SlideShare a Scribd company logo
1 of 31
What Exchange Administrators Need to Know
about Hybrid Deployments
Michael Van Horenbeeck
Agenda
• What’s life like for an admin in a Hybrid deployment?
• Common issues and misconceptions
• Moving mailboxes: the good, the bad and the ugly
• Keeping ADFS alive
• DirSync
• What’s next?
• Q&A
What is a Hybrid deployment?
Components of a Hybrid deployment
What is a hybrid deployment?
“Two distinct cross-premises Exchange organizations, combined to ‘act’
as a single organization through a series of customizations in both
environments”
HybridArchitecture
ACTIVE DIRECTORY
OFFICE 365 TENANT
EXCHANGE ONLINE
TENANT
MICROSOFT DATA CENTER INTERNET PERIMETER
NETWORK
INTERNAL NETWORK
EXCHANGE ON-PREM ORG.
AZURE AD
ADFS
PROXY
ADFS
ACTIVE
DIRECTORY
DIRSYNC
SERVER
EXCHANGE
2013
(CAS)ORGANIZATIONAL RELATIONSHIP /
OAUTH (INTRA-ORG CONNECTOR)
EXCHANGE
2013
(MBX)
ONLINE PROTECTION
HYBRID MAIL FLOW
SMTP
EXCHANGE ONLINE
AUTHENTICATION
SERVICE
EXTERNAL USER
(O365)
SYNC
HTTP(S)
HTTPS
HTTPS
OWA USER
(O365)
HTTPS
MAIL FLOW
AUTHENTICATION
SYNCHRONIZATION
APP. ACCESS (HTTP(S))
INTERNAL USER
(O365)
EXCHANGE USER
HTTPS
INTERNAL OWA USER
(O365)
Hybrid Building Blocks
Federation DirSync Secure Transport Mailbox Moves
• Free/Busy
• Mailtips
• Message Tracking
• eDiscovery
• …
• Unified GAL
• X500 (Mailbox
Moves)
• Online Archiving
• TLS encryption
• Header
Preservation
• Cert-based
security
• Centralized mail
flow
• Mailbox
Replication
Service (MRS)
• Online Moves
• Fast / Reliable
An admin’s life in the cloud…
What tasks does an admin commonly
execute?
• Daily Exchange Management
• Identity Management
• Moving Mailboxes
• Patching
• Monitoring
• Troubleshooting
Identity Management
• All user objects are managed on-premises (through
Exchange) because of DirSync
• Account for the DirSync interval (or force DirSync to
run)
• Can be important if you want to “quickly” do things.
• Watch out for accidental deletions!
• New DirSync feature might help…
DirSync Accidental Deletion
• New in version 6765.0006 (released end of May)
• If the number of objects being deleted exceeds a configurable
threshold, DirSync won’t sync the deletions to Azure AD.
• To enable the feature:
• Set-PreventAccidentalDeletes –Enable –ObjectDeletionThreshold <value>
Monitoring Hybrid Deployments
• New architecture paradigm, requires new way of thinking about
monitoring
• You don’t care about Microsoft’s side of the story
• End-user service availability is key (but it’s always been like that,
right?)
• Consider monitoring through a series of both Active and Passive tests
• Active tests allow you to be proactive
• Passive tests give you great feedback (counters…)
What components do I need to monitor?
• Directory Synchronization
• Identity Federation (if applicable)
• Exchange Federation
• Certificates
• Connectivity
Featured as Messaging and Unified
Communications Award Finalist
Patching
• Important to stay ‘current’ with patch levels (Exchange, DirSync) in
order to remain supported
• Challenge to keep up with cloud-cadence (CU’s are typically released
every quarter…)
• You can use RSS feeds and the Office Blog to stay up to date with the
latest and the greatest. Recently released Microsoft roadmap blog
might also help: http://office.microsoft.com/en-us/products/office-
365-roadmap-FX104343353.aspx
Moving Mailboxes
Moving Mailboxes
Exchange
On-Prem
“The Internet”
Exchange
Online
(Office 365)
MRS
Admin
Moving Mailboxes
• A trivial action, but touches many different components in Exchange
• Make sure the Mailbox Replication Service Proxy [MRS Proxy] is enabled on the
internet-facing Exchange Web Services
• Before a mailbox can be moved, certain ‘attributes’ need to be available on
the object:
• Prior to a mailbox move, check that the object have the correct attributes set (x500 +
Proxy Addresses)
• Because of the cross-premises nature of a hybrid deployment, certain
features won’t work after a mailbox move
• Watch out for permissions and large items in mailbox!
Mailbox move limitations
• Items larger than +/- 25 MB won’t be moved because of the item size
limits in place in Office 365.
• You can export them using this script
• Cross-premises permissions (currently?) are not supported. Make
sure to move associated mailboxes at the same time.
• Potential impact of your ‘pilot’ group.
Dealing with High Availability
What it takes to make a hybrid deployment highly available
What components should be highly available?
• Exchange (Hybrid Servers)
• AD FS (if deployed)
• Connectivity
“Hybrid Server” HA
• Deploy at least two hybrid servers
• Add site resiliency by deploying in two distinct physical locations
• Load balance incoming request through a LB device
Site 1 Site 2
Connectivity
Domain
Controller
Exchange
CAS/MBX
Exchange
CAS/MBX
INTERNE
T
Domain
Controller
HA Load Balancer pair
DirSync / Azure AD Sync
• No urgent need for high availability
• You can run w/o DirSync for a (short) period of time, although that would
reduce (admin-)functionality temporarily
• In case you cannot afford temporary functionality loss (SLAs?)
• Deploy a ‘standby’ DirSync server
• Consider deploying SQL (default choice for large enterprises anyway)
• Easier to backup
Active Directory Federation Services
• Critical to operations; No ADFS = No user logon possible
• Must be deployed HA – in all possible ways
• Deploy ADFS cluster; spread across sites to add site resiliency
• Can be costly…
AD FS HA
AD FS Topology
AD FS
Proxy
AD FS
Domain
Controller
INTERNET
AD FS
AD FS
Proxy
LoadBalancer
LoadBalancer
Domain
Controller
FW
FW
Troubleshooting
An overview of the most common scenarios
Troubleshooting AD FS
• Not easy.
• Use tools like e.g. Fiddler
• Enable Debug Logging in Event Viewer
• Pair AD FS Proxy w/ ADFS for easier troubleshooting
• Understanding different authentication flows is important
Enabling Debug Log
• Open Event Viewer
• Click View > Show Analytic and
Debug Logs
• Right-click Debug under AD FS
Tracing and click enable
• Reproduce issue
Exchange Federation
• Multiple areas where things can go wrong…
• Verify that Federation Information can be retrieved (get-
federationinformation)
• Test Organization Relationships (test-organizationrelationship)
• Verify Federation trust (Test-FederationTrust)
• When using oAuth: Test-oAuthConnectivity
Mailbox Moves
• Error message is critical; contains useful information
• Verify connectivity; e.g. MRS Proxy enabled?
• Use the Test-MigrationServerAvailability for more insights
DirSync
• No news = good news 
• Take a look into the console (miisclient.exe located in installation
folder)
• Check Permissions (inherit permissions enabled?)
About ENow Software
Download Mailscape
for Exchange Online
Free Trial
http://bit.ly/Mailscape-Hybrid
Q&A
Thank you!
www.enowsoftware.com

