Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Thanks Ants
May 21, 2004

#essereFerrari


I assumed that there was a requirement for another group of users to have edit access to the original groups calendars, but not themselves grant edit access to anybody else.

Adbot
ADBOT LOVES YOU

Thanks Ants
May 21, 2004

#essereFerrari


Happiness Commando posted:

I'm an even dumber exchange baby and I need help too.

Hybrid exchange with an on prem shared mailbox that I am trying to move to the cloud. I've been getting error message after error message. I finally got to the point where
New-moverequest - identity "sharedboxonprem" - remote - remotehostname "mail.contoso.com" - targetdeliverydomain "contoso.mail.onmicrosoft.com" -remotecredentials $creds
(where $creds is CONTOSO\mydomainadminaccount)
Gives me a MapiExceptionNoAccess unable to open message store 80070005 error

So it's a problem with permissions - but my user account is a domain administrator and has full rights to the mailbox I'm moving.

Sorry for the phone formatting, I'm not yet comfortable logging in to SA on my work computer

Try providing the credentials of an Office 365 global admin as the $creds variable

Thanks Ants
May 21, 2004

#essereFerrari


Spitballing an idea here. When external senders blast an email to several staff members as well as our help desk address, there are people in our company that will just hit reply-all and this ends up creating multiple tickets. I’m planning on making a transport rule that adds a banner to the top of messages that land into a users mailbox when the message was also sent into a help desk queue basically telling people to respond through the software rather than email.

The bit that I think makes this tricky is that I don’t want the banner to appear on the message being sent to the help desk queue - if I add a filter to exclude messages with the relevant mailboxes in the recipients list then it’s not going to match anything because I think Exchange just sees it as one message as it passes through the transport rules and then expands it afterwards if there are multiple recipients.

Is there a different approach I can take here?

Edit: I can set a custom MailTip on the mailbox which will cover off most of what I want to do, but it will pop up for new messages and also won’t show anything to native iOS users. I’ll start with that though.

Thanks Ants fucked around with this message at 08:42 on Apr 24, 2018

Thanks Ants
May 21, 2004

#essereFerrari


Just went with Mailtips in the end, didn't have the time to spare on looking too closely at the different routing options.

Thanks Ants
May 21, 2004

#essereFerrari


evobatman posted:

Please someone sanity check my plan, because I want to know if I'm on the right track or about to make a huge mistake.

I have inherited an Exchange 2016 installation with about 1300 users and four servers, replicated 1-3 and 2-4, so that we at any time can take down one server for patching, maintenance, upgrade etc.

We have 5 research vessels around the world with anything from 128k-1mbit satellite links. These use cached exchange mode of course, but they are always complaining about slow email. They use shared accounts for the positions on board, such as "Captain", "Technician" and so on. These mailboxes are not used on-shore.

My plan is to put an Exchange server on each ship and to move the mailboxes for the ship positions to these servers. That way, big attachments are sent to the ship only once and then distributed to 40 clients, instead of 40 clients trying to download cat gifs from the onshore mail servers through the tiny tiny bandwidth that barely supports the ships telemetry data.

I want to add a fifth server to our onshore servers to replicate the datastores from the vessels.

The ships have their own domain controllers that are replicated to shore, good ESX hosts, SCCM secondary site and pretty much decent prerequisites for having good infrastructure, besides bandwidth. Let's assume that getting the server software on board the ship won't be an issue.

Am I on the right track here, or is this going to be a disaster? What possible pitfalls/consequences are there?

I have previously worked with oil rigs where they had their own mail server on each rig, and that seemed to work fine. However they were pretty fixed in position and had 4+mbit lines.

I would encourage the use of webmail, with a separate system for distributing large files to people onboard vessels.

Thanks Ants
May 21, 2004

#essereFerrari


I'd have approval to open a per-incident support case in place before you start anything

Thanks Ants
May 21, 2004

#essereFerrari


The corporate email server is for emails from people, and a relay for stuff going to internal destinations (notifications, scan to email etc). All mass mailings go through SES, Mailgun, whatever. Office 365 is quite sensitive to locking down accounts that it thinks are sending outbound transactional email, which is preferable to being blacklisted by a third party but still not great. You don't want marketing screwing up a newsletter to result in your C-levels seeing their emails bounce.

Thanks Ants
May 21, 2004

#essereFerrari


quote:

We are starting to roll out several capabilities Outlook for iOS and Android that address the email and calendar needs for Enterprise customers.

Shared Mailboxes: You will be able read, write and send emails from the Exchange Online Shared Mailboxes in Outlook for iOS and Android. If you are part of the Office Insider program for iOS and using the Microsoft sync technology (MC165218), you will be able get an early preview of the capabilities via TestFlight this week. It is anticipated that we will start to roll out Shared Mailboxes in Outlook for iOS and Android (using Microsoft sync technology) for general availability in the next several weeks.

