Administrator Account has lost EMC access

This issue just started happening, I can still log in as Administrator and I can open the EMC but almost all the areas are greyed out and have a gold lock icon on the widows.  This is a server we have been using for years with no issues. 
Here are the groups that the administrator account is part of. 
Administrators, Domain Admins, Domain Users, Enterprise Admins, Group policy Creator Owners, Exchange- Organization Managment, Schema Admins, Exchange - Import Export Permissions Role Group.
I created a new user and gave the following rights - Domain admins, Exchange - Organization Managment.  This account works completely normally in the EMC. 
I also Deleted the Administrator user profile on the Exchange server and legged in and recreated it but it still has the issue.

Hi TJBenedict,
Base on my knowledge, there may be a mistake that you add the administrator to "View-Only Organization Management".
When the account in group of "View-Only Organization Management", administrator is unable to make any changes at any object level. All input fields are locked, as indicated by a yellow lock icon. Note that the Actions Pane on the right
also does not have several Actions such as New Mailbox, etc
More details for your reference:
http://blogs.technet.com/b/exchange/archive/2009/09/10/3408272.aspx
EMC and RBAC
Best regards,
Please remember to mark the replies as answers if they help, and unmark the answers if they provide no help. If you have feedback for TechNet Support, contact [email protected]
Niko Cheng
TechNet Community Support

Similar Messages

  • Server 10.4.4, administrator account has "access account" disabled

    Hi,
    I allowed a new tech to add users to our Xserve. Somehow he disabled the check box "access acount" in workgroup manager for the only administrator account. It now appears we cannot turn this back on! The end result is you can only access workgroup manager locally.Remote desktop and VNC now won't work. We can't re-enable the "access account" option for the administrator account or create new administrators as our only administrator account is now not active. I have no idea why you should be able to do this, but duplicated the problem on a test machine. If you create an admin account and uncheck the box "access acount" then the server can no longer be adminstrated!
    Any ideas?
    Dave

    answered my own question.
    logged in as root and resolved, phew

  • Administrator account has been disabled

    I've taken over support of Crystal Server 4.0 in my organization and was notified by a user that all scheduled jobs were failing with this error:
    login error. [CrystalEnterprise.DiskUnmanaged]: [Logon failure: the specified account password has expired.]
    I attempted to log into Central Management Console using the 'Administrator' account and password and receive the following:
    Account Information Not Recognized: The user account has been disabled. (FWB 00012)

