Jump to content

Recommended Posts

Posted

Before i start creating VMs and going ahead with this project i currently have a single domain forest running exchange server.

I want to move exchange to a resource forest, however i'm not sure how this affects Outlook 2016 and autodiscover.

Currently it points to the exchange server in the single domain forest, however once mailboxes are moved to the resource forest, how will outlook 2016 find the mailbox in the resource forest , as mailboxes will have to be migrated gradually.

Posted

Two options

 

 

1) you will have an SCP in Active Directory. clients use that to find the exchange servers. You can create a second SCP. Then have two AD groups "umigrated users" and "migrated users" and permission the the two SCPs with a DENY appropriately

 

2) Similar in approach but on client side, for your migrated users disable SCP and ensure autodiscover.organisation.com points to your new exchange environment. Do the opposite for nonmigrated (disable all but SCP)

 

Autodiscover (and directory sync!) is HARD. If you are not confident, repro this on a few VMs first.

Posted

Without being rude it does seem like you're hell bent on implementing something which is ludicrously complicated (and incredibly resource intensive) when O365 is free and it's not even like you're implementing it all as a result of existing experience, you're having to ask a lot of question on here which is fine but when something goes wrong with this complicated setup then where do you turn?

 

There's a reason most organisations have moved their email to the cloud.

Posted
Without being rude it does seem like you're hell bent on implementing something which is ludicrously complicated (and incredibly resource intensive) when O365 is free and it's not even like you're implementing it all as a result of existing experience, you're having to ask a lot of question on here which is fine but when something goes wrong with this complicated setup then where do you turn?

 

There's a reason most organisations have moved their email to the cloud.

O365 may well be free however please answer the following to convince me..

1. what does it cost to backup

2. requires backup internet connection by separate provider different cable in the event of internet connection loss

3. if internet goes down how do you email internally

4. have 1 global address list containing the users from 2 organisations in 1 global address list/,email system

5. office 365 is slow to navigate

6. can third party spam filters run on o365

7. o365 mailboxes easily hacked cannot lock down smtp authorisation?

and i can think of a few more

Posted
O365 may well be free however please answer the following to convince me..

1. what does it cost to backup

2. requires backup internet connection by separate provider different cable in the event of internet connection loss

3. if internet goes down how do you email internally

4. have 1 global address list containing the users from 2 organisations in 1 global address list/,email system

5. office 365 is slow to navigate

6. can third party spam filters run on o365

7. o365 mailboxes easily hacked cannot lock down smtp authorisation?

and i can think of a few more

 

1. How far back do you want to go - presumably you're limiting your users' mailboxes on prem in terms of storage.

2. Yes it does, but how productive do you think your staff are going to be in 2020 without Internet, also your on prem solution requires backup infrastructure that is way more complicated. In addition you've now got site to site connections with infrastructure in both locations, how comfortably will that deal with split brain and then reconciling once everything reappars if you have a connection outage. With more and more people moving to the cloud how easily will you find support if something goes wrong or you leave - again without being rude you're asking a lot of questions on here in order to implement this solution so it's not like it's something you've done before/are confident with.

3. You don't - why would you need to?

4. Yes

5. No it isn't

6. Yes

7. Nope, nope, nope

 

Are you implementing MFA on your new Exchange solution?

 

What's your disaster recovery plan if the disaster is you're taken seriously unwell or worse? With an O365 setup I can easily find someone to support it for me, with this complicated and obsolete/anachronistic system it's going to be far harder and take far longer to recover if anything does go wrong.

 

What will you do when MS inevitably ditches on prem Exchange - if you look at the resources needed to run Exchange 2019 it's clear they're seriously trying to discourage use!

Posted

I will answer your direct questions as I enjoy the challenge, and I'm not sure there's anything me or Primus could say that will change your view.

