Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Mierdaan
Sep 14, 2004

Pillbug
Where is get-exchangeserver actually pulling info from?

code:
Name                      ServerRole    Edition AdminDisplayVersion
----                      ----------    ------- -------------------
ex14cas01    ClientAccess, HubTransport   Standard Version 14.3 (Build 123.4)
ex14mbx01                    Mailbox Enterprise Version 14.3 (Build 123.4)
ex14et01                        Edge   Standard Version 14.2 (Build 247.5)
In this case, the ET server is also on 14.3 but get-exchangeserver run from any of the AD-integrated servers doesn't realize that. I think if I deleted and recreated the edge sync subscription, it'd show the correct version, but that's silly. Also, get-exchangeserver run from the ET server itself still shows a decomissioned Exchange 2007 server.

It's all just cosmetic, but still.

Adbot
ADBOT LOVES YOU

Mierdaan
Sep 14, 2004

Pillbug

Will Styles posted:

Technet has something similar to what you're seeing for Exchange 2007, maybe the same issue was carried into 2010?


Edit: Edge synchronization is still happening right? This is just a exchange server version display issue and not that the sync isn't running?

Right, it's just cosmetics. EdgeSync is running fine. I'm assuming that because the ET isn't integrated into AD there's no easy way to discover a version.

Mierdaan
Sep 14, 2004

Pillbug

KS posted:

We'd need the ability to archive all received and sent email indefinitely, with no user intervention or control necessary. We have enterprise CALs that we bought for the litigation hold feature, which I believe entitles us to use archiving as well. Is the built in archiving solution good enough to do what we need? Any third party recommendations?

We use GFI MailArchiver, and I can say that it's very infrequently the worst part of my day. I'm fairly certain that counts as a glowing recommendation in the email archive software space.

Mierdaan
Sep 14, 2004

Pillbug

Bob Morales posted:

Any suggestions on hosted spam filtering companies?

We've used MailMax and WebSense mail filtering. But the problem is that they silently drop false positives. That means we don't get a chance to whitelist or allow senders and usually don't know we are missing their messages for days or even weeks and this causes a bunch of problems.

What we'd really like it something with a feature that lets us see every single message blocked by the server and search through them, cases like these keep happening and it's biting us in the rear end when it's an important email.

Bob Morales posted:

GFI has a few products which can do things on outgoing emails such as insert those stupid disclaimers or check for keywords and file attachments. Other companies offer similar solutions that tie in to the Exchange message sink

http://www.gfi.com/products-and-solutions/email-and-messaging-solutions/gfi-mailessentials/specifications


Those two posts confused the hell out of me, because it sounds like you're answering your own question. Is your problem that a Barracuda Spam Firewall isn't a hosted solution? Because they do have a message log you can search through for dropped messages, as long as they're not dropped at the connection-level (e.g. rate-limited or something).

Mierdaan
Sep 14, 2004

Pillbug
What kind of troubleshooting abilities do you get for either of Google Apps or O365? We're an on-prem Exchange shop so that's what I'm used to, but we have a small org (5 people) on Google Apps as well and when they tell me "hey, can you tell me why this email didn't hit my inbox" I just shrug and tell them no.

Mierdaan
Sep 14, 2004

Pillbug

Caged posted:

Google Apps has full message tracking. I've never had issues with finding 'lost' emails.

I don't have an Email Log option on that left menu.

Mierdaan
Sep 14, 2004

Pillbug

Caged posted:

What edition of Apps are you on? This is the Business one.

We're grandfathered in on the free plan.

Mierdaan
Sep 14, 2004

Pillbug

NevergirlsOFFICIAL posted:

I mean just from a cost perspective it's a horrible idea

I'd assume he has MSDN licensing for it... Right?

Mierdaan
Sep 14, 2004

Pillbug

Lord Dudeguy posted:

:edit: Ah, gently caress. My server is severely underpowered/oversubscribed, isn't it? :doh:

More than likely, but it depends on the profile of your users. Definitely sends up red flags at those numbers though.

Mierdaan
Sep 14, 2004

Pillbug
loving Exchange. I've got a new user who just will not show up in my address lists / OAB. The OAB contains the address list in question, the Address List Preview shows the particular user, I've forced regeneration of the address lists and OAB (with logging turned up - nothing worrisome), taken Outlook in/out of Cached Exchange Mode, and verified that the user doesn't even show up in the lists via OWA. I don't know what the hell's preventing this user from showing up.

No, "Hide from address lists" is not checked.

Mierdaan
Sep 14, 2004

Pillbug

The Electronaut posted:

Can the user open their mailbox?

Not sure, they haven't started yet, but I don't have any reason to assume they can't.

Will Styles posted:

Get-Mailbox user | select OfflineAddressBook,AddressListMembership,AddressBookPolicy

Are these populated?

OfflineAddressBook isn't, but their ABP is which contains an OAB.

