Impersonation rights are not working in Office 365 Dedicated/ITAR

Symptoms
In Microsoft Office 365 Dedicated/ITAR, a user is a member of one of the following role groups but cannot impersonate Microsoft Exchange users:
  • EWS Impersonation role group in Exchange Server 2010
  • SSA-ApplicationImpersonation baseline role group or another role group that's associated with the SSA_ApplicationImpersonation management role in Exchange Server 2013
Cause
This issue occurs if the custom application is set up incorrectly.
Resolution
To resolve this issue, use EWSEditor to make sure that the roles in the O365 Dedicated/ITAR environment enable Exchange Web Service (EWS) impersonation. To do this, follow these steps:
  1. Download EWSEditor from http://ewseditor.codeplex.com, and then extract the application.
  2. Open EWSEditor.exe.
  3. On the File menu, click New Exchange Service.
  4. By default, this prompts for your SMTP address. Use Autodiscover to determine the correct URL to connect to. If you know the EWS URL, you can clear the Use Autodiscover to get the Exchange Web Services URL check box and then enter the URL manually.
  5. Select the correct version of Exchange or the most recent version if your version isn't listed.
  6. Select the Use the following credentials instead of the default Windows credentials check box, and then enter the account credentials that have impersonation rights. If you logged on to Windows through this account, this step isn't necessary.
  7. Make sure that the Use impersonation to log on to another mailbox using the credentials specified on the credentials tab by identifying the mailbox Id below check box is selected, specify the criteria for the target user, and then click OK.

    A screen shot of the EWS Editor page, selected Exchange version, checked the
  8. You should be prompted by a "Do you want to automatically add the mailbox root to the tree view?" message. Click Yes.

    A screen shot of the EWSEditor prompt
  9. Expand the tree view. If you can see folders or content, impersonation rights are working.
  10. If you receive a "The account does not have permissions to…" error, contact Microsoft Online Services Support by online submission or by telephone.
Properties

Article ID: 2932679 - Last Review: 03/29/2016 03:00:00 - Revision: 3.0

Microsoft Business Productivity Online Dedicated, Microsoft Business Productivity Online Suite Federal

  • vkbportal226 kbgraphxlink KB2932679
Feedback