The SeSecurityPrivilege right keeps getting reset on the Exchange Enterprise Servers group. This stops Exchange talking to AD and the mailstores dismount a shortwhile later. When I run the Policytest tool from the exchange CD it shows "right not found" for each DC. I can easily fix this by running the exchange setup /domainprep switch which adds the right back to the group. But it keeps getting reset and I have to keep running /domainprep.
I can keep checking Policytest during the day and running /domainprep but it's not really a proper solution, and I can't stay there all night either so email can be down in the morning causing major grief.
I've run through MSoft paper ID 314294 http://support.microsoft.com/?id=314294
and switched on security auditing for domain security events in event viewer but cannot find any trace of what they are looking for in the security log.
One clue maybe that I have to run /domainprep on each DC to give it back the right to it's copy of the AD.
So I'm stuck. I know this is a really tricky one but it's driving me mad and any help you can offer would be greatly appreciated!!!
Many thanks for reading this, please help!!!!!!!