Protected Groups changing rights
From: Paul (Paul_at_discussions.microsoft.com)
Date: 03/21/05
- Next message: Mike Brannigan [MSFT]: "Re: Transfer the forest-Level Operations Master Roles"
- Previous message: Stuart: "Transfer the forest-Level Operations Master Roles"
- Next in thread: ptwilliams: "Re: Protected Groups changing rights"
- Reply: ptwilliams: "Re: Protected Groups changing rights"
- Reply: Steven L Umbach: "Re: Protected Groups changing rights"
- Messages sorted by: [ date ] [ thread ]
Date: Mon, 21 Mar 2005 09:43:07 -0800
We have a problem here where someone had added all users to one of the AD
protected groups. This modified the rights on the user objects (specifically
the rights "Self" had to the user object) we have removed all users from the
protected group but now the rights that "self" has is incorrect on the user
accounts. This has caused an issue where users can not add delegates to their
exchange mailbox. They add the delegate in their outlook client but it does
not get written to exchange. If I modify the rights that "self" has back to
what they should be then this works fine.
So my question is this. Does anyone know if there is a way to reset users
rights back to what they were before (defaults) the user was moved into the
protected group? Or can anyone suggest a way to mass edit the user objects to
add these rights back in?
If not does anybody know if you can create a script to check each user
object and report if the "Self" rights are correct?
-- Paul
- Next message: Mike Brannigan [MSFT]: "Re: Transfer the forest-Level Operations Master Roles"
- Previous message: Stuart: "Transfer the forest-Level Operations Master Roles"
- Next in thread: ptwilliams: "Re: Protected Groups changing rights"
- Reply: ptwilliams: "Re: Protected Groups changing rights"
- Reply: Steven L Umbach: "Re: Protected Groups changing rights"
- Messages sorted by: [ date ] [ thread ]