Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Beefstorm
Jul 20, 2010

"It's not the size of the tower. It's the motion of the airwaves."
Lipstick Apathy
Is there any conceivable reason you would still want in house Exchange now for new deployments? I'm sure I'll catch some flak for this, but it seems like everyone should just make the move to Office 365 at this point.

Adbot
ADBOT LOVES YOU

Beefstorm
Jul 20, 2010

"It's not the size of the tower. It's the motion of the airwaves."
Lipstick Apathy

ghostinmyshell posted:

Today was fun. Got pulled into a meeting and told that we are migrating to o365... today. We made it as far as mailbox syncing and will pick up tomorrow. I'm hoping I can put the ad dirsync on a 2008 R2 vm and forget about it with syncing set to every 15 minutes. We are a small shop so about 100 mailboxes so this won't be as ulcer inducing as it should be...

I'm hoping someone could recommend a admin book to read or a site that goes over big picture things, gotchas and things like that. I don't know what this Delve or Sway poo poo is, trying to figure out how to hide sharepoint and we are terrified as poo poo about what is public and private, and what users can do to gently caress poo poo up like making secrets.docx public by accident.

I am currently in the process of shifting 100 people to Azure AD SSO with O365 E3 this weekend (buzzwords)! I've been planning and testing for the past two weeks.

First thing to read, https://azure.microsoft.com/en-us/documentation/articles/active-directory-aadconnect-get-started-custom/

What I can say is don't go looking for the DirDync tool. Just utilize Azure AD Connect in this documentation. It's accomplishes the same thing. But I found that AAD Connect utility is way better at not loving up. And Microsoft said this is what they will be supporting going forward, instead of DirSync. (If some of you goons are already on DirSync, there are instructions to upgrade)

Some gotchyas I ran into:

1. If you are on a .local domain, don't bother trying to rename the domain. Add a UPN for the actual domain name, and change login names to their email addresses. It's going to suck at the beginning because no one is going to know how to sign in. Just make sure you communicate the changes and time lines to all of your users sooner rather than later. Make these changes BEFORE turning on sync. You will see why in #2.

2. If you are going for SSO by synchronizing your AD, don't setup O365 accounts first. It's a real bitch to get accounts synced after you created them. YMMV but I just gave up and started from scratch by deleting all of the O365 accounts. Luckily I hadn't got as far as importing emails. Since it looks like you have migrated emails, here is a useful link on how to get accounts to sync. https://support.microsoft.com/en-us/kb/2643629

3. It shouldn't have taken me as long to figure out, but you set Exchange Online email addresses for the user in the proxyAddresses attribute in local Active Directory.

If I think of anything else, I'll post it.

Beefstorm
Jul 20, 2010

"It's not the size of the tower. It's the motion of the airwaves."
Lipstick Apathy
Update from the deployment. Authentication setup through AAD worked and the O365 software went out, with a few glitches. It was overall a pretty good deployment I thought.

Now I get to setup the Exchange portion...

Beefstorm
Jul 20, 2010

"It's not the size of the tower. It's the motion of the airwaves."
Lipstick Apathy
Day 1 of everyone officially being on Office 365.

30 minutes later, ISP has an outage in the area.

This is not my day.

Beefstorm
Jul 20, 2010

"It's not the size of the tower. It's the motion of the airwaves."
Lipstick Apathy

That was me for three hours.

Beefstorm
Jul 20, 2010

"It's not the size of the tower. It's the motion of the airwaves."
Lipstick Apathy

incoherent posted:

Stick with dirsync unless you really need password writeback.

I fought tooth and nail with ADFS to make it work. It's not worth it unless you already have ADFS setup for another purpose. Then it might go alot easier for you.

Beefstorm
Jul 20, 2010

"It's not the size of the tower. It's the motion of the airwaves."
Lipstick Apathy

Wilford Cutlery posted:

- User who is an employee of our ChildCo needed to have an email address of our ParentCo for a project
- I made a shared mailbox with the needed address, gave her Send As permission on it, added it to her Outlook (it shows up below her ChildCo mailbox)
- Showed her how to use the From: button when sending messages, she's been doing that
- Problem: every message, whether in Inbox or Sent Items, doesn't appear in her ParentCo shared mailbox. Instead they're all in her ChildCo mailbox

I've never seen this before, but before I was used to 365 shared mailboxes. This is an on-prem Exchange 2013 server and she uses Outlook 2013.

I ran into this exact problem with one of my customers. The fix is to connect to powershell and do this.

quote:

For emails Sent As the shared mailbox: set-mailbox <mailbox name> -MessageCopyForSentAsEnabled $True

For emails Sent On Behalf of the shared mailbox: set-mailbox <mailbox name> -MessageCopyForSendOnBehalfEnabled $True

Source: http://blogs.technet.com/b/exchange/archive/2015/03/03/want-more-control-over-sent-items-when-using-shared-mailboxes.aspx

Beefstorm
Jul 20, 2010

"It's not the size of the tower. It's the motion of the airwaves."
Lipstick Apathy

anthonypants posted:

Does anyone know why Office 365 users would suddenly get the "your mailbox has been temporarily moved" error? Creating a new profile doesn't resolve it 100% of the time.

e: I did some more digging and I think it might be because we didn't remove the SCP from AD? Can I just remove our old on-prem Exchange servers using ADSI Edit? They're both in the CN=Servers,CN=Exchange Administrative Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=OrganizationName,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=domain,DC=local container, and they're both powered off.

ee: I guess Office 2016 installs registry settings to disable SCP lookup so that isn't it.

I was banging my head against the wall for awhile with this. This was the solution for me at least.

https://www.reddit.com/r/sysadmin/comments/53vhwy/the_solution_to_weird_problem_windows_10/

If not that, try this. https://diagnostics.outlook.com/

Beefstorm
Jul 20, 2010

"It's not the size of the tower. It's the motion of the airwaves."
Lipstick Apathy

anthonypants posted:

ugh, reddit.

This is on Windows 7 and not Windows 10, but deleting old Outlook profiles seems like an incredibly bizarre solution. It's certainly worth a shot, and I think it might be happening after our users change their passwords.

It was that or go with the support rep's suggestion, which was recreate the windows profile. :/ Luckily that worked.

Beefstorm
Jul 20, 2010

"It's not the size of the tower. It's the motion of the airwaves."
Lipstick Apathy

wa27 posted:

I figured out our copier issue. We had a box acting as an SMTP relay (used for spam filtering). Disabling that let it connect to 365.

Better than my solution.

I had a Konika Minolta that refused to scan to email through 365. I worked with Microsoft and Konika on the phone at the same time. They both eventually agreed that the printer is simply not compatible with Office 365, and that I had to come up with a different solution.

I ended up putting an SMTP relay on one of the Windows VMs, and had it send to that. Then that would send to Office 365. It worked...just stupidly.

Beefstorm
Jul 20, 2010

"It's not the size of the tower. It's the motion of the airwaves."
Lipstick Apathy

Thanks Ants posted:

Microsoft are poo poo at text chat

I usually skip right to calling when it comes to O365 stuff. They are much more effective when you can clearly describe the issue, as well as what you have attempted so far to fix it.

Beefstorm
Jul 20, 2010

"It's not the size of the tower. It's the motion of the airwaves."
Lipstick Apathy

Internet Explorer posted:

That's... Not at all what he's talking about.

Picking up on that now...

Maybe I will try teams.

Beefstorm
Jul 20, 2010

"It's not the size of the tower. It's the motion of the airwaves."
Lipstick Apathy

NevergirlsOFFICIAL posted:

I have an on-prem exch 2010 server, and o365 for skype for business. I want to move all my mailboxes from exch 2010 to o365, and eliminate the exchange server. I cannot do cutover migration because dirsync is place. What is the best migration path assuming I do not want to keep hybrid server (at least not long term)?

In the middle of this right now. You want a Remote Migration.

Microsoft has created a handy step by step system for doing any migration or deployment you want. Answer a few question, and it dumps an instruction set for you.

https://technet.microsoft.com/en-us/exdeploy2013

Beefstorm
Jul 20, 2010

"It's not the size of the tower. It's the motion of the airwaves."
Lipstick Apathy

NevergirlsOFFICIAL posted:


this is inaccurate... what about azure ad connect?

anyway I think that wizard is kinda useless but this is what I need: https://blogs.technet.microsoft.com/exchange/2016/06/24/hcw-improvement-the-minimal-hybrid-configuration-option/

This will utilize Azure AD Connect. You manage users and groups in Active Directory DS and the changes are synchronized Azure AD through Azure AD Connect. Selecting the option you have pictured will utilize that.

And yes, you will need to utilize Exchange Hybrid Wizard. I recommend having that tool still dump you an instruction set. It was a life saver for me.

Edit: Possibly your confusion is that Office 365 email is built upon Exchange Online and Azure AD. If you don't look under the hood, it's a lot harder to understand whats going on.

How many users are you migrating? Depending on your user count, you could be eligible for fast track. Then, seasoned O365 techs will walk you through whatever you want.

Beefstorm fucked around with this message at 20:25 on May 16, 2017

Beefstorm
Jul 20, 2010

"It's not the size of the tower. It's the motion of the airwaves."
Lipstick Apathy

Thanks Ants posted:

Hybrid is a lot better if you're running Exchange 2013+. 2010 is a bit ropey.

Actually, in order to get everything to work correctly, I had to setup an Exchange 2016 server first ...an important detail I failed to mention.

Beefstorm
Jul 20, 2010

"It's not the size of the tower. It's the motion of the airwaves."
Lipstick Apathy

Old Binsby posted:

While you could, as far as I'm aware you'd lose the ability to edit Exchange properties of users in Exchange online since the on-prem AD becomes the source of authority for them after AADconnecting/dirsyncing. Then you'd either need that exchange server or ADSI edit. to change even simple things like email addresses. You'd need to run the first part of the Exchange setup every 3 months anyway because potentially every CU can extend your schema. Those CUs are the only source of the schema updates you need to keep your on-prem AD compatible with Exchange Online.

I don't think there exists a supported configuration of dir/aadsynced exchange online users without an on-prem Exchange server.

The transition from On Prem to O365 was WAY easier when everyone was already dirsynced. You eliminate having to then synchronize Azure AD after the fact and then matching AD accounts with Azure AD accounts.

Beefstorm
Jul 20, 2010

"It's not the size of the tower. It's the motion of the airwaves."
Lipstick Apathy

NevergirlsOFFICIAL posted:

I've never done an o365 implementation in AD when there wasn't an Exchange server in place pre migration. In almost every case I did cutover migration, then aadconnect, then decom exchange. proxyaddress and other exchange attributes can be changed in ADUC.

It really depends on the environment for the order you do things. If you are on Exchange 2013 or newer, I would definitely go for hybrid with remote migration.

Beefstorm
Jul 20, 2010

"It's not the size of the tower. It's the motion of the airwaves."
Lipstick Apathy

devmd01 posted:

And that's almost a wrap on killing the on premise 2010 environment, nothing but an internal smtp relay exists for on prem/hybrid services, everything else routes through proofpoint to O365 inbound and outbound.

Just to be clear, are you routing mail through proofpoint, and then to exchange online?

If so, I would just drop proofpoint. Multiple spam blockers can cause alot of headaches.

Beefstorm
Jul 20, 2010

"It's not the size of the tower. It's the motion of the airwaves."
Lipstick Apathy

Ranter posted:

A nice long recurring meeting on a room resource and the meeting is gone from the organizers calendar. Would like to know since Outlook doesn't let you delete without sending cancellation.

Sure it does. You just delete without sending a cancellation.

Beefstorm
Jul 20, 2010

"It's not the size of the tower. It's the motion of the airwaves."
Lipstick Apathy

devmd01 posted:

Last exchange 2010 server powered off prior to decommission next week, only thing left is two Exchange 2016 servers in HA for on prem SMTP relay and editing user mail attributes to sync to O365. It’s nice not having to give a poo poo about exchange, it just works now.

Just works ™

Beefstorm
Jul 20, 2010

"It's not the size of the tower. It's the motion of the airwaves."
Lipstick Apathy

devmd01 posted:

Just uninstalled the last exchange 2010 box in our environment we had around for legal hold restore purposes! :woop:

The only exchange bullshit I have to deal with now is two 2016 servers in HA for internal SMTP relay and exchange attribute editing, everything else is O365. :hellyeah:

I am SLOWLY moving everything from using an IIS relay or OnPrem Exchange relay, to just using O365.

I have a feeling though, it will be at least a year before I finally rid myself of OnPrem exchange.

Beefstorm
Jul 20, 2010

"It's not the size of the tower. It's the motion of the airwaves."
Lipstick Apathy

Old Binsby posted:

it's that time of year, stumbled upon that guy calling in that Outlook is really slow and has been for a while but he's hoping we can finally fix it. I'm the fourth person to get the ticket assigned ... lets... seee.... ah, the season for sharing the joy after all

User has had mailbox since start of employment - 1997.

There are 159922 unread items in his Inbox and he does not want to remove any. Or mark them read. The unread ones are unread for a reason. These include all messages ever placed in the Sent items box. And drafts. All folders in his mailbox are empty except the inbox, which we can't touch. New folders will throw him for a loop, how will he find anything? He know at what height important messages are on the scroll bar on his screen. Besides the search doesn't work. Poorly even when it was still Notes, probably. Please advise



If you have Office 365, utilize archiving. Dump the oldest 75-100k messages into his archive, and have the rest go into his standard mailbox. Should clear up some of his performance issues.

But yeah, he needs to just let go of some of his old stuff....

Adbot
ADBOT LOVES YOU

Beefstorm
Jul 20, 2010

"It's not the size of the tower. It's the motion of the airwaves."
Lipstick Apathy

AlternateAccount posted:

Exchange is poo poo.

Outlook is poo poo.

Gonna just spin up a dovecot/postfix server and keep everything in flat text files the way god intended and tell people to use that from now on.

Dude, what are you crazy? Why are you even using email?

Just setup an FTP server, give everyone credentials, and tell everyone to leave messages in there. It's up to the end user to be checking the FTP server for their messages.

Users are responsible enough that you shouldn't need to worry about people checking messages that don't belong to them.

Then, if someone REALLY needs to send an email, it has to be a request to IT. Tell them to upload their message to an email folder, which will be processed and sent by the admin. Ya know, for security. But honestly, it would be better if you could just get your customers and business partners to get on your FTP server too.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply