How to Resolve Event ID 8365 Source MSExchangeAL Exchange 2007

Event: 8365
Agent Time: xxx
Event Time: xxx
Source: MSExchangeAL
Category: Service Control
Username: N/A
Computer: xxx
Description: Could not read the Security Descriptor from the Exchange Server object with guid=CB1C16231B0F914CB33E16879B61AD38. As a result the Proxy Address Calculation RPC interface will not be available on the local Exchange Server.

-------------------------------------------------------------------------------
Microsoft's answer: (http://www.microsoft.com/technet/support/ee/transform.aspx?ProdName=Exchange&ProdVer=8.0&EvtID=8365&EvtSrc=MSExchangeAL&LCID=1033)
Review the System and Application event logs for related events. For example, events that occur immediately before and after this event may provide more information about the root cause of this error.

Open an Exchange Command Shell and execute the following command:

Get-ExchangeServer | fl name,guid (where name is the Exchange server name and guid is the GUID)

This command will match the GUID to the Exchange server name.

Verify that the Exchange server is a member of the Exchange Servers group.

If the Exchange server is a member of the Exchange Servers group, have the domain administrators verify that Active Directory replication is current in the Microsoft Windows site.

If Active Directory replication is up to date, run the tools that Exchange offers to help administrators analyze and troubleshoot their Exchange environment. Open the Toolbox node of the Exchange Management Console to run these tools.
----------------------------------------------------------------------
Our findings:

Install Microsoft Windows 2003 Server Support Tools
execute ADSIEDIT.MSC
Expand Configuration, expand Configuration
(CN=Configuration,DC=domain,DC=com), expand Services, and then expand
Microsoft Exchange.

Expand OrganizationName, expand Administrative Groups, expand
AdministrativeGroupName, and then expand Servers.

Right-click Server Name, and then click Properties.

Click the Security tab, verify that the server object is in the
list of accounts with rights, and then verify that the Allow check box for
Full Control is selected. If this permission is not selected, click to
select the Allow check box for Full Control, and then click OK.

Quit ADSI Edit.

Wait for the change to replicate among the domain controllers.

Start System Attendant.