<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>Steve Goodman's Exchange Blog</title>
	
	<link>http://www.stevieg.org</link>
	<description>The weblog of an IT pro specialising in Exchange, Exchange, VMware, Servers and Storage</description>
	<lastBuildDate>Wed, 09 May 2012 21:28:14 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/stevieg" /><feedburner:info uri="stevieg" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item>
		<title>Checking out GFI MailEssentials Online</title>
		<link>http://feedproxy.google.com/~r/stevieg/~3/SZYiDLXXz6I/</link>
		<comments>http://www.stevieg.org/2012/05/checking-out-gfi-mailessentials-online/#comments</comments>
		<pubDate>Mon, 07 May 2012 21:59:08 +0000</pubDate>
		<dc:creator>Steve Goodman</dc:creator>
				<category><![CDATA[Edge Protection]]></category>
		<category><![CDATA[Exchange]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[Filtering]]></category>
		<category><![CDATA[FOPE]]></category>
		<category><![CDATA[GFI]]></category>
		<category><![CDATA[Hosted]]></category>
		<category><![CDATA[MailEssentials]]></category>
		<category><![CDATA[Online]]></category>
		<category><![CDATA[Replacement]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[WebRoot]]></category>
		<category><![CDATA[WebSense]]></category>

		<guid isPermaLink="false">http://www.stevieg.org/?p=1401</guid>
		<description><![CDATA[In today’s modern world of spam and malware filtering, I’m of the opinion it’s not always worthwhile running spam filtering software on-premise. Because of the load it can put on systems and your networks, the larger the company the less value in running it yourself. First of all, let me give you a bit of [...]


Related posts:<ol><li><a href='http://www.stevieg.org/2012/02/testing-edge-blocking-in-forefront-online-protection-for-exchange-using-powershell/' rel='bookmark' title='Testing edge blocking in Forefront Online Protection for Exchange using Powershell'>Testing edge blocking in Forefront Online Protection for Exchange using Powershell</a></li>
<li><a href='http://www.stevieg.org/2012/03/great-joint-post-about-zimbra-verses-exchange/' rel='bookmark' title='Great joint post about Zimbra verses Exchange'>Great joint post about Zimbra verses Exchange</a></li>
<li><a href='http://www.stevieg.org/2010/11/missing-tech-ed-europe-2010-watch-the-exchange-sessions-online-now/' rel='bookmark' title='Missed Tech Ed Europe 2010? Watch the Exchange Sessions Online Now'>Missed Tech Ed Europe 2010? Watch the Exchange Sessions Online Now</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p align="justify"><a href="www.gfi.com/hosted-email-security-solution" target="_blank"><img style="background-image: none; border-right-width: 0px; margin: 0px 0px 0px 7px; padding-left: 0px; padding-right: 0px; display: inline; float: right; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="image" border="0" alt="image" align="right" src="http://www.stevieg.org/wp-content/uploads/image322.png" width="200" height="146" /></a>In today’s modern world of spam and malware filtering, I’m of the opinion it’s not always worthwhile running spam filtering software on-premise. Because of the load it can put on systems and your networks, the larger the company the less value in running it yourself.</p>
<p align="justify">First of all, let me give you a bit of background. Between 2004 and 2010 I spent a lot of time working with on-premise solutions which processed hundreds of thousands of clean mail each day and deflected many orders more spam. During that time I had to understand a lot about where spam and associated malware comes from and what techniques work well against it. By 2010 the kind of effort required to keep up with the above was something I particularly found resource intensive, even though much of it I was delegating to my team. So around that time, I decided it just wasn’t worth it and outsourced mail scanning to the cloud – and never looked back.</p>
<p align="justify">Working as a TA these days I see the same decisions made elsewhere and these days it really is the exception rather than the rule when I see a customer who is running on-premises mail scanning software at the edge.</p>
<p align="justify">With that in mind, it’s interesting to see that GFI, who have long been a leader in the market for on-premises spam and malware scanning software with <a href="http://www.gfi.com/exchange-server-antispam-antivirus" target="_blank">GFI MailEssentials</a>, move to offer a <a href="http://www.gfi.com/hosted-email-security-solution" target="_blank">cloud-based solution</a> to compete, primarily in the SMB market. GFI got in touch with me about a month ago and asked me to give their new product, <a href="http://www.gfi.com/hosted-email-security-solution" target="_blank">GFI MailEssentials Online</a> a spin and share my thoughts…</p>
<h4 align="justify">First Impressions</h4>
<p align="justify">I’ve worked with a number of cloud-based mail scanning solutions in the past – working on projects to migrate to them from on-premises systems, moving between different solutions and during Exchange Server migrations had experience when cutting mail over between the old and new systems. </p>
<p align="justify">A common theme with some of these solutions is that the user interface isn’t very intuitive and all of these products (e.g. Websense/Black Spider, Postini and FOPE) are very capable in terms of what they can do, but for your average IT administrator settings are found all over the place. If you’re not logging into the interface very often, it’s almost as if you’ve got to learn the interface from scratch. I’ve witnessed customers who have used their provider for years struggle to find basic settings through no fault of their own – the systems can be a right mess.</p>
<p align="justify">That’s where GFI seem to have got things right from the outset – the interface reflects that it’s not a dated offering where new features have been thrown in as time has went on; it’s fresh, clear and concise and not once did I need to refer to the actual documentation to accomplish anything. If you’ve ever had to work with policy rules or setup directory synchronization in FOPE, for example, you’ll see that this is a breath of fresh air.</p>
<p align="justify">In terms of features – again I am impressed. We know that for the SMB market, GFI have over a decade of experience with the on-premise MailEssentials product so we know it’s going to be capable, but I wasn’t expecting to see the option to use features like <a href="http://en.wikipedia.org/wiki/Greylisting" target="_blank">greylisting</a>, which I think is particulary effective in the fight against spam.</p>
<h4 align="justify">Getting Started and Setup</h4>
<p align="justify">I signed up for a trial <a href="http://mco-signup.gfi.com/en/mp/" target="_blank">via the GFI website</a>, and with a few minutes was granted access to the Administrator portal. Like most other solutions, a dashboard greets the admin with statistics shown for areas such as spam volume:</p>
