Members of the Mobility Administrators Group Cannot Enable Users for Wireless Access (297897)



The information in this article applies to:

  • Microsoft Mobile Information 2001 Server

This article was previously published under Q297897

SYMPTOMS

By default, if you are only a member of the Microsoft Mobility Administrators group, you cannot enable users for Mobile Information Server wireless access in any security topology other than the Integrated topology.

CAUSE

This behavior occurs because in topologies other than the Integrated topology, wireless accounts must be created. A wireless account is an account that includes the user name and a "-W" suffix, or a new account in an auxiliary domain or forest. By default, the Mobility Administrators group does not have permissions to create new accounts.

RESOLUTION

If you want to enable the Mobility Administrators group to create the necessary wireless accounts, add the Mobility Administrators group to the Account Operators built-in group in the domain where you want to create the wireless accounts. The domain where you add these accounts is dependant on the security topology that is being used.

The following list describes the possible topologies and the domains where the Mobility Administrators group should be added to the Account Operators group:
  • If you are using wireless accounts with a "-W" suffix in the same domain, add the Mobility Administrators group to the Account Operators group of the current domain.
  • If you are using an auxiliary domain, add the Mobility Administrators group to the Account Operators group of the auxiliary domain.
  • If you are using an auxiliary domain in an auxiliary forest, add the Mobility Administrators group to the Account Operators group of the auxiliary domain in the auxiliary forest.

Modification Type:MinorLast Reviewed:4/25/2005
Keywords:kbprb KB297897