Mierdaan
Sep 14, 2004

Pillbug

Will Styles posted:

What about AddressListMembership? If they don't have at least one address list listed in this property they won't appear in the address book at all. Specifically for the GAL your global address list needs to be listed here (Exchange default being "\Defaul Global Address List")

If it is null then simply hiding/unhinding the user should fix it since you can't modify this attribute directly in powershell.

AddressListMembership wasn't blank, they were members of several groups - including our org's GAL.

I ended up spending like 2 hours looking at this before I just blew away the user's account and reprovisioned it using exactly the same script; works fine now. :iiam:

Mierdaan
Sep 14, 2004

Pillbug
I may have hit that bug in Exchange 2007 a few years ago, but my fix was to turn off IMAP. I suppose that's not an option? :)

Mierdaan
Sep 14, 2004

Pillbug

carlcarlson posted:

And this is what I'd like to do going forward so I don't have to deal with lovely PSTs any more. I've got a demo on Thursday with Message Logic, they have a VM ready archive product which seems like it could do the trick. He already sent a quote, so a 200-user per year license is $3,900. Compared to what we pay for other legal expenses it's a drop in the bucket, but that still seems like an awful lot of money. I imagine any other similar product would probably be along the same lines though.

If that's too pricey, look into GFI MailArchiver. That's what we use, just pulling right from a journaling mailbox into read-only (SQL-backed) Archive Stores based on quarter. You can feed your PSTs back into the journal mailbox to populate historical data - ask me about loading 7 years worth of historical email in from PSTs written to CDs/DVDs!

Mierdaan
Sep 14, 2004

Pillbug

KennyTheFish posted:

I am happy with GFI. the support has been good.

I'm happy with GFI MailArchiver, though I think their support can be pretty lovely sometimes. I opened a ticket about a bug where the advanced search criteria reset for an undetermined reason, and their support staff closed it and said "That's the way it's supposed to work. You can submit an enhancement request to not have the search criteria reset randomly."

Great, thanks guys.

Mierdaan
Sep 14, 2004

Pillbug

Tab8715 posted:

Yea, that makes sense but I'm sort confused how come they don't have this listed in the TechNet Article? Or am I reading this wrong? Get-DistrobutionGroup.

Welcome to PowerShell. Remember that get-distributiongroup is returning an object, and each object should have an XML file describing its default formatting options. You can get around this with format-table or format-list, which will ignore the default formatting instructions.

Just wait until you run across stuff like get-aduser, which not only has the same default formatting issue, but only returns a subset of the object's properties even if you specify format-list. To get the rest of the properties, you have to explicitly ask for them.

code:
> get-aduser jsmith | fl extensionattribute*

> get-aduser jsmith -properties * | fl extensionattribute*

extensionAttribute1 : 10-04
extensionAttribute2 : 2013-01-07

Mierdaan
Sep 14, 2004

Pillbug

Just out of curiosity, what wasn't Barracuda doing that you wanted it to do? Per-user quarantine summaries are A Thing It Can Do, complete with Deliver|Whitelist|Delete|View links for each email in the quarantine.

Mierdaan
Sep 14, 2004

Pillbug
It's finally happened. Trying to track down a deliverability problem, eventually it came down to...

quote:

The issue is down to the internal ip range used by (company) internally, for historical reasons, this is 50.x.x.x which happens to clash with the ip address of your mailserver, so the connection fails.
If you try sending email to the (company) domain via a smarthost (e.g. your isp), this should hopefully work around this issue (unless your isp has an ip from the same range)

Anyone have a good smarthost recommendation? :downs:

Mierdaan
Sep 14, 2004

Pillbug

LmaoTheKid posted:

Mimecast has served us well.

I talked to Mimecast briefly, but I think our use-case is way too simple for what they do. They didn't even know how to bill me for 50 emails/month for 2 users, just for acting as a relay.

nexxai posted:

Get a basic VPS and set up Sendmail to act as one: http://www.cyberciti.biz/faq/configure-sendmail-as-a-smart-host/

:( Yeah, that's the last resort. I was hoping someone offered a simple relaying service. Anyone heard of AuthSMTP?

Mierdaan
Sep 14, 2004

Pillbug

Caged posted:

Mandrill

Thanks by the way, just what I wanted. It's even free for our pitifully-low volume.

Mierdaan
Sep 14, 2004

Pillbug
Ugh. This one will be fun.

Mierdaan
Sep 14, 2004

Pillbug

Swink posted:

I want the users to get an ndr that explains how to use a file sharing doodad. My hope we'll get less support calls from a comprehensive ndr than the prompt.

How can I apply this to all users for ever?

In the example command NevergirlsOFFICIAL gave, 'cocksucker' is the name of the send-connector, not your end user. I could see how this would be confusing.

Setting it on the send-connector should apply to everyone, as long as you understand which send-connector your users are utilizing.

