logo
search
Microsoft Account Errors

Fix Permission Errors When Adding an Email Alias for a New Domain

Partner EditorPartner Editor Oct 9, 2026 869 views

Question details

The user is encountering a permission error when attempting to add an email alias for a newly configured domain.

Fix Permission Errors When Adding an Email Alias for a New Domain
Product
Microsoft 365
Device & OS
not provided
Scenario
Adding an email alias to a user account for a new domain in an administrative environment.
Observed behavior
The system fails to add the alias, throwing an error that the source server lacks write permission to the target domain controller and that the user has insufficient access rights.
Before you start

Ensure you are logged in with Global Administrator or Exchange Administrator credentials, and verify that your new domain's DNS records have fully propagated and show a 'Healthy' status in the admin center.

Solution 1Recommended

Verify Directory Synchronization and Administrator Permissions

Fix permission errors by ensuring the domain is fully configured and the local directory synchronization service has write access to the target domain controller.

In hybrid environments, errors stating "insufficient access rights" often occur because the on-premises Active Directory (AD DS) Connector account lacks the necessary permissions to update user attributes in Azure AD or the local domain.

1
Check domain health

Log into the Microsoft 365 admin center as a Global Administrator. Navigate to Settings > Domains and ensure the new domain is marked as 'Healthy'.

2
Review synchronization logs

If you are using Azure AD Connect, open the Synchronization Service Manager on your local server and check the operations log for export errors related to the user object.

3
Grant write permissions

Open Active Directory Users and Computers. Ensure the AD DS Connector account has been granted 'Read' and 'Write' permissions for the 'proxyAddresses' attribute on the target user objects or organizational unit.

4
Force a delta sync

Open an elevated PowerShell prompt on your Azure AD Connect server and run 'Start-ADSyncSyncCycle -PolicyType Delta' to force synchronization. Try adding the alias again once the sync completes.

Verify Directory Synchronization and Administrator Permissions
Hybrid Environment Note: If your environment uses on-premises Exchange, you must add the alias via your local Exchange Admin Center or Active Directory rather than directly in the Microsoft 365 cloud portal.
Free Microsoft Office alternative

Looking for a hassle-free Office suite? Try WPS Office

While you manage complex domain setups and server configurations in Microsoft 365, you and your users still need a reliable, daily productivity suite. WPS Office is a lightweight, free alternative to Microsoft Office that offers full compatibility without the complex account management overhead.

Completely free to download and use for everyday document processing.Seamlessly compatible with Microsoft Office formats like .docx, .xlsx, and .pptx.Lightweight installation with extremely low system resource consumption.Familiar, intuitive user interface that requires zero learning curve for new users.Built-in robust PDF editing tools for easy document conversions and annotations.
microsoft office alternative - wps office

Frequently Asked Questions

Why do I get an 'insufficient access rights' error when adding an email alias?

This error typically occurs in hybrid directory setups. It means the account attempting to make the change (often the Azure AD Connect service account) lacks the required write permissions in your on-premises Active Directory to update the user's proxy addresses.

How long does it take for a new domain to fully sync in Microsoft 365?

After adding and verifying a new domain's DNS records, it can take anywhere from a few minutes up to 24 hours for the domain status to fully propagate and allow alias creation globally.

Can I add an email alias if the new domain is not fully verified?

No, Microsoft 365 requires the domain to be completely verified and set up in the Domains section before you can assign any email aliases associated with that domain to your users.

How many email aliases can a single user have in Microsoft 365?

You can add up to 400 email aliases to a single Microsoft 365 user account. Adding aliases does not require purchasing additional licenses.