LDAP Query against local administrators on a computer in a domain

     I am trying to use admodify.net to remove the local administrators group on a server (not a DC) called j-f-mmas1 from the access list on another users email account.  (There is a deny permission present which is causing grief and by removing that servers administrator group from the mailbox rights list altogether I would remove the deny permission.)  
      I can get the ldap listing for the computer itself, but admodify does not go further than that.  There is an option for a specific ldap query but I am not sure what variables would be used against the local administrators on a server within the domain.  Again I am trying to do this against the ADMINSTRATOR GROUP on that server, not the administrator itself.
     PS - Since these rights are under the advanced exchange setting of mailbox rights it is not present under the security tab and it can not be reached by adsiedit.  These rights are inherited but going up the list in AD or in RUS or ESM has yielded NO parent source.
     Thank you.


sfeder11554Asked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

zelron22Commented:
You can't give access to a mailbox or any other domain resource using a local group or user.  Local users and groups can only be given access to local resources, meaning on that machine.

Can you give us a screen print of where you're seeing these permissions?

0
zelron22Commented:
You might find what you're looking for in AD Users and Computers.  Right click on Microsoft Exchange Security Groups (or Microsoft Exchange System Objects) in the tree and get properties and look at the security tab.  If you see the group you're looking for in there (and it may be a domain local group, but it wouldn't be a machine local group) you can either change the permissions there or, if you click on the advanced button, see where it's inherited from.

You may need to go all the way up to the root of the domain and get security properties there.  Make sure you document any changes you make in case you need to reverse them.
0
sfeder11554Author Commented:
Good Idea - Picture is worth a thousand words - fourth item down.
j-f-mmas-deny.pdf
0
zelron22Commented:
What object are these the security permissions for?

You see it's inherited from the parent item.  You have to keep going up the tree to see where it actually gets that permission from.
0
sfeder11554Author Commented:
I WOULD DELETE THIS QUESTION BUT THE SITE WON'T LET ME - THERE IS NO ANSWER OR METHOD TO DO THIS - THERE IS NOTHING IN THE TREE ABOVE - ULTIMATELY WHAT HAPPENED WAS THAT THE DENY PERMISSION DISAPPEARED FOR SOME UNKNOWN REASON AND THEN I SPECIFICALLY GRANTED ACCESS.  NOW IF YOU WOULD BE SO KIND AS TO REMOVE THE BLOCK FROM MY ASKING A QUESTION - WHICH I HAVE BEEN PAYING FOR EVERY MONTH AND USING SO INFREQUENTLY I WOULD GREATLY APPRECIATE IT.  UNFORTUNATELY MY QUESTIONS ARE OFTEN THE MOST ONEROUS ONES AND WHILE SOMETIMES THERE ARE RESOLUTIONS PRESENTED - AND I GRANT THEM WHEN THEY DO WORK - IT DOESN'T HAPPEN EVERY TIME.  WHEN I TRY TO DELETE THE QUESTION WITH AN EXPLANATION YOUR SUBMIT BUTTON DOESN'T WORK.
DOES ANYONE HAVE A RESOLUTION FOR THAT PROBLEM???
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Databases

From novice to tech pro — start learning today.