Re: Strange Public Folder permission assignments





Sorry, you lost me. You mounted a 5.5 PF database on an E2K3 server?


No - I oversimplified, extracted to pst, then imported via Outlook to
the 2k3 box.

PF client permissions aren't kept in the AD, they're kept in the PF
database. Only mail-enabled public folders have a presence in the AD
(in the Microsoft Exchange System Objects container).

If you used Outlook to set the permissions the folders will have the
permissions set in the database.

All the permissions were set using the System Manager, and with
PFDAVAdmin


The users are not logging in with the AD creds, but still the NT
accounts.

But they must have an account in the AD for you to set the
permissions. The account's probably disabled and it's got an account i
the sIDHstory propertyy that references the NT domain where the active
account is found.


Oh yes - they do - it is how they are accessing their migrated mail. I
used the Migration Wizard to manage that for me, and wrote some scripts
to fix a few of the attributes.
I thought the SIDHistory attribute was only available in WIndows native
mode (ADMT uses this?). I was of the impression that the migration
wizard assigned the 'Associated External Account' to give access - or
is this the friendly name for SIDHistory?

The GAL is just the presentation of AD objects through the NSPI.


Yes - this i understand. Initially i added the users who required
access to the folder, call them A & B. this did not work. So i created
a group, called C and added the users A & B - and this grants the users
the access.

And as the domain is not in native mode, the groups are Security
Groups. Our Exchange box is in the top level domain, and the user
accounts are in a child domain, so exchange is not consistently
enumerating the memberships. Am trying to convince the client that they
can go Windows Native (no nt4 PDC's) and we can change the groups to
Universal. Hopefully this will solve that problem.

Im sure it will become clearer as I read the paper.

Maybe. Maybe not. :) PF permissions, as I said, in a mixed-mode
organization as really ugly.

Your preaching to the choir!!!!

thanks for the info Rich!

ta


--
Rich Matheisen
MCSE+I, Exchange MVP
MS Exchange FAQ at http://www.swinc.com/resource/exch_faq.htm
Don't send mail to this address mailto:h.pott@xxxxxxxxxxxxx
Or to these, either: mailto:h.pott@xxxxxxxxxxxxxxx mailto:melvin.mcphucknuckle@xxxxxxxxxxxxx mailto:melvin.mcphucknuckle@xxxxxxxxxxxxxxx

.



Relevant Pages

  • Re: Unable to add mailbox
    ... This is a regular exchange 2003 install, and no, I have not lately done a dr ... december, and another backup dc in Feb (which was the old mail server, but I ... Authenticated User has Read and Special Permissions, the under advanced, the ... make sure that box is checked on the user's account as well. ...
    (microsoft.public.exchange.admin)
  • Re: Server Unavailable - ASP.NET 2.0 on Windows XP
    ... The -ga command isn't a part of that beta version. ... permissions to the global assembly cache. ... Please review the steps in it, for creating a service account for an ASP.NET 2.0 application, ... I've also tried the aspnet_regiis thing as well as setting permissions on folders as described ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Create Permissions to previously made folder.
    ... if these folders are on an Exchange 5.5 server, ... owner permissions via the Exchadmin tool...or you can try pfdavadmin... ...
    (microsoft.public.exchange.admin)
  • Re: Homefolder path on multiple users with already existing home folders...
    ... "Somebody" messed up our security settings on the homefolders, ... folders anymore... ... So I tried to take one user, wihout his own permissions, went in to ... for account names and granting that account and administrators access. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Permissions on the Exchange Server
    ... but i have to run ADD_ADPermission manually for each user from Exchange ... access to that mailbox. ... For this its better to create an account ... where users have added me as a delegate with editor permissions, ...
    (microsoft.public.exchange.development)