Changes to groups not updating a policy
I've created a recipient policy to point to a group by using the groups full distinguished name. I set it up and it works great finding only those who belong to that group. I can also add users to that group and when I "apply policy now" I see that they are being affected. The problem is when I remove someone from that group the policy is still touching the mailbox. I have gone into the policy and clicked modify on the general tab of the policy and clicked find now and it shows the users have been removed but again when the policy runs it still wants to touch the users that have been removed. I am seeing it in the admin report. I have applied now and also went in and changed a value on for the deleted items field on the mailbox manager settings tab. I have manually ran the mailbox processing on the server and have also let it sit over night. Why is it still wanting to look at users that have been removed? Any help with this would be great. Thanks
December 23rd, 2007 10:40pm

I think I've found out why in this KB http://support.microsoft.com/kb/304516 It mentions a rebuild of the Recipient Update Service. I know its very easy to do...right click rebuild but I've never had to run a rebuild before. Are there any issues with running this during prodution hours? Is this just a bad thing to run just to update group changes for a recipient policy? Could running the rebuild cause any issues? Could it affect mail flow? I went with a group so that it would be easy to add and remove users to this policy. If rebuilding this is a bad idea does anyone have any suggestions on how to do this without using a group? Thanks
Free Windows Admin Tool Kit Click here and download it now
December 24th, 2007 2:13am

As you read in the KB, building policyn based on groups is not the ideal solution. the best way of doing this is to use attributes on useraccounts, such as company, department, customattribute etc. solution is to rebuild the RUS. If you are a small org. then there is no performance hit as it would be in a large organization. You can end up with adding/changing emailaddresses, but only if you have changed them manually after they have been set by the policy.
December 26th, 2007 11:28pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics