BlackBerry Forums Support Community               

Closed Thread
 
LinkBack Thread Tools
Old 03-06-2013, 05:40 AM   #1 (permalink)
Thumbs Must Hurt
 
Claidheamhmor's Avatar
 
Join Date: Apr 2009
Model: 9810
PIN: N/A
Carrier: Vodacom
Posts: 52
Post Thanks: 0
Thanked 2 Times in 2 Posts
Default Unable to create users on BES10

Please Login to Remove!

I have a bit of a strange one here that's annoying me terribly.

I've installed BES10 (BDS 6.2) successfully. Port 3101 is open, SRP is connected. We're still on the 60-day trial, and I'm hoping we'll figure out sometime where I can actually buy a server licence (but that's besides the point). Port 443 has been opened too.

When I try to add a user to BES10, I can successfully find the user, but when I add the user, with or without activation password, I get the following error:
The BlackBerry® Administration Service was unable to create the required external authenticator for the user.

Searching for that error yields this page: KB32589-Unable to add specific Active Directory users to BlackBerry Device Service 6.2
After looking at that page, I checked the msExchMasterAccountSid; it exists on our user accounts in our resource domain, but the accounts are disabled, as they should be, and the mailboxes are linked to enabled accounts in our user domain which doesn't have that msExchMasterAccountSid attribute, so in theory, this is not applicable. The only accounts I can create on BES10 are for mailboxes that do not have the msExchMasterAccountSid attribute.

Does anyone have any idea about this?

Our environment:
BES 5.04 working 100% on a different server.
BES10 loaded on a Windows 2012 server on VMWare.
A user domain for user accounts.
A resource domain in a separate forest, where Exchange and mailboxes are hosted. Each mailbox has its own disabled account in the resource domain, and a user account from the user domain has rights to the mailbox.
Exchange 2010.
__________________
Claidheamhmor's BlackBerry Blog
Offline  
Old 03-06-2013, 09:42 AM   #2 (permalink)
Knows Where the Search Button Is
 
AbidingSeraph's Avatar
 
Join Date: Apr 2006
Model: 9850
Carrier: Verizon
Posts: 46
Post Thanks: 3
Thanked 0 Times in 0 Posts
Default Re: Unable to create users on BES10

We are having the exact issue as well. We are running exchange in a resource forest with all accounts disabled (except a few service accounts) too. We have a ticket open with RIM currently for this issue, but they haven't gotten back to us yet, and its been a few days. When I first spoke to RIM about it, they gave me the same kb article and instructed me to remove msExchMasterAccountSid attribute, to which I said "are you crazy"?? They said they will get back with me. I will update you when I hear back.
Offline  
Old 03-06-2013, 03:31 PM   #3 (permalink)
Knows Where the Search Button Is
 
AbidingSeraph's Avatar
 
Join Date: Apr 2006
Model: 9850
Carrier: Verizon
Posts: 46
Post Thanks: 3
Thanked 0 Times in 0 Posts
Default Re: Unable to create users on BES10

Quick question: Does your resource forest have a one, or two way trust with the active user account domain? (Not sure that it matters) Also, does the service account used to install BDS have access to both domains?
Offline  
Old 03-07-2013, 06:37 AM   #4 (permalink)
Thumbs Must Hurt
 
Claidheamhmor's Avatar
 
Join Date: Apr 2009
Model: 9810
PIN: N/A
Carrier: Vodacom
Posts: 52
Post Thanks: 0
Thanked 2 Times in 2 Posts
Default Re: Unable to create users on BES10

Quote:
Originally Posted by AbidingSeraph View Post
Quick question: Does your resource forest have a one, or two way trust with the active user account domain? (Not sure that it matters) Also, does the service account used to install BDS have access to both domains?
I'd appreciate any reportback from RIM.

We have a two-way trust with the resource forest. The computer running BES10 is on the user domain, but BES was installed with an account from the resource domain that has all the appropriate rights on the resource domain.

