Cannot access Exchange Mgmt Shell - user "Domain\Administrator" isn't assigned to any management roles

This is a new domain-joined Server 2012 member server with no data. Domain Administrator account is in the Organization Management group. Domain functional level is Server 2012.
Setup /m:RecoverServer fails because "...server roles are already installed..."
Uninstall fails because the "mailbox database contains one or more mailboxes..." which I can't delete.

Hi,
I recommend you refer to the following article to troubleshoot the issue:
https://social.technet.microsoft.com/wiki/contents/articles/14874.error-the-user-domain-localusersadministrator-isnt-assigned-to-any-management-roles-on-exchange-2010-management-console.aspx
we may try to propagate the RBAC permissions for the user again! procedure is as below:
1.
Open Windows Powershell as  “Run As Administrator”
2.
Load the setup Snapin with the command: Add-Pssnapin *Setup*
3.
Run the commands one after the other to propagate the RBAC to the user who is logged on to the Exchange Server.
a. Install-CannedRbacRoleAssignments  –InvocationMode Install
b.
Install-CannedRbacRoles
c.
Install-CannedRbackRoleAssignmentsRAP
d.
Install-CannedAddressLists
Thanks.
Niko Cheng
TechNet Community Support

Similar Messages

  • Windows 7 pro client cannot access folders on server 2003 domain server

    I added a windows 7 64 bit client to a server 2003 32 bit domain 3 weeks ago and file sharing was working fine until today, 5/4/12. Now, when trying to access shared folders that reside on the server,
    I get the following "access denied" message:
    […folder…] is not accessible. You might not have permission to use this network resource. Contact the administrator of this server to find out if you have access permissions.
    The user name could not be found.
    Strangely enough...
    The windows 7 client
    can open shared folders that reside on the XP clients in the domain
    All the XP clients in the domain can access the server 2003 folders
    All the XP clients and the server 2003 machine can access shared folders and printers on the windows 7 client.
    The windows 7 client can ping the server 2003 machine and vice versa
    I can “see” the server in my network list, but when I click on it, I get the same “access denied” message listed above.
    So... the only problem is that the windows 7 client cannot access folders that reside on the windows server 2003 machine. There must be some sharing setting that got changed
    by a recent windows update.
    Here is what I have done/verified so far on the windows 7 client:
    In advanced sharing settings for Home/Work, Public and Domain profiles:
    network discovery is enabled
    file and print sharing is enabled
    use user accounts and passwords to connect to other computers is selected (I also tried allowing windows to manage homegroup connections instead, but the problem remained.)
    40 -56 bit encryption is enabled
    In “gpedit.msc” Local Policies/Security Settings:
    enabled the following policies:
    Network access: Allow anonymous SID/name translation
    Network access: Let Everyone permissions apply to anonymous users
    disabled the following policies:
    Network access: Restrict anonymous access to Named Pipes and Shares
    Network access: Do not allow anonymous enumeration of SAM accounts
    Network access: Do not allow anonymous enumeration of SAM accounts and shares
    What am I missing? Are there policies on the server that need to be adjusted?
    Please help! My business is crippled if I cannot access server files from this workstation. Thank you in advance.

    As this thread has been quiet for a while, we assume that the issue has been resolved. At this time, we will mark it as ‘Answered’ as the previous
    steps should be helpful for many similar scenarios.  <o:p></o:p>
    If the issue still persists and you want to return to this question, please reply this post directly so we will be notified to follow it up. You
    can also choose to unmark the answer as you wish.  <o:p></o:p>
    In addition, we’d love to hear your feedback about the solution. By sharing your experience you can help other community members facing similar
    problems.  <o:p></o:p>
    Thanks!<o:p></o:p>
    Arnav Sharma | http://arnavsharma.net/ Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading
    the thread.

  • Cannot access exchange attribute from java

    I have tried to access pwdLastSet attribute for a particular staff inside the Active Directory 2008, works fine. However when I try to access msDS-UserPasswordExpiryTimeComputed I get null pointer exception. The value associated with this attribute is available. Infact I am getting error for all msxxxx fields. I am unable to understand why I cannot, access these attributes.
    Attribute attr=attrs.get("pwdLastSet"); ---> works fine
    //Attribute attr=attrs.get("msDS-PrincipalName"); ---> throws an exception.
    Would appreciate help to resolve my problem.

    //Attribute attr=attrs.get("msDS-PrincipalName"); ---> throws an exception.If that throws a NullPointerException it can only be because attrs is null. Or else you need to post the stack trace here.

  • Cannot access itunes on iphone, nothing wrong with wifi, no problems with any other site!

    cannot access itumes with new iphone.  the internet is not the problem.  I can go to itunes on computer.  apple is losing business!!!!

    Since you have a few updates pending, would you be willing to use iTunes on your computer to do the updates?  That should be easier relative to downloading the updates.  You could use iTunes (version 11.0.1 on your computer), click "Apps" in the upper left, "Check for Updates" in the lower right, let them update, and then sync your iPad.

  • User cannot access Crystal reports after user was deleted and recreated

    We are using Crystal Enterprise XIr2.  We are using Windows AD authentication.  We had an issue with a user where they were deleted in Active Directory.  Now they can no longer run Crystal reports.  When I go into the CMC and open users I see this user.  When I try to open this user I get the following error
    There was an error while retrieving data from the server: Active Directory Authentication failed to get the Active Directory groups for the account with ID "8B003DF11D45B244AC3B61AB36B6C445:ALLENDG". Please make sure this account is valid and belongs to an accessible domain.
    I think Crystal is still trying to access the user's old Active Directory account.
    I cannot delete the user either in CMC.
    Is there someway I can correct this user.
    Thanks
    Adam

    Arjun - Thank you for your help.  I looked in Central Management Console but I could not find what you indicated.
    CMC--> Public Folder --> Administration Tools
    In administration tool, there are two objects
    1) Update Windows AD Group Graph
    2) Update Windows AD Group Graph and Aliases --> Right click on this Report and click on RUN Now.
    I ended up deleting the records for this user in these SQL tables and then user could access InfoView
    CMS_Aliases5 (2 records for this user)
    CMS_InfoObjects5 (1 record with both aliases)

  • Win 7 Client cannot access Win 2012 share by domain name

    Hello Everyone,
    We have Windows 2012 R2 Server configured as Domain cum File Server Role,
    There are 20 Win7 Clients / Domain Users who access and used their specific folder on server with \\Servername\Foldername
    After some hour (not fixed) for some users (not specific) the server path goes unavailable, but the same folder is accessible with IP address like \\192.168.1.1\Foldername. and after rebooting Win7 Client we can again access the server folder with name.
    This happen to any users anytime and the same time other users can access their folder by name,
    Please help me on this issue..
    Thanks in Advance

    > After some hour (not fixed) for some users (not specific) the server
    > path goes unavailable, but the same folder is accessible with IP address
    > like \\192.168.1.1\Foldername. and after rebooting Win7 Client we can
    > again access the server folder with name.
    This is a kerberos issue.
    By default, tickets (especially the TGT which is issued at logon) have a
    live time of 8 hours or so (can be adjustet). If this ticket expires and
    cannot be renewed (due to a lack of connectivity to a DC or whatever
    infrastructure issue), Kerberos fails and ressources cannot be accessed
    via name.
    IP on the other hand always uses NTLM and thus still works.
    How the Kerberos Version 5 Authentication Protocol Works:
    https://technet.microsoft.com/library/cc772815.aspx
    Martin
    Mal ein
    GUTES Buch über GPOs lesen?
    NO THEY ARE NOT EVIL, if you know what you are doing:
    Good or bad GPOs?
    And if IT bothers me - coke bottle design refreshment :))

  • Cannot access folders and files even with Administrator rights

    Hours & days gone trying to solve niggling issues that Microsoft cannot fix (using the built-in diagnosis tools/compatibility options/MS promises to advise when solutions found). But I am stopped from progress by restrictions to folder & file access preventing self-diagnosis. Why are administrator rights not effective? How do I as Administrator give myself access rights? If not available how do I return to XP and retrieve the cost of Windows 7? Note that the PC compatibility test tool for Win7 upgrade from XP noted no significant problems!