<p align="justify"><a href="http://www.stevieg.org/wp-content/uploads/image323.png"><img style="background-image: none; border-right-width: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://www.stevieg.org/wp-content/uploads/image_thumb259.png" width="244" height="162" /></a></p>
<p align="justify">The first thing you need to do is add a new domain, and configure it’s services. As I mentioned above – it’s actually very intuitive. I was asked for the domain name, and the primary mail server to list – perfect for the SMB market:</p>
<p align="justify"><a href="http://www.stevieg.org/wp-content/uploads/image303.png"><img style="background-image: none; border-right-width: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://www.stevieg.org/wp-content/uploads/image_thumb240.png" width="244" height="101" /></a></p>
<p align="justify">After adding the domain, we’re then led to the domain management section of the Administrative portal, which allows us to configure spam filtering service for the domain itself. First of all, we’ve got an “aggressiveness level”. This can at a high-level be compared to the built-in anti-spam features within Exchange, where blocking, quarantine levels can be specified based on score. You’ll also see configuration options for dealing with unknown users, and the ability to switch on or off the greylisting features.</p>
<p align="justify"><a href="http://www.stevieg.org/wp-content/uploads/image306.png"><img style="background-image: none; border-right-width: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://www.stevieg.org/wp-content/uploads/image_thumb243.png" width="244" height="120" /></a></p>
<p align="justify">One area most administrators are familiar with is making sure certain senders – such as partner companies – can send mail without being scanned both inbound and outbound. GFI call this “Whitelisting”, though personally I prefer the term “Safe Senders” as used within the Outlook client. From, To, Subject and mail server IP addresses can be specified here:</p>
<p align="justify"><a href="http://www.stevieg.org/wp-content/uploads/image307.png"><img style="background-image: none; border-right-width: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://www.stevieg.org/wp-content/uploads/image_thumb244.png" width="244" height="119" /></a></p>
<p align="justify">Another common area that control over blocking is required is based on the attachment type. Many forms of attachment are blocked, some to ensure that end-users cannot bypass web filtering to get access to executable files, and more commonly to ensure that malware is very unlikely to reach internal recipients. Yep, you can scan messages for known viruses, but there is a pretty big gap between a new form of malware appearing and definition updates being produced by most anti-virus companies. Therefore blocking executables (or exes renamed to a different file extension) from being received in the first place is extremely helpful.</p>
<p align="justify"><a href="http://www.stevieg.org/wp-content/uploads/image308.png"><img style="background-image: none; border-right-width: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://www.stevieg.org/wp-content/uploads/image_thumb245.png" width="244" height="129" /></a></p>
<p align="justify">Finally, in the basic setup we can add additional inbound mail servers, and of course make a note of the records we’ll need to change later on to switch MX records over from our on-premises mail server to the GFI service:</p>
<p align="justify"><a href="http://www.stevieg.org/wp-content/uploads/image309.png"><img style="background-image: none; border-right-width: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://www.stevieg.org/wp-content/uploads/image_thumb246.png" width="244" height="161" /></a><a href="http://www.stevieg.org/wp-content/uploads/image312.png"><img style="background-image: none; border-right-width: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://www.stevieg.org/wp-content/uploads/image_thumb249.png" width="244" height="87" /></a></p>
<h4 align="justify">Directory Synchronization</h4>
<p align="justify">There’s a couple of reasons why you’d wish to synchronize your local directory with your online service. First of all, there’s the ability to block unknown email addresses at the “edge” and prevent any attempt to deliver them to your local Exchange server. Secondly is if you wish to be able to give end-user access to the spam quarantine and release messages themselves.</p>
<p align="justify">Typically, there are two ways to accomplish this – first is via a dedicated on-premise piece of software that sits behind the perimeter network and reads the local Active Directory or Exchange organization information and synchronizes that data to the mail scanning solution, and the second is by the mail scanning solution initiating a connection to the on-premises Active Directory or other LDAP directory.</p>
<p align="justify">Personally, my preferred approach is the former, as larger enterprises especially tend to deploy dedicated DMZ networks and are not able or willing to allow an external internet-based source to connect to their on-premises directory. However the downside is that the on-premises sync tool often requires some maintenance and occasional troubleshooting. </p>
<p align="justify">GFI’s approach is to use the LDAP-based approach, which for the target market – small and medium enterprises – seems most appropriate as it’s low maintenance and requires minimal time and effort to keep running.</p>
<p align="justify">The configuration is fairly straightforward; once you have allowed GFI’s IP address ranges to contact an Active Directory domain controller (via port 636, if you want to ensure traffic is encrypted), GFI provide a wizard-driven interface to enter your server details:</p>
<p align="justify"><a href="http://www.stevieg.org/wp-content/uploads/image314.png"><img style="background-image: none; border-right-width: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://www.stevieg.org/wp-content/uploads/image_thumb251.png" width="244" height="169" /></a></p>
<p align="justify">After entering server details, you are able to test the configuration to ensure that it is indeed valid.</p>
<p align="justify"><a href="http://www.stevieg.org/wp-content/uploads/image316.png"><img style="background-image: none; border-right-width: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://www.stevieg.org/wp-content/uploads/image_thumb253.png" width="244" height="122" /></a></p>
<p align="justify">And finally, it gives an overview of the users it plans to create accounts for within the GFI service:</p>
<p align="justify"><a href="http://www.stevieg.org/wp-content/uploads/image317.png"><img style="background-image: none; border-right-width: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://www.stevieg.org/wp-content/uploads/image_thumb254.png" width="244" height="114" /></a></p>
<p align="justify">To be honest, it couldn’t get more straightforward. Another thing I did check was that it could handle more than just mailboxes – for example in my example organization, I’ve got mailboxes hosted on Office 365 and it imported these also without any issue.</p>
