Showing posts with label Exchange Server. Show all posts
Showing posts with label Exchange Server. Show all posts

Sunday, March 27, 2011

How to setup Outlook Autodiscover and Outlook Anywhere from LAN and Internet (with two certificates) on Exchange 2010 in a single server scenario


 

Ever wondered how will you configure outlook autodiscover and outlook anywhere in the simplest scenario. I am assuming that you are running a single server hosting all roles and CAS is also published on the Internet for access to emails from Internet.

Setup:

You need two certificates, one each for autodiscover and the other for mail. You also need two external IP address pointing to two internal IP addresses. The external IP addresses should point to mail.mydomain.com and autodiscover.mydomain.com

Configuration

  • Remove the auto discover Virtual Directory (VD) from the default site.

Remove-AutodiscoverVirtualDirectory -Identity "SERVERNAME\autodiscover (Default Web Site)"

  • Create a new website in IIS. You can name the website as autodiscover
  • Create the autodiscover VD in this new website

New-AutodiscoverVirtualDirectory -Websitename Autodiscover -BasicAuthentication:$true -WindowsAuthentication:$true

  • Enable outlook anywhere on the server

Enable-OutlookAnywhere -Server SERVERNAME -ExternalHostname "mail.mydomain.com" -DefaultAuthenticationMethod "Basic" -SSLOffloading:$False

  • Set the autodiscover location on the CAS server

Set-ClientAccessServer -Identity SERVERNAME -AutoDiscoverServiceInternalUri "https://autodiscover.mydomain.com/autodiscover/autodiscover.xml"

  • Run the below commands to setup the other VDs properly

Set-OABVirtualDirectory –Identity SERVERNAME\OAB (default web site) -InternalURL https://mail.mydomain.com/OAB ExternalURL https://mail.mydomain.com/OAB -RequireSSL:$true

Set-WebServicesVirtualDirectory –Identity SERVERNAME\EWS (default web site) -ExternalURL     https://mail.emydomain.com/ews/exchange.asmx -InternalURL https://mail.mydomain.com/ews/exchange.asmx -BasicAuthentication:$True

Set-OWAVirtualDirectory –Identity SERVERNAME\OWA (default web site) -InternalURL https://mail.mydomain.com/OWA -ExternalURL https://mail.mydomain.com/OWA

Set-ECPVirtualDirectory –Identity SERVERNAME\ECP (default web site) -InternalURL https://mail.mydomain.com/ECP -ExternalURL https://mail.mydomain.com/ECP

Set-ActiveSyncVirtualDirectory –Identity SERVERNAME\Microsoft-Server-ActiveSync (default web site) -ExternalURL https://mail.mydomain.com/Microsoft-Server-ActiveSync -InternalURL https://mail.mydomain.com/Microsoft-Server-ActiveSync


 

You can then use https://www.testexchangeconnectivity.com to test Auto discover and Outlook Anywhere you just configured.

I was able to do this setup by referring to this link (although it is a Wxchange 2007 link) http://technet.microsoft.com/en-us/library/bb332063(EXCHG.80).aspx


 

------------ End of Document ------------------------
Tags: Exchange Server, Autodiscover, Outlook Anywhere
Published Date: 20110326

Exchange - Multiple copies in forwarded mail

Q: If you forward all your mails (Exchange) to an external email account using ADUC you receive multiple copies only if you also keep a copy in your exchange mailbox. If you do not keep a copy then this issue does not occur.

A: After jostling with this issue for 3 day myself, logged a case with MS.

After 14 hrs of continuous troubleshooting on this SEV 1 case and 4 MS engineers putting all their exchange skills together, we were able to reach to a solution.
A pretty stupid indeed.

Go to virtual SMTP server properties in ESM -> Access -> Authentication.
Check all the authentication methods.

Bingo and the issue is resolved. It happens because of the way Exchange servers authecticate each other. The first incoming hop in my exchnage organisation receives a mail and should split the message and send two copies. One to forwarded address and one to my Exchange mailbox. This splitting does not work if only Anonymous authentication is selected on the SMTP virtual server of the HomeMDB server of the user.


 


Recovering Personal Folder Passwords (PST)


PSTs are pain in the back. And I hope every exchange Admin would agree to that.