    It appears that these are symbolic links and that WIn7 hasn't got the wherewithal to follow the symlink to the real folder to assess the security settings. - Hence everyone's frustration.
    For those of us who are extremely technical, we'd like to be able to remove and re-create a link as needed to test a scenario...
    I've done it for years with Altos Xenix, SCO Xenix, SCO OS/5, AIX and Linux from Caldera 2.2 through todays versions... Windows has been moving in a direction to incorporate more *nix like concepts as they move away from their DOS orientation, but in the process
    they have focused on the "general user" at the expense of the "administrative user" (i.e. "root" in *nix)
    I've always wanted to try a stripped down, non-backwards compatible, Windows Server. I'm sure it could be made admin-friendly and allow push updates without spending thousands of dollars on push-update software mechanisms... But so far, they've missed the boat.
    I have 1 Win7Prof PC at home, 1 Mac and 2 Debian systems. Both the Win and OS/X systems make it very hard to administer/customize/etc. the OS. The 2 Debian systems give more bang for the buck and don't inhibit the root user at all once you make 2 changes (using
    "su root" as a user) in /etc/pam.d to allow logging into the desktop as root.
    We can always hope MS will see those of us who recommend server platforms as a market at some point. (Wouldn't it be awesome to have basic *nix constructs available for admins? And "bash" vs. "cmd"?)
    I certainly don't see any need to utilize Windows except in those cases where some vendor/site is compatible with MS/IE only. There are a few of them and I rail on them constantly to be platform independent. Our software is. It takes a lot of work, but
    we use Apache/MySQL/PHP to deliver our medical practice management application from any of the *nix-OS/X-WinServer server platforms to anyone who has Chrome/FireFox/Safari/Opera/IE or
    similar browsers. But administering the server platform under Windows is about 5 times more time intensive to install and about 10 times more time intensive to maintain than *nix platforms.
    We have about 200 Linux servers we are able to support with 4 staff. We have about 50 Windows servers we are able to support with 4 staff.
    With numbers like that, I don't see us leaning toward Windows in the foreseeable future.

  • Cannot access network shares on AD domain

    I've joined my mac to an AD domain (over vpn tunnel). I used the Directory Access app and when I did a "bind" to the domain all seemed to go well.
    However when I try to access a network share using the "Connect to Server" menu item:
    smb://server/share
    I get this error:
    The Finder cannot complete the operation because some data in...could not be read or written. (Error code -36)
    Ok I've tried googling this error message. Could someone tell me what this means? Could you point me to documentation on how to do what I'm doing?

    Can you access the share while in the office?
    Can you access the share by using the servers IP address instead of name?

  • Cannot access Exchange 2013 powershell after cu6 update

    Hi All,
    Getting this error message when I try to access powershell.
    The WinRM client cannot process the request. It cannot determine the content type of the http response"
    Any ideas?

    thanks but i notice that the update stopped at the mailbox role: transport service.
    will the same solution above work?
    Error:
    The following error was generated when "$error.Clear();
     $connectors = Get-ReceiveConnector -Server $RoleFqdnOrName;
     foreach($connector in $connectors) { if($connector.MaxLocalHopCount -gt 1) { Set-ReceiveConnector -Identity $connector.Identity -MaxLocalHopCount 5 } };
     " was run: "Microsoft.Exchange.Management.SystemConfigurationTasks.ConnectorMappingConflictException: The values that you specified for the Bindings and RemoteIPRanges parameters conflict with
    the settings on Receive connector "EX2013\Incoming from Internet - Dummy". A Receive connector must have a unique combination of a local IP address & port bindings and remote IP address ranges. Change at least one of
    these values.
     at Microsoft.Exchange.Configuration.Tasks.Task.ThrowError(Exception exception, ErrorCategory errorCategory, Object target, String helpUrl)
     at Microsoft.Exchange.Configuration.Tasks.Task.WriteError(Exception exception, ErrorCategory category, Object target)
     at Microsoft.Exchange.Management.SystemConfigurationTasks.SetReceiveConnector.InternalValidate()
     at Microsoft.Exchange.Configuration.Tasks.Task.<ProcessRecord>b__b()
     at Microsoft.Exchange.Configuration.Tasks.Task.InvokeRetryableFunc(String funcName, Action func, Boolean terminatePipelineIfFailed)".
    Error:
    The following error was generated when "$error.Clear();
     $connectors = Get-ReceiveConnector -Server $RoleFqdnOrName;
     foreach($connector in $connectors) { if($connector.MaxLocalHopCount -gt 1) { Set-ReceiveConnector -Identity $connector.Identity -MaxLocalHopCount 5 } };
     " was run: "Microsoft.Exchange.Management.SystemConfigurationTasks.ConnectorMappingConflictException: The values that you specified for the Bindings and RemoteIPRanges parameters conflict with
    the settings on Receive connector "EX2013\Default
    Frontend EX2013". A Receive connector must have a unique combination of a local IP address & port bindings and remote IP address ranges. Change at least one of these values.
     at Microsoft.Exchange.Configuration.Tasks.Task.ThrowError(Exception exception, ErrorCategory errorCategory, Object target, String helpUrl)
     at Microsoft.Exchange.Configuration.Tasks.Task.WriteError(Exception exception, ErrorCategory category, Object target)
     at Microsoft.Exchange.Management.SystemConfigurationTasks.SetReceiveConnector.InternalValidate()
     at Microsoft.Exchange.Configuration.Tasks.Task.<ProcessRecord>b__b()
     at Microsoft.Exchange.Configuration.Tasks.Task.InvokeRetryableFunc(String funcName, Action func, Boolean terminatePipelineIfFailed)".

  • TS4363 cannot access exchange account thru calendar in mountain lion

    after upgrading, in addition to all the other exchange issues that everyone is having, i also find that i cannot even attempt to change settings in calendar when i go to click on the exchange account under options.  it simply gives me the middle finger spinning wheel of death.  then i have to force quite calendar.
    am i alone here?
    perhaps this is realted to the other exchange issues?   i hope apple fixes this. i've had to resort to using my PC as a back up.

    tjparchitecture wrote:
    after upgrading, in addition to all the other exchange issues that everyone is having,
    I am having no Exchange issues at all (SBS 2011 and Mail/Contacts/Calenders). How about some details?

  • Remote: cannot access Library if another user is logged in

    hi all
    Remote works fine for me, no firewall issues, a great solution! But if someone goes to the computer and switches users, then I cannot connect to the Library. Is it only me? Any ideas for a workaround? My daugther uses the other Mac and it means I still have to go to the iMac and switch users back to mine before I can control the music. Defeats the purpose somewhat...

    If its a fresh installation, RDM might not work at first.
    1. You need to check firewall and allow Remote Desktop. To be specific, communication to port 3389 TCP
    2. Right click My Computer --> Properties --> Remote tab
    Enable Remote Desktop
    Allow connections to this computer
    Click users and grant the permissions for the users. By default, Administrators do have the permission. An also, the users who are members of the 'Remote Desktop Users' security group also have the permission

  • Cannot access attachments from Windows users

    Recently I've had a few emails from friends using Windows with attachments (usually daft videos or the like).
    The message shows up in mail.app at being around 3Mb, for example, and in the mail list shows as having 2 attachments.
    When I open the message it only shows 1 attachment (usually their little 10Kb signature graphic or some such), but not the main, large, attachment.
    Anyone else experienced this, or found a solution?
    Steve

    I assume that both machines are on the same home network, and that there are no external gateways/routers/firewalls etc. in the way? No wireless networks?
    Is the Windows machine XP, or something else? What are the firewall settings on the Windows machine? Can you access any other FTP site from the PC?

