BESAdmin is not a member of any group other than "Domain Users". Looking at the advanced permissions shows no "deny"s for the things it needs.
BESAdmin does NOT have full Exchange rights. We can try that but if that's what it takes it's not going to fly in production.
We've always been able to use BESAdmin on the BES to view the Admin Groups and browse right down to the mailboxes.
I'm wondering if I need to set up a play domain and exchange server from scratch and see if we can get it to work. It'll probably work fine though.
|