Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

sukh

Members
  • Posts

    2,161
  • Joined

  • Last visited

Everything posted by sukh

  1. @x-13 - Yes it would. If you want to remove a specific rule, then will will have to be scripted. @Glennda - Make note of the above.
  2. @Glennda - What you may be able to do is create a simple script to add to the logon script for this user or all users and run the following command which will delete the rules. If it's a one then you can amend once or you can leave in login script. Outlook.exe /cleanclientrules Sukh
  3. @Glennda - If you want to delete the rules then you will have to have access to that mailbox and then you can delete by creating a new MAPI profile for that user. You can restrict where the user can send emails to and delete the others. So if he has a rule, depending on the content or the intended recipients etc.., then you can prevent them from sending. If the rules has a common phase then we can filter these auto-replies from being delivered.
  4. @Glennda - This request is a little tricky, as my understanding is that rules are actually stored in the edb in the mailbox therefore you cannot just go into the edb directly and delete the rules. You may be able to prevent the users from creating further rules by using the Office .adm for Outlook 2003. This still means you will have to delete the current rules. Do you want to prevent and delete I assume? Sukh
  5. @Glennda - What version of Exchange and Outlook are you using?
  6. @Iain - I have been shown and told to do the following. Pre-requisties. 1: You must be an owner of the site (i.e. content hierachy access and above) Steps: 1: Open the document Library 2: Click Settings, LIST Settings (or Document Library Settings) 3: Click PERMISSIONS FOR THIS LIST 4: A list of users is displayed who have access to the content. If you only see ACTIONS the security is inherited from the site. You will need to override this by clicking ACTIONS, then EDIT permissions 5: Click NEW, ADD USERS 6: Enter the users and grant the appropriate access 7: Click OK Sukh
  7. @gshaw - Sounds like a plan. I would throughly test the Veeam for Exchange, i.e running from backups. Also, what happens if you have a site failure? Is all your server infra in one room? Sukh
  8. Hi 1. By default the domain admins group should not have Full mailbox access to any mailboxes unless someone has been playing around with permissions. 2. When checking the permissions are you sure you are not looking at the Deny permission and not the allow permission? 3. This particular right/attribute is set on the Information Store and is also available in AD. Depends if this attriubute was set on the IS before a user was created and mail-enabled or not. 4. You should not remove these permissions but correct the issue you have. 5. You mention shared calendars, are these shared calendars in the staff mailboxes or are they dedicated as shared mailboxes which users can use? 6. Check the membership of the domain admins groups and check for a user who has access to the shared calendar that shouldn't is a member? Check for any other groups that exist in the domain admins group. 7. Run the following command from the exchange 2003 server for a user who should not have access to a shared mailbox. Replace username with the username of user as mentioned. DCNAME, enter your domain controller name. "DC......." enter your DN name for domain, i.e in example below the FQDN is mydomain.ad.local.com ldifde -f username.txt -t 3268 -s DCNAME -d "DC=mydomain,dc=ad,dc=local,dc=com" -p subtree -r "(&(objectClass=user)(samaccountname=username))" -v Sukh
  9. @gshaw - It's good going to a VM world. Using DAG on the same SAN is pointless to a certain degree due to the single point of failure that's why using JBOD/DAS give you the HA. In addition to using DAG, you have the advantage of lag copies and the additional checks Exchange will perform before log replay etc... so there more benefits too. 'Have you got HA/FT for your SAN/VM set-up (Hosts/dual HBA's/Dual FC connections/Switches/Controllers/Storage processors/RAM etc.. Can be costly. What happens if this SAN fails? Sukh
  10. Hi See below. Basically just create an auto-reply based on an template which includes the attachment. Out of Office Assistant | HowTo-Outlook Sukh
  11. Hi First of all, can you reproduce the issue? If you can then test the fix on one PC with the same user, if all good then make a global change to all your PC's. Sukh
  12. It is MSFT best practice to do so and also industry best practise. I have too seen AD deployments which share the same external namespace but the not for the rights reasons. DNS Namespace Planning Naming conventions in Active Directory for computers, domains, sites, and OUs Best Practice Active Directory Design for Managing Windows Networks Sukh
