Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations TouchToneTommy on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Remove non-existing user account Exchange 2k3

Status
Not open for further replies.

vostok1

MIS
Feb 15, 2005
50
US
Exchange 2k3 Enterprise running on 2k3 Server, DC
Domain: Three DCs: two 2k3 DCs and one 2000 DC


I have an event in the Event Viewer that pops up sometimes up to several times in an hour throughout the business day:

Logon Failure on database "First Storage Group\Mailbox Store (MAIL2)" - Windows 2000 account NT AUTHORITY\SYSTEM; mailbox /o=ICC TEST/ou=First Administrative Group/cn=Recipients/cn=Stephanie.
Error: -2147221231


The following warning keeps on popping up too:

Disabled user /o=ICC TEST/ou=First Administrative Group/cn=Recipients/cn=Stephanie does not have a master account SID. Please use Active Directory MMC to set an active account as this user's master account.

This user "Stephanie" hasn't worked for this organization for at least 6 months. The account has been deleted (not sure how) and can't be seen in Active Directory. It can't be seen in AD MMC, neither it does show up when i run dsquery user. How do I go about removing it completely, so the errors stop happening?

Answer kindly appreciated.
 
The quicka nd dirty way, if it works:
Create Stephanie in AD. Then connect the 'old' mailbox to the account. When AD has settled, remove the account in the proper way.

If that does not work, repost, we'll tackle the long way.

Marc
If 'something' 'somewhere' gives 'some' error, expect random guesses or no replies at all.
Free Tip: The F1 Key does NOT destroy your PC!
 
Thanks Marc for the answer. I'm leaving home now and will take a look at it tomorrow morning.

However, there is no "old" mailbox I believe, for everything was deleted: the user account and the mailbox. At least I do not see the mailbox in System Manager. Did you possibly mean to recreate the account and setup a new mailbox?
 
You can create the account without a mailbox. It's not because you don't see it, that some setting is not still floating around, as you errors indicate. The mailbox does not need to work or anything, as long as you can associate it with the account, the errors should go away after you remove the account the proper way.

Marc
If 'something' 'somewhere' gives 'some' error, expect random guesses or no replies at all.
Free Tip: The F1 Key does NOT destroy your PC!
 
The NoMas tool should go through the AD and fix these. I read there is a hotfix out, but I haven't seen it yet. NoMas always fixed this for me.

Pat Richard, MCSE(2) MCSA:Messaging, CNA(2)
 
I'm sorry for getting back late on the issue: it's been little hectic here.

Marc: I created a new "Stephanie" account in AD without a mailbox but am not sure how to associate it with a mailbox I can't see. Also, the account was given another SID, so neither of the messages disappeared. Please let me know if you had other suggestions.

Pat: I believe the right utility for the job will be NoMas.exe. I read a few articles about it, and it seems to be the perfect removal tool for a "strayed" individual account. The only caveat is that it is relatively tedious to obtain it, for I couldn't find a download on the Internet.

Thanks very much again - I will have to contact Microsoft with the KB number to be able to download the tool.
 
See also:

If you still have troubles, please post the EVENT ID and details, ALL of them!


Marc
If 'something' 'somewhere' gives 'some' error, expect random guesses or no replies at all.
Free Tip: The F1 Key does NOT destroy your PC!
 
Marc: thanks. I probably didn't describe the issue clearly enough.

Pat: Thanks for the advise. Instead of calling Microsoft, I used a script version (nomas.vbs) of Nomas.exe, and it did the job.

I found the script on Technet and am pasting it here in case somebody else would need it. It has to be placed in the Exchange /bin directory:

 
In order to get nomas, you have to call PSS and reference kb 555410

That tool will give you the option of applying it to a single OU, or more. You can also see which user accounts it will affect before actually making the change, and you can apply it against both inactive and active users.

Pat Richard, MCSE(2) MCSA:Messaging, CNA(2)
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top