Anything and every thing can go wrong with them corruption, stopping backups from running because some geek copied theirs to a network share and then left Outlook open, File servers crashing because of the amount of network connections being used by open PSTs, usage of space, users that think that the 2GB limit is a lie.

But the worst thing about them is customers who password protect them, then forget the password and then deny all knowledge of ever setting the password in the first place.

PstPassword is a small utility that recover lost password of Outlook .PST (Personal Folders) file.

http://www.nirsoft.net/utils/pst_password.html


It is an excellent tool for recovering the password or generating a new password for the file without corrupting it - give it a go, and the best thing about it is that its free (for non-commercial use).



Mukul

Script: Distribution List membership enumeration


net group "Name of Dist List" >c:\dist.txt would not give the Contacts who are members of that DL. Also it would be difficult to find the email addresses.

To retrieve the membership of a Distribution list to a file. (FullName,Sam Account,e-Mail ) use the below script.


On Error Resume Next

strPath = inputbox("Please enter in the path to your group in AD")

Set objGroup = GetObject ("LDAP://" & strPath)

objGroup.GetInfo

strArrMember = objGroup.GetEx("member")

dim fs,objWriteFile

set fs=CreateObject("Scripting.FileSystemObject")

set objWriteFile = fs.CreateTextFile("GrpMem.csv", True)

dim objDistinguishedName

objWriteFile.Write "FullName,Sam Account,e-Mail" & vbcrlf

For Each strMember in strArrMember

Set objUser = GetObject ("LDAP://" & strMember) objWriteFile.Write objUser.FullName & "," & objUser.sAMAccountName & "," & objuser.mail & vbcrlf

Mukul

Is a firewall blocking your Exchange Server's SMTP/POP3 communications!!!


It is interesting to note that if you have a cisco PIX firewall sitting in default security configuration somewhere between your exchange servers it is bound to cause hell lot of problems.

Exchange relies on three propreitary ESMTP verbs (X-EXPS, X-LINK2STATE and XEXCH50) for proper functioning and many others as well.
The stupid Mailgaurd feature, that is on by default, on Cisco PIX firewall allows ONLY RFC 821 SMTP commands to flow across (HELO, MAIL, RCPT, DATA, RSET, NOOP and Quit). All other commands are translated into X's.

When this happens, a number of symptoms can manifest:
  • Link state table does not update correctly
  • Mails keep pending to be submitted to sibling mail servers in a same Rotuing group
  • Exchange servers can't authenticate each other.
  • Seemingly commonplace commands are responded to with the 500 Unrecognized command error or one of its analogues.
  • Normal commands produce completely unexpected responses

You would need get the Mailgaurd feature disabled in the PIX firewall that is sitting between any exchange servers within a same Exchange organization.
Symantec's Raptor Firewall has also been identified as another culprit in such cases.

http://support.microsoft.com/kb/295725/en-us

Tuesday, August 17, 2010

Unable to send email even though message size limits are set

With exchange 2007, you may have come across a situation when you have set message size restrictions correctly at all the four places as per Microsoft:

1. Global/Organizational Limit

2. Connector Limit

2.1 Send Connector

2.2 Receive Connector

2.3 Active Directory SiteLink Limit

2.4 Routing Group Connector Limit

3. Server Limits

4. User Level Limits

There may be times still that if you have set a 10 MB limit everywhere, users are not able to send/receive emails with attachments of 7 MB even. The problem happens because content conversion happens when Exchange converts an internet (MIME) message into Exchange (MAPI) format, and vice versa.

This conversion is done by Exchange while sending/receiving emails to/from Internet. Content conversion generally increases the message size - roughly by 30%.

------------ End of Document ------------------------
Tags: Exchange Server
Published Date: 20100817

Thursday, August 5, 2010

Assign rights to helpdesk to give SendAs permissions

There are multiple ways to assign Recipient Administration permissions to the helpdesk users. Some of them are:

1. Add them to "Recipient Management" RoleGroup directly using Exchange Shell. This will assign them the two important Roles "Mail Recipients" and "Mail Recipient Creation"
2. Add them to "Recipient Management" Active Directory Group. This group is already added to the "Recipient Management" RoleGroup.
3. If you have a mixed environment (2007/2010) then the old "Exchange Recipient Administrators" group is already a member of "Recipient Management" group.