More Related Content

What's hot

Cloud Computing101 Azure, updated june 2017
Cloud Computing101 Azure, updated june 2017Cloud Computing101 Azure, updated june 2017
Cloud Computing101 Azure, updated june 2017Fernando Mejía
 
AWS vs. Azure vs. Google vs. SoftLayer: Network, Storage and DBaaS
AWS vs. Azure vs. Google vs. SoftLayer: Network, Storage and DBaaSAWS vs. Azure vs. Google vs. SoftLayer: Network, Storage and DBaaS
AWS vs. Azure vs. Google vs. SoftLayer: Network, Storage and DBaaSRightScale
 
Migrate SQL Server 2008 R2 to Azure Cloud
Migrate SQL Server 2008 R2 to Azure CloudMigrate SQL Server 2008 R2 to Azure Cloud
Migrate SQL Server 2008 R2 to Azure CloudRavi Yadav
 
Automating Cloud Operations: Tips from Managed Services
Automating Cloud Operations: Tips from Managed ServicesAutomating Cloud Operations: Tips from Managed Services
Automating Cloud Operations: Tips from Managed ServicesAngela_Tripp
 
AWS Data migration services
AWS Data migration servicesAWS Data migration services
AWS Data migration servicesArun Sirimalla
 
Managing your virtual environment with System Center & Windows Server 2012
Managing your virtual environment with System Center & Windows Server 2012Managing your virtual environment with System Center & Windows Server 2012
Managing your virtual environment with System Center & Windows Server 2012C/D/H Technology Consultants
 
What Every MSP Needs to Know for Cloud Success
What Every MSP Needs to Know for Cloud SuccessWhat Every MSP Needs to Know for Cloud Success
What Every MSP Needs to Know for Cloud SuccessRightScale
 
Service Fabric – building tomorrows applications today
Service Fabric – building tomorrows applications todayService Fabric – building tomorrows applications today
Service Fabric – building tomorrows applications todayBizTalk360
 
Windows Azure Overview for IT Professionals
Windows Azure Overview for IT ProfessionalsWindows Azure Overview for IT Professionals
Windows Azure Overview for IT ProfessionalsAlex Melching
 
Tokyo azure meetup #12 service fabric internals
Tokyo azure meetup #12   service fabric internalsTokyo azure meetup #12   service fabric internals
Tokyo azure meetup #12 service fabric internalsTokyo Azure Meetup
 
