Exchange server 2007 to 2010 Live migration!!!! Live blog!!! Live Platform…real time scenario!!!

Please find on my blog, one page dedicated to this task…you can see it on my blog top page… or click here

             TO                                          

 MIGRATION…Started on June 8, 2010 ….Today 20th of June..all the objects has been replicated to Exchange 2010..Now the decommissioning starts..Finish too

Microsoft Forefront security products – At a glance

The Microsoft Forefront comprehensive line of business security products provides greater protection and control through integration with your existing IT infrastructure and through simplified deployment, management, and analysis. Microsoft Forefront helps you confidently meet ever-changing threats and increased business demands with highly responsive information protection and access control solutions supported by Microsoft technical guidance…last year was a greater start for microsoft with the new line of Longhorn products..like Windows 7, Windows Server 2008, R2, Office 2010, Sharepoint 2010, GP10, CRM4, now Forefront…the security product…which seems to be very well working with client side and server side…cool one…To download the forefront products, click here

Also The Forefront products include:

Forefront Client Security – anti-virus for file-level protection

Forefront Security for Office Communications Server – Antivirus for Corporate Instant Messaging

Forefront Security for Exchange – Antivirus for Exchange databases and email traffic

Forefront Security for SharePoint – Antivirus that integrates into SharePoint sites

Forefront Product Pricing and Licensing

Exchange 2010 Mailbox role – installation failed

Error

Microsoft.Exchange.Management.Deployment.UpdateRmsSharedIdentity.Link()

This error occurs because the federated built-in e-mail account that links to the computer account no longer exists. Or, the federated built-in e-mail account in the Active Directory directory service is corrupted.

Resolution..go to Active Directory server

  1. Click Start, click Run, type adsiedit.msc, and then click OK.
  2. Locate the Default Naming Context node, and then locate to the CN=Users container.
  3. Locate and then right-click the CN=FederatedEmail.4c1f4d8b-8179-4148-93bf-00a95fa1e042 container. Then, click Delete.
  • Rerun the Exchange Server 2010 Mailbox role setup application.
  • Create a new federated e-mail account by using the following command: (No change in the below command…just type as it is)
    New-Mailbox -Arbitration -Name FederatedEmail.4c1f4d8b-8179-4148-93bf-00a95fa1e042 -UserPrincipalName FederatedEmail.4c1f4d8b-8179-4148-93bf-00a95fa1e042@<Default_Accepted_Domain>
  • Useful link : http://support.microsoft.com/kb/978776

    Outlook 2010: Information Rights Management with Windows Live ID

    On Outlook 2010, Information Rights Management is a free service from Microsoft which sets specific permissions on your sent emails.If you want to restrict your email from print, copy or forward your sent emails to someone else, then all you need to do is sign up for the Information Rights Management Service..out of the box and requirement is a windows Live ID.
    When you open Outlook 2010 for new email, you will see the ribbon as below on the Option tab.
    Permissions

    If you click this one, and in your organization, if you don’t have IRMS server, below screen will appear.

    IRS
    This is an initial screen to setup the IRMS with windows Live Id.
    Then select “I want to sign up” and click next then select “I have Windows Live ID” and  click next (those who don’t have Windows Live ID, then they have to register one)..Then enter your Live Id and password…and select this computer as Private…then click “Accept” and then click “Finish”…now you are ready to restrict your email. This is a free service from Microsoft and this service will terminate, when ever they wish to do so…Enjoy!!!
    For installing IRMS in your organization, there are useful links which i want to share with you all

    Microsoft Exchange Server – Remote wipe on iphone 3Gs

    Remote Wipe – on iPhone

    This feature is available on Mobile Me for iPhone, but you have to subscribe this account…if you have exchange server in your organization/company….below article is for you guys…!!!

