Symptoms or Error
This can result in no MAM resources being deployed unless they are bound to the 'All Users' Delivery Group.
You may also find that resources can still be deployed by using local groups in XenMobile Server itself.
Symptoms of this problem can been seen on the XenMobile web admin console under 'Manage' --> 'Users'.
When checking under 'Groups' on this page, you may find that this specific detail is left blank for any affected users.
Solution
The membership of 'Pre-Windows 2000 Compatible Access' should be configured so that the users who are enrolling in XenMobile are found to be members of 'Pre-Windows 2000 Compatible Access'.
The default settings for 'Pre-Windows 2000 Compatible Access' are such that 'Authenticated Users' is listed as a member of the group.
Any Domain Controller computer account objects are also found as members of this group, by default.
Problem Cause
This step may fail if the membership of 'Pre-Windows 2000 Compatible Access' has been changed from the default settings.
Changes to the default settings may have been performed so as to restrict security settings.
See the links under 'Additional Resources' for information about how to restrict security settings in Active Directory without changing the default membership of 'Pre-Windows 2000 Compatible Access'.