To test if the permissions are set right, you can run the IEMSTest.exe application. In your case, you might ask the BES admin to run it. It is located C:\Program Files\Research In Motion\BlackBerry Enterprise Server\Utility\ run it from a command prompt (i always run it from the server, but suppose you dont need to).
This will verify that the BES Admin account has access to open the user's mailbox and modify data inside.
If that checks out ok, It is most likely option 1 that amorgan2000 mentioned.