?
Solved

Security Permissions keep disappearing!!!

Posted on 2006-11-10
6
Medium Priority
?
2,070 Views
Last Modified: 2012-06-27
Dont know whether this is the right place but here goes:

We have a 2000 domain with some 2003 servers in it as well. We have just installed a 2003 Exchange Ent Cluster which is working fine, however, it had SP2 installed and affected our Blackberry Server. We applied the SP2 hotfix and followed the instructions from the knowledge base and all seemed fine. Now we have tried to add another blackberry to the server and one of the actions is in the user profile in AD it to grant BES admin permissions to send as and receive as in the Security option. This is fine and the permissions are there and the blackberry works but after about 20 mins the permissions "disappear" and the blackberry is unable to send but can receive. I have changed it again and again and replicate but it still keeps happening and I dont know why it keeps losing the permissions. There are 3 DC on W2K Sever with all relevant patches etc applied. All the other blackberry's are working fine so I am at a loss. We have create a new user and that does the same thing. Does anyone have any idea why this is happening and what can be done to fix it?
0
Comment
Question by:goldsmithwilliams
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
6 Comments
 
LVL 85

Expert Comment

by:oBdA
ID: 17913242
This user is (or has been at one point) member of a "protected group" (Administrators, Account Operators, Server Operators, Print Operators, Backup Operators, Domain Admins, Schema Admins, Enterprise Admins, Cert Publishers); check here for details:
The "Send As" right is removed from a user object after you configure the "Send As" right in the Active Directory Users and Computers snap-in in Exchange Server
http://support.microsoft.com/?kbid=907434

Delegated permissions are not available and inheritance is automatically disabled
http://support.microsoft.com/?kbid=817433

AdminSDHolder Thread Affects Transitive Members of Distribution Groups
http://support.microsoft.com/?kbid=318180

Security tab of the adminSDHolder object does not display all properties
http://support.microsoft.com/?kbid=301188
0
 

Author Comment

by:goldsmithwilliams
ID: 17913302
While the send as etc is removed, should it remove the user from the list. I have removed users from the list which no longer exist (they being with S then a number) and added the BES admin user. After 20 mins or so the BESAdmin user disappears the users beginning S-xxx which no longer exist and were deleted reappear.
0
 
LVL 85

Expert Comment

by:oBdA
ID: 17913816
Which "list" are you referring to?
0
Get 15 Days FREE Full-Featured Trial

Benefit from a mission critical IT monitoring with Monitis Premium or get it FREE for your entry level monitoring needs.
-Over 200,000 users
-More than 300,000 websites monitored
-Used in 197 countries
-Recommended by 98% of users

 

Author Comment

by:goldsmithwilliams
ID: 17913843
The user profile in Active Director and the security tab when you add group or username access. I think what might be happening is permissions are not being inherited and overriden but thats just a thought.
0
 
LVL 85

Accepted Solution

by:
oBdA earned 1200 total points
ID: 17913891
Then it seems like someone changed the properties of the adminsdholder object (iirc, it's described in one of the articles above), and added the (now deleted) users; if a user is deleted, it remains still in the ACLs of any resource where it had permissions.
0
 
LVL 19

Expert Comment

by:bevhost
ID: 23494467
On our server Power Users were part of the Print Operators Group.
SO, Power Users were also having the BESAdmin group removed.

I also read that the exchange message store must be restarted before or wait two hours for the cache to be discarded before the user could send.  I guess I'll know in two hours. (and by then I'll be offsite not returning for 5 days)

See also
http://support.microsoft.com/kb/912918
Users cannot send e-mail messages from a mobile device or from a shared mailbox in Exchange 2000 Server and in Exchange Server 2003
0

Featured Post

The Eight Noble Truths of Backup and Recovery

How can IT departments tackle the challenges of a Big Data world? This white paper provides a roadmap to success and helps companies ensure that all their data is safe and secure, no matter if it resides on-premise with physical or virtual machines or in the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
In the absence of a fully-fledged GPO Management product like AGPM, the script in this article will provide you with a simple way to watch the domain (or a select OU) for GPOs changes and automatically take backups when policies are added, removed o…
Have you created a query with information for a calendar? ... and then, abra-cadabra, the calendar is done?! I am going to show you how to make that happen. Visualize your data!  ... really see it To use the code to create a calendar from a q…
In this video, Percona Director of Solution Engineering Jon Tobin discusses the function and features of Percona Server for MongoDB. How Percona can help Percona can help you determine if Percona Server for MongoDB is the right solution for …
Suggested Courses

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question