    Hi David,
    Please follow the below steps:
    In Your Case only the Folder Name is changed other wise everything is same.
    Symptom:
    The password for the administrator password is lost and there is no other account with administrator rights to log in the CMC and reset the password for this user
    Resolution:
    The steps required to perform are detailed in the Installation guide attached in the references section. However, there is one mistake in the order of the steps.
    Page 71: Chapter 5.9.1 To reset the SAP BusinessObjects Business Intelligence platform administrator account password
    1. Locate the CMS process: launch the Process Explorer utility, and locate CMS.exe.
    2. Copy the CMS command to the clipboard. In Process Explorer, copy the "Command line" field.
    3. Use the Central Configuration Manager (CCM) to stop the SIA. To launch the CCM, go to Programs > SAP BusinessObjects Enterprise
    XI 4.0 > SAP BusinessObjects Enterprise > Central Configuration Manager. Once you have confirmed that the SIA has stopped,
    proceed to the next step.
    4. Paste the CMS command to a command-line. Do not press Enter. Open a "Command Prompt" window and paste in the contents from step3.
    5. Append the -serverconsole switch to the command and press Enter. For example, note that the following command has -serverconsole
    appended:
    "C:\Program Files (x86)\SAP BusinessObjects\SAP BusinessObjects Enterprise XI 4.0\win64_x64\cms.exe" -loggingPath "C:/Program Files (x86)/SAP BusinessObjects/SAP BusinessObjects Enterprise XI 4.0/logging/" -port 6400 -restart -dbinfo "C:/Program Files (x86)/SAP BusinessObjects/SAP BusinessObjects Enterprise XI 4.0/win64_x64/_boe_ACME.dbinfo" -noauditor -autoboot -fg -name ACME.cms - pidfile "C:/Program Files (x86)/SAP BusinessObjects/SAP BusinessObjects Enterprise XI 4.0/serverpids/ACME_ACME.CentralManagementServer.pid" -serverconsole
    The SIA is launched in serverconsole mode. You will be prompted when the SIA is ready to accept commands.
    6. Go to the following folder: <BOE_INSTALL_DIR>\SAP BusinessObjects\SAP BusinessObjects Enterprise XI 4.0\dfo The dfo folder
    contains a subfolder with a randomly generated name starting with dfo_.
    7. Copy the file named BusinessObjects_Administrator_dfo.xml from inside the dfo_ folder to the following folder:
    <BOE_INSTALL_DIR>\SAP BusinessObjects Enterprise XI 4.0\packages
    8. Enter the following query: select si_id from ci_systemobjects where si_name='Administrator' Four objects are returned. Record the
    SI_ID for each object.
    Tip: One of the entries should have the SI_ID set to 12.
    9. Delete the objects by typing the following command for each object: delete <ID_NUMBER>
    10. Verify that the objects have been deleted by re-entering the command from step 8: select si_id from ci_systemobjects where
    si_name='Administrator'
    No objects should be returned.
    11. Enter the following query: select si_id from ci_systemobjects where si_name='BusinessObjects_Administrator_dfo.xml' One object should be returned. Record the object's SI_ID number.
    12. Delete the object by entering the following command: delete <SI_ID>
    13. Type quit to exit.
    14. Use the CCM to start the SIA.
    15. Launch the CCM, go to Programs > SAP BusinessObjects Enterprise XI 4.0 > SAP BusinessObjects Enterprise > Central Configuration Manager.
    You can now log on to the administrator account without having to provide password (leave the "Password" field blank).
    Hope this will help you as well.
    Thanks,
    Daya

  • Built-in domain Administrator account not given full access to new Exchange 2013 server

    I migrated from Exchange 2010 to 2013 over the weekend.  I cannot log into the EAC with my domain administrator account I use to log into all my other servers.  I also cannot run the clean-mailboxdatabase cmdlet logged in as this user.  I
    had no trouble moving mailboxes from the old server to the new server with this account though.
    This account is a member of: Domain Admins, Enterprise Admins, Exchange Full Admin, Exchange Organization Admin, Organization Management, Schema Admins, Server Management.
    I can log into the EAC with another admin account that has the same memberships as the Administrator account.
    I tried giving the account the role of "Databases" as suggested by others to fix the clean-mailboxdatabase issue but that did not work for me either.
    The Administrator mailbox has been moved to the new database on the Exchange 2013 server.  The Exchange 2010 has been decommissioned and is turned off.

    Hi,
    Based on my research, to retrieves the mailbox statistics for the disconnected mailboxes for all mailbox databases in the organization, we can try the following command:
    Get-MailboxDatabase | Get-MailboxStatistics -Filter 'DisconnectDate -ne $null'
    http://technet.microsoft.com/en-us/library/bb124612(v=exchg.150).aspx
    Additionally, The Identity parameter specifies the disconnected mailbox in the Exchange database and it can be display name instead of mailbox GUID.
    http://technet.microsoft.com/en-us/library/jj863439(v=exchg.150).aspx
    Hope it can help you.
    Thanks,
    Angela Shi
    TechNet Community Support

  • C6-00 has lost AOL access

    Until 2 days ago, I had no trouble accessing AOL mail, but now it says AUTHENTICATE failure. I've tried using Profimail, the native Nokia email, and just going to AOL.com to log in. i have no problems logging on through a PC or my Nokia E7, which leads me to believe that AOL has done something that causes them to no longer recognize the phone or the version of Symbian? Any thoughts? Thanks.

    If you ever find out please let me know. Seems like the pre-defined settings takes priority and simply disables the user-defined settings previoulsy available.
    I even created an IMAP account with a non-existing pre-defined provider and where i configured advanced settings, access points and download limits etc, but when i then manually changed the definitions to my Gmail account it automatically switched to it's pre-defined state, disabling all advanced settings..
    Most annoying...
    Best regards!