<h4 align="justify"></h4>
<h4 align="justify">Reporting</h4>
<p align="justify">A key area most administrators in companies large and small are interested in, is the reporting facilities that a product offers. Being able to demonstrate that a product is working is very important when the time comes to prove that it’s been a valuable investment. </p>
<p align="justify">So GFI’s product certainly delivers in this area. I’m not a big fan of reports myself so I don’t get all that excited about them – and based on my demo experience, I haven’t been able to generate enough traffic to generate something worth showing, but suffice to say the facility is there and on a par with competitors:</p>
<p align="justify"><a href="http://www.stevieg.org/wp-content/uploads/image319.png"><img style="background-image: none; border-right-width: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://www.stevieg.org/wp-content/uploads/image_thumb256.png" width="244" height="89" /></a></p>
<p align="justify">The second type of reporting is message tracking reports – essential for troubleshooting delivery issues and verying that a message was or wasn’t delivered. I can definitely say that the product delivers in this area – and is equal or better to most other competitors – for example compared to FOPE it’s a lot easier to use, a bit more flexible and shows an equal amount of information:</p>
<p align="justify"><a href="http://www.stevieg.org/wp-content/uploads/image320.png"><img style="background-image: none; border-right-width: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://www.stevieg.org/wp-content/uploads/image_thumb257.png" width="244" height="72" /></a></p>
<p align="justify"><a href="http://www.stevieg.org/wp-content/uploads/image321.png"><img style="background-image: none; border-right-width: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://www.stevieg.org/wp-content/uploads/image_thumb258.png" width="244" height="187" /></a></p>
<h4 align="justify">Custom Policies</h4>
<p align="justify">Policy rules are an area that bigger customers I deal with do use and some find essential. The kind of things policies can do include:</p>
<ul>
<li>
<div align="justify">Profanity rules and exceptions; for example engineering terms that double as mild swearwords, or a pharmaceutical company wanting to ensure that messages containing references to certain prescription medicine aren’t blocked.</div>
</li>
<li>
<div align="justify">Confidentiality rules; for example to ensure that key terms or patterns are not sent outside the organization – such as credit card numbers.</div>
</li>
<li>
<div align="justify">Encryption rules; for example to ensure that TLS is enforced between particular domains.</div>
</li>
</ul>
<p align="justify">This is one area that just yet, GFI aren’t offering extensive functionality. However I don’t see these kind of features being used extensively in the small and medium business sectors, so it’s not in my opinion a big issue. For the most part this functionality can be used in Exchange itself using Transport rules or whitelisting domains or senders within the GFI service. In regards to TLS, GFI have confirmed opportunistic TLS (i.e. if the recipient domain supports it, TLS will be used) can be switched on if a customer requires it.</p>
<h4 align="justify"></h4>
<h4 align="justify">Summary</h4>
<p>Overall, I’m pretty impressed with the GFI MailEssentials Online service. It doesn’t feel like a “new” offering and it’s clear that the service is based upon experience elsewhere, possibly the many years offering similar products like the on-premises product.</p>
<p>I also think there is a great opening for MailEssentials for the SMB market looking to move/migrate from services with an uncertain future – like Webroot, <a href="http://www.crn.com/news/security/232500092/webroot-kills-e-mail-security-service-plans-end-point-offensive.htm;jsessionid=WaUW26x9G8Ul6ra52Zqdow**.ecappj01" target="_blank">who are closing their email protection service</a>. It will be interesting to see if this good timing pays off, and to be honest I hope it does.</p>
<p><a href="http://www.gfi.com/hosted-email-security-solution" target="_blank">Read more about GFI MailEssentials Online over at the GFI site</a></p>


<p>Related posts:<ol><li><a href='http://www.stevieg.org/2012/02/testing-edge-blocking-in-forefront-online-protection-for-exchange-using-powershell/' rel='bookmark' title='Testing edge blocking in Forefront Online Protection for Exchange using Powershell'>Testing edge blocking in Forefront Online Protection for Exchange using Powershell</a></li>
<li><a href='http://www.stevieg.org/2012/03/great-joint-post-about-zimbra-verses-exchange/' rel='bookmark' title='Great joint post about Zimbra verses Exchange'>Great joint post about Zimbra verses Exchange</a></li>
<li><a href='http://www.stevieg.org/2010/11/missing-tech-ed-europe-2010-watch-the-exchange-sessions-online-now/' rel='bookmark' title='Missed Tech Ed Europe 2010? Watch the Exchange Sessions Online Now'>Missed Tech Ed Europe 2010? Watch the Exchange Sessions Online Now</a></li>
</ol></p>
<p><a href="http://feedads.g.doubleclick.net/~a/biUV_jb9Dbsqki_3FZ76OIGxgVk/0/da"><img src="http://feedads.g.doubleclick.net/~a/biUV_jb9Dbsqki_3FZ76OIGxgVk/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/biUV_jb9Dbsqki_3FZ76OIGxgVk/1/da"><img src="http://feedads.g.doubleclick.net/~a/biUV_jb9Dbsqki_3FZ76OIGxgVk/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/stevieg/~4/SZYiDLXXz6I" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.stevieg.org/2012/05/checking-out-gfi-mailessentials-online/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.stevieg.org/2012/05/checking-out-gfi-mailessentials-online/</feedburner:origLink></item>
		<item>
		<title>Enabling a Remote Mailbox on Office 365 fails</title>
		<link>http://feedproxy.google.com/~r/stevieg/~3/auoxFjNw50A/</link>
		<comments>http://www.stevieg.org/2012/05/enabling-a-remote-mailbox-on-office-365-fails/#comments</comments>
		<pubDate>Tue, 01 May 2012 22:26:15 +0000</pubDate>
		<dc:creator>Steve Goodman</dc:creator>
				<category><![CDATA[Exchange]]></category>
		<category><![CDATA[Exchange 2010 SP2]]></category>
		<category><![CDATA[Office 365]]></category>
		<category><![CDATA[Powershell]]></category>
		<category><![CDATA[Bug]]></category>
		<category><![CDATA[Enable-RemoteMailbox]]></category>
		<category><![CDATA[error]]></category>
		<category><![CDATA[F0109C5E]]></category>
		<category><![CDATA[Failure]]></category>

		<guid isPermaLink="false">http://www.stevieg.org/2012/05/enabling-a-remote-mailbox-on-office-365-fails/</guid>
		<description><![CDATA[I came across this issue last week, and to be honest was a little surprised. I’m sure I’d used it before, probably before Exchange 2010 SP2, so just expected it to work. Let’s say you’ve built a Hybrid Exchange 2010 SP2 / Office 365 environment. You create a user, using your provisioning tool of choice [...]


