ADMT permissions issue, intra-forest migration


hi,

we consolidating root/child domain infrastructure, have root domain , using admt move users.

the problem exchange "send as" permissions. exchange 2013 in root domain.

after user migration root domain "send as" permissions lost (full access permissions remain). send , full access permissions granted universal groups in child domain.

what issue here?

hi,

thanks post.

regarding issue, please refer following troubleshooting steps:

1. allow inherited permission adsiedit.msc

opened adsiedit.msc,  looking "allow inheritable permissions parent propagate object , child objects." option on adminsdholder system container. if option unchecked, should check option. ad sites , services force dc replication between domain controllers.

2. remove affected accounts of following groups

  • administrators     
  • account operators
  • server operators
  • print operators
  • backup operators
  • domain admins
  • schema admins
  • enterprise admins
  • cert publishers

the "send as" right removed user object after configure "send as" right in active directory users , computers snap-in in exchange server

https://support.microsoft.com/en-us/kb/907434

additional information reference:

troubleshooting user migration issues

http://technet.microsoft.com/en-us/library/cc974359(ws.10).aspx  

best regards,

alvin wang


please remember mark replies answers if , un-mark them if provide no help. if have feedback technet subscriber support, contact tnmff@microsoft.com.



Windows Server  >  Directory Services



Comments

Popular posts from this blog

Azure MFA with Azure AD and RDS

Failed to setup initiator portal. Error status is given in the dump data.

Invalid pointer on gpresult /h gpreport.html