Jump to content

Recommended Posts

Posted (edited)

http://staticc3.cdngeek.net/images/misc/quote_icon.png Originally Posted by sukh http://staticc3.cdngeek.net/images/buttons/viewpost-right.png Done & yes, it works as expected.

 

I think you should do the same test in your env, create 2 accounts and set permissions as requied, don;t set the Send-As as you dont want that. Just Send-on-Behalf. No membership in any groups other than domain users for both accounts.

________________________________________________________________

 

i have done the same thing and still have the same frustrating results.

 

i am running server 2K8r2sp1 and exchange server 2010.

Edited by cynlis
added quote that i'm responding to
Posted (edited)
can you run get-mailbox "helpdesk alias"| fl

 

[PS] C:\Windows\system32>get-mailbox "Helpdesk"| fl

 

 

RunspaceId : 1199f269-4b79-4c4d-928d-760ae951989a

Database : ICT Services

UseDatabaseRetentionDefaults : True

RetainDeletedItemsUntilBackup : False

DeliverToMailboxAndForward : True

LitigationHoldEnabled : False

SingleItemRecoveryEnabled : False

RetentionHoldEnabled : False

EndDateForRetentionHold :

StartDateForRetentionHold :

RetentionComment :

RetentionUrl :

LitigationHoldDate :

LitigationHoldOwner :

ManagedFolderMailboxPolicy :

RetentionPolicy : Empty Deleted Items Folder after 30 Days

AddressBookPolicy : Staff Address Book Policy

CalendarRepairDisabled : False

ExchangeGuid : 7984b2ac-a1d1-459d-9322-d6e9f04dae8f

ExchangeSecurityDescriptor : System.Security.AccessControl.RawSecurityDescriptor

ExchangeUserAccountControl : None

MessageTrackingReadStatusEnabled : True

ExternalOofOptions : External

ForwardingAddress : DOMAIN.LOCAL/ICT Services/Users/My Full Name

ForwardingSmtpAddress :

RetainDeletedItemsFor : 14.00:00:00

IsMailboxEnabled : True

Languages : {en-GB}

OfflineAddressBook :

ProhibitSendQuota : unlimited

ProhibitSendReceiveQuota : unlimited

RecoverableItemsQuota : 30 GB (32,212,254,720 bytes)

RecoverableItemsWarningQuota : 20 GB (21,474,836,480 bytes)

DowngradeHighPriorityMessagesEnabled : False

ProtocolSettings : {RemotePowerShell§1}

RecipientLimits : unlimited

IsResource : False

IsLinked : False

IsShared : False

LinkedMasterAccount :

ResourceCapacity :

ResourceCustom : {}

ResourceType :

SamAccountName : helpdesk

SCLDeleteThreshold :

SCLDeleteEnabled :

SCLRejectThreshold :

SCLRejectEnabled :

SCLQuarantineThreshold :

SCLQuarantineEnabled :

SCLJunkThreshold :

SCLJunkEnabled :

AntispamBypassEnabled : False

ServerLegacyDN : /o=SCHOOL NAME/ou=Exchange Administrative Group (FYDIBOHF23SPDLT)/c

n=Configuration/cn=Servers/cn=ALBANYEXCH

ServerName : SERVER NAME

UseDatabaseQuotaDefaults : True

IssueWarningQuota : unlimited

RulesQuota : 64 KB (65,536 bytes)

Office :

UserPrincipalName : Helpdesk Email Address

UMEnabled : False

MaxSafeSenders :

MaxBlockedSenders :

ReconciliationId :

WindowsLiveID :

ThrottlingPolicy :

RoleAssignmentPolicy : Default Role Assignment Policy

SharingPolicy : Default Sharing Policy

RemoteAccountPolicy :

MailboxPlan :

ArchiveDatabase :

ArchiveGuid : 00000000-0000-0000-0000-000000000000

ArchiveName : {}

ArchiveQuota : 50 GB (53,687,091,200 bytes)

ArchiveWarningQuota : 45 GB (48,318,382,080 bytes)

ArchiveDomain :

ArchiveStatus : None

RemoteRecipientType : None

DisabledArchiveDatabase :

DisabledArchiveGuid : 00000000-0000-0000-0000-000000000000

QueryBaseDNRestrictionEnabled : False

MailboxMoveTargetMDB :

MailboxMoveSourceMDB :

MailboxMoveFlags : None

MailboxMoveRemoteHostName :

MailboxMoveBatchName :

MailboxMoveStatus : None

IsPersonToPersonTextMessagingEnabled : False

IsMachineToPersonTextMessagingEnabled : True

UserSMimeCertificate : {}

UserCertificate : {}

CalendarVersionStoreDisabled : False

ImmutableId :

PersistedCapabilities : {}

SKUAssigned : False

AuditEnabled : False

AuditLogAgeLimit : 90.00:00:00

AuditAdmin : {Update, Move, MoveToDeletedItems, SoftDelete, HardDelete, FolderBind, SendAs,

