Exchange Hybrid: Deployment, best practices, and what’s new

Slides:



Advertisements
Similar presentations
MEC /5/2017 7:36 PM © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks.
Advertisements

 This session details common scenarios for deploying Office 365 services. Office 365 provides a breadth of capability, but often there is a key scenario.
Module 12 Upgrading from Exchange Server 2003 or Exchange Server 2007 to Exchange Server 2010.
Module 6 Implementing Messaging Security. Module Overview Deploying Edge Transport Servers Deploying an Antivirus Solution Configuring an Anti-Spam Solution.
MCSE Guide to Microsoft Exchange Server 2003 Administration Chapter 14 Upgrading to Exchange Server 2003.
Microsoft ® Exchange Online Migration and Coexistence Name Title Microsoft Corporation.
Identity management integration options for Office 365
Microsoft Ignite /16/2017 4:33 PM
4/16/2017 © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks.
Version 2.0 for Office 365. Day 1 Administering Office 365 Day 2 Administering Exchange Online Office 365 Overview & InfrastructureLync Online Administration.
IMAP migration Cutover migration Staged migration 2010 Hybrid2013 Hybrid Exchange 5.5 Exchange 2000 Exchange 2003 Exchange 2007 Exchange 2010 Exchange.
Keys to a Successful Hybrid Deployment Tips and Tricks from the Field.
Configuring Hybrid Exchange the Easy Way
Archiving in the cloud with Exchange Online Archiving Bharat Suneja Sr Technical Writer | Exchange Microsoft Corporation EXL301.
Archiving in the Cloud with Exchange Online Archiving BHARAT SUNEJA SR TECHNICAL WRITER | EXCHANGE MICROSOFT CORPORATION EXL301.
1 © 2001, Cisco Systems, Inc. All rights reserved. Voice Connector Features Voic Interoperability – 4.0(5) Voice Connector features Rahul Singh.
TechEd /20/2017 2:02 AM © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks.
Introduction 4 FeatureSimpleHybrid Mail routing between on-premises and cloud (recipients on either side) Mail routing with shared namespace (if desired)
Exchange 2010 Recipient and Mailbox Management IT:Network:Applications.
Managing Client Access
Module 4 Managing Client Access. Module Overview Configuring the Client Access Server Role Configuring Client Access Services for Outlook Clients Configuring.
Introduction Please answer the survey questions posted at the end of this meeting. Let us know what sessions you want! Josh Topal at
Scenario covered in this presentation Separate credential from on- premises credential Authentication occurs via cloud directory service Does not.
Office 365 Exchange Online Migration Overview. Catapult Overview  An independent wholly owned subsidiary of CSI since 2013  Privately founded in 1993,
Cisco Confidential © 2010 Cisco and/or its affiliates. All rights reserved. 1 SAN Certificate in Unity Connection Presenter Name: Bhawna Goel.
Chris Goosen Infrastructure Consultant Kloud Solutions.
Timothy Heeney| Microsoft Corporation. Discuss the purpose of Identity Federation Explain how to implement Identity Federation Explain how Identity Federation.
©Kwan Sai Kit, All Rights Reserved Windows Small Business Server 2003 Features.
Copyright ®xSpring Pte Ltd, All rights reserved Versions DateVersionDescriptionAuthor May First version. Modified from Enterprise edition.NBL.
MIGRATING FROM MICROSOFT EXCHANGE SERVER AND OTHER MAIL SYSTEMS Appendix B.
Exchange Online Protection. About Speaker Prabhat Nigam Microsoft MVP: Exchange Server MCSE: Messaging 2013, MCITP 2010/2007, MS Ex – Microsoft Exchange.
Click to edit Master title style TechNet goes virtual ©2009 Microsoft Corporation. All Rights Reserved. TechNet goes virtual Upgrading and Coexisting with.
New SharePoint 2016 Features
…. PrePlanPrepareMigratePost Pre- Deployment PlanPrepareMigrate Post- Deployment First Mailbox.
Module 4 Planning and Deploying Client Access Services in Microsoft® Exchange Server 2010 Presentation: 120 minutes Lab: 90 minutes After completing.
Virtual techdays INDIA │ august 2010 virtual techdays INDIA │ august 2010 Moving/Co-existing your messaging platform to the cloud with Exchange.
Office 365 deployment choices Cutover, Staged, Hybrid What is AD FS (Active Directory Federation Services) Attribute Stores, ADFS Configuration Database.
Module 12 Integrating Exchange Server 2010 with Other Messaging Systems.
Lync Server Private cloud / dedicated Lync Server Single domain & directory Users split – server / online Lync Hybrid Office 365 Lync Online Hosted.
Office 365 hur kommer du dit – på riktigt Magnus Björk Altitude 365.
Module 12 Upgrading from Exchange Server 2003 or Exchange Server 2007 to Exchange Server 2010.
Module 11 Upgrading to Microsoft ® Exchange Server 2010.
DMI202 Experience Value Early New Cloud Experience Real World Benefits Broad Production Use Full Feature Value Meet your needs Deploy Enhance Pilot.
Module 7 Planning and Deploying Messaging Compliance.
Integrating and Troubleshooting Citrix Access Gateway.
ON YOUR TERMS Business needs * Enhanced by upcoming Azure IAAS features GoodBetterBest * * GoodBetterBestGoodBetterBestGoodBetterBestGoodBetterBestGoodBetterBest.
Configuring and Troubleshooting Identity and Access Solutions with Windows Server® 2008 Active Directory®
Implementing Microsoft Exchange Online with Microsoft Office 365
Exchange Hybrid Deployments: Stairway to Heaven or Highway to Hell?
DNS DNS changes required to validate domains in Office 365 UPN – User Principal Name Every user must have a UPN UPN suffixes must match a validated.
#SPSMX Hybrid Environments SharePoint On-premises & SharePoint Online Luis Du Solier SharePoint Premier Field Engineer Microsoft.
BE-com.eu Brussel, 26 april 2016 EXCHANGE 2010 HYBRID (IN THE EXCHANGE 2016 WORLD)
Agenda  Microsoft Directory Synchronization Tool  Active Directory Federation Server  ADFS Proxy  Hybrid Features – LAB.
Appendix B Advanced Topics in Exchange Server 2010.
Microsoft Virtual Academy Dean Yamada | Senior Premier Field Engineer, Microsoft Stephen Hall | Cloud Solutions Specialist, District Computers.
 Step 2 Deployment Overview  What is DirSync?  Purpose – What does it do?  Understanding Synchronization  Understanding Coexistence  Understanding.
Preparing Identities for the Cloud Randy Robb 2016 Redmond Summit | Identity Without Boundaries May 24 th 2016 Senior Consultant
Deployment on your terms Hybrid Exchange deployment on your terms On-premises.
Office 365 Migration Challenges Drew St. John 2016 Redmond Summit | Identity Without Boundaries May 24, 2016 Consultant
Jhong Catane Exchange Hybrid Deployment PRD34 2.
När verkligheten hälsar på
z/Ware 2.0 Technical Overview
Exam in just 24 hours!!! Pass your exam in first attempt by the help of our latest braindumps
Office 365 – Understanding Migrations: Hybrid migrations
Exact Microsoft Exam Dumps Real Exam Questions Answers
Hybrid Search Technical Guidance.
Migrating to Office 365 from Google mail and exchange
SharePoint Online Hybrid – Configure Outbound Search
M6: Advanced Identity Management topics for Office 365
10 | Implementing Directory Synchronization
Presentation transcript:

