Expiring Today—Celebrate National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Exchange 2010 - Manage Full Access Didn't Remove Account

Posted on 2015-02-18
4
Medium Priority
?
108 Views
Last Modified: 2015-02-19
I have a weird scenario that I need help with.

I have Exchange 2010 on Windows Server 2008.  Using the Exchange Management Console I added "Full Access" for User A, to see and manage User B's Account.  Now when it is time to remove that permission, exchange is not giving it up.  What I mean is that I went back to the account in Mailboxes under Recipient Config in EMC, and right clicked the account of User B, and chose "Manage Full Access" and selected User B, and removed them, and finished successfully.

The email account still shows up in User A's Outlook 2013 client on the left hand side as it always had.  It won't remove.

Things I have tried:
I have checked the Account Properties for Delegates and there are none.  I have right clicked the account and chosen delete, and it says something about it being managed by the server or the equivalent.  I have recreated the Profile of User A, and it still shows up. I have also checked the "Send Mail As" property in EMC, and User A is not on User B's list.
I tried a repair of outlook thinking this was a local problem to the client, and when that didn't fix it, I connected her account to another computer and had the same problem.  So the issue is definitely on the Exchange server.
I have checked Mail Flow settings, on both User A and B's mailbox properties, and it's all default there.
I tried adding the Full access permission back to User B's Account, waited a while, then removed it.  That didn't help.

User A, can still see and open mail that is sent to User B.  And when I connect to our Outlook Web Mail portal in a web browser as User A, I am not able to view User B's account.  It says I don't have permission.

What should I do to remove this mailbox from User A's Outlook?

Additional Info:
Somewhere between the time I added the full access permission for User A on User B's Account and the time I tried to remove it, User A got married, so I changed her account name in Active Directory.  I didn't create a new account, just went into the user account properties in AD, and in the "Account" tab, I changed the "User Logon Name" to match her new last name.  Everything seemed to be fine after that change.  No weird behavior except this outlook issue.  Of course her Exchange Mailbox is connected through AD to her account.  I didn't think changing her account name would effect that connection.  And she can still access her email and see all her folders and contacts etc...  All I did in EMC was add a new alias for her (because I'm unsure of another easy way to manage this scenario, I didn't want to learn how to migrate between old and new mailbox accounts, but will if that's the fix).  Not sure if this is related...

Thanks Experts!!
0
Comment
Question by:Nick Daniels
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 44

Accepted Solution

by:
Amit earned 2000 total points
ID: 40617376
We call this as auto mapping. Follow this article:
http://www.systematicuprising.com/2012/12/how-to-remove-auto-mapping-in-exchange-2010/

Follow adsiedit steps
0
 

Author Comment

by:Nick Daniels
ID: 40617734
Amit, thanks for this article, it looks to be close to what I need.  
But am I correct in understanding the AS Auto-Mapping to be the feature that allows me to add "full access" to a mailbox, and that mailbox is automatically added to the users outlook in the next few minutes?

If this article is saying that the solution to my problem is to disable Auto-Mapping, then I am not liking that answer.  I really use the auto-mapping feature all the time.  Users are always going on vacation, and asking someone to monitor their high traffic in-boxes.  I can easily add it, without being in front of their computer.

I'm hoping for a solution that allows me to just fix this one issue/mailbox account, and not disable AutoMapping.

What do you think?
0
 
LVL 44

Expert Comment

by:Amit
ID: 40618694
This is specific to each user, not a global setting. You can call it as Exchange 2010 bug. Normally, using EMC and EMS it should be removed, in some cases, it need adsiedit.
0
 

Author Closing Comment

by:Nick Daniels
ID: 40619518
Thank you Amit!  This solved my problem perfectly!
I appreciate the help!
0

Featured Post

Office 365 Training for IT Pros

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Let's recap what we learned from yesterday's Skyport Systems webinar.
A bad practice commonly found during an account life cycle is to set its password to an initial, insecure password. The Password Reset Tool was developed to make the password reset process easier and more secure.
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.
Suggested Courses

730 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question