Re: Domain Admins cannot access mailboxes!



You don't need to bring anything offline. Read up on the Recovery Storage
Group feature in Exchange 2003.

--
Thanks,
Brian Desmond
Windows Server MVP - Directory Services

www.briandesmond.com


"CELEMCS" <CELEMCS@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:1A42CB11-791E-4172-AC08-AFF485D0BB5D@xxxxxxxxxxxxxxxx
Brian,

Email is our main form of communication. We buy, develop, and sell
property.
Much of what we receive via email is contracts, proposals, agreements,
images... the list goes on. There are a select few individuals that have a
tendancy to delete or "lose" their email and rely on me to restore it.
Restoring the entire store would bring the server offline longer than I
can
endure... and restoring individually has always been quick and painless.
In 3
years I have not had any problems backing up the mailboxes... yes they
tend
to be slow backups, but worth the wait.

Now I'm having this problem, and can't seem to get past it. There has to
be
something in the DS restoration that went wrong that I can fix.... but I
cannot put my finger on it.

Thanks,
Chris


"Brian Desmond [MVP]" wrote:

Chris-

Why are you doing brick level backups? You only need to do store level
backups. Brick level ones are prone to failure, and slow.

--
Thanks,
Brian Desmond
Windows Server MVP - Directory Services

www.briandesmond.com


"CELEMCS" <CELEMCS@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:0DAD3B45-D66E-44F3-8318-939730D2BA71@xxxxxxxxxxxxxxxx
Okay. That part I've got completed. I have an account that can access
email
boxes via Outlook... the main problem is still pending though...
I cannot access the email boxes in my backup programs. If I backup the
IS
only then the job appears to work for a while - then fails. I cannot
even
attempt to backup the individual mailboxes because I am told I don't
have
the
rights. -- Does that make any sense? I am using Symantec Backup Exec
and
NTBACKUP - neither of which is working for me. (but they both worked
before
my DS was restored)

Thanks.
Chris


"Brian Desmond [MVP]" wrote:

Just make a normal user account and delegate it the rights. You can
runas
outlook with it or login to OWA when you need it.

--
Thanks,
Brian Desmond
Windows Server MVP - Directory Services

www.briandesmond.com


"CELEMCS" <CELEMCS@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:C79280B6-6F98-4D2D-BC23-637EB618D596@xxxxxxxxxxxxxxxx
Thank you. That sounds like a good idea.
How would you recommend setting up this special account? Any
suggestions
for
getting started?

-Chris


"Brian Desmond [MVP]" wrote:

It's probably an ACL at the org level or somewhere in the tree.

My suggestion is to make a special account just for looking at
mailboxes
and
build some process around it (e.g. have to log who what and why,
both
of
you
have to be present, etc).

--
Thanks,
Brian Desmond
Windows Server MVP - Directory Services

www.briandesmond.com


"CELEMCS" <CELEMCS@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:258FD71C-4DAB-4F14-BC74-064057082A1A@xxxxxxxxxxxxxxxx
Brian,

My domain admins are me and my network administrator. We cannot
access
other
individual email mailboxes in Outlook like we could before the
directory
services was restored. Also, I cannot access the mailboxes with
NTBACKUP
or
Symantec's Backup Exec because of a permission issue (none of the
accounts
I
can use will gain me access to properly backup the mailboxes).

-Chris


"Brian Desmond [MVP]" wrote:

Chris-

Why are your domain admins accessing mailboxes? This is not
access
to
hand
out that liberally.

--
Thanks,
Brian Desmond
Windows Server MVP - Directory Services

www.briandesmond.com


"CELEMCS" <CELEMCS@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:841C7318-C0A7-438E-9110-430A634B15F3@xxxxxxxxxxxxxxxx
Hello,

Recently we had a DC crash. This DC was also an Exchange
Server
and
was
our
main DC (PDC emulator, GC, Schema Master....etc)

The server has Windows 2000 SP4 - Exchange Server 2003 SP2.

We restored from tape and had some issues with recovering the
directory
services. After a couple hours of work we were able to get
Active
Directory
back together (for the most part), but we are now unable to
properly
backup
our Exchange Server. Symantec Backup Exec cannot open the
IS...
and
Domain
Admins cannot access anyone's mailboxes. Individuals can
access
their
own
mailboxes - but that's it.

I have tried adjusting some security settings in "Local Domain
Security"
on
the server, AD, and Exchange System Manager.... but nothing
has
changed.

Any ideas on how to resolve? Or how to discover what the
problem
is?
Thank you,
Chris L.














.



Relevant Pages

  • Re: Domain Admins cannot access mailboxes!
    ... I cannot access the email boxes in my backup programs. ... Windows Server MVP - Directory Services ... How would you recommend setting up this special account? ... My suggestion is to make a special account just for looking at mailboxes ...
    (microsoft.public.exchange2000.active.directory.integration)
  • Re: Domain Admins cannot access mailboxes!
    ... Just make a normal user account and delegate it the rights. ... Windows Server MVP - Directory Services ... My suggestion is to make a special account just for looking at mailboxes ...
    (microsoft.public.exchange2000.active.directory.integration)
  • Re: Domain Admins cannot access mailboxes!
    ... Windows Server MVP - Directory Services ... years I have not had any problems backing up the mailboxes... ... I cannot access the email boxes in my backup programs. ...
    (microsoft.public.exchange2000.active.directory.integration)
  • Re: Domain Admins cannot access mailboxes!
    ... years I have not had any problems backing up the mailboxes... ... Windows Server MVP - Directory Services ... I cannot access the email boxes in my backup programs. ...
    (microsoft.public.exchange2000.active.directory.integration)
  • Re: Domain Admins cannot access mailboxes!
    ... Windows Server MVP - Directory Services ... I cannot access the email boxes in my backup programs. ... attempt to backup the individual mailboxes because I am told I don't have ...
    (microsoft.public.exchange2000.active.directory.integration)

Loading