Fix Permission Errors When Adding an Email Alias for a New Domain
Question details
The user is encountering a permission error when attempting to add an email alias for a newly configured domain.

- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- Adding an email alias to a user account for a new domain in an administrative environment.
- Observed behavior
- The system fails to add the alias, throwing an error that the source server lacks write permission to the target domain controller and that the user has insufficient access rights.
Ensure you are logged in with Global Administrator or Exchange Administrator credentials, and verify that your new domain's DNS records have fully propagated and show a 'Healthy' status in the admin center.
Verify Directory Synchronization and Administrator Permissions
Fix permission errors by ensuring the domain is fully configured and the local directory synchronization service has write access to the target domain controller.
In hybrid environments, errors stating "insufficient access rights" often occur because the on-premises Active Directory (AD DS) Connector account lacks the necessary permissions to update user attributes in Azure AD or the local domain.
Log into the Microsoft 365 admin center as a Global Administrator. Navigate to Settings > Domains and ensure the new domain is marked as 'Healthy'.
If you are using Azure AD Connect, open the Synchronization Service Manager on your local server and check the operations log for export errors related to the user object.
Open Active Directory Users and Computers. Ensure the AD DS Connector account has been granted 'Read' and 'Write' permissions for the 'proxyAddresses' attribute on the target user objects or organizational unit.
Open an elevated PowerShell prompt on your Azure AD Connect server and run 'Start-ADSyncSyncCycle -PolicyType Delta' to force synchronization. Try adding the alias again once the sync completes.

Escalate to Microsoft 365 Support
Contact Microsoft Support if permissions are correctly configured but backend synchronization errors continue to block alias creation.
Looking for a hassle-free Office suite? Try WPS Office
While you manage complex domain setups and server configurations in Microsoft 365, you and your users still need a reliable, daily productivity suite. WPS Office is a lightweight, free alternative to Microsoft Office that offers full compatibility without the complex account management overhead.

Frequently Asked Questions
Why do I get an 'insufficient access rights' error when adding an email alias?
This error typically occurs in hybrid directory setups. It means the account attempting to make the change (often the Azure AD Connect service account) lacks the required write permissions in your on-premises Active Directory to update the user's proxy addresses.
How long does it take for a new domain to fully sync in Microsoft 365?
After adding and verifying a new domain's DNS records, it can take anywhere from a few minutes up to 24 hours for the domain status to fully propagate and allow alias creation globally.
Can I add an email alias if the new domain is not fully verified?
No, Microsoft 365 requires the domain to be completely verified and set up in the Domains section before you can assign any email aliases associated with that domain to your users.
How many email aliases can a single user have in Microsoft 365?
You can add up to 400 email aliases to a single Microsoft 365 user account. Adding aliases does not require purchasing additional licenses.