 

But there is merit in what Primus is saying. To be clear, I've been a consultant involved with Exchange since version 4 in the 90s, and since then have worked at dozens of FTSE100 companies as well as plenty gnarly O365 deployments in the tens of thousands. I've been a speaker at MS conferences. What you are trying to do is do-able but I would be working very hard on this for a few weeks whilst not doing anything else, just to have confidence before moving it into prod. There would be a 60 page low level design and detailed support notes. And Id still be saying to the client that this is daft and they should be hybridless, in cloud only. TBF most are going that way anyway. Exchange hybrid IS complex. Adding anything else to it (resource domains) doubly so.

  • Thanks 1
Posted
1. How far back do you want to go - presumably you're limiting your users' mailboxes on prem in terms of storage.

2. Yes it does, but how productive do you think your staff are going to be in 2020 without Internet, also your on prem solution requires backup infrastructure that is way more complicated. In addition you've now got site to site connections with infrastructure in both locations, how comfortably will that deal with split brain and then reconciling once everything reappars if you have a connection outage. With more and more people moving to the cloud how easily will you find support if something goes wrong or you leave - again without being rude you're asking a lot of questions on here in order to implement this solution so it's not like it's something you've done before/are confident with.

3. You don't - why would you need to?

4. Yes

5. No it isn't

6. Yes

7. Nope, nope, nope

 

Are you implementing MFA on your new Exchange solution?

 

What's your disaster recovery plan if the disaster is you're taken seriously unwell or worse? With an O365 setup I can easily find someone to support it for me, with this complicated and obsolete/anachronistic system it's going to be far harder and take far longer to recover if anything does go wrong.

 

What will you do when MS inevitably ditches on prem Exchange - if you look at the resources needed to run Exchange 2019 it's clear they're seriously trying to discourage use!

3. you don't? that's not a response put governors want to hear. they want contingency . what would you do for safeguarding, notifying users of potential intruders on site?

 

also our exchange server has never been hacked or mailboxes compromised because it's impossible due to strict firewall rules but I've had other tenencies on 365 who have been hacked with the emails showing in their outbox, blue button virus etc.

Posted

School Governor here:) (CoG and IT link governor, unsurprisingly) I want to hear the policies we have laid out are being followed operationally. If your intruder policy is based on email, firstly thats an interesting way to tackle it, but secondly without infinite resources risk-based decisions are required.

 

p.s. mobile phones.

  • Thanks 1
Posted
3. you don't? that's not a response put governors want to hear. they want contingency . what would you do for safeguarding, notifying users of potential intruders on site?

 

also our exchange server has never been hacked or mailboxes compromised because it's impossible due to strict firewall rules but I've had other tenencies on 365 who have been hacked with the emails showing in their outbox, blue button virus etc.

 

There are plenty of other solutions! By now the majority of schools will be cloud-based for email.

 

Of course you’d have been hacked in five minutes on O365...

 

Are you using MFA?

Posted
School Governor here:) (CoG and IT link governor, unsurprisingly) I want to hear the policies we have laid out are being followed operationally. If your intruder policy is based on email, firstly thats an interesting way to tackle it, but secondly without infinite resources risk-based decisions are required.

 

p.s. mobile phones.

well no we actually use some other software for intruder alerts, but I actually think along the lines of how everyone can communicate. a teacher in a classroom has an issue, no phone, no radio, least they can email someone .

 

lets change our mobile phone policy so that in the event of no internet, we can all use our mobiles..yay

 

Having used exchange for 16 years and 100% uptime, i see no benefit to office 365

Posted
well no we actually use some other software for intruder alerts, but I actually think along the lines of how everyone can communicate. a teacher in a classroom has an issue, no phone, no radio, least they can email someone .

 

lets change our mobile phone policy so that in the event of no internet, we can all use our mobiles..yay

 

Having used exchange for 16 years and 100% uptime, i see no benefit to office 365

 

So you never update your hosts?

 

You’ve never taken things offline even briefly to migrate from one version to another!

 

I’m calling BS on 16 years 100% uptime!

Posted
So you never update your hosts?

 

You’ve never taken things offline even briefly to migrate from one version to another!

 

I’m calling BS on 16 years 100% uptime!

 

 

So you never update your hosts? - of course, it's called DAGs and high availability , how do you think Microsoft keep their systems online which get more advisories with issues because they're always messing with things.

 

And when i migrate versions, i install a new exchange server, migrate mailbox, outlook detects change, close and re-open and boom all my emails are still there..

Posted

And in all that time you’ve never had even a minute of downtime with a dodgy update etc? I simply do not believe that.

 

I will ask again - are you using MFA?

Posted
And in all that time you’ve never had even a minute of downtime with a dodgy update etc? I simply do not believe that.

 

I will ask again - are you using MFA?

 

no because you set the second server in the DAG as active whilst you perform windows/exchange updates on the other one.

No, i'm not using MFA

 

only time our email has been down is in the first 2 years i started when our email server and services were outsourced, the raid failed and the company lost all the data. since i started and took it all on in-house i still have emails from 2006 so i have history of communications when people say do you remember when..

 

exchange is robust because unlike MS its not being tinkered with all the time with changes being made.

Posted
Haha Exchange is robust - ok then.

 

No MFA - sounds secure...

 

What does your DPO think about retaining emails back to 2006?

are you enforcing retention policies to delete emails on your users?

 

did you see Teams went down this week - microsoft forgot to renewal an SSL certificate! says it all really, reliant upon external companies running your infrastructure. things like that don't happen internally.

Posted

Yes I am as it happens.

 

Yes some occasional downtime is to be expected from time to time - nothing is perfect.

 

How many of your users do you think have re-used their passwords which have now been compromised across multiple website data breaches? How do you know you’ve never been hacked or had some phished? MFA isn’t a nice to have, in 2020 it’s an essential.

Posted
Yes I am as it happens.

 

Yes some occasional downtime is to be expected from time to time - nothing is perfect.

 

How many of your users do you think have re-used their passwords which have now been compromised across multiple website data breaches? How do you know you’ve never been hacked or had some phished? MFA isn’t a nice to have, in 2020 it’s an essential.

 

Put it this way, a tenancy i manage , a user contacted me to say i've got a load of un-deliverable emails in my inbox - i went into the users sent items and it listed all the emails that were being sent on office 365.

 

has a user ever told me this on exchange no. i don't yet know of anyone on exchange that has been hit by a virus which mails all users ? all schools i know which have been attacked or had ransomware through email links have been on o365.

 

what do you do if your 365 gets infected and have no backups? cost of backups then comes in. 365 is not a backup solution.

Posted
Put it this way, a tenancy i manage , a user contacted me to say i've got a load of un-deliverable emails in my inbox - i went into the users sent items and it listed all the emails that were being sent on office 365.

 

has a user ever told me this on exchange no. i don't yet know of anyone on exchange that has been hit by a virus which mails all users ? all schools i know which have been attacked or had ransomware through email links have been on o365.

 

what do you do if your 365 gets infected and have no backups? cost of backups then comes in. 365 is not a backup solution.

 

OMG this is now beyond ridiculous.

 

Enjoy your overly complicated and insecure solution that you yourself don’t properly understand. I genuinely hope it doesn’t go bang in your face.

  • Thanks 1
Posted
OMG this is now beyond ridiculous.

 

Enjoy your overly complicated and insecure solution that you yourself don’t properly understand. I genuinely hope it doesn’t go bang in your face.

of course it is. I asked a simple question and unlike some others provided me with a response to a question rather than find a way to avoid doing a job.

 

outsource all your network and wait for others to fix it when it doesn't work because you don't have the knowledge how to

Posted
of course it is. I asked a simple question and unlike some others provided me with a response to a question rather than find a way to avoid doing a job.

 

outsource all your network and wait for others to fix it when it doesn't work because you don't have the knowledge how to

 

Don’t look now but the Exchange expert you’re relying on for free just agreed with me more than once...

Posted (edited)

Yes because O365 is so bad and everyone is moving away from it...

 

You live in cloud cuckoo land if you think staying on prem is the right decision in 2020.

Edited by Primus

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...