However the catch is that they still will not be able to give SendAs permissions to the users on shared mailboxes.

The cmdlet that is required to give SendAs permissions is Add-ADPermission. This cmdlet is available in "Active Directory Permissions" Role. Do not worry because this role has only the below cmdlets:

Remove-ADPermission
Get-User
Get-SecurityPrincipal
Get-RoleGroup
Get-Group
Get-DomainController
Get-ADPermission
Add-ADPermission

As you can see that all of them are Get cmdlets and only Remove-ADPermission and Add-ADPermissions cmdlets so it is safe to add Helpdesk to this Management Role. Further more the switches that can be used with the Add and Remove AD Permission cmdlet are also restricted.

Now you have identified the RoleGroup and the Role to be assigned to the helpdesk to enable them to give SendAs permissions also. One you have done this, you need to asign the Role to the RoleGroup. We will choose the built-in Role Group "Mail Recipients". I have chosen this RoleGroup because it already contains most of the Roles required by the heldpesk to perform Mail User management.

To assign a Role to a Role Group, we use New-ManagementRoleAssignement cmdlet. Here is the syntax in this case

New-ManagementRoleAssignment -Name "Active Directory Permissions-Recipient Management" -SecurityGroup "Recipient Managemen" -Role "Active Directory Permissions"

The standard naming convention for creating management Role Assignment is as above only.

Once you have done the above then the Recipient Managament Role Groups will have the following Roles assigned:

Distribution Groups
Mail Enabled Public Folders
Mail Recipient Creation
Mail Recipients
Message Tracking
Migration
Move Mailboxes
Recipient Policies
Active Directory Permissions

The last Role has been assigned by the New-ManagementRoleAssignment cmdlet above. This will enable the helpdesk to do the complete management of the recipients including granting SendAs permissions.

------------ End of Document ------------------------
Tags: Exchange Server, Power Shell
Published Date: 20100805

Wednesday, July 28, 2010

RBAC console will not open in Exchange 2010

If you have a mixed environment (Exchange 2003, 2007 and 2010) then only those people can open RBAC console who have their mailbox on a 2010 server.

If people from other exchange servers try to open the RBAC console then they will get the following error.



------------ End of Document ------------------------
Tags: Exchange Server
Published Date: 20100728

Monday, January 11, 2010

Soft recovery of Exchange 2003 database

A step by step walk-through of procedure to be followed when exchange database fail to mount in Exchange System Manager. Please note that I have personally tried these steps with MS premier support executive on call, however I take no guarantee that

1. Ensure that Exchange System Attendant and Exchange Information Store service are started.
2. Now try to mount the database and if database is not mounting and giving an error then check the shutdown state of the database.
3. To check whether database are in clean shutdown or dirty shutdown. Run the below command from the “Exchsrv\bin” directory:

Eseutil /mh “Path of the database” as indicated below and check the state of the database for e.g. :

Eseutil /mh “K:\EXCHANGE20-SG01-DB\EXCHANGE20-SG01-MBX01.edb”




4. Check if the database is in dirty shutdown state. If yes then also check for the “Log required” field as shown above and make sure you have those log files for soft recovery.

5. To check how many logs files have been committed to the database RUN Eseutil /mk “path of the checkpoint file”

Eseutil /mk “L:\EXCHANGE20-SG01-LOGS\E00.chk”

The result of the above command and the logs required as per /mh may not match of the chk file is corrupt. The more reliable output is from /mh

6. To make sure that all the log files are consistent, run
Eseutil /ml “Path of the log files\log prefix” as indicated below.
Eseutil /ml “L:\EXCHANGE20-SG01-LOGS\E00”

Below command will help you check the health of all the log files in the location. Be careful that this command will take VERY long time to complete if you have too many files in the log folder.

A better option is to move the committed log files to a backup folder and then run the above command on the remaining log files to check the consistency of uncommitted log files.





7. You may not see the last log file required in the log folder because that log file may be E00.log. You can find the actual log file name of e00.log “Eseutil /ml “Path of Log File\e00.log”

8. Make sure that you have all the logs files in sequence and are in consistent state which have not yet been committed and if any log file is missing or corrupted then soft recovery will not be successful.

9. To run the soft recovery run the command “Eseutil /r Enn /L “Path of the log files” /d “path of database file”.

E.g. Eseutil /r E00 /l “L:\EXCHANGE20-SG01-LOGS” /d “K:\EXCHANGE20-SG01-DB\EXCHANGE20-SG01-MBX01.edb”






If the above command fails, you can include the switch “/s” for giving the location of the “.chk” file.

Another switch /i can be appended to the above command to ignore the other databases that run off the same set of log files if they are mounted.

7. If the above command does not work then you can cut and paste all the committed log files and Enn.chk from the log drive in another location as backup and try mounting the database. Exchange will create a new chk file and will try to do a soft recovery itself.

If all the above steps do not succeed it is time to call Microsoft and log a SEV 1 case with them.

------------ End of Document ------------------------
Tags: Exchange Server
Published Date: 20100111

Thursday, January 7, 2010

How to delete an email from a mailbox using Exchange Shell

There have been times when a user has sent an email to a big DL and wants it to be recalled. We all know that Exchange recall feature is not much effective. However in Exchange 2007 you can scan all mailboxes and delete the email from them. The best way is to narrow your search as much as possible.

However remember that you need an account which has full access to the mailbox from which you want to delete the email. The BES service account generally has that permissions. You will have to "Run As" the EMS with this account.

Below are two examples of such command.

Get-Mailbox -Server SERVER_NAME -resultsize unlimited | Where-Object {$_.OrganizationalUnit -like "Mydomain.corp/OU/OU/OU*"} | Export-Mailbox -SubjectKeywords "Some keywords from the subject line" -DeleteContent -StartDate 10/08/2009 -IncludeFolders "\Inbox"

The above command finds all mailboxes from a particular server and which are in a particular OU. It then users the Export-Mailbox command to delete the mails as per the specified criteria.

StartDate is use to delete the emails that are after the specified date. You can also use EndDate to specify the range.

Include Folders further narrows the search and reduces the scan time considerably.

Get-Mailbox -Server SERVER_NAME -resultsize unlimited | Export-Mailbox -SenderKeywords "Sender's SMTP address" -DeleteContent -StartDate 10/08/2009 -IncludeFolders "\Inbox"

You can also delete emails from a specific sender using the above command.

Please be careful to test this command before running in production environment as you may end up deleting emails from users mailbox that they need if any wrong criteria is chosen.

------------ End of Document ------------------------
Tags: PowerShell, Exchange Server
Published Date: 20100107

Thursday, December 31, 2009

Remove all DL membership from a user

As part of account termination process, it is often required that the user should be removed from all DLs. This is generally a manual process because of the way AD stores Group Membership information. However you can use Quest Management Shell and achieve the task in one line.

Import-Csv c:\My_UserNames.csv | foreach {(Get-QADUser $_.DisplayName).memberof | Get-QADGroup | Remove-QADGroupMember -Member $_.DisplayName}

The above line will read all names from a CSV. It will then find the DLs that the user is a member-of and call Remove-QADGroupMember to remove the member from the specified DLs. This command will run on all the DLs that a user is a member-of. 'foreach' will cause the entire command to run for all the users listed in the csv file.

We need to pipe it to Get-QADGroup because .memberOf spits the DN of the DLs and Remove-QADGroupMember will not take the DN as the identity for the DL.

------------ End of Document ------------------------
Tags: Active Directory, PowerShell, Exchange Server
Published Date: 20091231

Wednesday, November 18, 2009

Change multiple user password using command line

Quest QAD shell provides a very useful interface to do this often required task. The beautiful part is that you do not need to provide the password as a Secure string.

Set-QADUser –Identity –UserPassword -UserMustChangePassword $True

The above command will set the password for User to the one specified in this command.

Import-Csv UserList.csv | foreach {Set-QADUser -Identity $_.UserName -Password $_.UserPassword -UserMustChangePassword $True}

The above command will read the UserName and UserPassword from and excel sheet UserList.csv and will set them accordingly. You need to keep the row headers as UserName and UserPassword in the CSV. The most important feature here is that you can have a different password for each individual user in the sheet.

