Membership in Admin groups resets Send As permissions - Blackberry's broken for administrators



Ok, this is an odd one.

Blackberry Enterprise Server (BES 4.0, SP4, HF 3, i.e. version 4.0.4.5)

Exchange 2003, SP2, 2003 native mode domain.

Using the script in http://support.microsoft.com/kb/912918/en-us (KB Article
912918) per the latest security patch, I attempted to set the 'send as'
permission.

Everyone works but 4 people. I removed 2 of the people from administrative
groups, and the script works.

What happens is that about 5-10 minutes after I grant the Blackberry service
accounts permission to 'send as' ... they revert to not having 'send as'
permission.

The other, non admistrator, users work fine.

I called Blackberry support, and they said that Microsoft had 'hard coded'
it so that Administrators CANNOT use Blackberry's. Apparently
administrators will no longer be able to have another account have 'send as'
authority.

Obviously, one possible 'best practice' is to remove my 'normal' account
from admin groups and have a second account used only for administration,
but NOTHING should remove a permission I have explicitly set without some
kind of warning.

Also, this basically forces any admin to have 2 accounts, otherwise they
won't get notifications about critical events, given that their blackberry's
are non operational with administrator accounts.

Now I'll be typing my password 100's of times a day.

It's extremely frustrating to me that this 'feature' is being jammed down
our throats.

Thoughts?

== John ==


.



Relevant Pages

  • RE: ADMT never sucesess of migrating computer account :(
    ... The account you use to run ADMT must have enough permission to complete the ... of the local Administrators group on each computer to be migrated. ... Add Win2k3Dom Domain admins group to win2k Domain admins group and ...
    (microsoft.public.windows.server.migration)
  • RE: permission for nero
    ... Subject: permission for nero ... You wouldn't need to add the account to the Administrators group, ... Or you could simply create a NERO group, ...
    (Security-Basics)
  • RE: backup error in windows 2003
    ... I am running ntbackup from the administrators ... account. ... So can't see why I wouldn't have permission to access the C: ... > There may be a hardware or media problem. ...
    (microsoft.public.windows.server.general)
  • Administrator Issues
    ... but tried deleting her account to resolve my ... We were both set as administrators. ... See the administrator to get permission. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Event ID: 1202
    ... No mapping between account names and security IDs was ... SeIncreaseBasePriorityPrivilege = Administrators ... "Meinolf Weber" wrote: ... A user account in one or more Group policy objects (GPOs) could not ...
    (microsoft.public.win2000.active_directory)

Loading