  • Login in to my account has lost its settings

    I am in oman. I use a vpn to connect to internet. When I log into my account my contacts, profile picture and money!!! Have disapeared. Anybody knows why? And what to do?

    I am having the same issue this morning. I have one account on multiple devices (windows laptop, iphone5, ipad) and this morning all my devices asked to input my account login and pw again. After accessing the account my contacts  were not there anymore and my profile was empty.

  • Newbie question: how to tell if account has web services access?

    As the title suggests I am new to CRMOD though I have worked with other web Apis.
    Right now I have a CRM account but keep getting the "capslock" response in my SOAP call. I think it is because the account is just a regular account and is missing certain rights. How do I tell the admin to grant my account those rights? I'm not sure how to make such a request in words they will understand.

    Hello Daniel,
    You need to identify your role. If you go to mysetup you would know your role.
    Ask the admin to grant "Enable Web Services Access" prvilege to your role.
    This should be fine.
    Regards,
    Paul Swarnapandian

  • My icloud email account has lost all older emails.  What do I do, I don't see a way ti report this to Apple?

    Everthing older than January15, 201r is gone as of this morning.

    I should give more information.  I was on my iPad (original)  in Mail.  I was going through the message and it only displays so many.  At the bottom of the inbox list there was a notice that there were 67 more messages and an option to display.
    I tapped this several times and it did not display - just bounced me up to an eralier message.  Eventually the notice disappeared and there were no additonal message to display.  I thought the problem was with the iPad, but when I went to my main computer the messages were goen as well, so I went inot iCloud on the Web and the messages were gone there as well.
    If worst comes to worst I can use Time Machien to retrieve some of these, but I rarely use the MacBook that has time machine - so I may not be able to get them all.

  • SharePoint 2013 Administrative Account Permissions

    I'm looking for documentation about the permissions needed to administrate SharePoint Server 2013. My administrative account needs to have access to Central Administration, web applications, PowerShell, and local server resources like the file system, event
    logs, services, etc.
    I have found several articles that I had hoped would have the information but do not:
    Plan for administrative and service accounts in SharePoint 2013 literally has the sentence:
    This article does not describe security roles and permissions required to administer in SharePoint 2013.
    This upsets me as I am looking for the documentation that does describe the roles and permissions required to administer in SharePoint 2013 and this line offers no help other than telling me what I need isn't here. For anyone from the documentation
    team that happens to read this I offer the feedback that following that sentence there should be a link to the documentation that I am asking about here (assuming it exists ;)
    Initial deployment administrative and service accounts in SharePoint 2013 details permissions for the setup user account which is like an administrative account except that in my
    case the farm has been set up and I need to have administrative accounts.
    Account permissions and security settings in SharePoint 2013 describes the permissions accounts and groups are granted on individual resources on the server. While this is informative,
    it doesn't describe what rights I need to grant an account so it can administer.
    Use Windows PowerShell to administer SharePoint 2013 describes the permissions needed to run Add-SPShellAdmin to grant others administrative access, but doesn't actually
    describe the permission needed to use PowerShell to administrate.
    Does this information exist publicly?
    Jason Warren
    @jaspnwarren
    jasonwarren.ca
    habaneroconsulting.com/Insights

    Partner Support has confirmed there is no documentation that details specific rights needed for specific administration tasks. Given how the permissions depend on the task and how many tasks there are I don't see this ever appearing in official public documentation.
    I did some testing and I was able to use PowerShell as a non-admin, but I was limited to accessing objects that don't require the admin rights. For example I couldn't get the farm object (I get an exception) or the search service application (Get-SPEnterpriseSearchServiceApplication
    returns null), but I could list site collections and sites. Again, certain tasks require certain rights and this totally makes sense given the ability to delegate permissions built into the SharePoint platform.
    So where does this leave me? For now I suppose it needs to be tested on a case-by-case basis.
    For users who I want to administrate a farm with PowerShell, who have the ability to log into the servers to check local resources, services, logs, etc. practically they need to be local administrators and have SPShellAdmin. For anything else I would be
    looking at creating an account with no rights and gradually add permissions until I get to a level where it can perform the required tasks. If I want an account to manage site collections I may need Remote Desktop User machine group, SPShellAdmin against the
    content database, and site collection administrator (at the moment this is a guess).
    So in the end it seems there is no definitive answer or broad best practice for assigning permissions to administrators beyond testing it out to see what works and hiring administrators who you trust and are accountable for their actions.
    Jason Warren
    @jaspnwarren
    jasonwarren.ca
    habaneroconsulting.com/Insights

  • Administrator Account disabled

    Recieve run.dll errors on my laptop. Attempted to remove error by resfreshing. I lost apps and program files. Attempted to refresh lap to factory conditions. Now my laptop shows "Administrator account has been disabled". Unable to gets to windows program. Attempted to update BIOS. Was not able to select file from USB. 
    Any ideals....
    robcobb

    Hi there @robcobb 
    Welcome to the HP Support Forums! It is a great place to find the help you need, both from other users, HP experts and other support personnel.
    Since you already tried to do a factory restore,  I assume that you had already tried to backup any data on that driver first. So I offer the following, on the recovery process. Check through both pages, to verify what you were doing and also to see if the  troubleshooting portion is of use with what is happening on your machine.
    Performing an HP System Recovery (Windows 8)
    Troubleshooting HP System Recovery Problems (Windows 8)
    From what you wrote, I gather that the BIOS did not even start to update. This may have been due to how the USB key was setup. Your system should be UEFI, and be bootable your usb key would have to be prepared as well as a UEFI bootable device.
    Anyway if the recovery process still does not work for you, then please call our technical support at 800-474-6836. If you live outside the US/Canada Region, please click the link below to get the support number for your region.
    http://www8.hp.com/us/en/contact-hp/ww-phone-assist.html
    Malygris1
    I work on behalf of HP
    Please click Accept as Solution if you feel my post solved your issue, it will help others find the solution.
    Click Kudos Thumbs Up on the right to say “Thanks” for helping!

  • Msiexec /qn fails when its not run using the built-in local administrator account

    Hello all,
    I am working on a project where I am trying to automate the deployment of VMs through a self-service portal.
    Among other tasks such as clone VM, sysprep it, assign an IP, create AD computer object, join VM to domain and so on..., i need to install a few applications using msiexec, which is driving me crazy...
    For this purpose, I am using a local user account part of the administrators group.
    Please note, UAC is disabled on all the OS.
    Basically, the msi installation works as expected on Windows 7 machines, however on Windows 8/2012, it fails due to lack of permissions. The curious thing is that if I use the built-in\administrator account instead for the deployment on those systems, the
    application is installed correctly.
    I have tested some things such as: DisableMSI (http://msdn.microsoft.com/en-us/library/aa368304%28v=vs.85%29.aspx), but although it progresses a bit further, it keeps failing.
    Does anyone know what I can do to allow an user part of the administrators local group to be able to install using msiexec /qn?
    Thanks in advance.

    Hi,
    Does it work if you use the account in local admin, and run the commands prompt as administrator to install the msi file? Please know that Only the built in administrator account has admin privilege by default. On other admin accounts you need
    to run with elevated privilege (ie runas).
    I would like to know if you use SCCM to perform your deployment with task sequence.
    As I known, even if you disable UAC, the following policy is still enabled to detect application installation.
    Computer configuration\Windows settings\Security Settings\Local
    Policies\Security Options -> User Account Control: Detect application installations and prompt for elevation policy
    Please disable this policy to see if your issue can be fixed. 
    Kate Li
    TechNet Community Support

  • Administrator account gone

    Hi,
    When i first got my macbook i had always had problems trying to set up the administrator account since it hadnt been done during set up etc. however i got it working and everything was fine until i went overseas two months ago, only to recently use my macbook again to find that my administrative account has either gone or deleted itself and that i now cant do any updates, or use my word processors which i desperately need for uni. Do i have to go through the whole process again? (that is if i can find the installation cd)
    Thank you!

    make a new one under the system preferences "Accounts" panel.
    simple as that. just make sure the computer knows that it is an admin account, not a 'normal' account
    hope that helps
    -md55

  • Former Employee Obtained access to Administrator Account somehow and has been messing with roles, files ect... Just a question...

