?
Solved

Unable to remove calendar permission

Posted on 2015-02-10
8
Medium Priority
?
942 Views
Last Modified: 2015-02-19
User def.hij and klm.nop had permission on calendar folder of User abc. Now user def.hij is gone and the account is disabled. When i check the existing permission of calender folder of abc i see def.hij and klm.nop listed there and i am trying to remove that but getting below errors. i was able to remove klm.nop using the same command but cant remove def.hij

Using this to check the permission:


get-mailboxfolderPermission -Identity abc@xyz.net:\calendar

RunspaceId   : 7b90a9bb-33fe-4fca-9ef0-3298b530fd44
FolderName   : Calendar
User         : Default
AccessRights : {AvailabilityOnly}
Identity     : Default
IsValid      : True

RunspaceId   : 7b90a9bb-33fe-4fca-9ef0-3298b530fd44
FolderName   : Calendar
User         : NT User:xyz\def.hij
AccessRights : {Owner}
Identity     : NT User:xyz\def.hij
IsValid      : True


Using this to remove the permission:

Remove-MailboxFolderPermission -identity "abc@xyz.net:\calendar" -User def.hij


There is no existing permission entry found for user: def hij.
    + CategoryInfo          : NotSpecified: (0:Int32) [Remove-MailboxFolderPermission], UserNotFoundInPermissionEntryE
   xception
    + FullyQualifiedErrorId : B9E1C51A,Microsoft.Exchange.Management.StoreTasks.RemoveMailboxFolderPermission
    + PSComputerName        : servername.domain.net
0
Comment
Question by:techdeep
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
8 Comments
 
LVL 20

Expert Comment

by:Satya Pathak
ID: 40602543
try below command

remove-MailboxFolderPermission -Identity Owner:\Calendar -User TargetUser
0
 

Author Comment

by:techdeep
ID: 40602625
That's this exactly what i am using but getting error.

Remove-MailboxFolderPermission -identity "abc@xyz.net:\calendar" -User def.hij
0
 
LVL 24

Expert Comment

by:VB ITS
ID: 40602676
Re-enable the def.hij account and then try re-running the command.

You can't modify (add, edit or remove) the old user's permissions to another mailbox when their account is disabled. I tested and confirmed this very recently in another EE question.
0
Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

 

Author Comment

by:techdeep
ID: 40602868
You want me to enable account in AD only or you want to assign it a mailbox as-well before we try to remove it ?
0
 
LVL 24

Expert Comment

by:VB ITS
ID: 40602879
Did you remove the mailbox from the account then disable the account in AD?

Try enabling the account in AD and then run the command. If that doesn't work you may have to re-link the disconnected mailbox to the def.hij account.
0
 

Author Comment

by:techdeep
ID: 40603257
The mailbox was not disconnected and only AD account was disabled. I have enabled the account but still getting same error. Only one thing changed and that is when I run get-mailboxfolderPermission command I dont see "NT User" thing and now see the User's name.

Using this to check the permission:


get-mailboxfolderPermission -Identity abc@xyz.net:\calendar

RunspaceId   : 7b90a9bb-33fe-4fca-9ef0-3298b530fd44
FolderName   : Calendar
User         : Default
AccessRights : {AvailabilityOnly}
Identity     : Default
IsValid      : True

RunspaceId   : 7b90a9bb-33fe-4fca-9ef0-3298b530fd44
FolderName   : Calendar
User         : def hij
AccessRights : {Owner}
Identity     : def hij
IsValid      : True
0
 
LVL 24

Accepted Solution

by:
VB ITS earned 1500 total points
ID: 40603269
Do you have multiple DCs in your environment? If so you may have to wait for replication to occur before trying again.

From my experience you do have to wait a bit after you re-enable a disabled account before you can make changes and vice versa.
0
 

Author Comment

by:techdeep
ID: 40618504
yes... this issue was resolved. was able to remove the permission using same command after


Enabled the account ----> Forced AD replication ---> restarted exchange transport service
0

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Learn to move / copy / export exchange contacts to iPhone without using any software. Also see the issues in configuration of exchange with iPhone to migrate contacts.
This article will help to fix the below errors for MS Exchange Server 2013 I. Certificate error "name on the security certificate is invalid or does not match the name of the site" II. Out of Office not working III. Make Internal URLs and Externa…
In this video we show how to create a Resource Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: Navigate to the Recipients >> Resources tab.: "Recipients" is our default selection …
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…
Suggested Courses

765 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question