Mierdaan
Sep 14, 2004

Pillbug
Weird error I can't figure out. I'm trying to add an additional mailbox to an Outlook profile. I have rights to the mailbox, the user is in an address list that is part of the OAB and I can see them in the address list in Outlook as expected. Not hidden from the address lists.

However, when I go to add the mailbox (using the email address of the box, or the alias), Outlook says
code:
The name cannot be resolved.  The name cannot be matched to a name in the address list.
If I plug in the legacyExchangeDN it works just fine. This part of the Outlook GUI isn't particularly informative, so I have no clue why it's failing to resolve for this one mailbox but works for all our other Shared Mailboxes.

Mierdaan
Sep 14, 2004

Pillbug

NevergirlsOFFICIAL posted:

O365 migration Q from on prem Exch 2010 to Exchange Online:


1. Should I still use migrationwiz or can I use built-in migration plan

2. built-in migration plan says don't assign licenses until after migration is over. is this for real?

We're in the middle of this too, so my $0.02

1. I'm doing everything with PowerShell scripts because that's how I roll ¯\_(ツ)_/¯

2. Mailboxes can operate without a license for 30 days without a problem, which is probably why it says that.

Mierdaan
Sep 14, 2004

Pillbug

NevergirlsOFFICIAL posted:

ok BUT if I assign a license to a user and do the migration after, will it screw something up

Nope. You can even reassign a license to a user who already had one, it doesn't matter.

Mierdaan
Sep 14, 2004

Pillbug
We are in the middle of an Office365 deployment here, and while I've got a pretty good handle on the hybrid Exchange portion of it I've got a question about AADSync.

We had a user who was presented with a password expiration prompt when logging in to Office365, even though their AD password wasn't expired yet. Whatever, our integration partner didn't set the password expiration value correctly in our tenant, so we upped that from 90 to 120 days so at least the two expire together.

It did allow him to 'reset' his password from the Office365 login page though, so he's in the weird situation of having a different password in our local AD than Office365 has - even after another AAD sync ran. Is this fix for this to do some Azure AD Basic magic so that we can write-back password changes into our local AD, or is there an option to turn off password resets via Office365, so you have to reset it in local AD like we've always done?

We don't have a very mobile workforce, so the latter's not a bad option for us. Not sure how much work is involved in the former.

Mierdaan
Sep 14, 2004

Pillbug

Thanks Ants posted:

If you're using an AD account synced into O365 you shouldn't be having a password expire or be able to change it online.

If you want password write back from O365 to AD then you need Azure AD Premium.

Huh. Yeah I see that I can't change my password via O365, but I watched him do it so I know he's not crazy. He's even updated his local AD password now to attempt to get them back in sync but the O365 password he set before is still in effect. Just forced a delta sync with
code:
DirectorySyncClientCmd.exe delta
and it doesn't look like it processed any changes for his user.

Mierdaan
Sep 14, 2004

Pillbug

KS posted:

Obvious question: on the user page of the portal, does that user show as "In cloud" or "Synced with Active Directory"? Any differences from your other users there?

"Synced with Active Directory". Only cloud-only accounts we have are our administrative ones. No other differences that I can see.

Mierdaan
Sep 14, 2004

Pillbug
Is EOP's quarantine page horrible for everyone, or is it just some tenant-specific thing? Every time I load it it's like loving error roulette. Probably loads successfully one out of every 20 tries.

Mierdaan
Sep 14, 2004

Pillbug

Old Binsby posted:

it’s poo poo and being phased out in favor of the one at protection.office.com which is slightly snappier but annoying in different ways

https://admin.protection.outlook.com/quarantine is the one i'm using :saddowns:

Mierdaan
Sep 14, 2004

Pillbug

incoherent posted:

Absolutely no communication about winding down these onprem exchange requirements if you're completely over to exchange online!

I watched the video, they basically say to keep using 2016 on-prem so you get your free hybrid key, because they're not ready to announce anything yet. If they're not pushing people to buy licenses and upgrade to 2019, there's at least a hope that removing your last onprem server in a hybrid deploy is "soon".

Mierdaan
Sep 14, 2004

Pillbug
We've been migrated to hybrid Exchange Online for years now, but one of my users just had a very strange error. When she accepted meeting invites from her Outlook client, the responses would fail because she didn't have permissions to send on behalf of a user. That user was herself, and looking at her sent items folder showed that her X500 address was trying to send on behalf of... herself?

Accepting a meeting invite via OWA worked fine, and a restart of Outlook fixed the issue, but has anyone ever seen that before?

https://imgur.com/ySJy1Pj

Adbot
ADBOT LOVES YOU

Mierdaan
Sep 14, 2004

Pillbug

minusX posted:

First part: We're using ClickDimensions

Can/does ClickDimensions add any specific message headers you can whitelist?

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply