Forum Discussion
brogyi
Mar 22, 2022Brass Contributor
Full access with mail enabled security group access denied
Hello, I read the MS docs Add-MailboxPermission docs (https://docs.microsoft.com/en-us/powershell/module/exchange/add-mailboxpermission?view=exchange-ps) and the User parameter accepts security grou...
Anonymous
Mar 23, 2022Could you please post the results of "get-mailboxpermission $mbox" and "get-casmailbox $mbox | fl owaenabled"?
brogyi
Mar 23, 2022Brass Contributor
Deleted
this is the get mailboxpermission with format list
RunspaceId : 5c55fc5e-0b2f-4ad4-8e71-940942488e19
AccessRights : {FullAccess}
Deny : True
InheritanceType : All
User : domainName\delegate user
Identity : domainName.hu/domainName/Users/teszt/Teszt Barnabás
IsInherited : False
IsValid : True
ObjectState : Unchanged
RunspaceId : 5c55fc5e-0b2f-4ad4-8e71-940942488e19
AccessRights : {FullAccess, ReadPermission}
Deny : False
InheritanceType : All
User : NT AUTHORITY\SELF
Identity : domainName.hu/domainName/Users/teszt/Teszt Barnabás
IsInherited : False
IsValid : True
ObjectState : Unchanged
RunspaceId : 5c55fc5e-0b2f-4ad4-8e71-940942488e19
AccessRights : {FullAccess}
Deny : False
InheritanceType : All
User : domainName\xch_full-access-1-1356144182
Identity : domainName.hu/domainName/Users/teszt/Teszt Barnabás
IsInherited : False
IsValid : True
ObjectState : Unchanged
RunspaceId : 5c55fc5e-0b2f-4ad4-8e71-940942488e19
AccessRights : {FullAccess}
Deny : True
InheritanceType : All
User : domainName\Tartománygazdák (<-- maybe "domain owners" not sure how to translate, it is a built in group)
Identity : domainName.hu/domainName/Users/teszt/Teszt Barnabás
IsInherited : True
IsValid : True
ObjectState : Unchanged
RunspaceId : 5c55fc5e-0b2f-4ad4-8e71-940942488e19
AccessRights : {FullAccess}
Deny : True
InheritanceType : All
User : domainName\Vállalati rendszergazdák (<-- maybe "domain administrators" not sure how to translate, it is a built in group)
Identity : domainName.hu/domainName/Users/teszt/Teszt Barnabás
IsInherited : True
IsValid : True
ObjectState : Unchanged
RunspaceId : 5c55fc5e-0b2f-4ad4-8e71-940942488e19
AccessRights : {FullAccess}
Deny : True
InheritanceType : All
User : domainName\delegate user
Identity : domainName.hu/domainName/Users/teszt/Teszt Barnabás
IsInherited : True
IsValid : True
ObjectState : Unchanged
RunspaceId : 5c55fc5e-0b2f-4ad4-8e71-940942488e19
AccessRights : {FullAccess}
Deny : True
InheritanceType : All
User : domainName\Organization Management
Identity : domainName.hu/domainName/Users/teszt/Teszt Barnabás
IsInherited : True
IsValid : True
ObjectState : Unchanged
RunspaceId : 5c55fc5e-0b2f-4ad4-8e71-940942488e19
AccessRights : {FullAccess}
Deny : False
InheritanceType : All
User : NT AUTHORITY\SYSTEM
Identity : domainName.hu/domainName/Users/teszt/Teszt Barnabás
IsInherited : True
IsValid : True
ObjectState : Unchanged
RunspaceId : 5c55fc5e-0b2f-4ad4-8e71-940942488e19
AccessRights : {ReadPermission}
Deny : False
InheritanceType : All
User : NT AUTHORITY\HÁLÓZATI SZOLGÁLTATÁS (<-- network service)
Identity : domainName.hu/domainName/Users/teszt/Teszt Barnabás
IsInherited : True
IsValid : True
ObjectState : Unchanged
RunspaceId : 5c55fc5e-0b2f-4ad4-8e71-940942488e19
AccessRights : {FullAccess, DeleteItem, ReadPermission, ChangePermission, ChangeOwner}
Deny : False
InheritanceType : All
User : domainName\Tartománygazdák (<-- maybe "domain owners" not sure how to translate, it is a built in group)
