BlackBerryForums.com : Your Number One BlackBerry Community
     

»Sponsored Links

BlackBerryApps.com Best Sellers



Closed Thread
 
LinkBack Thread Tools
  (#1 (permalink)) Old
gloowee Offline
New Member
 
Posts: 14
Join Date: Aug 2009
Model: 7100t
PIN: N/A
Carrier: mts
Default Bes On A Standalone Server - 08-11-2009, 09:24 AM

Hi friends. Newbie to BES here.

I've setup BES 5.0 for Exchange 2007. I have experienced some issues that I'll work out with the help & suggestions in the other threads.

My question today is has anyone tried setting BES 5.0 up on a standalone server? Meaning, does the machine have to be a member of the domain? If so, what did you discover? Does it work?

The reason I ask this is because the BESAdmin account is running as a service and is also a domain admin. Since all domain computers trust the BES server because it's part of the domain, if someone got control of the BESAdmin account then that'd be game over.
   
Sponsored Links
Please Login or Register to Remove these Advertisements!

  (#2 (permalink)) Old
skyman84 Offline
CrackBerry Addict
 
skyman84's Avatar
 
Posts: 918
Join Date: Sep 2008
Location: Swindon, UK
Model: Bold
OS: 5.0.0.441
PIN: ask!
Carrier: Vodafone UK
Default 08-11-2009, 09:31 AM

Then why make the besadmin account a domain admin account?
   
  (#3 (permalink)) Old
penguin3107 Offline
BlackBerry God
 
penguin3107's Avatar
 
Posts: 10,024
Join Date: Jan 2005
Model: 9700
Carrier: ATT
Default 08-11-2009, 09:36 AM

Quote:
Originally Posted by gloowee View Post
the BESAdmin account is running as a service and is also a domain admin.
Why would you do this?


BCSA
BES 5.0.2 :-: Exchange 2007 SP1
http://port3101.org
   
  (#4 (permalink)) Old
gloowee Offline
New Member
 
Posts: 14
Join Date: Aug 2009
Model: 7100t
PIN: N/A
Carrier: mts
Default 08-11-2009, 09:46 AM

I'm pretty sure the setup tutorial said to put the besadmin account in the group "administrators" at the domain level.
   
  (#5 (permalink)) Old
skyman84 Offline
CrackBerry Addict
 
skyman84's Avatar
 
Posts: 918
Join Date: Sep 2008
Location: Swindon, UK
Model: Bold
OS: 5.0.0.441
PIN: ask!
Carrier: Vodafone UK
Default 08-11-2009, 09:48 AM

No no, the BESAdmin account needs to be a local admin on the BES server it's self only, not the domain.

It does need access to the mailfiles of the mail system your using, but as far as AD admin rights go, only local admin access to the server is sits on, and the ability to run as a service.
   
  (#6 (permalink)) Old
penguin3107 Offline
BlackBerry God
 
penguin3107's Avatar
 
Posts: 10,024
Join Date: Jan 2005
Model: 9700
Carrier: ATT
Default 08-11-2009, 09:48 AM

Quote:
Originally Posted by gloowee View Post
I'm pretty sure the setup tutorial said to put the besadmin account in the group "administrators" at the domain level.
No, it doesn't. The BES Service Account shouldn't be a Domain Admin.
It should be a local admin on the BES.


BCSA
BES 5.0.2 :-: Exchange 2007 SP1
http://port3101.org
   
  (#7 (permalink)) Old
CanuckBB Offline
BlackBerry Extraordinaire
 
CanuckBB's Avatar
 
Posts: 1,029
Join Date: Feb 2006
Location: YYZ
Model: 8330
OS: 4.5.0.131
Carrier: Bell
Default 08-11-2009, 10:03 AM

Quote:
Originally Posted by gloowee View Post
The reason I ask this is because the BESAdmin account is running as a service and is also a domain admin. Since all domain computers trust the BES server because it's part of the domain, if someone got control of the BESAdmin account then that'd be game over.
As other have said BESAdmin needs to be local admin.

And how is BESAdmin any different than 'Administrator'? The chances of somebody getting access to BESAdmin are no greater than Administrator.
   
  (#8 (permalink)) Old
usererror Offline
Thumbs Must Hurt
 
Posts: 95
Join Date: Jul 2007
Location: Petoskey, MI
Model: 8530
OS: Win 7
PIN: N/A
Carrier: Verizon Droid
Default 08-11-2009, 10:26 AM

I thought the besadmin account also had to be a member of the domain in order for it to do the "Send As" abilities on each user's account.
   
  (#9 (permalink)) Old
skyman84 Offline
CrackBerry Addict
 
skyman84's Avatar
 
Posts: 918
Join Date: Sep 2008
Location: Swindon, UK
Model: Bold
OS: 5.0.0.441
PIN: ask!
Carrier: Vodafone UK
Default 08-11-2009, 10:29 AM

Wirelessly posted (Bold 9000)

The besadmin account must be a domain account, and have the sendas permissions, but it does not need to be added to the domain admin group. Just make sure its added locally to the admin group on the server.
   
  (#10 (permalink)) Old
gloowee Offline
New Member
 
Posts: 14
Join Date: Aug 2009
Model: 7100t
PIN: N/A
Carrier: mts
Default 08-11-2009, 10:31 AM

Check out module #2.

blackberry. com/ select/ toolkit/ 02.shtml#

Should the besadmin account also be a local admin on the Exchange server in order to get access to other peoples mailbox?
   
  (#11 (permalink)) Old
penguin3107 Offline
BlackBerry God
 
penguin3107's Avatar
 
Posts: 10,024
Join Date: Jan 2005
Model: 9700
Carrier: ATT
Default 08-11-2009, 10:58 AM

Quote:
Originally Posted by gloowee View Post
Check out module #2.

blackberry. com/ select/ toolkit/ 02.shtml#

Should the besadmin account also be a local admin on the Exchange server in order to get access to other peoples mailbox?
You seem to be really confused about permissions assigned to the BES service account.
This should clear things up for you:
KB02276 - Assigning permissions for a BlackBerry Enterprise Server service account - Port3101.org : Your BES Connection

Follow that KB article and you should be fine.


BCSA
BES 5.0.2 :-: Exchange 2007 SP1
http://port3101.org
   
  (#12 (permalink)) Old
MarshBklyn Offline
Thumbs Must Hurt
 
Posts: 63
Join Date: Aug 2009
Model: 9000
PIN: N/A
Carrier: crApT&T
Default 08-11-2009, 11:02 AM

Quote:
Originally Posted by gloowee View Post
Should the besadmin account also be a local admin on the Exchange server in order to get access to other peoples mailbox?
No. Only Exchange View Administrator within exchange. Also, send, receive, and administer store permissions as well.
   
  (#13 (permalink)) Old
gloowee Offline
New Member
 
Posts: 14
Join Date: Aug 2009
Model: 7100t
PIN: N/A
Carrier: mts
Default 08-11-2009, 11:32 AM

Thank you. I followed your instructions to the letter and all was good. Still having issues that I'll search the forums for help on.
   
Closed Thread


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On





Copyright © 2004-2010 BlackBerryFAQ.com, BlackBerryForums.com.
The names RIM © and BlackBerry © are registered Trademarks of Research In Motion Limited.