Exchange Exchange
A community dedicated to Exchange and related technology.

Exchange hotfix may break Blackberry BES or GoodLink Server

rated by 0 users
This post has 1 Reply | 0 Followers

Top 10 Contributor
Points 3,290
Joel Stidley Posted: 04-28-2006 9:13 AM

There has recently been some changes in store permissions which could cause BES or GoodLink Server to stop functioning properly.  Microsoft has prepared an article outlining the fix.

http://support.microsoft.com/kb/912918

- Joel

  • | Post Points: 0
Top 10 Contributor
Points 3,290

The biggest changes here is that the mailboxes no longer inherit the Send As permission from the Full Mailbox access nor do they inherit this from the Database or Server the mailbox is located in.

Previously you could assign an account to have Send As/Receive As for the Exchange Org and it would flow down to the mailbox.  That no longer works and the rights have to be set on the mailbox directly (ie the user account). Also Domain Admins, Schema Admins, and Enterprise admin accounts cannot have this permission assigned to their mailbox because of the AdminSDHolder constraint.  This means that Blackberry users should not be in these groups (there is a work around in the link above but it requires some work)

The link the previous post has this method of assigning access to the multiple accounts.

How to grant the Send As permission for multiple accounts


You can also grant the Send As permission by inheritance on every user object in an Active Directory domain or in a container. If you grant the Send As permission by this method, you may grant permission for objects that you did not intend. Additionally, you may lose permission for objects that are moved from the container. Therefore, this method is not preferred and may have security implications which should be carefully considered before you implement it.

To grant Send As for a single account on all user accounts in an Active Directory domain or container, follow these steps:

1. Start the Active Directory Users and Computers management console.
2. On the View menu, make sure that the Advanced Features option is selected. If this option is not selected, the Security page will not be visible for domain and container objects.
3. Open the properties of the domain or container, and then click the Security page.
4. Click the Advanced button.
5. If the account that needs permission is not already listed, click Add, and then select the account. Otherwise double-click the account for editing.
6. In the Applies Onto list, click User Objects.
7. Grant the account Send As and Read permissions.
8. Click OK until you have exited and saved all changes.

Note You may have to wait up to 15 minutes before the Exchange permission cache updates and the changes take effect.

- Joel

  • | Post Points: 0
Page 1 of 1 (2 items) | RSS
© 2003-2009 NamedPipes Consulting. All other company and product names are property of their owners.
Powered by Community Server (Non-Commercial Edition), by Telligent Systems