Could be related to the Exchange server changes by microsoft that affected our Blackberry. Although, you seem to have slightly additional issues - here is the solution found on another forum. Also, look for the October 31st Microsoft update related to this. If the user once had protected group membership (domain admin, etc.) and now does not, you need to go in and re-check by hand for each user the "inherit permissions" selection, otherwise they will not retain the security settings you add in the solution below.
Here is the first part of what worked for us, found on pinstack.com. Part two is above.
=========================
Ok Folks,
After struggling with both Microsoft and Blackberry, here is the low down.
Exchange 2003 SP 2 changed the way send as work. So Blackberry Service account got locked out.
Solution:
Go to the AD Users & Computer.
Right Click on the domain, go the security tab,
select Advanced
Add the Blackberry service account
From the Applies Onto list, click User Objects select user objects
Give snd as permisions
Replicated if you have other ADs
Note:
If you can reboot your domain server and exchange servers, you donot have to wait and 1 hour to find out if it works.
If you find that the send as permision disappers from some users; especialy administrator type accounts, run
dsacls "cn=adminsdholder,cn=system,dc=mydomain,dc=com " /G "MYDOMAIN\BlackBerrySA :CA;Send As"
Note: In this command, MYDOMAIN\BlackBerrySA is a placeholder for the name of the BlackBerry Service account. Change it to represent the proper account name in use for this domain, also correct the MYDOMAIN portion to match the real local domain. Make sure that you do not add a space between BlackBerrySA and ":CA". Don't forget to replace the mydomain and com with the proper user local domain.
Also,
If you have a migrated AD, some accounts will not work. IF so go to the properties page of the user in AD.
In the Security tab, Advanced
Make sure to check the box that says "allow inheritaed permisions to propergate..."
If this done correctly, you can see from the user properties (of an effected person), Security/advanced tab/alonf the Blackberry service account/in the column for Inherited From;
;It will have the domain infomation there "DC=yourdomain,DC=COM"
This should fix every ones problems. Micorsoft has promissed me that they will update the article to relflect this information.
Sorry I could not reply on MOnday when I discovered this with MS.
|