SendOnBehalf, Create}

AuditDelegate : {Update, SoftDelete, HardDelete, SendAs, Create}

AuditOwner : {}

WhenMailboxCreated : 10/04/2012 14:29:36

UsageLocation :

Extensions : {}

HasPicture : False

HasSpokenName : False

AcceptMessagesOnlyFrom : {}

AcceptMessagesOnlyFromDLMembers : {}

AcceptMessagesOnlyFromSendersOrMembers : {}

AddressListMembership : {\Mailboxes(VLV), \All Mailboxes(VLV), \All Recipients(VLV), \Default Global A

ddress List, \All Users}

Alias : helpdesk

ArbitrationMailbox :

BypassModerationFromSendersOrMembers : {}

OrganizationalUnit : domain.local/Mailbox Only

CustomAttribute1 :

CustomAttribute10 :

CustomAttribute11 :

CustomAttribute12 :

CustomAttribute13 :

CustomAttribute14 :

CustomAttribute15 :

CustomAttribute2 :

CustomAttribute3 :

CustomAttribute4 :

CustomAttribute5 :

CustomAttribute6 :

CustomAttribute7 :

CustomAttribute8 :

CustomAttribute9 :

ExtensionCustomAttribute1 : {}

ExtensionCustomAttribute2 : {}

ExtensionCustomAttribute3 : {}

ExtensionCustomAttribute4 : {}

ExtensionCustomAttribute5 : {}

DisplayName : Helpdesk

EmailAddresses : {smtp:Helpdesk Full Email Old Web Domain, SMTP:Helpdesk Full Email New Web Domain,

smtp:Original Help.Desk Email Address Old Web Domain, smtp:[email protected], smtp:[email protected]}

GrantSendOnBehalfTo : {DOMAIN.LOCAL/ICT Services/Users/My Full Name}

ExternalDirectoryObjectId :

HiddenFromAddressListsEnabled : False

LastExchangeChangedTime :

LegacyExchangeDN : /o=SCHOOL NAME/ou=Exchange Administrative Group (FYDIBOHF23SPDLT)/c

n=Recipients/cn=Helpdesk Full Name

MaxSendSize : unlimited

MaxReceiveSize : unlimited

ModeratedBy : {}

ModerationEnabled : False

PoliciesIncluded : {}

PoliciesExcluded : {{26491cfc-9e50-4857-861b-0cb8df22b5d7}}

EmailAddressPolicyEnabled : False

PrimarySmtpAddress : Helpdesk Full Email Address

RecipientType : UserMailbox

RecipientTypeDetails : UserMailbox

RejectMessagesFrom : {}

RejectMessagesFromDLMembers : {}

RejectMessagesFromSendersOrMembers : {}

RequireSenderAuthenticationEnabled : False

SimpleDisplayName :

SendModerationNotifications : Always

UMDtmfMap : {emailAddress:43573375, lastNameFirstName:43573375252269, firstNameLastName:25

226943573375}

WindowsEmailAddress : Helpdesk Full Email Address

MailTip :

MailTipTranslations : {}

PartnerObjectId : 00000000-0000-0000-0000-000000000000

IsValid : True

ExchangeVersion : 0.10 (14.0.100.0)

Name : Helpdesk Full Name

DistinguishedName : CN=Helpdesk Full Name,OU=Mailbox Only,DC=DOMAIN,DC=LOCAL

Identity : DOMAIN.LOCAL/Mailbox Only/Helpdesk Full Name

Guid : cc8e521a-dd01-4258-bd67-e2725b031c31

ObjectCategory : DOMAIN.LOCAL/Configuration/Schema/Person

ObjectClass : {top, person, organizationalPerson, user}

WhenChanged : 08/02/2013 09:16:10

WhenCreated : 10/04/2012 14:29:36

WhenChangedUTC : 08/02/2013 09:16:10

WhenCreatedUTC : 10/04/2012 13:29:36

OrganizationId :

OriginatingServer : Our Primary DC FQDN

 

 

 

[PS] C:\Windows\system32>

Edited by AceDaz
Posted
It isn't something to do with AD Security Permissions? I know that if a user needs to use a Mobile device to connect to their emails then I need to give them allow access to Create msExchActiveSyncDevices objects and Delete msExchActiveSyncDevices objects
Posted
Wanted I wanted to see was the actual email addresses so I can see what's going on. I know you have edited by giving the description but I wanted to verify. Can you PM me?
  • 3 months later...
Posted (edited)
Hi All

 

We setup our own Exchange Server as part of a complete server refresh a few months ago, and now it is hit and miss whether the SendAs works or not.

 

I have a Helpdesk mailbox that I SendAs when I need to send anything out, if you add the email address in to my Outlook and go to send a email, it comes back with "You can't send a message on behalf of this user unless you have permission to do so. Please make sure you're sending on behalf of the correct sender, or request the necessary permission. If the problem continues, please contact your helpdesk."

 

I have tried removing the rights, I have tried leaving it 24 hours, It sometimes works if I remove the email address from my Outlook "From" field and retype it.

 

 

It has been working for about a week, but when I tried to sort out someone elses SendAs for the accounts it stopped mine (presumably when I restarted the Information Store service). I have noticed that I am currently running native SP2 and not any additional RollUps. Could this affect it?

 

Many thanks

 

I have been having the same issues and found your forum looking for the answer. I just worked through the issue and wanted to let you all know what I did...

 

My symptoms: Trying to Send As another mailbox user for which the sending user had full access permissions. This was not an issue testing from my login which is a Domain Admin. Received all variations of no access to send as the specified user when testing from non-Domain Admin accounts.

 

My fix:

 

Exchange - User must have full access permission and send on behalf permission. Send As permission not required. (the send as was not needed for the domain admin account. Inheritance setting were the same between the Domain User and Domain Admin accounts.)

 

Outlook - Open Mail from Control Panel and delete the existing profile. Create a new profile named Outlook and add your primary account. Choose "Add another account" after your primary account has been configured and add the account for which you've given yourself/the user full access/send on behalf permissions. This worked for cached exchange mode.

 

Open Outlook. You'll see the second account listed twice. Close Outlook. Open Outlook. The second listing will have dropped off. Click the second account and start a new message. The From should already be set as the secondary account.

 

In addition you may configure Signatures for each account. The signature will change depending on which account you start the message from, or for whichever account you choose the message to be From once composing.

 

NOTE: Another little nugget I learned along the way is that the account/s you wish to send on behalf of MUST NOT be hidden from the Address Lists.

 

Hope this helps someone!

Edited by mgrieve
  • 6 months later...
Posted

Does anyone have a solution for the original problem? I'm having the exact same situation - some of my users cannot use SendAs while others can. SendOnBehalfOf is no option in our environment.

 

The problems started after applying SP3 RU2 to all of our EX2010. We have over 60 DCs, some 24 EX with CAS/HUB/MBX roles and 1 DAG, 8 MBX only in 2 stretched DAGs, 6 CAS/HUB only behind LoadBalancers.

 

Removing the address we want to send as and re-adding works for just one email, as described by the others having this problem, but this is not really an option, for sure.

 

If someone has a hint where to look for, I'd be glad.

 

Bob

Posted

1) does it work from webmail?

2) disable outlook autocomplete and try again adding the email specifically by selecting from the address book not typing by self

2) disable outlook autocomplete and try again adding the email specifically by typing and not from the address book

Posted
1) does it work from webmail?

 

Yes, it does work each time. But whats notable: The address in question is disappearing from the From: Button, so I have to re-enter it each time I compose a new message. With other accounts, from which the users can SendAs as wanted, the SendAs-addresses do NOT disappear.

 

2) disable outlook autocomplete and try again adding the email specifically by selecting from the address book not typing by self

2) disable outlook autocomplete and try again adding the email specifically by typing and not from the address book

 

None of the above change the behaviour: The first email gets send correctly, the following don't.

 

Remarkably, when I delete and re-add the permission over and over, sending emails using the SendAs right at some point works ok. This is not reproducable - sometimes it takes 3 tries, sometimes 6, some work from the very start. Not the game I can play with my users.

 

Remarkable might be, that the SendAs addresses in question are in fact contacts, not mailboxes. SendAs on mailboxes works all the time for every user. If it wouldn't, we'd be at a loss, because none of my users actually use the account they're logged in with to send emails, but use a second mailbox the have FullAccess to and the SendAs right for. It's just some contacts that can't be used as SendAs.

 

We used to set the SendAs right via Add-ADPermission, which after applying SP3 RU2 is not usable anymore. Trying Add-ADPermission throws an Error 5, "Permission denied", no matter which admin tries to use it. Even Exchange Organization Admins cannot set the SendAs right via Add-ADPermission, so we have to use the security tab in ADUC. I don't know if this has something to do with the problem of being unable to actually *use* the SendAs right, but it sounds strange that we cannot set it for contacts and not use it with contacts, so there might be a connection between the two errors.

 

Any hint would be greatly appreaciated.

Posted
I finally got this working just recently, I think it was linked to it not finding it in the Global Address List. Are the email accounts you are trying to SendAs visible and available in the GAL?
Posted

I resolved this. In fact, it has something to do with the address lists, but nothing one could have expected:

 

We're using Outlook 2010. When Outlook wants to send a message one has SendAs rights onto, it does not simply give the address to the mailbox server in question, which would be sufficient, but instead it seems to pass a pointer to the entry in the address list the entry derives from. Having Outlook configured in the way that it starts searching in a customized address list and NOT letting it continue the search in the global address list makes it merely impossible to use addresses from the global address list as SendAs addresses. You have to put those addresses in the customized address list.

 

This is complete nonsense, because Outlook could have let the mailbox server decide wether to accept the message or not (which in fact it does in cached mode!), but I guess we have to live with it.

 

Bob

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...