Exchange Hybrid: Deployment, best practices, and what’s new 4/27/2017 7:59 AM Cloud Roadshow Exchange Hybrid: Deployment, best practices, and what’s new © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Agenda Why Hybrid Hybrid Prerequisites History of the HCW 4/27/2017 7:59 AM Agenda Why Hybrid Hybrid Prerequisites History of the HCW Tour of the new HCW Improved error handling experience © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Why Exchange Hybrid 4/27/2017 7:59 AM © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Calendaring & Free/Busy Microsoft Exchange 4/27/2017 Why Exchange Hybrid? Address Book User Experiences Calendaring & Free/Busy Messaging Mail Migrations Exchange on-premises MRS Mailbox data Office 365 © 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Hybrid benefits vs. other migration options Microsoft Ignite 2015 4/27/2017 7:59 AM Hybrid benefits vs. other migration options Deployment Complexity EASY Really? Hybrid Cutover Staged DirSync/Identity Management Hybrid Configuration Wizard, oAuth,MRS, …. Auto profile updates Batch Approach Offboarding Rich Coexistence No Additional Servers Cloud ID’s Only OST Sync All at Once… DirSync needed No 2010/2013 OST Sync Batch Approach Really? End User Complexity EASY © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Hybrid Prerequisites Have an Office 365 Tenant 4/27/2017 7:59 AM Hybrid Prerequisites Have an Office 365 Tenant Add your domain to the Tenant (Contoso.com) Ensure you have a third party Certificate on-premises Ensure Exchange is properly deployed on-premises Have Directory Synchronization activate and deployed Ensure that you are running in a supported configuration © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Exchange Hybrid Wizard History 4/27/2017 Exchange Hybrid Wizard History 1 2 3 4 5 6 Exchange 2010 SP1 72 pages of documentation Exchange 2010 SP2 HCW introduced Exchange 2013 HCW with web-based UI Exchange 2013 SP1 Exchange 2013 CU5 Exchange 2013 CU10 and 2016 Extremely complex and low adoption Removed confusing requirements for additional domains: exchangedelegation and service.contoso.com Greatly simplified transport configuration Multiple exchange organizations now supported Supports Exchange 2013 Edge Native OAUTH and Gallatin Support Office 365 HCW © 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Hybrid Configuration Engine Microsoft Exchange Hybrid Configuration Engine 4/27/2017 Latest HCW Blob Exchange Online Step 1 Download the latest Hybrid Configuration Engine Organization Level Configuration Objects (Exchange Federation Trust, Organization Reclationship, Forefront Inbound Connector, & Forefront Outbound Connector) Step 2 The Hybrid Configuration Engine reads the “desired state” stored on the HybridConfiguration Active Directory object. Domain Level Configuration Objects (Accepted Domains & Remote Domains) 1 4 Step 3 The Hybrid Configuration Engine connects via Remote PowerShell to both the on-premises and Exchange Online organizations. On-Premises Exchange Organization Level Configuration Objects (Exchange Federation Trust, Organization Relationship, Availability Address Space, & Send Connector) Step 4 The Hybrid Configuration Engine discovers topology data and current configuration from the on-premises Exchange organization and the Exchange Online organization. 5 EAC 3 4 Domain Level Configuration Objects (Accepted Domains, Remote Domains, & E-mail Address Policies) Hybrid Configuration Engine Desired state Topology & current configuration state Execute configuration tasks Step 5 Based on the desired state, topology data, and current configuration, across both the on-premises Exchange and Exchange Online organizations, the Hybrid Configuration Engine establishes the “difference” and then executes configuration tasks to establish the “desired state.” 5 2 Exchange Server Level Configuration (Mailbox Replication Service Proxy, Certificate Validation, Exchange Web Service Virtual Directory Validation, & Receive Connector) © 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

