Full Mailbox Access
Posted on 2016-09-29
We have an Exchange coexistence scenario between Exchange 2010/2016. I'm having an issue since migrating users from Exchange 2010 to Exchange 2016. Specific users have full mailbox access to all mailboxes in the environment. These users are also members of the organizational management group. There are no issues when the mailboxes that is access is on 2010. As soon as the mailbox is migrated to 2016 it can no longer be accessed by these users. If the user is not a member of organizational management there is no issue. I understand the best practices and the security implication of this configuration but unfortunately this is the setup that is forced upon me. From what I can tell is fullaccess is denied at the 2016 database levels by default. The following command is run to grant full mailbox access on all 2016 databases: Get-mailboxdatases|add-adpermission -user username -accessrights genericall. The right exists just access is still not granted. Somewhere an inherited right is propagating from the database is my assumption.