --> Advanced --> Add

Let me know the result.
0
 
LVL 14

Author Comment

by:Ben Hart
ID: 40366814
I actually did the first half of your suggestion yesterday before posting here as suggested by some random blog I found.  Disabling Automapping as well.

I will find out what's in the Add box..
0
 
LVL 14

Author Comment

by:Ben Hart
ID: 40368374
I feel as though I should diagram this to help follower understand better.

SITE A                                                SITE B
Exch 1                                               Exch 2
remote user                                    Shared mailbox

Ok so last night I rebooted Exch 1.. all of this started because power was shut down in all of Site B and I had been able to bounce both DC's in SITE A so the only thing left was Exch 1.

The issue persists this morning though.  Remote Users cannot access the Shared Mailbox.  But still local users to SITE B can access the Shared Mailbox.

Here's an interesting thing though, my admin in SITE A whose bene helping me test.. after I bounce Exch 1 last night he says that he can now connect to a test shared mailbox..but he was over VPN.. not in the SITE A office.  What's doubly odd is that the VPN session terminated as an ASA 5500 in SITE A.  So the only thing different was the subnet he was on.
0
 
LVL 14

Assisted Solution

by:Ben Hart
Ben Hart earned 0 total points
ID: 40369114
Ok issue is resolved.

Long story short, on day one firs thing I did was check perms.  Both reporting users were in a security group who was given FullAccess rights to the problematic mailboxes.  I tried adding them specifically, which did not resolve the issue.

Last night I bounced their local Exchange server and the issue persists still.  Until I removed those explicit permission entries, after that and restarting their Outlook they could open the mailboxes just fine.

So moral of the story is.. two rights make a wrong?  Maybe this story has no moral.
0
 
LVL 14

Author Closing Comment

by:Ben Hart
ID: 40376637
the solution to my issue was half Abdul and half me.  He reminded me of the command to remove-mailboxpermissions but that was not the sole solution.
0

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Find out what you should include to make the best professional email signature for your organization.
This article outlines the process to identify and resolve account lockout in an Active Directory environment.
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…

820 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question