I have some very peeved superiors right now. You can spout best practice methods off, but the fact remains that MANY Domain Admins have mailboxes. I agree 100% that if you're so adamant about the best practice to be that Domain Admins are not mailbox enabled, then why not make a patch to kill that ability?? You take it away from us as a side-effect of a patch and then more or less tell us "it should be like this anyway"??? :confused:
So as see it, I have 2 options right now, as my CTO and Manager are in Las Vegas at Networkers and can't send any mail (they're Domain Admins).
1) Uninstall the patch and make sure I NEVER install it again.
2) Modify the adminSDholder permissions
I'm not a fan of backing out patches, but I'm leaning towards number 1.
Side Note: I'm sure Microsoft was aware that this would break BES. It's not like BES is some small, 3rd party app that a few companies run. Was RIM contacted ahead of time? I spent 3 hours on hold yesterday, just to find out that anyone with a mail-enabled Admin account was more or less screwed.
Time to back the patch out, and I'm pulling my Exchange server from WSUS, because I'm not going through this again.