Include inheritable permissions continually being removed - causing problems with ActiveSync in Exchange 2010 SP1
Posted on 2010-11-24
Migrating away from SBS 2003 to Exchange 2010 and Server 2008. Select users are not able to set up ActiveSync or are having problems afterwards.
- Company has outgrown SBS 2003 and we are migrating them to Exchange 2010sp1 and AD 2008.
- No problems with iPhone syncing to exchange 2003
- unable to get iPhones to setup activesync to exchange 2010
- found that the users with problems were members of the restricted groups affected by adminSDHolder
- SBS 2003 server is still in place as we have not finished migrating all items yet (close though)
- removed users from restricted groups
- checked the "include inheritable permissions from this object's parent"
- used adsiedit.msc to set adminCount to 0 (zero) and also tried <not set>
Worked great...at first. Started getting complaints that people who didn't immediately set up their phone were having problems. Also, people who did set up their phone immediately were no longer able to "push sync."
Took a look at the checkbox for inherit and it was unchecked again for the users with problems. Ran through the steps listed above to verify that we didn't miss anything. adminCount is still at 0/<not set>, triple checked the list of restricted groups, etc...
Yet the inherit rights checkbox is getting unchecked from time to time.
Looking through EE and through Blackberry forums (where we first ran into this problem a long time ago) has not given any insight to the problem beyond the steps we have already tried.