Go Back   BlackBerry Forums > BlackBerry Enterprise Server > Microsoft Exchange

Reply
 
LinkBack Thread Tools Display Modes
  #11 (permalink)  
Old 17-07-2007, 05:10 PM
Member
 
Join Date: Jun 2007
Posts: 9
Quote:
Originally Posted by GaryCutri View Post
Re: AdminSDHolder

The AdminSDHolder container is a special container object inside of the System container in Active Directory. The basic function of AdminSDHolder is exactly what it says it does - it holds the Access Control List (ACL) for every admin account. This container is just a template. Once every hour, the DC that holds the PDC Emulator role goes through every account that is in built-in Administrators group and checks the ACL for each user object. It compares this ACL to that of the AdminSDHolder container and if any Access Control Entry (ACE) is different, it rips out the old ACL and copies the ACL from the AdminSDHolder over to it.

The purpose of AdminSDHolder is to prevent against a specific attack scenario. Active Directory is extremely flexible down to it' s most granular level. Because of this, a user can have write access to anything inside of a specific OU. If an admin account is moved to an OU that a non-admin has rights to, he could give himself privileged access to the admin account. AdminSDHolder tries to prevent this from happening by continuously refreshing the ACL on an admin account.
------------

in my case i need to have domain admins rights associated with my AD profile. How do i keep my admin righst and not loose my BESadmin permissions???
Reply With Quote
  #12 (permalink)  
Old 17-07-2007, 09:15 PM
BESadmin's Avatar
Administrator
 
Join Date: Aug 2006
Posts: 1,736
Quote:
Originally Posted by cs-sysadmin View Post
------------

in my case i need to have domain admins rights associated with my AD profile. How do i keep my admin righst and not loose my BESadmin permissions???
Please refer to the following link to correct your issue:
Send As Permissions when Domain Admin
Reply With Quote
Reply

Bookmarks

Tags
red x , send as , unable to submit message , unlisted message error

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT +11. The time now is 02:44 AM.

Copyright ©2006 - 2008 BLACKBERRYFORUMS - RIM and Blackberry are Registered Trademarks of Research In Motion


Search Engine Friendly URLs by vBSEO 3.2.0