Exchange 2010 Domain Admin Group Member cant do Email Push / ActiveSync Error 0x80072F7D

deibel
deibel used Ask the Experts™
on
Hi

as i wrote in my thread
http://www.experts-exchange.com/Software/Server_Software/Email_Servers/Exchange/Q_25088868.html 
exchange push doesent work with user that are member of the domain admin group.

so i removed the user from the domain admin group but the error is still there for the user. what is different from a user that has already been in a domain admin group and one who was not?

Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Awarded 2009
Top Expert 2010
Commented:
If a user has already been a member of any Built In Group then there does appear to be problems with ActiveSync.

To fix this in Active Directory users and computers click View and select advanced Features, then find the user, right click and select properties, under the security tab click the Advanced button and put a check in the inherit permissions check box.

Click Apply and then you should be able to use ActiveSync.

Author

Commented:
i tried it out but it didnt work then i used the button default settings and afther that it worked
From what I can tell, if the user has been a domain admin in the past this still won't work. The way I have fixed this problem in the past is do do the following

1) Demote the user so the account isn't a domain admin account
2) Disable activesync for the user through the exchange 2010 MC (check the Mailbox Features tab of the Exchange Management Console)
3) Try to sync the the user (should fail) (you can use testexchangeconnectivity.com to do this)
4) Open up adsi edit from a domain controller or exchange server and reset the "admin count" from 1 to 0 for the user (right click on the CN=xxx entity usually under CN=Users once you attach to your AD).
5) Check the "Allow inheritable permissions form the parent to propagate to this object and all child object. Include thse with entries explicitly defined here" checkbox from the advanced button on the security tab from the properties of the user account in Active Directory users and computers
6) Reenable activesync for the user through the exchange 2010 MC (check the Mailbox Features tab of the Exchange Management Console)

7) Try to sync the the user again (should now work)


Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial