Solved

Unable to remove calendar permission

Posted on 2015-02-10
8
654 Views
Last Modified: 2015-02-19
User def.hij and klm.nop had permission on calendar folder of User abc. Now user def.hij is gone and the account is disabled. When i check the existing permission of calender folder of abc i see def.hij and klm.nop listed there and i am trying to remove that but getting below errors. i was able to remove klm.nop using the same command but cant remove def.hij

Using this to check the permission:


get-mailboxfolderPermission -Identity abc@xyz.net:\calendar

RunspaceId   : 7b90a9bb-33fe-4fca-9ef0-3298b530fd44
FolderName   : Calendar
User         : Default
AccessRights : {AvailabilityOnly}
Identity     : Default
IsValid      : True

RunspaceId   : 7b90a9bb-33fe-4fca-9ef0-3298b530fd44
FolderName   : Calendar
User         : NT User:xyz\def.hij
AccessRights : {Owner}
Identity     : NT User:xyz\def.hij
IsValid      : True


Using this to remove the permission:

Remove-MailboxFolderPermission -identity "abc@xyz.net:\calendar" -User def.hij


There is no existing permission entry found for user: def hij.
    + CategoryInfo          : NotSpecified: (0:Int32) [Remove-MailboxFolderPermission], UserNotFoundInPermissionEntryE
   xception
    + FullyQualifiedErrorId : B9E1C51A,Microsoft.Exchange.Management.StoreTasks.RemoveMailboxFolderPermission
    + PSComputerName        : servername.domain.net
0
Comment
Question by:techdeep
  • 4
  • 3
8 Comments
 
LVL 20

Expert Comment

by:Satya Pathak
ID: 40602543
try below command

remove-MailboxFolderPermission -Identity Owner:\Calendar -User TargetUser
0
 

Author Comment

by:techdeep
ID: 40602625
That's this exactly what i am using but getting error.

Remove-MailboxFolderPermission -identity "abc@xyz.net:\calendar" -User def.hij
0
 
LVL 24

Expert Comment

by:VB ITS
ID: 40602676
Re-enable the def.hij account and then try re-running the command.

You can't modify (add, edit or remove) the old user's permissions to another mailbox when their account is disabled. I tested and confirmed this very recently in another EE question.
0
Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 

Author Comment

by:techdeep
ID: 40602868
You want me to enable account in AD only or you want to assign it a mailbox as-well before we try to remove it ?
0
 
LVL 24

Expert Comment

by:VB ITS
ID: 40602879
Did you remove the mailbox from the account then disable the account in AD?

Try enabling the account in AD and then run the command. If that doesn't work you may have to re-link the disconnected mailbox to the def.hij account.
0
 

Author Comment

by:techdeep
ID: 40603257
The mailbox was not disconnected and only AD account was disabled. I have enabled the account but still getting same error. Only one thing changed and that is when I run get-mailboxfolderPermission command I dont see "NT User" thing and now see the User's name.

Using this to check the permission:


get-mailboxfolderPermission -Identity abc@xyz.net:\calendar

RunspaceId   : 7b90a9bb-33fe-4fca-9ef0-3298b530fd44
FolderName   : Calendar
User         : Default
AccessRights : {AvailabilityOnly}
Identity     : Default
IsValid      : True

RunspaceId   : 7b90a9bb-33fe-4fca-9ef0-3298b530fd44
FolderName   : Calendar
User         : def hij
AccessRights : {Owner}
Identity     : def hij
IsValid      : True
0
 
LVL 24

Accepted Solution

by:
VB ITS earned 500 total points
ID: 40603269
Do you have multiple DCs in your environment? If so you may have to wait for replication to occur before trying again.

From my experience you do have to wait a bit after you re-enable a disabled account before you can make changes and vice versa.
0
 

Author Comment

by:techdeep
ID: 40618504
yes... this issue was resolved. was able to remove the permission using same command after


Enabled the account ----> Forced AD replication ---> restarted exchange transport service
0

Featured Post

Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

We are happy to announce a brand new addition to our line of acclaimed email signature management products – CodeTwo Email Signatures for Office 365.
This article explains in simple steps how to renew expiring Exchange Server Internal Transport Certificate.
In this video we show how to create an Address List in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Organization >> Ad…
In this video we show how to create an email address policy in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Mail Flow…

680 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question