Insufficient access rights to perform the operation. Active directory response: 00002098: SecErr: DSID-03150F94, problem 4003

abdi mreza 1 Reputation point
2021-12-08T10:26:02.76+00:00

hi
exchange 2019
cannot create new mailbox
error
Active Directory operation failed on <domain controller>. This error is not retriable. Additional information: Insufficient access rights to perform the operation. Active directory response: 00002098: SecErr: DSID-03150F94, problem 4003 (INSUFF_ACCESS_RIGHTS)

Exchange | Exchange Server | Management
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Kael Yao 37,746 Reputation points Moderator
    2021-12-09T06:05:30.253+00:00

    Hi @abdi mreza

    What is the detailed command you are using to create new mailboxes?

    Please have a check in Active Directory Users and Computers if the server is a member of the Exchange Trusted System.
    156110-10.png

    If this issue occurs when you try to modify or enable mailboxes for users in a specific OU, please follow these steps to ensure Exchange Trusted Substystem has the required permissions:

    • Open Active Directory Users and Computers.
    • Click View, and then click Advanced Features.
    • Right-click the OU that contains the user and then click Properties.
    • In the Security tab, click Advanced.
    • In the Permissions tab, click Add.
    • In the Enter object name to select box, type Exchange trusted subsystem, and then click OK.
    • In the Object tab, select This object and all descendant’s objects in the Apply onto list, locate Modify Permissions in the Permissions list, and then set it to Allow.
    • Click OK
    • Make sure above option is checked on all OU’S listed in the object path of the user object

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    1 person found this answer helpful.

  2. Limitless Technology 39,926 Reputation points
    2021-12-10T09:06:47.72+00:00

    Hi there,

    This might be due to the permission inheritance . Check the following setting and see if this can help you.

    -Open ADSIEdit -> Configuration container
    -Services -> Microsoft Exchange -> First Organization -> Administrative Groups -> Exchange Administrative Group (FYDIBOHF23SPDLT)
    -Double-click on it, under the Security tab. Choose Exchange Trusted Subsystem, check the full access permission, and enable inheritance (If it's enabled, disable then enable it).

    You can also try other troubleshooting steps from this article
    https://learn.microsoft.com/en-us/exchange/troubleshoot/administration/insufficient-access-rights-perform-operation

    -------------------------------------------------------------------------------------------------------------------------------------------------------------

    --If the reply is helpful, please Upvote and Accept it as an answer--

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.