RE: Help: SBS 2003 Exchange Send As permissions not working (and disappearing!)

From: Jerry zhao (v-jerryz_at_online.microsoft.com)
Date: 03/14/05


Date: Mon, 14 Mar 2005 08:59:22 GMT

Hi Matt,

Nice to hear you again.

I though that I have replied your previous post about the some issue last
week. I am not sure if you have already got that. Here, I would provide my
reply again:

====================================================
Hi Matt,

Thanks for using SBS newsgroup!

>From your problem description, I understand your issue to be: you could not
use the "Send As" in your SBS 2k3 network. If I have misunderstood your
issue, please let me know.
It seems to be related to the AD AdminSDHolder resetting the permissions
for users that are members of one of the protected groups.

318180 AdminSDHolder Thread Affects Transitive Members of Distribution
Groups
http://support.microsoft.com/?id=318180

817433 Delegated permissions are not available and inheritance is
automatically disabled
http://support.microsoft.com/?id=817433

Please check the group membership of the affected users, if the user where
the permissions are being changed is a member of any of the following
groups, the ACLs will be reset on the hour.

* Enterprise Admins
* Schema Admins
* Domain Admins
* Administrators
* Domain Controllers
* Cert Publishers
* Backup Operators
* Replicator Server Operators
* Account Operators
* Print Operators

If this is not the case, please help me collect the following information
to isolate the issue:

1. What the exact error when you fail to using "send as"?

2. Are there any event logs related to this issue?

3. You have mentioned that one account can work well with "send as". What
is the difference between this account and the problematic accounts?

If you have any concern on this thread, I am glad to be of further
assistance. We look forward to hearing from you.

Best regards,

Jerry Zhao (MSFT)

Microsoft CSS Online Newsgroup Support

=======================================================

Best regards,

Jerry Zhao (MSFT)

Microsoft CSS Online Newsgroup Support

Get Secure! - www.microsoft.com/security

=====================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
=====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.



Relevant Pages

  • Re: Rid AD of Circular Group Membership
    ... and have use on members if it is used there. ... Administrators group is still intact), nor do they have empowerments over ... Admins is being used for by the 30+ can be delegated I(ex. ... The quess is each has an account and uses it, ...
    (microsoft.public.windows.group_policy)
  • Re: Problem managing accounts in protected groups
    ... we have two domain admins: ... that someone will give more security permissions to users then to the admins. ... I think you have realized that the account management group is able to reset ... Most members of OU A are either members of Domain ...
    (microsoft.public.windows.server.active_directory)
  • RE: Help with Exchange Send As permissions not working and disappearing (SBS 2003)
    ... Thanks for using SBS newsgroup! ... 318180 AdminSDHolder Thread Affects Transitive Members of Distribution ... Schema Admins ... You have mentioned that one account can work well with "send as". ...
    (microsoft.public.windows.server.sbs)
  • Re: Problem managing accounts in protected groups
    ... For you administrator accounts create an own OU directly under the domain name and place there the domain admin accounts without any restrictions through policies or whatever. ... And create for them a normal domain user account for the daily work with normal restrictions like any other user. ... If now the account under the Administrators OU is locked another one from that OU can easily unlock them without any problem, because they all are domain admins in that OU. ... heard about that someone will give more security permissions to users ...
    (microsoft.public.windows.server.active_directory)
  • Re: Single User/Multiple Domain Authority Delegation
    ... For example, by default, Enterprise Admins and Domain Admins are members of the Administrators group in each domain. ... By virtue of being members of Administrtors group, both of these groups would normally be able to logon and administer any domain. ... members of the Administrators group on Domain Controllers have the rights required to logon to the Domain Controller remotely. ... When the 'useradmin' account is granted EnterpriseAdmin ...
    (microsoft.public.windows.server.active_directory)