BlackBerryForums.com : Your Number One BlackBerry Community
     

»Sponsored Links

BlackBerryApps.com Best Sellers



Closed Thread
 
LinkBack Thread Tools
  (#1 (permalink)) Old
msr145 Offline
New Member
 
Posts: 9
Join Date: Aug 2009
Model: 8330
PIN: N/A
Carrier: Verizon
Default Domain Admin, Send As, and Red X issue - 08-17-2009, 11:01 AM

Strange one here. Two of my domain admins get the red x when attempting to send email from their Blackberries. I have to continually go back and grant 'Send As' permissions to the BESAdmin account to allow them to send. I am also a domain admin but do not have the problem and nor does the BESAdmin account have 'Send As' permissions on my account. Anyone have any clue what's going on here?
Thanks
   
Sponsored Links
Please Login or Register to Remove these Advertisements!

  (#2 (permalink)) Old
penguin3107 Offline
BlackBerry God
 
penguin3107's Avatar
 
Posts: 10,024
Join Date: Jan 2005
Model: 9700
Carrier: ATT
Default 08-17-2009, 11:03 AM

A BES user should NOT be a Domain Admin. This is well documented by RIM.
(Your account will eventually fail as well, so just consider yourself lucky for now.)
You should remove Domain Admin privileges from all BES users.

See here:
KB04707 - Unable to send email messages because Send As permission has been revoked - Port3101.org : Your BES Connection

and here:
AdminSDHolder - or where did my permissions go? - Port3101.org : Your BES Connection


BCSA
BES 5.0.2 :-: Exchange 2007 SP1
http://port3101.org
   
  (#3 (permalink)) Old
msr145 Offline
New Member
 
Posts: 9
Join Date: Aug 2009
Model: 8330
PIN: N/A
Carrier: Verizon
Default 08-18-2009, 11:16 AM

Thanks peguin. I appreciate that and was aware of the recommendation but I'm getting slack from them for possibly having to reconfigure their mailboxes to be associated with a non-domain admin account. I've gone days now without having a problem - and BESAdmin does not even have send as permissions listed on the security for my account. I'm in the exact same protected groups as they are - what's the deal?
   
  (#4 (permalink)) Old
penguin3107 Offline
BlackBerry God
 
penguin3107's Avatar
 
Posts: 10,024
Join Date: Jan 2005
Model: 9700
Carrier: ATT
Default 08-18-2009, 11:22 AM

If you want your BES and handhelds to work correctly for everyone, all of the time, then you need to follow RIM's guidelines and best practices.

It's called the Principle of Least Privilege... and you're not following it.
Principle of least privilege - Wikipedia, the free encyclopedia

Make yourselves normal users, and then create a secondary login with Domain Admin privileges. Only use that secondary login when necessary.


BCSA
BES 5.0.2 :-: Exchange 2007 SP1
http://port3101.org
   
  (#5 (permalink)) Old
msr145 Offline
New Member
 
Posts: 9
Join Date: Aug 2009
Model: 8330
PIN: N/A
Carrier: Verizon
Default 08-18-2009, 11:31 AM

I realize I am not following guidelines and best practices. I'm telling you, BESAdmin does NOT HAVE 'send as' privileges on my account yet I'm in the same exact protected groups as those with the problem. I mostly would like to understand what might be different about my account. Is it something with when I've Enterprise Activated, or reloaded my own account?
Anyone?
   
  (#6 (permalink)) Old
hdawg Offline
BlackBerry Genius
 
hdawg's Avatar
 
Posts: 6,647
Join Date: Aug 2006
Model: hdawg
PIN: port3101.org
Carrier: hdawg
Default 08-18-2009, 12:25 PM

did you ever modify the adminsdholder object?
   
  (#7 (permalink)) Old
msr145 Offline
New Member
 
Posts: 9
Join Date: Aug 2009
Model: 8330
PIN: N/A
Carrier: Verizon
Default 08-18-2009, 02:21 PM

No, and I may not have been clear about the issue. I'm a domain admin just as those who cannot send. The BESAdmin account is not listed as having 'Send As' permissions on my account, yet I have no problem sending. I'm curious as to what might be different about my account. I've read I can modify the adminsdholder object, but wasn't sure if I wanted to go that route. Again, what might be different about my acccount that I don't have a problem? Thanks for your help.
   
  (#8 (permalink)) Old
knottyrope Offline
The Knotty BES A D M I N
 
knottyrope's Avatar
 
Posts: 3,571
Join Date: Jan 2008
Location: Massachusetts
Model: 9700a
OS: 6.0.0.105
PIN: t of blood has been taken
Carrier: AT&T-US with I dee ten tee errors
Default 08-18-2009, 03:45 PM

It might be a random issue for you on why you can send. I have seen it before.

penguin3107 and hdawg did give you a solution to your problem.


BES 4.1.6 MR7, SQL 05, EX03, WES 09 and 10
RTFM? You LIAR!!! Read the FAQ yet?
Know how to use search yet?
Is your DataBase backed up? don't
Now you can sign up for free! Blackberry Expert Support Center
   
  (#9 (permalink)) Old
msr145 Offline
New Member
 
Posts: 9
Join Date: Aug 2009
Model: 8330
PIN: N/A
Carrier: Verizon
Default 08-18-2009, 04:04 PM

I KNOW they gave me a solution. I'm not doubting that, I'm just looking for someone who can give a solid answer on this 'random issue' - jeesh!
   
  (#10 (permalink)) Old
knottyrope Offline
The Knotty BES A D M I N
 
knottyrope's Avatar
 
Posts: 3,571
Join Date: Jan 2008
Location: Massachusetts
Model: 9700a
OS: 6.0.0.105
PIN: t of blood has been taken
Carrier: AT&T-US with I dee ten tee errors
Default 08-18-2009, 04:32 PM

I wish you luck in your findings.


BES 4.1.6 MR7, SQL 05, EX03, WES 09 and 10
RTFM? You LIAR!!! Read the FAQ yet?
Know how to use search yet?
Is your DataBase backed up? don't
Now you can sign up for free! Blackberry Expert Support Center
   
  (#11 (permalink)) Old
hdawg Offline
BlackBerry Genius
 
hdawg's Avatar
 
Posts: 6,647
Join Date: Aug 2006
Model: hdawg
PIN: port3101.org
Carrier: hdawg
Default 08-20-2009, 07:03 AM

Quote:
Originally Posted by msr145 View Post
I KNOW they gave me a solution. I'm not doubting that, I'm just looking for someone who can give a solid answer on this 'random issue' - jeesh!
You've got some issue with active directory ... look there.
   
Closed Thread


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On





Copyright © 2004-2010 BlackBerryFAQ.com, BlackBerryForums.com.
The names RIM © and BlackBerry © are registered Trademarks of Research In Motion Limited.