Unable to remove users with "FullAccess" from some mailboxes
I have an pure Exchange 2007 environment, migrated before my time from Exchange 2003 and there is no Exchange 2003 in the company any more.I am trying to migrate the legacy "shared mailboxes" to Exchange 2007 real Shared mailboxes with the rights assigned over a group (before the rights were assigned directly to users)In the Exchange Management Console,"Manage Full Access Permission" Wizard, I have a few users with a question mark next to their logo. I couldn't find out what it means but I suppose it is linked to my problem. When I try to remove these users from the mailbox I get following message:Summary: 1 item(s). 0 succeeded, 1 failed. Elapsed time: 00:00:00FREU\PorrasDFailedError:Cannot remove ACE on object "CN=FRIB-Roboguide,OU=Dummy,OU=UsersAndComputers,OU=FRIB,OU=ALL SUBS,DC=fanucrobotics,DC=eu" for account "FREU\PorrasD" because it is not present.Exchange Management Shell command attempted:Remove-MailboxPermission -Identity 'CN=FRIB-Roboguide,OU=Dummy,OU=UsersAndComputers,OU=FRIB,OU=ALL SUBS,DC=fanucrobotics,DC=eu' -User 'FREU\PorrasD' -InheritanceType 'All' -AccessRights 'FullAccess'Elapsed Time: 00:00:00or in EMSGet-MailboxPermission -identity "FRIB-Roboguide" | where {$_.User -match "Porras"} | select *AccessRights : {FullAccess}Deny : FalseInheritanceType : AllUser : FREU\PorrasDIdentity : fanucrobotics.eu/ALL SUBS/FRIB/UsersAndComputers/Dummy/FRIB-RoboguideIsInherited : FalseIsValid : TrueObjectState : Unchangedremove-MailboxPermission -identity "FRIB-Roboguide" -user "PorrasD" -accessrights fullaccessConfirmAre you sure you want to perform this action?Removing mailbox permission "FRIB-Roboguide" for user "PorrasD" with access rights "'FullAccess'".[Y] Yes [A] Yes to All [N] No [L] No to All [S] Suspend [?] Help (default is "Y"): yRemove-MailboxPermission : Cannot remove ACE on object "CN=FRIB-Roboguide,OU=Dummy,OU=UsersAndComputers,OU=FRIB,OU=ALL SUBS,DC=fanucrobotics,DC=eu" for account "FREU\PorrasD" because it is not present.At line:1 char:25+ remove-MailboxPermission <<<< -identity "FRIB-Roboguide" -user "PorrasD" -accessrights fullaccessI can add the same user, with the EMC Wizard or EMS cmdlet, I will have the User twice, once with a question mark next to the user logo and on without. The only one which i will be able to delete is the one without (?).... !!!Any idea will be welcome
June 4th, 2009 7:52pm

Please try solution posted by James Luo on this thread: http://social.technet.microsoft.com/Forums/en-US/exchangesoftwareupdate/thread/50a94a45-903e-409e-ba5c-116d84bed7ffPlease reply here if it works (or otherwise) to benefit all readers.Bhargav Shukla - MSFT - Exchange Reference: Exchange Server 2007 TechCenter - http://technet.microsoft.com/en-us/library/bb124558.aspx; Exchange Server 2003 TechCenter - http://technet.microsoft.com/en-us/library/bb123872(EXCHG.65).aspx; Microsoft Exchange Team Blog - http://msexchangeteam.com/default.aspx
Free Windows Admin Tool Kit Click here and download it now
June 4th, 2009 10:51pm

Hey !The solution that works for me:- Installing the Exchange 2003 Management Tool (incl. AdminPack and IIS)- Right click -> Properties -> Exchange Advanced -> Remove 12 SID's and the User(s) with "Full access"My Problem now:There are 12 SID's on every mailbox, which are NOT inherited, and the only chance for me to remove them is clicking on +-1000 user accounts...Is there an easier way ?Thanks
June 5th, 2009 5:00pm

Hello Phets,You should be able to remove all unresolved SIDs using ADFIND in bulk. Please refer http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/f389b0eb-8095-48d6-a004-c63487aa7499for further examples and reading.Milind Naphade | MCTS:M | http://www.msexchangegeek.com
Free Windows Admin Tool Kit Click here and download it now
June 5th, 2009 5:11pm

Hey Milind Naphade !Sorry but the link you provided couldn't help me.... I think if I start now beside searching for a "bulk Edit" i will have it finished earlier ;)
June 5th, 2009 7:18pm

Hey,There are some cool tools available from WiseSoft on internet. You can check fromt their range if they can help.. http://www.petri.co.il/password-control-bulk-modify-for-active-directory-windows-server-2008.htmPersonally, ADFIND should work in your case though. The only trouble you will have to go through is running it more than once.Milind Naphade | MCTS:M | http://www.msexchangegeek.com
Free Windows Admin Tool Kit Click here and download it now
June 5th, 2009 8:43pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics