Microsoft KB Archive/326018

From BetaArchive Wiki
Knowledge Base


Active Directory Users Cannot Obtain Access to Mailbox After Upgrade from Exchange 5.5

Article ID: 326018

Article Last Modified on 10/25/2007



APPLIES TO

  • Microsoft Exchange Server 2003 Enterprise Edition
  • Microsoft Exchange Server 2003 Standard Edition
  • Microsoft Exchange 2000 Server Standard Edition



This article was previously published under Q326018

SYMPTOMS

After you upgrade from Exchange Server 5.5 on Microsoft Windows NT Server to Exchange 2000 Server or Exchange Server 2003 on Microsoft Windows 2000 Server, you may experience the following symptoms:

  • Only Windows NT Server accounts can obtain access to their mailboxes on the Exchange-based computer.
  • Migrated Active Directory users cannot obtain access to their mailboxes on the Exchange-based computer.
  • Migrated Active Directory users may receive the following error message during a connection attempt:

    You do not have permission to logon.

  • You may receive the following entry in the Event Viewer Application Log:

    Event Type: Error
    Event Source: MSExchangeIS Mailbox Store Event Category: Logons
    Event ID: 1022
    User: N/A Computer: server name
    Description: Logon Failure on database "First Storage Group\Mailbox Store (Exchange computer name)" - Windows 2000 account domain name\user name; mailbox /o=Active Directory organization name/ou=organizational unit name/cn=Recipients/cn=user name. Error: -2147024891


CAUSE

This issue may occur if all of the permissions that are necessary for mailbox access were not migrated. This may occur when the account was copied from Windows NT Server.

RESOLUTION

To resolve this issue, modify permissions for the Active Directory users to include SELF rights:

  1. Click Start, point to Programs, point to Administrative Tools, and then click Active Directory Users and Computers.
  2. Double-click Users.
  3. Right-click the user who cannot log on, and then click Properties.
  4. Click the Exchange Advanced tab, and then click Mailbox Rights.
  5. Click Add.
  6. In the list of names, click Self, and then click Add.
  7. Click OK, and then click OK.
  8. Repeat this process for each user who cannot log on to their mailbox.


MORE INFORMATION

For future migrations, use the Active Directory Migration Tool (ADMT) to migrate users from Windows NT to the Active Directory in Windows 2000. Do this before you complete the Exchange upgrade.

For additional information about how to use the ADMT, click the article number below to view the article in the Microsoft Knowledge Base:

260871 How to Set Up ADMT for Windows NT 4.0 to Windows 2000 Migration


For more information about how to plan an upgrade from Exchange 5.5 to Exchange 2000, visit the following Microsoft Web site:


Additional query words: XADM

Keywords: kberrmsg kbprb KB326018