Can't edit Send As Permission on on-premise Mailboxes Hybrid Exchange set up.

Mike Carter 246 Reputation points
2020-11-09T21:19:37.207+00:00

We are deploying a new Hybrid exchange set between an on-premise exchange 2013 mail server and Office 365. About 2 weeks ago, I noticed that our Organizational Management group disappeared on the on-premise server's ECP console. Along with this my non-domain admin account that I use to delegate limited permissions to lost all rights to administer the on-premise exchange server. At the same time I noticed that on the shared mailboxes, using my domain admin account, I can edit who has full access to the mailbox but I can not add or remove permissions to Send As from the same mailbox.

38435-image.png

In the above screen shot from my on premise ECP console, the plus and Minus buttons are missing and I can not make changes to the Send As permissions.

My other Admin does not recall making any changes that would do this to our On-premise email server. I am looking for help to restore the Organizational Management group and the ability to change the Send As Permissions on our on Premise Email Exchange 2013 Server.

--Update--

It was just pointed out to me that I can no longer make changes to send and receive connectors or any thing else that is on the Mail Flow section. they are all just grayed out.

38728-image.png

Help. I am getting locked out of my On Premise Exchange server.

Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,674 questions
0 comments No comments
{count} votes

Accepted answer
  1. Mike Carter 246 Reputation points
    2020-11-10T23:27:16.817+00:00

    After much pain and suffering of pouring through documentation and starting form the basic about permissions, I found the problem.

    38961-image.png

    The Organization Management group needs to be a Universal Group. Some how it was changed to a Domain local group. Once I made this change, everything was right with the world again in the Exchange Admin Console. The group showed up under permissions and everything that I was having problems with was fixed.

    This is a case example of not to screw with the Built in User Groups.

    0 comments No comments

2 additional answers

Sort by: Most helpful
  1. KyleXu-MSFT 26,271 Reputation points
    2020-11-10T01:47:42.587+00:00

    @Mike Carter

    Here are management roles that contained in "Organization Management" permission group:

    • Active Directory Permissions
    • Address Lists
    • Audit Logs
    • Cmdlet Extension Agents
    • Compliance Admin
    • Data Loss Prevention
    • Database Availability Groups
    • Database Copies
    • Databases
    • Disaster Recovery
    • Distribution Groups
    • Edge Subscriptions
    • E-Mail Address Policies
    • Exchange Connectors
    • Exchange Server Certificates
    • Exchange Servers
    • Exchange Virtual Directories
    • Federated Sharing
    • Information Rights Management
    • Journaling
    • Legal Hold
    • Mail Enabled Public Folders
    • Mail Recipient Creation
    • Mail Recipients
    • Mail Tips
    • Mailbox Import Export
    • Mailbox Search
    • Message Tracking
    • Migration
    • Monitoring
    • Move Mailboxes
    • Org Custom Apps
    • Org Marketplace Apps
    • Organization Client Access
    • Organization Configuration
    • Organization Transport Settings
    • POP3 And IMAP4 Protocols
    • Public Folders
    • Receive Connectors
    • Recipient Policies
    • Remote and Accepted Domains
    • Retention Management
    • Role Management
    • Security Admin
    • Security Group Creation and Membership
    • Security Reader
    • Send Connectors
    • Team Mailboxes
    • Transport Agents
    • Transport Hygiene
    • Transport Queues
    • Transport Rules
    • UM Mailboxes
    • UM Prompts
    • Unified Messaging
    • User Options
    • View-Only Audit Logs
    • View-Only Configuration
    • View-Only Recipients
    • WorkloadManagement

    About Send As permission, we can use command below to know this command permission is contained in "Active Directory Permissions" permission role:
    38594-qa-kyle-09-45-19.png

    You just need to create a permission group(such as Organization Management) with this permission role, then add your account into this permission group. After that, login in ECP again, you will could using this permission again.


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


  2. KyleXu-MSFT 26,271 Reputation points
    2020-11-10T02:27:54.303+00:00

    @Mike Carter
    The Get-ManagementRole just used to check the "Add-ADPermission" command contained in which permission role, don't mean your account has this permission. You need to add the "Active Directory Permissions" into a "role group", then add your account into this group, such as:
    38578-qa-kyle-10-21-04.png

    I notice that you even cannot create a new role group, try to check from ADUC, make sure you admin account contained in those groups:
    38579-qa-kyle-10-25-07.png

    Then sign out and login ECP, check whether you could modify role group and whether is the "Active Directory Permissions" role group exist.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.