    Mobile phones can store sensitive corporate data and provide access to many corporate resources. If a device is lost or stolen, that data can be compromised. Microsoft Exchange Server 2010 / 2007 provides a remote device wipe feature. You can issue a remote device wipe command from the Exchange Management Shell. Users can issue their own remote device wipe commands from the Microsoft Office Outlook Web App user interface. (For users to do their remote wipe from Outlook Web Access->log into their Outlook Web access->on the right top, there will be a menu called “Options”->click Options–>on the left pane…you will find “Mobile Devices”–>click and select “Wipe all Data from Device…”)

    The remote device wipe feature also includes a confirmation function that writes a time stamp in the sync state data of the user’s mailbox. This time stamp is displayed in Outlook Web App and in the user’s mobile phone properties dialog box in the Exchange Management Console.

    So to test this feature, i’ve done the remote wipe from my Exchange server  to my iPhone 3Gs…(This server should be mailbox store where the mailbox properties of each user displayed) as displayed below.

    Select the user whom you want to do the remote wipe, Click on Manage mobile device…

    From the “Managed mobile device for….” area, select the iPhone, which is listed for this particular user, and at the bottom area where “Action” pane….select “Perform a remote wipe…” and then click “Clear” button.

    IF YOU ARE DOING THIS AS A TEST, MAKE SURE THAT YOU TAKE A BACKUP OF YOUR IPHONE FROM ITUNES FOR LATER RESTORE MODE…VERY IMPORTANT.

    Once this action is done, the next sync from the mobile to the server, Wipe command executes on the iPhone device..and screen goes blank….cool..No tention about the contacts or data.

    Now the hardest part is …this sounds great on, when you lost your iPhone and your IT team secure your data safe…!!!! but if you are doing a test on your own iPhone…errrrrrrrrrrrrrrrrrrrrrrrrrr

    After the remote wipe…iPhone just hung and display only Apple logo….for a very long time…(i never had a patient to wait…so i hard boot it…still the same logo smiling at me…and my colegues are telling me…”I told you…i told you…)

    Next step is to take the iphone to the next level….First Switch off the phone.. take it to DFU mode!!!! What is this? DFU (Device Firmware Upgrade) mode is not the same as restore mode. DFU mode bypasses the current OS installed and allows you to upgrade or downgrade your OS.

  • Attach the iPhone to the PC/MAC (make sure that your USB bay on your computer is working and the cable from apple too)
  • Turn the iPhone power off
  • Hold power and home together for *exactly* 10 seconds
  • Release power but keep holding home button in your phone until the PC/MAC beeps as a USB device is recognized.
  • At no point will the display come on with a USB symbol and iTune. Now your restore should work…iTunes will turn on and will ask you to upgrade the firmware and it starts downloading the firmware from apple site and once it is done,
  • Your restoress starts on the iphone…
  • After it is done, Device will get activated…but make sure that all the sync you should choose to “NONE” (There is a reason for this…believe me)…NO NEED TO CONFIGURE ANYTHING…BECAUSE WE ARE GOING TO RESTORE IT.
  • When we are doing all these stuff, there must be a mail from Exchange server to the selected user, in that user name.. in his/her inbox…a cool one like below..(i did not get this pic so i choose one from the net..instead of Device Type as PocketPC…our case it will show iPhone)
  • Read the red line…cool is’nt it…now you go back to Exchange server where you initiate the wipe..remove the device from the user list…and then clear the data….now your iphone is ready to sync
  • If you don’t do it, in my case..i was busy with restore option and did’nt saw the mail and once i restore from my backup…syncing contacts….gone again…thats a real pain…i’ve to do all from scratch…!!
  • Now connect your newly restored iPhone…it will show you on the iTunes area..Rightclick on the iPhone name and click Restore from Backup…and select the time you did last backup.
  • Now you iPhone is back as it was before….HOPE YOU WILL FIND A LOT OF MISSED CALL NOTIFICATION..
  • ENJOY…!!!!

    Microsoft Outlook 2010 – Social connector

    The all-new Outlook Social Connector connects you to the social and business networks you use, including Microsoft SharePoint, Windows Live, and other popular third-party sites, so you can get more information and stay in touch with the people in your network without leaving Outlook…..Stay up-to-the-minute with the people in your networks by accessing everything from e-mail threads to status updates in one single, centralized view.