    Ok, so about six months ago, my company let go of their Systems Administrator because she was causing many problems in the workplace... Yesterday morning i logged onto the server and found several files open with her name on them, including her confidentiality
    agreement, and Employment offer letter, as well as the confidential folder that holds all employees personal identity information (she remote into the Server about 10 Minutes before i logged in, thus kicking her off not allowing her to close what she was opening/copying.
    I attempted to check the logs to see what IP she was connecting with but was only able to find the following:
    She remoted into the server about through Remote Desktop about 20 times on the 27th of May 2014, (horrible weather and she was probably logging in in a McDonald's Wifi and it kept kicking her off).
    I took the day off because my area was flooded and couldnt make it to work.
    She logged on, on the 28th of May, 2014 about 16 times before i logged on kicking her off, leaving everything she was doing open for me to see.
    Everytime i remote into the server from my house or the office i get the following...
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-TerminalServices-RemoteConnectionManager" Guid="{C76BAA63-AE81-421C-B425-340B4B24157F}"
    />
      <EventID>1149</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x1000000000000000</Keywords>
      <TimeCreated
    SystemTime="2014-05-28T03:24:49.860045100Z" />
      <EventRecordID>1943</EventRecordID>
      <Correlation
    />
      <Execution ProcessID="3884" ThreadID="3868" />
      <Channel>Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational</Channel>
      <Computer>Servername.server.local</Computer>
      <Security UserID="S-1-5-20" />
      </System>
    <UserData>
    <EventXML xmlns:auto-ns2="http://schemas.microsoft.com/win/2004/08/events" xmlns="Event_NS">
      <Param1>Administrator</Param1>
      <Param2>ServerName</Param2>
      <Param3>IP.IP.IP.IP</Param3>
      </EventXML>
      </UserData>
     </Event>
    when she would log in, there was no IP address everytime except the first time she logged in it seems, and looks like the following.. The first time she logged in remotley I have an IP address that seems to belong to a McDonalds using AT&T wifi,
    and was able to trace it to the center of town, and get a Longitude/Latitude...
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-TerminalServices-RemoteConnectionManager" Guid="{C76BAA63-AE81-421C-B425-340B4B24157F}"
    />
      <EventID>261</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x1000000000000000</Keywords>
      <TimeCreated
    SystemTime="2014-05-28T17:25:03.210845100Z" />
      <EventRecordID>1969</EventRecordID>
      <Correlation
    />
      <Execution ProcessID="3884" ThreadID="4224" />
      <Channel>Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational</Channel>
      <Computer>Servername.Server.local</Computer>
      <Security UserID="S-1-5-20" />
      </System>
    <UserData>
    <EventXML xmlns:auto-ns2="http://schemas.microsoft.com/win/2004/08/events" xmlns="Event_NS">
      <listenerName>RDP-Tcp</listenerName>
      </EventXML>
      </UserData>
      </Event>
    As you can see no IP address is shown unlike everyone other PC that remotes into the server... She has been using our server as her personal file host for her real estate business, she was fired last year for sabotaging AutoCad drawings her ex boyfriend
    was working on (they are back together and was the one she set up with full access to server)  and she has been adding and modifying files in her group drive via the administrator account. She also disabled several roles we had installed, and gave her
    boyfriend (who happens to work at the company) More administrator right than myself, as I built the server from ground up, and Only the Company owners had access to remote desktop, besides the administrator account... I want to make sure she didn't create
    any hidden accounts that she can still log into.. I found under ADSI Edit Under Domain Controllers, Subscription Properties an account (servername$) which doesn't not show up in active directory, but had full access to everything... Is there a way to uncover
    hidden Accounts she may have created to get into the server, as I've know from previous experiences, that $ sign normally refers to a hidden account or file of some sort.. Any help with this would be greatly appreciated, The FBI is currently investigating
    the situation, but i am trying to make sure all my basis are covered so this doesn't happen again... Thank you for taking the time to read my long ass thread, I will bestow upon you great fortune and Karma for any help given =-D

    Hello,
    the $ behind the machine name object is normal.
    For security related questions please use
    http://social.technet.microsoft.com/Forums/windowsserver/en-US/home?forum=winserversecurity
    Also I would immediately remove all people form any kind of administrative groups, MUST of course be agreed from the company owner, then change the administrator account password. If there is a need for the additional administrators the company chief
    has to agree on this and there should also be made some clear rules, maybe from a lawyer about consequences etc. Remote access to the network should be blocked or made more secure with two factor authentication, tokens for example, just using Remote Desktop
    at the moment I would not allow until the network is better secured and you can be sure there are no unknown administrative accounts.
    Best regards
    Meinolf Weber
    MVP, MCP, MCTS
    Microsoft MVP - Directory Services
    My Blog: http://msmvps.com/blogs/mweber/
    Disclaimer: This posting is provided AS IS with no warranties or guarantees and confers no rights.

  • After trying to change permissions on my computer so others on my network can access files, my external Hard Drive has a lock on it and I can't access files. I've tried repairing permissions, logging in under another Administrator account, using Terminal

    After trying to change permissions on my computer so others on my network can grab files, my external Hard Drive has a lock on it and I can't access files. I've tried repairing permissions, logging in under another Administrator account, using Terminal to fix the problem, downloaded BatChmod but nothing works… Any other suggestions? I have an Imac running OS10.6.8.

    There is suddenly a lock icon on my external backup drive!
    Custom Permissions

  • HT201272 I have over 350 songs that were lost on mutliple devices in an accident. My account has been the same for years but I can't access my old library. Help!!

    I have over 350 songs that were lost on mutliple devices in an accident.The original computer and Ipod were lost. My account has been the same  for years but I can't access my old library. Help!!
    <Email Edited by Host>

    Whatever you bought from iTunes is yours forever and can be downloaded as many times as you want. This assumes what you purchased is still available in the Store.
    Here is the procedure for your reference.
    On a computer, launch iTunes. Click on iTunes Store on the left
    On the right you will see this
    "Sign in" using the Apple ID used to purchase your songs, then click on "Purchased" (with the orange blob)
    On the summary page that appears select the tab "Not on This Computer" on the right.
    On the list that appears, select what you want and then click the "Download" button.
    Whatever you have that did not originate from iTunes will have to be obtained from whatever means you used to obtain it in the past.

Maybe you are looking for

  • LaserJet Pro 400 M401dn - 79 SERVICE ERROR

    We have only had this printer less than a year and I am getting a 79 SERVICE ERROR.  I have power cycled, unplugged and all the normal tries... no go.  It will print the menu map but will not accept a print job from a user. I try to get to the printe

  • How do I get 4 monitors on Mac Pro?

    I've got a MacPro with the following specs: Model Name: Mac Pro Model Identifier: MacPro4,1 Processor Name: Quad-Core Intel Xeon Processor Speed: 3.32 GHz Number Of Processors: 1 Total Number Of Cores: 4 L2 Cache (per core): 256 KB L3 Cache: 8 MB Mem

  • Archiving MM documents

    Hi Gurus, I need help in archiving SAP documents. By T.Code ABOJ, I am directed to Archiving object MM_EKPO. After that, how will I archive POS and STOs? I need to extract them from SAP database and put those documents as flat files in the computer.

  • Authorization about Web Dynpro ABAP

    Dear all:              I have some problem withs the authorization about the web dynpro for abap.Please give me some advices. For example: In my web dynpro abap,i have two tabs,one is "upload",anthor is "preview".Now there are two users, in this exam

  • PDF indexing and multiple searches.

    Dear members: Please forgive me if my question is rather basic but I haven't been able to find the exact answers I am looking for in order to address my project needs. I have a folder where I keep all of my PDF files. These are all articles from medi