SlideShare a Scribd company logo
1 of 35
Download to read offline
SINGAPORE

               Sanjeev Thakur
               Sr. Premier Field Engineer, Microsoft Singapore

               Ram Muthukaruppan
               Sr. Consultant, Microsoft Singapore



Microsoft
Exchange
Server and
Office 365 :
Hybrid
Deployment
Agenda
 Overview of Hybrid Deployment
 Planning Hybrid Deployment
 Mail Flow Architecture
 Calendar Sharing
 Secure Transport
 Deployment
 Migration
 What’s new in SP2
 Q&A
Exchange   Large    On-Premises
     IMAP       Medium   Single Sign-On
     Lotus      Small    On-Cloud
     Notes
     Google




Hybrid                          DirSync
Exchange                        Bulk
sharing                         Provisioning
features
Overview of Hybrid Deployment

Seamless interactions between on-premises and cloud
mailboxes
Calendars and free/busy information sharing between
on-Premises and Cloud Mailboxes.
Mailbox Management can be done using on-premises
Exchange Management Console
Users can log on to their email accounts with their
existing credentials regardless of their mailboxes
Location
Migrations into and out of Exchange Online are
transparent to the user.
Limitations - Hybrid Deployment

Coexistence of mailbox permissions –Permissions are
migrated, but do not work when Delegator and
Delegate are split between on-premise & cloud
Migration of Send As for non mailbox recipients
Multi-forest – Only single forest source environments
Public Folders
6
Hybrid Server Roles
2 Required Server Roles:
• Office 365 Active Directory Synchronization
• Exchange Server 2010 SP1 CAS/Hub*

   1 Optional Server Role:
Planning Hybrid Deployment
Planning Hybrid Deployment
To use hybrid deployment, you must maintain at least one
Federation technology
 Identity Federation
     Provides SSO
     Requires AD FS 2.0
     Applies to all Office 365 services

 Exchange Federation
     Exchange Federation Trust
     Organization relationships
     Applies only to all Exchange Online services
Identity Vs. Exchange Federation
Domain Name Requirement

Primary SMTP Domain : contoso.com
   MX record points to on-premises


Service Domain :- service.contoso.com
   MX record points to Office 365
   Used for Mail routing between On-premises and Office 365


    Delegation Domain :exchangedelegation.contoso.com
    Only used for setting up the Federation Trust
    DNS TXT records configured for proof of ownership purposes
Certificate Requirement

A public certificate is required to successfully setup both
Identity Federation and Exchange Federation
A public certificate is required for the following services:
AD FS endpoints (AD FS Proxy)
Exchange Web Services
Autodiscover
The Exchange Federation Trust can use a self-signed, public,
or internal CA generated certificate
The Exchange Management Console wizard creates a self-signed
certificate if one does not exist.
This certificate is only used to sign and encrypt delegation tokens
Exchange automatically distributes this certificate to other CAS
servers.
Mail Routing Architecture
Single Namespace – Core
                       Concepts
MX for contoso.com = On Premises                External Recipient
                                                 (joe@foo.com)




                                     Internet


    On Premises
     AD Forest


                                   Email from
       Exchange 2003
                                   joe@foo.com to
  DC
        FE/BE Server
                                   ben@contoso.com
Shared Namespace-Core Concepts
MX for contoso.com = On Premises
                                                            External Recipient
                                                             (joe@foo.com)

                                    Internet




     On Premises                     MX for service.contoso.com = Exchange
      AD Forest
                                                     Online



        Exchange 2003
   DC
         FE/BE Server                                    Exchange Online
                         Email from joe@foo.com to
                         ben@contoso.com
Calendar Sharing
Standard On-Premises Free/busy

                Brad Mailbox
         Ben          Server




    Client Access
        Server




     On Premises
     User “Ben”

           On Premises
Federated Free/busy
                                  Microsoft
                                 Federation
                       Mailbox    Gateway
                       Server
  Ben



Client Access
    Server
                Free
                Busy
                Requ
                est
                From
                Ben
                To
                Joe




                                 Exchange
                                  Online
On Premises
User “Ben”
        On Premises

                                              Joe
Exchange Online Archive

                             Microsoft
                            Federation
                  Mailbox    Gateway
 Ben              Server




 Client Access
     Server
          Archi
          ve
          Requ
          est
          From
          Ben
          To
          Archi
          ve




                            Exchange
                             Online
 On Premises
 User “Ben”
        On Premises
Secure Transport
ForeFront Online

                Secure Mail – TLS
                                Protection for
                                  Exchange




Domain
Secure                                Exchange
                                       Online



                 Mailbox
On Premises      Server
Mailbox “Ben”


                                           Cloud
                   Hub                  Mailbox “Joe”
                Transport
                  Server

       On Premises
Secure Mail - Sending Internal Headers
              to the Cloud                     ForeFront Online
                                                Protection for
                                                  Exchange
                                    XOORG
                                     Data
                                    Certific
                                      ate
                                    Subject




                                                      Exchange
                                                       Online



                 Mailbox
On Premises      Server
Mailbox “Ben”
                                                    Cross-premises
                                                      emails are
                                                           Cloud
                   Hub                                 Mailbox “Joe”
                                                    authenticated
                Transport   XOORG
                             Data                    as “Internal”
                  Server

       On Premises
Secure Mail – Sending Internal Headers to
                On-premises      ForeFront Online
                                            Protection for
                                              Exchange




                                                  Exchange
                                                   Online
                                    XOORG
                                     Data



                Mailbox
On Premises     Server
Mailbox “Ben”

   Emails
 from the                                              Cloud
                  Hub                               Mailbox “Joe”
 cloud are
               Transport
  seen as        Server
                      XOORG

Internal by            Data



 Transport Premises
        On
Centralized Mail flow Control
                           Internet




                                      ForeFront Online
                                       Protection for
                                         Exchange

                  Hub
Mailbox
 Centralized   Transport
Server           Server
 Mail flow
 Control                                     Exchange
                                              Online
    On Premises
Deployment
Exchange Deployment Assistant
Step 1 – Office 365 Configuration
Step 2 – Exchange Configuration
Creating the Exchange Federation
                     Trust
Create Exchange Federation Trust with the
    MFG using a “unique namespace”
 e.g. “exchangedelegation.contoso.com”                             MSO ID

                                            Microsoft Federation               Automatic implied
                                              Gateway (MFG)
                                                                               trust between the
                                                                                Exchange Online
                                                                                tenant and MFG

               On Premises
                AD Forest



                                                                     Exchange Online

                                                                      Exchange Online
     On-premises OrgExchange
                     2010 CAS/                                        Org Relationship
     Relationship with Server
                     HUB
                                                                      with
     “service.contoso.com”
                                                                      “contoso.com”
Creating the Secure Mail
              Connectors


                        FOPE
On Premises
 AD Forest




   Exchange
  2010 CAS/
  HUB Server                   Exchange Online
Migration
Hybrid Coexistence Migration
 It’s a true “online” move – user stays connected to their mailbox through the move
    – Client switchover happens automatically at the end
    – Traditional “offline” move when moving from Exchange 2003 source

 Outlook uses Autodiscover to detect the change and fixes up the user’s Outlook
  profile automatically on the client machine

 Since it’s a move (not a new mailbox + data copy), Outlook doesn’t see it as a
  new/different mailbox. End result = No OST resync

 Moves are queued and paced by the datacenter

 Object conversion for mail routing happens automatically after data move
   – Mailbox on-premises gets converted to Mail-enabled user automatically
   – Admin can override this automation and stage the move-then-convert steps
Autodiscover



                                                                  Mailbox
                                                                  Primary SMTP Address = ben@contoso.com
                                                                  Secondary SMTP Address = guid@service.contoso.com



              Remote Mailbox
              Primary SMTP Address = ben@contoso.com
              Remote Routing Address = guid@service.contoso.com


                                            (3) Outlook attempts to discover
                       (1) Where is my mailbox? through DNS record
                                            endpoint
                                            “autodiscover.service.contoso.com”
                          (2) Local Exchange passes a redirect to
                          “service.contoso.com”Authentication
                                      (4) Request
  Outlook client                   (5) Authentication Success
                                (6) Profile Builds
What’s New in Exchange 2010
                              SP2?
 New Hybrid Configuration Wizard
   –   Exchange federation trust
   –   Organization relationships
                                                        Pre-SP2: Approximately 50 manual
   –   Remote domains/accepted domains                  steps
   –   Email address policies
   –   Send/Receive connector                           With SP2: Now only 6 manual
                                                        steps
   –   Forefront inbound/outbound connectors
   –   MRSProxy
   –   Pre-req checks (i.e. Office365 Active Directory Sync, Exchange certificates,
       registered custom domains, etc…)
 New PowerShell cmdlets
   – New/Get/Set/Update-HybridConfiguration
 Namespaces improvements
   – Removing requirement for unique namespace
   – Providing every customer a coexistence domain, for every hybrid deployment
        • Service.contoso.com is now Contoso.mail.onmicrosoft.com
Questions?



             37

More Related Content

Similar to MS TechDays 2011 - Microsoft Exchange Server and Office 365 Hybrid Deployment

Viestinnän seminaari 8.11.2012 / Exchange
Viestinnän seminaari 8.11.2012 / ExchangeViestinnän seminaari 8.11.2012 / Exchange
Viestinnän seminaari 8.11.2012 / ExchangeSalcom Group
 
Dave hay desktop single sign-on in an active directory world
Dave hay   desktop single sign-on in an active directory worldDave hay   desktop single sign-on in an active directory world
Dave hay desktop single sign-on in an active directory worldDave Hay
 
Web sphere user group march 2012 - desktop single sign-on in an active dire...
Web sphere user group   march 2012 - desktop single sign-on in an active dire...Web sphere user group   march 2012 - desktop single sign-on in an active dire...
Web sphere user group march 2012 - desktop single sign-on in an active dire...Dave Hay
 
Dave hay desktop single sign-on in an active directory world
Dave hay   desktop single sign-on in an active directory worldDave hay   desktop single sign-on in an active directory world
Dave hay desktop single sign-on in an active directory worldDave Hay
 
Microsoft Unified Communication - Exchange Server 2010 Outlook Web App Presen...
Microsoft Unified Communication - Exchange Server 2010 Outlook Web App Presen...Microsoft Unified Communication - Exchange Server 2010 Outlook Web App Presen...
Microsoft Unified Communication - Exchange Server 2010 Outlook Web App Presen...Microsoft Private Cloud
 
Microsoft India – Unified Communications Exchange Server 2010 Outlook Web App...
Microsoft India – Unified Communications Exchange Server 2010 Outlook Web App...Microsoft India – Unified Communications Exchange Server 2010 Outlook Web App...
Microsoft India – Unified Communications Exchange Server 2010 Outlook Web App...Microsoft Private Cloud
 
Strata Software Architecture NY: The Data Dichotomy
Strata Software Architecture NY: The Data DichotomyStrata Software Architecture NY: The Data Dichotomy
Strata Software Architecture NY: The Data DichotomyBen Stopford
 
Kafka Summit NYC 2017 - The Data Dichotomy: Rethinking Data and Services with...
Kafka Summit NYC 2017 - The Data Dichotomy: Rethinking Data and Services with...Kafka Summit NYC 2017 - The Data Dichotomy: Rethinking Data and Services with...
Kafka Summit NYC 2017 - The Data Dichotomy: Rethinking Data and Services with...confluent
 
Romulus Crisan - Information exchange using hybrid azure integration - codeca...
Romulus Crisan - Information exchange using hybrid azure integration - codeca...Romulus Crisan - Information exchange using hybrid azure integration - codeca...
Romulus Crisan - Information exchange using hybrid azure integration - codeca...Codecamp Romania
 

Similar to MS TechDays 2011 - Microsoft Exchange Server and Office 365 Hybrid Deployment (12)

Viestinnän seminaari 8.11.2012 / Exchange
Viestinnän seminaari 8.11.2012 / ExchangeViestinnän seminaari 8.11.2012 / Exchange
Viestinnän seminaari 8.11.2012 / Exchange
 
Dave hay desktop single sign-on in an active directory world
Dave hay   desktop single sign-on in an active directory worldDave hay   desktop single sign-on in an active directory world
Dave hay desktop single sign-on in an active directory world
 
Web sphere user group march 2012 - desktop single sign-on in an active dire...
Web sphere user group   march 2012 - desktop single sign-on in an active dire...Web sphere user group   march 2012 - desktop single sign-on in an active dire...
Web sphere user group march 2012 - desktop single sign-on in an active dire...
 
