Re: Remove old SID permissions

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Look at

http://support.microsoft.com/kb/310866/

and also look at

http://msdn.microsoft.com/library/default.asp?url=/library/en-us/adsi/adsi/iadsaccesscontrollist_removeace.asp?frame=true


--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Edition
www.joeware.net


---O'Reilly Active Directory Third Edition now available---

http://www.joeware.net/win/ad3e.htm



TONY-LCG wrote:
Thanks Joe,
I found a script on the MS knowledge base for adding permissions, but I can't find one to take these permissions away. Again, If I have a user who has full mailbox rights to another mailbox, how can I build a script that will remove their rights?

Thanks,
Tony

"Joe Richards [MVP]" wrote:

You would have to write a script that munged through all of the user objects cleaning the permissions up.

--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Edition
www.joeware.net


---O'Reilly Active Directory Third Edition now available---

http://www.joeware.net/win/ad3e.htm



TONY-LCG wrote:
We have a lot of old outdated SIDs with full mailbox access permissions to multiple mailboxes. Typically, these are users who had access to mailboxes other than their own but have left the company. Is there a way to remove all invalid SIDs from all our mailbox's in one fell swoop?
.



Relevant Pages

  • Re: Exporting mails from exchange server to a website
    ... Joe Richards Microsoft MVP Windows Server Directory Services ... Probably the easiest mechanism would be to send to a mailbox and then use POP3 via perl to read the messages in the mailbox and dump into some other store, say some sort of database or as a series of flatfiles that your web code can then read. ... I am new to exchange server technology,but I am interested in pulling out mails from a Mailing List to a web site. ...
    (microsoft.public.exchange.development)
  • Re: Force Password change (Delegate control)
    ... It is selling like hotcakes and I am getting a ton of positive feedback. ... Joe Richards Microsoft MVP Windows Server Directory Services ... Author of O'Reilly Active Directory Third Edition ...
    (microsoft.public.win2000.active_directory)
  • Re: How to tell whihc OU the users belongs to
    ... If you are logged on as the user, you can most easily use username ... Obviously you can also write scripts to do this stuff as well, if you are interested in that, check out the AD Cookbook 2nd Edition and/or the Technet Script Center ... Joe Richards Microsoft MVP Windows Server Directory Services ... Author of O'Reilly Active Directory Third Edition ...
    (microsoft.public.windows.server.active_directory)
  • Re: Calling IMailboxStore.CreateMailbox fails
    ... Ok an error there means it isn't even getting into CDOEXM, that is simply trying to get the object you are trying to mailbox enable. ... Joe Richards Microsoft MVP Windows Server Directory Services ... for the domain account which is trying to create the mailbox, ...
    (microsoft.public.exchange.development)
  • Re: How to create VHD file via VSS (Volume Shadow Copy Service)
    ... Maybe you want to look at the VHD specification ... Joe Richards Microsoft MVP Windows Server Directory Services ... Author of O'Reilly Active Directory Third Edition ...
    (microsoft.public.win32.programmer.kernel)