2016
764 TopicsDemystifying Certificate Based Authentication with ActiveSync in Exchange 2013 and 2016 (On-Premises
Some of the more complicated support calls we see are related to Certificate Based Authentication (CBA) with ActiveSync. This post is intended to provide some clarifications of this topic and give you troubleshooting tips. What is Certificate Based Authentication (CBA)? Instead of using Basic or WIA (Windows Integrated Authentication), the device will have a client (user) certificate installed, which will be used for authentication. The user will no longer have to save a password to authenticate with Exchange. This is not related to using SSL to connect to the server as we assume that you already have SSL setup. Also, just to be clear (as some people have those things confused) CBA is not two-factor authentication (2FA). How does the client certificate get installed on the device? There’s several MDM (Mobile Device Management) solutions to install the client certificate on the device. The most important part of working with CBA is to know where the client certificate will be accepted (or ‘terminated’). How you implement CBA will depend on the response to following questions: Will Exchange server be accepting the client certificate? Will an MDM or other device using Kerberos Constrained Delegation (KCD) be accepting the client certificate? Learn more on the Exchange blog.2.8KViews4likes0CommentsExchange Hybrid Configuration Wizard error - root element is missing when connecting to 365
Hi Exchange Brain trust, I have an Exchange 2016 environment where I recently joined a Exchange 2019 server to move everything and eventually decommission 2016 server. Everything is configured manually to match what we currently have in 2016 server - configuration wise, they both are identical now. We don't have any mailbox on-prem. Its just being used for administration and SMTP relay. The question is, do we still have to run Hybrid Config Wizard ? The reason I'm asking is, I'm stuck on the following stage with an error I pulled my hair off for hours trying to figure the root cause. Connectivity is all working well. Any idea would be really appreciated !3.2KViews4likes18CommentsReleased: Exchange Server Role Requirements Calculator 8.4
Today, The Exchange Team released an updated version of the Exchange Server Role Requirements Calculator. This release focuses on bug fixes with the DAG auto-calculation functionality that was introduced in 8.3, as well as, support for ReplayLagMaxDelay. For all other improvements and bug fixes, read the Exchange Team Blog.1.3KViews4likes0CommentsReleased: December 2016 Quarterly Exchange Updates
Today, The Exchange Team announced the latest set of Cumulative Updates for Exchange Server 2016 and Exchange Server 2013. These releases include fixes to customer reported issues and updated functionality. Exchange Server 2016 Cumulative Update 4 and Exchange Server 2013 Cumulative Update 15 are available on the Microsoft Download Center. Update Rollup 22 for Exchange Server 2007 Service Pack 3 and Update Rollup 16 for Exchange Server 2010 Service Pack 3 are also available. The updates include: - A new Outlook on the web compose experience - Support for .Net 4.6.2 - Change to Pre-Requisites installed by Setup - Update on Windows Server 2016 support - Latest time zone updates - Important Public Folder fix included in these releases Read more on The Exchange Team blog.2KViews4likes1CommentThe June 2016 Quarterly Exchange Updates are here!
