09-17-2008 01:41 PM
I just foundout somethign interesting. It is working for everyone accept for those who are in the Administrators group. What do i need to do? I have tried to follow some guides, but i have had no success and i allowed time for systems to propogate.
09-17-2008 01:44 PM
the fix is in the thread i posted, if you look closely.
2. make sure that this account is not a member of admistrators group by clicking on member of tab, if they are follow this work around first
Right-click on system container in AD, and then click, properties , Click Advanced, Click to select the Allow inheritable permissions to propagate to this object and all child objects check box , Click OK, and then click Close
3. after you are done with above step, right click on the affected user in AD and go to options and then go to security tab and click on advanced and in the new window make sure besadmin is listed with send as permission, if not add besadmin with a send as permission.
also make sure to put a check in the box on -allow inheritable permissions to propagate permissions from parent to child........
09-17-2008 01:45 PM
You need to remove the users from the groups in question ... it'd be good to be following the principle of least privilege too.
09-17-2008 01:56 PM
I am reconfiguring my permissions to see if it works. I have removed myself from Administrators group.
What is wierd is that one of the users is not in Administrators group directly but he is in the Domain Admins security group which is in the Administrators group, and it is working fine. lol. Crazy!
09-17-2008 02:17 PM
09-17-2008 02:18 PM
wait 2 hours ... you need for the Exchange / AD permissions cache to flush.