Real world example: integration in the cloud
Real world example: integration in the cloud Real world example: integration in the cloud
Real world example: integration in the cloud
 
Dave hay desktop single sign-on in an active directory world
Dave hay   desktop single sign-on in an active directory worldDave hay   desktop single sign-on in an active directory world
Dave hay desktop single sign-on in an active directory world
 
Microsoft Unified Communication - Exchange Server 2010 Outlook Web App Presen...
Microsoft Unified Communication - Exchange Server 2010 Outlook Web App Presen...Microsoft Unified Communication - Exchange Server 2010 Outlook Web App Presen...
Microsoft Unified Communication - Exchange Server 2010 Outlook Web App Presen...
 
Microsoft India – Unified Communications Exchange Server 2010 Outlook Web App...
Microsoft India – Unified Communications Exchange Server 2010 Outlook Web App...Microsoft India – Unified Communications Exchange Server 2010 Outlook Web App...
Microsoft India – Unified Communications Exchange Server 2010 Outlook Web App...
 
What's new in Exchange 2013?
What's new in Exchange 2013?What's new in Exchange 2013?
What's new in Exchange 2013?
 
Strata Software Architecture NY: The Data Dichotomy
Strata Software Architecture NY: The Data DichotomyStrata Software Architecture NY: The Data Dichotomy
Strata Software Architecture NY: The Data Dichotomy
 
Kafka Summit NYC 2017 - The Data Dichotomy: Rethinking Data and Services with...
Kafka Summit NYC 2017 - The Data Dichotomy: Rethinking Data and Services with...Kafka Summit NYC 2017 - The Data Dichotomy: Rethinking Data and Services with...
Kafka Summit NYC 2017 - The Data Dichotomy: Rethinking Data and Services with...
 
Exchange Server 2013 Architecture Deep Dive, Part 1
Exchange Server 2013 Architecture Deep Dive, Part 1Exchange Server 2013 Architecture Deep Dive, Part 1
Exchange Server 2013 Architecture Deep Dive, Part 1
 
Romulus Crisan - Information exchange using hybrid azure integration - codeca...
Romulus Crisan - Information exchange using hybrid azure integration - codeca...Romulus Crisan - Information exchange using hybrid azure integration - codeca...
Romulus Crisan - Information exchange using hybrid azure integration - codeca...
 

More from Spiffy

01 server manager spiffy
01 server manager spiffy01 server manager spiffy
01 server manager spiffySpiffy
 
Active Directory Upgrade
Active Directory UpgradeActive Directory Upgrade
Active Directory UpgradeSpiffy
 
Checking the health of your active directory enviornment
Checking the health of your active directory enviornmentChecking the health of your active directory enviornment
Checking the health of your active directory enviornmentSpiffy
 
Agile in Action - Act 2: Development
Agile in Action - Act 2: DevelopmentAgile in Action - Act 2: Development
Agile in Action - Act 2: DevelopmentSpiffy
 
Agile in Action - Act 3: Testing
Agile in Action - Act 3: TestingAgile in Action - Act 3: Testing
Agile in Action - Act 3: TestingSpiffy
 
Agile in Action - Keynote: Becoming and Being Agile - What Does This Mean?
Agile in Action - Keynote: Becoming and Being Agile - What Does This Mean?Agile in Action - Keynote: Becoming and Being Agile - What Does This Mean?
Agile in Action - Keynote: Becoming and Being Agile - What Does This Mean?Spiffy
 
Agile in Action - Act 1 (Set Up, Planning, Requirements and Architecture)
Agile in Action - Act 1 (Set Up, Planning, Requirements and Architecture)Agile in Action - Act 1 (Set Up, Planning, Requirements and Architecture)
Agile in Action - Act 1 (Set Up, Planning, Requirements and Architecture)Spiffy
 
MS TechDays 2011 - WCF Web APis There's a URI for That
MS TechDays 2011 - WCF Web APis There's a URI for ThatMS TechDays 2011 - WCF Web APis There's a URI for That
MS TechDays 2011 - WCF Web APis There's a URI for ThatSpiffy
 
MS TechDays 2011 - NUI, Gooey and Louie
MS TechDays 2011 - NUI, Gooey and LouieMS TechDays 2011 - NUI, Gooey and Louie
MS TechDays 2011 - NUI, Gooey and LouieSpiffy
 
