2016
764 TopicsRule using wildcard (or domain) for handling incoming emails
In line with the email security best practices recommended at Ignite this year, we are blocking our staff from using auto-forwarding rules in Outlook/Exchange Online. However there are valid scenarios where they need to know certain urgent emails have been delivered. We have many staff working for clients or partner companies in sensitive industries where they are not permitted to access Office 365 (or indeed any webmail service) while at work. What I want them to be able to do on their Office 365 email, account is something like: IF sender = *@importantclient.com THEN send notification to myemail@importantclient.com There are variations (perhaps include the subject line or from address in the notification, butt not the content), but that is the general idea. I can do it for fixed email addresses such as knownaccount@importantclient.com, but can't find any way for end users to do this for domains (@importantclient.com or *@importantclient.com) or other wildcards (from:managersname@*). I've tried in Outlook and Flow, but can't seem to make it work. I know it is possible with a Transport Rule, but I don't feel inclined to give my end user enough access to create these, for some strange reason.. Is this doable in O365 in any way (Outlook, Exchange, Flow, anything) in a way that normal (non-technical) users are likely to be able to handle? Thanks, Bob.322KViews0likes12CommentsShared mailbox: Use send-as, not send on behalf from Outlook 2016
Hello, We have a lot of shared mailboxes. For every shared mailbox, we create a specific security group that contains the members who should have access to that particular shared mailbox. We give full mailbox permissions and send-as permissions for that particular security group onto the shared mailbox. For example, security group A has full mailbox access and send-as permissions onto shared mailbox A. By adding users to security group A, they have full access to the shared mailbox. We create every new shared mailbox/security group combo using Powershell. That has been working flawlessly for the last years. However, for a recent new shared mailbox/security group combination, when a user that's member of the related security group wants to send an e-mail from the shared mailbox (by changing the from field in Outlook and selecting the shared mailbox from the global address list), Outlook tries to send every time 'send-on behalf'. This only happens for that newly created mailbox. I compared the output of Get-Mailbox and Get-RecipientPermission for the new problem shared mailbox and an older shared mailbox (which enable users to send mail send-as from outlook just fine) but I couldn't find any differences. For your information, that's the error we get back immediately after trying to do a send-as for the new shared mailbox: Your message did not reach some or all of the intended recipients. Subject: Test from Outlook Sent: 23/11/2017 9:27 The following recipient(s) cannot be reached: name of sending user on 23/11/2017 9:27 This message could not be sent. Try sending the message again later, or contact your network administrator. You do not have the permission to send the message on behalf of the specified user. Error is [0x80070005-0x0004dc-0x000524]. Why does Outlook always tries to do a send on behalf (what we don't want) where else for other shared mailboxes, send-as works fine? Using send-as from OWA however works just fine for the newest shared mailbox. It only seems a problem related to Outlook (tested on multiple clients that have access to the shared mailbox) and that particular new shared mailbox. Thanks in advance.Solved317KViews3likes13CommentsOutlook - Certificate has been revoked
Hi all, not sure if anyone has experienced it, but we are getting tthis error multiple times a day when using outlook. It says : Outlook.office365.com Information you Exchange with this site cannot be viewed or changed by others. However, there is a problem with the sites security certificate. The security certificate for this site has been revoked, This site should not be trusted, If we dont click OK, outlook cannot send or receive emails. Sometime this window is hidden behind and therefor are not aware of it during the day. if we click view certificate, it looks legit and everything seems to be ok. If enter OWA, we get same certificate(according to thumbprint), but there is no warning or error, We have created a case with Exchange online team, but they say there are no error from their side and its internal network issue. We have cleared certificate revoke list from our DNS servers without any help. Any ideas on how to troubleshoot this further? We use Outlook 2016 with latest updates and have all mailboxes in Exchange online. I only have my archive mailbox attached to my outlook, Thanks!150KViews1like40CommentsUpdating SSL Certificate
Hello! I am trying to update our expiring SSL certificate and here is what I am following to do so: To Install an Intermediate Certificate in Microsoft Exchange Server 2016 Click Start, and then click Run.... Type mmc, and then click OK. The Microsoft Management Console (Console1) window opens. In the Console1 window, click File, and then select Add/Remove Snap-in. In the Add or Remove Snap-ins window, select Certificates, and then click Add. In the Computer Account window, select Computer Account, and then click Next. In the Select Computer window, select Local Computer, and then click Finish. In the Add or Remove Snap-ins window, click OK. In the Console1 window, click + to expand the Certificates (Local Computer) folder on the left. Right-click Intermediate Certification Authorities, mouse over All Tasks, and then click Import. In the Certificate Import Wizard window, click Next. Click Browse to find the intermediate certificate file. In the Open window, change the file extension filter to PKCS #7 Certificates (*.spc;*.p7b), select the *_iis_intermediates.p7b file, and then click Open. In the Certificate Import Wizard window, click Next. Select Place all certificates in the following store, and then click Browse. In the Select Certificate Store window, select Intermediate Certification Authorities, and then click OK. In the Certificate Import Wizard window, click Next. Click Finish. Click OK. Close the Console1 window, and then click No to remove the console settings. To Install an SSL Certificate in Microsoft Exchange Server 2016 Log in to the Exchange Admin Center. From the left menu, select Servers, and then click Certificates. Select your certificate (it has a “Pending request” status), and then click Complete. For File to import from, enter the certificate file path we provided (such as \\server\folder\coolexample.crt), and then click OK. Exchange installs your certificate. In the Certificates section, select your certificate again (the status changed to “Valid”), and then click Edit (pencil icon). Click Services, select the services to which the certificate applies (SMTP, UM, UM call router, IMAP, POP, and/or IIS), and then click OK. Your certificate is now ready to use with Exchange 2016. The issue I get is at the "pending certificate" does not show up in the list in EAS, just the original certificate still showing "expires on" as shown in the image. I have tried several times, verified that I am downloading the Exchange SLL, verified that it is for this particular server, restarted IIS etc etc. The server is on prem physical Windows 2016 Exchange server and there is only only one. Ideas? Thanks!128KViews0likes2CommentsAutoMapping Shared Mailbox based on security group
Hi, We were under the impression that once on exch 2016 we would be able to use mail enabled security groups for shared mailboxes -- and (this is the important part) still be able to have the automapping feature work (ie. all members of the security group would see the share mailbox in their outlook profile) Testing has shown this not to be the case, and now I am seeing this: https://technet.microsoft.com/en-us/library/jj919240(v=exchg.160).aspx which is also suggesting that shared mailboxes cannot automap on a security group. Can anyone say for sure one way or the other - is this on the radar to start working eventually? I know people have been talking about this since exch 2010.Solved90KViews0likes21CommentsHow to Troubleshoot EWS Connection Issues Using EWS Editor
How to Troubleshoot EWS Connection Issues Using EWS Editor Problem: You get errors when you use any application to connect to (or execute a specific action upon) a mailbox or public folder via the Exchange Web Services (EWS) protocol. Solution: To verify if an error is related to application or to your environment, you can use a tool called EWS Editor to connect to the mailbox or public folder that causes errors and check if the error appears. This can be very useful in scenarios when: An application cannot establish connection to a mailbox or upload/download required data An application cannot access public folders An application cannot impersonate a mailbox – Connecting to a mailbox via EWSEditor 1. Go to the https://github.com/dseph/EwsEditor/releases and download the bin package. 2. Copy the downloaded file to the machine where application is installed and extract it. 3. Open the program and click File > New Exchange Service (Fig. 1.). Fig. 1. Creating a new EWS connection to a mailbox in EWSEditor. 4. Use the Autodiscover Email option or manually provide the Service URL by using the FQDN of the machine you are connecting to (CAS server). If you use Office 365, click the 365 Default button (Fig. 2.). Note : The Service URL for EWS should be as follows: https: machine FQDN>/EWS/Exchange.asmx for example: https://exchange.example.com/EWS/Exchange.asmx Fig. 2. Configuring the EWS connection. 5. Configure the authentication options: o Direct access: If you want to access your mailbox directly, select Use the following credentials instead of the default Windows credentials and provide the user name and password for that mailbox account (Fig. 3.). o Mailbox impersonation: If you want to connect to another mailbox by using the admin’s credentials, click Use the following credentials instead of the default Windows credentials and provide the administrator’s credentials. After that, select the Check if using EWS Impersonation checkbox and provide the primary SMTP address of the mailbox you want to access. Fig. 4. Configuring a connection to a mailbox as an administrator, by using impersonation. 6. When the configuration is complete, click OK. If the connection is successful, you will see a confirmation in the program. If the connection is not successful, the software will throw an error. The appearance of any errors means that the mailbox connection problem is not related to your application and the problem relates to your environment. If you are getting Error 500, then probably your XML configuration file for web services (including EWS) is corrupted. Please consider reverting any recent changes made to that file. Browsing a mailbox Directly after you finish configuring the connection, you get a prompt asking if you want to add the mailbox root to the tree view. Please confirm by clicking Yes (Fig. 5.). Fig. 5. The prompt that allows you to browse the mailbox content in EWSEditor. After the addition is complete, you can browse the content of your mailbox under Root\Top of Information Store (Fig. 6.). If you are getting any errors while accessing any of the folders within that container, it means that the mailbox is corrupted. Fig. 6. Browsing the content of a mailbox. Browsing public folders To browse public folders of a mailbox account that you added to the EWSEditor’s tree view, right-click the name (email address) of the mailbox at the very top of the tree, and select Add Root Folder. After selecting Identify folder by well known name, choose PublicFoldersRoot (Fig. 7.) and click OK. Fig. 7. Adding public folders to the mailbox tree view. If you are getting any errors when accessing public folders, this might mean that public folders are not yet created or their creation is still pending. However, if you are getting trouble accessing some particular public folders, it means that you are missing some of the required permissions. Reference : http://jasparrow.info/2020/08/how-to-troubleshoot-ews-connection-by-using-ews-editor/ Regards Jason61KViews1like0CommentsRoom calendar working hours not showing properly in Outlook
Hej guys, Please correct me if I am being crazy but I have an issue with the working hours display when viewing a room mailbox calendar through Outlook. In OWA and the scheduling assistant it's fine. For example, I have created a brand new room mailbox in Exchange 2016 CU4. The working hours are default at 0800 - 1700, weekdays only and PST. When viewed through Outlook the whol day is grey, when using the scheduling assistant or OWA the working hours are displayed okay. Technically this should not be an issue as I do not block booking rooms based on working hours. But the user experience is a bit crap and it could cause support cases. Any clues what to look for? Thanks in advance Neil46KViews0likes20Comments