"The account does not have permission to impersonate the requested user" error

%3CLINGO-SUB%20id%3D%22lingo-sub-305235%22%20slang%3D%22en-US%22%3E%22The%20account%20does%20not%20have%20permission%20to%20impersonate%20the%20requested%20user%22%20error%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-305235%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3ELast%20week%20we're%20started%20to%20get%20%22%3CSPAN%3EThe%20account%20does%20not%20have%20permission%20to%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%20class%3D%22il%22%3Eimpersonate%3C%2FSPAN%3E%3CSPAN%3E%26nbsp%3Bthe%20requested%20user'%20error%20on%20the%20customer%26nbsp%3B%3C%2FSPAN%3Eaccounts%20that%20were%20working%20perfectly%20up%20to%20last%20week.%3C%2FP%3E%3CP%3EWhen%2C%20for%20example%20customer%20with%20100%20accounts%20that%20impersonated%20by%201%20service%20account%2C%20we%20see%20each%20day%20errors%20for%20different%20impersonated%20accounts.%26nbsp%3B%3C%2FP%3E%3CP%3ETalking%20with%20support%20on%20behalf%20of%20the%20customer%20didn't%20provided%20any%20help.%20Their%20answers%20as%20usual.%3C%2FP%3E%3CP%3EWhile%20doing%20more%20research%20we're%20found%20that%20if%20doing%202%20accounts%20impersonating%20in%20parallel%20(even%20from%20different%20servers)%20we%20get%20this%20error%2C%20and%20when%20doing%202%20or%20even%20more%20accounts%20impersonating%20serial%2C%20everything%20is%20working%20fine.%3C%2FP%3E%3CP%3EI'm%20afraid%20that%20MS%20has%20a%20bug%20in%20their%20permissions%20checking%20mechanism%20while%20trying%20to%20impersonate%20more%20than%201%20account%20in%20parallel.%3C%2FP%3E%3CP%3EMS%20Exchange%20engineers%2C%20can%20you%20please%20check%20this%20%3F%20Your%20customer%20supports%20is%20lacks%20of%20willing%20to%20assist.%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-305235%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EExchange%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-307019%22%20slang%3D%22en-US%22%3ERe%3A%20%22The%20account%20does%20not%20have%20permission%20to%20impersonate%20the%20requested%20user%22%20error%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-307019%22%20slang%3D%22en-US%22%3E%3CP%3EWell%2C%20if%202%20accounts%20in%20parallel%26nbsp%3Bis%20hitting%20the%20limit%20%3A)%3C%2Fimg%3E%20than%20it's%20very%20sad.%3C%2FP%3E%3CP%3EThere's%20a%20ticket%20within%20MS%20Support%2C%20but%20seems%20to%20be%20totally%20useless.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-307009%22%20slang%3D%22en-US%22%3ERe%3A%20%22The%20account%20does%20not%20have%20permission%20to%20impersonate%20the%20requested%20user%22%20error%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-307009%22%20slang%3D%22en-US%22%3ENot%20sure%20if%20this%20is%20a%20bug%20or%20you%20have%20hit%20a%20limit%20in%20terms%20of%20the%20number%20of%20impersonations%20that%20are%20possible%20for%20a%20specific%20account.%20I%20also%20recommend%20to%20open%20a%20support%20ticket%20explaining%20this%20problem%20because%20I%20think%20the%20Exchange%20Online%20Team%20might%20not%20see%20this%20thread%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-482684%22%20slang%3D%22en-US%22%3ERe%3A%20%22The%20account%20does%20not%20have%20permission%20to%20impersonate%20the%20requested%20user%22%20error%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-482684%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F255393%22%20target%3D%22_blank%22%3E%40SlavaG%3C%2FA%3EDid%20you%20ever%20find%20out%20why%20this%20happend%20or%20even%20resolved%20this%3F%20Currently%20we%20have%20the%20same%20problem%20for%20one%20customer%20using%20O365%20Exchange%2C%20but%20we've%20got%20no%20clue%20why%20some%20users%20can%20be%20impersonated%20and%20some%20cannot.%20There%20are%20no%20management%20scopes%20set%20limiting%20the%20impersonated%20users%20on%20the%20impersonation%20role.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-664561%22%20slang%3D%22en-US%22%3ERe%3A%20%22The%20account%20does%20not%20have%20permission%20to%20impersonate%20the%20requested%20user%22%20error%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-664561%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F327344%22%20target%3D%22_blank%22%3E%40alex3683%3C%2FA%3E%26nbsp%3B%3CSPAN%3EHi%2C%3C%2FSPAN%3E%3C%2FP%3E%3CDIV%3EPlease%20check%20those%20accounts%20that%20can't%20be%20impersonated%2C%20most%20likely%20they're%20unlicensed.%3C%2FDIV%3E%3CDIV%3EThis%20was%20a%20reason%20in%20our%20case.%3C%2FDIV%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-664644%22%20slang%3D%22en-US%22%3ERe%3A%20%22The%20account%20does%20not%20have%20permission%20to%20impersonate%20the%20requested%20user%22%20error%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-664644%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F327344%22%20target%3D%22_blank%22%3E%40alex3683%3C%2FA%3E%26nbsp%3BWe%20had%20exactly%20the%20same%20problem.%20The%20solution%20was%20to%20use%20the%26nbsp%3BX-AnchorMailbox%20header.%20More%20information%20is%20here%3A%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fblogs.msdn.microsoft.com%2Fwebdav_101%2F2015%2F05%2F11%2Fbest-practices-ews-authentication-and-access-issues%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fblogs.msdn.microsoft.com%2Fwebdav_101%2F2015%2F05%2F11%2Fbest-practices-ews-authentication-and-access-issues%2F%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%22%3CSPAN%3EWhen%20EWS%20Impersonation%20is%20used%20the%20X-AnchorMailbox%20always%20should%20be%20correctly%20set.%26nbsp%3B%20Without%20doing%20so%20you%20may%20get%20500%20or%20503%20errors%20at%20times.%20It%20is%20critical%20for%20performance%20and%20also%20for%20notifications%20with%20Exchange%20Online%2FExchange%202013.%26nbsp%3B%20Not%20setting%20it%20can%20double%20or%20more%20the%20time%20it%20takes%20to%20complete%20the%20call.%20In%20some%20cases%20you%20can%20also%20get%20timeouts.%26nbsp%3B%20The%20rule%20is%20to%20always%20set%20this%20header%20when%20using%20impersonation%20-%20this%20will%20make%20your%20EWS%20Impersonated%20code%20from%20Exchange%202007%20work%20better%20with%20Exchange%202013.%22%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-664766%22%20slang%3D%22en-US%22%3ERe%3A%20%22The%20account%20does%20not%20have%20permission%20to%20impersonate%20the%20requested%20user%22%20error%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-664766%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F353656%22%20target%3D%22_blank%22%3E%40stevereinhold%3C%2FA%3E%26nbsp%3B%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F255393%22%20target%3D%22_blank%22%3E%40SlavaG%3C%2FA%3E%20Thanks%20for%20your%20replies.%20I'll%20try%20your%20solutions%20and%20let%20you%20(and%20further%20visitors)%20know%20if%20that%20worked%20out.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-666556%22%20slang%3D%22en-US%22%3ERe%3A%20%22The%20account%20does%20not%20have%20permission%20to%20impersonate%20the%20requested%20user%22%20error%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-666556%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F353656%22%20target%3D%22_blank%22%3E%40stevereinhold%3C%2FA%3E%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F255393%22%20target%3D%22_blank%22%3E%40SlavaG%3C%2FA%3E%20Thank%20you%20both%20for%20your%20help.%20In%20the%20end%20it%20was%20really%20the%20missing%20X-AnchorMailbox%20header%20that%20resolved%20the%20issue%20for%20us.%20A%20pity%20that%20this%20isn't%20set%20by%20default%20in%20the%20EWS%20API%20when%20using%20impersonation%20with%20an%20email%20address.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