  • I cannot access or reinstall Itunes, and my ipod isn't being detected

    So, sometime after the fall of 2010, which I suspect was after iTunes 10 was launched, I noticed I couldn't access iTunes.
    It read error 2330.
    I did some sleuthing for months, and now I get these error messages under the heading "iTunes + Quicktime" when I attempted a re-installation of iTunes:
    "There's a problem with this Windows Installer package. A program required for this install to complete could not be run. Contact your support personnel or package vendor"
    "An error occurred while attempting to create the directory: C:\Documents and Settings\All Users\Application Data\Apple Computer\iTunes"
    In the past while attempting to re-install iTunes, I got error message 2330...STILL don't fully know what this means.
    I currently have Bonjour, the iTunes folder, The iPhone Configuration Utility folder, and Quicktime on my desktop...The actual programs are also in my C:\ drive in Program Files...I can also see Apple software in the Add/Remove Programs section of the Control Panel on my PC.
    I seem to be able to access iTunes/iTunes store via the executable file in the iTunes folder by clicking "iTunes.exe", but no other way...I also noticed that the software will run normally, but not detect my iPod or allow my computer access...So in other words, iTunes doesn't recognize my computer as being authorized for my account, and yet it displays my email address in the upper-right hand corner of iTunes.
    It's like I can only access a "half version" of the full iTunes I once had by going through that folder...No clue what's happening or what files may be missing or corrupted.
    Quite simply put, I need help...I want to be able to use iTunes and my iPod Touch (1st gen) like I was able to this past fall before the mysterious accident or corrupt files ruined everything.

    For that 2330 error, run chkdsk on your C drive.
    How to perform disk error checking in Windows XP
    http://support.microsoft.com/?kbid=315265

  • Cannot access YouTube. Error message: The page isn't redirecting properly Firefox has detected that the server is redirecting the request for this address in a way that will never complete.

    I accessed YouTube briefly, but as soon as I linked my YouTube account to my Google account (now required by YouTube), I got that message.

    Hey, I have an easier solution. No need to wipe all of your cookies or restart firefox:
    Go to Tools > Options, select the Privacy Tab, then click on the link to "remove individual cookies".
    In the window that comes up, type youtube into the Search box at the top, and then remove all of the cookies that are displayed.
    Now when you visit youtube.com you'll be signed out of your account, and you can sign back in without getting the redirect error.

  • I cannot access the recently added folder in Instagram on my iPad.  Any ideas why?

    when trying to access photos  on my iPad in Instagram I can access my shared photo streams but not the recently added folder and the photos taken on my iPhone.  Any ideas?

    Hello wintergreenchip,
    The troubleshooting steps detailed below can help get your Photo Stream working correctly.
    Your device will keep up to 1000 photos, even if they're older than 30 days. Photos older than 30 days are removed from the iCloud server, so your devices might not have the same photos, depending on when you enabled My Photo Stream. Due to storage limitations, your Apple TV might display only your most recent photos.
    If you want to have the most current photos in My Photo Stream on each of your devices and delete the older photos:
    If there are any photos in My Photo Stream that you want to keep, save them to your Camera Roll, then back up your Camera Roll and other data using iCloud or iTunes.
    Turn My Photo Stream off in Settings > iCloud > Photos (or Photo Stream in iOS 6).
    Confirm that you wish to Delete Photos.
    Turn My Photo Stream back on. iCloud will automatically push your stored photos to your device.
    Repeat these steps for each device.
    iCloud: Get help using My Photo Stream
    http://support.apple.com/kb/TS3989
    Cheers,
    Allen

Maybe you are looking for

  • My Ipod touch 3rd Gen. will not turn on

    I have a 3rd gen ipod touch. I have tried charging it but it will not turn on or do anything. I have tried hooking it to my laptop but it will not show up as being connected. Any ideas?

  • HD video using Macbook

    Is there any way to edit HD video on a Macbook 2GHZ Intel core 2 duo without it being RIDICULOUSLY slow? I can't even play back a track in the sequence without having to render first, and if i edit that same track, i have to render again for playback

  • Do I need to download Real or Win Media Players

    I have attempted to download "Arkansas Week" found at AETN.org. The applications provided Real or Win media players. Do I need one of the them on my iMac?

  • I just noticed that my ethernet port stopped working.

    I looked, and it seems to be a bit damaged. I also noticed that the power supply chord tends to come loose. How much do you think it will cost to have this fixed at the Apple Store? Will it be worth it?

  • Apple TV optical out to DAC plus HDMI to receiver?

    I currently have my Apple TV connected to my Denon AV receiver via HDMI which then outputs 5.1 audio and video to the TV. My hope is to also stream my lossless iTunes music library to Apple TV (from my Mac Mini) which would take the audio from the AT