<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
    <title>Tools for Exchange &amp; Active Directory</title>
    <link rel="alternate" type="text/html" href="http://www.tools4exchange.com/" />
    <link rel="self" type="application/atom+xml" href="http://www.tools4exchange.com/atom.xml" />
    <id>tag:www.tools4exchange.com,2009-09-21://13</id>
    <updated>2013-03-18T17:24:41Z</updated>
    
    <generator uri="http://www.sixapart.com/movabletype/">Movable Type 5.12</generator>

<entry>
    <title>GALsync v5 announced for Exchange 2013 and Office 365</title>
    <link rel="alternate" type="text/html" href="http://www.tools4exchange.com/2013/03/galsync-5-announced-for-exchange-2013-and-office-365.html" />
    <id>tag:www.tools4exchange.com,2013://13.1769</id>

    <published>2013-03-18T17:14:13Z</published>
    <updated>2013-03-18T17:24:41Z</updated>

    <summary><![CDATA[ NETsec announced version 5 of its favorite software GALsync to synchronize Global Address Lists between Exchange organizations.&nbsp; With version 5.0 of GALsync,&nbsp; support for Exchange Web Services and PowerShell 2.0 was added. GALsync now can synchronize with Exchange Online...]]></summary>
    <author>
        <name>Hans Willi Kremer</name>
        <uri>http://www.NETsec.de</uri>
    </author>
    
        <category term="Exchange 2013" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Free/Busy" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="GALsync" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="calendarfederation" label="calendar federation" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="exchange2013crossforestgal" label="Exchange 2013 cross-forest GAL" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="exchangeonlinedirsync" label="Exchange Online DirSync" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="federation" label="federation" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="galfederation" label="GAL federation" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="galsync" label="GALsync" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="globaladdresslistbetweenmultipleexchangeorganization" label="Global address list between multiple Exchange organization" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="office365dirsync" label="Office 365 Dirsync" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://www.tools4exchange.com/">
        <![CDATA[<p>
	NETsec announced version 5 of its favorite software GALsync to synchronize Global Address Lists between Exchange organizations.&nbsp;</p>
<ul>
	<li>
		With version 5.0 of GALsync,&nbsp; support for Exchange Web Services and PowerShell 2.0 was added.</li>
	<li>
		GALsync now can synchronize with Exchange Online (Microsoft Office 365).</li>
	<li>
		GALsync version 5 is able to synchronize the Global Address Lists between Exchange 2007 SP1, Exchange 2010 SP1, Exchange 2013 and Exchange Online.</li>
	<li>
		The former built-In Free/Busy solution (Synchronizing Public Folder contents using MAPI) has been deprecated, thus version 5.0 of GALsync enables customers to set up an live Free/Busy using Online Free/Busy or MS Federation.</li>
	<li>
		Extended performance improvements and&nbsp;less bandwidth needs</li>
	<li>
		GUI of GALsync is updated&nbsp;to the new Windows8-Style</li>
</ul>
<p>
	more information at <a href="http://www.netsec.de/en/download/galsync/" target="_blank">NETsec Website</a></p>
]]>
        
    </content>
</entry>

<entry>
    <title>Troubleshooting Cross Forest Delegation</title>
    <link rel="alternate" type="text/html" href="http://www.tools4exchange.com/2013/03/troubleshooting-cross-forest-delegation.html" />
    <id>tag:www.tools4exchange.com,2013://13.1766</id>

    <published>2013-03-03T12:44:53Z</published>
    <updated>2013-03-19T13:26:52Z</updated>

    <summary><![CDATA[ Setting up&nbsp;a untrusted&nbsp; cross-forest environment supports&nbsp;a simple Free/Busy query between two the&nbsp;forests using &bdquo;galsynced&ldquo; contacts.&nbsp; This feature I described in article&nbsp; Cross-Forest Free/Busy without Federation&nbsp;and its corresponding troubleshooting guide. In this article I want to share some experiences&nbsp;with troubleshooting...]]></summary>
    <author>
        <name>Hans Willi Kremer</name>
        <uri>http://www.NETsec.de</uri>
    </author>
    
