BlackBerry Forums Support Community
              

Closed Thread
 
Thread Tools
Old 08-15-2007, 01:19 AM   #1
monkeyhanger
New Member
 
Join Date: Aug 2007
Model: 8300
PIN: N/A
Carrier: Vodafone
Posts: 9
Default "send as" permission keeps unsetting

Please Login to Remove!

I'm setting up my first BES with one user.

Having read some other posts on setting "send as" permissions on my user accounts, I get the blackberry to be able to both send and receive - for a while.

After a number of hours though (seems to happen within 12), the ability to send e-mails dies. Looking back on the server, it appears that the send as permissions I've loaded in Active Directory have somehow unset themselves.

I've tried manually entering them twice (works, then unsets) and have downloaded the SetSendAsPermission.exe tool and used it sucessfully twice (works then unsets).

Is there another way around this problem to get this fixed?

(One odd thing, that may or may not be relevant - in active directory, the user I'm trying to set up appears in the root of the directory, at the same level as the "users" subdirectory.)

Last edited by monkeyhanger; 08-15-2007 at 01:33 AM..
Offline  
Old 08-15-2007, 06:18 AM   #2
banthon
Knows Where the Search Button Is
 
Join Date: Jun 2007
Model: Bold
Carrier: various
Posts: 48
Default

BES Users *may not* be member of any administrative AD-group because MS (patch ?????) revokes the send as permissions over and over gain

Check this RIM KNW entry
BlackBerry Search Results
and the liked MS KNB entries, too - especially entry 912918

Last edited by banthon; 08-15-2007 at 06:28 AM..
Offline  
Old 08-15-2007, 06:25 AM   #3
hdawg
BlackBerry Genius
 
hdawg's Avatar
 
Join Date: Aug 2006
Model: hdawg
PIN: port3101.org
Carrier: hdawg
Posts: 6,632
Default

Are any of your users in privelegded AD groups?

AdminSDHolder ...

I would recommend NOT modifying the AdminSDHolder object, but rather not adding users that are in these special groups to the BES and only having user-level accounts on the BES.
Offline  
Old 08-15-2007, 08:09 AM   #4
monkeyhanger
New Member
 
Join Date: Aug 2007
Model: 8300
PIN: N/A
Carrier: Vodafone
Posts: 9
Default

Thanks for your comments.

I'm a little confused by some of the terminology but I think I understand this now.

The user is a member of the Administrators and Domain Admins groups. As I understand it, AdminSdHolder is a thread which resets security information on certain priveledged accounts.

The solutions I believe I have are:
1) to remove membership of these groups from the user or
2) to use dsacls.exe to modify something - I'm not entirely clear what - that either modifies the behavior of AdminSdHolder or modifies the default security information for priveledged accounts.

(Please correct me if I've got this wrong)

I'm going to try 1) first (probably this evening) - my only concern is that the relevant user does need to be able to perform some priveledged tasks like installing their own software, running Windows Update, installing printers etc. There may be knock on effects that I'm currently unaware of which would crop up if I make these changes for them.

Option 2) sounds like its considered bad-practice and weakens security - by what degree, I can't tell. If option 1 is a non-starter, I'll have to give this a go.
Offline  
Old 08-15-2007, 11:06 AM   #5
monkeyhanger
New Member
 
Join Date: Aug 2007
Model: 8300
PIN: N/A
Carrier: Vodafone
Posts: 9
Default

I THINK THAT'S DONE THE TRICK!

I've removed membership of all admin groups for this user (Administrator, Domain Admin and Schema Admin) and "Send As" permissions seem to be holding up. The only downside is that the user needs to log in to their PC as an admin account if they need to do any installs or updates which affect system files.

Thanks for your help.
Offline  
Old 08-15-2007, 09:24 PM   #6
hdawg
BlackBerry Genius
 
hdawg's Avatar
 
Join Date: Aug 2006
Model: hdawg
PIN: port3101.org
Carrier: hdawg
Posts: 6,632
Default

That would be exactly it. You can make the user an Administrator on their computer; they just can't be a member of those Domain level groups. I have 2 accounts hdawg and megasuperduperuberslickhdawg ... one I pretend to be a user and one I live the life of a mega h4x0r. ... besides its best practice to do this; and you were right on to not modify AdminSDHolder; bravo, good troubleshooting, and glad its workin for ya!

Here's a banana.
Offline  
Closed Thread



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


Vintage Printer Switch box Commodore 64/Sanyo Mountable Computer PC picture

Vintage Printer Switch box Commodore 64/Sanyo Mountable Computer PC

$49.00



Commodore Rechargeable Portable Electronic Calculator 9R-25 W/ Case - Tested picture

Commodore Rechargeable Portable Electronic Calculator 9R-25 W/ Case - Tested

$99.99



Vintage MOS 8500 HMOS Commodore C64 IC x 1pc picture

Vintage MOS 8500 HMOS Commodore C64 IC x 1pc

$35.00



MSA Commodore V-Gard Cap Safety Hard Hat Suspension with Harness Standard White picture

MSA Commodore V-Gard Cap Safety Hard Hat Suspension with Harness Standard White

$4.02



Jelenko Commodore LS VPF with Pump  picture

Jelenko Commodore LS VPF with Pump

$875.00



To Suit Holden Commodore 3 Button Car Remote Case/Shell Uncut Key VS VX VY VZ WH picture

To Suit Holden Commodore 3 Button Car Remote Case/Shell Uncut Key VS VX VY VZ WH

$11.99







Copyright © 2004-2016 BlackBerryForums.com.
The names RIM © and BlackBerry © are registered Trademarks of BlackBerry Inc.