Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.

The "Allow Create Top Level Public Folder" Access Control Entry for the Exchange Organization container unexpectedly includes the Everyone and the Anonymous Logon groups


View products that this article applies to.

Symptoms

In your Exchange Server 2003 organization, the Allow create top level public folder access control entry (ACE) for the Exchange Organization container may unexpectedly include the Everyone group or the Anonymous Logon group.

Note The Anonymous Logon security principal will only exist if the Active Directory directory service has been prepared for Microsoft Windows Server 2003. For additional information, click the following article number to view the article in the Microsoft Knowledge Base:
278259� Everyone group does not include anonymous security identifier

↑ Back to the top


Cause

This problem occurs in an organization that has Exchange 2000 Server computers installed after the organization has been prepared for Exchange Server 2003. When you run the Exchange Server 2003 ForestPrep utility, the Everyone security principal or the Anonymous Logon security principal is configured to not have the Allow create top level public folder ACE for the Exchange Organization container. But when you install the Exchange 2000 server, Exchange 2000 Setup adds the Everyone ACE back to the Organization container because Exchange 2000 Setup resets certain permissions on the organization during normal setup.

For additional information about this issue in Exchange 2000 Server Setup, click the following article number to view the article in the Microsoft Knowledge Base:
320007� Permissions that are modified manually are reset to the default values

↑ Back to the top


Workaround

To work around this problem, use either of the following methods:
  • Rerun the Exchange Server 2003 ForestPrep utility from any server in the forest.

    -or-
  • Manually remove the following from the Organization container: the Create Top Level Public Folder allow permission that is associated with the Everyone ACE or with the Anonymous Logon ACE.

To manually remove the Create Top Level Public Folder allow permission from the Organization container for the Everyone ACE or the Anonymous Logon ACE, follow these steps:
  1. Start Registry Editor.
  2. Locate the following key in the registry:
    HKEY_CURRENT_USER\Software\Microsoft\Exchange\ExAdmin
  3. On the Edit menu, click Add Value, and then add the following registry value:
    Value Name: ShowSecurityPage
    Data Type: REG_DWORD
    Value: 1
  4. Quit Registry Editor.
  5. Start Exchange System Manager by using an account that has Exchange Full Administrator privileges at the organization context.
  6. Right-click the Organization, and then click Properties.
  7. Click the Security tab.
  8. Click the Everyone permission.
  9. In the Permissions For box, locate Create Top Level Public Folder, and then click to clear the Allow check box.
  10. If Active Directory has been prepared for Windows Server 2003, repeat steps 8 through 9 for ANONYMOUS LOGON.
  11. Click OK to apply the permission change.

Notes
  • If you reinstall or add another Exchange Server 2003 to the organization, this does not remove the Everyone ACE. This operation is completed as part of Exchange Server 2003 ForestPrep.
  • After you complete this workaround, if you add another Exchange 2000 server to your organization, Exchange 2000 Setup will add the Everyone ACE back to the Organization container. Therefore, you must repeat the method that you used in the "Workaround" section.

↑ Back to the top


Status

Microsoft has confirmed that this is a problem in Exchange 2000 Server setup.

↑ Back to the top


Keywords: KB822576, kbbug, kbtshoot

↑ Back to the top

Article Info
Article ID : 822576
Revision : 6
Created on : 10/25/2007
Published on : 10/25/2007
Exists online : False
Views : 277