Exchange 2003 to 2007 Permissions issues

After moving some mailboxes i got the following error:

Exchange ActiveSync doesn’t have sufficient permissions to create the “CN=[user name],OU=[User OU],DC=[domain],DC=com” container under Active Directory user “Active Directory operation failed on [DC server name]. This error is not retriable. Additional information: Access is denied.
Active directory response: 00000005: SecErr: DSID-03151E07, problem 4003 (INSUFF_ACCESS_RIGHTS), data 0
Make sure the user has inherited permission granted to domain\Exchange Servers to allow List, Create child, Delete child of object type “msExchActiveSyncDevices” and doesn’t have any deny permissions that block such operations.



Open Active Directory console, make sure advanced features are on then:

Open user account properties in Active Directory Users and Computers, change to Security tab > Advanced – check Include inheritable permissions from this object’s parents.

This fixes error.

Leave a Reply

Your email address will not be published. Required fields are marked *

Blue Captcha Image