Jump to content

AndyBurt

Members
  • Posts

    3
  • Joined

  • Last visited

Reputation

0 Neutral

About AndyBurt

  1. Finally find a way.... For anyone that needs it, this is what I found works for us. Create an outbound Access rule, from the DirSync server to a Domain Name Set (see below domains added) for all users and apply. Domain Name Set *.microsoft.com *.verisign.com *.onmircosoft.com (You may be able to just use this one) Then go to Web Access Policy > Configure HTTPS Inspection > Source Exceptions and add your DirSync Server. After applying and waiting for TMG to sort itself out, go back to the DirSync server and you should now be able to authenticate and sync. On another note if you're syncing passwords, when DirSync runs make sure the .onmicrosoft.com global admin you're using is a different username than your AD account syncing. The sync through up errors halfway through due to my account syncing and 365 updating to my AD my password. School boy error I know. Also be aware DirSync does not sync any AD updates to UPN. This has to be done with remote powershell. Syntax (I Think) - "Set-MsolUserPrincipalName -newuserprincipalname [email protected] -userprincipalname [email protected]". Please note I've not tried this syntax yet as more TMG woe with remote powershell... the joy! :0) Hope this helps. Cheers Andy
  2. Thanks for the reply but my woes are definitely TMG 2010 not allowing anonymous traffic on 443. I can see the authentication request and denies in TMG for DirSync server. I hate TMG, I don't trust it working as it should but its all we have to play with :0(
  3. Hi Mike I'm have the same issue and tried adding domain sets and allow all users etc and still errors Any help would be appreciated. I hope this post will allow me to PM :0) Kind Regards Andy
×
×
  • Create New...