Checking and setting Read Member Of permission for Network Service account

When using Signature Manager Exchange Edition with a group policy, you observe that the Policy Tester is showing the correct behavior. However, when an email message is sent, the membership of this group cannot be correctly identified, so the policy does not get applied.

Ensure that the NETWORK SERVICE account has "Read Member of" permissions to the user object you are testing with e.g. Colin Smith.

  1. Open Active Directory User and Computers. (dsa.msc).
  2. Click View, then Advanced Features:

  3. Image 189
  4. Locate a problem user and open their Properties.
  5. Click the Security tab, Advanced button, then the Effective Permissions tab.
  6. Click the Select button and type the NETWORK SERVICE account. Click OK.
  7. Locate the permission Read Member of and confirm that the permission is present:

  8. Image 190
    If the Read Member of permission is not present against the NETWORK SERVICE account then follow the next steps below:

    To apply the permission change to all users in an OU.

  9. Right click the OU and choose Properties.
  10. Click the Security tab, then click the Advanced button.
  11. Click Add and type NETWORK SERVICE. Click OK.
  12. Click the Properties tab and on the Apply to: drop down list choose Descendant User objects:

  13. Image 191
  14. Locate the permission Read Member of and tick the Allow check box:

  15. Image 192

  16. Click OK until you return to Active Directory Users & Computers.
  17. Repeat steps 1 to 5 above to confirm that NETWORK SERVICE now has the permission "Read Member of".

Note: In some environments this change may not take affect straight away until the changes have been replicated to the Global Catalog server.