BlackBerry Forums Support Community               
Unlock My BlackBerry!

Closed Thread
 
LinkBack Thread Tools
Old 08-17-2009, 11:01 AM   #1 (permalink)
New Member
 
Join Date: Aug 2009
Model: 8330
PIN: N/A
Carrier: Verizon
Posts: 9
Post Thanks: 0
Thanked 0 Times in 0 Posts
Default Domain Admin, Send As, and Red X issue

Please Login to Remove!

Strange one here. Two of my domain admins get the red x when attempting to send email from their Blackberries. I have to continually go back and grant 'Send As' permissions to the BESAdmin account to allow them to send. I am also a domain admin but do not have the problem and nor does the BESAdmin account have 'Send As' permissions on my account. Anyone have any clue what's going on here?
Thanks
Offline  
Old 08-17-2009, 11:03 AM   #2 (permalink)
BlackBerry God
 
penguin3107's Avatar
 
Join Date: Jan 2005
Model: iOS 5
Carrier: VZW
Posts: 11,711
Post Thanks: 1
Thanked 237 Times in 219 Posts
Default

A BES user should NOT be a Domain Admin. This is well documented by RIM.
(Your account will eventually fail as well, so just consider yourself lucky for now.)
You should remove Domain Admin privileges from all BES users.

See here:
KB04707 - Unable to send email messages because Send As permission has been revoked - Port3101.org : Your BES Connection

and here:
AdminSDHolder - or where did my permissions go? - Port3101.org : Your BES Connection
__________________
BCSA
BES 5.0.3 MR4 :-: Exchange 2007 SP3 RU3
http://port3101.org
Offline  
Old 08-18-2009, 11:16 AM   #3 (permalink)
New Member
 
Join Date: Aug 2009
Model: 8330
PIN: N/A
Carrier: Verizon
Posts: 9
Post Thanks: 0
Thanked 0 Times in 0 Posts
Default

Thanks peguin. I appreciate that and was aware of the recommendation but I'm getting slack from them for possibly having to reconfigure their mailboxes to be associated with a non-domain admin account. I've gone days now without having a problem - and BESAdmin does not even have send as permissions listed on the security for my account. I'm in the exact same protected groups as they are - what's the deal?
Offline  
Old 08-18-2009, 11:22 AM   #4 (permalink)
BlackBerry God
 
penguin3107's Avatar
 
Join Date: Jan 2005
Model: iOS 5
Carrier: VZW
Posts: 11,711
Post Thanks: 1
Thanked 237 Times in 219 Posts
Default

If you want your BES and handhelds to work correctly for everyone, all of the time, then you need to follow RIM's guidelines and best practices.

It's called the Principle of Least Privilege... and you're not following it.
Principle of least privilege - Wikipedia, the free encyclopedia

Make yourselves normal users, and then create a secondary login with Domain Admin privileges. Only use that secondary login when necessary.
__________________
BCSA
BES 5.0.3 MR4 :-: Exchange 2007 SP3 RU3
http://port3101.org
Offline  
Old 08-18-2009, 11:31 AM   #5 (permalink)
New Member
 
Join Date: Aug 2009
Model: 8330
PIN: N/A
Carrier: Verizon
Posts: 9
Post Thanks: 0
Thanked 0 Times in 0 Posts
Default

I realize I am not following guidelines and best practices. I'm telling you, BESAdmin does NOT HAVE 'send as' privileges on my account yet I'm in the same exact protected groups as those with the problem. I mostly would like to understand what might be different about my account. Is it something with when I've Enterprise Activated, or reloaded my own account?
Anyone?
Offline  
Old 08-18-2009, 12:25 PM   #6 (permalink)
BlackBerry Genius
 
hdawg's Avatar
 
Join Date: Aug 2006
Model: hdawg
PIN: port3101.org
Carrier: hdawg
Posts: 6,647
Post Thanks: 0
Thanked 0 Times in 0 Posts
Default

did you ever modify the adminsdholder object?
Offline  
Old 08-18-2009, 02:21 PM   #7 (permalink)
New Member
 
Join Date: Aug 2009
Model: 8330
PIN: N/A
Carrier: Verizon
Posts: 9
Post Thanks: 0
Thanked 0 Times in 0 Posts
Default

No, and I may not have been clear about the issue. I'm a domain admin just as those who cannot send. The BESAdmin account is not listed as having 'Send As' permissions on my account, yet I have no problem sending. I'm curious as to what might be different about my account. I've read I can modify the adminsdholder object, but wasn't sure if I wanted to go that route. Again, what might be different about my acccount that I don't have a problem? Thanks for your help.
Offline  
Old 08-18-2009, 03:45 PM   #8 (permalink)
BlackBerry Genius
 
knottyrope's Avatar
 
Join Date: Jan 2008
Location: Massachusetts
Model: 9860
OS: 7.1.0.402
PIN: t of blood has been taken
Carrier: AT&T-US with I dee ten tee errors
Posts: 5,561
Post Thanks: 121
Thanked 164 Times in 156 Posts
Default

It might be a random issue for you on why you can send. I have seen it before.

penguin3107 and hdawg did give you a solution to your problem.
__________________
Please click on THANKS if someone was helpful
RTFM? You LIAR!!! Read the FAQ? Use search?
Is your device or BES database backed up? don't
Follow me http://twitter.com/knottyrope
Offline  
Old 08-18-2009, 04:04 PM   #9 (permalink)
New Member
 
Join Date: Aug 2009
Model: 8330
PIN: N/A
Carrier: Verizon
Posts: 9
Post Thanks: 0
Thanked 0 Times in 0 Posts
Default

I KNOW they gave me a solution. I'm not doubting that, I'm just looking for someone who can give a solid answer on this 'random issue' - jeesh!
Offline  
Old 08-18-2009, 04:32 PM   #10 (permalink)
BlackBerry Genius
 
knottyrope's Avatar
 
Join Date: Jan 2008
Location: Massachusetts
Model: 9860
OS: 7.1.0.402
PIN: t of blood has been taken
Carrier: AT&T-US with I dee ten tee errors
Posts: 5,561
Post Thanks: 121
Thanked 164 Times in 156 Posts
Default

I wish you luck in your findings.
__________________
Please click on THANKS if someone was helpful
RTFM? You LIAR!!! Read the FAQ? Use search?
Is your device or BES database backed up? don't
Follow me http://twitter.com/knottyrope
Offline  
Old 08-20-2009, 07:03 AM   #11 (permalink)
BlackBerry Genius
 
hdawg's Avatar
 
Join Date: Aug 2006
Model: hdawg
PIN: port3101.org
Carrier: hdawg
Posts: 6,647
Post Thanks: 0
Thanked 0 Times in 0 Posts
Default

Quote:
Originally Posted by msr145 View Post
I KNOW they gave me a solution. I'm not doubting that, I'm just looking for someone who can give a solid answer on this 'random issue' - jeesh!
You've got some issue with active directory ... look there.
Offline  
Closed Thread


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On





Copyright © 2004-2011 BlackBerryFAQ.com, BlackBerryForums.com.
The names RIM © and BlackBerry © are registered Trademarks of Research In Motion Limited.