RightScale Webinar: How to Cloud Enable vSphere with RightScale
RightScale Webinar: How to Cloud Enable vSphere with RightScale RightScale Webinar: How to Cloud Enable vSphere with RightScale
RightScale Webinar: How to Cloud Enable vSphere with RightScale RightScale
 
Key Design Considerations Private and Hybrid Clouds - RightScale Compute 2013
Key Design Considerations Private and Hybrid Clouds - RightScale Compute 2013Key Design Considerations Private and Hybrid Clouds - RightScale Compute 2013
Key Design Considerations Private and Hybrid Clouds - RightScale Compute 2013RightScale
 
Blockchain for the DBA and Data Professional
Blockchain for the DBA and Data ProfessionalBlockchain for the DBA and Data Professional
Blockchain for the DBA and Data ProfessionalKaren Lopez
 
PaaSport to Paradise: Back to the Future with SSIS in Azure Data Factory
PaaSport to Paradise: Back to the Future with SSIS in Azure Data FactoryPaaSport to Paradise: Back to the Future with SSIS in Azure Data Factory
PaaSport to Paradise: Back to the Future with SSIS in Azure Data FactorySandy Winarko
 
Cassandra-as-a-Service
Cassandra-as-a-ServiceCassandra-as-a-Service
Cassandra-as-a-ServiceInstaclustr
 
Blockchain for the DBA and Data Professional
Blockchain for the DBA and Data ProfessionalBlockchain for the DBA and Data Professional
Blockchain for the DBA and Data ProfessionalKaren Lopez
 
(SPOT205) 5 Lessons for Managing Massive IT Transformation Projects
(SPOT205) 5 Lessons for Managing Massive IT Transformation Projects(SPOT205) 5 Lessons for Managing Massive IT Transformation Projects
(SPOT205) 5 Lessons for Managing Massive IT Transformation ProjectsAmazon Web Services
 
Configuration in azure done right
Configuration in azure done rightConfiguration in azure done right
Configuration in azure done rightRick van den Bosch
 
Tokyo azure meetup #2 big data made easy
Tokyo azure meetup #2   big data made easyTokyo azure meetup #2   big data made easy
Tokyo azure meetup #2 big data made easyTokyo Azure Meetup
 

What's hot (20)

Cloud Computing101 Azure, updated june 2017
Cloud Computing101 Azure, updated june 2017Cloud Computing101 Azure, updated june 2017
Cloud Computing101 Azure, updated june 2017
 
AWS vs. Azure vs. Google vs. SoftLayer: Network, Storage and DBaaS
AWS vs. Azure vs. Google vs. SoftLayer: Network, Storage and DBaaSAWS vs. Azure vs. Google vs. SoftLayer: Network, Storage and DBaaS
AWS vs. Azure vs. Google vs. SoftLayer: Network, Storage and DBaaS
 
Migrate SQL Server 2008 R2 to Azure Cloud
Migrate SQL Server 2008 R2 to Azure CloudMigrate SQL Server 2008 R2 to Azure Cloud
Migrate SQL Server 2008 R2 to Azure Cloud
 
Automating Cloud Operations: Tips from Managed Services
Automating Cloud Operations: Tips from Managed ServicesAutomating Cloud Operations: Tips from Managed Services
Automating Cloud Operations: Tips from Managed Services
 
AWS Data migration services
AWS Data migration servicesAWS Data migration services
AWS Data migration services
 
Managing your virtual environment with System Center & Windows Server 2012
Managing your virtual environment with System Center & Windows Server 2012Managing your virtual environment with System Center & Windows Server 2012
Managing your virtual environment with System Center & Windows Server 2012
 
What Every MSP Needs to Know for Cloud Success
What Every MSP Needs to Know for Cloud SuccessWhat Every MSP Needs to Know for Cloud Success
What Every MSP Needs to Know for Cloud Success
 
Service Fabric – building tomorrows applications today
Service Fabric – building tomorrows applications todayService Fabric – building tomorrows applications today
Service Fabric – building tomorrows applications today
 
Windows Azure Overview for IT Professionals
Windows Azure Overview for IT ProfessionalsWindows Azure Overview for IT Professionals
Windows Azure Overview for IT Professionals
 
Tokyo azure meetup #12 service fabric internals
Tokyo azure meetup #12   service fabric internalsTokyo azure meetup #12   service fabric internals
Tokyo azure meetup #12 service fabric internals
 
RightScale Webinar: How to Cloud Enable vSphere with RightScale
RightScale Webinar: How to Cloud Enable vSphere with RightScale RightScale Webinar: How to Cloud Enable vSphere with RightScale
RightScale Webinar: How to Cloud Enable vSphere with RightScale
 
Key Design Considerations Private and Hybrid Clouds - RightScale Compute 2013
Key Design Considerations Private and Hybrid Clouds - RightScale Compute 2013Key Design Considerations Private and Hybrid Clouds - RightScale Compute 2013
Key Design Considerations Private and Hybrid Clouds - RightScale Compute 2013
 
Serverless Patterns
Serverless PatternsServerless Patterns
Serverless Patterns
 
Blockchain for the DBA and Data Professional
Blockchain for the DBA and Data ProfessionalBlockchain for the DBA and Data Professional
Blockchain for the DBA and Data Professional
 
PaaSport to Paradise: Back to the Future with SSIS in Azure Data Factory
PaaSport to Paradise: Back to the Future with SSIS in Azure Data FactoryPaaSport to Paradise: Back to the Future with SSIS in Azure Data Factory
PaaSport to Paradise: Back to the Future with SSIS in Azure Data Factory
 
Cassandra-as-a-Service
Cassandra-as-a-ServiceCassandra-as-a-Service
Cassandra-as-a-Service
 
Blockchain for the DBA and Data Professional
Blockchain for the DBA and Data ProfessionalBlockchain for the DBA and Data Professional
Blockchain for the DBA and Data Professional
 
(SPOT205) 5 Lessons for Managing Massive IT Transformation Projects
(SPOT205) 5 Lessons for Managing Massive IT Transformation Projects(SPOT205) 5 Lessons for Managing Massive IT Transformation Projects
(SPOT205) 5 Lessons for Managing Massive IT Transformation Projects
 
Configuration in azure done right
Configuration in azure done rightConfiguration in azure done right
Configuration in azure done right
 
Tokyo azure meetup #2 big data made easy
Tokyo azure meetup #2   big data made easyTokyo azure meetup #2   big data made easy
Tokyo azure meetup #2 big data made easy
 

Similar to What Exchange Administrators Need to Know About Hybrid Deployments

Troubleshooting Exchange Hybrid Deployments
Troubleshooting Exchange Hybrid DeploymentsTroubleshooting Exchange Hybrid Deployments
Troubleshooting Exchange Hybrid DeploymentsJoel Brda
 
WIN401_Migrating Microsoft Applications to AWS
WIN401_Migrating Microsoft Applications to AWSWIN401_Migrating Microsoft Applications to AWS
WIN401_Migrating Microsoft Applications to AWSAmazon Web Services
 
AWS Summit Singapore Webinar Edition | Architecting a Serverless Data Lake on...
AWS Summit Singapore Webinar Edition | Architecting a Serverless Data Lake on...AWS Summit Singapore Webinar Edition | Architecting a Serverless Data Lake on...
AWS Summit Singapore Webinar Edition | Architecting a Serverless Data Lake on...Amazon Web Services
 
AWS Summit Singapore - Managing a Database Migration Project | Best Practices
AWS Summit Singapore - Managing a Database Migration Project | Best PracticesAWS Summit Singapore - Managing a Database Migration Project | Best Practices
AWS Summit Singapore - Managing a Database Migration Project | Best PracticesAmazon Web Services
 
Supporting architecture office 365 on windows azure
Supporting architecture office 365 on windows azure  Supporting architecture office 365 on windows azure
Supporting architecture office 365 on windows azure Jethro Seghers
 
Supporting architecture office 365 on windows azure
Supporting architecture office 365 on windows azure  Supporting architecture office 365 on windows azure
Supporting architecture office 365 on windows azure Jethro Seghers
 
ArchitectNow - Migrating Legacy .NET Apps to Azure
ArchitectNow - Migrating Legacy .NET Apps to AzureArchitectNow - Migrating Legacy .NET Apps to Azure
ArchitectNow - Migrating Legacy .NET Apps to AzureKevin Grossnicklaus
 
Serverless without Code (Lambda)
Serverless without Code (Lambda)Serverless without Code (Lambda)
Serverless without Code (Lambda)CloudHesive
 
ENT305 Migrating Your Databases to AWS: Deep Dive on Amazon Relational Databa...
ENT305 Migrating Your Databases to AWS: Deep Dive on Amazon Relational Databa...ENT305 Migrating Your Databases to AWS: Deep Dive on Amazon Relational Databa...
ENT305 Migrating Your Databases to AWS: Deep Dive on Amazon Relational Databa...Amazon Web Services
 
The move-to-hybrid-cloud-itsmf-april2015
The move-to-hybrid-cloud-itsmf-april2015The move-to-hybrid-cloud-itsmf-april2015
The move-to-hybrid-cloud-itsmf-april2015Eduserv
 
Introduction to Microservices
Introduction to MicroservicesIntroduction to Microservices
Introduction to MicroservicesMahmoudZidan41
 
AWS re:Invent 2016: Workshop: Migrating Microsoft Applications to AWS (ENT216)
AWS re:Invent 2016: Workshop: Migrating Microsoft Applications to AWS (ENT216)AWS re:Invent 2016: Workshop: Migrating Microsoft Applications to AWS (ENT216)
AWS re:Invent 2016: Workshop: Migrating Microsoft Applications to AWS (ENT216)Amazon Web Services
 
Using Camunda on Kubernetes through Operators
Using Camunda on Kubernetes through OperatorsUsing Camunda on Kubernetes through Operators
Using Camunda on Kubernetes through Operatorscamunda services GmbH
 
Best practices When Migrating to Office 365
Best practices When Migrating to Office 365Best practices When Migrating to Office 365
Best practices When Migrating to Office 365Perficient, Inc.
 
Adelaide Global Azure Bootcamp 2018 - Azure 101
Adelaide Global Azure Bootcamp 2018 - Azure 101Adelaide Global Azure Bootcamp 2018 - Azure 101
Adelaide Global Azure Bootcamp 2018 - Azure 101Balabiju
 
Database@Home : Data Driven Apps - Data-driven Microservices Architecture wit...
Database@Home : Data Driven Apps - Data-driven Microservices Architecture wit...Database@Home : Data Driven Apps - Data-driven Microservices Architecture wit...
Database@Home : Data Driven Apps - Data-driven Microservices Architecture wit...Tammy Bednar
 
Stay productive_while_slicing_up_the_monolith
Stay productive_while_slicing_up_the_monolithStay productive_while_slicing_up_the_monolith
Stay productive_while_slicing_up_the_monolithMarkus Eisele
 
Designing Microservices
Designing MicroservicesDesigning Microservices
Designing MicroservicesDavid Chou
 

Similar to What Exchange Administrators Need to Know About Hybrid Deployments (20)

Troubleshooting Exchange Hybrid Deployments
Troubleshooting Exchange Hybrid DeploymentsTroubleshooting Exchange Hybrid Deployments
Troubleshooting Exchange Hybrid Deployments
 
WIN401_Migrating Microsoft Applications to AWS
WIN401_Migrating Microsoft Applications to AWSWIN401_Migrating Microsoft Applications to AWS
WIN401_Migrating Microsoft Applications to AWS
 
AWS Summit Singapore Webinar Edition | Architecting a Serverless Data Lake on...
AWS Summit Singapore Webinar Edition | Architecting a Serverless Data Lake on...AWS Summit Singapore Webinar Edition | Architecting a Serverless Data Lake on...
AWS Summit Singapore Webinar Edition | Architecting a Serverless Data Lake on...
 
AWS Summit Singapore - Managing a Database Migration Project | Best Practices
AWS Summit Singapore - Managing a Database Migration Project | Best PracticesAWS Summit Singapore - Managing a Database Migration Project | Best Practices
AWS Summit Singapore - Managing a Database Migration Project | Best Practices
 
Supporting architecture office 365 on windows azure
Supporting architecture office 365 on windows azure  Supporting architecture office 365 on windows azure
Supporting architecture office 365 on windows azure
 
Supporting architecture office 365 on windows azure
Supporting architecture office 365 on windows azure  Supporting architecture office 365 on windows azure
Supporting architecture office 365 on windows azure
 
ArchitectNow - Migrating Legacy .NET Apps to Azure
ArchitectNow - Migrating Legacy .NET Apps to AzureArchitectNow - Migrating Legacy .NET Apps to Azure
ArchitectNow - Migrating Legacy .NET Apps to Azure
 
Serverless without Code (Lambda)
Serverless without Code (Lambda)Serverless without Code (Lambda)
Serverless without Code (Lambda)
 
ENT305 Migrating Your Databases to AWS: Deep Dive on Amazon Relational Databa...
ENT305 Migrating Your Databases to AWS: Deep Dive on Amazon Relational Databa...ENT305 Migrating Your Databases to AWS: Deep Dive on Amazon Relational Databa...
ENT305 Migrating Your Databases to AWS: Deep Dive on Amazon Relational Databa...
 
The move-to-hybrid-cloud-itsmf-april2015
The move-to-hybrid-cloud-itsmf-april2015The move-to-hybrid-cloud-itsmf-april2015
The move-to-hybrid-cloud-itsmf-april2015
 
Introduction to Microservices
Introduction to MicroservicesIntroduction to Microservices
Introduction to Microservices
 
AWS re:Invent 2016: Workshop: Migrating Microsoft Applications to AWS (ENT216)
AWS re:Invent 2016: Workshop: Migrating Microsoft Applications to AWS (ENT216)AWS re:Invent 2016: Workshop: Migrating Microsoft Applications to AWS (ENT216)
AWS re:Invent 2016: Workshop: Migrating Microsoft Applications to AWS (ENT216)
 
Using Camunda on Kubernetes through Operators
Using Camunda on Kubernetes through OperatorsUsing Camunda on Kubernetes through Operators
Using Camunda on Kubernetes through Operators
 
Best practices When Migrating to Office 365
Best practices When Migrating to Office 365Best practices When Migrating to Office 365
Best practices When Migrating to Office 365
 
Adelaide Global Azure Bootcamp 2018 - Azure 101
Adelaide Global Azure Bootcamp 2018 - Azure 101Adelaide Global Azure Bootcamp 2018 - Azure 101
Adelaide Global Azure Bootcamp 2018 - Azure 101
 
Azure basics
Azure basicsAzure basics
Azure basics
 
Database@Home : Data Driven Apps - Data-driven Microservices Architecture wit...
Database@Home : Data Driven Apps - Data-driven Microservices Architecture wit...Database@Home : Data Driven Apps - Data-driven Microservices Architecture wit...
Database@Home : Data Driven Apps - Data-driven Microservices Architecture wit...
 
Stay productive_while_slicing_up_the_monolith
Stay productive_while_slicing_up_the_monolithStay productive_while_slicing_up_the_monolith
Stay productive_while_slicing_up_the_monolith
 
Designing Microservices
Designing MicroservicesDesigning Microservices
Designing Microservices
 
Newt global meetup microservices
Newt global meetup microservicesNewt global meetup microservices
Newt global meetup microservices
 

More from ENow Software

Are you ready for Exchange 2016
Are you ready for Exchange 2016Are you ready for Exchange 2016
Are you ready for Exchange 2016ENow Software
 
Identity Management Over the Horizon: What’s New and What’s Next
Identity Management Over the Horizon: What’s New and What’s NextIdentity Management Over the Horizon: What’s New and What’s Next
Identity Management Over the Horizon: What’s New and What’s NextENow Software
 
Deploy exchange 2016 on prem hybrid final
Deploy exchange 2016 on prem hybrid finalDeploy exchange 2016 on prem hybrid final
Deploy exchange 2016 on prem hybrid finalENow Software
 
Lync & Skype Interop V2 Deep Dive - By Johan Delimon
Lync & Skype Interop  V2 Deep Dive - By Johan DelimonLync & Skype Interop  V2 Deep Dive - By Johan Delimon
Lync & Skype Interop V2 Deep Dive - By Johan DelimonENow Software
 
Troubleshooting Exchange Hybrid Deployments
Troubleshooting Exchange Hybrid DeploymentsTroubleshooting Exchange Hybrid Deployments
Troubleshooting Exchange Hybrid DeploymentsENow Software
 
Top 10 Tips for Supporting & Troubleshooting Lync 2013
Top 10 Tips for Supporting & Troubleshooting Lync 2013Top 10 Tips for Supporting & Troubleshooting Lync 2013
Top 10 Tips for Supporting & Troubleshooting Lync 2013ENow Software
 

More from ENow Software (6)

Are you ready for Exchange 2016
Are you ready for Exchange 2016Are you ready for Exchange 2016
Are you ready for Exchange 2016
 
Identity Management Over the Horizon: What’s New and What’s Next
Identity Management Over the Horizon: What’s New and What’s NextIdentity Management Over the Horizon: What’s New and What’s Next
Identity Management Over the Horizon: What’s New and What’s Next
 
Deploy exchange 2016 on prem hybrid final
Deploy exchange 2016 on prem hybrid finalDeploy exchange 2016 on prem hybrid final
Deploy exchange 2016 on prem hybrid final
 
Lync & Skype Interop V2 Deep Dive - By Johan Delimon
Lync & Skype Interop  V2 Deep Dive - By Johan DelimonLync & Skype Interop  V2 Deep Dive - By Johan Delimon
Lync & Skype Interop V2 Deep Dive - By Johan Delimon
 
Troubleshooting Exchange Hybrid Deployments
Troubleshooting Exchange Hybrid DeploymentsTroubleshooting Exchange Hybrid Deployments
Troubleshooting Exchange Hybrid Deployments
 
Top 10 Tips for Supporting & Troubleshooting Lync 2013
Top 10 Tips for Supporting & Troubleshooting Lync 2013Top 10 Tips for Supporting & Troubleshooting Lync 2013
Top 10 Tips for Supporting & Troubleshooting Lync 2013
 

Recently uploaded

Azure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & ApplicationAzure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & ApplicationAndikSusilo4
 
Hyderabad Call Girls Khairatabad ✨ 7001305949 ✨ Cheap Price Your Budget
Hyderabad Call Girls Khairatabad ✨ 7001305949 ✨ Cheap Price Your BudgetHyderabad Call Girls Khairatabad ✨ 7001305949 ✨ Cheap Price Your Budget
Hyderabad Call Girls Khairatabad ✨ 7001305949 ✨ Cheap Price Your BudgetEnjoy Anytime
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking MenDelhi Call girls
 
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptxMaking_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptxnull - The Open Security Community
 
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Patryk Bandurski
 
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...Neo4j
 
Next-generation AAM aircraft unveiled by Supernal, S-A2
Next-generation AAM aircraft unveiled by Supernal, S-A2Next-generation AAM aircraft unveiled by Supernal, S-A2
Next-generation AAM aircraft unveiled by Supernal, S-A2Hyundai Motor Group
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsEnterprise Knowledge
 
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure serviceWhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure servicePooja Nehwal
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsMark Billinghurst
 
SIEMENS: RAPUNZEL – A Tale About Knowledge Graph
SIEMENS: RAPUNZEL – A Tale About Knowledge GraphSIEMENS: RAPUNZEL – A Tale About Knowledge Graph
SIEMENS: RAPUNZEL – A Tale About Knowledge GraphNeo4j
 
Pigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking MenDelhi Call girls
 
Unblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesUnblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesSinan KOZAK
 
Snow Chain-Integrated Tire for a Safe Drive on Winter Roads
Snow Chain-Integrated Tire for a Safe Drive on Winter RoadsSnow Chain-Integrated Tire for a Safe Drive on Winter Roads
Snow Chain-Integrated Tire for a Safe Drive on Winter RoadsHyundai Motor Group
 
Maximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptxMaximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptxOnBoard
 
Pigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping ElbowsPigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping ElbowsPigging Solutions
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonetsnaman860154
 
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024BookNet Canada
 

Recently uploaded (20)

Azure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & ApplicationAzure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & Application
 
Hyderabad Call Girls Khairatabad ✨ 7001305949 ✨ Cheap Price Your Budget
Hyderabad Call Girls Khairatabad ✨ 7001305949 ✨ Cheap Price Your BudgetHyderabad Call Girls Khairatabad ✨ 7001305949 ✨ Cheap Price Your Budget
Hyderabad Call Girls Khairatabad ✨ 7001305949 ✨ Cheap Price Your Budget
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men
 
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptxMaking_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
 
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
 
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
 
Next-generation AAM aircraft unveiled by Supernal, S-A2
Next-generation AAM aircraft unveiled by Supernal, S-A2Next-generation AAM aircraft unveiled by Supernal, S-A2
Next-generation AAM aircraft unveiled by Supernal, S-A2
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
 
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure serviceWhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR Systems
 
SIEMENS: RAPUNZEL – A Tale About Knowledge Graph
SIEMENS: RAPUNZEL – A Tale About Knowledge GraphSIEMENS: RAPUNZEL – A Tale About Knowledge Graph
SIEMENS: RAPUNZEL – A Tale About Knowledge Graph
 
Pigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food Manufacturing
 
Vulnerability_Management_GRC_by Sohang Sengupta.pptx
Vulnerability_Management_GRC_by Sohang Sengupta.pptxVulnerability_Management_GRC_by Sohang Sengupta.pptx
Vulnerability_Management_GRC_by Sohang Sengupta.pptx
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
 
Unblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesUnblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen Frames
 
Snow Chain-Integrated Tire for a Safe Drive on Winter Roads
Snow Chain-Integrated Tire for a Safe Drive on Winter RoadsSnow Chain-Integrated Tire for a Safe Drive on Winter Roads
Snow Chain-Integrated Tire for a Safe Drive on Winter Roads
 
Maximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptxMaximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptx
 
Pigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping ElbowsPigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping Elbows
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
 