Today Microsoft announced the latest set of Cumulative Updates for Exchange Server 2016 and Exchange Server 2013. In addition to normal fixes to customer reported issues, these releases also include updated functionality. Exchange Server 2016 Cumulative Update 2 and Exchange Server 2013 Cumulative Update 13 are available on the Microsoft Download Center. Read more on the Exchange Blog.784Views3likes0CommentsOn-Premises Architectural Requirements for the REST API
In the near future, hybrid customers will be able to take advantage of the REST APIs for both Office 365 and on-premises mailboxes. The REST APIs (Mail, Calendar, and Contact APIs), simplify programming against Exchange by providing a familiar syntax that is designed with openness (e.g., open standards support JSON, OAUTH, ODATA) and flexibility (e.g., granular, tightly scoped permission to access user data). These APIs allow developers to connect from any platform, whether it be web, PC, or mobile. SDKs exist for.NET, iOS, Android, NodeJS, Ruby, Python, Cordova, and CORS for use in single page JavaScript web apps. Get more details on the Exchange Team Blog.1.5KViews3likes0CommentsShared mailbox: Use send-as, not send on behalf from Outlook 2016
Hello, We have a lot of shared mailboxes. For every shared mailbox, we create a specific security group that contains the members who should have access to that particular shared mailbox. We give full mailbox permissions and send-as permissions for that particular security group onto the shared mailbox. For example, security group A has full mailbox access and send-as permissions onto shared mailbox A. By adding users to security group A, they have full access to the shared mailbox. We create every new shared mailbox/security group combo using Powershell. That has been working flawlessly for the last years. However, for a recent new shared mailbox/security group combination, when a user that's member of the related security group wants to send an e-mail from the shared mailbox (by changing the from field in Outlook and selecting the shared mailbox from the global address list), Outlook tries to send every time 'send-on behalf'. This only happens for that newly created mailbox. I compared the output of Get-Mailbox and Get-RecipientPermission for the new problem shared mailbox and an older shared mailbox (which enable users to send mail send-as from outlook just fine) but I couldn't find any differences. For your information, that's the error we get back immediately after trying to do a send-as for the new shared mailbox: Your message did not reach some or all of the intended recipients. Subject: Test from Outlook Sent: 23/11/2017 9:27 The following recipient(s) cannot be reached: name of sending user on 23/11/2017 9:27 This message could not be sent. Try sending the message again later, or contact your network administrator. You do not have the permission to send the message on behalf of the specified user. Error is [0x80070005-0x0004dc-0x000524]. Why does Outlook always tries to do a send on behalf (what we don't want) where else for other shared mailboxes, send-as works fine? Using send-as from OWA however works just fine for the newest shared mailbox. It only seems a problem related to Outlook (tested on multiple clients that have access to the shared mailbox) and that particular new shared mailbox. Thanks in advance.Solved317KViews3likes13CommentsFocused Inbox not working
Finally got Focused Inbox to appear in my Windows Outlook 2016 client yesterday, after finally enabling Modern Authentication in our Exchange Online tenant. It had been present and working in my Mac Outlook 2016 client, as well as in both OWA and iOS Outlook clients, just missing from the Windows Outlook 2016 client. However, it seems to have stopped working, in all clients! So, two things have occurred recently, which may have affected this functionality. (1) A few days ago, I uninstalled and reinstalled the Office 2016 suite on my Macbook, and installed the latest version from our Office 2016 tenant (E3 corporate license). I only mention this because I saw someone else report a similar problem that started after installing or upgrading his Mac client. (2) I enabled Modern Authentication in our Exchange Online tenant yesterday. I don't believe this to be the culprit because Focused Inbox is confirmed working for at least one of my co-workers, so the problem seems to be limited to my mailbox. I've reviewed both the tenant and mailbox settings, and both show Focused Inbox as enabled. Where else can I check, or how else can I troubleshoot this issue? I'm really bummed because Clutter was so useful, and now everything is going to my inbox. I've been using "Move to Other" all day, but so far it's not getting the hint. :) Any ideas? Thanks!36KViews2likes24CommentsHelp us test Exchange 2013/2016 to Exchange Online public folder migration
Read more on TechNet. Right on the heels of our recent TAP program announcement, we wanted to see if there are customers who would like to help us validate migration of modern public folders from Exchange 2013/2016 to Exchange Online (EXO). This is a scenario that at this time we do not support, but plan on doing so. Estimated availability of bits for testing those topologies (subject to change): Exchange 2013 public folders > EXO: September 2016 Exchange 2016 public folders > EXO: November 2016 In order to participate, you will need to enroll into the above mentioned TAP program. If you are interested in trying out the migration, please contact the PF migration team atmodernpfmigrationtoexo@service.microsoft.com with the following details: Organization Name Exchange version Total size of Public Folders Number of PF mailboxes Largest Public Folder size Total count of Public Folders Count of Mail enabled Public Folders Which clients are used by users to access PF? Number of users Number of exchange server installations Is Exchange Hybrid setup done? When is the plan to migrate users to EXO? We will review the details and see if we can on-board the organization into TAP/Beta program. We are looking for customers with <250GB of public folder data.1.1KViews2likes1Comment