BlackBerry Forums Support Community
              

Closed Thread
 
Thread Tools
Old 03-26-2010, 05:59 PM   #1
chrislehr
Knows Where the Search Button Is
 
Join Date: Jan 2007
Model: none
Carrier: ATT
Posts: 17
Default BES + Exchange 2010 (and 2k7 too) permissions

Please Login to Remove!

So, I have often wondered this, and never had it be a "problem" until now.

In the BES 5.x instructions, there is this step:
Type Add-ADPermission -InheritedObjectType User -InheritanceType Descendents -ExtendedRights Send-As -
User "BESAdmin" -Identity "CN=Users,DC=<domain_1>,DC=<domain_2>,DC=<domain_3 >"


Now, these instruction work, as long as you have all your users in the "Users" CN. At my employer, this needed to be replaced with OU=Employees instead, because that is where all the users are.

Now, I have a customer who has about 35 OU's off their root. Now, I can audit, and specifically set this permission at each OU.. I can also script and loop through the root OU's applying this permission..

However, if the customer add's another Root OU, they would need to re-run this permission. That's acceptable to some customers, but not all.

And if you try to run the above and apply to just DC=domain,DC=com, it errors out in a pretty non-descriptive manner.

Any feedback welcome.
Chris
Offline  
Old 04-01-2010, 06:51 PM   #2
Wiseman13
Knows Where the Search Button Is
 
Join Date: Mar 2008
Model: 8830
PIN: N/A
Carrier: Alltel
Posts: 22
Default

The easiest fix, from the outside looking in, would be to create a OU at the root called something like "Employees" and put all the other root OUs under that Employee OU, this makes things cleaner overall I would think, and solves your issue as you only need to run the permissions for the Employees OU.

Just a thought, not really a "fix"
Offline  
Old 04-02-2010, 03:07 PM   #3
chrislehr
Knows Where the Search Button Is
 
Join Date: Jan 2007
Model: none
Carrier: ATT
Posts: 17
Default

Quote:
Originally Posted by Wiseman13 View Post
The easiest fix, from the outside looking in, would be to create a OU at the root called something like "Employees" and put all the other root OUs under that Employee OU, this makes things cleaner overall I would think, and solves your issue as you only need to run the permissions for the Employees OU.

Just a thought, not really a "fix"
Yea, I thought of offering that as well, but instead I just issued the command 40 times, and told the customer they would need to add the line for any new OU's as well. Wish this could be applied at the domain level.
Offline  
Closed Thread



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


Moxa NPort 5210A - 2 Ports Device Server, 10/100M Ethernet, RS-232, DB9 Male,... picture

Moxa NPort 5210A - 2 Ports Device Server, 10/100M Ethernet, RS-232, DB9 Male,...

$74.79



NEW Fujitsu TX100 S3 Server Intel Xeon E3-1220v2 3.1GHz 4GB 1TB NIB RAID 0,1,10 picture

NEW Fujitsu TX100 S3 Server Intel Xeon E3-1220v2 3.1GHz 4GB 1TB NIB RAID 0,1,10

$249.99



EMC2 HPE-S HPES Server picture

EMC2 HPE-S HPES Server

$465.00



Server - 92020 - Double Dip Server picture

Server - 92020 - Double Dip Server

$348.84



Server SE-SS 07020 Server Express Single Drop-In - NEW - COMPLETE - Genuine OEM picture

Server SE-SS 07020 Server Express Single Drop-In - NEW - COMPLETE - Genuine OEM

$199.99



DIGI EtherLite 160 16-Port Terminal Server,PN: (1P)50000986-01 P picture

DIGI EtherLite 160 16-Port Terminal Server,PN: (1P)50000986-01 P

$260.00







Copyright © 2004-2016 BlackBerryForums.com.
The names RIM © and BlackBerry © are registered Trademarks of BlackBerry Inc.