Re: Mailbox maps to Sid when running Data collection

From: Steven Halsey [MSFT] (Stevhal_at_Online.Microsoft.com)
Date: 06/09/04


Date: Wed, 9 Jun 2004 10:54:38 -0700

I believe the problem is the ADCTools are finding the Foreign Security
Priniciple through a trust relationship to the NT4 domain.
Basically you have the SID on two objects currently 1 on a Windows Account,
and one on the NT4 Account.

You could do a couple of things to Resolve the Issues:

- Delete the NT4 account and tell the users to just use the new W2k3
Accounts. I doubt you are ready to do this however.

- If you haven't deployed any E2k or E2k3 servers, You could change the
Primary Account on the Exchange 5.5 Mailbox to point to the Windows 2003
Account instead of the NT4 Account. Then I'm not sure if you would have to
add permissions for the NT4 Account. Try to see if the User can access the
mailbox after you change the permissions, if they can't add the rights
directly. Open Exchange 5.5 Administrator, From the Tools menu select
Options, Go to the permissions tab and make sure the "Show Permissions page
for all objects" is checked. Now Open the mailbox in Exchange 5.5 and goto
the permissions tab. in the "Windows NT Accounts with Permissions" add
specifically the NT4 Account with the User Right. If you need to add the
account just before you break the Trust with the NT4 Domain I would go into
these accounts and remove the reference to the NT4 Account, from the mailbox
Rights in Active Directory Users and Computers.

-- 
Steven Halsey
Stevhal@online.microsoft.com
Microsoft Exchange
Please do not send email directly to this alias.  This alias is for
newsgroup purposes only.
This posting is provided "AS IS" with no warranties, and confers no rights.
"Chris S" <anonymous@discussions.microsoft.com> wrote in message 
news:DD8367E5-DAFB-4276-9C8C-8EE455482EA7@microsoft.com...
> The users from whom this error message has shown up for have not started 
> to use the W2k3 domain yet.  Their accounts are imported with the sid 
> history into the new domain 


Relevant Pages

  • Re: Permissions Problem
    ... real pain when you tie this in with permissions across domains. ... Why dont you cut your losses and pass the text as a post request to your NT4 ... web server and have asp create the file for you on the NT 4 box. ... > logged in with an admin account of the 2003 box. ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Incoming E-Mail - cant create contact in OU
    ... account out of local administrator to attempt to find any denied access. ... I then added full permissions to my user account on both of these keys, ... local admin rights to the server hosting incoming email. ... what permission I need to give the app pool locally to avoid this issue. ...
    (microsoft.public.sharepoint.windowsservices)
  • Re: Incoming E-Mail - cant create contact in OU
    ... account out of local administrator to attempt to find any denied ... I then added full permissions to my user account on both of these keys, ... that's for every app pool you create for every new web app on the ... local admin rights to the server hosting incoming email. ...
    (microsoft.public.sharepoint.windowsservices)
  • Re: Win2k - Account Operator not working properly
    ... You very likely have other ACL issues other than what was mentioned and I can point them out here for you for free or you can pay someone $200-500 an hour to come check it out. ... In order for that to result in inheritence protection it means the schema had to be modified. ... set the account in the GUI to inherit from its parents. ... Used the delegation wizard, on the top level OU, to assign the desired permissions. ...
    (microsoft.public.windows.server.active_directory)
  • Consider Windows XP File Security and Group Policies
    ... If you are running Windows XP and are using the NTFS file system, ... Account from being able to purge its history footprint files. ... Changing Folder permissions to Read-Execute instead of Full ... you globally apply Full Control for the Administrators group and the SYSTEM ...
    (microsoft.public.windowsxp.general)