Re: adminSDholder and permissions resets
- From: bruce <badiii@xxxxxxxxxxxx>
- Date: Tue, 17 Oct 2006 13:06:24 -0700
"Rich Matheisen [MVP]" <richnews@xxxxxxxxxxxxxxxxxxxxx> wrote in
news:63f0j254o924p83j43f43f37ljpm7b1ea7@xxxxxxx:
bruce <badiii@xxxxxxxxxxxx> wrote:
I applied a recent Exchange hotfix that affected the SendAs
permissions required for Blackberry services to work. I granted SendAs
permissions to the BESADMIN service on the domain level.
I found that despite this, permissions for most of IT kept getting
reset, and the besadmin account was being removed. I finally figured
out that these IT accounts were all members of Account Operators,
which is associated with the adminSDHolder object and the permissions
reset every hour.
I removed a couple of us from the Account Operators group a couple
days ago, but our permissions still get reset. The accounts are not
members of any other builtin groups. Why is this happening? How can I
disassociate these acccounts from adminSDholder?
MS tech support's best suggestion is to create new accounts and move
all mail, etc over to them. what a great idea :(
See if this KB article helps:
Delegated permissions are not available and inheritance is
automatically disabled [817433]
Thank you. It does help show the problem, but not why. I used the ldifde
example to list all my accounts that have the admincount set to 1.
However, the problem I see is that once an account has been in an
adminSDholder protected group and then removed, it is still being reset
from inheriting permissions, even after I explicitly allow inheritance. I
actually have an account that is currently only in "Domain Users", but it
used to be in Administrators. Nonetheless, it shows up with admincount=1.
Do you have any idea why this is still set even when I remove my accounts
from those groups? Any idea how to remove that setting manually? TIA
.
- Follow-Ups:
- Re: adminSDholder and permissions resets
- From: Rich Matheisen [MVP]
- Re: adminSDholder and permissions resets
- References:
- adminSDholder and permissions resets
- From: bruce
- Re: adminSDholder and permissions resets
- From: Rich Matheisen [MVP]
- adminSDholder and permissions resets
- Prev by Date: Re: Archive or log for RBL
- Next by Date: Re: Archive or log for RBL
- Previous by thread: Re: adminSDholder and permissions resets
- Next by thread: Re: adminSDholder and permissions resets
- Index(es):
Relevant Pages
|