------------ End of Document ------------------------
Tags: Active Directory, PowerShell,
Published Date: 20091118

Saturday, September 6, 2008

How to rename an Exchange Server running on a Windows Cluster

Though I would agree that is not a good idea to rename your Exchange server that is running on a Windows Server Cluster, however you may need to it for various reasons. I did test this in my test environment.

I had two tasks at hand:

  1. Rename the cluster name itself
  2. Rename the Exchange Virtual Server name

How to rename the cluster:

  • To Rename the Cluster right click on the cluster name and choose rename.

image

image

  • Type the new name of the cluster and you are done.
  • Check the properties of 'cluster name' resource to confirm the change of name.

image

  • Take the 'cluster name' resource offline and bring it back online.
  • DTC resource would also have gone offline. Bring it online as well.

How to rename the Exchange Virtual Server:

  • Bring all the Exchange resources off line including the network name (Exchange Virtual Server network name).
  • Rename the Exchange Virtual Server network name resource by choosing properties and editing the parameter of the resource.

image

image

  • Bring the Exchange Virtual Servername and Exchange Virtual Server IP address resources online.

image

  • Delete the Exchange Virtual Server System Attendant resource. It is necessary because a Windows Cluster server can only run a single instance of Exchange Virtual Server.

image

  • All other dependant resources should also be deleted. choose Yes to do so.

image

  • Move all the databases and log files to an alternate location. If you do not do so Windows will not let you create the System Attendant resource and will complain that the exchange data directory is not empty.

image

  • Create a new System Attendant resource and all other dependant resources would be created automatically.
  • Bring all the resources online once and check everything is fine in the cluster administrator.

image

  • Now open Exchange System Manager and you should see both the new and the old Exchange Servers listed.

image

  • If you try removing the old server, Exchange would complain that some users still exist on the server and you cannot remove the Exchange Server.

image

  • Use the following article to find all the users whose AD attributes for current mailbox server has not yet been update to the new server and rip off the Exchange attributes from all these users.

image

  • Put a check mark against the box "This database can be overwritten by a restore" found under Mailstore -> Properties -> Database tab. Do this for all the information stores in the new Exchange Virtual Server.

image

  • Take the System Attendant resource offline from the cluster.
  • Copy back all the exchange database and log files that you had copied earlier to an alternate location.
  • Bring back the System Attendant and all other resources online.
  • Check the Mailstore of the new Exchange Virtual Server and it should now list all the users who had their mailbox on this server.

image

  • Run the MailBox cleanup Agent Exchange System Manager.

image

  • Once you run the mailbox cleanup agent all the mailboxes would appear as disconnected.

image

  • Right click on each mailbox and reconnect them to the correct username in the AD.

Tempuser01 connected to old mailbox:

image

Tempuser01 with exchange attributes ripped off:

image

Tempuser01 connected to new mailbox

image

  • Purge all other mailboxes such as SMTP and System Attendant from the new Exchange Server.

image

  • Now remove the old server from Exchange System Manager

image

image

image

-----------------End of Document-------------

Tags: Clustering, Exchange Server, Windows Server 2003

Published Date: 20080609

Tuesday, June 17, 2008

Send Mails using Telnet with authentication

Sending mails using telnet comes handy when you are troubleshooting mail issues. You will find lots of such small set of instructions for the same however this guide also explains how to authenticate to the server before sending a mail.

1. Open a telnet session on port 25

2. type 'ehlo YourDomain.com', and hit enter.

3. Type 'auth login', and hit enter. You will see output something like this.

image

4. Now enter your full email address and then your password encoded in BASE64. To convert your full email address and your password to BASE64, you can use this handy BASE64 encoding tool.

5. If your username (the full email address) and password were entered correctly, the mail server would respond with “Authentication successful”.

image3

6. You have just authenticated yourself with the mail server and now can start entering the email details.

7. Type 'mail from: YourUserName@YourDomain.com', and hit enter.

8. Type 'rcpt to: Destinationemail@DestinationDomain.com' and hit enter.

9. Type 'DATA', hit enter

10. Type 'Subject: Your Subject Here', hit enter.

11. Hit enter once again to send a blank line to seperate header from the message body.

12. Type your mail.

13. Type '.' (A single dot in a line to indicate end of your mail and submit it for delivery).

image6

------------------- End of Document -----------------------

Tags: Exchange Server

Published Date: 20080617