I wonder if I shouldn't give it rights on the user domain too...
__________________
Claidheamhmor's BlackBerry Blog
Offline  
Old 03-07-2013, 08:01 PM   #5 (permalink)
Talking BlackBerry Encyclopedia
 
Join Date: Feb 2011
Model: 9860
PIN: N/A
Carrier: Virgin Mobile Canada
Posts: 257
Post Thanks: 2
Thanked 3 Times in 3 Posts
Default Re: Unable to create users on BES10

Try this;

Give your BDSAdmin (or whatever you called it) account Administrators access. I have had more success with giving BDSAdmin both Administrator and Domain Users group access.
Offline  
Old 03-08-2013, 05:35 AM   #6 (permalink)
Thumbs Must Hurt
 
Claidheamhmor's Avatar
 
Join Date: Apr 2009
Model: 9810
PIN: N/A
Carrier: Vodacom
Posts: 52
Post Thanks: 0
Thanked 2 Times in 2 Posts
Default Re: Unable to create users on BES10

Found the issue:

In BDS Admin, user Microsoft Active Directory Integration, Manage Microsoft Active Directory Access, I had to edit Active Directory Configuration.

The "Microsoft Active Directory Access" section requires the BDS Admin account details for the resource domain.

The "Microsoft Active Directory Login" section requires the account details on the account/user domain for an account with (presumably) account operator rights.
__________________
Claidheamhmor's BlackBerry Blog
Offline  
Old 03-08-2013, 09:47 AM   #7 (permalink)
Knows Where the Search Button Is
 
AbidingSeraph's Avatar
 
Join Date: Apr 2006
Model: 9850
Carrier: Verizon
Posts: 46
Post Thanks: 3
Thanked 0 Times in 0 Posts
Default Re: Unable to create users on BES10

Thanks for the update: I am still awaiting to hear back from rim, for final update. I am trying to implement your resolution, but unfortunately my BDS admin account only has rights into the resource domain and not the user domain (which I suspect is the problem). This was historically sufficient for BES 5.0 and earlier, but apparently has changed. I guess i will need to wait for RIM to give me the official word so that I can put in the change request to grant the BDS admin account access to both domains.
Offline  
Old 03-11-2013, 07:37 AM   #8 (permalink)
Thumbs Must Hurt
 
Claidheamhmor's Avatar
 
Join Date: Apr 2009
Model: 9810
PIN: N/A
Carrier: Vodacom
Posts: 52
Post Thanks: 0
Thanked 2 Times in 2 Posts
Default Re: Unable to create users on BES10

Quote:
Originally Posted by AbidingSeraph View Post
Thanks for the update: I am still awaiting to hear back from rim, for final update. I am trying to implement your resolution, but unfortunately my BDS admin account only has rights into the resource domain and not the user domain (which I suspect is the problem). This was historically sufficient for BES 5.0 and earlier, but apparently has changed. I guess i will need to wait for RIM to give me the official word so that I can put in the change request to grant the BDS admin account access to both domains.
The BDSAdmin account doesn't necessarily need rights in the user domain; I used an account with rights in the user domain but no rights to the account domain.
__________________
Claidheamhmor's BlackBerry Blog
Offline  
Old 03-25-2013, 09:25 PM   #9 (permalink)
Thumbs Must Hurt
 
Join Date: Jun 2005
Location: Detroit, MI
Model: 9800
Carrier: AT&T
Posts: 68
Post Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: Unable to create users on BES10

Can you be more specific, I am having the same issue, but don't know what to actually change. Thanks.
Offline  
Old 03-26-2013, 01:52 PM   #10 (permalink)
Knows Where the Search Button Is
 
AbidingSeraph's Avatar
 
Join Date: Apr 2006
Model: 9850
Carrier: Verizon
Posts: 46
Post Thanks: 3
Thanked 0 Times in 0 Posts
Default Re: Unable to create users on BES10

It depends on your environment...do you have an exchange resource forest? If so does the service account with which you installed BDS have permissions in both the resource forest as well as your user domain. Using a service account that had permissions into both domains solved this issue for me. This was the case for me, because there is only a one way trust between domains, i suppose if there was a two way trust, you wouldn't necessarily need permissions into both. I hope this helps you.
Offline  
Old 04-15-2013, 08:59 AM   #11 (permalink)
New Member
 
Join Date: Feb 2013
Model: Z10
PIN: N/A
Carrier: Vodafone UK
Posts: 5
Post Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: Unable to create users on BES10

I have had the similar issue during the initial setup and then i "un-ticked - Associated external account" tab under the Mailbox rights which solved that issue!
Offline  
Old 04-30-2013, 04:35 AM   #12 (permalink)
Knows Where the Search Button Is
 
Join Date: Nov 2007
Model: 9780
PIN: N/A
Carrier: ITC
Posts: 22
Post Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: Unable to create users on BES10

Hi guys, I am having the same issue, i have tried this "In BDS Admin, user Microsoft Active Directory Integration, Manage Microsoft Active Directory Access, I had to edit Active Directory Configuration.

The "Microsoft Active Directory Access" section requires the BDS Admin account details for the resource domain.

The "Microsoft Active Directory Login" section requires the account details on the account/user domain for an account with (presumably) account operator rights."

But nothing change, I'm actually reinstalling everything from 0.

I will let you know.

in additional I used the besadmin account for the first install. Now for the new installation, I created also a new user with a mailbox.

Last edited by shox974 : 04-30-2013 at 04:37 AM.
Offline  
Old 04-30-2013, 05:12 AM   #13 (permalink)
Knows Where the Search Button Is
 
Join Date: Nov 2007
Model: 9780
PIN: N/A
Carrier: ITC
Posts: 22
Post Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: Unable to create users on BES10

So new install all services up, new sql database called BDS all is UP.
Same problem with one user impossible to add but I tested to add other users and everything is ok.
I checked the AD account of the user and he has an information in the attribute of msExchMasterAccountSid
referring to this kb KB32589-Unable to add specific Active Directory users to BlackBerry Device Service 6.2
Someone knows the effect of cancelling this information ?

Last edited by shox974 : 04-30-2013 at 05:19 AM.
Offline  
Old 04-30-2013, 09:26 AM   #14 (permalink)
BlackBerry Elite
 
knottyrope's Avatar
 
Join Date: Jan 2008
Location: Massachusetts
Model: Z30
OS: 10.2.1
PIN: t of blood has been taken
Carrier: AT&T-US with I dee ten tee errors
Posts: 6,637
Post Thanks: 264
Thanked 269 Times in 255 Posts
Default Re: Unable to create users on BES10

is user a mamber of any groups in AD?

Also is user set to inherit permissions in Exchange?
__________________
irony : many old timer posters have de-evolved into the trolls they once fought
I am on http://supportforums.blackberry.com
BES 10 running sweet for my Z30, Z10 and Q10
Online  
Old 04-30-2013, 02:07 PM   #15 (permalink)
Knows Where the Search Button Is
 
Join Date: Nov 2007
Model: 9780
PIN: N/A
Carrier: ITC
Posts: 22
Post Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: Unable to create users on BES10

I solved my problem the mailbox of the user was a link mailbox, I used this KB How to Convert a Mailbox: Exchange 2007 Help to convert it as a standard mailbox and per miracle the attribute msExchMasterAccountSid disappeared. After this I was able to add my user and activate his Z10 and his playbook on his account without problem.

Thanks for your help.

Cheers.
Offline  
Closed Thread


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads for: Unable to create users on BES10
Thread Thread Starter Forum Replies Last Post
Unable to create a Blackberry ID sanste General BlackBerry Discussion 1 11-02-2010 06:25 PM
Max amount of users you can create in one go? dodgydane BES Admin Corner 2 09-14-2010 02:33 PM
unable to search new domain users uchytilian BES Admin Corner 4 09-10-2009 08:56 PM
I.M Security zerog46 Aftermarket Software 11 06-09-2008 07:29 PM





Copyright © 2004-2014 BlackBerryForums.com.
The names RIM © and BlackBerry © are registered Trademarks of BlackBerry Inc.