Hi,

Last week we're started to get "The account does not have permission to impersonate the requested user' error on the customer accounts that were working perfectly up to last week.

When, for example customer with 100 accounts that impersonated by 1 service account, we see each day errors for different impersonated accounts. 

Talking with support on behalf of the customer didn't provided any help. Their answers as usual.

While doing more research we're found that if doing 2 accounts impersonating in parallel (even from different servers) we get this error, and when doing 2 or even more accounts impersonating serial, everything is working fine.

I'm afraid that MS has a bug in their permissions checking mechanism while trying to impersonate more than 1 account in parallel.

MS Exchange engineers, can you please check this ? Your customer supports is lacks of willing to assist. 

Thanks

7 Replies
Highlighted
Not sure if this is a bug or you have hit a limit in terms of the number of impersonations that are possible for a specific account. I also recommend to open a support ticket explaining this problem because I think the Exchange Online Team might not see this thread
Highlighted

Well, if 2 accounts in parallel is hitting the limit :) than it's very sad.

There's a ticket within MS Support, but seems to be totally useless.

Highlighted

@SlavaGDid you ever find out why this happend or even resolved this? Currently we have the same problem for one customer using O365 Exchange, but we've got no clue why some users can be impersonated and some cannot. There are no management scopes set limiting the impersonated users on the impersonation role.

Highlighted

@alex3683 Hi,

Please check those accounts that can't be impersonated, most likely they're unlicensed.
This was a reason in our case.
Highlighted

@alex3683 We had exactly the same problem. The solution was to use the X-AnchorMailbox header. More information is here: 

https://blogs.msdn.microsoft.com/webdav_101/2015/05/11/best-practices-ews-authentication-and-access-...

 

"When EWS Impersonation is used the X-AnchorMailbox always should be correctly set.  Without doing so you may get 500 or 503 errors at times. It is critical for performance and also for notifications with Exchange Online/Exchange 2013.  Not setting it can double or more the time it takes to complete the call. In some cases you can also get timeouts.  The rule is to always set this header when using impersonation - this will make your EWS Impersonated code from Exchange 2007 work better with Exchange 2013."

Highlighted

@stevereinhold  @SlavaG Thanks for your replies. I'll try your solutions and let you (and further visitors) know if that worked out.

Highlighted

@stevereinhold @SlavaG Thank you both for your help. In the end it was really the missing X-AnchorMailbox header that resolved the issue for us. A pity that this isn't set by default in the EWS API when using impersonation with an email address.