MS TechDays 2011 - Mango, Mango! Developing for Windows Phone 7
MS TechDays 2011 - Mango, Mango! Developing for Windows Phone 7MS TechDays 2011 - Mango, Mango! Developing for Windows Phone 7
MS TechDays 2011 - Mango, Mango! Developing for Windows Phone 7Spiffy
 
MS TechDays 2011 - Generate Revenue on Azure
MS TechDays 2011 - Generate Revenue on AzureMS TechDays 2011 - Generate Revenue on Azure
MS TechDays 2011 - Generate Revenue on AzureSpiffy
 
MS TechDays 2011 - HTML 5 All the Awesome Bits
MS TechDays 2011 - HTML 5 All the Awesome BitsMS TechDays 2011 - HTML 5 All the Awesome Bits
MS TechDays 2011 - HTML 5 All the Awesome BitsSpiffy
 
MS TechDays 2011 - Cloud Computing with the Windows Azure Platform
MS TechDays 2011 - Cloud Computing with the Windows Azure PlatformMS TechDays 2011 - Cloud Computing with the Windows Azure Platform
MS TechDays 2011 - Cloud Computing with the Windows Azure PlatformSpiffy
 
MS TechDays 2011 - Simplified Converged Infrastructure Solutions
MS TechDays 2011 - Simplified Converged Infrastructure SolutionsMS TechDays 2011 - Simplified Converged Infrastructure Solutions
MS TechDays 2011 - Simplified Converged Infrastructure SolutionsSpiffy
 
MS TechDays 2011 - SCDPM 2012 The New Feature of Data Protection
MS TechDays 2011 - SCDPM 2012 The New Feature of Data ProtectionMS TechDays 2011 - SCDPM 2012 The New Feature of Data Protection
MS TechDays 2011 - SCDPM 2012 The New Feature of Data ProtectionSpiffy
 
MS TechDays 2011 - How to Run Middleware in the Cloud Story of Windows Azure ...
MS TechDays 2011 - How to Run Middleware in the Cloud Story of Windows Azure ...MS TechDays 2011 - How to Run Middleware in the Cloud Story of Windows Azure ...
MS TechDays 2011 - How to Run Middleware in the Cloud Story of Windows Azure ...Spiffy
 
MS TechDays 2011 - Cloud Management with System Center Application Controller
MS TechDays 2011 - Cloud Management with System Center Application ControllerMS TechDays 2011 - Cloud Management with System Center Application Controller
MS TechDays 2011 - Cloud Management with System Center Application ControllerSpiffy
 
MS TechDays 2011 - Virtualization Solutions to Optimize Performance
MS TechDays 2011 - Virtualization Solutions to Optimize PerformanceMS TechDays 2011 - Virtualization Solutions to Optimize Performance
MS TechDays 2011 - Virtualization Solutions to Optimize PerformanceSpiffy
 
MS TechDays 2011 - Automating Your Infrastructure System Center Orchestrator ...
MS TechDays 2011 - Automating Your Infrastructure System Center Orchestrator ...MS TechDays 2011 - Automating Your Infrastructure System Center Orchestrator ...
MS TechDays 2011 - Automating Your Infrastructure System Center Orchestrator ...Spiffy
 
MS TechDays 2011 - Self-Service Private Cloud Management through Integrated P...
MS TechDays 2011 - Self-Service Private Cloud Management through Integrated P...MS TechDays 2011 - Self-Service Private Cloud Management through Integrated P...
MS TechDays 2011 - Self-Service Private Cloud Management through Integrated P...Spiffy
 

More from Spiffy (20)

01 server manager spiffy
01 server manager spiffy01 server manager spiffy
01 server manager spiffy
 
Active Directory Upgrade
Active Directory UpgradeActive Directory Upgrade
Active Directory Upgrade
 
Checking the health of your active directory enviornment
Checking the health of your active directory enviornmentChecking the health of your active directory enviornment
Checking the health of your active directory enviornment
 
Agile in Action - Act 2: Development
Agile in Action - Act 2: DevelopmentAgile in Action - Act 2: Development
Agile in Action - Act 2: Development
 
Agile in Action - Act 3: Testing
Agile in Action - Act 3: TestingAgile in Action - Act 3: Testing
Agile in Action - Act 3: Testing
 
Agile in Action - Keynote: Becoming and Being Agile - What Does This Mean?
Agile in Action - Keynote: Becoming and Being Agile - What Does This Mean?Agile in Action - Keynote: Becoming and Being Agile - What Does This Mean?
Agile in Action - Keynote: Becoming and Being Agile - What Does This Mean?
 