        <category term="Exchange 2007" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Exchange 2010" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Exchange 2013" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Free/Busy" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="GALsync" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="availabilityaddressspace" label="AvailabilityAddressSpace" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="crossforestdelegation" label="cross-forest delegation" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="crossforestfreebusy" label="cross-forest free/busy" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="crossforestsharedcalendar" label="cross-forest shared calendar" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="galsync" label="GALsync" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://www.tools4exchange.com/">
        <![CDATA[<p>
	Setting up&nbsp;a untrusted&nbsp; cross-forest environment supports&nbsp;a simple Free/Busy query between two the&nbsp;forests using &bdquo;galsynced&ldquo; contacts.&nbsp; This feature I described in article&nbsp; <a href="http://www.tools4exchange.com/2012/11/cross-forest-freebusy-without-federation.html">Cross-Forest Free/Busy without Federation</a>&nbsp;and its corresponding <a href="http://www.tools4exchange.com/2012/12/freebusy-information-without-federation---troubleshooting-guide.html">troubleshooting guide</a>.</p>
<p>
	In this article I want to share some experiences&nbsp;with troubleshooting the Cross-Forest Delegation feature. Cross-Forest Delegation allows completly to manage a delegated calendar even if people are placed in different mail-organizations. But there must be a domain-trust in place.</p>
<p>
	To synchronize objects I prefer NETsec&#39;s GALsync, which is much easier to use than Microsofts FIM etc.</p>
]]>
        <![CDATA[<h3 style="color: blue">
	Topology<br />
	<a href="http://www.tools4exchange.com/assets_c/2013/03/cfd-923.html" onclick="window.open('http://www.tools4exchange.com/assets_c/2013/03/cfd-923.html','popup','width=696,height=617,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img alt="cfd.png" class="mt-image-none" height="472" src="http://www.tools4exchange.com/assets_c/2013/03/cfd-thumb-533x472-923.png" style="height: 296px; width: 352px" width="533" /></a><br />
	&nbsp;</h3>
<h3 style="color: blue">
	Summary</h3>
<p>
	Basically the following prerequisites must be met&hellip;</p>
<ul>
	<li>
		Network and Messaging availability</li>
	<li>
		Forest Trust between Forests</li>
	<li>
		Cross-Forest Availability Configured</li>
	<li>
		Outlook 2007 SP1+</li>
	<li>
		Exchange Server 2007 SP1+</li>
	<li>
		GALsync configured with option CROSS-FOREST-DELEGATION</li>
</ul>
<p>
	NOTE: WE STRONGLY RECOMMEND TO TROUBLESHOOT WITH OUTLOOK FIRST SET TO ONLINE-MODE.</p>
<h3 style="color: blue">
	Troubleshooting Level 1</h3>
<p>
	At this level you check the ability to set up a simple mail communication between two forests. The &bdquo;galsynced&ldquo; contacts of your partner are available in your Global Address Book.</p>
<h3 style="color: red">
	Network</h3>
<p>
	Ensure that you can communicate over the network by using DNS. Assumed you have a DNS Forwarder at FORESTA.COM side to FORESTX.COM and vice versa:<br />
	Can you nslookup / ping the Domain Controller and the Exchange Server at the other site?&nbsp;</p>
<h3 style="color: red">
	Simple Mail-Communication</h3>
<p>
	Assumed you have mailbox-enabled user JANE at FORESTA.COM and JOHN at FORESTX.COM:</p>
<ul>
	<li>
		Is JANE able to send an email to JOHN by inserting <a href="mailto:JOHN@FORESTX.COM">JOHN@FORESTX.COM</a> into her TO-Line of the message?&nbsp;</li>
	<li>
		Is JOHN able to send an email to JANE by inserting <a href="mailto:JANE@FORESTA.COM">JANE@FORESTA.COM</a> into his TO-Line of the message?&nbsp;</li>
</ul>
<h3 style="color: red">
	GALsync</h3>
<p>
	Synchronize all mailbox-enabled users with GALSYNC from your domain to the other domain. They are created as mail-enabled contacts. Export JANE from FORESTA TO FORESTX and import her at FORESTX: Export JOHN from FORESTX TO FORESTA and import him at FORESTA.<br />
	If you do not want to configure Cross-Forest Delegation you can use the default configurations setting of GALsync. A synchronized object should have these attribute values (check with Attribute-Editor):</p>
<table border="1" cellpadding="1" cellspacing="1" style="height: 188px; width: 417px">
	<tbody>
		<tr>
			<td>
				&nbsp;</td>
			<td>
				&nbsp;</td>
			<td>
				Source Mailbox Attributes</td>
			<td>
				Cross-forest mail contact attributes in the target forest</td>
		</tr>
		<tr>
			<td>
				1&nbsp;</td>
			<td>
				legacyExchangeDN</td>
			<td>
				Must be set&nbsp;</td>
			<td>
				Must be set&nbsp;</td>
		</tr>
		<tr>
			<td>
				2</td>
			<td>
				proxyAddresses</td>
			<td>
				The primary SMTP-Address from the source object will be the value of the attribute targetaddress in the targetdomain</td>
			<td>
				Not significant</td>
		</tr>
		<tr>
			<td>
				3</td>
			<td>
				targetAddress</td>
			<td>
				Not Set&nbsp;</td>
			<td>
				The primary SMTP-Address from the source object should be the value of attribute targetaddress</td>
		</tr>
	</tbody>
</table>
<ul>
	<li>
		Are the values of the attributes as expected?</li>
</ul>
<p>
	If you want to configure Cross-Forest Delegation you must tick a box in the appropriate export policy and appropriate import policy<br />
	<a href="http://www.tools4exchange.com/assets_c/2013/03/cfd2-926.html" onclick="window.open('http://www.tools4exchange.com/assets_c/2013/03/cfd2-926.html','popup','width=477,height=390,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img alt="cfd2.png" class="mt-image-none" height="435" src="http://www.tools4exchange.com/assets_c/2013/03/cfd2-thumb-533x435-926.png" style="height: 275px; width: 330px" width="533" /></a></p>
<ul>
	<li>
		Is there any warning or error by running the export policy?</li>
	<li>
		Is there any warning or error by running the import policy?</li>
</ul>
<p>
	The synchronized objects should have these attribute values (check with Attribute-Editor):<br />
	&nbsp;</p>
<table border="1" cellpadding="1" cellspacing="1" style="height: 763px; width: 411px">
	<tbody>
		<tr>
			<td>
				&nbsp;</td>
			<td>
				&nbsp;</td>
			<td>
				Source Mailbox Attributes</td>
			<td>
				Cross-forest mail contact attributes (target forest)<br />
				&nbsp;</td>
		</tr>
		<tr>
			<td>
				1</td>
			<td>
				legacyExchangeDN</td>
			<td>
				Not significant&nbsp;</td>
			<td>
				Must be set</td>
		</tr>
		<tr>
			<td>
				2</td>
			<td>
				mailNickname&nbsp;</td>
			<td>
				Not significant&nbsp;</td>
			<td>
				Must be set</td>
		</tr>
		<tr>
			<td>
				3</td>
			<td>
				objectSid</td>
			<td>
				&nbsp;(i.e)<br />
				S-1-5-21-3511955210-643191710-2064615621-5187&nbsp;</td>
			<td>
				Not significant</td>
		</tr>
		<tr>
			<td>
				4</td>
			<td>
				mAPIRecipient&nbsp;</td>
			<td>
				Not significant&nbsp;</td>
			<td>
				Not Set</td>
		</tr>
		<tr>
			<td>
				5</td>
			<td>
				msExchMasterAccountSid&nbsp;</td>
			<td>
				Not significant&nbsp;</td>
			<td>
				Must have the same value like the objectSid of the source object</td>
		</tr>
		<tr>
			<td>
				6</td>
			<td>
				msExchOriginatingForest</td>
			<td>
				Not significant&nbsp;</td>
			<td>
				Must have the same value like the Forest FQDN&nbsp; of the source object<br />
				&nbsp;</td>
		</tr>
		<tr>
			<td>
				7</td>
			<td>
				msExchRecipientDisplayType</td>
			<td>
				Not significant&nbsp;</td>
			<td>
				&nbsp;Must have the value<br />
				-1073741818</td>
		</tr>
		<tr>
			<td>
				8</td>
			<td>
				msExchRecipientTypeDetails&nbsp;</td>
			<td>
				Not significant&nbsp;</td>
			<td>
				Must have the value 32768</td>
		</tr>
		<tr>
			<td>
				9</td>
			<td>
				proxyAddresses&nbsp;</td>
			<td>
				&nbsp;The primary SMTP-Address from the source object will be the value of the attribute targetaddress in the targetdomain</td>
			<td>
				&nbsp;Not significant</td>
		</tr>
		<tr>
			<td>
				10</td>
			<td>
				targetAddress&nbsp;</td>
			<td>
				Not Set&nbsp;</td>
			<td>
				The primary SMTP-Address from the source object should be the value of attribute targetaddress</td>
		</tr>
	</tbody>
</table>
<ul>
	<li>
		Are the values of the attributes as expected?</li>
	<li>
		Is the RECIPIENT TYPE of JOHN in Exchange Management Console displayed as CROSS-FOREST MAIL CONTACT?</li>
</ul>
<h3 style="color: red">
	Mail-Communication supported by GALsync</h3>
<p>
	After objects are synchronized endusers can pick the names from the Global Address List.</p>
<ul>
	<li>
		Is JANE able to send an email to JOHN by picking the contact of JOHN from the GLOBAL ADDRESS BOOK?&nbsp;</li>
	<li>
		Is JOHN able to send an email to JANE by picking the contact of JANE from the GLOBAL ADDRESS BOOK?</li>
</ul>
<p>
	<a href="http://www.tools4exchange.com/assets_c/2013/03/cfd4-929.html" onclick="window.open('http://www.tools4exchange.com/assets_c/2013/03/cfd4-929.html','popup','width=869,height=137,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img alt="cfd4.png" class="mt-image-none" height="84" src="http://www.tools4exchange.com/assets_c/2013/03/cfd4-thumb-533x84-929.png" style="height: 56px; width: 440px" width="533" /></a></p>
<h3 style="color: blue">
	Troubleshooting Level 2</h3>
<p>
	At this level you check the ability to setup a cross-forest environment with a simple Free/Busy query between two untrusted forests using &bdquo;galsynced&ldquo; contacts of your partner. To configure this have a look at the note below.<br />
	NOTE: FOR SETTING UP AN TEST-LAB FOR CROSS-FOREST FREE/BUSY WITHOUT FEDERATION SEE <a href="http://WWW.TOOLS4EXCHANGE.COM/2012/11/CROSS-FOREST-FREEBUSY-WITHOUT-FEDERATION.HTML">HTTP://WWW.TOOLS4EXCHANGE.COM/2012/11/CROSS-FOREST-FREEBUSY-WITHOUT-FEDERATION.HTML</a><br />
	&nbsp;</p>
<h3 style="color: red">
	Trust</h3>
<p>
	To configure a Cross-Forest Delegation a trust is required. Check if the trusts are in place and if they are working.<br />
	&nbsp;<br />
	NOTE: TO CHECK TRUST FOLLOW THIS ARTICLE:&nbsp; HOW TO DETERMINE TRUST RELATIONSHIP CONFIGURATIONS AT <a href="http://SUPPORT.MICROSOFT.COM/KB/228477/EN-US">HTTP://SUPPORT.MICROSOFT.COM/KB/228477/EN-US</a> OR DOMAIN AND FOREST TRUST TOOLS AND SETTINGS AT <a href="http://TECHNET.MICROSOFT.COM/EN-US/LIBRARY/CC756944(V=WS.10).ASPX">HTTP://TECHNET.MICROSOFT.COM/EN-US/LIBRARY/CC756944(V=WS.10).ASPX</a></p>
<p>
	<a href="http://www.tools4exchange.com/assets_c/2013/03/cfd5-932.html" onclick="window.open('http://www.tools4exchange.com/assets_c/2013/03/cfd5-932.html','popup','width=628,height=596,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img alt="cfd5.png" class="mt-image-none" height="505" src="http://www.tools4exchange.com/assets_c/2013/03/cfd5-thumb-533x505-932.png" style="height: 388px; width: 412px" width="533" /></a></p>
<h3 style="color: red">
	Certificates</h3>
<ul>
	<li>
		In FORESTA.COM: are you able to log into OWA (by https) or Outlook (by Outlook Anywhere) as JANE without any certificate error indicated?&nbsp;</li>
	<li>
		In FORESTX.COM: are you able to log into OWA (by https) or Outlook (by Outlook Anywhere) as JOHN without any certificate error indicated?&nbsp;</li>
</ul>
<p>
	NOTE: IF YOU EXPERIENCE ANY ERROR, PLEASE LOOK AT TROUBLESHOOTING CERTIFICATE VALIDATION ERRORS AT <a href="http://TECHNET.MICROSOFT.COM/EN-US/LIBRARY/BB331963(V=EXCHG.141).ASPX">HTTP://TECHNET.MICROSOFT.COM/EN-US/LIBRARY/BB331963(V=EXCHG.141).ASPX</a><br />
	&nbsp;</p>
<h3 style="color: red">
	Autodiscover</h3>
<p>
	Cross-forest free/busy queries and cross-forest delegation requires a working autodiscover.</p>
<ol>
	<li>
		If&nbsp; FORESTA and FORESTX are internetfacing use MICROSOFT REMOTE CONNECTIVITY ANALYZER at <a href="https://www.testexchangeconnectivity.com/">https://www.testexchangeconnectivity.com/</a>.</li>
	<li>
		If&nbsp; FORESTA and FORESTX are intranet-based then use MICROSOFT CONNECTIVITY ANALYZER TOOL at <a href="http://technet.microsoft.com/library/feba32b0-b7eb-4b1b-ba3d-99e20ba82a8c">http://technet.microsoft.com/library/feba32b0-b7eb-4b1b-ba3d-99e20ba82a8c</a></li>
</ol>
<p>
	If you experience issues with autodiscover, reset the virtual directory for autodiscover in Exchange Management Console. This was often the solution for me!</p>
<h3 style="color: red">
	Availability Adressspace</h3>
<p>
	We assume that you have configured Availability Adressspace similar as shown below</p>
<ul>
	<li>
		Add-AvailabilityAddressSpace -ForestName &quot;TargetSMTPnamespace.com&quot; -AccessMethod PerUserFB -UseServiceAccount $true</li>
	<li>
		Get-ClientAccessServer | Add-AdPermission -AccessRights ExtendedRight -ExtendedRights &quot;ms-exch-epi-token-serialization&quot; -User &quot;Remote Forest\Exchange Servers&quot;</li>
	<li>
		$a = Get-Credential &lt;Enter Administrator credentials in the remote forest when prompted&gt;<br />
		Export-AutoDiscoverConfig -DomainController &lt;Local GC&gt; -TargetForestDomainController &lt;Target GC&gt; -TargetForestCredential $a -MultipleExchangeDeployments $true</li>
</ul>
<p>
	Check GET-AVAILABILITYADDRESSSPACE and GET-AVAILABILITYCONFIG and GET-AUTODISCOVERCONFIG.<br />
	NOTE: SEE ALSO FREE/BUSY INFORMATION WITHOUT FEDERATION - TROUBLESHOOTING GUIDE AT <a href="http://WWW.TOOLS4EXCHANGE.COM/2012/12/FREEBUSY-INFORMATION-WITHOUT-FEDERATION---TROUBLESHOOTING-GUIDE.HTML">HTTP://WWW.TOOLS4EXCHANGE.COM/2012/12/FREEBUSY-INFORMATION-WITHOUT-FEDERATION---TROUBLESHOOTING-GUIDE.HTML</a></p>
<h3 style="color: red">
	A simple cross-forest Free/Busy Query</h3>
<ul>
	<li>
		Is JANE able to create an new meeting request by inviting JOHN (by picking the contact of JOHN from the GLOBAL ADDRESS BOOK) and have a lookup to his F/B information?&nbsp;</li>
</ul>
<p>
	The best place to collect logging data is in the Outlook client. Enable this in Outlook&rsquo;s OPTIONS (either via the Tools menu in Outlook 2007 or backstage in Outlook 2010) -&gt; ADVANCED. Tick the ENABLE TROUBLESHOOTING LOGGING box and restart Outlook. Logfiles are stored in %TEMP%\... (note: this folder is by default not visible)<br />
	&nbsp;</p>
<p>
	<a href="http://www.tools4exchange.com/assets_c/2013/03/cfd6-935.html" onclick="window.open('http://www.tools4exchange.com/assets_c/2013/03/cfd6-935.html','popup','width=478,height=143,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img alt="cfd6.png" class="mt-image-none" height="159" src="http://www.tools4exchange.com/assets_c/2013/03/cfd6-thumb-533x159-935.png" style="height: 102px; width: 418px" width="533" /></a></p>
<p>
	<a href="http://www.tools4exchange.com/assets_c/2013/03/cfd7-938.html" onclick="window.open('http://www.tools4exchange.com/assets_c/2013/03/cfd7-938.html','popup','width=794,height=298,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img alt="cfd7.png" class="mt-image-none" height="200" src="http://www.tools4exchange.com/assets_c/2013/03/cfd7-thumb-533x200-938.png" style="height: 111px; width: 422px" width="533" /></a></p>
<h3 style="color: blue">
	Troubleshooting Level 3</h3>
<p>
	At this level you check the ability to setup a cross-forest delegation. This enables you to configure a so called delegate access. So JOHN from FORESTX&nbsp; grants JANE from FORESTA access to his calendar.</p>
<h3 style="color: red">
	Delegation</h3>
<ul>
	<li>
		Is JOHN able to delegate access to JANE?</li>
</ul>
<p>
	&nbsp;<a href="http://www.tools4exchange.com/assets_c/2013/03/cfd8-941.html" onclick="window.open('http://www.tools4exchange.com/assets_c/2013/03/cfd8-941.html','popup','width=1079,height=571,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img alt="cfd8.png" class="mt-image-none" height="282" src="http://www.tools4exchange.com/assets_c/2013/03/cfd8-thumb-533x282-941.png" style="height: 186px; width: 403px" width="533" /></a></p>
<ul>
	<li>
		Is JANE able to open the delegated calendar of JOHN BY PICKING JOHN FROM GAL?</li>
</ul>
<p>
	&nbsp;<a href="http://www.tools4exchange.com/assets_c/2013/03/cfd9-944.html" onclick="window.open('http://www.tools4exchange.com/assets_c/2013/03/cfd9-944.html','popup','width=309,height=97,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img alt="cfd9.png" class="mt-image-none" height="167" src="http://www.tools4exchange.com/assets_c/2013/03/cfd9-thumb-533x167-944.png" style="height: 110px; width: 361px" width="533" /></a></p>
<ul>
	<li>
		Is JANE able to insert a new appointment directly to JOHNS calendar?</li>
</ul>
<p>
	&nbsp;<a href="http://www.tools4exchange.com/assets_c/2013/03/cfd10-947.html" onclick="window.open('http://www.tools4exchange.com/assets_c/2013/03/cfd10-947.html','popup','width=686,height=590,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img alt="cfd10.png" class="mt-image-none" height="458" src="http://www.tools4exchange.com/assets_c/2013/03/cfd10-thumb-533x458-947.png" style="height: 340px; width: 402px" width="533" /></a></p>
<p>
	&nbsp;</p>
]]>
    </content>
</entry>

<entry>
    <title>Federated GAL sharing between Office 365 and Exchange On-Premise</title>
    <link rel="alternate" type="text/html" href="http://www.tools4exchange.com/2013/03/a-cross-forest-directory-sync-between-office-365-tenant-and-exchange-on-premise.html" />
    <id>tag:www.tools4exchange.com,2013://13.1767</id>

    <published>2013-03-01T15:32:25Z</published>
    <updated>2013-03-03T17:35:39Z</updated>

    <summary><![CDATA[ With GALsysnc v5 we introduce a software for synchronizing Global Address List between independent Office 365 and Exchange On-Premise organizations.&nbsp; Some people call it Federated GAL sharing. The only thing you need, is GALsync. In this article I provide...]]></summary>
    <author>
        <name>Hans Willi Kremer</name>
        <uri>http://www.NETsec.de</uri>
    </author>
    
        <category term="Exchange 2007" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Exchange 2010" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Exchange 2013" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Free/Busy" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Mailscape" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="dirsync" label="DIRSync" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="federatedgalsharing" label="Federated GAL sharing" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="galsync" label="GALsync" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="office365andexchangeonpremise" label="Office365 and Exchange On-Premise" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://www.tools4exchange.com/">
        <![CDATA[<p>
	With GALsysnc v5 we introduce a software for synchronizing Global Address List between independent Office 365 and Exchange On-Premise organizations.&nbsp; Some people call it Federated GAL sharing.</p>
<p>
	The only thing you need, is GALsync. In this article I provide you with a Quickstep installation (i.e. for testing environment).</p>
]]>
        <![CDATA[<h3 style="color: blue">
	Topology</h3>
<p>
	&nbsp;<a href="http://www.tools4exchange.com/assets_c/2013/03/fs1-950.html" onclick="window.open('http://www.tools4exchange.com/assets_c/2013/03/fs1-950.html','popup','width=532,height=503,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img alt="fs1.PNG" class="mt-image-none" src="http://www.tools4exchange.com/assets_c/2013/03/fs1-thumb-533x503-950.png" style="border-top: 0px solid; height: 308px; border-right: 0px solid; border-bottom: 0px solid; border-left: 0px solid; width: 370px" /></a></p>
<p>
	With GALsync v5 you can share your GAL between Exchange 2007, Exchange 2010, Exchange 2013 and Exchange Online organizations.</p>
<p>
	Here you test the basic steps for a successful first unidirectional synchronization. In this example the source and/or the target may be On-Premise or Exchange Online (only).</p>
<p>
	<a href="http://www.tools4exchange.com/assets_c/2013/03/eo1-972.html" onclick="window.open('http://www.tools4exchange.com/assets_c/2013/03/eo1-972.html','popup','width=850,height=372,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img alt="eo1.PNG" class="mt-image-none" height="233" src="http://www.tools4exchange.com/assets_c/2013/03/eo1-thumb-533x233-972.png" style="height: 219px; width: 437px" width="533" /></a></p>
<h3 style="color: blue">
	Prerequisites</h3>
<ol>
	<li>
		Your environment must be based on Exchange 2007 SP1 and higher or Exchange Online (only).</li>
	<li>
		The computer you want to install GALsync on</li>
</ol>
<ul style="margin-left: 40px">
	<li>
		Must be a member of the domain if your side is On-Premise. It should have a good bandwidth to the next DC/GC and an Exchange Server with CAS role.</li>
	<li>
		May be a standalone machine if your side is Exchange-Online.</li>
	<li>
		Should have a dual-core processor and 2GB RAM.</li>
	<li>
		Can be a client OS, i.e. Windows 7 Professional (64-Bit), for testing or a server OS, i.e. Windows 2008 R2 SP1 (64-Bit).</li>
	<li>
		Must be configured with .NET Framework 3.5. Even if .NET Framework 4 is installed you have to add .NET Framework 3 .5 (SERVER MANAGER -&gt; ADD ROLES AND FEATURES -&gt; FEATURES -&gt; .NET FRAMEWORK 3.5 (includes .NET 2.0 and 3.0)</li>
	<li>
		Must be configured with PowerShell 2.0 Engine note. Even if PowerShell 3.0 is installed you have to add PowerShell 2.0 Engine (SERVER MANAGER -&gt; ADD ROLES AND FEATURES -&gt; FEATURES -&gt; WINDOWS POWERSHELL&nbsp; -&gt; POWERSHELL&nbsp; 2.0 ENGINE)</li>
</ul>
<ol start="3">
	<li>
		Create a mailbox in source and in target forest. Ensure that messages can be send between these mailboxes.</li>
</ol>
<ul style="margin-left: 40px">
	<li>
		On-Premise: Provide the user of the mailbox with administrative permissions on the machine you want to install GALsync on. Provide the user of the mailbox in the target forest with administrative permissions on the machine you want to install GALsync on.</li>
	<li>
		Exchange-Online: The user of the mailbox must be member of the EXCHANGE ORGANIZATION MANAGEMENT role.</li>
	<li>
		Ensure that the mailbox is accessible (i.e. by Outlook Web Access), that the mailbox can send to and receive mails from the other organization and that incoming mails from the other organization do not get caught by your spam filter or firewall.</li>
</ul>
<ol start="4">
	<li>
		If your target side is On-Premise then create an Organizational Unit where you want to import the source objects. The GALsync Service Account needs write permissions in the Active Directory for the import OU. To grant this see chapter PERMISSIONS in section ACTIVE DIRECTORY PERMISSION FOR THE IMPORT OU.</li>
	<li>
		If your side is On-Premise, make sure that you can logon with the configured SA. Also it is required that the setup of GALsync can grant this account with local security permissions to LOG ON AS SERVICE. Also you may add the SA account to the local group REMOTE DESKTOP USERS.</li>
	<li>
		For testing purposes create some mailboxes and a group. Add the mailboxes as member to the group.</li>
</ol>
<h3 style="color: blue">
	Install the software in the source forest</h3>
<ol>
	<li>
		Login with the user you created before. Run setup.</li>
	<li>
		Run GALsync the first time and configure a Service Account (SA) by taking the same account as you are logged in (On-Premise).<br />
		<br />
		<a href="http://www.tools4exchange.com/assets_c/2013/03/ns_config23-956.html" onclick="window.open('http://www.tools4exchange.com/assets_c/2013/03/ns_config23-956.html','popup','width=598,height=466,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img alt="ns_config23.PNG" class="mt-image-none" height="415" src="http://www.tools4exchange.com/assets_c/2013/03/ns_config23-thumb-533x415-956.png" style="height: 232px; width: 344px" width="533" /></a></li>
</ol>
<p style="margin-left: 40px">
	If the setup detects that GALsync was installed on a standalone machine, the SA will be added automatically as LOCALSYSTEM.</p>
<p style="margin-left: 40px">
	<a href="http://www.tools4exchange.com/assets_c/2013/03/eo2-975.html" onclick="window.open('http://www.tools4exchange.com/assets_c/2013/03/eo2-975.html','popup','width=467,height=247,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img alt="eo2.PNG" class="mt-image-none" height="281" src="http://www.tools4exchange.com/assets_c/2013/03/eo2-thumb-533x281-975.png" style="height: 151px; width: 347px" width="533" /></a><br />
	&nbsp;</p>
<ol start="3">
	<li>
		Running GALsync you can check the SA configuration and your log-in account at bottom left corner.</li>
	<li>
		In menu HELP select ABOUT and add your license. See also chapter LICENSING.</li>
	<li>
		On-Premise only: In menu OPTIONS select EXCHANGE. Configure the access to your Exchange Server. Click MANUAL SETTING and the SEARCH icon. Now GALsync tries to use autodiscover and displays the URI it discovers. If you get an error message please insert the correct URI for your environment.<br />
		<br />
		<a href="http://www.tools4exchange.com/assets_c/2013/03/ns_config12-959.html" onclick="window.open('http://www.tools4exchange.com/assets_c/2013/03/ns_config12-959.html','popup','width=782,height=484,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img alt="ns_config12.PNG" class="mt-image-none" height="329" src="http://www.tools4exchange.com/assets_c/2013/03/ns_config12-thumb-533x329-959.png" style="height: 200px; width: 383px" width="533" /></a><br />
		<br />
		&nbsp;</li>
	<li>
		Leave the other options unclicked.</li>
	<li>
		Confirm the first configuration by pressing the SAVE button.</li>
</ol>
<h3 style="color: blue">
	Create and run an export policy</h3>
<p>
	Create a first Export policy lead by the wizard</p>
<ol>
	<li>
		Choose to EXPORT DIRECTORY INFORMATION if you are On-Premise or choose EXPORT EXCHANGE ONLINE if you use Office 365. Click NEXT.<br />
		<br />
		<a href="http://www.tools4exchange.com/assets_c/2013/03/eo3-978.html" onclick="window.open('http://www.tools4exchange.com/assets_c/2013/03/eo3-978.html','popup','width=642,height=309,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img alt="eo3.PNG" class="mt-image-none" height="256" src="http://www.tools4exchange.com/assets_c/2013/03/eo3-thumb-533x256-978.png" style="height: 195px; width: 380px" width="533" /></a><br />
		&nbsp;</li>
	<li>
		If you are Exchange Online then insert the user-ID and password of an appropriate account in the cloud. Click NEXT. GALsync tries to connect to Exchange Online. This may take a certain time.<br />
		<br />
		<a href="http://www.tools4exchange.com/assets_c/2013/03/eo4-981.html" onclick="window.open('http://www.tools4exchange.com/assets_c/2013/03/eo4-981.html','popup','width=669,height=262,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img alt="eo4.PNG" class="mt-image-none" height="208" src="http://www.tools4exchange.com/assets_c/2013/03/eo4-thumb-533x208-981.png" style="height: 147px; width: 387px" width="533" /></a></li>
</ol>
<p style="margin-left: 40px">
	<a href="http://www.tools4exchange.com/assets_c/2013/03/eo5-984.html" onclick="window.open('http://www.tools4exchange.com/assets_c/2013/03/eo5-984.html','popup','width=335,height=175,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img alt="eo5.PNG" class="mt-image-none" height="278" src="http://www.tools4exchange.com/assets_c/2013/03/eo5-thumb-533x278-984.png" style="height: 126px; width: 204px" width="533" /></a><br />
	&nbsp;</p>
<ol start="4">
	<li>
		Choose VIA EMAIL as data transfer mode. Insert the SMTP address of the mailbox in the target forest which will receive the data. Click NEXT.<br />
		<br />
		<a href="http://www.tools4exchange.com/assets_c/2013/03/eo6-987.html" onclick="window.open('http://www.tools4exchange.com/assets_c/2013/03/eo6-987.html','popup','width=473,height=305,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img alt="eo6.PNG" class="mt-image-none" height="343" src="http://www.tools4exchange.com/assets_c/2013/03/eo6-thumb-533x343-987.png" style="height: 169px; width: 292px" width="533" /></a><br />
		<br />
		<a href="http://www.tools4exchange.com/assets_c/2013/03/eo7-990.html" onclick="window.open('http://www.tools4exchange.com/assets_c/2013/03/eo7-990.html','popup','width=666,height=287,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img alt="eo7.PNG" class="mt-image-none" height="229" src="http://www.tools4exchange.com/assets_c/2013/03/eo7-thumb-533x229-990.png" style="height: 125px; width: 295px" width="533" /></a><br />
		<br />
		&nbsp;</li>
	<li>
		Exchange On-Premise: As directory information SEARCH for the group which you created for test purposes with some test-mailboxes and groups as member. APPLY and click NEXT. Choose GROUP + MEMBERSHIP. Choose INCLUDE NESTED GROUPS. Choose SETTINGS FOR ALL GROUPS. Click OK. Click NEXT.<br />
		<br />
		<a href="http://www.tools4exchange.com/assets_c/2013/03/ns_config15-969.html" onclick="window.open('http://www.tools4exchange.com/assets_c/2013/03/ns_config15-969.html','popup','width=520,height=460,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img alt="ns_config15.PNG" class="mt-image-none" height="471" src="http://www.tools4exchange.com/assets_c/2013/03/ns_config15-thumb-533x471-969.png" style="height: 269px; width: 383px" width="533" /></a><br />
		&nbsp;</li>
	<li>
		Exchange On-Premise: As&nbsp;<br />
		As directory information SEARCH for the group which you created for test purposes with some test-mailboxes and groups as member. APPLY and click NEXT. Choose GROUP + MEMBERSHIP. Choose INCLUDE NESTED GROUPS. Choose SETTINGS FOR ALL GROUPS. Click OK. Click NEXT.<br />
		<br />
		<a href="http://www.tools4exchange.com/assets_c/2013/03/eo8-993.html" onclick="window.open('http://www.tools4exchange.com/assets_c/2013/03/eo8-993.html','popup','width=447,height=215,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img alt="eo8.PNG" class="mt-image-none" height="256" src="http://www.tools4exchange.com/assets_c/2013/03/eo8-thumb-533x256-993.png" style="height: 202px; width: 382px" width="533" /></a><br />
		&nbsp;</li>
	<li>
		Leave STATUS NOTIFICATION EMAILS unclicked and click NEXT.</li>
	<li>
		Leave SCHEDULE SERVICE unclicked and click NEXT.</li>
	<li>
		In the GENERAL SECTION insert a name for the policy and click NEXT.</li>
	<li>
		After in SUMMARY SECTION all your configuration is validated click FINISH.</li>
	<li>
		Execute the policy by clicking RUN while mouse focus is set to the policy name in the hierarchy tree on the left hand side. The OPERATION STATUS displays the progress. After execution click CLOSE.</li>
</ol>
<h3 style="color: blue">
	GALsync sends the result to the target forest</h3>
<p>
	This procedure is done by the GALsync software. It sends the data of your source forest through the configured mailbox (i.e. service account if On-Premise). The message is routed with the attached data to the recipient mailbox in the target forest.</p>
<h3 style="color: blue">
	Install the software in the target forest</h3>
<ol>
	<li>
		<span style="color: #000000">Login with the user you created before. Run setup.</span></li>
	<li>
		<span style="color: #000000">Run GALsync the first time and configure a Service Account (SA) by taking the same account as you are logged in (On-Premise).</span></li>
	<li>
		<span style="color: #000000">If the setup detects that GALsync was installed on a standalone machine, the SA will be added automatically as LOCALSYSTEM.</span><br />
		<span style="color: #000000">Running GALsync you can check the SA configuration and your log-in account at bottom left corner.</span></li>
	<li>
		In menu HELP select ABOUT and add your license. See also chapter LICENSING.</li>
	<li>
		On-Premise only: In menu OPTIONS select EXCHANGE.</li>
	<li>
		Configure the access to your Exchange Server. Click &ldquo;Manual setting&rdquo; and the SEARCH icon. Now GALsync tries to use autodiscover and displays the URI it discovers. If you get an error message please insert the correct URI for your environment.</li>
	<li>
		Leave the other option unclicked.</li>
	<li>
		Confirm the first configuration by pressing the SAVE button.</li>
</ol>
<h3 style="color: blue">
	GALsync receives the result from the source forest</h3>
<p>
	This procedure is done by the GALsync software. It receives the data of the source forest through the configured mailbox (i.e. service account if On-Premise).</p>
<h3 style="color: blue">
	Create and run an import policy</h3>
<p>
	Create a first Import policy lead by the wizard.</p>
<ol>
	<li>
		Choose to IMPORT DIRECTORY INFORMATION if you are On-Premise or IMPORT EXCHANGE ONLINE if you use Exchange Online. Click NEXT.</li>
	<li>
		If you are Exchange Online then insert the user-ID and password of an appropriate account in the cloud. Click NEXT. GALsync tries to connect to Exchange Online. This may take a certain time.</li>
	<li>
		Choose VIA EMAIL as data transfer mode. Leave the FILTER: SUBJECT blank. Click NEXT.</li>
	<li>
		If you are Exchange Online skip the Directory step with NEXT. If you are On-Premise choose (step DIRECTORY INFORMATION) the Organizational Unit where to store the new objects. Click NEXT.</li>
	<li>
		If you are On-Premise choose (step DIRECTORY INFORMATION) the Organizational Unit where to store the new objects. Click NEXT.<br />
		Note: The SA must have suffient permissions to create and modify objects in this OU.</li>
	<li>
		Leave STATUS NOTIFICATION emails unclicked and click NEXT.</li>
	<li>
		Leave SCHEDULE SERVICE unclicked and click NEXT.</li>
	<li>
		In the GENERAL SECTION insert a name for the policy and click NEXT.</li>
	<li>
		After in SUMMARY section all your configuration is validated click FINISH.</li>
	<li>
		Execute the policy by clicking RUN while mouse focus is set to the policy name in the hierarchy tree lefthander.</li>
	<li>
		The OPERATION STATUS displays the progress. After execution click CLOSE.</li>
</ol>
<p style="margin-left: 40px">
	Now you should see the synchronized group and the group member as contacts in the GAL of the target forest. Please note that Exchange On-Premise sometimes requires a certain time to update the address lists.</p>
<div>
	<hr />
</div>
<div id="cke_pastebin">
	<span style="font-size: 11pt; font-family: 'Calibri','sans-serif'; color: #002060; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA">We had a great time developing our products and we hope you have an equally great time working with them. If you experience any problems we are more than happy to support you.&nbsp;<font color="#222222" face="Arial" size="2">&nbsp;</font><a href="mailto:support@netsec.de"><font face="Arial" size="2">support@netsec.de</font></a></span></div>
]]>
    </content>
</entry>

<entry>
    <title>Free/Busy between two Exchange Online / Office365 Organizations</title>
    <link rel="alternate" type="text/html" href="http://www.tools4exchange.com/2013/02/freebusy-between-two-exchange-onlineoffice365-organizations.html" />
    <id>tag:www.tools4exchange.com,2013://13.1761</id>

    <published>2013-02-05T11:50:00Z</published>
    <updated>2013-02-05T11:54:44Z</updated>

    <summary> In this blog I will describe how you can provide Free/Busy information between different Exchange Online / Office 365 organizations. Usually people are able to send requests to share calendar individually, but we want to implement an enterprise-wide configuration....</summary>
    <author>
        <name>Hans Willi Kremer</name>
        <uri>http://www.NETsec.de</uri>
    </author>
    
        <category term="Exchange 2013" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Free/Busy" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="GALsync" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="crossforestfreebusy" label="cross-forest Free/Busy" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="exchangefederation" label="Exchange Federation" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="exchangeonline" label="Exchange Online" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="freebusyaccesslevel" label="FreeBusyAccessLevel" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="galsync" label="GALsync" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="getfederationinformation" label="Get-FederationInformation" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="office365" label="Office365" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://www.tools4exchange.com/">
        <![CDATA[<p>
	In this blog I will describe how you can provide Free/Busy information between different Exchange Online / Office 365 organizations.<br />
	Usually people are able to send requests to share calendar individually, but we want to implement an enterprise-wide configuration.<br />
	If you want that all the mailobjects of your partners organization are present in your own Global Address List (GAL) then you can use a tool like NETsec&#39;s GALsync.</p>
<p>
	Between 2 Exchange Online Partners you do not need to establish a Federation Trust or configure autodiscover records because this is already present (by default).<span style="display: none;">&nbsp;</span><br />
	&nbsp;</p>
]]>
        <![CDATA[<p>
	In this example we have two Exchange Online organizations named A and B.</p>
<p>
	Regarding organization a.onmicrosoft.com execute in Windows Powershell the set of commands described below using the credential of an admin in a (i.e. <a href="mailto:admin@a.onmicrosoft.com">admin@a.onmicrosoft.com</a>)</p>
<p>
	Set-ExecutionPolicy RemoteSigned</p>
<p>
	$LiveCred = Get-Credential</p>
<p>
	$Session = New-PSSession -ConfigurationName Microsoft.Exchange -ConnectionUri <a href="https://ps.outlook.com/powershell/">https://ps.outlook.com/powershell/</a> -Credential $LiveCred -Authentication Basic &ndash;AllowRedirection</p>
<p>
	Import-PSSession $Session</p>
<p>
	Enable-OrganizationCustomization (has an error as result in mz experiences but it does not impact the total result)</p>
<p>
	Get-FederationInformation &ndash;DomainName b.onmicrosoft.com | New-OrganizationRelationship &ndash;Name b -FreeBusyAccessEnabled $true -FreeBusyAccessLevel LimitedDetails</p>
<p>
	After that users from organization B can take users from A throug picking the object from GAL (done by GALsync) and send a meeting invitation with a prior free/busy lookup.</p>
<p>
	Regarding organization b.onmicrosoft.com execute in Windows Powershell the set of commands described below using the credential of an admin in a (i.e. <a href="mailto:admin@a.onmicrosoft.com">admin@b.onmicrosoft.com</a>)</p>
<p>
	<br />
	Set-ExecutionPolicy RemoteSigned<br />
	$LiveCred = Get-Credential<br />
	$Session = New-PSSession -ConfigurationName Microsoft.Exchange -ConnectionUri <a href="https://ps.outlook.com/powershell/">https://ps.outlook.com/powershell/</a> -Credential $LiveCred -Authentication Basic &ndash;AllowRedirection<br />
	Import-PSSession $Session<br />
	Enable-OrganizationCustomization (has an error as result in mz experiences but it does not impact the total result)<br />
	Get-FederationInformation &ndash;DomainName a.onmicrosoft.com | New-OrganizationRelationship &ndash;Name a -FreeBusyAccessEnabled $true -FreeBusyAccessLevel LimitedDetails</p>
<p>
	After that users from organization A can take users from B throug picking the object from GAL (done by GALsync) and send a meeting invitation with a prior free/busy lookup.</p>
<p>
	<br />
	Links:</p>
<p>
	<a href="http://maso.dk/2011/07/26/federation-in-the-cloud-enable-freebusy/">http://maso.dk/2011/07/26/federation-in-the-cloud-enable-freebusy/</a></p>
<p>
	<a href="http://help.outlook.com/en-us/140/ff383252.aspx">http://help.outlook.com/en-us/140/ff383252.aspx</a></p>
]]>
    </content>
</entry>

<entry>
    <title>Free/Busy information without Federation - Troubleshooting Guide</title>
    <link rel="alternate" type="text/html" href="http://www.tools4exchange.com/2012/12/freebusy-information-without-federation---troubleshooting-guide.html" />
    <id>tag:www.tools4exchange.com,2012://13.1754</id>

    <published>2012-12-26T10:50:42Z</published>
    <updated>2012-12-26T17:00:10Z</updated>

    <summary><![CDATA[ In a previous article I described how to share free/busy information in an untrusted cross-forest environment. The procedures are published not very often and you sometimes get some &quot;nice errors&quot;.&nbsp;&nbsp;I use the follwoing steps to troubleshoot these issues....]]></summary>
    <author>
        <name>Hans Willi Kremer</name>
        <uri>http://www.NETsec.de</uri>
    </author>
    
    
    <content type="html" xml:lang="en" xml:base="http://www.tools4exchange.com/">
        <![CDATA[<p>
	In a <a href="http://www.tools4exchange.com/2012/11/cross-forest-freebusy-without-federation.html" target="_blank">previous article </a>I described how to share free/busy information in an untrusted cross-forest environment. The procedures are published not very often and you sometimes get some &quot;nice errors&quot;.&nbsp;&nbsp;I use the follwoing steps to troubleshoot these issues.</p>
]]>
        <![CDATA[<div class="asset-body">
	<p>
		<strong>Checklist</strong></p>
</div>
<p class="asset-more">
	<strong>1.&nbsp;Basic Tests</strong></p>
<div class="asset-more">
	<ul>
		<li>
			Does dcdiag on your&nbsp; DCs or does exbpa on your&nbsp;Exchange server indicate any errors, which could be related to your issue?</li>
		<li>
			Are the clients in both forests able to get free/busy information of other clients in the same domain?</li>
	</ul>
</div>
<p>
	<strong>2.&nbsp;Connectors</strong></p>
<ul>
	<li>
		Are clients able to send/receive mails (between the 2 forests) by sending mail using the SMTP address of the recipient</li>
	<li>
		Are clients able to send/receive/accept/decline meeting invitations (between the 2 forests) by sending mail using the SMTP address of the recipient</li>
</ul>
<p>
	<strong>3.&nbsp;GALsync</strong></p>
<ul>
	<li>
		Are the mailboxes from source created as contacts in the target by using GALsync?</li>
	<li>
		Are clients able to send/receive mails (between the 2 forests) by sending mail using the&nbsp;GAL&nbsp;to address the recipient</li>
	<li>
		Are clients able to send/receive/accept/decline meeting invitations (between the 2 forests) by sending mail using the&nbsp;GAL&nbsp;to address the recipient</li>
</ul>
<p>
	<strong>4.&nbsp;Proxy Account</strong></p>
<ul>
	<li>
		Are the proxy accounts on both sides present? (if you want only a uni-directional f/b query the proxy account must be present in the target domain which will be queried).</li>
</ul>
<p>
	<strong>5. Certificates</strong></p>
<ul>
	<li>
		Is the certificate of the source domains CAS servers &nbsp;present in the target domains CAS servers certificate store?</li>
	<li>
		Is the certificate of the target domains CAS servers &nbsp;present in the source domains CAS servers certificate store?</li>
	<li>
		Is the certificate of the CAS server assigned to IIS?</li>
	<li>
		Are the correct alternate names configured in the certificates?</li>
</ul>
<p>
	<strong>6. Virtual Directories</strong></p>
<ul>
	<li>
		Are you able to connect to the target mailbox by using&nbsp;OWA Client (i.e. without getting certificate errors)?</li>
	<li>
		Are the&nbsp;internal and external URLs for autodiscover configured?<br />
		Get-autodiscoverVirtualDirectory| fl name,server,InternalURL,ExternalURL<br />
		Get-AutodiscoverVirtualDirectory | Set-AutodiscoverVirtualDirectory &ndash;InternalURL <a href="https://adc.foresta.com/autodiscover/autodiscover.xml">https://adc.foresta.com/autodiscover/autodiscover.xml</a> &ndash;ExternalURL <a href="https://adc.foresta.com/autodiscover/autodiscover.xml">https://adc.foresta.com/autodiscover/autodiscover.xml</a><br />
		Please wait&nbsp;15 MS-Minutes after configuring the value</li>
	<li>
		connection test</li>
	<li>
		<ul>
			<li>
				Exchange 2010: test-outlookwebservice -targetaddress <a href="mailto:user@anderedomain.tld">user@forestB.com</a> | fl</li>
			<li>
				Exchange 2013: $cred=get-credentials<br />
				test-outlookwebservice -id:juser@<u><font color="#0066cc">forestC.com</font></u> -mailboxcredential $cred| fl</li>
			<li>
				Get-WebServicesVirtualDirectory | fl name,server,InternalURL,ExternalURL</li>
			<li>
				Get-WebServicesVirtualDirectory | Set-WebServicesVirtualDirectory &ndash;ExternalURL <a href="https://adc.foresta.com/EWS/Exchange.asmx">https://mobile.forestC.com/EWS/Exchange.asmx</a></li>
		</ul>
	</li>
	<li>
		Are the CAS Servers ot the source able to perform&nbsp;nslookup/ping to autodiscover.targetdomain.xx?</li>
	<li>
		Can you query the&nbsp;autodiscover URL with Internet Explorer and check if you get an certificate issue?<br />
		If you get an&nbsp;authentication request then insert a valid user name and password. Getting error 600 then this is the expected result and means: everything ok.</li>
</ul>
<p>
	<strong>7. Availability Address Space</strong></p>
<ul>
	<li>
		Did you configure the&nbsp;AddressSpace&nbsp;in the source domain&nbsp;correctly?<br />
		Get-AvailabilityAddressSpace<br />
		Add-AvailabilityAddressSpace &ndash;Forestname &quot;ForestB.com&quot; -AccessMethod OrgWideFB &ndash;Credential (get-Credential)<br />
		please use the credentiasl of the proxyaccount, which was configured in the target forest</li>
	<li>
		Did you configure&nbsp;&ndash;OrgWideAccount &lt;proxyaccount&gt; in the target forest?<br />
		Get-AvailabilityConfig<br />
		Set-AvailabilityConfig &ndash;OrgWideAccount freebusy</li>
</ul>
<p>
	TROUBLESHOOTING</p>
<ul>
	<li>
		Increase the eventlog level:<br />
		Get-EventLogLevel | Set-EventLogLevel -Level expert<br />
		<br />
		If you do not want to get a lot of results you should reduce the services to the following:<br />
		Set-EventLogLevel&nbsp; &quot;MSExchange Autodiscover\Core&quot; -Level expert<br />
		Set-EventLogLevel&nbsp; &quot;MSExchange Autodiscover\Web&quot; -Level expert<br />
		Set-EventLogLevel&nbsp; &quot;MSExchange Autodiscover\Provider&quot; -Level expert<br />
		Set-EventLogLevel&nbsp; &quot;MSExchange Availability\Availability Service&quot; -Level expert<br />
		Set-EventLogLevel&nbsp; &quot;MSExchange Availability\Availability Service General&quot; -Level expert<br />
		Set-EventLogLevel&nbsp; &quot;MSExchange Availability\Availability Service Authentication&quot; -Level expert<br />
		Set-EventLogLevel&nbsp; &quot;MSExchange Availability\Availability Service Authorization&quot; -Level expert</li>
	<li>
		Open Outlook in protocol mode<br />
		<a href="http://support.microsoft.com/kb/300479?wa=wsignin1.0">http://support.microsoft.com/kb/300479?wa=wsignin1.0</a></li>
	<li>
		Note: Outlook 2013 seems not to use the&nbsp;fblog*.log as in earlier versions like in Outlook 2010, so troubleshooting with OLK13 is much more difficult. Use 2010!</li>
	<li>
		Run your Outlook clients&nbsp; in online mode, not in cached mode to keep your testing results &quot;clean&quot;.</li>
	<li>
		Re-assign the password of the proxy account.</li>
	<li>
		Run Get-AvailabilityAddressSpace | remove-AvailabilityAddressSpace in the source forest and re-create the addresspace. Please&nbsp; keep an eye on the correct password.</li>
	<li>
		Re-create the virtual services for EWS and&nbsp;autodiscover. You can perform this in the EMC (Exchange 2007/2010)&nbsp;&ndash;&nbsp; please wait&nbsp;&nbsp;15 minutes after that.</li>
</ul>
<p>
	LINKS</p>
<ul>
	<li>
		<a href="http://www.msxfaq.de/e2007/autodiscover.htm">http://www.msxfaq.de/e2007/autodiscover.htm</a></li>
	<li>
		<a href="http://msexchangefaq.de/howto/calfed2007.htm">http://msexchangefaq.de/howto/calfed2007.htm</a></li>
	<li>
		<a href="http://technet.microsoft.com/en-us/library/ff597979(v=exchg.80).aspx">http://technet.microsoft.com/en-us/library/ff597979(v=exchg.80).aspx</a></li>
	<li>
		<a href="http://community.office365.com/en-us/w/exchange/1042.aspx">http://community.office365.com/en-us/w/exchange/1042.aspx</a></li>
	<li>
		<a href="https://www.testexchangeconnectivity.com/">https://www.testexchangeconnectivity.com/</a></li>
	<li>
		<a href="http://www.expta.com/2011/08/exchange-federated-freebusy-doesnt-work.html">http://www.expta.com/2011/08/exchange-federated-freebusy-doesnt-work.html</a></li>
	<li>
		<a href="http://office.microsoft.com/en-us/outlook-help/what-is-the-enable-logging-troubleshooting-option-HA010356489.aspx">http://office.microsoft.com/en-us/outlook-help/what-is-the-enable-logging-troubleshooting-option-HA010356489.aspx</a></li>
	<li>
		<a href="http://technet.microsoft.com/de-de/library/ff597979(v=exchg.80).aspx">http://technet.microsoft.com/de-de/library/ff597979(v=exchg.80).aspx</a></li>
</ul>
<p>
	Experiences</p>
<p>
	If you want to set&nbsp; internalurl or externalurl parameters inside Set-AutodiscoverVirtualDirectory, this will not work. Even if TECHNET says that it would work. i.e.&nbsp;Set-AutodiscoverVirtualDirectory -identity &quot;CASserver\Autodiscover (Default Web Site)&quot; &ndash;InternalUrl will produce an error saying that the arguments do not exist.<br />
	Solution: Use adsiedit in configuration partition. Look for msExchInternalHostName and msExchExternalHostName in:</p>
<p>
	CN=Autodiscover (Default Web Site),CN=HTTP,CN=Protocols,CN=B,CN=Servers,CN=Exchange Administrative Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=First Organization,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=&lt;domain&gt;,DC=com</p>
]]>
    </content>
</entry>

<entry>
    <title>Migration Tools: CopyOUStructure and user objects</title>
    <link rel="alternate" type="text/html" href="http://www.tools4exchange.com/2012/12/migration-tools-copyoustructure-and-user-objects.html" />
    <id>tag:www.tools4exchange.com,2012://13.1748</id>

    <published>2012-12-06T11:18:42Z</published>
    <updated>2012-12-10T10:02:51Z</updated>

    <summary> CopyOUStructure is a command-line solution to aid cross-forest migration scenarios. Most cross-forest migration projects happen under heavy time pressure. The structure of organizational units within the common target forest is in most cases no subject to change, as the...</summary>
    <author>
        <name>Hans Willi Kremer</name>
        <uri>http://www.NETsec.de</uri>
    </author>
    
        <category term="Migration" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="activedirectorymigrationtooladmtcloneoustructurecrossforestmigration" label="Active Directory Migration Tool ADMT clone OU structure cross-forest migration" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="cloneorganizationalunits" label="clone Organizational Units" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://www.tools4exchange.com/">
        <![CDATA[<p>
	<strong>CopyOUStructure </strong>is a command-line solution to aid cross-forest migration scenarios.</p>
<p>
	Most cross-forest migration projects happen under heavy time pressure. The structure of organizational units within the common target forest is in most cases no subject to change, as the current structure shall be kept from the source. The redesign of the OU structure is in most cases part of a later project, as it should not have any impact with the migration itself, and would only increase the budget and lenght in time of the migration project.</p>
<p>
	The effect will carry out the most when using ADMT: It is only able to migrate all user-objects in one target OU or to clone source OUs with users direct to the target root. But in most cases you will want to replicate the source OU-structure into on sub-OU on the target. There is&nbsp; a possibility to copy a whole OU-structure, but only at top-level, which is desaterous when planning a company-merge.</p>
<p>
	We also need to replicate the source OU-structure to be able to migrate the GPOs of the source and link them corresponding to the source domain. Groups on the other hand are not in the scope of this tool, as for a membership it does not matter where the group physically exists.</p>
<p>
	As our consulting is involved in many migration projects, we developed this tool to aid the projects.</p>
<p>
	We also decided that we want to provide this tool without any cost:</p>
<p style="margin-left: 18pt">
	<a href="http://www.netsec.de/en/download/formular/?datei=20" target="_blank"><u>Download free full-version</u></a></p>
]]>
        <![CDATA[<p>
	&nbsp;Just replicating the OU-Structure will not do the whole job. If you would only like that (so not moving the migrated users to the corresponding OU) you might find these links helpful:</p>
<ul>
	<li>
		<a href="http://www.sysadminlab.net/windows/migrate-or-copy-ou-structure-between-domains-using-powershell" target="_blank">Migrate or copy OU structure between domains using&nbsp;</a>oder</li>
	<li>
		<a href="http://globalknowledgeblog.com/technology/microsoft/cloning-parallel-ou-hierarchy/" target="_blank">Cloning Parallel OU Hierarchy</a></li>
</ul>
<p style="margin-left: 18pt">
	&nbsp;<strong>Starting Point</strong></p>
<p style="margin-left: 18pt">
	In the following example we have two Companys (CompanyA and CompanyB) sharing the same forestname. For different reasons they want to merge CompanyB into CompanyA.</p>
<p style="margin-left: 18pt">
	The Structure of CompanyA will stay untouched. The OU-Structure of CompanyB will be replicated into one top-level OU in CompanyA. Using ADMT, the Active Directory Objects of CompanyB will be migrating into this OU. Once all objects are successfully migrated, they shall be moved into the OU corresponding to their Parent-OU of their source domain. To aid understanding of this structure, please see the picture at the end of this article.</p>
<p style="margin-left: 18pt">
	<strong>The Tool</strong></p>
<p style="margin-left: 18pt">
	To prevent the administrators from manually moving the user objects into their new OU (Corresponing to their source-OU), we developed the tool <em>CopyOUStructure</em>:</p>
<p style="margin-left: 18pt">
	&nbsp;Syntax:&nbsp;<br />
	CopyOUStructure &lt;Source-OU-DN&gt;, &lt;Target-OU-DN&gt;<br />
	Example:<br />
	CopyOUStructure &quot;OU=Top One,DC=companyB,DC=com&quot;, &quot;ou=FromcompanyB,DC=CompanyA,DC=com&quot;</p>
<p style="margin-left: 18pt">
	Please Note: Both DN-Parameters are case sensitive. When you enter the DNs mismatching the case the tool will correct that automatically.</p>
<p style="margin-left: 18pt">
	You can also run the tool multiple times, e.g. while testing or migrating only some users at a time.</p>
<p style="margin-left: 18pt">
	<strong>Prerequisities</strong></p>
<p style="margin-left: 18pt">
	The account executing the tool will need read-permissions on the source domain and modify permissions on the targeted OU. Also the domains need to have a fully functioning trust between them.</p>
<p style="margin-left: 18pt">
	Also the migrated users need all to be placed in the OU of the target-ou parameter.</p>
<p style="margin-left: 18pt">
	<strong>Process</strong></p>
<p style="margin-left: 18pt">
	The Tool will start with searching all users in and under the given source-ou parameter. Next it will create all needed OUs in the target-ous. Please note that empty OUs will not be replicated.</p>
<p style="margin-left: 18pt">
	In the next step, the tool will move all objects that are found both in source and target to their corresponding OU in ther target structure.</p>
<p style="margin-left: 18pt">
	The tool will give you logging via console output, so you might want to pipe the output into a text file using &bdquo;&gt;&gt; %pathoftextfile%&ldquo;.&nbsp;</p>
<p style="margin-left: 18pt">
	<a href="http://www.netsec.de/en/download/formular/?datei=20" target="_blank"><u>Download free full-version</u></a></p>
<p style="margin-left: 18pt">
	<a href="http://www.tools4exchange.com/assets_c/2012/12/CopyOUStructure-thumb-533x326-910-911.html" onclick="window.open('http://www.tools4exchange.com/assets_c/2012/12/CopyOUStructure-thumb-533x326-910-911.html','popup','width=533,height=326,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img alt="Vorschaubild für CopyOUStructure.PNG" class="mt-image-none" height="326" src="http://www.tools4exchange.com/assets_c/2012/12/CopyOUStructure-thumb-533x326-910-thumb-533x326-911.png" width="533" /></a></p>
<p>
	&nbsp;</p>
]]>
    </content>
</entry>

<entry>
    <title>Cross-Forest Free/Busy without Federation</title>
    <link rel="alternate" type="text/html" href="http://www.tools4exchange.com/2012/11/cross-forest-freebusy-without-federation.html" />
    <id>tag:www.tools4exchange.com,2012://13.1745</id>

    <published>2012-11-30T13:27:15Z</published>
    <updated>2013-03-18T18:43:06Z</updated>

    <summary> We want to supply GAL between 2 untrusted Active Directory forests with Exchange organizations. This we will perform with NETsec&#39;s GALsync software. Additionally we want to share Free/Busy information without configuring a Microsoft Federation (using the MS Federation Gateway)....</summary>
    <author>
        <name>Hans Willi Kremer</name>
        <uri>http://www.NETsec.de</uri>
    </author>
    
        <category term="Exchange 2007" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Exchange 2010" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Exchange 2013" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="GALsync" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="accessmethodorgwidefb" label="AccessMethod OrgWideFB" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="addavailabilityaddressspace" label="Add-AvailabilityAddressSpace" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="availabilityinformation" label="Availability information" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="configuretheavailabilityserviceforcrossforesttopologies" label="Configure the Availability Service for Cross-Forest Topologies" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="crossforestexchangemigration" label="Cross-forest Exchange migration" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="crossforestfreebusy" label="Cross-forest free/busy" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="dirsync" label="DIRsync" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="exchange2007" label="Exchange 2007" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="exchange2010" label="Exchange 2010" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="exchangefederation" label="Exchange Federation" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="galsync" label="GALsync" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="interorgreplicationtool" label="Inter-Org Replication Tool" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="netsec" label="NETsec" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="organisationsübergreifendeexchangemigration" label="Organisationsübergreifende Exchange Migration" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="organisationsübergreifendefreigebuchtzeiten" label="Organisationsübergreifende Frei/Gebucht Zeiten" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="setavailabilityconfigorgwideaccount" label="Set-AvailabilityConfig -OrgWideAccount" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="sharecalendarandcontactinformationcrossforest" label="share Calendar and Contact information cross-forest" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://www.tools4exchange.com/">
        <![CDATA[<p>
	<span style="font-size: 12px"><span style="font-family: arial,helvetica,sans-serif"><span style="color: #222222"><o:p>We want to supply GAL between 2 untrusted Active Directory forests with Exchange organizations. This we will perform with NETsec&#39;s GALsync software.</o:p></span></span></span><br />
	<span style="font-family: arial,helvetica,sans-serif"><span style="font-size: 9pt; color: #222222"><o:p></o:p></span></span><span style="font-size: 12px"><span style="font-family: 'Arial','sans-serif'; color: #222222"><o:p></o:p></span><span style="font-family: arial,helvetica,sans-serif"><span style="color: #222222"><o:p>Additionally we want to share Free/Busy information without configuring a Microsoft Federation (using the MS Federation Gateway). We do not want to use the Free/Busy feature of GALsync. </o:p></span></span></span></p>
<p>
	<span style="font-size: 12px"><span style="font-family: arial,helvetica,sans-serif"><span style="color: #222222"><o:p>In this article&nbsp;I will demonstrate t<span style="font-size: 12px"><span style="font-family: arial,helvetica,sans-serif"><span style="color: #222222"><o:p>he procedure to supply Free/Busy in this way.</o:p></span></span></span></o:p></span></span></span></p>
]]>
        <![CDATA[<p>
	<span style="font-size: 12px"><span style="font-family: arial,helvetica,sans-serif"><strong>High-Level-Steps</strong></span></span></p>
<ol>
	<li>
		<span style="font-size: 12px"><span style="font-family: arial,helvetica,sans-serif">Exchange Web Service (EWS) is published in Internet&nbsp;(SAN-Certificates and autodiscover work properly)</span></span></li>
	<li>
		<span style="font-size: 12px"><span style="font-family: arial,helvetica,sans-serif">Create a proxy-account without mailbox in each&nbsp;forest</span></span></li>
	<li>
		<span style="font-size: 12px"><span style="font-family: arial,helvetica,sans-serif">Perform Add-AvailabilityAddressSpace and <em>Set-AvailabilityConfig</em></span></span></li>
	<li>
		<span style="font-size: 12px"><span style="font-family: arial,helvetica,sans-serif">Synchronize the objects with GALsync</span></span></li>
	<li>
		<span style="font-size: 12px"><span style="font-family: arial,helvetica,sans-serif">With Outlook / OWA invite people in the other forest using the Free/Busy information</span></span></li>
</ol>
<p>
	<span style="font-size: 12px"><span style="font-family: arial,helvetica,sans-serif">In the test environment I use for this procedure I do not have Internet access. Therefor I use&nbsp;self-signed certificates.</span></span></p>
<table align="left" border="1" cellpadding="1" cellspacing="1" style="height: 216px; width: 403px">
	<caption>
		<strong>Used machines and accounts</strong></caption>
	<thead>
		<tr>
			<th scope="col">
				name</th>
			<th scope="col">
				function</th>
			<th scope="col">
				ip</th>
		</tr>
	</thead>
	<tbody>
		<tr>
			<td>
				ADC.foresta.com</td>
			<td>
				DC/DNS/Exchange 2010 SP2</td>
			<td>
				172.20.25.100</td>
		</tr>
		<tr>
			<td>
				AGS.foresta.com</td>
			<td>
				GALsync Server</td>
			<td>
				172.20.25.101</td>
		</tr>
		<tr>
			<td>
				ClientForestA.foresta.com</td>
			<td>
				Outlook 2010 Client</td>
			<td>
				172.20.25.104</td>
		</tr>
		<tr>
			<td>
				&nbsp;</td>
			<td>
				&nbsp;</td>
			<td>
				&nbsp;</td>
		</tr>
		<tr>
			<td>
				BDC.forestb.com</td>
			<td>
				DC/DNS/Exchange 2010 SP2</td>
			<td>
				172.20.25.102</td>
		</tr>
		<tr>
			<td>
				BGS.forestb.com</td>
			<td>
				GALsync Server</td>
			<td>
				172.20.25.103</td>
		</tr>
		<tr>
			<td>
				ClientForestB.forestb.com</td>
			<td>
				Outlook 2010 Client</td>
			<td>
				172.20.25.105</td>
		</tr>
	</tbody>
</table>
<p>
	&nbsp;</p>
<p>
	&nbsp;</p>
<p>
	&nbsp;</p>
<p>
	&nbsp;</p>
<p>
	&nbsp;</p>
<p>
	&nbsp;</p>
<p>
	&nbsp;<br />
	&nbsp;</p>
<p>
	&nbsp;</p>
<p>
	--------</p>
<table align="left" border="1" cellpadding="1" cellspacing="1" style="height: 347px; width: 392px">
	<tbody>
		<tr>
			<td>
				name</td>
			<td>
				function</td>
			<td>
				permissions</td>
		</tr>
		<tr>
			<td>
				foresta.com\freebusy\freebusy</td>
			<td>
				proxy account</td>
			<td>
				domain user</td>
		</tr>
		<tr>
			<td>
				foresta.com\users\GALsync</td>
			<td>
				service account</td>
			<td>
				look in GALsync manual</td>
		</tr>
		<tr>
			<td>
				foresta.com\freebusy\freebusytest1foresta</td>
			<td>
				Testuser</td>
			<td>
				domain user</td>
		</tr>
		<tr>
			<td>
				foresta.com\freebusy\freebusytest2foresta</td>
			<td>
				Testuser</td>
			<td>
				domain user</td>
		</tr>
		<tr>
			<td>
				forestb.com\freebusy\freebusy</td>
			<td>
				proxy account</td>
			<td>
				domain user</td>
		</tr>
		<tr>
			<td>
				forestb.com\users\GALsync</td>
			<td>
				service account</td>
			<td>
				look in GALsync manual</td>
		</tr>
		<tr>
			<td>
				forestb.com\freebusy\freebusytest1forestb</td>
			<td>
				Testuser</td>
			<td>
				domain user</td>
		</tr>
		<tr>
			<td>
				forestb.com\freebusy\freebusytest2forestb</td>
			<td>
				Testuser</td>
			<td>
				domain user</td>
		</tr>
	</tbody>
</table>
<p>
	&nbsp;</p>
<p>
	&nbsp;</p>
<p>
	&nbsp;</p>
<p>
	&nbsp;</p>
<p>
	&nbsp;</p>
<p>
	<br />
	&nbsp;<br />
	&nbsp;</p>
<p>
	&nbsp;</p>
<p>
	&nbsp;</p>
<p>
	&nbsp;</p>
<p>
	&nbsp;</p>
<p>
	&nbsp;</p>
<p>
	<span style="font-size: 12px"><span style="font-family: arial,helvetica,sans-serif"><span style="font-size: 12px"><span style="font-family: arial,helvetica,sans-serif"><strong>Trust</strong></span></span>: There is no trust between the domains. If there is a trust, it doesn&#39;t matter.</span></span></p>
<p>
	<span style="font-size: 12px"><span style="font-family: arial,helvetica,sans-serif"><strong><strong>Configure</strong>&nbsp;send connectors and receive connectors</strong></span></span></p>
<p>
	<span style="font-size: 12px"><span style="font-family: arial,helvetica,sans-serif">Send connectors and receive connectors are present and you can email between both organizations</span></span></p>
<p>
	&nbsp;<strong>Configure SAN-Certificates</strong></p>
<p>
	I create&nbsp;self-signed SAN-Certificates for my non-public test environment</p>
<p>
	Link: <a href="http://blog.exchange-addict.com/2012/11/cross-forest-freebusy-simple-version_13.html">http://blog.exchange-addict.com/2012/11/cross-forest-freebusy-simple-version_13.html</a></p>
<ul>
	<li style="margin-left: 54pt">
		selfssl7.exe /N cn=autodiscover.foresta.com;cn=adc.foresta.com;cn=adc /K 1024 /V 18250 /X /F c:\exchangeForesta.pfx /W passwort /Q</li>
	<li style="margin-left: 54pt">
		selfssl7.exe /N cn=autodiscover.forestb.com;cn=bdc.forestb.com;cn=bdc /K 1024 /V 18250 /X /F c:\exchangeForestb.pfx /W passwort /Q</li>
</ul>
<p style="margin-left: 54pt">
	<br />
	<u>Import certificates</u><br />
	ForestA-certificate:<br />
	ADC: computer account Trusted root CA container<br />
	BDC:&nbsp;computer account Trusted root CA container<br />
	ClientForestA: current user<br />
	Trusted root CA container<br />
	ForestB-Zertifikat:&nbsp;<br />
	ADC: computer account Trusted root CA container<br />
	BDC:&nbsp;computer account Trusted root CA container<br />
	ClientForestB: current user<br />
	Trusted root CA container</p>
<p style="margin-left: 54pt">
	<u>Tests</u></p>
<ul>
	<li style="margin-left: 54pt">
		do&nbsp; <a href="https://adc/owa">https://adc/owa</a> works? <a href="https://adc.foresta.com/owa">https://adc.foresta.com/owa</a> as well?</li>
	<li style="margin-left: 54pt">
		Does Outlook start without certificate-warning?</li>
	<li style="margin-left: 54pt">
		Test with&nbsp;Outlook Email-Autoconfiguration</li>
</ul>
<p style="margin-left: 54pt">
	<u>Exchange (&uuml;ber EMC)</u></p>
<ul>
	<li style="margin-left: 54pt">
		Import certificates</li>
	<li style="margin-left: 54pt">
		Apply certificate to service&nbsp;IIS</li>
</ul>
<p>
	<strong>Configure HOSTS file</strong></p>
<ul>
	<li>
		BDC: 172.20.25.100 AUTODISCOVER.foresta.com</li>
	<li>
		ADC: 172.20.25.102 &nbsp;AUTODISCOVER.forestb.com</li>
</ul>
<p>
	<strong>Configure Exchange</strong></p>
<p style="margin-left: 40px">
	<u>On CAS Server in forestA (ADC)</u></p>
<ul>
	<li>
		Add-AvailabilityAddressSpace &ndash;Forestname &quot;ForestB.com&quot; -AccessMethod OrgWideFB &ndash;Credential (get-Credential)<br />
		use credentials of forestb\freebusy</li>
	<li>
		Set-AvailabilityConfig &ndash;OrgWideAccount freebusy</li>
</ul>
<p style="margin-left: 40px">
	<u>On CAS Server in forestA (ADC)</u></p>
<ul>
	<li>
		Add-AvailabilityAddressSpace &ndash;Forestname &quot;ForestA.com&quot; -AccessMethod OrgWideFB &ndash;Credential (get-Credential)&nbsp;<br />
		use credentials of foresta\freebusy</li>
	<li>
		Set-AvailabilityConfig &ndash;OrgWideAccount freebusy</li>
</ul>
<p>
	<strong><strong>Configure </strong>GALsync</strong></p>
<ul>
	<li>
		Synchronize with GALsync the objects&nbsp;FreeBusyTest1Foresta to ForestB and FreeBusyTest1ForestB to ForestA;</li>
	<li>
		do not configure the GALsync Free/Busy option;</li>
	<li>
		update the addresslists for contacts and the OAB in Exchange (EMC).</li>
</ul>
<p>
	<strong><strong>Configure </strong>Testdata</strong></p>
<p>
	Create some appointments in all calenders of the 4 users</p>
<p>
	<strong>Expected results</strong></p>
<ul>
	<li>
		FreeBusyTest1ForestA and FreeBusyTest2ForestA can see the Free/Busy inforemation of FreeBusyTest1ForestB,</li>
	<li>
		but not of FreeBusyTest2ForestB;</li>
	<li>
		Note: in OWA the contact is to add by using &quot;add from addressbook&quot;. never insert the name by yourself.</li>
</ul>
<p>
	Tip: if you modify the permissions of DEFAULT&nbsp;in a calendar folder&nbsp;of a user you can define more granuarly the data people can see.</p>
<p>
	<strong>Links</strong></p>
<ul>
	<li>
		<a href="http://blog.exchange-addict.com/2012/11/cross-forest-freebusy-simple-version_13.html">http://blog.exchange-addict.com/2012/11/cross-forest-freebusy-simple-version_13.html</a></li>
	<li>
		<a href="http://geekswithblogs.net/renewieldraaijer/archive/2011/05/11/self-signed-san-certificates.aspx">http://geekswithblogs.net/renewieldraaijer/archive/2011/05/11/self-signed-san-certificates.aspx</a></li>
</ul>
<p>
	&nbsp;</p>
]]>
    </content>
</entry>

