Permissions for restore into mailbox from Enterprise Vault Search
Hello together,
we are facing a problem with the restore into the mailbox from the Enterprise Vault Search and also from the old search applications with delegated access to the mailbox.
Which permissions do we need to restore items from an archive to the original mailbox or to a selected folder?
We set the following permissions on ToiS: contributor and on inbox: editor.
When trying to restore from the search we get the error messsage that the restore failed. EV eventlog shows Event ID 2778, 5211 and 41480
ID 2278 "The error c0041801 occurred whilst calling the method CArchivingAgentQueue::RestoreItemV35"
ID 5211 "Failed to restore an item from the Web Application"
ID 41480 "The User domain\user attempted to restore following item(s) into mailbox user@domain.com - Restore Operation Status: 1 Failed SSIDs"
Dtrace shows:
{CClientIdentity::CheckAccess:#738} User domain\user does not have permissions (Read) to Archive [Name = ArchiveName VaultId = <VaultID>]
-When setting read permissions in the vac the user with delegated access is able to restore items.
-Synchronize folder permissions is set to on
I found Technote http://www.veritas.com/docs/000016114 which states that the user will need Full Mailbox access to restore items.
-I am a bit confused about this.
-The above constellation was working with EV9 and is not working any longer with EV10 and 11
-I was able to reproduce the "problem" in my lab with EV10 and EV11 and the permissions I mentioned above
based on the technote you found, it looks like Veritas changed the security requirements from version to version.
"User A requires explicit full mailbox rights to User B in order to run a restore of messages to the mailbox using Enterprise Vault restore methods. Note: Security has been tightened starting in 8.0 SP3 that the vault service account will no longer be able to restore items to anyone's mailbox by design. The restoring user now needs explicit rights to the destination mailbox and permissions to the archive from which the item is being restored."