Jump to content

Recommended Posts

Posted

Feel like a bit of a noob asking this question, but, this is a safe space yeah? ;)

 

We moved away from MS Exchange 10 years ago, migrated to M365 and use Azure/Entra AD Sync to sync users from AD up to M365. But, the company that did the migration for us back then, never actually removed Microsoft Exchange, we just switched off the server, removed from the domain, etc. But, Exchange itself was never removed from Active Directory. So, I have components in AD that are Exchange related which I believe are causing issues with our Locker install.

 

Is is a simple case of following this guide here: How to remove Exchange from Active Directory - ALI TAJRAN and removing those elements with ADSI Edit ? I remember removing the autodiscover parts myself (a long time ago) as this was causing issues with Outlook users taking an age to connect to their mailbox. But, in reality should a proper de-install of Exchange have been completed after doing a migration?

 

I'm hovering over the delete button on components in ADSIEdit, but just want to do a sanity check on this one!

 

TIA

 

Pete

Posted
Hmm, I suppose being pedantic they should have left an exchange server in the environment to be supported, though that’s been a nonsense ever since exchange has been in hybrid. All the the attributes for exchange / exchange online are in the AD directory. So, assuming your accounts are still mastered on premise then you’re setting values on prem. So, you can clean up a few permissions that might be lying about, as per what fn-go said and you can nuke server names if there are still in AD but I’m not sure what more you can do.
Posted
Hmm, I suppose being pedantic they should have left an exchange server in the environment to be supported, though that’s been a nonsense ever since exchange has been in hybrid. All the the attributes for exchange / exchange online are in the AD directory. So, assuming your accounts are still mastered on premise then you’re setting values on prem. So, you can clean up a few permissions that might be lying about, as per what fn-go said and you can nuke server names if there are still in AD but I’m not sure what more you can do.

Thanks. Yeah, bad advice given many years ago. Just trying to decide best course of action. End of the day, it's just a group somewhere buried in the depths of AD that has [email protected] as an alias which is clashing with Locker trying to create the group. I've removed all traces of that e-mail address on the on-prem AD group, which I can't delete as it's tied to a lot of things locally.

 

More reading to do before I do something.

 

Pete

Posted

Just an update for any of those that are updated.

 

I've resolved the issue with Locker not being able to create the group. Even though I had removed the attributes in AD that made that particular group mail-enabled, M365 was still insistent it was mail enabled and hanging onto the e-mail address [email protected]. I didn't want to delete the group in AD, as it's used throughout our on-prem stuff so would have been a nightmare to sort out all the resources that used that group. So, instead I moved that particular group into another OU that is not sync'd on Azure Sync, did a delta and the group was removed from M365. Moved the group back to where it was in AD, forced another sync and the group was recreated this time without any mail attributes. Locker could then create a new group for our All Staff.

 

The fall out from this could be that some 'azure' services used that group to permit staff access to things. Our Portal Page which is the school wide home page had targeted links that needed to be updated, but not too many. I may have to deal with a sharepoint site (or a Team) that might have issues, but those are easily resolved. I'll see who shouts after I've checked everything through.

 

In terms of the switched off exchange server and the schema associated with Exchange, I can kick that down the road for now and come up with a solution in the near future. Just means for now our rollover can proceed and we can crack on with Summer work.

 

Take care all.

 

Pete

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...