When I try to delete a mailbox I get this error:
Active Directory operation failed on dc01.domain.local. This error is not retriable. Additional information: Access is denied. Active directory response: 00000005: SecErr: DSID-031520B2, problem 4003 (INSUFF_ACCESS_RIGHTS), data 0
I've ensured that "Inheritable Permissions" are checked for this user.
I noticed "Deny" permissions when I run this powershell command on the Exchange server:
[PS] C:\Windows\system32>Get-MailboxPermission -Identity jane.doe | fl
RunspaceId : 2bd98ff2-251e-4b74-ade0-6cb0d81215a4
AccessRights : {FullAccess, ReadPermission}
Deny : False
InheritanceType : All
User : NT AUTHORITY\SELF
Identity : DOMAIN.local/Accounting/Jane Doe
IsInherited : False
IsValid : True
ObjectState : Unchanged
RunspaceId : 2bd98ff2-251e-4b74-ade0-6cb0d81215a4
AccessRights : {FullAccess}
Deny : True
InheritanceType : All
User : DOMAIN\administrator
Identity : DOMAIN.local/Accounting/Jane Doe
IsInherited : True
IsValid : True
ObjectState : Unchanged
RunspaceId : 2bd98ff2-251e-4b74-ade0-6cb0d81215a4
AccessRights : {FullAccess}
Deny : True
InheritanceType : All
User : DOMAIN\Domain Admins
Identity : DOMAIN.local/Accounting/Jane Doe
IsInherited : True
IsValid : True
ObjectState : Unchanged
RunspaceId : 2bd98ff2-251e-4b74-ade0-6cb0d81215a4
AccessRights : {FullAccess}
Deny : True
InheritanceType : All
User : DOMAIN\Enterprise Admins
Identity : DOMAIN.local/Accounting/Jane Doe
IsInherited : True
IsValid : True
ObjectState : Unchanged
RunspaceId : 2bd98ff2-251e-4b74-ade0-6cb0d81215a4
AccessRights : {FullAccess}
Deny : True
InheritanceType : All
User : DOMAIN\Exchange Organization Administrators
Identity : DOMAIN.local/Accounting/Jane Doe
IsInherited : True
IsValid : True
ObjectState : Unchanged
RunspaceId : 2bd98ff2-251e-4b74-ade0-6cb0d81215a4
AccessRights : {FullAccess}
Deny : True
InheritanceType : All
User : DOMAIN\Organization Management
Identity : DOMAIN.local/Accounting/Jane Doe
IsInherited : True
IsValid : True
ObjectState : Unchanged
RunspaceId : 2bd98ff2-251e-4b74-ade0-6cb0d81215a4
AccessRights : {FullAccess}
Deny : False
InheritanceType : All
User : NT AUTHORITY\SYSTEM
Identity : DOMAIN.local/Accounting/Jane Doe
IsInherited : True
IsValid : True
ObjectState : Unchanged
RunspaceId : 2bd98ff2-251e-4b74-ade0-6cb0d81215a4
AccessRights : {ReadPermission}
Deny : False
InheritanceType : All
User : NT AUTHORITY\NETWORK SERVICE
Identity : DOMAIN.local/Accounting/Jane Doe
IsInherited : True
IsValid : True
ObjectState : Unchanged
RunspaceId : 2bd98ff2-251e-4b74-ade0-6cb0d81215a4
AccessRights : {FullAccess, DeleteItem, ReadPermission, ChangePermission, ChangeOwner}
Deny : False
InheritanceType : All
User : DOMAIN\administrator
Identity : DOMAIN.local/Accounting/Jane Doe
IsInherited : True
IsValid : True
ObjectState : Unchanged
RunspaceId : 2bd98ff2-251e-4b74-ade0-6cb0d81215a4
AccessRights : {FullAccess, DeleteItem, ReadPermission, ChangePermission, ChangeOwner}
Deny : False
InheritanceType : All
User : DOMAIN\Domain Admins
Identity : DOMAIN.local/Accounting/Jane Doe
IsInherited : True
IsValid : True
ObjectState : Unchanged
RunspaceId : 2bd98ff2-251e-4b74-ade0-6cb0d81215a4
AccessRights : {FullAccess, DeleteItem, ReadPermission, ChangePermission, ChangeOwner}
Deny : False
InheritanceType : All
User : DOMAIN\Enterprise Admins
Identity : DOMAIN.local/Accounting/Jane Doe
IsInherited : True
IsValid : True
ObjectState : Unchanged
RunspaceId : 2bd98ff2-251e-4b74-ade0-6cb0d81215a4
AccessRights : {FullAccess, ReadPermission}
Deny : False
InheritanceType : All
User : DOMAIN\Exchange Servers
Identity : DOMAIN.local/Accounting/Jane Doe
IsInherited : True
IsValid : True
ObjectState : Unchanged
RunspaceId : 2bd98ff2-251e-4b74-ade0-6cb0d81215a4
AccessRights : {FullAccess, DeleteItem, ReadPermission, ChangePermission, ChangeOwner}
Deny : False
InheritanceType : All
User : DOMAIN\Exchange Organization Administrators
Identity : DOMAIN.local/Accounting/Jane Doe
IsInherited : True
IsValid : True
ObjectState : Unchanged
RunspaceId : 2bd98ff2-251e-4b74-ade0-6cb0d81215a4
AccessRights : {ReadPermission}
Deny : False
InheritanceType : All
User : DOMAIN\Exchange View-Only Administrators
Identity : DOMAIN.local/Accounting/Jane Doe
IsInherited : True
IsValid : True
ObjectState : Unchanged
RunspaceId : 2bd98ff2-251e-4b74-ade0-6cb0d81215a4
AccessRights : {ReadPermission}
Deny : False
InheritanceType : All
User : DOMAIN\Exchange Public Folder Administrators
Identity : DOMAIN.local/Accounting/Jane Doe
IsInherited : True
IsValid : True
ObjectState : Unchanged
RunspaceId : 2bd98ff2-251e-4b74-ade0-6cb0d81215a4
AccessRights : {FullAccess, DeleteItem, ReadPermission, ChangePermission, ChangeOwner}
Deny : False
InheritanceType : All
User : DOMAIN\Exchange Trusted Subsystem
Identity : DOMAIN.local/Accounting/Jane Doe
IsInherited : True
IsValid : True
ObjectState : Unchanged
RunspaceId : 2bd98ff2-251e-4b74-ade0-6cb0d81215a4
AccessRights : {FullAccess, DeleteItem, ReadPermission, ChangePermission, ChangeOwner}
Deny : False
InheritanceType : All
User : DOMAIN\Organization Management
Identity : DOMAIN.local/Accounting/Jane Doe
IsInherited : True
IsValid : True
ObjectState : Unchanged
RunspaceId : 2bd98ff2-251e-4b74-ade0-6cb0d81215a4
AccessRights : {ReadPermission}
Deny : False
InheritanceType : All
User : DOMAIN\Public Folder Management
Identity : DOMAIN.local/Accounting/Jane Doe
IsInherited : True
IsValid : True
ObjectState : Unchanged
RunspaceId : 2bd98ff2-251e-4b74-ade0-6cb0d81215a4
AccessRights : {ReadPermission}
Deny : False
InheritanceType : All
User : DOMAIN\Delegated Setup
Identity : DOMAIN.local/Accounting/Jane Doe
IsInherited : True
IsValid : True
ObjectState : Unchanged
RunspaceId : 2bd98ff2-251e-4b74-ade0-6cb0d81215a4
AccessRights : {ReadPermission}
Deny : False
InheritanceType : All
User : DOMAIN\Managed Availability Servers
Identity : DOMAIN.local/Accounting/Jane Doe
IsInherited : True
IsValid : True
ObjectState : Unchanged
These permissions remain the same whether "Inheritable Permissions" is checked or not.
I think I'm running into a permissions issue, but I'm not sure where. A few weeks ago I messed with the permissions in AD for Exchange Servers, Exchange Trusted Subsystem, etc. This was in relation to another issue we were running into. The problem turned out to be something else, but the permissions were left the way they were (not reverted back to the original). I feel that if I could get back to the default Exchange permissions that I'd be set. Is there a way to do that in a production environment without breaking everything? Can I run /adprep?
Is there an easier way to get rid of those DENY's listed above? Are those even causing my problem?
Thanks in adavance.