Solved

Security Rights  disappear

Posted on 2004-09-03
6
200 Views
Last Modified: 2010-04-14
I am currently in the middle of an Exchange 5.5 to 2003
migration and have run into a little problem (if there is
such a thing). I believe it is a W2K AD issue...

Any new rights added for a user will disappear after about
30 minutes.

Details:

Single Exchange site - Single W2K AD domain (native
mode).  NOTE - customer claims domain was in Native Mode
before Exchange 2003 install. I believe it was changed
AFTER.

All ExDeploy tools pass - Exch2003 Domain Prep/Forest Prep
ran OK.

Customer installed Exch2003 server - migrated 4 test
mailboxes successfully.

Mail flow is working correctly both internal and internet.

No errors logged on 5.5 server or 2003 server. DC's have
no events logged either.

I'll give you the exact steps used to add the "send as"
right (this is how I discovered the problem):

Open AD Users and Computers on GC.

Under VIEW select ADVANCED FEATURES (adds security tab to
the properties page).

Open properties sheet for USER1. Select Security tab.
Add USER2 with "Receive As" and "Send As" rights.
Close properties.

The right will take effect and function properly and then
disappear after about 30 minutes.

ANY new user/right disappears after 30 minutes.
It looks like only default permissions remain (all groups
by the way.).
Tried the same with mailboxes that live on the 2003 server
with the same result, but I don't believe this is related
to just mailboxes.

Also tried setting up the ADC as 1-way from Windows to
Exchange just for giggles.
This may be one for the AD guru's!

Thanks All!

SM
0
Comment
Question by:smunicom
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
6 Comments
 
LVL 2

Expert Comment

by:sqwasi
ID: 11976406
smunicom,

Have you tried installing the Exchange 2003 Service Pack 1?  I have had a number of wierd things happen with Exchange 2003 and SP1 seemed to help it.  Also, since your checking on that Service Pack, does your 2KServer have SP4?
0
 

Author Comment

by:smunicom
ID: 11977164
W2K Server is SP4 w/hotfixes.
Exchange 2003 server is SP1. Also applied SP1 to ADC.

I'm heavily leaning toward a hiccup with the ADC connectors...

SM
0
 
LVL 2

Expert Comment

by:sqwasi
ID: 12013433
smunicom,
Did you get this problem solved?  If not I will look into this more.  Let us know.  Thanks.
0
Optimize your web performance

What's in the eBook?
- Full list of reasons for poor performance
- Ultimate measures to speed things up
- Primary web monitoring types
- KPIs you should be monitoring in order to increase your ROI

 

Author Comment

by:smunicom
ID: 12098663
Problem solved.

The users in question were somehow part of the Backup Operators group, which is a protect group in AD. The AdminSDholder object fires off a script to reset all protected groups to a security template every 60 minutes, therefore removing and rights which were manually set on the accounts in question.

I made sure to put this one in my personal notes!

SM
0
 
LVL 2

Expert Comment

by:sqwasi
ID: 12118790
SM,

Thank you for letting us know how you solved that problem.  That is great to hear that you solved it!  Could you please close this question by assiging the points if you think they are deserved.  If not you can just delete the question.  Thank you.
0
 

Accepted Solution

by:
ee_ai_construct earned 0 total points
ID: 12204244
Question answered by asker or dialog valuable.
Closed, 500 points refunded.
ee_ai_construct (replacement part #xm34)
Community Support Admin
0

Featured Post

Get 15 Days FREE Full-Featured Trial

Benefit from a mission critical IT monitoring with Monitis Premium or get it FREE for your entry level monitoring needs.
-Over 200,000 users
-More than 300,000 websites monitored
-Used in 197 countries
-Recommended by 98% of users

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
Compliance and data security require steps be taken to prevent unauthorized users from copying data.  Here's one method to prevent data theft via USB drives (and writable optical media).
Monitoring a network: why having a policy is the best policy? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the enormous benefits of having a policy-based approach when monitoring medium and large networks. Software utilized in this v…
This is my first video review of Microsoft Bookings, I will be doing a part two with a bit more information, but wanted to get this out to you folks.

632 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question