Ureader.com  
Microsoft software help and Community
   home   |   control panel login   |   archive   |  
 
Exchange
2000.active.directory
2000.admin
2000.announcements
2000.app.conversion
2000.applications
2000.clients
2000.clustering
2000.connectivity
2000.development
2000.documentation
2000.general
2000.information.store
2000.interop
2000.kms
2000.misc
2000.protocols
2000.realtime.collabo.
2000.setup
2000.transport
2000.win2000
admin
application.conversion
applications
clients
clustering
connectivity
design
development
misc
mobility
setup
tools
  
 
date: Thu, 2 Feb 2006 07:31:59 -0800,    group: microsoft.public.exchange2000.active.directory.integration        back       


Remove old SID permissions   
We have a lot of old outdated SIDs with full mailbox access permissions to 
multiple mailboxes.  Typically, these are users who had access to mailboxes 
other than their own but have left the company.  Is there a way to remove all 
invalid SIDs from all our mailbox's in one fell swoop?
date: Thu, 2 Feb 2006 07:31:59 -0800   author:   TONY-LCG

Re: Remove old SID permissions   
You would have to write a script that munged through all of the user objects 
cleaning the permissions up.

--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Edition
www.joeware.net


---O'Reilly Active Directory Third Edition now available---

         http://www.joeware.net/win/ad3e.htm



TONY-LCG wrote:
> We have a lot of old outdated SIDs with full mailbox access permissions to 
> multiple mailboxes.  Typically, these are users who had access to mailboxes 
> other than their own but have left the company.  Is there a way to remove all 
> invalid SIDs from all our mailbox's in one fell swoop?
date: Sat, 04 Feb 2006 15:28:21 -0500   author:   Joe Richards [MVP]

Re: Remove old SID permissions   
Thanks Joe,
I found a script on the MS knowledge base for adding permissions, but I 
can't find one to take these permissions away.  Again, If I have a user who 
has full mailbox rights to another mailbox, how can I build a script that 
will remove their rights?

Thanks,
Tony

"Joe Richards [MVP]" wrote:

> You would have to write a script that munged through all of the user objects 
> cleaning the permissions up.
> 
> --
> Joe Richards Microsoft MVP Windows Server Directory Services
> Author of O'Reilly Active Directory Third Edition
> www.joeware.net
> 
> 
> ---O'Reilly Active Directory Third Edition now available---
> 
>          http://www.joeware.net/win/ad3e.htm
> 
> 
> 
> TONY-LCG wrote:
> > We have a lot of old outdated SIDs with full mailbox access permissions to 
> > multiple mailboxes.  Typically, these are users who had access to mailboxes 
> > other than their own but have left the company.  Is there a way to remove all 
> > invalid SIDs from all our mailbox's in one fell swoop?
>
date: Mon, 27 Feb 2006 11:39:15 -0800   author:   TONY-LCG

Re: Remove old SID permissions   
Look at

http://support.microsoft.com/kb/310866/

and also look at

http://msdn.microsoft.com/library/default.asp?url=/library/en-us/adsi/adsi/iadsaccesscontrollist_removeace.asp?frame=true


--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Edition
www.joeware.net


---O'Reilly Active Directory Third Edition now available---

         http://www.joeware.net/win/ad3e.htm



TONY-LCG wrote:
> Thanks Joe,
> I found a script on the MS knowledge base for adding permissions, but I 
> can't find one to take these permissions away.  Again, If I have a user who 
> has full mailbox rights to another mailbox, how can I build a script that 
> will remove their rights?
> 
> Thanks,
> Tony
> 
> "Joe Richards [MVP]" wrote:
> 
>> You would have to write a script that munged through all of the user objects 
>> cleaning the permissions up.
>>
>> --
>> Joe Richards Microsoft MVP Windows Server Directory Services
>> Author of O'Reilly Active Directory Third Edition
>> www.joeware.net
>>
>>
>> ---O'Reilly Active Directory Third Edition now available---
>>
>>          http://www.joeware.net/win/ad3e.htm
>>
>>
>>
>> TONY-LCG wrote:
>>> We have a lot of old outdated SIDs with full mailbox access permissions to 
>>> multiple mailboxes.  Typically, these are users who had access to mailboxes 
>>> other than their own but have left the company.  Is there a way to remove all 
>>> invalid SIDs from all our mailbox's in one fell swoop?
date: Sat, 18 Mar 2006 23:15:49 -0500   author:   Joe Richards [MVP]

Google
 
Web ureader.com


    COPYRIGHT 2007, YARDI TECHNOLOGY LIMITED, ALL RIGHT RESERVE  |   contact us