Re: Incoming E-Mail - cant create contact in OU



I apologize if I dont understand your suggestion. My current/initial setup
is delegating the application pool rights to the OU, and that doesnt seem to
work.

Today I have added the application pool account as a local administrator to
all my WSS 3.0 boxes, and rebooted the boxes to be entirely sure.

I then enabled email, and logged into my sharepoint site and attempted to
add an email to a discussion and it still fails.

I am pretty sure its an AD/OU issue, not a local WSS issue. Reason? Because
if I add the Application Pool user to Domain Admins, it then works. There is
something missing in AD or possibly Exchange rights that is not allowing WSS
to create the contact in an OU. Again, to confirm - I am delegating rights
to the new OU for my sharepoint application pool user account.

"Daniel Bugday" wrote:

Paul,
i think you have to follow callahans suggestion of adding the account to the
local admin froup of that server.

Could you try one other thing..

Try to delegate permission to the account which is running the IIS pool for
the central administration site without adding to admin group and then do an
IISReset.

/Daniel Bugday

"callahan" <cacallahan@xxxxxxxxxxxxxxxxxxx> wrote in message
news:%23NTN2SR7HHA.4436@xxxxxxxxxxxxxxxxxxxxxxx
The application pool account, in my experience, must be a local admin of
the sharepoint server that is doing incoming email and hosting DMS. Also
the account must have those permissions to all the child objects for that
OU as well.

In addition, if you are going to do approval for the groups, I found that
I had to give the farm account rights to the OU as well in order to be
able to delete a group. Please let me know if that is the case for you.

Frankly, I am impressed. I personally have never gotten it to work with
Exchange 2007.

-callahan
"Paul" <Paul@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:E9308C36-1A8C-4071-93EB-BAB58A0C7DD8@xxxxxxxxxxxxxxxx
Running Windows 2003 R2 AD, Exchange 2007 and WSS 3.0.

I have WSS website application pool running as a domain user account, not
network service.
I created an OU called Sharepoint and delegated rights to this user
account
(Create, delete and manage user accounts + Read All User Information).

When I create a site and attempt to enable email, it gives me "Error in
the
application. "

However to prove its a permission issue, I then added this website
application pool account to domain admins, rebooted my WSS to be sure and
tried again - now it works! Obviously I dont want to run this as domain
admin, so removal of domain admin kills the ability to add email.

There must be other AD OU permissions that are not listed in the
Microsoft
instructions to make this work, but what?



.



Relevant Pages

  • Re: Incoming E-Mail - cant create contact in OU
    ... already have the application pool delegated rights to the OU. ... In my experience it is because you didn't quite delegate enough rights to ... the account in the OU. ...
    (microsoft.public.sharepoint.windowsservices)
  • Re: Incoming E-Mail - cant create contact in OU
    ... Go to the OU in security/advanced I added my sharepoint application pool ... that account a little (if the web app is compromised or something, ... Now I understand that you have given the account "full rights" of the OU, ... So I started with giving the app pool account domain admins permissions then ...
    (microsoft.public.sharepoint.windowsservices)
  • Re: Integrated Authentication, Application Pools, and SQL Server
    ... I did check the application pool user's rights and group membership. ... When I access it locally I'm using a Domain Admin account. ...
    (microsoft.public.inetserver.iis)
  • Re: Unlock accounts in same security group - account operators
    ... This posting is provided "AS IS" with no warranties, and confers no rights. ... unlock one anothers accounts? ... not if they are in the Account Operators group. ... Delegating the read/write lockout time option does not work as the ...
    (microsoft.public.windows.server.active_directory)
  • Re: w3wp.exe Account
    ... Shadowfax Dev Team ... This posting is provided "AS IS" with no warranties, and confers no rights. ... > Anavailable", When the default pool runs, it works fine. ... > ASP.NET account. ...
    (microsoft.public.dotnet.framework.aspnet.security)

Loading