    Stay up-to-the-minute with the people in your networks by accessing everything from e-mail threads to status updates in one single, centralized view.

     Synchronize your contact data right into Outlook 2010 and obtain information about your friends and colleagues. See status updates from various networks and recently posted files—even view shared photos
    Connect to SharePoint Server 2010 social data and receive updates from your workplace, such as newly posted or tagged documents, site activity, and more.
    Easily track your communication history. Use the Outlook Social Connector to display a quick view of related Outlook content when you click on a contact’s name, such as recent e-mail conversations, meetings, and shared documents.

    Top 10 benefits of Outlook 2010 – using Microsoft Office professional plus…this version has the social connector…all you need is to  install it

    Top 10 benefits of Outlook 2010 using Business Contact Manager – using Microsoft Office professional plus

    Outlook 2010 Social Connector

    Connecting Outlook to each social network requires a provider. To get started, download and install social network provider for Outlook.

    Linkedin Outlook 2010 connector, download here once you finish installing it, re-start Outlook 2010

    Enjoy…!!!!

    Exchange server 2010 – ActiveSync – Issues on Administrative group members

    For your information, When you are running Exchange server 2010 active sync on a mobile device, make sure that the user you are testing is not  a member of any administrator group. In Exchnage 2010, by default if a user is a member of any Administrator group, then he will not be able to sync his mobile device..

    Make sure that you have to open TCP Port 443 on the firewall to listen.

    If you have to test a user, who is falling under any administrative group,  then on active directory users and computers –>view menu select Advanced options–>then user properties->select the security tab->click advanced and ensure that  inheritable permissions check box has to be checked

    Exchange Server – Autodiscovery – A New turn on Exchange14/2010

    As you are aware of the autodiscovery feature from Exchange server 2007, with outlook 2007, this feature has gone a far ahead to reduce the RPC over HTTPS configuration headaches or the outlook configuration for client which is part of the network and is sitting outside the firewall…good na. Here i’m talking about the server in a domain…autodiscovery works a bit different on Non-domain platform..configuration is slightly different.

    When you upgrade Exchange server 2007 to SP2, this is going to be a bit demanding task. clients connecting from outside and inside starts demanding for authentication…in which you need a SSL certificate with Subject Alternative Names (SAN) specified..

    Once the upgrade is done, Autodiscover information is stored in a so called SCP or Service Connection Point. You can view this SCP using Active Directory Sites and Services after you have enabled the “View Services Node” option. (When installing the Client Access Server (Autodiscover is part of this Server Role) the SCP is automatically created in Active Directory and configured with the default values. If you have multiple CAS Servers there will be multiple SCP’s as well)…now will see  how to configure Microsoft  Exchange  services,  such as the Availability service, for the Autodiscover service on a Microsoft Exchange Server 2007 computer that has the Client Access server role installed.  When you enable Outlook Anywhere, you must also configure external access to Microsoft Exchange services for the Autodiscover service. This includes the URLs for the Availability service, Exchange Web Services, Unified Messaging (UM), and the offline address book. If you do not configure the external URL values, the Autodiscover service information provided to the Microsoft Office Outlook 2007 client may be incorrect for clients that are connecting from outside your network. They may be able to connect to their Microsoft Exchange mailbox. However, they will be unable to use Exchange features such as Out of Office functionality, the Availability service, Unified Messaging, or offline address book downloads. Generally, the internal URL is configured by Microsoft Exchange Setup. However, the external URLs must be configured by using the virtual directory cmdlet for each component

    In general – Autodiscover service provides the following information to the client computer that is running Outlook 2007:

    • The user’s display name.
    • Separate connection settings for internal and external connectivity.
    • The location of the user’s Exchange 2007 server that has the Mailbox server role installed.
    • The URLs for Exchange features such as free/busy information, UM, and the OAB.
    • Outlook Anywhere server settings. Outlook Anywhere was formerly known as RPC over HTTP.

    So when a user starts Outlook 2007 for the first time, they no longer have to specify any information if their computer is joined to the domain. Outlook 2007 will start, gather the information automatically, log the user on to their mailbox, and begin retrieving information from your Exchange deployment.

     * Exchange Management Shell to configure the external host name for Outlook Anywhere for the Autodiscover service

    Enable-OutlookAnywhere -Server HnC01 -ExternalHostname “mail.company.com” -DefaultAuthenticationMethod “Basic” -SSLOffloading:$False

    * Exchange Management Shell to configure the external URL for the offline address book for the Autodiscover service

    Set-OABVirtualDirectory -identity “HnC01\OAB (Default Web Site)” -externalurl https://mail.company.com/OAB -RequireSSL:$true

    * Exchange Management Shell to configure the external URL for Unified Messaging for the Autodiscover service

    Set-UMVirtualDirectory -identity “HnC01\UnifiedMessaging (Default Web Site)” -externalurl https://mail.company.com/UnifiedMessaging/Service.asmx  -BasicAuthentication:$True

    * Exchange Management Shell to configure the external URL for Exchange Web Services for the Autodiscover service

    Set-WebServicesVirtualDirectory -identity “HnC01\EWS (Default Web Site)” -externalurl https://mail.company.com/EWS/Exchange.asmx -BasicAuthentication:$True

     To troubleshooting your Autodiscover configuration, ther is a site which is developed by a few guys from the Microsoft Exchange Product Team to test Remote Analyzer that is available on the Internet

    Microsoft Exchange server 2010 Deployment Assistant

    A good tool…

    Microsoft Exchange Server 2010 introduces the Exchange Deployment Assistant or ExDeploy, a new Web-based tool that can help you with your Exchange deployment. ExDeploy asks you a few questions about your current environment and then generates a custom checklist and procedures that help simplify your deployment. 

    You can use ExDeploy for the following scenarios:

    • Upgrade from Exchange Server 2003 
    • Upgrade from Exchange 2007
    • Upgrade from mixed Exchange 2003 and Exchange Server 2007 
    • New installation of Exchange 2010

    For more info click here

    Microsoft Exchange 2010 – Dumpster

    Dumpster is essentially a view stored per folder.  Items in the dumpster  stay in the folder where they were soft-deleted (shift-delete or delete from Deleted Items) and are stamped with the ptagDeletedOnFlag flag.  These items are special-cased in the store to be excluded from normal Outlook views and quotas.  In addition, data with this flag cannot be searched or indexed. 

    Key architectural changes in Exchange 2010 must meet these requirements

    • Exchange has to ensure that dumpster data moves with the mailbox.
    • Dumpster data must be indexed and discoverable.
    • Dumpster must have a quota.
    • Exchange has to prevent purging of data from dumpster.
    • Exchange has to track edits of certain content.
    • Dumpster should be per mailbox and not per folder.

    To facilitate these requirements, Dumpster was re-architected, Dumpster 2.0 is no longer simply a view…Dumpster in Exchange 2010 is implemented as a folder called the Recoverable Items and is located within the Non-IPM subtree of the user’s mailbox (note that this is a hidden section of the mailbox and is not exposed to the end user through any client interface).  The folder has three sub-folders:

    1. Deletions
    2. Versions
    3. Purges

    Dumpster data is now indexed and discoverable,  can now be moved with the mailbox, and is now stored on a per-mailbox basis rather than a per folder basis. Exchange 2010 includes capability for each mailbox to also maintain an archive mailbox as well.  There is a dumpster for both the primary mailbox and the archive mailbox. Data deleted in the primary mailbox is placed in the primary mailbox dumpster, while data deleted in the archive mailbox is placed in the archive mailbox dumpster. Unlike previous exchange server, Exchange 2010 automatically purges items from dumpster 14 days by default and 120 days for calendar items..you can set this up..

    Exchange 2010 includes the ability to ensure that data within the mailbox is preserved for a period of time…short term or long term.  This feature can be enabled enabled on a per mailbox basis by running the following cmdlet:  Set-Mailbox <identity> -SingleItemRecoveryEnabled $true