We're trying to add a Send As permission in the properties for a group through Adaxes. It works for Send on Behalf, but whenever we try to add Send As delegation in Adaxes, we get this error. Not quite sure what wouldn't have "sufficient access rights" on dc2, when it can perform other tasks.

Softerra.Adaxes.BackgroundThreadException: Exchange 2013 PowerShell API: Failed to execute the following operation: Modify mail settings for teamtest2 (domain.com\Distribution Groups)' ---> System.Management.Automation.RemoteException: Active Directory operation failed on dc2.domain.com This error is not retriable. Additional information: Access is denied.
Active directory response: 00000005: SecErr: DSID-03152612, problem 4003 (INSUFF_ACCESS_RIGHTS), data 0

--- End of inner exception stack trace ---

It looks like the issue occurs because the account that was specified during the domain registration in Adaxes does not have required permissions in Exchange. For information on how to check/change the account, have a look at the following help article: https://www.adaxes.com/help/?HowDoI.Man ... nInfo.html. It is recommended to assign the account to the Organization Management role group. It provides administrative access to an entire Exchange organization and can perform almost any task.

If, for some reason, you do not want to provide the account administrative access to your Exchange organization, you need to assign the account to the following role groups in Exchange:

For more details, see Understanding Management Roles.

If the issue persists after updating the Exchange permissions, please, enable tracing of requests sent to Exchange servers, reproduce the issue and send us (support[at]adaxes.com) the log file. For information on how to enable the tracing, have a look at the following help article: https://www.adaxes.com/help/?HowDoI.Per ... uests.html.


Thanks for your response, Adaxes Support.

I have verified that the account is a member of Organization Management in Exchange. Recently we decommissioned a domain controller, and the one stating that there are insufficient permissions is one of the new ones. Could this change of domain controllers also cause this? Since the Adaxes Admin account already is granted Organization Management role within Exchange.

Edit: actually, let me check a few things. It may not be using the admin account to perform this, maybe it's actually using the logged-in user.



Thank you for the provided Exchange Tracing log. According to the log, the error appears when the Add-ADPermissions cmdlet tries to change ACL in AD and Exchange Trusted Subsystem is not granted the "modify permissions" permission by default. For details and resolution, have a look at the following article:
https://support.microsoft.com/en-za/hel ... s-permissi.


Hello Adaxes Support,

That fixed it! Thanks so much for finding that. That was a strange one, and I believe had been working in the past, so somehow the permissions must have gotten changed. Although we're not sure how long ago.


