The user has insufficient access rights
Hello
Im upgrading exchange 2007 to exchange 2010. When I run tha setup to install the client access role, Im obtaining the next error in the log file ExchangeSetup.log
[03/27/2012 22:06:03.0519] [2] Used domain controller dmnbck.midominio.gob.mx to read object CN=Address Lists Container,CN=midominio,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=midominio,DC=gob,DC=mx.
[03/27/2012 22:06:03.0519] [2] Used domain controller dmnbck.midominio.gob.mx to read object CN=Offline Address Lists,CN=Address Lists Container,CN=midominio,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=midominio,DC=gob,DC=mx.
[03/27/2012 22:06:03.0535] [2] Used domain controller dmnbck.midominio.gob.mx to read object CN=Recipient Policies,CN=midominio,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=midominio,DC=gob,DC=mx.
[03/27/2012 22:06:03.0535] [2] Used domain controller dmnbck.midominio.gob.mx to read object CN=Sites,CN=Configuration,DC=midominio,DC=gob,DC=mx.
[03/27/2012 22:06:03.0535] [2] Used domain controller dmnbck.midominio.gob.mx to read object CN=Exchange Administrative Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=midominio,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=midominio,DC=gob,DC=mx.
[03/27/2012 22:06:03.0550] [2] Used domain controller dmnbck.midominio.gob.mx to read object CN=Arrays,CN=Exchange Administrative Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=midominio,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=midominio,DC=gob,DC=mx.
[03/27/2012 22:06:03.0769] [2] Adding access control entries to the security descriptor for the object CN=Configuration,DC=midominio,DC=gob,DC=mx.
[03/27/2012 22:06:03.0878] [2] The appropriate access control entry is already present on the object "CN=Configuration,DC=midominio,DC=gob,DC=mx" for account "midominio\Exchange Servers".
[03/27/2012 22:06:03.0878] [2] Taking ownership of CN=Deleted Objects,CN=Configuration,DC=midominio,DC=gob,DC=mx.
[03/27/2012 22:06:03.0956] [2] [ERROR] Active Directory operation failed on dmnbck.midominio.gob.mx. This error is not retriable. Additional information: Access is denied.
Active directory response: 00000005: SecErr: DSID-031521D0, problem 4003 (INSUFF_ACCESS_RIGHTS), data 0
[03/27/2012 22:06:03.0956] [2] [ERROR] The user has insufficient access rights.
[03/27/2012 22:06:03.0988] [2] Ending processing initialize-ExchangeConfigurationPermissions
[03/27/2012 22:06:03.0988] [1] The following 1 error(s) occurred during task execution:
[03/27/2012 22:06:03.0988] [1] 0. ErrorRecord: Active Directory operation failed on dmnbck.midominio.gob.mx. This error is not retriable. Additional information: Access is denied.
Active directory response: 00000005: SecErr: DSID-031521D0, problem 4003 (INSUFF_ACCESS_RIGHTS), data 0
[03/27/2012 22:06:03.0988] [1] 0. ErrorRecord: Microsoft.Exchange.Data.Directory.ADOperationException: Active Directory operation failed on dmnbck.midominio.gob.mx. This error is not retriable. Additional information: Access is denied.
Active directory response: 00000005: SecErr: DSID-031521D0, problem 4003 (INSUFF_ACCESS_RIGHTS), data 0
---> System.DirectoryServices.Protocols.DirectoryOperationException: The user has insufficient access rights.
at System.DirectoryServices.Protocols.LdapConnection.ConstructResponse(Int32 messageId, LdapOperation operation, ResultAll resultType, TimeSpan requestTimeOut, Boolean exceptionOnTimeOut)
at System.DirectoryServices.Protocols.LdapConnection.SendRequest(DirectoryRequest request, TimeSpan requestTimeout)
at Microsoft.Exchange.Data.Directory.PooledLdapConnection.SendRequest(DirectoryRequest request, LdapOperation ldapOperation, IAccountingObject budget, Nullable`1 clientSideSearchTimeout)
at Microsoft.Exchange.Data.Directory.ADSession.ExecuteModificationRequest(ADObject entry, DirectoryRequest request, ADObjectId originalId, Boolean emptyObjectSessionOnException)
--- End of inner exception stack trace ---
at Microsoft.Exchange.Data.Directory.ADSession.AnalyzeDirectoryError(PooledLdapConnection connection, DirectoryRequest request, DirectoryException de, Int32 totalRetries, Int32 retriesOnServer)
at Microsoft.Exchange.Data.Directory.ADSession.ExecuteModificationRequest(ADObject entry, DirectoryRequest request, ADObjectId originalId, Boolean emptyObjectSessionOnException)
at Microsoft.Exchange.Data.Directory.ADSession.SaveSecurityDescriptor(ADObject obj, RawSecurityDescriptor sd, Boolean modifyOwner)
at Microsoft.Exchange.Management.Tasks.DirectoryCommon.TakeOwnership(ADObjectId id, RawSecurityDescriptor sd, ADSystemConfigurationSession session)
at Microsoft.Exchange.Management.Tasks.InitializeConfigPermissions.InternalProcessRecord()
at Microsoft.Exchange.Configuration.Tasks.Task.ProcessRecord()
[03/27/2012 22:06:03.0988] [1] [ERROR] The following error was generated when "$error.Clear();
initialize-ExchangeConfigurationPermissions -DomainController $RoleDomainController
" was run: "Active Directory operation failed on dmnbck.midominio.gob.mx. This error is not retriable. Additional information: Access is denied.
Active directory response: 00000005: SecErr: DSID-031521D0, problem 4003 (INSUFF_ACCESS_RIGHTS), data 0
".
[03/27/2012 22:06:03.0988] [1] [ERROR] Active Directory operation failed on dmnbck.midominio.gob.mx. This error is not retriable. Additional information: Access is denied.
Active directory response: 00000005: SecErr: DSID-031521D0, problem 4003 (INSUFF_ACCESS_RIGHTS), data 0
[03/27/2012 22:06:03.0988] [1] [ERROR] The user has insufficient access rights.
[03/27/2012 22:06:03.0988] [1] [ERROR-REFERENCE] Id=CommonGlobalConfig___faf991c2f0874a8dba67f91db0ea193e Component=EXCHANGE14:\Current\Release\Shared\Datacenter\Setup
[03/27/2012 22:06:04.0003] [1] Setup is stopping now because of one or more critical errors.
[03/27/2012 22:06:04.0003] [1] Finished executing component tasks.
[03/27/2012 22:06:04.0066] [1] Ending processing Install-ExchangeOrganization
[03/27/2012 22:47:06.0349] [0] End of Setup
[03/27/2012 22:47:06.0349] [0] **********************************************
Can you help me, please, your ideas are important.
Thanks
March 27th, 2012 7:30pm
Do the usual, make sure the user has schema admin rights, Exch Org permission, local admin on the server, do a run-as administrator on the exe and test.Sukh
Free Windows Admin Tool Kit Click here and download it now
March 27th, 2012 7:47pm