Related posts:<ol><li><a href='http://www.stevieg.org/2010/11/managing-office-365-on-premises-exchange-2010-powershell-session/' rel='bookmark' title='Managing Office 365 and On-Premises Exchange 2010 from the same Powershell Session'>Managing Office 365 and On-Premises Exchange 2010 from the same Powershell Session</a></li>
<li><a href='http://www.stevieg.org/2012/04/enabling-silent-owa-redirection-for-office-365-hybrid/' rel='bookmark' title='Enabling Silent OWA Redirection for Office 365 Hybrid'>Enabling Silent OWA Redirection for Office 365 Hybrid</a></li>
<li><a href='http://www.stevieg.org/2011/02/disable-exchange-2010-sp1s-auto-shared-mailbox-mapping/' rel='bookmark' title='Disable Exchange 2010&#8242;s Auto Shared Mailbox Mapping Feature'>Disable Exchange 2010&#8242;s Auto Shared Mailbox Mapping Feature</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>I came across this issue last week, and to be honest was a little surprised. I’m sure I’d used it before, probably before Exchange 2010 SP2, so just expected it to work.</p>
<p>Let’s say you’ve built a Hybrid Exchange 2010 SP2 / Office 365 environment. You create a user, using your provisioning tool of choice – for this example we’ll say Active Directory Users and Computers:</p>
<p><a href="http://www.stevieg.org/wp-content/uploads/image301.png"><img style="background-image: none; border-right-width: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://www.stevieg.org/wp-content/uploads/image_thumb238.png" width="244" height="205" /></a></p>
<p>So generally, running <font color="#0000ff" face="Courier New">Enable-RemoteMailbox</font> should work, in the same way running Enable-Mailbox should work too – all the components in Exchange are configured correctly, and if you create a mailbox using <font color="#0000ff" size="2" face="Courier New">New-RemoteMailbox</font> or the Exchange Management Console everything works.</p>
<p>However, the following happens:</p>
<p><a href="http://www.stevieg.org/wp-content/uploads/image610.png"><img style="background-image: none; border-right-width: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://www.stevieg.org/wp-content/uploads/image6_thumb.png" width="644" height="109" /></a></p>
<p>The error – for the purposes of people searching for it is <em>The Address @tenant.mail.onmicrosoft.com is invalid: </em><a href="mailto:&ldquo;@tenant.mail.onmicrosoft.com"><em>“@tenant.mail.onmicrosoft.com</em></a><em>” isn’t a valid SMTP address. The domain name can’t contain spaces and it has to have a prefix and a suffix, such as example.com. FullyQualifiedErrorID : F0109C5E,Microsoft.Exchange.Management.Recipient.Tasks.EnableRemoteMailbox</em>.</p>
<p>I did a quick search on the net, and didn’t find any answers however I did find <a href="http://social.technet.microsoft.com/Forums/en-US/exchangesoftwareupdate/thread/e2d460e3-990f-4bf9-a8af-4ce05c347863" target="_blank">someone having the same problem</a>. Sadly they hadn’t had much luck with forum support or Office 365 support.. So I had a little bit more of a look into the issue and found that the solution in most cases should be fairly simple. </p>
<p>When enabling the remote mailbox, use the –<strong>RemoteRoutingAddress</strong> parameter, specifying your alias and service domain/Office 365 tenant, for example:</p>
<p><font color="#0000ff" size="2" face="Courier New">Enable-RemoteMailbox &lt;username&gt; -RemoteRoutingAddress &lt;alias&gt;@&lt;tenantName&gt;.mail.onmicrosoft.com</font></p>
<p>After using the command as shown above, the remote mailbox should be created and thus provisioned correctly by DirSync:</p>
<p><a href="http://www.stevieg.org/wp-content/uploads/image910.png"><img style="background-image: none; border-right-width: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://www.stevieg.org/wp-content/uploads/image9_thumb.png" width="644" height="110" /></a></p>
<p>A few points of note in addition – if you’ve configured your Hybrid organization the “old” way – i.e. you’ve got a service domain, replace the above &lt;tenantName&gt;.mail.onmicrosoft.com with your chosen Service Domain (i.e. service.contoso.com). And the original poster to the question I answered on TechNet found in his environment, he needed to use the –Alias parameter also to get things moving.</p>
<p>Hope this helps <img style="border-bottom-style: none; border-left-style: none; border-top-style: none; border-right-style: none" class="wlEmoticon wlEmoticon-smile" alt="Smile" src="http://www.stevieg.org/wp-content/uploads/wlEmoticon-smile5.png" /></p>
<p>Steve</p>


<p>Related posts:<ol><li><a href='http://www.stevieg.org/2010/11/managing-office-365-on-premises-exchange-2010-powershell-session/' rel='bookmark' title='Managing Office 365 and On-Premises Exchange 2010 from the same Powershell Session'>Managing Office 365 and On-Premises Exchange 2010 from the same Powershell Session</a></li>
<li><a href='http://www.stevieg.org/2012/04/enabling-silent-owa-redirection-for-office-365-hybrid/' rel='bookmark' title='Enabling Silent OWA Redirection for Office 365 Hybrid'>Enabling Silent OWA Redirection for Office 365 Hybrid</a></li>
<li><a href='http://www.stevieg.org/2011/02/disable-exchange-2010-sp1s-auto-shared-mailbox-mapping/' rel='bookmark' title='Disable Exchange 2010&#8242;s Auto Shared Mailbox Mapping Feature'>Disable Exchange 2010&#8242;s Auto Shared Mailbox Mapping Feature</a></li>
</ol></p>
<p><a href="http://feedads.g.doubleclick.net/~a/t_C27FkY_yZ-ciTZenG6RZ2DLOU/0/da"><img src="http://feedads.g.doubleclick.net/~a/t_C27FkY_yZ-ciTZenG6RZ2DLOU/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/t_C27FkY_yZ-ciTZenG6RZ2DLOU/1/da"><img src="http://feedads.g.doubleclick.net/~a/t_C27FkY_yZ-ciTZenG6RZ2DLOU/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/stevieg/~4/auoxFjNw50A" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.stevieg.org/2012/05/enabling-a-remote-mailbox-on-office-365-fails/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.stevieg.org/2012/05/enabling-a-remote-mailbox-on-office-365-fails/</feedburner:origLink></item>
		<item>
		<title>Using the KEMP LoadMaster with Exchange Server 2010</title>
		<link>http://feedproxy.google.com/~r/stevieg/~3/rhLsv5Wt1y4/</link>
		<comments>http://www.stevieg.org/2012/05/using-the-kemp-loadmaster-with-exchange-server-2010/#comments</comments>
		<pubDate>Tue, 01 May 2012 18:31:10 +0000</pubDate>
		<dc:creator>Steve Goodman</dc:creator>
				<category><![CDATA[Exchange]]></category>
		<category><![CDATA[Exchange 2010 SP1]]></category>
		<category><![CDATA[Exchange 2010 SP2]]></category>
		<category><![CDATA[Load Balancer]]></category>
		<category><![CDATA[KEMP]]></category>
		<category><![CDATA[Load Balancing]]></category>
		<category><![CDATA[LoadMaster]]></category>
		<category><![CDATA[Review]]></category>
		<category><![CDATA[VLB]]></category>
		<category><![CDATA[VLM]]></category>

		<guid isPermaLink="false">http://www.stevieg.org/2012/05/using-the-kemp-loadmaster-with-exchange-server-2010/</guid>
		<description><![CDATA[If you’re a regular reader of this blog, you’ll know that I produce the free Exchange 2010 Virtual Load Balancer, based on HAProxy. However, that’s really aimed at lab use, so you might wonder what I usually recommend in it’s place.. So, it’s about time I wrote about the KEMP LoadMaster, ran through a quick [...]


