Updated to SP1 RU3 and lost critical functionality in EMC!
Last week, we upgraded from 2010 RTM RU5 to 2010 SP1 RU3. Our environment has a user forest and resource forest with a full 2 way trust. We were able to grant full access permissions to certain mailboxes by creating a domain local group in the resource forest, adding the ID's from the user forest to the DL group, and selecting that group in the Manage Full Access Permissions wizard in the EMC. Since the upgrade, when you pull up the search screen in the Full Access Permissions Wizard, only users show up, and not groups. I can add the permissions find through the management shell. Interestingly, if you go to the Send-As permissions wizard, the groups show up fine and I can select/add them from there. There were no such issues prior to the upgrade from the RTM code. Has anyone else seen this issue? Thanks, Craige Lukowicz
April 21st, 2011 4:25pm

Has anyone been able to duplicate this issue? Thanks, Craige
Free Windows Admin Tool Kit Click here and download it now
April 25th, 2011 4:00pm

Hi Craige, I test it in my lab(non resource forest), and the same result as yours. You can add the Domain local group to the Manage Full access permissions wizard in Exchange 2010 RTM. You cannot do it in Exchange 2010 SP1. But suggest you convert customized non-universal groups to universal ones in Exchange 2010 organization.Please remember to click Mark as Answer on the post that helps you, and to click Unmark as Answer if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.
April 26th, 2011 1:59am

Has that functionality been intentionally taken out of the SP1 code, or is Microsoft considering this to be a bug? The only way we have been able to successfully grant full access or send as permissions to users is with the domain local groups, because they are using their AD accounts in the user forest to authenticate to Exchange. About 98% of our users have linked mailboxes. Doesn't make sense to me that you can add the DL groups in the Send As wizard, but not in the Full Access Permissions wizard....You'd think if this was a feature the developers were taking away from the GUI, they would do it across the board and not leave the functionality there in one of the wizards.
Free Windows Admin Tool Kit Click here and download it now
April 26th, 2011 4:32pm

Can anyone at Microsoft confirm if this is a bug or if it was intentionally left out of the SP1 code? Converting the groups as you suggest doesn't solve the problem - we need the domain local groups to grant the access to customer service mailboxes for ID's in the user forest because that's where the bulk of the credentials reside. If we can't see the groups as we were previously able to, then the full access permissions wizard is useless. Not everyone performing an admin role here is powershell savvy, so I need to make it as simple as possible for everyone who needs to do this.
April 27th, 2011 4:56pm

Can anyone at Microsoft speak to whether or not this is a bug or intentional? We are still using the shell as a workaround, but would like to know if this will be fixed in a future rollup update.
Free Windows Admin Tool Kit Click here and download it now
May 5th, 2011 4:49pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics