User with Full Access to mailbox cannot view calendar
I have a user who one of several users that manages the schedules for several conference rooms using regular mailboxes on Exchange Server 2007. She (and she alone), has lost the right to manage the mailbox calendar. When she tries to access the
calendar she gets the error message, "You do not have permission to view this calendar".
I verified her rights as Full Access and even ran the cmdlet below which says, "Appropriate ACE is already present on object ".
[PS] C:\Windows\system32>Add-MailboxPermission -Identity "mailbox" -User user -AccessRights FullAccess -InheritanceType All
WARNING: Appropriate ACE is already present on object "CN=mailbox
49,OU=Service Accounts,OU= xxx,OU=xxxxx),OU=xxx,DC=xxx,DC=xx,DC=xxx" for
account "user".
Identity User AccessRights IsInherited Deny
Domaim domain\user {FullAccess} False False
When I get the permissions on the mailbox she has the following:
AccessRights : {FullAccess}
Deny : False
InheritanceType : All
User : domain\user
Identity : domain/OU/OU/OU/mailbox
IsInherited : False
IsValid : True
ObjectState : Unchanged
Any help out there?
[email protected]
Hi,
According to your post, the permission seems to be configured properly in your Exchange server. This user has full access permission to Domaim’s mailbox.
Please try to open shared mailbox in OWA to check whether she can access the calendar. In Outlook, we can open shared calendar in Calendar panel by clicking Open Calendar > Open shared calendar. If it fails, please try the following steps:
1. Click File > Account Settings > Change > More Settings > Advanced.
2. Add the Shared mailbox that you want to open and click OK.
If there is any updates, please feel free to let us know.
Best Regards,
Winnie Liang
TechNet Community Support
Similar Messages
-
Set Single user with reviewer access to multiple conference room calendars
Want to add a single user with reviewer access to multiple conference room calendars, used the below but it given a below error , Single user i am able to add but single user for multiple confernce room calendars hot happening.
Import-csv C:\smtp1.csv | foreach-object {Add-MailboxFolderPermission -identity $_mail":\Calendar" -User "Mike" -AccessRights "Reviewer"}
Smtp1.csv
mail
[email protected]
[email protected]
Error:--
[PS] C:\>Import-csv "C:\smtp1.csv" | foreach-object {Add-MailboxFolderPermission -identity "$_mail:\Calendar" -User "Mike" -AccessRights "Reviewer"}
The specified mailbox "\Calendar" doesn't exist.
+ CategoryInfo : NotSpecified: (0:Int32) [Add-MailboxFolderPermission], ManagementObjectNotFoundException
+ FullyQualifiedErrorId : 78C23328,Microsoft.Exchange.Management.StoreTasks.AddMailboxFolderPermission
The specified mailbox "\Calendar" doesn't exist.
+ CategoryInfo : NotSpecified: (0:Int32) [Add-MailboxFolderPermission], ManagementObjectNotFoundException
+ FullyQualifiedErrorId : 78C23328,Microsoft.Exchange.Management.StoreTasks.AddMailboxFolderPermission
The specified mailbox "\Calendar" doesn't exist.
+ CategoryInfo : NotSpecified: (0:Int32) [Add-MailboxFolderPermission], ManagementObjectNotFoundException
+ FullyQualifiedErrorId : 78C23328,Microsoft.Exchange.Management.StoreTasks.AddMailboxFolderPermission
The specified mailbox "\Calendar" doesn't exist.
+ CategoryInfo : NotSpecified: (0:Int32) [Add-MailboxFolderPermission], ManagementObjectNotFoundException
+ FullyQualifiedErrorId : 78C23328,Microsoft.Exchange.Management.StoreTasks.AddMailboxFolderPermissioni tried with that as well but getting the below
A positional parameter cannot be found that accepts argument ':\Calendar'.
+ CategoryInfo : InvalidArgument: (:) [Add-MailboxFolderPermission], ParameterBindingException
+ FullyQualifiedErrorId : PositionalParameterNotFound,Add-MailboxFolderPermission
A positional parameter cannot be found that accepts argument ':\Calendar'.
+ CategoryInfo : InvalidArgument: (:) [Add-MailboxFolderPermission], ParameterBindingException
+ FullyQualifiedErrorId : PositionalParameterNotFound,Add-MailboxFolderPermission
A positional parameter cannot be found that accepts argument ':\Calendar'.
+ CategoryInfo : InvalidArgument: (:) [Add-MailboxFolderPermission], ParameterBindingException
+ FullyQualifiedErrorId : PositionalParameterNotFound,Add-MailboxFolderPermission
Cannot process argument transformation on parameter 'Identity'. Cannot convert value "" to type "Microsoft.Exchange.Configuration.Tasks.MailboxFolderIdParameter". Error: "Valu
e cannot be null.
Parameter name: mailboxFolderId"
+ CategoryInfo : InvalidData: (:) [Add-MailboxFolderPermission], ParameterBindin...mationException
+ FullyQualifiedErrorId : ParameterArgumentTransformationError,Add-MailboxFolderPermission -
I want to be able to create directory user ID for the iPlanet administrators. They should be able to access the admin console and all the instances created. They should be able to configure each instance and directory. I was able tocreate Admin Server Administrators but they were only able to modify the directory(tab) and not the configurations(tab). Any help would be greatly appreciated!
Thanks.
KeithHi Keith,
In o=netscaperoot, edit the static group called cn=Configuration Administrators, ou=Groups, ou=TopologyManagement, o=NetscapeRoot - this group contains the admins peer to your config admin. Since the console is quirky and doesn't let you add in users not in netscaperoot, just click advanced and put in the full dn of whoever you want in by hand, e.g., uid=scarter, ou=people, dc=mydomain,dc=com as a static member. then rebind to the console with the full dn and passwd, and away you go :)
james -
How to Find mailboxes a specific user has full access to
Hi,
I have been searching all the threads but all i am getting is user mailbox is accessible to following users. I run this command:
Get-Mailbox -resultsize unlimited | Get-MailboxPermission | Where {(!$_.isinherited) -and ($_.user.SecurityIdentifier -ne "S-1-5-10") -and ($_.accessrights -contains "fullaccess") } | Select Identity,User
It is taking so much time as we have 20K mailboxes. Then i tried this:
Get-Mailbox -server exdm01 -resultsize unlimited | Get-MailboxPermission | Where {(!$_.isinherited) -and ($_.user.SecurityIdentifier -ne "S-1-5-10") -and ($_.accessrights -contains "fullaccess") } | Select Identity,User
It gives me list of those users who have access to mailboxes. But what if i want to see user_A is accessing which mailboxes. we
need to find out which mailboxes user has FULL MAILBOX ACCESS to NOT which users can access this user's mailbox. I hope you will understand, i DONT want the list which MANAGE FULL ACCESS PERMISSION option gives in GUI, but i WANT vice-versa.
We migrated 100 users to different domain, now i want to know these users' association with others' mailboxes.
HasanPlease check with this
Get-Mailbox -Server "SERVERNAME" -resultsize "Unlimited" | Get-MailboxPermission | where { ($_.AccessRights -eq "FullAccess") -and ($_.User -like "DOMAIN\TESTUSER") -and ($_.IsInherited -eq $false) -and -not ($_.User -like "NT AUTHORITY\SELF") } | ft User, @{Name="Identity";expression={($_.Identity -split "/")[-1]}} -Autosize
Replace "DOMAIN\TESTUSER" with "Yourdomain\Yourusername" to check, which will list the users which testuser has FullAccessPermission on.
@Amit
Apologize for the duplicate posting.
Thanks, MAS
Please mark as helpful if you find my comment helpful or as an answer if it does answer your question. That will encourage me - and others - to take time out to help you. -
Users with direct access to tables
I need to find out which users have direct access to tables, not through the roles.
Is dba_tab_privs the right table to query or table_privileges is the correct one.
Please let me know the difference between these two.
I have gone through the documentation but I am still not clear about the difference between them.
Let me know whatever your thoughts are on this.
Thanks,
RushiAh, an opportunity to illustrate the value of COMMENTs:
SQL> select * from dict where table_name = 'TABLE_PRIVILEGES';
TABLE_NAME
COMMENTS
TABLE_PRIVILEGES
Grants on objects for which the user is the grantor, grantee, owner,
or an enabled role or PUBLIC is the grantee
SQL> select * from dict where table_name = 'DBA_TAB_PRIVS';
TABLE_NAME
COMMENTS
DBA_TAB_PRIVS
All grants on objects in the database
SQL>So, TABLE_PRIVILEGES is a view relevant to the user who is currently connected and SELECTing from it.
DBA_TAB_PRIVS is what you want to use to find users with direct access granted to tables. -
If I have a sub site URL and a user with Site Admin, can I list all users in that sub site that have Full Control at that level?
Any C# code sample?Still you can do that, just pass the subsites to your code and from their you can find the users dynamically.
You could also use SPWeb.Users property to get users assigned to a subsite
http://msdn.microsoft.com/en-us/library/microsoft.sharepoint.spweb.users(v=office.15).aspx
alternatively you can also use SPWeb.SiteUsers to get all users
http://msdn.microsoft.com/en-us/library/microsoft.sharepoint.spweb.siteusers(v=office.15).aspx
other APIs of help-
http://msdn.microsoft.com/en-us/library/microsoft.sharepoint.spweb.associatedmembergroup(v=office.15).aspx
http://msdn.microsoft.com/en-us/library/microsoft.sharepoint.spweb.associatedownergroup(v=office.15).aspx
http://sharepoint.stackexchange.com/questions/101671/object-model-list-all-users-with-full-control-on-a-sub-site-in-sharepoint-2013
Hope this helps!
Ram - SharePoint Architect
Blog - SharePointDeveloper.in
Please vote or mark your question answered, if my reply helps you -
Security batch job to evaluate users with SAP_ALL access:
Hello,
I need to run some kind of batch report or program that runs for users that have SAP_ALL access.
Basically we need to run a report or program that shows what these users that currently have SAP_ALL are executing on a daily basis.
Do you have or know of a report/program that we can schedule nightly to find this information out ?
Thanks,
SteveHi Steve,
I don't think any SAP standard report or query is available for this. You probably have to design your own Z report/query to achive this.
However since SAP_ALL is a restricted access and you will have very few users with this access, if you want to find it out programs/transation being executed by these users, it can be done manually from ST03, through "Memory Use Statistics", probably this may help to identify the tables using which you can design your own report.
Regards,
Sanujit
Edited by: Sanujit Purohit on Jul 20, 2010 2:25 AM -
A user cant see anything in SharePoint calendar with full access
Hi,
I have a wierd issue, where only one user cannot see anything in SharePoint 2010 Calendar, when everyone else can.
The calendar has more than 100 events, and he cannot see anything in Calendar view. The calendar.aspx page comes up with no items in it.
The calendar is very basic with default settings, I also gave the user full access but still nothing changed.
FYI- in list settings, the users can "read all items", not just their own. It happens in all the other calendars also which he opened in front of me.
Also, I logged in with my credentrials on his machine, and I could see all the items.
We were migrating the exchange public calendars manually to SharePoint(about 10 of them), the calendars worked great for so many years without SharePoint, and now after migration the users have to face issues.
ThanksCan you try to use fiddler
to trace why the details are not showing for that particular user? You may get few details to troubleshoot the issue. Does that user see the problem in other machines/browsers as well?
My Blog- http://www.sharepoint-journey.com|
If a post answers your question, please click Mark As Answer on that post and Vote as Helpful -
How to give full access to mailbox to users in trusted domain?
Hi,
I am working on a migration-project where we migrate all users from one domain to a new domain. I have Exchange in both domains, and migrates mailoboxes from the old to the new domain. In the old domain I have a number of mailboxes that are used for common
calendars for the departments. My problem is: How can I give the users who has been migrated to the new domain full access to the existing calendar-mailboxex in the old domain? I have given the accounts in the new domain full access to the mailboxes
in the old domain by using to following command: get-mailbox mailboxname | add-mailboxpermission -accessrights FullAccess,ExternalAccount -user newdomain\username
After the command has completed I can see the account listed in the "Manage Full Access Permission"-dialog, but still the new useraccount cannot create appointments etc in the original calendar from Outlook.
Any tips on this?
Thor-EgilHi Thor,
Thank you for your question.
Did the issue occur when we use OWA?
Are there any errors when they cannot create appointments?
We could enable “Support cross forest delegation” on FIM(Forefront Identity Manager) to check if the issue persist.
There is an article for us to how to enable “Support cross forest delegation” by the following link:
http://blogs.technet.com/b/neiljohn/archive/2011/10/12/exchange-server-2010-cross-forest-delegation.aspx
If there are any questions regarding this issue, please be free to let me know.
Best Regard,
Jim
Please remember to mark the replies as answers if they help, and unmark the answers if they provide no help. If you have feedback for TechNet Support, contact [email protected]
Jim Xu
TechNet Community Support -
Users with read access to the site unable to view Managed Metadata Navigation
Hi everyone,
I created a Managed Metadata service and created group, term-set and terms
I gave read access to users
I set up navigation to use Managed Navigation
I am logged in as farm admin and able to view the navigation when i browse site. But user are not seeing navigation.
One thing i noticed is when i give users full access or designer access to site they will be able to see the navigation. but i don't want to give users full access or designer access to the site.
How can users with read only access to site can view Managed Metadata Navigation...Please help?Hi Sunil,
Have you given your users permissions to actually read the MMS data from the service application?
http://technet.microsoft.com/en-us/library/ff625176.aspx covers permissions on the MMS.
Regards
Paul.
<<edit>> On reflection you might be hitting the issue in this Stackexchange post..
http://sharepoint.stackexchange.com/questions/75636/permissions-and-managed-metadata-in-navigation Is yours behaving the same way?
Please ensure that you mark a question as Answered once you receive a satisfactory response. This helps people in future when searching and helps prevent the same questions being asked multiple times. -
Auto-Mapping with Full Access Mailboxes-not working in exchange 2010 clients outlook 2013
hello, I have exchange server 2010, the clients are running outlook 2013, I set an mailbox for automapping (full access) but when i restart client it does not appear in the client. i also did the command in the exchange shell, no errors. how can i fix this.
no sp info shows with the
Get-ExchangeServer | Format-List Name, Edition, AdminDisplayVersionName
Edition : Enterprise
AdminDisplayVersion : Version 14.0 (Build 639.21)
chart says
Exchange Server 2010 November 9, 200914.00.0639.021
is that the issue need sp 1? -
Exchange 2010 Full Access to mailbox not working.
Hi Guys
Few changes were made to exchange so users can only have "send on behalf of" when using shared mailboxes.
for example : Sent from Bob Smith on behalf of [EmailAddress1]
need to grant full access, then use the client delegate (outlook 2010) and add them to that also.
even if you set permissions to none in Delegate the full access kicks in.
if you remove the users name from delegate (set with no permissions) full access is gone.
has anyone else come across this ?
ive been trolling the net the last 2 days and havernt found a thing . .
any help would be great.Hi ITWizchch,
Try these methods to check what's happening and set the required access (i.e. SendOnBehalfOf without Full Access)
Check for individual user or all users having access on John's mailbox:
Get-MailboxPermission -Identity [email protected] | Format-List
Get-MailboxPermission -Identity [email protected] -User "Ayla"
Once permission is set you can use below to remove it:
Remove-MailboxPermission -Identity John -User 'Ayla' -AccessRights FullAccess -InheritanceType All
Set SendOnBehalf Permission:
Set-mailbox John -GrantSendOnBehalfto @{Add="Ayla"}
Set SendOnBehalf Permission:
Set-mailbox John -GrantSendOnBehalfto @{Remove="Ayla"}
NOTE:- When you modify a multivalued property, you must ensure that you append / remove the values accordingly , without Overwriting the existing list.
Regards,
Satyajit
Please “Vote As Helpful”
if you find my contribution useful or “Mark As Answer” if it does answer your question. That will encourage me - and others - to take time out to help you. -
Granting full access and Mailbox Caching
Hi!
We have a Microsoft Server 2008 R2 (terminal server) with Office 2013. The mailboxes are hosted by Microsoft Online. If a user creates a Outlook profile everything goes well. I
even have a policy set up that forces to Cache one month to speed things up.
Now when I give this person 'full access to a colleges mailbox it appears (magically) on its own which is perfect yes? However it starts caching the entire mailbox from that college
and not just a month. What Group Policy should I set? Or should I do this differently.
The only Group Policies which I have set (for Outlook that is) are:
Cached Exchange Mode Sync Settings (1 month)
Use Cached Exchange mode for new and existing Outlook profiles. (enable)Thank you for sharing your solution and experience here. Have a good time.
Tony Chen
TechNet Community Support -
One connection user with full rights for a bunch of schemas
How can I give all rights of one user to another without declaring each object privilege one by one? For my application I would like to devide the data to maintain into four different schemas to. Never the less I would like to connect to the db by one account and have full access to all of the four schemas. My client denies to give the connect user DBA rights. The connection user is not allowed to have "ANY" grants, either. But my application often creates tables, views etc. and drops it when they aren't usefull any more. So it is nearly impossible to manage the grants on each db object one by one. So, how can I give a user all rights for a bunch of others?
My program uses logical "firms" to allow separation of clients client data. Sounds like Row Level Security - or even Views - would be saving you some grief here.
The most dynamic created tables are used to optimize performance for (sub-)queries builded at runtime by the user. Do you really have benchmarks to prove that building tables through dynamic execution of DDL results in faster response times than plain queries? Are the query structures some various that temporary tables won't do?
Cheers, APC -
Resetting the Registry so other Users have full access to Flash Player 9
Does anyone have a solution for fixing the registry after
installing FP9, so all users can have full access to it.
I found this site
http://www.donglefree.com/toppage1.htm
to fix the installation problem, (and it worked perfectly),
but now all other users have limited access to the Flash Player.
(Some sites still say Flash needs to be installed).
Operating System: Windows XP Home Edition, SP1, Internet.
Exp. Version 6.0.2800.1106.xpsp2.050301-1526
Any help would be appriciated.Has anyone tried this to fix the registry problem?
http://www.adobe.com/cfusion/knowledgebase/index.cfm?id=tn_19148
Maybe you are looking for
-
How do i connect my macbook pro retina display to lcd projector
How do i connect my macbook pro retina display to lcd projector?
-
My Apple bluetooth keyboard no longer connects to my Macbook Pro
My wireless keyboard no longer connects to my Macbook using Bluetooth. I've put in fresh batteries, checked the on/off switch, and attempted to connected using system dialog. Also tried turning Bluetooth off and on. Nothing works. Wireless trackpad w
-
Prevent changes to ship-to and vendor address in Process Purchase Orders
Hi SRM experts, I have recently used BBP_UI_CONTROL_BADI to affect the displays of fields and buttons in the shopping cart. I now need to change the displayed fields in the Process Purchase Order screens (Vendor Address and Ship-To address) to preven
-
Are "plug ins" and "Add ons" the same thing
I think the question is detailed enough
-
Hello everybody, I am newbie here and not very experienced with JSF. :) I have a mySQL database with different kind of data in it. My web application displays the results of a SELECT directly on the browser via a table; some of the fields contain BLO