Showing posts with label Exchange migration. Show all posts
Showing posts with label Exchange migration. Show all posts

Monday, May 12, 2025

Exchange Anonymous Connector

 If you're like most, you need an internal relay on your Exchange server to allow devices and applications inside to send email without the need for credentials.  Since the connector can be scoped to the IP address of the source, this is a pretty good way to set it up.

I ran into a new issue on our new Exchange server today.  When you create the new Internal Relay receive connector to allow anonymous access, you must run a PowerShell command to make the connector accept messages.  This assumes you have the correct IP addresses in the relay.

Run this first:

Get-ADPermission "YourConnectorName" |

Where-Object { $_.User -like "NT AUTHORITY\ANONYMOUS LOGON" -and $_.ExtendedRights -like "*SMTP-Accept-Any-Recipient*" }

If this returns nothing, and it probably will, run this command to add the permissions:

Get-ReceiveConnector "YourConnectorName" |

Add-ADPermission -User "NT AUTHORITY\ANONYMOUS LOGON" `

-ExtendedRights "Ms-Exch-SMTP-Accept-Any-Recipient"

Good luck!

Saturday, June 09, 2012

Active directory response: 00002098: SecErr: DSID-03150BB9, problem 4003 (INSUFF_ACCESS_RIGHTS)

Active directory response: 00002098: SecErr: DSID-03150BB9, problem 4003 (INSUFF_ACCESS_RIGHTS)

If you're getting this error trying to move mailboxes from Exchange 2003 or 2007 to Exchange 2010 then here's the simple fix.
  • Go into the user's account in AD and go to the Security tab. 
  • Check the box to Inherit permissions. If it's already set, clear it, force an AD update, and then check the box again. 

I had 2 boxes do this on my last Exchange migration. It's a real pain to find out after you've waited on the mailbox to copy but a very easy fix.

Friday, June 08, 2012

Outlook 2010 Certificate Error After Migration

I recently did a migration from Exchange 2003 to Exchange 2010.  The new environment uses a CAS/HT server and a mailbox only server.  Everything went great until the first user opened up Outlook 2010 and there was the dreaded SECURITY ALERT stating that the certificate is invalid or does not match the name of the site.

Here's the fix for that little issue.

Assuming you have already installed the UCC certificate on the Exchange server you will need to enable the cert.  You can run the following command to enable the certificate.

Enable-ExchangeCertificate -Thumbprint 59 5e a4 7c f0 4e 66 da 3d 6b 29 95 f7 c4 b1 72 ca 0f 82 -Services "SMTP, IIS"

Note: The thumbprint needs to match the certificate you installed.  You can use either the GET-CERTIFICATE command or use the MMC, select the certificate, click on details, and then click on thumbprint.

For each CAS server that is installed a Service Connection Point (SCP) record is created for the autodiscover service for internal clients.

When i go into Outlook i get the following error:

image

This happens because the connection is using the NetBIOS name of mbx1 which does not match the name on the certificate. If you run Get-ClientAccessServer -Identity mbx1 | FL you would see that the AutoDiscoverServiceInternalUri says https://MBX1/Autodiscover/Autodiscover.xml and this does not match the certificate.  If you also check the other services and you will get the same results for OAB, EWS, Outlook Anywhere (OA) and Exchange Active Sync (EAS).  The fix is to update all theses internal URL links to match the name on the cert.
  • Set-ClientAccessServer -Identity "mbx1" –AutodiscoverServiceInternalURI https://nlb.nwtraders.msft/autodiscover/autodiscover.xml


  • Set-WebServicesVirtualDirectory -Identity "mbx1\EWS (Default Web Site)" –InternalUrl  https://nlb.nwtraders.msft/EWS/Exchange.asmx

  • Set-OABVirtualDirectory -Identity “mbx1\OAB (Default Web Site)” -InternalURL https://nlb.nwtraders.msft/OAB

  • Enable-OutlookAnywhere -Server mbx1 -ExternalHostname “nlb.nwtraders.msft” -ClientAuthenticationMethod “NTLM”

  • Set-ActiveSyncVirtualDirectory -Identity “mbx1\Microsoft-Server-ActiveSync (Default Web Site)” -InternalURL https://nlb.nwtraders.msft/Microsoft-Server-Activesync

Note: If you do decide to enable OA externally it is important to note that the external host name value configured for Outlook Anywhere must match the Certificate Principal Name (CPN) on the certificate used by clients and must match the end point property in the client.

In order for Subject Alternate Name (SAN) certificates to be used for clients to connect to the OA service, where the CPN does not match the msstd value configured in the Outlook client profile (but the URL is listed in the SAN part of the certificate), certain conditions need to be met, these are listed below:-
  • Outlook 2007 or higher
  • Vista SP1

After this is completed once you open Outlook 2010 you will no longer get the certificate error.

Thursday, July 28, 2011

How to Move Public Folders to Exchange 2010

Move public folder data to Exchange 2010

Public folders are an optional feature in Exchange 2010. If all client computers in your organization are running Microsoft Office Outlook 2007 or later, then public folders are an optional feature. However, if Outlook 2003 clients are in use, then public folders are required. In addition, if you're currently using public folders for collecting, organizing, or sharing documents and other information and you want to continue doing so, you can use public folder replication to move your public folder data to Exchange 2010.

How do I do this?
You can use the Exchange Management Console to perform this task.
  1. In the Console tree, click Toolbox.
  2. In the Result pane, double-click Public Folder Management Console. The Public Folder Management Console appears.
  3. In the public folder tree, click or expand Default Public Folders, and then select the parent public folder of the public folder that you want to move to Exchange 2010. Note: To configure replication for the offline address book (OAB) or for Schedule+ free/ busy information, expand System Public Folders, and then click OFFLINE ADDRESS BOOK or SCHEDULE+ FREE BUSY.
  4. In the Result pane, right-click the public folder you want to replicate to Exchange 2010 and select Properties.
  5. On the Replication tab, click Add to select an Exchange 2010 public folder database and then click OK.
  6. By default, Exchange uses the replication schedule configured for the public folder database. To create a custom replication schedule for the public folder, clear the Use public folder database replication schedule check box and select one of the settings in the list.
  7. To create a customized schedule, click Customize.
  8. To set the schedule, click the time grid in the Schedule dialog box. Public folder replication will run during the time slots that you specify.
  9. Click OK to close the Schedule dialog box.
  10. To specify the age limit for items in this public folder, type the number of days in the Local replica age limit (days) box. Items that have reached the age limit are deleted.
Note: Age limits should be used for public folders only. They should not be used for System Folders, such as OFFLINE ADDRESS BOOK or SCHEDULE+ FREE BUSY.
  1. Click OK to close the Properties dialog and to save your changes.
  2. Repeat Steps 4-11 for each public folder you want to move to Exchange 2010.
How do I know this worked?

You can use the Get-PublicFolder cmdlet in the Exchange Management Shell to verify replicas on the Exchange 2010 public folder database. For example, to determine the replicas for all public folders in the public folder tree, run the following command: Get-PublicFolder -Recurse | Format-List Name,Replicas To determine the replicas for all system folders, run the following command: Get-PublicFolder \NON_IPM_SUBTREE | Format-List Name,Replicas