Re: [ActiveDir] OT: File Server Permissions Design Question

2006-10-13 Thread Mark Parris
Mmm- I didn't read the question properly. Sorry. Mark Mark Parris Base IT Ltd Active Directory Consultancy Tel +44(0)7801 690596 -Original Message- From: Grillenmeier, Guido [EMAIL PROTECTED] Date: Thu, 12 Oct 2006 23:04:17 To:ActiveDir@mail.activedir.org

Re: [ActiveDir] OT:Exchange/outlook auth question

2006-10-13 Thread Tom Kern
The i'm curious why Exchange won't let me change the perms on a PF through Outlook when logged into that user's mailbox but logged into the domain as a Exchange Full Admin. If i put the mailbox enabled user account into the Exchange full admin group, then it works. What am I not seeing here?

RE: [ActiveDir] OT:Exchange/outlook auth question

2006-10-13 Thread joe
Is it doing it and then getting changed as you mention or is it not doing it? When you put the user in the full admin group are you then logging on as the user or are you logging on as the other user accessing the first user's mailbox? This could be something specific to public folders. The

Re: [ActiveDir] OT: File Server Permissions Design Question

2006-10-13 Thread Al Mulnick
As someone who's currently battling token size issues (migration and legacy issues), I can vouch for that approach as well. There really is no great single method that will fit everyone unfortunately. One thing that seems a pretty good idea is to ensure that resources are acl'd for the largest

RE: [ActiveDir] OT: File Server Permissions Design Question

2006-10-13 Thread McClure, David (MED US)
The magic number (ie, the number of unique SIDs that a token can hold) is limited to 1000 by design (http://support.microsoft.com/kb/275266/). Once you get above 1000, you can't logon at all, period. The best way I can think of to evaluate the complexity and nesting of your group structure

Re: [ActiveDir] OT: File Server Permissions Design Question

2006-10-13 Thread Al Mulnick
Good point but not always the case, for what it's worth. The problem can also manifest itself as not able to logon to some (random) resources as well. Very tricky when in that state. Topology and architecture make a big difference here as well. There's also some tools such as ntdsutil

[ActiveDir] SBS 2003 and exchange full vs on diff machine

2006-10-13 Thread Quatro Info
Hi all, Easy question i thought, but cant find a thing about it; is it possible to have a second win2k3 server with exchange 2003 full version next to a sbs2k3 server? Thx for your input. Jorre List info : http://www.activedir.org/List.aspx List FAQ: