• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 96
  • Last Modified:

Exchange 2007 Account Inheritance issue on Full Permissions

Hello Experts,

Recently we have noticed that in one of our exchange server all the mailboxes has lost access to one of our admin account.
To tackle this issue temporarily, I have used the following power-shell command:
Get-Mailbox -Database “Server\Database” | Add-MailboxPermission -user 'accountname' -AccessRights 'FullAccess' -InheritanceType All

This command has added the admin user on full permissions to all the mailboxes on the server, but when I create new mailbox on the server, the admin account is not getting added on full permissions  for the new mailbox.

I request your help to get help and troubleshoot this issue.
0
Moinuddin_Imam
Asked:
Moinuddin_Imam
  • 2
1 Solution
 
Md. MojahidCommented:
Mailbox Rights for New Users Shows Only Self
http://support.microsoft.com/kb/272153/en-us
 
The permissions inheritance and the permissions will appear only after the creation of mailbox. The mailbox will be created only after we send an email to the mailbox or try to access the mailbox. This behavior occurs because the mailbox security descriptor is not read from the Active Directory account object until the user logs on or gets mail. The Recipient Update Service does not stamp the inherited permissions when the mailbox is created. After the mailbox is created in the store, the store calculates inherited mailbox rights.
 
and similar question ask here before

http://www.experts-exchange.com/Software/Server_Software/Email_Servers/Exchange/Q_22704560.html
0
 
Manikandan NarayanswamySecurity Specialist & IBM Security GuardiumCommented:
Hi,

So you mean to say that the Admin user doesn't have the rights to manage the Recipient mailboxes. Check if the Admin account is added to the Recipient Management group.

Thanks
Manikandan
0
 
Moinuddin_ImamAuthor Commented:
I have checked the suggested solution earlier, it does not work here.
The issue is that this problem is only with one exchange server within the environment. When the user mailbox is created on exchange server 1 and inheritance does not work for the admin account.

However, if the user mailbox is created on other exchange server, the inheritance works perfectly fine for the admin account. I have checked the recipient management group and the admin account is a member of the group.
0
 
Manikandan NarayanswamySecurity Specialist & IBM Security GuardiumCommented:
Hi,

Can you run the following command on the server you're having issues and see if the inheritance works for the admin account. The same is been suggested on a previous case on expert-exchange hence i would recommend you to try the same.

http://www.experts-exchange.com/Software/Server_Software/Email_Servers/Exchange/Q_22704560.html

Add-ADPermission -Identity "Mailbox Store" -User "domain\user" -ExtendedRights Send-As, Receive-As, ms-Exch-Store-Admin

Thanks
Manikandan
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Upgrade your Question Security!

Your question, your audience. Choose who sees your identity—and your question—with question security.

  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now