Related posts:<ol><li><a href='http://www.stevieg.org/2010/11/exchange-team-no-longer-recommend-windows-nlb-for-client-access-server-load-balancing/' rel='bookmark' title='Exchange Team no longer recommend Windows NLB for Client Access Server Load Balancing'>Exchange Team no longer recommend Windows NLB for Client Access Server Load Balancing</a></li>
<li><a href='http://www.stevieg.org/2011/09/new-release-exchange-2010-virtual-load-balancer/' rel='bookmark' title='New Release &ndash; Exchange 2010 Virtual Load Balancer'>New Release &ndash; Exchange 2010 Virtual Load Balancer</a></li>
<li><a href='http://www.stevieg.org/2011/05/unified-messaging-now-supported-in-a-virtual-machine-with-exchange-server-2010-sp1/' rel='bookmark' title='Unified Messaging now supported in a virtual machine with Exchange Server 2010 SP1'>Unified Messaging now supported in a virtual machine with Exchange Server 2010 SP1</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.kemptechnologies.com" target="_blank"><img style="background-image: none; border-bottom: 0px; border-left: 0px; margin: 0px 3px 0px 0px; padding-left: 0px; padding-right: 0px; display: inline; float: right; border-top: 0px; border-right: 0px; padding-top: 0px" title="Blog Kemp Article" border="0" alt="Blog Kemp Article" align="right" src="http://www.stevieg.org/wp-content/uploads/Blog-Kemp-Article2.png" width="142" height="112" /></a>If you’re a regular reader of this blog, you’ll know that I produce the <a href="http://www.stevieg.org/e2010haproxy/" target="_blank">free Exchange 2010 Virtual Load Balancer</a>, based on HAProxy. However, that’s really aimed at lab use, so you might wonder what I usually recommend in it’s place.. </p>
<p>So, it’s about time I wrote about the <a href="http://www.kemptechnologies.com" target="_blank">KEMP LoadMaster</a>, ran through a quick overview of how it works and re-iterate why you really should consider load balancing Exchange Server 2010 with a load balancer rather than Windows Network Load Balancing.</p>
<h4>Why use a load balancer?</h4>
<p>With Exchange Server 2010 clients in a highly-available environment need a resilient point to communicate with Exchange client access servers. In Exchange 2010, not only do clients like web browsers, mobile devices and Outlook Anywhere clients (e.g. Outlook!) connect to the Client Access servers, but also traditional MAPI clients too. The “Client Access Array” within Exchange Server provides a single name that is used by MAPI clients as the Exchange Server name, and because of this it is very important that this is highly available and in the event of failover or switchover clients are not disconnected.</p>
<p>When you listen to the advantages of Exchange Server, one of the areas where benefits are apparent over previous versions is in this area – the ability to perform maintenance on servers without affecting end-users. The real benefit to you as an IT admin is that you can patch Exchange during the working day instead of waiting until a scheduled out-of-hours maintenance period in the evening. It’s kind of like the vMotion of Exchange.</p>
<p>However if you’re just relying on Windows Network Load Balancing, you kind of only get half of that advantage. Common problems using Windows Network Load balancing are issues like some Outlook clients not automatically reconnecting to the NLB after one node is removed and this often means you are back at square one when it comes to performing maintenance.</p>
<p>The second more fundamental set of reasons lie in scalability, service awareness and session affinity. Rather than re-iterate what I’ve written about in the past, check out my article <a href="http://www.stevieg.org/2010/11/exchange-team-no-longer-recommend-windows-nlb-for-client-access-server-load-balancing/" target="_blank">Exchange Team no longer recommend Windows NLB for CAS load balancing</a>. </p>
<p>Finally if you’re building out a new Exchange 2010 environment, hardware costs and licensing are real considerations. As an example, let’s look at two options for building out a small but resilient Exchange infrastructure:</p>
<p>Option 1, using NLB:</p>
<ul>
<li>2 x Client Access / Hub Transport Servers </li>
<li>2 x Mailbox Servers forming a Database Availability Group </li>
</ul>
<p>Option 2, using a Load Balancer:</p>
<ul>
<li>1 or 2 Load Balancers, depending on requirements </li>
<li>2 x Combined Client Access, Hub Transport and Mailbox Servers forming a Database Availability Group </li>
</ul>
<p>So, with Option 1 we’re possibly looking at the following <em>additional servers</em> just to support Windows NLB on the Client Access/Hub Transport roles:</p>
<ul>
<li>2 x Exchange Server Standard Edition Licences </li>
<li>2 x Windows Server Standard Edition Licences </li>
<li>2 x Servers with probably 8GB RAM each, RAID 1 storage and Xeon CPUs with multiple NICs, redundant PSUs. </li>
</ul>
<p>But with option 2, we’re replacing all that with a load balancer (bear in mind that in a typical environment the combined role Exchange servers will have a lot of spare CPU cycles available and not need as much additional memory as standalone CAS/HT servers).</p>
<p>Now, traditionally with load balancers like the F5 and the Cisco ACE I’ve found that it’s not easy to justify the benefits when the primary application may just be Exchange, and possibly Lync – they are just too expensive and completely overshadow the hardware and licensing costs of CAS/HT servers. </p>
<p>However I think this is where KEMP have found a good niche in the market – not only are they now an established player with a lot of people in the Exchange community using them, the price point fits the bill perfectly. Even in a virtual environment where there’s no additional hardware and Windows licences to purchase, the KEMP is still competitive against Exchange Server Standard edition licences. </p>
