Some AD permissions are not fully migrated from source to target. Accounts that have access to mailboxes in the source other than their own do not have this access on the target. An example would be the Send As/Receive As access.
Skipping of NtSecurityDescriptor and msExchMailboxSecurityDescriptor attributes during Directory Synchronization or Migration will prevent some AD permissions from being fully synchronized. Security Descriptor migration rule setting also affects how QMM treats these attributes. Please see an explanation below for more details on QMM behavior in each corresponding scenario.