cynlis Posted March 1, 2013 Posted March 1, 2013 (edited) http://staticc3.cdngeek.net/images/misc/quote_icon.png Originally Posted by sukh http://staticc3.cdngeek.net/images/buttons/viewpost-right.png Done & yes, it works as expected. I think you should do the same test in your env, create 2 accounts and set permissions as requied, don;t set the Send-As as you dont want that. Just Send-on-Behalf. No membership in any groups other than domain users for both accounts. ________________________________________________________________ i have done the same thing and still have the same frustrating results. i am running server 2K8r2sp1 and exchange server 2010. Edited March 1, 2013 by cynlis added quote that i'm responding to
cynlis Posted March 2, 2013 Posted March 2, 2013 yes, outlook 2010 i am having exact same issue as darren
sukh Posted March 2, 2013 Posted March 2, 2013 Was the testing exactly the same? 2 NEW users? Can you do a remote session?
AceDaz Posted March 4, 2013 Author Posted March 4, 2013 (edited) can you run get-mailbox "helpdesk alias"| fl [PS] C:\Windows\system32>get-mailbox "Helpdesk"| fl RunspaceId : 1199f269-4b79-4c4d-928d-760ae951989a Database : ICT Services UseDatabaseRetentionDefaults : True RetainDeletedItemsUntilBackup : False DeliverToMailboxAndForward : True LitigationHoldEnabled : False SingleItemRecoveryEnabled : False RetentionHoldEnabled : False EndDateForRetentionHold : StartDateForRetentionHold : RetentionComment : RetentionUrl : LitigationHoldDate : LitigationHoldOwner : ManagedFolderMailboxPolicy : RetentionPolicy : Empty Deleted Items Folder after 30 Days AddressBookPolicy : Staff Address Book Policy CalendarRepairDisabled : False ExchangeGuid : 7984b2ac-a1d1-459d-9322-d6e9f04dae8f ExchangeSecurityDescriptor : System.Security.AccessControl.RawSecurityDescriptor ExchangeUserAccountControl : None MessageTrackingReadStatusEnabled : True ExternalOofOptions : External ForwardingAddress : DOMAIN.LOCAL/ICT Services/Users/My Full Name ForwardingSmtpAddress : RetainDeletedItemsFor : 14.00:00:00 IsMailboxEnabled : True Languages : {en-GB} OfflineAddressBook : ProhibitSendQuota : unlimited ProhibitSendReceiveQuota : unlimited RecoverableItemsQuota : 30 GB (32,212,254,720 bytes) RecoverableItemsWarningQuota : 20 GB (21,474,836,480 bytes) DowngradeHighPriorityMessagesEnabled : False ProtocolSettings : {RemotePowerShell§1} RecipientLimits : unlimited IsResource : False IsLinked : False IsShared : False LinkedMasterAccount : ResourceCapacity : ResourceCustom : {} ResourceType : SamAccountName : helpdesk SCLDeleteThreshold : SCLDeleteEnabled : SCLRejectThreshold : SCLRejectEnabled : SCLQuarantineThreshold : SCLQuarantineEnabled : SCLJunkThreshold : SCLJunkEnabled : AntispamBypassEnabled : False ServerLegacyDN : /o=SCHOOL NAME/ou=Exchange Administrative Group (FYDIBOHF23SPDLT)/c n=Configuration/cn=Servers/cn=ALBANYEXCH ServerName : SERVER NAME UseDatabaseQuotaDefaults : True IssueWarningQuota : unlimited RulesQuota : 64 KB (65,536 bytes) Office : UserPrincipalName : Helpdesk Email Address UMEnabled : False MaxSafeSenders : MaxBlockedSenders : ReconciliationId : WindowsLiveID : ThrottlingPolicy : RoleAssignmentPolicy : Default Role Assignment Policy SharingPolicy : Default Sharing Policy RemoteAccountPolicy : MailboxPlan : ArchiveDatabase : ArchiveGuid : 00000000-0000-0000-0000-000000000000 ArchiveName : {} ArchiveQuota : 50 GB (53,687,091,200 bytes) ArchiveWarningQuota : 45 GB (48,318,382,080 bytes) ArchiveDomain : ArchiveStatus : None RemoteRecipientType : None DisabledArchiveDatabase : DisabledArchiveGuid : 00000000-0000-0000-0000-000000000000 QueryBaseDNRestrictionEnabled : False MailboxMoveTargetMDB : MailboxMoveSourceMDB : MailboxMoveFlags : None MailboxMoveRemoteHostName : MailboxMoveBatchName : MailboxMoveStatus : None IsPersonToPersonTextMessagingEnabled : False IsMachineToPersonTextMessagingEnabled : True UserSMimeCertificate : {} UserCertificate : {} CalendarVersionStoreDisabled : False ImmutableId : PersistedCapabilities : {} SKUAssigned : False AuditEnabled : False AuditLogAgeLimit : 90.00:00:00 AuditAdmin : {Update, Move, MoveToDeletedItems, SoftDelete, HardDelete, FolderBind, SendAs, SendOnBehalf, Create} AuditDelegate : {Update, SoftDelete, HardDelete, SendAs, Create} AuditOwner : {} WhenMailboxCreated : 10/04/2012 14:29:36 UsageLocation : Extensions : {} HasPicture : False HasSpokenName : False AcceptMessagesOnlyFrom : {} AcceptMessagesOnlyFromDLMembers : {} AcceptMessagesOnlyFromSendersOrMembers : {} AddressListMembership : {\Mailboxes(VLV), \All Mailboxes(VLV), \All Recipients(VLV), \Default Global A ddress List, \All Users} Alias : helpdesk ArbitrationMailbox : BypassModerationFromSendersOrMembers : {} OrganizationalUnit : domain.local/Mailbox Only CustomAttribute1 : CustomAttribute10 : CustomAttribute11 : CustomAttribute12 : CustomAttribute13 : CustomAttribute14 : CustomAttribute15 : CustomAttribute2 : CustomAttribute3 : CustomAttribute4 : CustomAttribute5 : CustomAttribute6 : CustomAttribute7 : CustomAttribute8 : CustomAttribute9 : ExtensionCustomAttribute1 : {} ExtensionCustomAttribute2 : {} ExtensionCustomAttribute3 : {} ExtensionCustomAttribute4 : {} ExtensionCustomAttribute5 : {} DisplayName : Helpdesk EmailAddresses : {smtp:Helpdesk Full Email Old Web Domain, SMTP:Helpdesk Full Email New Web Domain, smtp:Original Help.Desk Email Address Old Web Domain, smtp:[email protected], smtp:[email protected]} GrantSendOnBehalfTo : {DOMAIN.LOCAL/ICT Services/Users/My Full Name} ExternalDirectoryObjectId : HiddenFromAddressListsEnabled : False LastExchangeChangedTime : LegacyExchangeDN : /o=SCHOOL NAME/ou=Exchange Administrative Group (FYDIBOHF23SPDLT)/c n=Recipients/cn=Helpdesk Full Name MaxSendSize : unlimited MaxReceiveSize : unlimited ModeratedBy : {} ModerationEnabled : False PoliciesIncluded : {} PoliciesExcluded : {{26491cfc-9e50-4857-861b-0cb8df22b5d7}} EmailAddressPolicyEnabled : False PrimarySmtpAddress : Helpdesk Full Email Address RecipientType : UserMailbox RecipientTypeDetails : UserMailbox RejectMessagesFrom : {} RejectMessagesFromDLMembers : {} RejectMessagesFromSendersOrMembers : {} RequireSenderAuthenticationEnabled : False SimpleDisplayName : SendModerationNotifications : Always UMDtmfMap : {emailAddress:43573375, lastNameFirstName:43573375252269, firstNameLastName:25 226943573375} WindowsEmailAddress : Helpdesk Full Email Address MailTip : MailTipTranslations : {} PartnerObjectId : 00000000-0000-0000-0000-000000000000 IsValid : True ExchangeVersion : 0.10 (14.0.100.0) Name : Helpdesk Full Name DistinguishedName : CN=Helpdesk Full Name,OU=Mailbox Only,DC=DOMAIN,DC=LOCAL Identity : DOMAIN.LOCAL/Mailbox Only/Helpdesk Full Name Guid : cc8e521a-dd01-4258-bd67-e2725b031c31 ObjectCategory : DOMAIN.LOCAL/Configuration/Schema/Person ObjectClass : {top, person, organizationalPerson, user} WhenChanged : 08/02/2013 09:16:10 WhenCreated : 10/04/2012 14:29:36 WhenChangedUTC : 08/02/2013 09:16:10 WhenCreatedUTC : 10/04/2012 13:29:36 OrganizationId : OriginatingServer : Our Primary DC FQDN [PS] C:\Windows\system32> Edited March 4, 2013 by AceDaz
AceDaz Posted March 5, 2013 Author Posted March 5, 2013 It isn't something to do with AD Security Permissions? I know that if a user needs to use a Mobile device to connect to their emails then I need to give them allow access to Create msExchActiveSyncDevices objects and Delete msExchActiveSyncDevices objects
sukh Posted March 5, 2013 Posted March 5, 2013 Wanted I wanted to see was the actual email addresses so I can see what's going on. I know you have edited by giving the description but I wanted to verify. Can you PM me?
AceDaz Posted March 5, 2013 Author Posted March 5, 2013 It says it's too long, can you PM your email address please?
mgrieve Posted June 19, 2013 Posted June 19, 2013 (edited) Hi All We setup our own Exchange Server as part of a complete server refresh a few months ago, and now it is hit and miss whether the SendAs works or not. I have a Helpdesk mailbox that I SendAs when I need to send anything out, if you add the email address in to my Outlook and go to send a email, it comes back with "You can't send a message on behalf of this user unless you have permission to do so. Please make sure you're sending on behalf of the correct sender, or request the necessary permission. If the problem continues, please contact your helpdesk." I have tried removing the rights, I have tried leaving it 24 hours, It sometimes works if I remove the email address from my Outlook "From" field and retype it. It has been working for about a week, but when I tried to sort out someone elses SendAs for the accounts it stopped mine (presumably when I restarted the Information Store service). I have noticed that I am currently running native SP2 and not any additional RollUps. Could this affect it? Many thanks I have been having the same issues and found your forum looking for the answer. I just worked through the issue and wanted to let you all know what I did... My symptoms: Trying to Send As another mailbox user for which the sending user had full access permissions. This was not an issue testing from my login which is a Domain Admin. Received all variations of no access to send as the specified user when testing from non-Domain Admin accounts. My fix: Exchange - User must have full access permission and send on behalf permission. Send As permission not required. (the send as was not needed for the domain admin account. Inheritance setting were the same between the Domain User and Domain Admin accounts.) Outlook - Open Mail from Control Panel and delete the existing profile. Create a new profile named Outlook and add your primary account. Choose "Add another account" after your primary account has been configured and add the account for which you've given yourself/the user full access/send on behalf permissions. This worked for cached exchange mode. Open Outlook. You'll see the second account listed twice. Close Outlook. Open Outlook. The second listing will have dropped off. Click the second account and start a new message. The From should already be set as the secondary account. In addition you may configure Signatures for each account. The signature will change depending on which account you start the message from, or for whichever account you choose the message to be From once composing. NOTE: Another little nugget I learned along the way is that the account/s you wish to send on behalf of MUST NOT be hidden from the Address Lists. Hope this helps someone! Edited June 19, 2013 by mgrieve
BobK_BN Posted January 13, 2014 Posted January 13, 2014 Does anyone have a solution for the original problem? I'm having the exact same situation - some of my users cannot use SendAs while others can. SendOnBehalfOf is no option in our environment. The problems started after applying SP3 RU2 to all of our EX2010. We have over 60 DCs, some 24 EX with CAS/HUB/MBX roles and 1 DAG, 8 MBX only in 2 stretched DAGs, 6 CAS/HUB only behind LoadBalancers. Removing the address we want to send as and re-adding works for just one email, as described by the others having this problem, but this is not really an option, for sure. If someone has a hint where to look for, I'd be glad. Bob
Demarcation Posted January 13, 2014 Posted January 13, 2014 1) does it work from webmail? 2) disable outlook autocomplete and try again adding the email specifically by selecting from the address book not typing by self 2) disable outlook autocomplete and try again adding the email specifically by typing and not from the address book
BobK_BN Posted January 14, 2014 Posted January 14, 2014 1) does it work from webmail? Yes, it does work each time. But whats notable: The address in question is disappearing from the From: Button, so I have to re-enter it each time I compose a new message. With other accounts, from which the users can SendAs as wanted, the SendAs-addresses do NOT disappear. 2) disable outlook autocomplete and try again adding the email specifically by selecting from the address book not typing by self 2) disable outlook autocomplete and try again adding the email specifically by typing and not from the address book None of the above change the behaviour: The first email gets send correctly, the following don't. Remarkably, when I delete and re-add the permission over and over, sending emails using the SendAs right at some point works ok. This is not reproducable - sometimes it takes 3 tries, sometimes 6, some work from the very start. Not the game I can play with my users. Remarkable might be, that the SendAs addresses in question are in fact contacts, not mailboxes. SendAs on mailboxes works all the time for every user. If it wouldn't, we'd be at a loss, because none of my users actually use the account they're logged in with to send emails, but use a second mailbox the have FullAccess to and the SendAs right for. It's just some contacts that can't be used as SendAs. We used to set the SendAs right via Add-ADPermission, which after applying SP3 RU2 is not usable anymore. Trying Add-ADPermission throws an Error 5, "Permission denied", no matter which admin tries to use it. Even Exchange Organization Admins cannot set the SendAs right via Add-ADPermission, so we have to use the security tab in ADUC. I don't know if this has something to do with the problem of being unable to actually *use* the SendAs right, but it sounds strange that we cannot set it for contacts and not use it with contacts, so there might be a connection between the two errors. Any hint would be greatly appreaciated.
AceDaz Posted January 14, 2014 Author Posted January 14, 2014 I finally got this working just recently, I think it was linked to it not finding it in the Global Address List. Are the email accounts you are trying to SendAs visible and available in the GAL?
BobK_BN Posted January 18, 2014 Posted January 18, 2014 I resolved this. In fact, it has something to do with the address lists, but nothing one could have expected: We're using Outlook 2010. When Outlook wants to send a message one has SendAs rights onto, it does not simply give the address to the mailbox server in question, which would be sufficient, but instead it seems to pass a pointer to the entry in the address list the entry derives from. Having Outlook configured in the way that it starts searching in a customized address list and NOT letting it continue the search in the global address list makes it merely impossible to use addresses from the global address list as SendAs addresses. You have to put those addresses in the customized address list. This is complete nonsense, because Outlook could have let the mailbox server decide wether to accept the message or not (which in fact it does in cached mode!), but I guess we have to live with it. Bob
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now