  13. Hi There's plenty on these specific topics on the MSFT website to include best practices. Generally you should keep your external and internal namespace separate, this can cause issue with DNS and lookups. For detailed explanation see the AD planning guide on the MSFT website, if you can find I'll send the link. Sukh
  14. @Rabbie - Yes, it should work with NTLM. Only thing from the logs I can see is that both authentication were set ( MaxValidValue) even though, it should have used NTLM. Also, in IIS, the authentication methods must be configured too. If it's working using Basic and you dont want to use NTLM then it's ok, if you want to try NTLM then we try to do that. Sukh
  15. Hi Claire Can you reproduce the problem? Can you open the same PPT file which is on the network if saved locally? Is this issue with all PPT file or is there a pattern? Is there anything special with these PPT files, i.e embedded movies, music etc...? Sukh
  16. Password/username is sent in cleartest, however is encryted if HTTPS is used. Did you have the original issue using NTLM? As from your output it indicates that both basic and NTLM were specified. Sukh
  17. I'm assuming you set the ClientAuthenticationMethod and Outlook to Basic?
  18. @Rabbie - can you run the same command but omit the ClientAuthticationMethod and post/PM Sukh
  19. @Gshaw - As the others have mentioned. It really depends on your usage for the SAN. If it's only for Exchange then I'd consider using JBOD/DAS. You need to have a clear understanding of the requirements. Generally speaking SAN deployments are more expensive than using DAS/JBOD for Exchange and you can still have HA. I'd also consider your backup/recovery before you choose disk solution. You mention performance. Well this can be meausured using free tools such as Download details: Microsoft Exchange Server Profile Analyzer (32 bit) From here you can capture your requirements using the Exchange Calculator (v14.4 of the Exchange 2010 Mailbox Server Role Requirements Calculator) to get your IOPS that you require from disks. If you're using HP/EMC then these vendors will be able to provide you with your disk requirements for a particular SAN. HP/EMC also have Exchange out of the box solutions which are worth looking at for ideas on what type of SAN you should use. If you do decide to go with SAN and if you have specified your IO/disk requirements to the vendor, you can then use Jetstress (Download details: Microsoft Exchange Server Jetstress 2010 (64 bit)) to validate/simulate user activity to see how these disks will perform in production. Even though SANs are and were the only options for Exchange in the past, this has changed. MSFT have been talking about reduction on IOPS for Exchange 2010 from 2007 (claim 70% reduction). This has been a trade-off for the loss of SIS. However MSFT argue that using JBOD/DAS may make up for this (cheapaer large disks). To answer your question about Exchange 2010 in a virtual environment. Basically, yes, Exchange 2010 is supported apart from the UM role which Nathan mentioned. There are some caveats which are here (Exchange 2010 System Requirements: Exchange 2010 SP1 Help). One of the main scenarios I have come across is deployments whereby HA is used by the Virtual infrastructure and Exchange. This is NOT supported by MSFT, however I have seen some deployments configured this way.
  20. Hi You should be able to use a the java deployment.properties file. You can configure the proxy settings in here and use a logon script to copy the file to the users area and put a copy on the netlogon/sysvol share. You may also be able to do this on a per machine level. Sukh
  21. Hi See this. YouTube - SharePoint Item Level Security Sukh
  22. Hi What is the exact error you're getting? Can you try a new PPT file with a new .WAV file and test? Do the same test on another PC, what is the result? Sukh
  23. Hi Yes you can upgrade from STD to ENT. Although the OS mayhave more RAM etc, you need to know the limitations of the application and see if they can take advantage. Putting more RAM into a server doesn't always mean your application will perform better. You may also have to adjust the memory allocation between the OS and application. Sukh
  24. Hi Can you check the event logs for any errors and post any error messages you see after the reboot. I would focus on getting the SP installed rather than moved. Please also, look at the article below. How to troubleshoot Windows Vista and Windows Server 2008 service pack installation issues Sukh
  25. I assume you have exported the users from Exchange 2003 forest and want to import to the Exchange 2010 forest? If so, I'd download the Quest AD cmdlets and use that to import the CSV file you have. Sukh
×
×
  • Create New...