What Exchange Administrators Need to Know About Hybrid Deployments

  • 1. What Exchange Administrators Need to Know about Hybrid Deployments Michael Van Horenbeeck
  • 2. Agenda • What’s life like for an admin in a Hybrid deployment? • Common issues and misconceptions • Moving mailboxes: the good, the bad and the ugly • Keeping ADFS alive • DirSync • What’s next? • Q&A
  • 3. What is a Hybrid deployment? Components of a Hybrid deployment
  • 4. What is a hybrid deployment? “Two distinct cross-premises Exchange organizations, combined to ‘act’ as a single organization through a series of customizations in both environments”
  • 5. HybridArchitecture ACTIVE DIRECTORY OFFICE 365 TENANT EXCHANGE ONLINE TENANT MICROSOFT DATA CENTER INTERNET PERIMETER NETWORK INTERNAL NETWORK EXCHANGE ON-PREM ORG. AZURE AD ADFS PROXY ADFS ACTIVE DIRECTORY DIRSYNC SERVER EXCHANGE 2013 (CAS)ORGANIZATIONAL RELATIONSHIP / OAUTH (INTRA-ORG CONNECTOR) EXCHANGE 2013 (MBX) ONLINE PROTECTION HYBRID MAIL FLOW SMTP EXCHANGE ONLINE AUTHENTICATION SERVICE EXTERNAL USER (O365) SYNC HTTP(S) HTTPS HTTPS OWA USER (O365) HTTPS MAIL FLOW AUTHENTICATION SYNCHRONIZATION APP. ACCESS (HTTP(S)) INTERNAL USER (O365) EXCHANGE USER HTTPS INTERNAL OWA USER (O365)
  • 6. Hybrid Building Blocks Federation DirSync Secure Transport Mailbox Moves • Free/Busy • Mailtips • Message Tracking • eDiscovery • … • Unified GAL • X500 (Mailbox Moves) • Online Archiving • TLS encryption • Header Preservation • Cert-based security • Centralized mail flow • Mailbox Replication Service (MRS) • Online Moves • Fast / Reliable
  • 7. An admin’s life in the cloud…
  • 8. What tasks does an admin commonly execute? • Daily Exchange Management • Identity Management • Moving Mailboxes • Patching • Monitoring • Troubleshooting
  • 9. Identity Management • All user objects are managed on-premises (through Exchange) because of DirSync • Account for the DirSync interval (or force DirSync to run) • Can be important if you want to “quickly” do things. • Watch out for accidental deletions! • New DirSync feature might help…
  • 10. DirSync Accidental Deletion • New in version 6765.0006 (released end of May) • If the number of objects being deleted exceeds a configurable threshold, DirSync won’t sync the deletions to Azure AD. • To enable the feature: • Set-PreventAccidentalDeletes –Enable –ObjectDeletionThreshold <value>
  • 11. Monitoring Hybrid Deployments • New architecture paradigm, requires new way of thinking about monitoring • You don’t care about Microsoft’s side of the story • End-user service availability is key (but it’s always been like that, right?) • Consider monitoring through a series of both Active and Passive tests • Active tests allow you to be proactive • Passive tests give you great feedback (counters…)
  • 12. What components do I need to monitor? • Directory Synchronization • Identity Federation (if applicable) • Exchange Federation • Certificates • Connectivity Featured as Messaging and Unified Communications Award Finalist
  • 13. Patching • Important to stay ‘current’ with patch levels (Exchange, DirSync) in order to remain supported • Challenge to keep up with cloud-cadence (CU’s are typically released every quarter…) • You can use RSS feeds and the Office Blog to stay up to date with the latest and the greatest. Recently released Microsoft roadmap blog might also help: http://office.microsoft.com/en-us/products/office- 365-roadmap-FX104343353.aspx
  • 16. Moving Mailboxes • A trivial action, but touches many different components in Exchange • Make sure the Mailbox Replication Service Proxy [MRS Proxy] is enabled on the internet-facing Exchange Web Services • Before a mailbox can be moved, certain ‘attributes’ need to be available on the object: • Prior to a mailbox move, check that the object have the correct attributes set (x500 + Proxy Addresses) • Because of the cross-premises nature of a hybrid deployment, certain features won’t work after a mailbox move • Watch out for permissions and large items in mailbox!
  • 17. Mailbox move limitations • Items larger than +/- 25 MB won’t be moved because of the item size limits in place in Office 365. • You can export them using this script • Cross-premises permissions (currently?) are not supported. Make sure to move associated mailboxes at the same time. • Potential impact of your ‘pilot’ group.
  • 18. Dealing with High Availability What it takes to make a hybrid deployment highly available
  • 19. What components should be highly available? • Exchange (Hybrid Servers) • AD FS (if deployed) • Connectivity
  • 20. “Hybrid Server” HA • Deploy at least two hybrid servers • Add site resiliency by deploying in two distinct physical locations • Load balance incoming request through a LB device Site 1 Site 2 Connectivity Domain Controller Exchange CAS/MBX Exchange CAS/MBX INTERNE T Domain Controller HA Load Balancer pair
  • 21. DirSync / Azure AD Sync • No urgent need for high availability • You can run w/o DirSync for a (short) period of time, although that would reduce (admin-)functionality temporarily • In case you cannot afford temporary functionality loss (SLAs?) • Deploy a ‘standby’ DirSync server • Consider deploying SQL (default choice for large enterprises anyway) • Easier to backup
  • 22. Active Directory Federation Services • Critical to operations; No ADFS = No user logon possible • Must be deployed HA – in all possible ways • Deploy ADFS cluster; spread across sites to add site resiliency • Can be costly…
  • 23. AD FS HA AD FS Topology AD FS Proxy AD FS Domain Controller INTERNET AD FS AD FS Proxy LoadBalancer LoadBalancer Domain Controller FW FW
  • 24. Troubleshooting An overview of the most common scenarios
  • 25. Troubleshooting AD FS • Not easy. • Use tools like e.g. Fiddler • Enable Debug Logging in Event Viewer • Pair AD FS Proxy w/ ADFS for easier troubleshooting • Understanding different authentication flows is important
  • 26. Enabling Debug Log • Open Event Viewer • Click View > Show Analytic and Debug Logs • Right-click Debug under AD FS Tracing and click enable • Reproduce issue
  • 27. Exchange Federation • Multiple areas where things can go wrong… • Verify that Federation Information can be retrieved (get- federationinformation) • Test Organization Relationships (test-organizationrelationship) • Verify Federation trust (Test-FederationTrust) • When using oAuth: Test-oAuthConnectivity
  • 28. Mailbox Moves • Error message is critical; contains useful information • Verify connectivity; e.g. MRS Proxy enabled? • Use the Test-MigrationServerAvailability for more insights
  • 29. DirSync • No news = good news  • Take a look into the console (miisclient.exe located in installation folder) • Check Permissions (inherit permissions enabled?)
  • 30. About ENow Software Download Mailscape for Exchange Online Free Trial http://bit.ly/Mailscape-Hybrid

Editor's Notes

  1. http://social.technet.microsoft.com/wiki/contents/articles/24544.how-to-avoid-syncing-accidental-deletes-to-the-cloud-directory.aspx