Re: Sending on behalf of mail-enabled folder > "You do not have permission to send to this recipient"

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Ben Winzenz [Exchange MVP] wrote:

1. Don't mix Send As and Send on Behalf. Pick one.

Could you elaborate? I didn't know of any such recommendation. So far
we always used both (unless the "on behalf of" part was actually
desired) and to my knowledge have never experienced any problems with
that setup.


2. John may have Send As allow rights, but are there inherited Deny
rights for Send As as well? If both Allow and Deny are inherited for
Send As, then the Deny will win. If this is the case, you either
need to set an explicit allow (at that level), or remove the
inherited Deny.

There are no Deny rights anywhere in the hierarchy and the Send As
right is granted explicitly at exactly that level.


3. So John is sending to himself in the To field?
It wasn't clear who the recipient was. Can John send As the PF to
anyone else? Outside mail accounts? Or does he always get the same
error?

It's always the same error regardless of whether the message goes to
outside or inside recipients.

Thanks for replying so fast.

Cheers,

--
Regards,

Oliver Giesen

Lucatec GmbH phone +49-421-57953-0
Leerkämpe 8b fax +49-421-57953-20
D-28259 Bremen VAT-No. DE 208891410

business e-mail team@xxxxxxxxxx
direct e-mail giesen@xxxxxxxxxx
web http://www.lucatec.de
.



Relevant Pages

  • Re: "access denied" for members of Administrators, stand-alone server
    ... then the explict grant added would have overridden the inherited deny ... surely by indirect membership in related security groups as is the case ... as you say his direct membership in a group that is allowed access ... explict grant overrules inherited deny. ...
    (microsoft.public.windows.server.security)
  • Re: "access denied" for members of Administrators, stand-alone server
    ... then the explict grant added would have overridden the inherited deny ... surely by indirect membership in related security groups as is the case ... as you say his direct membership in a group that is allowed access ... explict grant overrules inherited deny. ...
    (microsoft.public.windows.server.security)
  • Re: OU Acling
    ... So, even if you deny delete, but still allow to delete_child, then you'll be ... >> shouldnt Deny over ride all permissions no matter what it is? ... > -- explicit deny ... > -- inherited deny ...
    (microsoft.public.windows.server.active_directory)
  • Re: Permissions inherited..from where?
    ... In AD and Explicit Allow with override and Inherited Deny but only on the level that it is set. ... Doesn't the Windows security model always apply explicit "deny" over "allow", ... Also, I remember granting an admin account permissions on single mailboxes and full stores, but it was never allowed to access them before removing the inherited "deny". ...
    (microsoft.public.exchange2000.admin)
  • Re: How can I Tell BT...
    ... delivery (and even that isn't foolproof) it's all too easy for the ... recipient to deny all knowledge of receipt. ... Last time I looked in The Phone Book there was a section near the front ...
    (uk.telecom)