Agile in Action - Act 1 (Set Up, Planning, Requirements and Architecture)
Agile in Action - Act 1 (Set Up, Planning, Requirements and Architecture)Agile in Action - Act 1 (Set Up, Planning, Requirements and Architecture)
Agile in Action - Act 1 (Set Up, Planning, Requirements and Architecture)
 
MS TechDays 2011 - WCF Web APis There's a URI for That
MS TechDays 2011 - WCF Web APis There's a URI for ThatMS TechDays 2011 - WCF Web APis There's a URI for That
MS TechDays 2011 - WCF Web APis There's a URI for That
 
MS TechDays 2011 - NUI, Gooey and Louie
MS TechDays 2011 - NUI, Gooey and LouieMS TechDays 2011 - NUI, Gooey and Louie
MS TechDays 2011 - NUI, Gooey and Louie
 
MS TechDays 2011 - Mango, Mango! Developing for Windows Phone 7
MS TechDays 2011 - Mango, Mango! Developing for Windows Phone 7MS TechDays 2011 - Mango, Mango! Developing for Windows Phone 7
MS TechDays 2011 - Mango, Mango! Developing for Windows Phone 7
 
MS TechDays 2011 - Generate Revenue on Azure
MS TechDays 2011 - Generate Revenue on AzureMS TechDays 2011 - Generate Revenue on Azure
MS TechDays 2011 - Generate Revenue on Azure
 
MS TechDays 2011 - HTML 5 All the Awesome Bits
MS TechDays 2011 - HTML 5 All the Awesome BitsMS TechDays 2011 - HTML 5 All the Awesome Bits
MS TechDays 2011 - HTML 5 All the Awesome Bits
 
MS TechDays 2011 - Cloud Computing with the Windows Azure Platform
MS TechDays 2011 - Cloud Computing with the Windows Azure PlatformMS TechDays 2011 - Cloud Computing with the Windows Azure Platform
MS TechDays 2011 - Cloud Computing with the Windows Azure Platform
 
MS TechDays 2011 - Simplified Converged Infrastructure Solutions
MS TechDays 2011 - Simplified Converged Infrastructure SolutionsMS TechDays 2011 - Simplified Converged Infrastructure Solutions
MS TechDays 2011 - Simplified Converged Infrastructure Solutions
 
MS TechDays 2011 - SCDPM 2012 The New Feature of Data Protection
MS TechDays 2011 - SCDPM 2012 The New Feature of Data ProtectionMS TechDays 2011 - SCDPM 2012 The New Feature of Data Protection
MS TechDays 2011 - SCDPM 2012 The New Feature of Data Protection
 
MS TechDays 2011 - How to Run Middleware in the Cloud Story of Windows Azure ...
MS TechDays 2011 - How to Run Middleware in the Cloud Story of Windows Azure ...MS TechDays 2011 - How to Run Middleware in the Cloud Story of Windows Azure ...
MS TechDays 2011 - How to Run Middleware in the Cloud Story of Windows Azure ...
 
MS TechDays 2011 - Cloud Management with System Center Application Controller
MS TechDays 2011 - Cloud Management with System Center Application ControllerMS TechDays 2011 - Cloud Management with System Center Application Controller
MS TechDays 2011 - Cloud Management with System Center Application Controller
 
MS TechDays 2011 - Virtualization Solutions to Optimize Performance
MS TechDays 2011 - Virtualization Solutions to Optimize PerformanceMS TechDays 2011 - Virtualization Solutions to Optimize Performance
MS TechDays 2011 - Virtualization Solutions to Optimize Performance
 
MS TechDays 2011 - Automating Your Infrastructure System Center Orchestrator ...
MS TechDays 2011 - Automating Your Infrastructure System Center Orchestrator ...MS TechDays 2011 - Automating Your Infrastructure System Center Orchestrator ...
MS TechDays 2011 - Automating Your Infrastructure System Center Orchestrator ...
 
MS TechDays 2011 - Self-Service Private Cloud Management through Integrated P...
MS TechDays 2011 - Self-Service Private Cloud Management through Integrated P...MS TechDays 2011 - Self-Service Private Cloud Management through Integrated P...
MS TechDays 2011 - Self-Service Private Cloud Management through Integrated P...
 

Recently uploaded

Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationSlibray Presentation
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsMark Billinghurst
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 3652toLead Limited
 
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek SchlawackFwdays
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Mark Simos
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfAddepto
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfAlex Barbosa Coqueiro
 
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage CostLeverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage CostZilliz
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupFlorian Wilhelm
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity PlanDatabarracks
 
Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Manik S Magar
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Mattias Andersson
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Commit University
 
Commit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyCommit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyAlfredo García Lavilla
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...Fwdays
 
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfHyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfPrecisely
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
Search Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfSearch Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfRankYa
 
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo Day
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo DayH2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo Day
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo DaySri Ambati
 

Recently uploaded (20)

Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck Presentation
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR Systems
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365
 
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdf
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdf
 
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage CostLeverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project Setup
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity Plan
 
Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!
 
Commit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyCommit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easy
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
 
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfHyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
Search Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfSearch Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdf
 
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo Day
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo DayH2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo Day
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo Day
 

MS TechDays 2011 - Microsoft Exchange Server and Office 365 Hybrid Deployment

  • 1. SINGAPORE Sanjeev Thakur Sr. Premier Field Engineer, Microsoft Singapore Ram Muthukaruppan Sr. Consultant, Microsoft Singapore Microsoft Exchange Server and Office 365 : Hybrid Deployment
  • 2. Agenda Overview of Hybrid Deployment Planning Hybrid Deployment Mail Flow Architecture Calendar Sharing Secure Transport Deployment Migration What’s new in SP2 Q&A
  • 3. Exchange Large On-Premises IMAP Medium Single Sign-On Lotus Small On-Cloud Notes Google Hybrid DirSync Exchange Bulk sharing Provisioning features
  • 4. Overview of Hybrid Deployment Seamless interactions between on-premises and cloud mailboxes Calendars and free/busy information sharing between on-Premises and Cloud Mailboxes. Mailbox Management can be done using on-premises Exchange Management Console Users can log on to their email accounts with their existing credentials regardless of their mailboxes Location Migrations into and out of Exchange Online are transparent to the user.
  • 5. Limitations - Hybrid Deployment Coexistence of mailbox permissions –Permissions are migrated, but do not work when Delegator and Delegate are split between on-premise & cloud Migration of Send As for non mailbox recipients Multi-forest – Only single forest source environments Public Folders
  • 6. 6
  • 7. Hybrid Server Roles 2 Required Server Roles: • Office 365 Active Directory Synchronization • Exchange Server 2010 SP1 CAS/Hub* 1 Optional Server Role:
  • 9. Planning Hybrid Deployment To use hybrid deployment, you must maintain at least one Federation technology Identity Federation  Provides SSO  Requires AD FS 2.0  Applies to all Office 365 services Exchange Federation  Exchange Federation Trust  Organization relationships  Applies only to all Exchange Online services
  • 10. Identity Vs. Exchange Federation
