But as sukh pointed out above, upgrading to service pack 2 shouldn't have affected individual account permissions in Active Directory.
Originally Posted by Abaddon
Agreed, it shouldn't.. :p
I've had a couple of issues like yours, with random connection errors (to mail boxes), on diverse handsets (iOS, Blackberry and one Android), and this fixed it on all occasions. May not work for you, but it was worth a try.. :)
Some AD ubergeekery that *might* be relevant and has explained a Very Great & Perplexing Mystery[tm] for me in the past:
If you find a normal user where the AD Inherit permissions tick box is clear then look at the adminCount attribute on the user object. If that's 1, then that will usually explain why the tick box is clear and you must set that attribute to 0, otherwise any tick you put in the Inherit permissions box will be automagically cleared again.
If you want to find users where adminCount =1, make an ADUC custom query where the advanced tab LDAP query is:
** eliminate the space this forum puts in the word "admincount" **
Don't do this to Admin accounts without Googling, in fact Google first regardless. Here's some relevant MS info about AdminSDHolder, protected groups and SDPROP to get you started. In my world this has *always* been about Orphaned AdminSDHolder Objects i.e. someone temporarily put user accounts in a privileged group for some reason or other.