ADMT permissions issue, intra-forest migration


hi,

we consolidating root/child domain infrastructure, have root domain , using admt move users.

the problem exchange "send as" permissions. exchange 2013 in root domain.

after user migration root domain "send as" permissions lost (full access permissions remain). send , full access permissions granted universal groups in child domain.

what issue here?

hi,

thanks post.

regarding issue, please refer following troubleshooting steps:

1. allow inherited permission adsiedit.msc

opened adsiedit.msc,  looking "allow inheritable permissions parent propagate object , child objects." option on adminsdholder system container. if option unchecked, should check option. ad sites , services force dc replication between domain controllers.

2. remove affected accounts of following groups

  • administrators     
  • account operators
  • server operators
  • print operators
  • backup operators
  • domain admins
  • schema admins
  • enterprise admins
  • cert publishers

the "send as" right removed user object after configure "send as" right in active directory users , computers snap-in in exchange server

https://support.microsoft.com/en-us/kb/907434

additional information reference:

troubleshooting user migration issues

http://technet.microsoft.com/en-us/library/cc974359(ws.10).aspx  

best regards,

alvin wang


please remember mark replies answers if , un-mark them if provide no help. if have feedback technet subscriber support, contact tnmff@microsoft.com.



Windows Server  >  Directory Services



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS