Access Denied 0x8007005 error on manual archive ...
Hello,
Since yesterday, some (about 50%) of our users are getting an access denied/0x8007005 error when they try to manually archive or restore any message in their Outlook mailbox. For other users, it works completely as normal.
However, the automatic archiving works normally, as does vault searching and the vault explorer. Archiving via OWA works for all users and if we use the http-only light client that works.
We have checked that DCOM is enabled on both the clients and server. The EV server names are listed in Internet Explorer.
We have the same AD domain, Windows XP/Outlook 2003, Exchange 2003 and Enterprise Vault 9.0 SP4 (one cluster) environment for all users.
The logs on the server show no errors at all. For the problem users, the client shows an error mentioning the word "CreateDirectory" when we try to manually restore and a non-descript informational message when we try to manually archive.
Any ideas please?
Thanks,
- Alan.
Comments 11 Comments • Jump to latest comment
It would be better if you attach Outlook Enterprise Vault Add-in logs. Please ensure you have log level set to MAXIMUM and Virtual Vault checkbox set if VV is enabled for user.
Steps to collect logs
1) Press Ctrl + Shift and click on any of enterprise vault icon
2) Set setting to collect maximum log
3) Restart outlook
4) Press Ctrl + Shift and now press open log
Thanks.
No cached mode/no virtual vault.
Fyi also checked that the DCOM settings in the local security policy are still "not defined" ie they haven't been changed.
Here's the client log (my server names removed for security):
What happens if you upgrade the client to be 9 SP4 as well?
It may be worth just doing a reset of the password on the ev account to refresh all the dcom packages and such and then restart the services
Also could be firewall related
Just as a matter of interest does it prompt them for credentials?
Wondering whether it could be cached username/password in the servers list or NTFS premissions on the \Enterprise Vault install directory
Nope, doesn't prompt for anything just gives access denied.
They can open previously-archived items without any prompts too, as usual.
old items open ok but newer ones don't?!
Just as a matter of interest, do you include links to the original email as part of the banner?
If you get an old one that opens and a new one that doesnt, are those links almost the same except for the URL?
Wondering if maybe its a URL issue or something like that
Thanks but let's do a reset.
There is only one issue here: in Outlook, some of my users can't manually archive items or restore previously archived items. They get an "access denied" error when they try.
EVERYTHING else in EV works for them. That even includes manually archiving items or restoring items using OWA as a client instead of Outlook.
The rest of my users have no problems manually archiving or restoring items in either Outlook or OWA.
Fair play
Then what i would do is the following
1. Upgrade the client from 8 SP3 to 9 SP4
2. run a ScanOST.exe against the mailbox and have it repair any errors
3. See if the issue still occurs and run a resetevclient.exe
4. If the issue still occurs, reset the password on the VAC
If it still fails then you will have to dtrace AgentClientBroker and AuthServer to see where the failures are occuring, if its a DCOM issue you will receive an error on the EV Servers System Logs under Distributed COM
It could be an SPN issue, a kerberos issue etc
another thing you could try is setting the users to HTTP mode and see if it works there, if it does then you can concentrate on the DCOM side of things
Some feedback:
0. I think the problem affects all our users. They just haven't noticed yet.
2. We run Outlook in online mode only so there's no offline files to scan.
3. Already tried ResetEvClient to no avail.
5. Archiving in OWA works so running the client in http mode works too. So DCOM is the issue?
Will check (1) on your list later. Not doing (4).
One very strange thing: the users who have problems manually archiving items in their own mailboxes can manually archive items in other mailboxes to which they have delegate access!
Thanks.
Whats wrong with #4? its a fairly common troubleshooting procedure and will ensure that all dcom packages across all servers are correct etc
Really though would need to see a dtrace of agentclientbroker and authserver
Oh and the reason it works for delegate access is because when you go in to a shared mailbox or public folder, it switches to HTTP and does not use DCOM
Found the problem. The DCOM Machine Launch Permissions had been changed. Put them back and it works fine again. Phew.
Thanks for your pointers. Much appreciated.
Would you like to reply?
Login or Register to post your comment.