Solved

SBS 2003 resets inheritance of security entries from OU to User records.

Posted on 2006-06-21
3
492 Views
Last Modified: 2010-04-19
I'm trying to workaround SendAs permissions problem introduced by the last Exchange patch on our SBS 2003.

It affects Research in Motion BlackBerry Enterprise Server (BES) and other simmilar systems.

Recomendation in MS KB 912918 was to add service account additional rights to OU container for the users that needs BES service, but the problem is that SBS seems to periodically dissable the "Allow inheritable permissions from the parent to propagate to this object and all child objects. Include this with entities explicitly defined here." in AD Users and Computers MCC.

This reset happens every few hours.

Do you know how to dissable this reset?

regards, nejc
 
0
Comment
Question by:JernejS
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 74

Accepted Solution

by:
Jeffrey Kane - TechSoEasy earned 250 total points
ID: 16955385
Are yo uusing the default OU?  \MyBusiness\Users\SBSUsers  ??

If not you need to be.  Please see http://sbsurl.com/itpro for an overview of this.

So, therefore you should be modifying the SendAs permission on the SBSUsers container, or if you just want a sub-group to have this permission, you need to create a SECURITY GROUP in the Security Groups OU and put the permission on the new Security Group.  You would then join any users that need this to the security group, or what would be easier is to add the security group to the Mobile User's template and then just reapply that template to the affected users with the "Change User Permissions" wizard.  This will ensure that any users you add in the future get this setting correctly.

Jeff
TechSoEasy

0
 
LVL 1

Author Comment

by:JernejS
ID: 16957594
Jeff,

thanks for your quick answer, the idea with new security group is great, modifying Mobile Template is even better...

Works fine now.

Regards,

Nejc
0
 
LVL 74

Expert Comment

by:Jeffrey Kane - TechSoEasy
ID: 16967756
Terrific!  Glad you got it working... If you've ever worked with AD before and are used to creating OUs for everything, it can be difficult to grasp SBS's concepts... but once you do, as you have, it's obvious that these things work well.  Especially considering you have to make sure that everything is set in so many places if you don't use the tools provided!  :-)

Jeff
TechSoEasy
0

Featured Post

Webinar: Aligning, Automating, Winning

Join Dan Russo, Senior Manager of Operations Intelligence, for an in-depth discussion on how Dealertrack, leading provider of integrated digital solutions for the automotive industry, transformed their DevOps processes to increase collaboration and move with greater velocity.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Restore a single mailbox Exchange 2007 3 71
SBS 2011 6 56
WSUS 3.0 SP2 Replicate to WSUS 2016 3 106
aes256 Ransomware on SBS 2011 13 75
Written by Glen Knight (demazter) as part of a series of how-to articles. Introduction One of the biggest consumers of disk space with Small Business Server 2008(SBS) is Windows Server Update Services, more affectionately known as WSUS. For t…
The SBS 2011 release date (RTM) is supposed to be around Christmas, 2011.  This article is a compilation of my notes -- things I have learned first hand.  The items are in a rather random order, but I think this list covers most of what is new and d…
Finds all prime numbers in a range requested and places them in a public primes() array. I've demostrated a template size of 30 (2 * 3 * 5) but larger templates can be built such 210  (2 * 3 * 5 * 7) or 2310  (2 * 3 * 5 * 7 * 11). The larger templa…

739 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question