Unable to remove mailbox permissions from one mailbox.
Exchange 2007. Running get-maiboxpermission on one particular mailbox show various account with {FullAccess} and also {FullAccess, DeleteItem, ReadPermission, ChangePermission, ChangeOwner}. Some of these are service accounts that are no longer being used. I cannot figure out how to remove these permissions. I've been trying the command > Remove-MailboxPermission "mailbox" -User "user" -AccessRights fullaccess -InheritanceType All It asks me to confirm and I do. Then returns to prompt. There is no error indicating that it did not succeed. However, when I run get-mailboxpermission again the permission is still there. I've even tried deleting one of the user accounts with permissions but now I see the SID instead of the username and I still cannot remove it. I've checked the parent containers to see if the permissions are being inherited but don't see them anywhere. How do I remove these permissions? Thanks, KennyKenny
November 9th, 2011 3:19pm

Did you allow DC replication to occur? This will depend on the AD topology. How long did you allow the AD replication to occur before you check the permissions again? Worse case, you might have to use adsiedit to manually remove the service accounts from mailboxes.
Free Windows Admin Tool Kit Click here and download it now
November 9th, 2011 9:19pm

Hi, Maybe firstly you need to remove SIDhistory from adsiedit. Or follow this KB: http://support.microsoft.com/kb/KB295758 Additionally, you can add deny permission to them as workaround.Best Regards!
November 10th, 2011 1:16am

I've been trying to get rid of these for months so it's not a replication issue. I've looked in ADSIEdit and they don't show up anywhere. Where should I be looking?Kenny
Free Windows Admin Tool Kit Click here and download it now
November 10th, 2011 8:33am

We've always had only one domain so I can't see how SIDHistory would come into play. The weird thing is that if I look in the Exchange console at who has Full Mailbox Access these names do not show up but when I run the get-mailboxpermission they do.Kenny
November 10th, 2011 8:38am

Hi Kenny, Have you ever moved the mailbox? How about using below workaround: - Export the emails from "user" mailbox using Outlook Client - Create a new Mailbox in Exchange 2007 for the users. - Import the emails in new mailbox on Exchange 2007 server.Best Regards!
Free Windows Admin Tool Kit Click here and download it now
November 11th, 2011 2:20am

Hi Kenny, Have you ever moved the mailbox? How about using below workaround: - Export the emails from "user" mailbox using Outlook Client - Create a new Mailbox in Exchange 2007 for the users. - Import the emails in new mailbox on Exchange 2007 server.Best Regards!
November 11th, 2011 10:13am

Hi Kenny, Any update?Best Regards!
Free Windows Admin Tool Kit Click here and download it now
November 18th, 2011 2:35am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics