Exchange 2010 SP3, remote users unable to open shared mailboxes

This weekend we had a scheduled power outage, so I shutdown all the servers at my site including the Exchange box.  Today users from a remote location who open a couple shared mailboxes that are hosted from my site are unable to do so.

I have verified those users are in the correct security group, that security groups is listed with Full Access to these two mailboxes.  Local users have no trouble opening the mailboxes in question.

I've checked the Event logs on both servers and am seeing nothing with regards to these two mailboxes, or the users trying to access them.

As a test I gave an Admin at the remote site Full Access to a totally different mailbox hosted here.. Outlook could not find that user.  What's more, the test admin in the remote site CAN see the test mailbox listed in the GAL.
LVL 14
Ben HartAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Abdul Khadja AlaoudineTechnical ConsultantCommented:
It looks to me it could be DNS issue. Test mailbox could be listed in the GAL because Outlook may have Offline Address Book cached.

From remote site see if you can ping / nslookup to Exchange servers and DCs.
Ben HartAuthor Commented:
Test admin can ping my Exch server and the two DC's which are both GC's as well.  Ive also tried removing and re-adding the permissions which did not help.
Abdul Khadja AlaoudineTechnical ConsultantCommented:
What's the error message? Would you be able to provide screenshot?
Big Business Goals? Which KPIs Will Help You

The most successful MSPs rely on metrics – known as key performance indicators (KPIs) – for making informed decisions that help their businesses thrive, rather than just survive. This eBook provides an overview of the most important KPIs used by top MSPs.

Ben HartAuthor Commented:
The set of folders cannot be opened.  Exchange is not available, etc

sounds just like a network issue, but with pings and nslookups completing successfully from those desktops it can't be network related.  I found out two other users who have main mailboxes on that server but are also remotely opening the problematic mailboxes are doing so without issue.
Abdul Khadja AlaoudineTechnical ConsultantCommented:
Do the following:

1. Remove full access to those users for the shared mailboxes
2. Run below PS command and disable Automapping

Add-MailboxPermission -Identity <shared mailbox> -User '<user needs access>' -AccessRight FullAccess -InheritanceType All -Automapping $false

See for more info -

3. Open Outlook on users' PC who need access. In Outlook click on File --> Account Settings --> Account Settings --> Change --> More Settings --> Advanced --> Add

Let me know the result.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Ben HartAuthor Commented:
I actually did the first half of your suggestion yesterday before posting here as suggested by some random blog I found.  Disabling Automapping as well.

I will find out what's in the Add box..
Ben HartAuthor Commented:
I feel as though I should diagram this to help follower understand better.

SITE A                                                SITE B
Exch 1                                               Exch 2
remote user                                    Shared mailbox

Ok so last night I rebooted Exch 1.. all of this started because power was shut down in all of Site B and I had been able to bounce both DC's in SITE A so the only thing left was Exch 1.

The issue persists this morning though.  Remote Users cannot access the Shared Mailbox.  But still local users to SITE B can access the Shared Mailbox.

Here's an interesting thing though, my admin in SITE A whose bene helping me test.. after I bounce Exch 1 last night he says that he can now connect to a test shared mailbox..but he was over VPN.. not in the SITE A office.  What's doubly odd is that the VPN session terminated as an ASA 5500 in SITE A.  So the only thing different was the subnet he was on.
Ben HartAuthor Commented:
Ok issue is resolved.

Long story short, on day one firs thing I did was check perms.  Both reporting users were in a security group who was given FullAccess rights to the problematic mailboxes.  I tried adding them specifically, which did not resolve the issue.

Last night I bounced their local Exchange server and the issue persists still.  Until I removed those explicit permission entries, after that and restarting their Outlook they could open the mailboxes just fine.

So moral of the story is.. two rights make a wrong?  Maybe this story has no moral.
Ben HartAuthor Commented:
the solution to my issue was half Abdul and half me.  He reminded me of the command to remove-mailboxpermissions but that was not the sole solution.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today

From novice to tech pro — start learning today.