Article ID: 316047 - Last Review: February 27, 2007 - Revision: 2.5 XADM: Addressing Problems That Are Created When You Enable ADC-Generated Accounts
This article was previously published under Q316047 On This PageSUMMARY
This article provides information about disabled accounts that the Active Directory Connector (ADC) creates and describes how to enable those disabled accounts.
MORE INFORMATIONGeneral Information About ADC-Created Disabled AccountsIn general, you should not enable the disabled accounts that the Exchange 2000 ADC creates, and then use those accounts to log on. The ADC creates these accounts only to serve as placeholders, to represent mailboxes that are replicated from the Microsoft Exchange Server 5.5 directory. The ADC creates a disabled user in Active Directory for several reasons:
The Exchange information store uses several Active Directory attributes to calculate permissions when you try to gain access to public folders and delegate mailboxes. Exchange 2000 information store access control lists (ACLs) are based on Security Identifiers (SID). This differs from Exchange Server 5.5, which uses Exchange Server 5.5 distinguished names for ACLs. Because of this difference, the information store must sometimes do conversions from a distinguished name to a SID and from a SID to a distinguished name. The Microsoft Outlook permissions dialog boxes also expect to use ACLs that are based on the distinguished name. The Active Directory attributes that the information store uses to calculate permissions are:
If disabled accounts do not have the msExchMasterAccountSID attribute set, you may receive the following event message in the Application log:
Event Type: Warning
For additional information about how to properly set the msExchMasterAccountSID attribute to resolve these event messages in the Application log, click the article number below to view the article in the Microsoft Knowledge Base:
Event Source: MSExchangeIS Event Category: General Event ID: 9548 Description: Disabled user /o=Microsoft/ou=AdminGroup/cn=Recipients/cn=Alias does not have a master account SID. Please use Active Directory MMC to set an active account as this user's master account. 278966
(http://support.microsoft.com/kb/278966/
)
You cannot move or log on to an Exchange resource mailbox
Disabled account permissions are calculated by using the msExchMasterAccountSID value, instead of the actual SID value of the placeholder account. This is so that the user can continue to log on to the preexisting Windows NT 4.0 domain security context and still be granted rights to the user's Exchange 2000 objects.Accounts that are created in Active Directory do not have the msExchMasterAccountSid attribute. Such accounts rely on their own security context (objectSID or sIDHistory) to be granted permissions in Exchange 2000 information store ACLs. After a disabled account that the ADC created is enabled in Active Directory, two conflicting security contexts suddenly exist that may be examined in various circumstances. For example, when you open the permissions dialog box for a public folder, the information store must convert the SID-based ACL that is held on the folder to a distinguished name-based ACL for Outlook to use. If a user who was granted permissions on that folder is matched on the msExchMasterAccountSID attribute, but the account is an enabled account, the information store cannot properly resolve the SID in the ACL to a legacyExchangeDN attribute. Instead of displaying the proper user's name, the information store displays "NT User:Domain\User". NOTE: If you want to use the Active Directory Migration Tool to import the SidHistory values, you may also want to modify the account samAccountName values on the ADC-created accounts before you start these steps. This ensures that when you run the Active Directory Migration Tool, the samAccountName values of the existing disabled users do not conflict with the newly migrated accounts. Enabling and Removing ADC-Created Disabled AccountsMicrosoft does not recommend that you enable the disabled accounts that are generated by the ADC. However, if there is a critical business requirement that requires you to enable them, follow these instructions to enable and to use the ADC-created disabled accounts:
Removing the "msExchMasterAccountSID" AttributeYou can remove the msExchMasterAccountSID attribute two different ways:
309222
(http://support.microsoft.com/kb/309222/
)
The Active Directory Cleanup Wizard sets the "msExchMasterAccountSID" attribute on the enabled users in Exchange 2000
| Other Resources Other Support Sites
CommunityGet Help NowArticle Translations
|






Windows Live
Facebook
Twitter
Linkedin
Digg it
Yahoo
Delicious
StumbleUpon
Yammer
Reddit
Technorati
FriendFeed
Email
Back to the top