What have we been doing Microsoft Office365 4/27/2017 Piloting of HCW changes is controlled The latest and same version is used by all What have we been doing Supported on Exchange 2013 CU10 and 2016 Resolving the common upgrade issues (upgrade from 2010/2013) Agility with future releases HCW updates not tied to CU’s any longer Improvements to OAUTH and Multi Forest Better Diagnostics built in (HCW and other Troubleshooters) Stand Alone HCW (New Web Based HCW) HCW looks and feels familiar © 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

What does the new experience look like?

Stand Alone HCW Common Questions Will I be able to run it on Exchange 2010? Will I be able to run in on Exchange 2013? Can I upgrade from Exchange 2010 to newer version? Can I opt out of the new HCW experience? Will I need to add any additional URL to my outbound proxy device? Will running the Stand Alone HCW change any of my settings?

Entry Point

4/27/2017 Welcome page © 2015 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Server detection page The configuration will be done from this server 4/27/2017 Server detection page The configuration will be done from this server We check local AD for a list of all Exchange servers and version (this is not a remote call) 1st see if the server we are on is running the latest version 2nd we look to see if a server in site is running the latest version 3rd we cross sight to connect to a random server running the latest version You can manually override this logic You can also specify 21v from this page © 2015 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

4/27/2017 Credential page We do not force you to enter your on-premises credentials You then just provide the cloud creds and we connect © 2015 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

“Enable” Federation Trust page

Shared namespace page We then show you a list of domains that are accepted in both on- premises and EXO This is were you choose your shared domain

Domain Proof We now copy just the string needed, no extra garbage

Mail Flow options Then you choose your familiar mail flow options 4/27/2017 Mail Flow options Then you choose your familiar mail flow options © 2015 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Send and receive server selection 4/27/2017 Send and receive server selection © 2015 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Transport Certificate We then show a list of valid certs.. Third Party Cert SMTP Service Assigned Installed properly on Exchange Not Self Signed

Certificate field is empty Certificate field is empty when running the HCW Certificate not correctly installed Required on selected CAS & MBX CAS are used for Receive Connectors MBX are used for send Connectors Both need same cert installed, else HCW won’t show. Third Party Proper SAN Assigned to SMTP Service Private Key Certificate requirements not met Need access to CRL url over 80 from all servers CRL Blocked

Namespace for on-premises

Ready to update

Scenario / Action Items On the last page Feedback On Every Page Scenario / Action Items Error: Time Offset check on the on-premises server to get Federation to succeed Usability: Scroll bar needed when on accepted domain page Error: Improve the invalid TXT error experience Error: Improve Error experience for Hybrid Domains Error: Add information on certificates to show why it failed Error: Improve error reporting around Autodiscover issues Usability: remove server that are considered deleted objects from view in HCW

Improved Logging (1 of 2) Application version information Log File location: %Appdata%\Microsoft\Exchange Hybrid Configuration Improved Logging (1 of 2) Application version information Exchange versions and other information found that will be used by the wizard

SMTP certificate information from each server Improved Logging (2 of 2) SMTP certificate information from each server Exchange versions and other information found that will be used by the wizard

Better error Handling Link to a Solution Link to log files Link to open Shell with current credentials

Active Monitoring for HCW 2000+ HCW runs every day Validation against multiple Regions and Datacenters Detected 2 Incidents over the last year before ANY customers reported the problems Detected a transient issue with Remote Powershell that are being fixed

4/27/2017 7:59 AM © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

MRS Enablement delays The last portion of the legacy HCW enabled MRS Proxy ERROR:Updating hybrid configuration failed with error 'Subtask Configure execution failed: Configuring organization relationship settings.Execution of the Set-WebServicesVirtualDirectory cmdlet had thrown an exception. This may indicate invalid parameters in your Hybrid Configuration settings. Unable to access the configuration system on the remote server. Make sure that the remote server allows remote configuration This process ran a cmdlet Get-WebServicesVirtualDirectory This added hours to the HCW often killing the HCW This is the longest part of the Hybrid process We have resolved this issue in the Office 365 HCW using the “- ADPropertiesOnly” switch with Get-WebServicesVirtualDirectory

Hybrid Upgrade issues We had issues upgrading Hybrid from 2010 to 2013 The solutions were to perform action like: - rename Org Relationships - rename Connectors for Mail flow - Remove Hybrid configuration objects from ADSIEDIT None of this was graceful and this is all addressed in the Office 365 HCW

Why are the logs so important? Exchange Online We use the logs to find our top problems 30% of our failures come from “execution failed: Creating Organization Relationships.” The point is that we often see customer with Autodiscover configured properly but still fail to complete the HCW… 1 Get-FedInfo does a call to on-prem DNS for Autodiscover.contoso.com 2 If there is no DNS record internally we could fail to complete HCW 3 What if we used External DNS as well? 3 “execution failed: Creating Organization Relationships.” On-premises 1 Exchange On-Premises