Microsoft.Exchange.Common entraîne des erreurs d'accès refusé lors d'une sauvegarde sur bandes des éléments individuels ou lors d'une restauration depuis un disque des éléments individuels avec la technologie GRT.
book
Article ID: 100035121
calendar_today
Updated On:
Description
Issue
Microsoft.Exchange.Common causes access denied errors when backing up individual items to tape or restoring them from disk using GRT technology.
DETAILS:
GRT technology enables backing up and restoring individual items across multiple Backup Exec Remote Agents for Windows Servers. The GRT feature for Exchange allows you to use MAPI to impersonate individual users from a single account to access mailboxes and create a catalog of their contents.
During a GRT tape backup or GRT disk restore, this mailbox content cataloging process is performed after the information store (or storage groups, depending on how the selection list was created) backup is complete. The store is "sequenced," and the Exchange environment is simulated so that Backup Exec can use GRT technology to access mailboxes and create catalogs in the case of a backup, or read catalogs in the case of a restore.
Error message
- V-79-57344-33928 - Access denied. Unable to back up the Storage_Group directory and its subdirectories.
0xe00002fe - Unable to connect to the MAPI with the specified credentials. Review the job's resource credentials and then rerun the job.
OR
- The Exchange information store backup fails with the error "Access denied," and the following error appears in the job log:
Completed status: Failed.
Final error: 0xe0008488 - Access is denied.
Final error category: Security Errors - Access Denied. Cannot back up directory mailbox database and its subdirectories.
Cause
The errors described above occur if the login account used in the backup job does not have sufficient privileges, or if one or more Active Directory user accounts with mailboxes in the mailbox store are disabled. Backup Exec uses the Exchange server's MAPI subsystem to create granular restore selections of database items in the Exchange information store, which sends a query to Active Directory. This only occurs when the backup job is redirected to tape, as opposed to a disk backup folder.
If a user account has been disabled, Backup Exec cannot retrieve that user's mailbox information from Active Directory, and an Access Denied error is returned. This can also occur if the system login account is not set in the Backup Exec console.
Resolution
- To enable this complex process, the necessary account must have very specific permissions and attributes:
- This must be a top-level Exchange Full Administrator (Exchange 2003), Exchange Organization Administrator (Exchange 2007), or Exchange Organization Management (Exchange 2010) account.
- The account must be either of type Domain Administrator (recommended setting, this ensures that the domain administrator is a member of the local Administrator group on the Exchange server), or Local Administrator on the Exchange server, or both (recommended).
- The account must have an active mailbox on the Exchange server.
- The account must have received emails via the mailbox.
- The account must have sent email via the mailbox.
- The first 5 characters of the account name must be unique . Refer to the technical note 100026696 for more information.
- The account must be visible to the global address list and not hidden .
- Ensure that the system login account in Backup Exec is the same as the one assigned to the Backup Exec services .
- Verify that the backup/restore job is set up to use the same system login account and that it is configured as DOMAIN \ USER .
- Verify in Active Directory that the account name, the login account name, and the display name of the USER account match. Names and fields may vary depending on the version of Active Directory.
- The Exchange Management Console (Exchange 2010) or the Exchange Management Tools (Exchange 2007) must be installed on both the Backup Exec media server and the mail server. The same version and upgrades must be installed on both servers. See System Requirements for Using Backup Exec Exchange Agent .
- Assign the Backup Exec system login account the same ID as the Exchange backup. The system login account ID must also match the Backup Exec service ID.
- In the Backup Exec console, click Network -> Login Account and verify that a system login account is specified. If not, create a system login account by clicking the System Account button .
- To resolve the error when user accounts or mailboxes have been disabled, and when you are running a GRT backup to tape, perform one or more of the following actions:
- Grant the "Full Access to Mailbox" and "External Account associated with SELF" rights to the disabled mailbox.
- Reactivate the mailbox by reconnecting it to an active user account in Active Directory.
- Purge the mailbox from the mailbox bank.
- Perform the backup to a backup folder on disk rather than to a tape device.
- Verify that the resource authentication information for the Exchange server and the information store has sufficient privileges to back up the resources.
Issue/Introduction
Microsoft Exchange Common causes access denied errors when backing up individual items to tape or restoring them from disk using GRT technology.
DETAILS:
GRT technology enables backing up and restoring individual items across multiple Backup Exec Remote Agents for Windows Servers. The GRT feature for Exchange allows you to use MAPI to impersonate individual users from a single account to access mailboxes and create a catalog of their contents.
During a GRT tape backup or GRT disk restore, this mailbox content cataloging process is performed after the information store (or storage groups, depending on how the selection list was created) backup is complete. The store is "sequenced," and the Exchange environment is simulated so that Backup Exec can use GRT technology to access mailboxes and create catalogs in the case of a backup, or read catalogs in the case of a restore.
Additional Information
UMI: V-79-57344-33928 ETrack: 0xe00002fe UMI: V-79-57344-766
Was this article helpful?
thumb_up
Yes
thumb_down
No