Exchange 2010 - Manage Full Access Didn't Remove Account

Posted on 2015-02-18
Medium Priority
Last Modified: 2015-02-19
I have a weird scenario that I need help with.

I have Exchange 2010 on Windows Server 2008.  Using the Exchange Management Console I added "Full Access" for User A, to see and manage User B's Account.  Now when it is time to remove that permission, exchange is not giving it up.  What I mean is that I went back to the account in Mailboxes under Recipient Config in EMC, and right clicked the account of User B, and chose "Manage Full Access" and selected User B, and removed them, and finished successfully.

The email account still shows up in User A's Outlook 2013 client on the left hand side as it always had.  It won't remove.

Things I have tried:
I have checked the Account Properties for Delegates and there are none.  I have right clicked the account and chosen delete, and it says something about it being managed by the server or the equivalent.  I have recreated the Profile of User A, and it still shows up. I have also checked the "Send Mail As" property in EMC, and User A is not on User B's list.
I tried a repair of outlook thinking this was a local problem to the client, and when that didn't fix it, I connected her account to another computer and had the same problem.  So the issue is definitely on the Exchange server.
I have checked Mail Flow settings, on both User A and B's mailbox properties, and it's all default there.
I tried adding the Full access permission back to User B's Account, waited a while, then removed it.  That didn't help.

User A, can still see and open mail that is sent to User B.  And when I connect to our Outlook Web Mail portal in a web browser as User A, I am not able to view User B's account.  It says I don't have permission.

What should I do to remove this mailbox from User A's Outlook?

Additional Info:
Somewhere between the time I added the full access permission for User A on User B's Account and the time I tried to remove it, User A got married, so I changed her account name in Active Directory.  I didn't create a new account, just went into the user account properties in AD, and in the "Account" tab, I changed the "User Logon Name" to match her new last name.  Everything seemed to be fine after that change.  No weird behavior except this outlook issue.  Of course her Exchange Mailbox is connected through AD to her account.  I didn't think changing her account name would effect that connection.  And she can still access her email and see all her folders and contacts etc...  All I did in EMC was add a new alias for her (because I'm unsure of another easy way to manage this scenario, I didn't want to learn how to migrate between old and new mailbox accounts, but will if that's the fix).  Not sure if this is related...

Thanks Experts!!
Question by:Nick Daniels
  • 2
  • 2
LVL 45

Accepted Solution

Amit earned 2000 total points
ID: 40617376
We call this as auto mapping. Follow this article:

Follow adsiedit steps

Author Comment

by:Nick Daniels
ID: 40617734
Amit, thanks for this article, it looks to be close to what I need.  
But am I correct in understanding the AS Auto-Mapping to be the feature that allows me to add "full access" to a mailbox, and that mailbox is automatically added to the users outlook in the next few minutes?

If this article is saying that the solution to my problem is to disable Auto-Mapping, then I am not liking that answer.  I really use the auto-mapping feature all the time.  Users are always going on vacation, and asking someone to monitor their high traffic in-boxes.  I can easily add it, without being in front of their computer.

I'm hoping for a solution that allows me to just fix this one issue/mailbox account, and not disable AutoMapping.

What do you think?
LVL 45

Expert Comment

ID: 40618694
This is specific to each user, not a global setting. You can call it as Exchange 2010 bug. Normally, using EMC and EMS it should be removed, in some cases, it need adsiedit.

Author Closing Comment

by:Nick Daniels
ID: 40619518
Thank you Amit!  This solved my problem perfectly!
I appreciate the help!

Featured Post

Easily Design & Build Your Next Website

Squarespace’s all-in-one platform gives you everything you need to express yourself creatively online, whether it is with a domain, website, or online store. Get started with your free trial today, and when ready, take 10% off your first purchase with offer code 'EXPERTS'.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

There’s hardly a doubt that Business Communication is indispensable for both enterprises and small businesses, and if there is an email system outage owing to Exchange server failure, it definitely results in loss of productivity.
The Windows Firewall provides an important layer of protection and a rich interface to configure it. Unfortunately, it lacks item level filtering. This article details my process of implementing firewall-as-code to reduce GPO bloat.
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…

627 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question