Windows 10: Grant shared mailbox access to users from trusted forest

Discus and support Grant shared mailbox access to users from trusted forest in Windows 10 Customization to solve the problem; Hi I am unable to grant shared mailbox access to users in another trusted forest. I've used the command "Add-MailboxPermission sharedmailboxalias -User... Discussion in 'Windows 10 Customization' started by Chiew Sheng Liew, Sep 29, 2021.

  1. Grant shared mailbox access to users from trusted forest


    Hi I am unable to grant shared mailbox access to users in another trusted forest. I've used the command "Add-MailboxPermission sharedmailboxalias -User "DomainA\UserA" -AccessRights FullAccess" but is getting the error "User or group wasn't found. Please make sure you've typed it correctly."May I know if this is by design not to be able to grant access to users in another trusted forest?Regards,Liew

    :)
     
    Chiew Sheng Liew, Sep 29, 2021
    #1
  2. Hub-Site Win User

    root forest -Trust

    Hi all,

    hope someone can shed some light on this issue. In our environment we have Windows Server 2003 DC on domain (A). and DC 2012 R2 Domain (B). these two are not same forest root.

    we setup one-way Trust (Type) Forest trust transitive= Domain B (2012 R2 DC) trusted Domain A (2003 DC)=

    -Direction of trust- Outgoing

    -Transitivity of trust- forest transitive

    -Validated successful.

    -Name suffix Routing setup for Domain.local B forest.

    -authentication Forest wide - forest wide authentication

    validated = passed (no problem here)

    adding users to domain B group = failed error stated (some of the object names cannot be shown in their user-friendly name form , this can happen if the object is from an external domain and that domain is not available to translate the object name)



    this happened after selected some users from domain A, which mean I did able browsing on domain-A of AD.

    If we tried two way trust then everything seemed OK, we were able successfully added some users. so no issue on two-way trust.

    if two way-trust is fine, that's rule out DNS, right?

    thank you every much in advance.
     
    Hub-Site, Sep 29, 2021
    #2
  3. changari Win User
    Raising the windows domain and forest issues?


    hi,

    I run a domain that was all 2003 r2 servers. I recently upgraded all my domain controllers to windows 2012 r2.
    That went off without any problems.. Our trust relationships had no issues also.

    My first step was to raise the Domain and Forest levels past 2003 to 2008. This went off without a hitch.
    These are the features for raising the levels to 2008:

    • Features and benefits include all default Active Directory features, all features from the Windows Server 2003 domain functional level, plus:
    • Read-Only Domain Controllers – Allows implementation of domain controllers that only host read-only copy of NTDS database.
    • Advanced Encryption Services – (AES 128 and 256) support for the Kerberos protocol.
    • Distributed File System Replication (DFSR) – Allows SYSVOL to replicate using DFSR instead of older File Replication Service (FRS). It provides more robust and detailed replication of SYSVOL contents.

    Forest Level Windows Server 2008

    • Features and benefits include all of the features that are available at the Windows Server 2003 forest functional level, but no additional features. All domains that are subsequently added to the forest will operate at the Windows Server 2008 domain functional level by default.


    My next step is to raise the domain and forest to 2008 r2, then 2012, and finally 2012 r2. I have been trying to find out exactly what I could expect from raising the Domain and Forest for each step.

    The step involving 2008 r2 seems relatively a non issue. But getting the couple of new features seem very nice

    Domain Level Windows Server 2008 R2

    • All default Active Directory features, all features from the Windows Server 2008 domain functional level, plus 2 new features

    Forest Level Windows Server 2008 R2

    • All of the features that are available at the Windows Server 2003 forest functional level, plus the following features:


    • Active Directory Recycle Bin, which provides the ability to restore deleted objects in their entirety while AD DS is running. <== New Feature very cool
    • All domains subsequently added to the forest will operate at the Windows Server 2008 R2 domain functional level by default.

    Here is my big concerns for the next raising of domain and forest to 2012.

    Forest Level Windows Server 2012:

    • All of the features that are available at the Windows Server 2008 R2 forest functional level, but no additional features.
    • All domains subsequently added to the forest will operate at the Windows Server 2012 domain functional level by default.

    Domain Level Windows Server 2012 R2: <=====
    Need to investigate more and why this post

    • DC-side protections for Protected Users. Protected Users authenticating to a Windows Server 2012 R2 domain can no longer:


    • Authenticate with NTLM authentication <==============(what issues may arise)
    • Use DES or RC4 cipher suites in Kerberos pre-authentication
    • Be delegated with unconstrained or constrained delegation
    • Renew user tickets (TGTs) beyond the initial 4-hour lifetime


    Will this affect my exchange anywhere users with remote access authenticating either clear of NTLM???
    and what would/may not to work properly day 1 when I raise the domain and forest to 2012. I cant really find anyone that can answer a straight question.

    Has anyone gone through this? what problems did you have, if any , if a lot???

    Any thoughts and suggestions will be much appreciated??

    thanks


    - - - Updated - - -

    One more point... I am not sure if I posted this to the correct forum.. So if I was wrong and it should be in a different one..
    PLEASE LET ME KNOW
     
    changari, Sep 29, 2021
    #3
  4. DTG1 Win User

    Grant shared mailbox access to users from trusted forest

    Cannot access shared network drive


    Personally, I wouldnt use Everyone. If anyone hacks into you, they have full access to everything and can demolish everything on your raid. I would rather set up accounts and access separately for each person. That way, I know who did all that damage. In the end with a little extra work, I feel more secure by using Authenticated Users.


    If this helps.
    step 1 create non-microsoft account and without email and address without admin rights
    step 2 share a drive or folder to specific user account (if Everyone is listed, remove it)
    step 3 set security > add Authenticated Users (if more than 1 account) or add specific users
    step 3a remove Everyone from list
    step 3b uncheck full control and write for all items listed except SYSTEM and Admin account.
    step 4 right click Start > Computer Management > System Tools > Shared Folders > Shares ... to verify settings and change anything else. You can also see the number of connections to each share here.
     
Thema:

Grant shared mailbox access to users from trusted forest

Loading...
  1. Grant shared mailbox access to users from trusted forest - Similar Threads - Grant shared mailbox

  2. Windows Copilot for Shared Mailboxes?

    in Windows 10 Software and Apps
    Windows Copilot for Shared Mailboxes?: Hi all,We have just signed up for a subscription for Windows Copilot, but we see we can't use it on Shared Mailboxes.An executive assistant wants to use it to analyse emails for the CEO, but they can't use it for anything other than their own mailbox. This makes the...
  3. setting up CES and CEP PKI in a trusted forest scenario

    in Windows 10 Gaming
    setting up CES and CEP PKI in a trusted forest scenario: I have two domains with a two-way forest trust. I want computer accounts in DomainB to enroll for computer client auth certificates from the two-tier Windows CA in DomainA. I configured a certificate cert template in the issuing CA for this and gave Read and Enroll rights to...
  4. users notified when their mailboxes are shared

    in Windows 10 Gaming
    users notified when their mailboxes are shared: users notified when their mailboxes are sharedFrom a government regulation and privacy regulation how can we set it so that when a users mailbox is shared in office 365 that the user has the option to be notified. Currently o365 and azure are stuck on their fixed lists and...
  5. users notified when their mailboxes are shared

    in Windows 10 Software and Apps
    users notified when their mailboxes are shared: users notified when their mailboxes are sharedFrom a government regulation and privacy regulation how can we set it so that when a users mailbox is shared in office 365 that the user has the option to be notified. Currently o365 and azure are stuck on their fixed lists and...
  6. grant users device manager access

    in AntiVirus, Firewalls and System Security
    grant users device manager access: have few users who require access device manager to make chnages, these are basic domain users and we dont want to give or add them to local admin or doamin admin modes....
  7. grant users device manager access

    in Windows 10 Gaming
    grant users device manager access: have few users who require access device manager to make chnages, these are basic domain users and we dont want to give or add them to local admin or doamin admin modes....
  8. grant users device manager access

    in Windows 10 Software and Apps
    grant users device manager access: have few users who require access device manager to make chnages, these are basic domain users and we dont want to give or add them to local admin or doamin admin modes....
  9. GRANT ACCESS

    in Windows 10 Customization
    GRANT ACCESS: Aditional permissions are required to access the following files... MS Word needs access to the file named.. Sečect the mite to grant access. Word cannot open the document : user does not have access privileges...
  10. How To: Save mail sent as Shared Mailbox in sent items Shared Mailbox

    in Windows 10 Tutorials
    How To: Save mail sent as Shared Mailbox in sent items Shared Mailbox: When you have a situation of a user having full access and send as access on a shared mailbox and the user sends an email send-as or on behalf of a Shared Mailbox, the sent item will be saved in the user’s mailbox and not in the Shared Mailbox. To fix this, there is not...