XADM: Certain Administrative Accounts and System Accounts Do Not Have Proxy Addresses (257803)



The information in this article applies to:

  • Microsoft Exchange 2000 Server

This article was previously published under Q257803

SUMMARY

All accounts that belong to "Administrators" or "Domain Admins" lose the "inheritance bit" on the Security Descriptor. This is a design element of Microsoft Windows 2000 that is intended to prevent hackers from playing with security and inappropriately increasing their permissions to the level of administrator. On the Security tab of the Group account's properties page you can see that the flag is unchecked.

MORE INFORMATION

If these accounts need to have proxy addresses generated, click to select the Allow inheritable permissions from parent to propagate to this object check box on the Group account's properties page.

Modification Type:MinorLast Reviewed:4/25/2005
Keywords:kbinfo KB257803