Welcome to David Sandor Sign in | Join | Help
in Search

Professional Software Architecture

Move Mailbox - Access control list (ACL) inheritance is blocked for the Exchange server object.

 

I am migrating a client from Exchange Server 2003 to Exchange Server 2007.  In doing so I decided to move some test mailboxes from the Exchange Server 2003 server and promptly received the following error:

Error occurred in the step: Preparing mailbox to be moved. Failed to copy basic mailbox information with error: The Microsoft Exchange Information Store service could not find the specified object., error code: -1056749241

I decided to run the Best Practices Analyzer from the Exchange Server 2007 toolkit and discovered a permissions issue:

Access control list (ACL) inheritance is blocked for the Exchange server object (CN=GAEXCHS1,CN=Servers,CN=First Administrative Group,CN=Administrative Groups,CN=domain,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=domain,DC=toplevel). This may cause mail flow problems, store mounting issues and other service outages. Follow Microsoft Knowledge Base article 264733 and use the Exchange System Manager to re-enable inheritance on this object.

I read this error message about ten times before I realized how I can actually implement the change that was recommended. 

You need to download ADSIEDIT in order to fix this problem.
http://www.microsoft.com/downloads/details.aspx?FamilyID=96a35011-fd83-419d-939b-9a772ea2df90&DisplayLang=en

Run ADSIEdit and drill down to the object that the error message is talking about.
ADSI Editor

Right Click on the server object and choose properties.  Then choose the Security tab.
Security Tab

Click the Advanced button and you should see a familiar inheritance dialog.

Make sure the check box is checked that allows the server object in adsi to inherit the security permissions from it's domain level parent.

"OK OUT" of the dialogs and close ADSIEdit.  Your mailboxes should now transfer!

Published Thursday, March 27, 2008 7:32 PM by david

Comments

No Comments
Anonymous comments are disabled

This Blog

Syndication

Powered by Community Server (Personal Edition), by Telligent Systems