BlackBerry Forums Support Community
              

Closed Thread
 
Thread Tools
Old 12-24-2008, 01:18 PM   #1
SmoothRunnings
Talking BlackBerry Encyclopedia
 
Join Date: May 2007
Location: Toronto, Canada
Model: 9700
OS: 5.0.0.423
PIN: 21B694E3
Carrier: Virgin Mobile Canada
Posts: 396
Default BESAdmin permissions

Please Login to Remove!

Under Exchange 2007 SP1, does the BESAdmin user itself need to also have the "xxx8211;accessrights ExtendedRight xxx8211;extendedrights Send-As, Receive-As, ms-Exch-Store-Admin"?

Do the users in the Exchange organization who need to have the BESAdmin user added to their Security tab need the same rights added to the BESAdmin user?

I am looking carefully at the 'Get-MailboxServer | ' commands in the Exchange installation notes and notice that Microsoft has made a few changes to the commands after the "|" since Service Pack 1 for Exchange 2007 that could make it easier to getting BES installed in an Exchange 2007 SP1 environment.

Adding '-Identity "user name"' to the Add-ADPermissions command will add the "-User BESAdmin" and off the rights to the "user name", this could replace step 4 of the tutorial if it's possible to script the command to assing BESAdmin and its righes to the users currently in their Exchange organization.

Removing BESAdmin from the Add-ExchangeAdministrator command and adding '-Identity <mail_server_name>\BESAdmin' at the end of the command completely removes the need for having the "Get-MailboxServer' at all.. Not to mention that entire command listed in the tutorial doesn't work in Exchange 2007 SP1 under SBS 2008.

Andrew

Last edited by SmoothRunnings; 12-24-2008 at 01:26 PM..
Offline  
Old 12-25-2008, 12:46 AM   #2
CarterTan
Knows Where the Search Button Is
 
CarterTan's Avatar
 
Join Date: Oct 2008
Location: Singapore
Model: 9000
PIN: 20959bbb
Carrier: M1
Posts: 30
Default

In Active Directory, the BESAdmin needs to have the Send as permissions applied in the Domain Level or OU level where all the BlackBerry users are located.

As for Exchange permissions:
1. Send as
2. Receive as
3. Administer Information Store

This is required so that the BESAdmin account will send, receive and administer information store on behalf of all the BlackBerry users.

Exchange-View-Only administrator rights is required so that there will not be any limited MAPI connections for the BESAdmin account.

BTW, installing BES on SBS2008 is not supported at the moment for BES but installing BES in an 2008 AD environment is supported.
__________________
Hit me on my BlackBerry



MCSE, MCITP Enterprise Messaging Administrator, MCITP Enterprise Administrator
Offline  
Old 01-27-2009, 01:08 PM   #3
aesajithmu
New Member
 
Join Date: Jan 2009
Model: 7100T
PIN: N/A
Carrier: ETISALAT
Posts: 1
Default

If BESAdmin user has permission to read /send and recieve, does it mean using the BESAdmin - the admin could access /read mail of these mailboxes serviced by Blackberry ?
Or is there a way to secure with a two level authentication (say by using user's privledges) ???
Offline  
Old 01-27-2009, 01:20 PM   #4
TargetIT
CrackBerry Addict
 
Join Date: Jan 2008
Model: 9700
PIN: N/A
Carrier: Rogers
Posts: 709
Default

Quote:
Originally Posted by aesajithmu View Post
If BESAdmin user has permission to read /send and recieve, does it mean using the BESAdmin - the admin could access /read mail of these mailboxes serviced by Blackberry ?
Or is there a way to secure with a two level authentication (say by using user's privledges) ???
Yes, they can read all the email. You prevent that by getting the BES up and running and then not using the BESAdmin account any further, at least not interactively.

Last edited by TargetIT; 01-27-2009 at 01:21 PM..
Offline  
Old 01-28-2009, 09:01 AM   #5
stuwhite
Feeling Blue, Bigly ;->
 
stuwhite's Avatar
 
Join Date: Jan 2007
Location: U to the K
Model: 9000
PIN: 3, it's the magic number
Carrier: Most of them, it's a Global Village man!
Posts: 1,273
Default

Quote:
Originally Posted by TargetIT View Post
Yes, they can read all the email. You prevent that by getting the BES up and running and then not using the BESAdmin account any further, at least not interactively.
Absolutely. One thing you don't do is share your besadmin password . As TargetIT says, once up and running you shouldn't need it for any day to day stuff. Make sure your besadmin account doesn't have OWA access .
__________________
I was a BES and Exchange admin once.
Then my world turned Blue.
Offline  
Old 01-28-2009, 05:24 PM   #6
knottyrope
BlackBerry Elite
 
knottyrope's Avatar
 
Join Date: Jan 2008
Location: Massachusetts
Model: DT60
OS: 123456789
PIN: t of blood has been taken
Carrier: AT&T-US with I dee ten tee errors
Posts: 7,325
Default

Quote:
Originally Posted by stuwhite View Post
Absolutely. Make sure your besadmin account doesn't have OWA access .
Please clarify on why.
__________________
I had to fall
To lose it all
But in the end
It doesn't even matter

Rocking the Motion with out lotion.
Offline  
Old 01-28-2009, 06:35 PM   #7
stuwhite
Feeling Blue, Bigly ;->
 
stuwhite's Avatar
 
Join Date: Jan 2007
Location: U to the K
Model: 9000
PIN: 3, it's the magic number
Carrier: Most of them, it's a Global Village man!
Posts: 1,273
Default

Wirelessly posted

Quote:
Originally Posted by knottyrope
Quote:
Originally Posted by stuwhite View Post
Absolutely. Make sure your besadmin account doesn't have OWA access .
Please clarify on why.
Coz if you have the same idiotic setup I inherited, you can use owa and BESadmin login to read any mail straight off and send as if you try hard enough ;->
__________________
I was a BES and Exchange admin once.
Then my world turned Blue.
Offline  
Old 01-28-2009, 06:51 PM   #8
TargetIT
CrackBerry Addict
 
Join Date: Jan 2008
Model: 9700
PIN: N/A
Carrier: Rogers
Posts: 709
Default

True, but that assumes you have the password for the account. If that is widely known, then you got other problems.
Offline  
Old 01-29-2009, 05:18 AM   #9
stuwhite
Feeling Blue, Bigly ;->
 
stuwhite's Avatar
 
Join Date: Jan 2007
Location: U to the K
Model: 9000
PIN: 3, it's the magic number
Carrier: Most of them, it's a Global Village man!
Posts: 1,273
Default

Quote:
Originally Posted by TargetIT View Post
True, but that assumes you have the password for the account. If that is widely known, then you got other problems.
Agreed but I think it's not uncommon for a few admins to know the password. In these days of SOX we are forced to share this info at some levels, so we need to guard against anyone stumbling on the sheer power of the account.
__________________
I was a BES and Exchange admin once.
Then my world turned Blue.
Offline  
Closed Thread



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


Motorola 68060 68EC060 MC68EC060RC75 CPU / Processor AMIGA unused, new USA stock picture

Motorola 68060 68EC060 MC68EC060RC75 CPU / Processor AMIGA unused, new USA stock

$69.99



6500/1 A 6502 VARIENT CPU COMMODORE USE IN AMIGA KB & 1520 PLOTTER NMOS NCR NOS picture

6500/1 A 6502 VARIENT CPU COMMODORE USE IN AMIGA KB & 1520 PLOTTER NMOS NCR NOS

$5.89



New Greaseweazle V4.1 USB Floppy Adapter Flux Reader Writer Amiga PC Case 1598 picture

New Greaseweazle V4.1 USB Floppy Adapter Flux Reader Writer Amiga PC Case 1598

$36.64



New Greaseweazle V4.1 USB Floppy Adapter Flux Reader Writer Amiga Atari ST 1591 picture

New Greaseweazle V4.1 USB Floppy Adapter Flux Reader Writer Amiga Atari ST 1591

$28.72



Mitsubishi FR-A540-0.75K-NA AC DRIVE INVERTER 1 HP 380-480 VAC 50/60 HZ 4.1 AMP  picture

Mitsubishi FR-A540-0.75K-NA AC DRIVE INVERTER 1 HP 380-480 VAC 50/60 HZ 4.1 AMP

$649.99



Radiomatic Flo-One Beta Radio-Chromatography Detector A-500 Model A525 [E2FL] picture

Radiomatic Flo-One Beta Radio-Chromatography Detector A-500 Model A525 [E2FL]

$245.00







Copyright © 2004-2016 BlackBerryForums.com.
The names RIM © and BlackBerry © are registered Trademarks of BlackBerry Inc.