<p>So for the same ballpark price, it’s an easier implementation, easier to manage and it’s a nice compact straightforward design. For example, using a load balancer fits in quite well with the idea of using combined role servers as “building blocks” to scale Exchange simply as your requirements grow.</p>
<h4>Overview of the KEMP Virtual LoadMaster</h4>
<p>A good start when you’re looking at the <a href="http://www.kemptechnologies.com" target="_blank">KEMP LoadMaster</a> is the Virtual LoadMaster, or VLM for short. There’s a <a href="http://www.kemptechnologies.com/uk/server-load-balancing-appliances.html" target="_blank">few different models in the KEMP range</a> – and the <a href="http://www.kemptechnologies.com/uk/server-load-balancing-appliances/virtual-load-balancers/vlm-overview.html" target="_blank">VLM</a> is a good one to get a <a href="http://www.kemptechnologies.com/uk/server-load-balancing-appliances/virtual-loadbalancer/vlm-download.html" target="_blank">demo</a> of to see what it’s actually like in practice. You’ve got the Exchange specific ones and generic ones which can balance pretty much anything.</p>
<p>For this example, I’ve drawn a quick diagram to illustrate what we’ll be attempting to do. You’ll see the HTTP/S namespace for exchange (mail.exchangelabs.co.uk) and the CAS Array name (outlook.exchangelabs.co.uk) both pointing internally at the KEMP VLM. Behind it is three Exchange Servers, all hosting the Client Access, Hub Transport and Mailbox roles as part of a Database Availability Group:</p>
<p><a href="http://www.stevieg.org/wp-content/uploads/Blog-Kemp-Article1.png"><img style="background-image: none; border-right-width: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="Blog Kemp Article" border="0" alt="Blog Kemp Article" src="http://www.stevieg.org/wp-content/uploads/Blog-Kemp-Article_thumb.png" width="371" height="292" /></a></p>
<p>Initial setup of the KEMP LoadMaster is straightforward – but in overview you need to perform the following steps:</p>
<ul>
<li>Installation of the VHD of VMDK into your Virtual environment. </li>
<li>First boot and access of the VLM via HTTP </li>
<li>Licensing </li>
<li>Configuration of network interfaces. </li>
<li>Installation of my Wildcard SSL certificate onto the LoadMaster. </li>
</ul>
<p>Next it’s onto the configuration of the environment to match the diagram above. I’ve configured two network interfaces, bridging the above two VLANs/LAN segments shown. This allows the LoadMaster to act in a transparent fashion and report the original client IP addresses to the Exchange Servers themselves. I’ve then configured the Exchange Servers, covered in detail within the <a href="http://www.kemptechnologies.com/fileadmin/content/downloads/documentation/5.1/KEMP_MS__Exchange_2010_Deployment_Guide_5_1_0924.pdf" target="_blank">KEMP Exchange 2010 deployment guide</a>:</p>
<ul>
<li>Using the LoadMaster as the default gateway on each Exchange server hosting the CAS role (all of them, in our scenario). </li>
<li><a href="http://social.technet.microsoft.com/wiki/contents/articles/1267.how-to-configure-ssl-offloading-in-exchange-2010-en-us.aspx#Scripted_Method" target="_blank">Configured SSL Offloading on each Exchange server hosting CAS.</a> </li>
<li><a href="http://blogs.technet.com/b/bshukla/archive/2011/10/21/script-to-configure-static-ports-on-exchange-server-2010.aspx" target="_blank">Configured Static RPC ports for MAPI and the Address Book Service on each Exchange server hosting CAS</a>. </li>
</ul>
<p>I’ve then added services for HTTPS, and the two RPC services, as shown below:</p>
<p><a href="http://www.stevieg.org/wp-content/uploads/image298.png"><img style="background-image: none; border-right-width: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://www.stevieg.org/wp-content/uploads/image_thumb235.png" width="644" height="320" /></a></p>
<p>As you can see, it’s a fairly straightforward configuration, and we can add more services under different ports, or different IP addresses as required; for example to publish SMTP services, or indeed other servers such as Lync.</p>
<p>Similarly, when it comes to management of the devices and services, we’ve got an easy to use interface to disable the real Client Access Servers from receiving traffic:</p>
<p><a href="http://www.stevieg.org/wp-content/uploads/image299.png"><img style="background-image: none; border-right-width: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://www.stevieg.org/wp-content/uploads/image_thumb236.png" width="644" height="320" /></a></p>
<p>Finally, we can examine statistics about the Loadmaster itself, client connections and the traffic sent to each Exchange Server:</p>
<p><a href="http://www.stevieg.org/wp-content/uploads/image300.png"><img style="background-image: none; border-right-width: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://www.stevieg.org/wp-content/uploads/image_thumb237.png" width="644" height="322" /></a></p>
<h4>Conclusions</h4>
<p>So, we’ve had a quick look at the KEMP and as you can see, it’s fairly straightforward to administer and look after. It’s certainly a lot easier to get to grips with than, say a Cisco ACE (something I’ve had some experience with) and that means it’s likely to be more than just some “black box” that you don’t ever log into, or are worried about breaking something if you use. And if you’re implementing it for someone else, you’ll be able to hand over the unit confident in the knowledge that you won’t get a phone call next time someone needs to disable one of the servers for patching.</p>
<p>But the one thing that makes KEMP especially attractive is the combination that it’s a well known product, with decent support and a decent price. There are free solutions out there (like my own!) but I wouldn’t use them in a production environment simply because you need quality support available if there is an issue.</p>
<p>A final note – KEMP did ask me to write about their Load Balancer but I’d like to make it clear that I didn’t receive any compensation for it, apart from a Not For Resale (NFR) demo copy of the VLM to use for the review. What their marketing people <em>didn’t</em> know when they asked me to write about their Load Balancer is that I already recommend KEMP to my customers – in fact I’m implementing another for a new deployment in a couple of weeks time, so I figured.. why not <img style="border-bottom-style: none; border-left-style: none; border-top-style: none; border-right-style: none" class="wlEmoticon wlEmoticon-smile" alt="Smile" src="http://www.stevieg.org/wp-content/uploads/wlEmoticon-smile4.png" /></p>
<p>You can download the demo version of the KEMP LoadMaster <a href="http://www.kemptechnologies.com/uk/server-load-balancing-appliances/virtual-loadbalancer/vlm-download.html" target="_blank">here, for the standard version</a> and <a href="http://www.kemptechnologies.com/uk/server-load-balancing-appliances/virtual-loadmaster-exchange/vlmex-download.html" target="_blank">here for the pre-configured Exchange version</a>.</p>
<p>Steve</p>


<p>Related posts:<ol><li><a href='http://www.stevieg.org/2010/11/exchange-team-no-longer-recommend-windows-nlb-for-client-access-server-load-balancing/' rel='bookmark' title='Exchange Team no longer recommend Windows NLB for Client Access Server Load Balancing'>Exchange Team no longer recommend Windows NLB for Client Access Server Load Balancing</a></li>
<li><a href='http://www.stevieg.org/2011/09/new-release-exchange-2010-virtual-load-balancer/' rel='bookmark' title='New Release &ndash; Exchange 2010 Virtual Load Balancer'>New Release &ndash; Exchange 2010 Virtual Load Balancer</a></li>
<li><a href='http://www.stevieg.org/2011/05/unified-messaging-now-supported-in-a-virtual-machine-with-exchange-server-2010-sp1/' rel='bookmark' title='Unified Messaging now supported in a virtual machine with Exchange Server 2010 SP1'>Unified Messaging now supported in a virtual machine with Exchange Server 2010 SP1</a></li>
</ol></p>
<p><a href="http://feedads.g.doubleclick.net/~a/oz7PEQZzDfboVvQ2vAcZqqxWVwA/0/da"><img src="http://feedads.g.doubleclick.net/~a/oz7PEQZzDfboVvQ2vAcZqqxWVwA/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/oz7PEQZzDfboVvQ2vAcZqqxWVwA/1/da"><img src="http://feedads.g.doubleclick.net/~a/oz7PEQZzDfboVvQ2vAcZqqxWVwA/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/stevieg/~4/rhLsv5Wt1y4" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.stevieg.org/2012/05/using-the-kemp-loadmaster-with-exchange-server-2010/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.stevieg.org/2012/05/using-the-kemp-loadmaster-with-exchange-server-2010/</feedburner:origLink></item>
		<item>
		<title>Outlook 2003 is unresponsive when managing Delegates with Exchange 2010</title>
		<link>http://feedproxy.google.com/~r/stevieg/~3/2dDuprOHGUo/</link>
		<comments>http://www.stevieg.org/2012/04/outlook-2003-is-unresponsive-when-managing-delegates-with-exchange-2010/#comments</comments>
		<pubDate>Tue, 24 Apr 2012 22:10:13 +0000</pubDate>
		<dc:creator>Steve Goodman</dc:creator>
				<category><![CDATA[Exchange]]></category>
		<category><![CDATA[Exchange 2010 SP1]]></category>
		<category><![CDATA[Exchange 2010 SP2]]></category>
		<category><![CDATA[Outlook]]></category>
		<category><![CDATA[Delegate]]></category>
		<category><![CDATA[Exchange 2010]]></category>
		<category><![CDATA[hang]]></category>
		<category><![CDATA[issue]]></category>
		<category><![CDATA[known]]></category>
		<category><![CDATA[Outlook 2003]]></category>
		<category><![CDATA[Permissions]]></category>
		<category><![CDATA[timeout]]></category>
		<category><![CDATA[unresponsive]]></category>

		<guid isPermaLink="false">http://www.stevieg.org/2012/04/outlook-2003-is-unresponsive-when-managing-delegates-with-exchange-2010/</guid>
		<description><![CDATA[Here’s something I came across while helping a colleague out with an unusual issue they were seeing against a customer’s Exchange 2010 environment with Outlook 2003 clients. We spent a fair bit of time looking into the issue and determined that it affected Outlook 2003, and Outlook 2007 SP2 and below (unless this patch was [...]


Related posts:<ol><li><a href='http://www.stevieg.org/2010/12/enabling-outlook-2003-and-2007-to-display-exchange-gal-photos/' rel='bookmark' title='Enabling Outlook 2003 and 2007 to display Exchange GAL photos'>Enabling Outlook 2003 and 2007 to display Exchange GAL photos</a></li>
<li><a href='http://www.stevieg.org/2010/06/calendar-sharing-improvements-coming-in-exchange-2010-sp1/' rel='bookmark' title='Managing iCal Calendar Sharing with Exchange 2010 SP1 [Updated]'>Managing iCal Calendar Sharing with Exchange 2010 SP1 [Updated]</a></li>
<li><a href='http://www.stevieg.org/2010/08/auto-mapping-shared-mailboxes-in-exchange-2010-sp1-with-outlook-2010/' rel='bookmark' title='Auto-mapping shared mailboxes in Exchange 2010 SP1 with Outlook 2010 and Outlook 2007'>Auto-mapping shared mailboxes in Exchange 2010 SP1 with Outlook 2010 and Outlook 2007</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>Here’s something I came across while helping a colleague out with an unusual issue they were seeing against a customer’s Exchange 2010 environment with Outlook 2003 clients. We spent a fair bit of time looking into the issue and determined that it affected Outlook 2003, and Outlook 2007 SP2 and below (unless <a href="http://support.microsoft.com/default.aspx?scid=kb;en-US;2475891" target="_blank">this patch</a> was applied). </p>
<p>Confirmation came from Microsoft PSS that this was an issue, however it’s not something that had been publically documented. After talking to Henrik Walther I was glad to find that I wasn’t the only person out there to have seen this, though, however it’s fair to say it’s unusual that this would be a major issue. Here’s a little more on the problem:</p>
<p>When reviewing or modifying delegate information via <strong>Tools&gt;Options</strong> and choosing the <strong>Delegates</strong> tab, Outlook 2003 may exhibit some or all of the following symptoms:</p>
<ul>
