Solved

Owners cannot change Distribution Group Members

Posted on 2013-05-15
3
683 Views
Last Modified: 2013-05-21
I have many, many users that cannot change members of their distribution groups through the GAL.
The check box for "Manager can update membership list" is checked in Active Directory.
The security permissions also show that the user has "write members" selected as a property and no denies.
If given access to the Active Directory Users and Computers MMC, the user (logged in as them) can change the membership list. It only appears that it will not work when the users try changing them in the GAL.
Any ideas at all?
0
Comment
Question by:tcole333
  • 2
3 Comments
 

Expert Comment

by:manikandadevan
ID: 39170691
Hi,
I personally would do this with RBAC and create a custom role group. I would recommend placing your distribution groups in certain OU's and set your scope to OU. The one thing I love about RBAC is that it can get as granular as you would like to.
0
 

Accepted Solution

by:
tcole333 earned 0 total points
ID: 39173562
Turns out, I figured this out!!!
I appreciate the response Manikandadevan....

The answer that worked for us is that we have a forest root domain with 2 child domains.
Users are located in both of the child domains. Users in a site were connecting to a GC (root domain or the other child domain) that did not hold a writable copy. We created a reg key defining the GC that held a writeable copy.
Hope this helps someone else.
0
 

Author Closing Comment

by:tcole333
ID: 39183819
figured out the problem and added a reg key to fix.
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Learn to move / copy / export exchange contacts to iPhone without using any software. Also see the issues in configuration of exchange with iPhone to migrate contacts.
Find out what you should include to make the best professional email signature for your organization.
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
This video discusses moving either the default database or any database to a new volume.

867 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now