  • 11. Domain Name Requirement Primary SMTP Domain : contoso.com  MX record points to on-premises Service Domain :- service.contoso.com  MX record points to Office 365  Used for Mail routing between On-premises and Office 365 Delegation Domain :exchangedelegation.contoso.com Only used for setting up the Federation Trust DNS TXT records configured for proof of ownership purposes
  • 12. Certificate Requirement A public certificate is required to successfully setup both Identity Federation and Exchange Federation A public certificate is required for the following services: AD FS endpoints (AD FS Proxy) Exchange Web Services Autodiscover The Exchange Federation Trust can use a self-signed, public, or internal CA generated certificate The Exchange Management Console wizard creates a self-signed certificate if one does not exist. This certificate is only used to sign and encrypt delegation tokens Exchange automatically distributes this certificate to other CAS servers.
  • 14. Single Namespace – Core Concepts MX for contoso.com = On Premises External Recipient (joe@foo.com) Internet On Premises AD Forest Email from Exchange 2003 joe@foo.com to DC FE/BE Server ben@contoso.com
  • 15. Shared Namespace-Core Concepts MX for contoso.com = On Premises External Recipient (joe@foo.com) Internet On Premises MX for service.contoso.com = Exchange AD Forest Online Exchange 2003 DC FE/BE Server Exchange Online Email from joe@foo.com to ben@contoso.com
  • 17. Standard On-Premises Free/busy Brad Mailbox Ben Server Client Access Server On Premises User “Ben” On Premises
  • 18. Federated Free/busy Microsoft Federation Mailbox Gateway Server Ben Client Access Server Free Busy Requ est From Ben To Joe Exchange Online On Premises User “Ben” On Premises Joe
  • 19. Exchange Online Archive Microsoft Federation Mailbox Gateway Ben Server Client Access Server Archi ve Requ est From Ben To Archi ve Exchange Online On Premises User “Ben” On Premises
  • 21. ForeFront Online Secure Mail – TLS Protection for Exchange Domain Secure Exchange Online Mailbox On Premises Server Mailbox “Ben” Cloud Hub Mailbox “Joe” Transport Server On Premises
  • 22. Secure Mail - Sending Internal Headers to the Cloud ForeFront Online Protection for Exchange XOORG Data Certific ate Subject Exchange Online Mailbox On Premises Server Mailbox “Ben” Cross-premises emails are Cloud Hub Mailbox “Joe” authenticated Transport XOORG Data as “Internal” Server On Premises
  • 23. Secure Mail – Sending Internal Headers to On-premises ForeFront Online Protection for Exchange Exchange Online XOORG Data Mailbox On Premises Server Mailbox “Ben” Emails from the Cloud Hub Mailbox “Joe” cloud are Transport seen as Server XOORG Internal by Data Transport Premises On
  • 24. Centralized Mail flow Control Internet ForeFront Online Protection for Exchange Hub Mailbox Centralized Transport Server Server Mail flow Control Exchange Online On Premises
  • 27. Step 1 – Office 365 Configuration
  • 28. Step 2 – Exchange Configuration
  • 29. Creating the Exchange Federation Trust Create Exchange Federation Trust with the MFG using a “unique namespace” e.g. “exchangedelegation.contoso.com” MSO ID Microsoft Federation Automatic implied Gateway (MFG) trust between the Exchange Online tenant and MFG On Premises AD Forest Exchange Online Exchange Online On-premises OrgExchange 2010 CAS/ Org Relationship Relationship with Server HUB with “service.contoso.com” “contoso.com”
  • 30. Creating the Secure Mail Connectors FOPE On Premises AD Forest Exchange 2010 CAS/ HUB Server Exchange Online
  • 32. Hybrid Coexistence Migration  It’s a true “online” move – user stays connected to their mailbox through the move – Client switchover happens automatically at the end – Traditional “offline” move when moving from Exchange 2003 source  Outlook uses Autodiscover to detect the change and fixes up the user’s Outlook profile automatically on the client machine  Since it’s a move (not a new mailbox + data copy), Outlook doesn’t see it as a new/different mailbox. End result = No OST resync  Moves are queued and paced by the datacenter  Object conversion for mail routing happens automatically after data move – Mailbox on-premises gets converted to Mail-enabled user automatically – Admin can override this automation and stage the move-then-convert steps
  • 33. Autodiscover Mailbox Primary SMTP Address = ben@contoso.com Secondary SMTP Address = guid@service.contoso.com Remote Mailbox Primary SMTP Address = ben@contoso.com Remote Routing Address = guid@service.contoso.com (3) Outlook attempts to discover (1) Where is my mailbox? through DNS record endpoint “autodiscover.service.contoso.com” (2) Local Exchange passes a redirect to “service.contoso.com”Authentication (4) Request Outlook client (5) Authentication Success (6) Profile Builds
  • 34. What’s New in Exchange 2010 SP2?  New Hybrid Configuration Wizard – Exchange federation trust – Organization relationships Pre-SP2: Approximately 50 manual – Remote domains/accepted domains steps – Email address policies – Send/Receive connector With SP2: Now only 6 manual steps – Forefront inbound/outbound connectors – MRSProxy – Pre-req checks (i.e. Office365 Active Directory Sync, Exchange certificates, registered custom domains, etc…)  New PowerShell cmdlets – New/Get/Set/Update-HybridConfiguration  Namespaces improvements – Removing requirement for unique namespace – Providing every customer a coexistence domain, for every hybrid deployment • Service.contoso.com is now Contoso.mail.onmicrosoft.com