Hello,
I recently started working for a company that has made MANY changes in their IT department over the last 6 months. Many of the people that initially setup a number of the systems we use are no longer here, for good reason. I am only a help desk technician, but they have put me fully in charge of the Blackberries, from user training to BES administration. The previous person in charge of the BES installed everything to run as the administrator account. As we all know this is a VERY bad idea. The domain administrative account used for the BES is the same account used for every other server function on every other server. Initially we were having an issue with the calendars not synchronizing. Any calendar request added to the Blackberry would not add to our Exchange server. The log for an event would look similar to the following:
Code:
[40700] (04/19 15:07:48):{0x19F8} {HelpDesk@domain.com} Receiving packet from device, size=358, TransactionId=-1188106255, Tag=404525, content type=CMIME, cmd=0x3
[30112] (04/19 15:07:48):{0x19F8} {HelpDesk@domain.com} Receiving message from device, RefId=457044663, Tag=404525, TransactionId=-1188106255
[40000] (04/19 15:07:48):{0x19F8} CDO helper 04e1dc48 is not in memory
[40000] (04/19 15:07:48):{0x19F8} Starting new CDO helper 04e1dc48
[40574] (04/19 15:07:48):{0x1D44} CDO helper 04e1dc48 started
[30001] (04/19 15:07:51):{0x1D44} CDOCalendar::Initialize - Code = 80040705, WCode = 0505, Code meaning = IDispatch error #1285,
[30002] (04/19 15:07:51):{0x1D44} Server = domainbe, Mailbox = /o=DOMAIN/ou=First Administrative Group/cn=Recipients/cn=Help Desk07229329 Description = You do not have permission to log on. [Microsoft Exchange Server Information Store - [MAPI_E_FAILONEPROVIDER(8004011D)]].
[30180] (04/19 15:07:51):{0x1D44} {Help Desk07229329} CDOCalendar::Initialize - Error in call m_spCalendarFolder = m_spCDOSession->GetDefaultFolder.
I have (I hope accurately) diagnosed this calendar issue as a rights issue because the domain administrative account used to run the BES does not have the necessary rights. The domain administrative account has inherited the rights of “deny – send as” and “deny – receive as.” These rights cannot be changed. The only solution I can think of is to change/reinstall the BES so that it is running everything under a seperate account.
We are a small organization of only about 25 Blackberries, but they are scattered around the country and very few of them reside here where the BES is. I think I need a solution to get the BES running under a new account that I can assign “allow – send as” and “allow – receive as” permissions to. Ideally this solution would not require me to have physical access to every Blackberry to set them back up on the new server, and would have as little user impact as possible. Any suggestions would be greatly helpful. I have never set up a BES before, and this is my first time administering Blackberries. If anyone could point me to some instructions on resolving this with low user impact, I would greatly appreciate it.
Thank you,
Shawn