Exchange 2007 Experts - Impersonate user help please

Hello,
We use Exhcange 2007 (2 x CAS & 2 x MBX servers)
We have 2 issues:
1.)
We are trying to get our a hosted CRM sysem called ForceManager to Impersonate some users.  What is strange I create a new user and then run these commands and Exchange accepts them:
Add-ADPermission -Identity "forcetest" -User "forcemgnsync" -ExtendedRights ms-Exch-EPI-May-Impersonate
WARNING: Appropriate ACE is already present on object
"CN=forcetest,OU=Test,OU=Spain,DC=contoso,DC=local" for account
"CONTOSO\forcemgnsync".
Identity             User                 Deny  Inherited Rights
CONTOSO.LOCAL/Spain... CONTOSO\forcemgnsync    False False     ms-Exch-EPI-May-Im...
Get-Mailbox -Identity forcetest | Get-ADPermission -User forcemgnsync | fl
User                : CONTOSO\forcemgnsync
Identity            : CONTOSO.LOCAL/Spain/Test/forcetest
Deny                : False
AccessRights        : {ExtendedRight}
ExtendedRights      : {ms-Exch-EPI-May-Impersonate}
IsInherited         : False
Properties          :
ChildObjectTypes    :
InheritedObjectType :
InheritanceType     : All
User                : CONTOSO\forcemgnsync
Identity            : CONTOSO.LOCAL/Spain/Test/forcetest
Deny                : False
AccessRights        : {ExtendedRight}
ExtendedRights      : {ms-Exch-EPI-Impersonation}
IsInherited         : False
Properties          :
ChildObjectTypes    :
InheritedObjectType :
InheritanceType     : All
But ForceManager say the account still doesn't have rights to impersonate, any ideas?
2.)
If I try the same commands on an existing user (have tried many) it can't even find them:
Add-ADPermission -Identity "bill" -User "forcemgnsync" -ExtendedRights ms-Exch-EPI-May-Impersonate
Add-ADPermission : bill was not found. Please make sure you have typed it correctly.
At line:1 char:17
+ Add-ADPermission <<<<  -Identity "bill" -User "forcemgnsync" -ExtendedRights
 ms-Exch-EPI-May-Impersonate
    + CategoryInfo          : NotSpecified: (0:Int32) [Add-ADPermission], ManagementObjectNotFoundException
    + FullyQualifiedErrorId : D5B1825B,Microsoft.Exchange.Management.Recipient
   Tasks.AddADPermission
Hope you guys can help, I'm really struggling as I'm not really an Exchange guy.
Regards

same issue, trying with another user via the CAS servers:
get-mailbox anovo
Name             Alias            ServerName       ProhibitSendQuo
                                                                ta
Alejandro Novo   anovo            ccf-exch-vmbx    unlimited
Add-ADPermission anovo -User "forcemgnsync" -ExtendedRights ms-Exch-EPI-May-Impersonate
Add-ADPermission : anovo was not found. Please make sure you have typed it corr
ectly.
At line:1 char:17
+ Add-ADPermission <<<<  anovo -User "forcemgnsync" -ExtendedRights ms-Exch-EPI
-May-Impersonate
    + CategoryInfo          : NotSpecified: (0:Int32) [Add-ADPermission], Mana
   gementObjectNotFoundException
    + FullyQualifiedErrorId : D5B1825B,Microsoft.Exchange.Management.Recipient
   Tasks.AddADPermission

Similar Messages

  • Brand new Mac user help please! How do you connect a 17" monitor to the MacBook? I have the monitor plugged into the Mac, but the F8 that I am used to with PC does not work. Please help. Thanks.

    Brand new Mac user help please! How do you connect a 17" monitor to the MacBook? I have the monitor plugged into the Mac, but the F8 that I am used to with PC does not work. Please help. I am getting lots of spelling errors as the MacBook laptop screen is too small. Thank you so much! .

    Contentmom6 wrote:
    Brand new Mac user help please! How do you connect a 17" monitor to the MacBook? I have the monitor plugged into the Mac, but the F8 that I am used to with PC does not work.
    Normally, you just connect the monitor to the MacBook using a VGA adaptor that you can buy from an Apple Store.  Now try System Preferences > Displays > Detect Displays.  You should now be able to select a display mode for the monitor.  If it still doesn't work, then I'd check that everything is properly connected.  I've had problems with colours disappearing due to a faulty connection in the VGA adaptor.
    Bob

  • First time Nokia user - help please!

    Just got my first ever Nokia (6303).  I seem to be having troubl;se with a couple of things, that I hope some of you can help me with please
    Firstly, I've signed with the ovi store and everything's fine on the computer (signing in etc) BUT I can't sign in using the mobile.  A message keeps coming up, saying my user name or password is wrong - but I know they are right!
    Secondly, how do I put a sim lock on, where I need to enter a password when the phone turns on?
    Thanks in advance

    U can read the user guide for your device here: http://nds1.nokia.com/phones/files/guides/Nokia_6303_classic_UG_en.pdf

  • Portlets can not be seen by Public Users: Help Please!

    Hi,
    I have seen another message that might be the same that is happening to me. I have created a content area, with folders and items. I have selected all available options to make them public , appart from publish them as portlets. I have added them to a page but when I enter the page as a Public User (without logging into Portal) the portlets can not be seen...There are others that can be seen ...Could you help me with this?
    Many thanks
    Mariela

    I assume you're using the generic folder portlet to view the folders.
    If you publish a folder as a portlet, are you able to see it?

  • Hello I have just bought light room five, done the download and it won't open because it doesn't recognise the user, help please

    Hello

    Thank you for your reply,  using a MacBook Pro which is up to date, on not that cloy as you can Work out, I bought from camera  electronic's in Perth Western Australia, I thought I was getting at desk and I got a card with numbers on, I put the numbers and it gave me A serial number and it said download White Room which I did, I went into downloads and clicked on it, it said I'm unable to recognise user, I tried five times and the sam, Kevin

  • Firepod users,  help please

    I had a problem a few weeks back where through my headphones on the firepod, sound would only come through one speaker. Turned out I had a Mono headphone adapter. So I got some stero adapters, everthing worked fine. But all of the sudden for no apparent reason it's happening again even with the stereo adapter. What do I do. Thanks all, you're great

    actually I restarted and now it works, but what the ****?

  • Exchange 2007 migrate to Exchange 2013

    Dear MS Support,
    I did migrate Exchange 2007 to Exchange 2013
    The install complete, the exchange 2007 and 2013 can work together successful
    DAG has created and work fine
    Below is capture on exchange group after migrate
    The exchange 2007 work fine with outlook anywhere, all the users can connected and send and receive mail in 5 year
    The cerificate enroll with
    Alternative Names: mail.biendongpoc.vn
    The autodiscover on exchange 2007:
    [PS] C:\Windows\system32>Get-ClientAccessServer | ft Identity,*uri* -AutoSize
    Creating a new session for implicit remoting of "Get-ClientAccessServer" command...
    Identity      AutoDiscoverServiceInternalUri
    BDPOC-SERVER1 https://mail.biendongpoc.vn/Autodiscover/Autodiscover.xml
    I have created new certificate for Two exchange 2013
    The certificate enroll with
    Alternative Names: cas.biendongpoc.vn
    I have create cname cas point to dag  on DNS server
    I have create A record autodiscover.biendongpoc.vn point to IP of dag.biendongpoc.vn
    I did migrate mailbox from exchange 2007 to exchange 2013, the migrate successful , the outlook can
    connected to Exchange 2013 and working perfectly
    Our problem, the account exchange 2007 work not stable ,
    sometime it connect to mail.abc.com, sometime it connect to cas.abc.com
    If the outlook connect to cas.biendongpoc.vn, the request put password and i can't connect to exchange 2007, if outlook connect to mail.biendongpoc.vn i can connect
    It is not stable for current exchange 2007
    Anyone who can help me ?
    Thanks

    Hi
    huynhtrongnhatminh,
    I suggest you please go through this article.
    http://blogs.technet.com/b/exchange/archive/2014/03/12/client-connectivity-in-an-exchange-2013-coexistence-environment.aspx
    Please check this for step by step guide.
    http://blogs.technet.com/b/meamcs/archive/2013/07/25/part-1-step-by-step-exchange-2007-to-2013-migration.aspx
    Please point your autodiscover and commonname to Exchange2013 CAS
    Please configure your URLs. There is no CAS array in Exchange2013 but the concept of single name space remains.
    You need to have an A record (e.g. legacy.domain.com) in yout external DNS and add that name (legacy.domain.com) in your certificate for exchange 2007 users to have access externally. 
    Configure your commonname URLs in Exchange2013. Point commonname and autodiscover to exchange2013 in both external and internal DNS servers
    Configure URLshttp://www.mustbegeek.com/configure-external-and-internal-url-in-exchange-2013/
    No CASARRAY in 2013http://exchangeserverpro.com/exchange-2013-client-access-server-high-availability/
    Please configure splitdns or pinpoint DNS in your internal DNS server if not configured
    http://exchange.sembee.mobi/network/split-dns.asp
    Thanks, MAS
    Please mark as helpful if you find my comment helpful or as an answer if it does answer your question. That will encourage me - and others - to take time out to help you.

  • Unable to insert hyperlinks in Exchange 2007 OWA messages

    Hi, we have recently moved to Exchange 2007 OWA and users are unable to insert links to shared files on the network.  I was wondering if there might be something in our Windows 7 GPO that is preventing this from happening?

    do you mean they cannot see the network path or that they are not able to type
    \\networkshare\share ?
    If first one,please check Outlook Web app policy and enable/customize Direct file Access.
    Please mark as helpful if you find my contribution useful or as an answer if it does answer your question. That will encourage me - and others - to take time out to help you. Thank you! Off2work

  • Update Rollup in Exchange 2007 SCR environment.

    Dear Experts. 
    I am going to install Rollup 12 for Exchange 2007 SP3, so could you please confirm if any issue with Rollup 12 Exchange 2007 SP3?
    Could you please advise to update Rollup in Exchange 2007 SCR environment with CCR.? I would appreciate. If you provide step by step
    process, Thanks
    Regards Vijaya Babu S | MCITP | MCTS | MCP| MCSA

    Hi Vijaya,
    Based on my known, Exchange 2007 SP3 Rollup 12 doesn't have a known issue so far.
    About the steps of update Exchange 2007 SCR with CCR, please follow the above article Mike provided.
    What's more, I recommend you make a complete backup of the clustered mailbox server prior to applying the update rollup and again after successfully applying the update rollup.
    Here is an article for your reference.
    How to Install Update Rollups in a CCR Environment
    http://technet.microsoft.com/en-us/library/bb885047(v=exchg.80).aspx
    Hope it helps.
    If you need further assistance, please feel free to let me know.
    Best regards,
    Amy
    Amy Wang
    TechNet Community Support

  • Since upgrade from Exchange 2007 to Exchange 2013 the conversations in Outlook do not group by subject

    Hi Microsoft,
    Since we have upgraded from Exchange 2007 to 2013 users complain their conversations in Outlook are no longer grouped based on the subject of an e-mail. I looks like Outlook uses other message properties for grouping e-mails in a conversation.
    I have investigated all the forum topics and see that with exchange 2010 there is support added for the use of conversation-ID's. However the functionality to automatically group e-mails with the same subject in one conversation in Outlook is gone!
    I would like to know if there is a fix to implement so that some our users get this functionality back. For Example: Let the exchange server not generate conversation-ID's and message-ID's for certain users.
    Your help is greatly appreciated!

    Totally correct!
    If you don't plan to maintain Outlook then you plan to fail :( 
    Additional links etc are in here:
    http://blogs.technet.com/b/rmilne/archive/2013/07/18/patching-exchange-don-t-overlook-outlook.aspx 
    Cheers,
    Rhoderick
    Microsoft Senior Exchange PFE
    Blog:
    http://blogs.technet.com/rmilne 
    Twitter:   LinkedIn:
      Facebook:
      XING:
    Note: Posts are provided “AS IS” without warranty of any kind, either expressed or implied, including but not limited to the implied warranties of merchantability and/or fitness for a particular purpose.

  • Migration from Exchange 2007 to Exchange 2013

    We are migrating from Exchange 2007 to Exchange 2013. We have a new Exchange 2013 server will all of the roles installed, but none of the mailboxes have even been moved yet. We are seeing some of our users getting prompted to accept the self signed certificate
    on the exchange 2013 server. Exchange 2007 server is still handling all of the mail flow and connectors. Any reason why some of our users would be prompted with the certificate for the exchange 2013 server even though their mailbox is still on exchange 2007.
    Our users are on outlook 2010.
    Ed
    Ed

    Hi,
    Could you show us what is the prompt details?
    According to your desciption,I recommend you refer to the following methods to troubleshoot:
    1.Please check if outlook anywhere been configured to connect exchange 2013.
    2.Ctrl+Right click outlook, use “Test E-mail AutoConfiguration” to check all the settings .
    Thanks.
    Niko Cheng
    TechNet Community Support

  • Free/Busy not working Exchange 2007 and 2013 co-existence

    Hi,
    I'm migrating our Exchange 2007 environment to Exchange 2013. Now I am in a co-existence environment where all the mailboxes except some test-users resides on Exchange 2007. Between Users on the same Exchange MBX Server athe FREE/BUSY Information sharing
    works correctly, but between Exchange 2007 and 2013 it's not working.
    I verified my settings and also the EWS virtual directory on 2007 CAS Servers using Get-WebServicesVirtualDirectory.
    The internal and the external URLs are set to https://legacy.mydomain.com/....
    What am I missing?
    Thanks & Kind Regards,
    Jürgen

    Hi,
    According to your description, I understand that the free/busy information between Exchange 2007 and Exchange 2013 is not available for your coexistence environment. To narrow down the issue, please check the following points:
    1. Does the issue happen to all users or specific users?
    2. Although a user on Exchange 2013 can't get free/busy information from a user on Exchange 2007, please confirm whether Exchange 2007 user can get free/busy information from Exchange 2013 users.
    3. Close Outlook and only access user mailbox from OWA to check whether the issue persists. For Outlook client,
    create a new Outlook profile
    to have a try.
    4. Please make sure the virtual directories settings are configured correctly in both Exchange 2013 and Exchange 2007.
    Virtual directories settings in Exchange 2007:
    http://blogs.technet.com/b/meamcs/archive/2013/07/25/part-3-step-by-step-exchange-2007-to-2013-migration.aspx
    Certificate and Virtual directories settings in Exchange 2013:
    http://blogs.technet.com/b/meamcs/archive/2013/07/25/part-2-step-by-step-exchange-2007-to-2013-migration.aspx
    5. Restart IIS service in Exchange server by running iisreset /noforce from a command prompt window.
    If possible, please run Test E-mail AutoConfiguration in Outlook to check whether the autodiscover service can get correct Availability service URL in the results. If there is any event logs, please collect some for further analysis.
    Regards,
    Winnie Liang
    TechNet Community Support

  • Migrating Exchange 2007 to Exchange 2010 at a different physical location - Suggestions??

    Hello! I have a domain in Canada that is running Exchange 2007. My company wants to consolidate this Exchange and migrate the mail to the USA based Exchange 2010 in NYC. Not only is it migrating from 2007 to 2010, it's also moving locations physically. 
    Does anyone have any thoughts on how to best approach such a situation?

    ok... in addition to sarvesh comments i would also add a checklist based approach .. please follow below link
    http://blogs.technet.com/b/mspfe/archive/2014/03/20/checklist-upgrading-to-exchange-2010-from-exchange-2007.aspx  this would help you not to miss anything in terms to critical or non-critical aspects.
    after checklist i would suggest you give a shot at exchange server deployment assistant which will help you putting your scenario and suggesting the best practices. http://technet.microsoft.com/en-us/office/dn756393.aspx
    this guide for planning of migrations also shows the full scenario step by step : http://exchangeserverpro.com/wp-content/uploads/Exchange%20Server%202007%20to%202010%20Migration%20Guide%20V1.0%20-%20Planning%20Chapter.pdf
    this is also a step by step graphical representation for the process. THIRD PARTY LINK though.. http://www.petenetlive.com/KB/Article/0000236.htm
    Let me know if this helps.
    MARK AS USEFUL/ANSWER IF IT DID
    Thanks
    Happiness Always
    Jatin

  • Exchange 2013 and exchange 2007 mixed mode questions

    I made my first attempt at migrating from 2007 to 2013 but ran into some problems. My 2013 CAS and MB servers are successfully installed along with their prerequisites (AD entries, external and internal DNS is active or ready to be, FW rules etc..). I'm
    at this point here in the Microsoft plan..
    http://technet.microsoft.com/en-US/exdeploy2013/PrintChecklist?state=2284-W-CQCkAgIAQACACEEAAQAAAA~~
    "Perform the switch over"
    My questions are about behavior.
    1. When I have everything setup correctly and DNS and the SCP's changed, the Webmail OWA site for all users will be the 2013 login interface, and after logging in will my 2007 users then see the 2007 OWA interface on my old CAS?, or will they access their
    2007 MB using the 2013 interface?
    2. There is a "backend imap4" service on my 2013 servers.  We will still have some 2007 mapi connected MB clients.  Do I need these services started to hand off 2007 mapi requests to the 2007 portion of the environment?

    Hi,
    Yes.
    Based on my knowledge, we should do some configurations.
    More details in the following articles:
    http://blogs.technet.com/b/meamcs/archive/2013/07/25/part-3-step-by-step-exchange-2007-to-2013-migration.aspx
    http://blogs.technet.com/b/meamcs/archive/2013/07/25/part-4-step-by-step-exchange-2007-to-2013-migration.aspx
    Please also add the new URLs into certificates.
    Thanks
    Mavis
    Mavis Huang
    TechNet Community Support

  • Outlook 2013 with Exchange 2007 - out of office problem

    We are using outlook 2013 with Exchange 2007. When users select their out of office it will work fine for the first day, however there after the Out of Office replies stop working. Out of Office is set correctly within Outlook, but what we have found
    is that if the user opens Outlook the Out of Office starts to work again. Also when the user opens Outlook it takes around two minutes before it registers that Out of Office is on.
    Any Ideas?

    Hi,
    How do you configure your OOF? From standard OOF wizard or define an automatic reply template from Rule wizard?
    If you are using a template, Outlook must be running for the Rules Wizard to automatically reply. Please refer to the Note in the following KB:
    http://support.microsoft.com/kb/311107
    If it is configured by using standard Out of Office assistance in File > Automatic Replies, please remove OOF settings in Outlook and set it from OWA 2007, then check whether the issue can be reproduced.
    Regards,
    Winnie Liang
    TechNet Community Support

Maybe you are looking for