<li>Choosing the Delegates tab causes Outlook 2003 to stop responding for upwards of 30 seconds to 2 minutes before displaying information.</li>
<li>When saving delegate information, Outlook 2003 stops responding for upwards of 30 seconds to 2 minutes before closing the <strong>Options</strong> window.</li>
<li>The message &quot;Outlook is trying to retrieve data from the Microsoft Exchange Server&quot; pop-up notification is displayed to the user.</li>
</ul>
<p>You’ll see this in action in the video below:</p>
<div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:5737277B-5D6D-4f48-ABFC-DD9C333F4C5D:f9e6b77b-ea35-44af-a17e-cb538675f08a" class="wlWriterEditableSmartContent">
<div><!-- copy and paste. Modify height and width if desired. --> <object id="scPlayer"  width="681" height="521" type="application/x-shockwave-flash" data="http://content.screencast.com/users/SteveGoodman/folders/Jing/media/1294fcbc-1cfa-42cf-85ff-e6b4f3b12c2d/jingswfplayer.swf" ><param name="movie" value="http://content.screencast.com/users/SteveGoodman/folders/Jing/media/1294fcbc-1cfa-42cf-85ff-e6b4f3b12c2d/jingswfplayer.swf" /><param name="quality" value="high" /><param name="bgcolor" value="#FFFFFF" /><param name="flashVars" value="thumb=http://content.screencast.com/users/SteveGoodman/folders/Jing/media/1294fcbc-1cfa-42cf-85ff-e6b4f3b12c2d/FirstFrame.jpg&amp;containerwidth=681&amp;containerheight=521&amp;content=http://content.screencast.com/users/SteveGoodman/folders/Jing/media/1294fcbc-1cfa-42cf-85ff-e6b4f3b12c2d/Outlook%202003%20Delegates.swf&amp;blurover=false" /><param name="allowFullScreen" value="true" /><param name="scale" value="showall" /><param name="allowScriptAccess" value="always" /><param name="base" value="http://content.screencast.com/users/SteveGoodman/folders/Jing/media/1294fcbc-1cfa-42cf-85ff-e6b4f3b12c2d/" />Unable to display content. Adobe Flash is required.</object></div>
<div style="width:681px;clear:both;font-size:.8em">A long video showing what should be a 30 second process</div>
</div>
<p>In previous versions of Exchange Server, the Outlook Client talked directly to a Global Catalog server after a DSProxy referral. In Exchange Server 2010, the Client Access Service runs the Address Book Service which provides the NSPI endpoint that Outlook clients connect to for accessing directory information.</p>
<p>This issue is caused by the method Outlook 2003 requests data from the Address Book Service on the Client Access Server. The issue is corrected in current versions of Outlook 2007 and 2010, but will not be corrected in Outlook 2003.</p>
<p>The workaround to this issue is to limit which users should be delegates on mailboxes, and grant general calender sharing permissions via the following method, which is also applicable to other Outlook folders.</p>
<ol>
<li>Right-click the <strong>Calendar</strong> folder, and then click <strong>Properties</strong>. </li>
<li>Click the <strong>Permissions</strong> tab. </li>
<li>Click <strong>Add</strong>. </li>
<li>Click the name of the user who you want to grant permissions to, click <strong>Add</strong>, and then click <strong>OK</strong>. </li>
<li>In the <strong>Name</strong> box, click the user name, and then choose the permission level, for example <strong>Editor</strong> in the<strong> Permission Level</strong> box. </li>
<li>Click <strong>Apply</strong>, and then click <strong>OK</strong>.</li>
</ol>
<p>There is a way to force Outlook 2003 to contact a Global Catalog server directly – this was published in the KB article <a href="http://support.microsoft.com/kb/319206"><strong>KB319206, How to configure Outlook to a specific global catalog server or to the closest global catalog server</strong></a>. In our customer’s environment, MS suggested it’s use, and theoretically it should be similar to an Exchange client access server running on a AD DC/GC (which is supported). However, given the article says it should never be used in an Exchange 2010 environment I would stay away from it unless specifically advised otherwise by Microsoft.</p>
<p>I’ve updated the TechNet Wiki article <strong><em><a href="http://social.technet.microsoft.com/wiki/contents/articles/1586.concern-is-having-outlook-2003-clients-going-to-prevent-me-from-deploying-exchange-2010.aspx" target="_blank">Concern: Is Having Outlook 2003 Clients Going to Prevent Me from Deploying Exchange 2010?</a></em></strong> with this information.</p>
<p>Steve</p>


<p>Related posts:<ol><li><a href='http://www.stevieg.org/2010/12/enabling-outlook-2003-and-2007-to-display-exchange-gal-photos/' rel='bookmark' title='Enabling Outlook 2003 and 2007 to display Exchange GAL photos'>Enabling Outlook 2003 and 2007 to display Exchange GAL photos</a></li>
<li><a href='http://www.stevieg.org/2010/06/calendar-sharing-improvements-coming-in-exchange-2010-sp1/' rel='bookmark' title='Managing iCal Calendar Sharing with Exchange 2010 SP1 [Updated]'>Managing iCal Calendar Sharing with Exchange 2010 SP1 [Updated]</a></li>
<li><a href='http://www.stevieg.org/2010/08/auto-mapping-shared-mailboxes-in-exchange-2010-sp1-with-outlook-2010/' rel='bookmark' title='Auto-mapping shared mailboxes in Exchange 2010 SP1 with Outlook 2010 and Outlook 2007'>Auto-mapping shared mailboxes in Exchange 2010 SP1 with Outlook 2010 and Outlook 2007</a></li>
</ol></p>
<p><a href="http://feedads.g.doubleclick.net/~a/l9klWI7bTmLDJ-XXLEEI45l-DzA/0/da"><img src="http://feedads.g.doubleclick.net/~a/l9klWI7bTmLDJ-XXLEEI45l-DzA/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/l9klWI7bTmLDJ-XXLEEI45l-DzA/1/da"><img src="http://feedads.g.doubleclick.net/~a/l9klWI7bTmLDJ-XXLEEI45l-DzA/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/stevieg/~4/2dDuprOHGUo" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.stevieg.org/2012/04/outlook-2003-is-unresponsive-when-managing-delegates-with-exchange-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.stevieg.org/2012/04/outlook-2003-is-unresponsive-when-managing-delegates-with-exchange-2010/</feedburner:origLink></item>
	</channel>
</rss>

