Bankesy Posted March 4, 2024 Posted March 4, 2024 Good afternoon all, I'm trying to understand what is causing X500 proxy addresses to be added to distribution lists in AD and how to stop it? My vague understanding is it's something to do with Azure AD Sync, I've got a mail-enabled security group that I can't delete but don't want people to e-mail. But every time I remove the X500 address it just comes back, I've tried mail-disable via PowerShell. Any other suggestions? Thanks
3s-gtech Posted March 4, 2024 Posted March 4, 2024 I think you'll need to move it to an OU that's not synced with your M365.
Bankesy Posted March 4, 2024 Author Posted March 4, 2024 @3s-gtech Okay, hopefully there are some that are not synced with M365. I didn't do setup here, I guess there's a way I can check with OUs are and change this if required? Through Azure AD sync right? Thanks
howartp Posted March 4, 2024 Posted March 4, 2024 Yes, you get a directory structure with ticky boxes for each OU/level that you tick/untick.
3s-gtech Posted March 4, 2024 Posted March 4, 2024 Indeed, and you can change that structure post-install. You should not sync all directories.
Bankesy Posted March 5, 2024 Author Posted March 5, 2024 Thanks for the tips, I've got a strange feeling that the people before me might have set every directory to sync but I will check.
psydii Posted March 5, 2024 Posted March 5, 2024 We've had oddness when accounts have fallen out of scope of AAD Sync and then fallen back in scope seemingly causing 3rd party systems syncing with on prem AD to start preferring the X500 address for those users. It probably has something to do with adding/removing exchange licenses on mail enabled accounts.
Bankesy Posted March 7, 2024 Author Posted March 7, 2024 Thanks everyone, I've had another look and it seems the entire directory is selected for sync so I'll have to think about which ones I don't want to get around this problem. While I'm here, I wonder if anybody could help me troubleshoot a security certificate issue as I don't really understand these things. I believe it's related to the Exchange certificate that got renewed but I'm confused as to why only one user is having the issue, as you can see from the screenshot below there appears to be an issue with the path but I'm not sure what to do from here. I've tried exporting the cert from Exchange thinking I could manually install it on that one PC but seems I need a secret key that I don't have, I do know that the cert is generated by LetsEncrypt on the Exchange server.
howartp Posted March 7, 2024 Posted March 7, 2024 Is the date/time correct on the one PC that is struggling with it? What is the date from/to on the certificate?
Bankesy Posted March 8, 2024 Author Posted March 8, 2024 @howartp The date to and from is November last year to February this so it is out of date but I don't understand why when I have updated on Exchange server and it's working for everyone else. Thanks
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now