:woop:

Thanks Ants
May 21, 2004

#essereFerrari


Finally!

https://support.office.com/en-us/article/add-a-shared-mailbox-to-outlook-mobile-f866242c-81b2-472e-8776-6c49c5473c9f

Thanks Ants
May 21, 2004

#essereFerrari


I assume you aren't using Office 365 if that is people's objection to it

Thanks Ants
May 21, 2004

#essereFerrari


What did you do - reinstall and then uninstall?

Thanks Ants
May 21, 2004

#essereFerrari


I thought I'd missed something but angry armadillo's post was from 2011.

Thanks Ants
May 21, 2004

#essereFerrari


It's the closest you'll get to reading a post from the archives

Thanks Ants
May 21, 2004

#essereFerrari


Have you configured SPF and DKIM properly?

Thanks Ants
May 21, 2004

#essereFerrari


If it has a calendar it has a mailbox, so run Add-MailboxFolderPermission -Identity groupname@company.com:\Calendar -User you@company.com -AccessRights Editor

Thanks Ants
May 21, 2004

#essereFerrari


If someone has to "go through a group of users" isn't that basically the same thing as having booking delegates?

Thanks Ants
May 21, 2004

#essereFerrari


Is the shared mailbox so important that you can't rename it and just make a new one?

Thanks Ants
May 21, 2004

#essereFerrari


At last



No more creating a DL and then granting send-as for one person to send out as their alias

Thanks Ants
May 21, 2004

#essereFerrari


2016 and 2019 are new enough that this is just a member server joining an Exchange cluster, picking up roles, running alongside the old server for a bit and then the old server having roles removed before being shut down. As long as your autodiscover points to a server running the mailbox role then you should be golden.

Thanks Ants
May 21, 2004

#essereFerrari


Doesn't the dotted outline represent a tentative event, e.g. your C-level hasn't accepted it yet?

Thanks Ants
May 21, 2004

#essereFerrari


Here are your options

https://docs.microsoft.com/en-us/exchange/architecture/client-access/load-balancing?view=exchserver-2019

Just setting the DNS record with the CNAMEs of all the mailbox servers should get you 99% of the way there, it's probably not worth deploying (redundant) load balancers to add a small amount more availability.

Thanks Ants
May 21, 2004

#essereFerrari


Outlook is getting a new feature if you use Exchange Online, where you can tag external messages in the application rather than having to use a transport rule to banner the messages

I can't see a blog post so you can have these screenshots from the admin portal




The cmdlet is https://docs.microsoft.com/en-gb/powershell/module/exchange/set-externalinoutlook?view=exchange-ps

Thanks Ants
May 21, 2004

#essereFerrari


I’m absolutely paranoid about having things exposed to the internet even if they are designed to be exposed and their network is segmented properly. Always looking for ways to get things working behind reverse proxies or whatever.

Thanks Ants
May 21, 2004

#essereFerrari


I like Migrationwiz but *providing your on-prem Exchange is working well* then doing a hybrid would still be my preferred way to do that migration, even if it's just so everything can be done in phases without anybody noticing.

Thanks Ants
May 21, 2004

#essereFerrari


At a guess you can take the message ID and shove it into eDiscovery and get the message itself, not sure if there's a way to restrict access to just the headers though.

Thanks Ants
May 21, 2004

#essereFerrari


Countries are writing laws about being contacted outside of work, I'd have assumed companies have sprung up to control access to things on a schedule.

Thanks Ants
May 21, 2004

#essereFerrari


So you don't have any on-prem Exchange servers, did you ever have on-prem Exchange, how did you decommission it? Where does autodiscover.yourdomain.com resolve to when you're on the network? Do you still have the SCPs in AD for any on-prem infrastructure?

I presume you are doing Azure AD sync from your AD to Microsoft 365? Do clients work for SSO if you browse to https://outlook.office.com or do they have to authenticate again?

Thanks Ants
May 21, 2004

#essereFerrari


Is there a reference anywhere to the default permissions on the "Organization Management" role group in Exchange Online? Someone has hosed with ours and I've copied the permissions from another tenant but would prefer to be able to compare them to the defaults / run a PS command to reset it if that exists.

Thanks Ants
May 21, 2004

#essereFerrari


This is Exchange Online which as far as I can tell doesn't have that feature

Thanks Ants
May 21, 2004

#essereFerrari


That'll do it, thanks.

Thanks Ants
May 21, 2004

#essereFerrari


I hate Exchange Online but then I have a reason to try and achieve something in Google Workspace and it's a nice reminder of how much worse things could be.

Adbot
ADBOT LOVES YOU

Thanks Ants
May 21, 2004

#essereFerrari


A DL that only certain accounts can send to that then forwards the message to an external mailing list service on a domain that isn't the one you rely on for your main business, so that when a bunch of the delivery attempts fail after people write their personal email addresses down incorrectly it doesn't cause delivery issues for the rest of the company.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply