Re: Incoming E-Mail - cant create contact in OU



The application pool account, in my experience, must be a local admin of the
sharepoint server that is doing incoming email and hosting DMS. Also the
account must have those permissions to all the child objects for that OU as
well.

In addition, if you are going to do approval for the groups, I found that I
had to give the farm account rights to the OU as well in order to be able to
delete a group. Please let me know if that is the case for you.

Frankly, I am impressed. I personally have never gotten it to work with
Exchange 2007.

-callahan
"Paul" <Paul@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:E9308C36-1A8C-4071-93EB-BAB58A0C7DD8@xxxxxxxxxxxxxxxx
Running Windows 2003 R2 AD, Exchange 2007 and WSS 3.0.

I have WSS website application pool running as a domain user account, not
network service.
I created an OU called Sharepoint and delegated rights to this user
account
(Create, delete and manage user accounts + Read All User Information).

When I create a site and attempt to enable email, it gives me "Error in
the
application. "

However to prove its a permission issue, I then added this website
application pool account to domain admins, rebooted my WSS to be sure and
tried again - now it works! Obviously I dont want to run this as domain
admin, so removal of domain admin kills the ability to add email.

There must be other AD OU permissions that are not listed in the Microsoft
instructions to make this work, but what?


.



Relevant Pages

  • Re: Incoming E-Mail - cant create contact in OU
    ... central admin pool different than the web app. ... that account a little (if the web app is compromised or something, ... So I started with giving the app pool account domain admins permissions then ...
    (microsoft.public.sharepoint.windowsservices)
  • Re: administrator password not accepted at boot Windows XP Pro SP2
    ... unfortunately I only have the admin account on the PC; ... If you only have the one user account (and now you can see why having only ... one user account is foolish, so make an extra one after you get into the ...
    (microsoft.public.windowsxp.general)
  • Re: Security Breach in AD! Help!
    ... > about 5 minutes the user was removed from the built in admin group. ... > changed the default domain policy, the default domain controller policy, ... >> auditing of account logon for success and failure and account management ... >> success and failure in Domain Controller Security Policy. ...
    (microsoft.public.win2000.security)
  • Re: administrator password not accepted at boot Windows XP Pro SP2
    ... unfortunately I only have the admin account on the PC; ... If you only have the one user account (and now you can see why having ... one user account is foolish, so make an extra one after you get into the ...
    (microsoft.public.windowsxp.general)
  • Re: cant verify disk
    ... She went to DU, and when she pressed "verify disk", it asked her user ... Disk Utility has required an administrator name and password for certain ... This is clearly a task which requires admin privileges, ... seriously mucked up with her user account settings in the NetInfo ...
    (comp.sys.mac.system)