Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Bandire
Jul 12, 2002

a rabid potato

J posted:

Happy 2022 to any suckers like myself still responsible for on-prem exchange, your mail flow is probably down! Fortunately there is a workaround that is easy to do even if you're still drunk.

https://borncity.com/win/2022/01/01/exchange-fip-fs-scan-engine-failed-to-load-cant-convert-2201010001-to-long-1-1-2022/

Disable-antimalwarescanning.ps1 as seen here: https://docs.microsoft.com/en-us/exchange/disable-or-bypass-anti-malware-scanning-exchange-2013-help got our mailflow working again.

Seriously wtf. Luckily I discovered the problem early in the evening because of external mail flow monitoring. I'm not even sure if this is something that can be fixed by automated self updating.

Its kind of amazing that the cause is the variable they use for the definitions serial number is too small when the year rolled over to 2022, and the failurestate is oops no mail flow.

Adbot
ADBOT LOVES YOU

Bandire
Jul 12, 2002

a rabid potato

Do you get any errors running an autodiscover/Outlook connectivity check on https://testconnectivity.microsoft.com/ ?

Bandire
Jul 12, 2002

a rabid potato

Yep, Enabling modern auth and disabling legacy auth are two distinct steps. We are running modern auth preferred, but haven't gotten the go ahead to turn off basic yet.

If this is working for non-domain joined machines, it sounds like it could be something in your provisioning process that changed. Are the affected boxes in the same OUs/SGs/GPOs as the ones that work?

Bandire
Jul 12, 2002

a rabid potato

Maybe get a freshly imaged machine before it is domain joined and test. If that works, then join it to the domain and test both local and domain accounts, and then disjoin it from the domain and test one more time.

Bandire
Jul 12, 2002

a rabid potato

Thanks Ants posted:

Is there a reference anywhere to the default permissions on the "Organization Management" role group in Exchange Online? Someone has hosed with ours and I've copied the permissions from another tenant but would prefer to be able to compare them to the defaults / run a PS command to reset it if that exists.

You'll want to look at reinstalling the canned RBAC roles. I've never had to do this before, but it could help your situation. Disclaimer here is you could end up with redundant groups and more cleanup after.

https://everything-powershell.com/exchange-2019-reset-rbac-to-default/

Bandire
Jul 12, 2002

a rabid potato

Using an external bulk sender that is already having RBL problems still means those external people will have trouble receiving mail, even if you circumvent the problem with internal recipients.

The most reliable way to do this is likely with an internal DL that contains your internal people and mail contacts for the external users. You can hide the DL and contacts from the GAL if needed and sender restrict the DL so that only permitted people can send to it. What kind of problem would creating mail contacts create beyond the obvious object management headache?

Bandire
Jul 12, 2002

a rabid potato

minusX posted:

We have just shy of 11k AD objects for users that don't have internal e-mails (some which might be termed users that were missed mind, but blue collar workers who aren't doing e-mails to/from the company) and adding that many e-mail contacts will be a mess. Plus we're going to run into send limits with that number for sure.

Also the AD objects are connected to Workday in some way, but none of the personal data (including personal contact e-mail) is synched and I know I personally wouldn't want to have that added in a way that others might be reaching out to me or connecting me to that e-mail address for other reasons.

Yeah that's a lot. Exchange only counts a DL as one recipient, but you may run in to issues with external email services. If ClickDimensions will let you create a DL on their side that you can email, you could create a local DL with your internal addresses plus a mail contact for that external DL and then sender restrict/hide both. That would get the CEO a single address to email.

Adbot
ADBOT LOVES YOU

Bandire
Jul 12, 2002

a rabid potato

Mierdaan posted:

Can/does ClickDimensions add any specific message headers you can whitelist?

That may not help with RBL'd MTA's though. In my experience (Mimecast most recently), an email coming from a blacklisted IP is rejected before any header data is accepted.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply