We help IT Professionals succeed at work.
Get Started

AD LDAP attribute - assign 'modify' permission

Last Modified: 2013-12-19
Hi all

I have written a script to modify a single LDAP attribute for all users across the domain.  The attribute in question is msExchOmaAdminWirelessEnable.

If i run the script as my domain admin account, it works fine and updates the attribute value as expected.

This script will be running as a scheduled task, so i have created a domain user for this script to run as, and have given 'write' permissions to the attribute in question using ADSIEdit.

But it doesn't work and i can't write the value to the attribute.

If i get out LDP, bind as the user in question, and try and perform a modify operation on the above value, i get [INSUFF_ACCESS_RIGHTS} problem 4003, server error 00002098.

So it seem pretty clear that simply giving write permission to this user account has not had the desired effect...

Can anybody point me in the right direction?

I have assigned this permission by opening ADSI edit as a schema admin, connecting to the Schema partition, finding the entry "CN=ms-Exch-Oma-Admin-Wireless-Enable", Properties, security tab and Add.

User account in question is brand new (yesterday), and a member of the Domain Users group only.

One other thing to note is our AD is parent-child domain - parent domain is basically empty, everything lives in child domain so i am operating on the child domain directory.
Watch Question
Top Expert 2010
This problem has been solved!
Unlock 1 Answer and 7 Comments.
See Answer
Why Experts Exchange?

Experts Exchange always has the answer, or at the least points me in the correct direction! It is like having another employee that is extremely experienced.

Jim Murphy
Programmer at Smart IT Solutions

When asked, what has been your best career decision?

Deciding to stick with EE.

Mohamed Asif
Technical Department Head

Being involved with EE helped me to grow personally and professionally.

Carl Webster
CTP, Sr Infrastructure Consultant
Ask ANY Question

Connect with Certified Experts to gain insight and support on specific technology challenges including:

  • Troubleshooting
  • Research
  • Professional Opinions
Did You Know?

We've partnered with two important charities to provide clean water and computer science education to those who need it most. READ MORE