03-26-2014 08:45 AM
Have event log producing event id 4216.
I have changed VSA account password and submitted the new account info to the site properties / service log on / and task log on
but still the error occurs and synchronizing won't work...
from dtrace log:
15890 17:06:58.353 [11248] (TaskController) <13412> EV:L {CSecurityWrapper::HasServerClientGotPermission:#515} Checking role access for admin operation [4001]...
15891 17:06:58.353 [11248] (TaskController) <13412> EV:L {CSecurityWrapper::IsServerClientTheVSA:#864} Checking if server client is VSA...
15892 17:06:58.353 [11248] (TaskController) <13412> EV:L {CSecurityWrapper::IsServerClientTheVSA:#894} Client server is running as VSA: [False] (in a client COM call: [True]).
15893 17:06:58.353 [11248] (TaskController) <13412> EV:L {CSecurityWrapper::CommonRoleAccessCheck:#920} Checking access for operation [4001]. Impersonating client: [True]...
15894 17:06:58.353 [11248] (TaskController) <13412> EV:L {CSecurityWrapper::UpdateAzStoreCacheIfNecessary:#1455} Updating if required...
15895 17:06:58.353 [11248] (TaskController) <13412> EV:M {CSecurityWrapper::CommonRoleAccessCheck:#997} Access [denied]
15896 17:06:58.353 [11248] (TaskController) <13412> EV:L {CSecurityWrapper::HasServerClientGotPermission:#557} Caller [doesn't have] role [4001]. Permission [denied].
15897 17:06:58.353 [11248] (TaskController) <13412> EV:L {CSecurityWrapper::GetOperationNameFromID:#656} Getting name of operation [4001]...
15898 17:06:58.353 [11248] (TaskController) <13412> EV:M {CSecurityWrapper::ServerClientCheckPermissions:#1567} Operation [Can query Enterprise Vault tasks (4001)] has been denied.
15899 17:06:58.353 [11248] (TaskController) <13412> EV:L {CSecurityWrapper::HasServerClientGotPermission:#515} Checking role access for admin operation [48]...
15900 17:06:58.353 [11248] (TaskController) <13412> EV:L {CSecurityWrapper::IsServerClientTheVSA:#864} Checking if server client is VSA...
15901 17:06:58.353 [11248] (TaskController) <13412> EV:L {CSecurityWrapper::IsServerClientTheVSA:#894} Client server is running as VSA: [False] (in a client COM call: [True]).
15902 17:06:58.353 [11248] (TaskController) <13412> EV:L {CSecurityWrapper::CommonRoleAccessCheck:#920} Checking access for operation [48]. Impersonating client: [True]...
15903 17:06:58.353 [11248] (TaskController) <13412> EV:L {CSecurityWrapper::UpdateAzStoreCacheIfNecessary:#1455} Updating if required...
15904 17:06:58.353 [11248] (TaskController) <13412> EV:M {CSecurityWrapper::CommonRoleAccessCheck:#997} Access [denied]
15905 17:06:58.353 [11248] (TaskController) <13412> EV:L {CSecurityWrapper::HasServerClientGotPermission:#557} Caller [doesn't have] role [48]. Permission [denied].
15906 17:06:58.353 [11248] (TaskController) <13412> EV:L {CSecurityWrapper::GetOperationNameFromID:#656} Getting name of operation [48]...
15907 17:06:58.353 [11248] (TaskController) <13412> EV:M {CSecurityWrapper::ServerClientCheckPermissions:#1567} Operation [Can manage Enterprise Vault Exchange Mailbox tasks (48)] has been denied.
15908 17:06:58.353 [11248] (TaskController) <13412> EV~W Event ID: 4216 Access denied. User is not in a role that allows 'Can manage Enterprise Vault Exchange Mailbox tasks'.|User: 'NT AUTHORITY\SYSTEM'| |
15911 17:06:58.774 [11248] (TaskController) <16528> EV:L {CTaskControl::SynchRetrievalTask} (Entry)
Does anyone have more ideas how to solve this problem?
EV version 10.0.4 on a clustered Windows Server 2008 R2, Service Pack 1 environmeant.
exchange version 2007
Sani B.
03-26-2014 08:53 AM
Have you failed over the cluster to see if it is something specific to the current node? Have you restarted the services on each node, and ensure the new password is used?
I can't be sure though about clusters, it's been a long time....
03-26-2014 09:00 AM
Yes done multiple times over all sorts of restartings and node switching and made sure the systemmailboxes are as they should and VSA still has the permissions etc....