Solved

disabling users in active directory then enabling removes permissions

Posted on 2006-06-19
2
237 Views
Last Modified: 2010-03-06
In the past, we have created a new user w/in AD and associating a mailbox on the exchange server & giving these accounts a typical password.  Well,  the new users are no longer contacting the IT department to get them up and running; other users are telling them what the initial password is.

What we have been doing is creating the user in AD + the mailbox - we send a welcome email to the user which then populates access rights (through a group policy) and then disabling the account.  We thought this was a good idea, since the password has become so "known".  The problem seems to be, once the account is created and all the necessary groups and permissions are in place and we disable it....once the employee begins and the account is enabled, it appears all group membership has disappeared along w/the access rights to the mailbox, so the mailbox is rejecting messages.  So, the mailbox has had to be deleted then recreated and all is fine and dandy.

I know we  can just change the initial password and not disable the account, and once the initial pw becomes "known" we can just change it again.  But, I'd like to find out why creating -> disabling -> enabling is messing up the configuration of the user.

Our security admin will not allow us to keep a record of user passwords - the initial passwords in a spreadsheet (he says it's a security risk - so that's out the window).  Any thoughts?
0
Comment
Question by:mdmcq5
2 Comments
 
LVL 13

Accepted Solution

by:
hstiles earned 250 total points
ID: 16935470
it isn't messing up the configuration, but I believe it is a common experiemnce for it to take an hour or more for the exchaneg attributes to propagate back to the user.  We no longer disable accounts as soon as a user leaves, but change the password, remove any remote access rights and leave it like that for a few weeks before exmerging their mailbox to a PST, moving home directory files and deleting account.
0
 

Author Comment

by:mdmcq5
ID: 16935797
We do the same for when a user leaves.

So, you're saying, when a user is disabled and then re-enabled, it will take an hour for the account info (including group membership & mailbox access) to propagate & become usable?
0

Featured Post

Are end users causing IT problems again?

You’ve taken the time to design and update all your end user’s email signatures, only to find out they’re messing up the HTML, changing the font and ruining the imagery. What can you do to prevent this? Find out how you can save your signatures from end users today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Exchange 2016 Setup - Incomplete installation - then it just hangs at 0% 36 71
exchange, outlook 8 54
OUTLOOK, KERBERO, NTLM 1 26
exchange, 2 15
We are happy to announce a brand new addition to our line of acclaimed email signature management products – CodeTwo Email Signatures for Office 365.
Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
In this video we show how to create a Shared Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Sha…
In this Micro Video tutorial you will learn the basics about Database Availability Groups and How to configure one using a live Exchange Server Environment. The video tutorial explains the basics of the Exchange server Database Availability grou…

914 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now