Identity : domainName.hu/domainName/Users/teszt/Teszt Barnabás
IsInherited : True
IsValid : True
ObjectState : Unchanged
RunspaceId : 5c55fc5e-0b2f-4ad4-8e71-940942488e19
AccessRights : {FullAccess, DeleteItem, ReadPermission, ChangePermission, ChangeOwner}
Deny : False
InheritanceType : All
User : domainName\Vállalati rendszergazdák (<-- maybe "domain administrators" not sure how to translate, it is a built in group)
Identity : domainName.hu/domainName/Users/teszt/Teszt Barnabás
IsInherited : True
IsValid : True
ObjectState : Unchanged
RunspaceId : 5c55fc5e-0b2f-4ad4-8e71-940942488e19
AccessRights : {FullAccess, DeleteItem, ReadPermission, ChangePermission, ChangeOwner}
Deny : False
InheritanceType : All
User : domainName\delegate user
Identity : domainName.hu/domainName/Users/teszt/Teszt Barnabás
IsInherited : True
IsValid : True
ObjectState : Unchanged
RunspaceId : 5c55fc5e-0b2f-4ad4-8e71-940942488e19
AccessRights : {FullAccess, DeleteItem, ReadPermission, ChangePermission, ChangeOwner}
Deny : False
InheritanceType : All
User : domainName\Organization Management
Identity : domainName.hu/domainName/Users/teszt/Teszt Barnabás
IsInherited : True
IsValid : True
ObjectState : Unchanged
RunspaceId : 5c55fc5e-0b2f-4ad4-8e71-940942488e19
AccessRights : {ReadPermission}
Deny : False
InheritanceType : All
User : domainName\Public Folder Management
Identity : domainName.hu/domainName/Users/teszt/Teszt Barnabás
IsInherited : True
IsValid : True
ObjectState : Unchanged
RunspaceId : 5c55fc5e-0b2f-4ad4-8e71-940942488e19
AccessRights : {ReadPermission}
Deny : False
InheritanceType : All
User : domainName\Delegated Setup
Identity : domainName.hu/domainName/Users/teszt/Teszt Barnabás
IsInherited : True
IsValid : True
ObjectState : Unchanged
RunspaceId : 5c55fc5e-0b2f-4ad4-8e71-940942488e19
AccessRights : {FullAccess, ReadPermission}
Deny : False
InheritanceType : All
User : domainName\Exchange Servers
Identity : domainName.hu/domainName/Users/teszt/Teszt Barnabás
IsInherited : True
IsValid : True
ObjectState : Unchanged
RunspaceId : 5c55fc5e-0b2f-4ad4-8e71-940942488e19
AccessRights : {FullAccess, DeleteItem, ReadPermission, ChangePermission, ChangeOwner}
Deny : False
InheritanceType : All
User : domainName\Exchange Trusted Subsystem
Identity : domainName.hu/domainName/Users/teszt/Teszt Barnabás
IsInherited : True
IsValid : True
ObjectState : Unchanged
RunspaceId : 5c55fc5e-0b2f-4ad4-8e71-940942488e19
AccessRights : {ReadPermission}
Deny : False
InheritanceType : All
User : domainName\Managed Availability Servers
Identity : domainName.hu/domainName/Users/teszt/Teszt Barnabás
IsInherited : True
IsValid : True
ObjectState : UnchangedThe get-casmailbox owa enabled property is set to true
- AnonymousMar 24, 2022Is "teszt.barnabas" member of the group "xch_full-access-1-1356144182"?
- brogyiMar 24, 2022Brass Contributorno-no, teszt.barnabas is the test user who's mailbox should be viewed through the xch_full_access group. To be clear in the Add-MailboxPermission the -identity is teszt.barnabas the test user and the -user is xch_full_access the security group.
- AnonymousMar 24, 2022
Ok, I missed that. Sorry. What about granting full access to a single user account. Does this work?
I'm still wondering if all rights are set correctly. But while searching the web I saw some similar cases which pointed in the direction of a corrupt database. Maybe this happened to you, either.