Exchange permissions removed from AD

Walter Salvatore 1 Reputation point
2021-12-17T18:46:34.23+00:00

We are running Exchange 2013 on prem. Someone was mucking around in AD yesterday and apparently did a "reset default permissions" on the root of AD. All Exchange permissions have now been removed so we can no longer make any changes to any accounts from exchange. Before we open a ticket with Microsoft, is there any easier way to restore the default exchange permissions on AD?

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,935 questions
Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,373 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Andy David - MVP 142.3K Reputation points MVP
    2021-12-17T18:53:51.677+00:00

    Here is the doc listing what perms are set when you run setup/PrepareAD

    https://learn.microsoft.com/en-us/exchange/exchange-2013-deployment-permissions-reference-exchange-2013-help#prepare-active-directory-permissions

    YOu can walk through and ensure its set correctly.

    I would especially focus on and make sure the Exchange Trusted Subsystem has full access down the objects

    158569-image.png

    0 comments No comments

  2. Walter Salvatore 1 Reputation point
    2021-12-20T13:35:00.683+00:00

    Opened a ticket with Microsoft, but as of this time have still not heard from anyone so we will be closing the ticket and asking for a refund.

    We where able to restore the permissions with the help of a group on reddit.

    Copied the Exchange install media to the Exchange server (C:\Temp\Exchange) and ran the following command at an elevated command prompt.

    C:\temp\exchange\Setup.exe /PrepareAD /OrganizationName:"OurOrgName" /IAcceptExchangeServerLicenseTerms

    This fixed the issue.