<entry>
    <title>EPR Setup</title>
    <link rel="alternate" type="text/html" href="http://www.tools4exchange.com/2012/07/epr-setup.html" />
    <id>tag:www.tools4exchange.com,2012://13.1678</id>

    <published>2012-07-16T11:35:18Z</published>
    <updated>2012-07-17T10:44:57Z</updated>

    <summary> After downloading the installation file, open the *msi-Installer. If you make an update, the directory \program files\NETsec\epr will be checked.The existing data are transferred, so you can continue to work with your pre-defined reports. If the directory does not...</summary>
    <author>
        <name>Hans Willi Kremer</name>
        <uri>http://www.NETsec.de</uri>
    </author>
    
    <category term="enterprisepermissionreportersetupandunistall" label="Enterprise Permission Reporter Setup and Unistall" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="monitorgroupmembershipchanges" label="monitor group membership changes" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://www.tools4exchange.com/">
        <![CDATA[<p>
	<img alt="Vorschaubild für Vorschaubild für eprlogo.jpg" class="mt-image-none" height="81" src="http://www.tools4exchange.com/assets_c/2012/07/eprlogo-thumb-533x81-631-thumb-533x81-703.jpg" style="width: 340px; height: 51px" width="533" />After downloading the installation file, open the *msi-Installer. If you make an update, the directory \program files\NETsec\epr will be checked.The existing data are transferred, so you can continue to work with your pre-defined reports. If the directory does not exist, it will be created.<span style="display: none"> </span></p>
]]>
        <![CDATA[<p>
	Furthermore, the directory \Users\&lt;username&gt;\AppData\Local\NETsec is checked by existence. Here are the personalized configuration configuration settings. If no data are available, the directory is created.</p>
<p>
	With the installation of EPR a new Windows service is provided and immediately started in the context of local user.<span style="display: none">&nbsp;</span></p>
<p>
	<a href="http://www.tools4exchange.com/EPRSetup04.PNG"><img alt="EPRSetup04.PNG" class="mt-image-none" height="38" src="http://www.tools4exchange.com/assets_c/2012/07/EPRSetup04-thumb-533x38-705.png" style="width: 360px; height: 40px" width="533" /></a></p>
<h2>
	<span style="font-size: 14px">1. The service account</span></h2>
<p>
	EPR signals at the first boot after installation with a notice that the service account must be configured:</p>
<p>
	<img alt="EPRSetup02.PNG" class="mt-image-none" height="379" src="http://www.tools4exchange.com/EPRSetup02.PNG" style="width: 340px; height: 311px" width="500" /></p>
<p>
	&nbsp;</p>
<p>
	In the initial runs, the EPR service account logs on in the name of local system. This account has but (hopefully) in your AD do not have rights to the reports you want to define more soon. we recommend that you create a special service account (eg EPRSRV) in AD. Enter the account in the EPR configuration.</p>
<p>
	On the machine running on the GUI, the service account must be a member of the local Administrators group.</p>
<p>
	<img alt="EPRSetup03.PNG" class="mt-image-none" height="299" src="http://www.tools4exchange.com/EPRSetup03.PNG" style="width: 390px; height: 246px" width="522" /></p>
<p>
	In the Information bar, you get the information about who is currently logged on whether the EPR service is started and the service account.<span style="display: none">&nbsp;</span></p>
<p>
	<img alt="EPRInfoLine.PNG" class="mt-image-none" height="37" src="http://www.tools4exchange.com/EPRInfoLine.PNG" width="353" /></p>
<h2>
	2. Entering the License</h2>
<p>
	The trial version is in the title bar indicated that the performance of file system reports, and included more than 100 reports of Active Directory objects. The Watcher Membership runs for 10 days.</p>
<p>
	The license file can be activated by Options -&gt; About -&gt; Add License.</p>
<p>
	<img alt="EPRLimited.PNG" class="mt-image-none" height="24" src="http://www.tools4exchange.com/EPRLimited.PNG" width="291" /></p>
<h2>
	3.The basic settings</h2>
<p>
	So you do not report back on any need to define the connection data to the database or the new mail subscription data, you can configure in the top node of the TAB program, storage, and notification settings as a template. Each report definition, you can accept or change the settings.</p>
<p>
	<a href="http://www.tools4exchange.com/eprGeneral01.PNG"><img alt="eprGeneral01.PNG" class="mt-image-none" height="224" src="http://www.tools4exchange.com/assets_c/2012/07/eprGeneral01-thumb-533x224-711.png" style="width: 370px; height: 207px" width="533" /></a></p>
<p>
	<u>Program:</u></p>
<ul>
	<li>
		Specify here, to delete after how many days the log files EPR. These lie in the installation directory under epr \logger.</li>
	<li>
		Because the internal modules of the Software communicate about a TCP/IP Port, you can change the standart port in another parameter , if you use another tools which needs the configurated port.</li>
</ul>
<p>
	&nbsp;</p>
<p>
	<span style="color: rgb(255,0,0)">ATTENTION: Please remember to save the settings with SAVE!</span></p>
<p>
	&nbsp;</p>
<p>
	<u>Storage:</u></p>
<p>
	Configure the Storage tab, where the user data to be stored. We strongly recommend the use of a database. Use the File option to quickly test the software. Each report definition, you can accept or change the settings.</p>
<p>
	After the address of the SQL Server instance specified (in this case Samsung PC \ SQLExpress) test</p>
<ul>
	<li>
		availability to access the SQL server by clicking <em>Test Connection</em></li>
	<li>
		the existence of a database with the name EPR by clicking on <em>Test Database</em></li>
</ul>
<p>
	&nbsp;</p>
<p>
	If the Database does not exist, she will be created automatically by clicking <em>Create Database.</em></p>
<p>
	By default, access to the SQL Server is made in name of local service account. However, you can also access a SQL Server logging on SQL Authenticate.</p>
<p>
	In the current version of the data on the SQL Server are stored securely. In the next release, an additional option &ldquo;Maintanance&rdquo; will be available, which allows you to configure the storage times.</p>
<p>
	<span style="color: rgb(255,0,0)">ATTENTION: Please remember to save the settings with SAVE!</span></p>
<p>
	&nbsp;</p>
<p>
	&nbsp;</p>
<p>
	<u>Notification</u></p>
<p>
	Configure in the tab Notification, whether and to whom you want to send the resulting data and who should receive information about the execution of a report. The latter is likely to be an employee of</p>
<p>
	IT, the former (department) responsible for data accuracy. Each report definition, you can accept or change the settings.<span style="display: none">&nbsp;</span></p>
<p>
	<img alt="Vorschaubild für EPRMW04.PNG" class="mt-image-none" height="565" src="http://www.tools4exchange.com/assets_c/2012/07/EPRMW04-thumb-533x565-558.png" style="width: 394px; height: 446px" width="533" /></p>
<p>
	&nbsp;</p>
<p>
	The SMTP server must be able to accept your data package. For internal mail servers please ask if the server accepts anonymous logins counter. Otherwise, select External SMTP - this option allows you to authenticate data transferred.</p>
<p>
	&nbsp;</p>
<p>
	Since the Data attached Security reports (not the summary) may be very large and this can not be allowed on all mail servers, you can determine the maximum size of messages. If these are exceeded, the recipient receives a message that it is not for this reason the data can be delivered. The default value is 5 MB.</p>
<p>
	&nbsp;</p>
<p>
	By clicking the Test button to the addressees are sent test mails, you should check that they are receiving.</p>
<p>
	<span style="color: rgb(255,0,0)">ATTENTION: Please remember to save the settings with SAVE!</span></p>
<h2>
	4. Upgrades</h2>
<p>
	Users of versions prior to v3.5 EPR must uninstall the previous version completely. Since the data structures have been redefined, previous reports can not be accepted. If you this is not possible, the new version can also be installed on another computer and other SQL Server.</p>
<p>
	&nbsp;</p>
<p>
	Take an uninstall of software to make the Control Panel. The report data is all still present, only the necessary program files will be replaced.</p>
<h2>
	5. Complete Uninstall</h2>
<p>
	In the &quot;normal&quot; uninstall the service and the registry entries will be removed. Remove to uninstall the software, the directory \ windows \ NETsec \ epr and \ Users \ &lt;username&gt; \ AppData \ Local \ NETsec \ &lt;* epr *&gt; if you want to remove all report data and configurations from the computer.</p>
<h2>
	6.Informations to the Architecture of EPR</h2>
<ul>
	<li>
		The file system reports and the delta reports can be automated via a scheduler or the GUI on the RUN button triggered.</li>
	<li>
		The Active Directory Reports, and the delta reports can be automated via a scheduler or the GUI on the RUN button triggered.</li>
	<li>
		The Watcher Membership runs automatically in the configured time interval.</li>
</ul>
<p style="margin-left: 36pt">
	&nbsp;</p>
<p style="margin-left: 36pt">
	In the example image you can see that the service runs under the appropriate account, the GUI is started by someone else.<span style="display: none">&nbsp;</span></p>
<p>
	<a href="http://www.tools4exchange.com/assets_c/2012/07/EPRTasks-thumb-533x252-714.png"><img alt="Vorschaubild für EPRTasks.PNG" class="mt-image-none" height="252" src="http://www.tools4exchange.com/assets_c/2012/07/EPRTasks-thumb-533x252-714-thumb-533x252-715.png" style="width: 361px; height: 213px" width="533" /></a></p>
<p style="margin-left: 36pt">
	Note: If you test the software, then let the software enough time to query the data. For example, you should expect from a new report on the Definition Membership Watcher with a &quot;First-time-schedule&quot; about 10 minutes. Only after the configuration values ​​are taken into account.</p>
<p style="margin-left: 36pt">
	&nbsp;</p>
<p style="margin-left: 36pt">
	<span style="color: rgb(255,0,0)">For Questions, please contact our Sales-oriented or technical support team at your disposal.<span style="display: none">&nbsp;</span></span></p>
<p>
	&nbsp;</p>
<p>
	&nbsp;</p>
]]>
    </content>
</entry>

<entry>
    <title>ENow Releases ForeSite - A New SharePoint Management Solution</title>
    <link rel="alternate" type="text/html" href="http://www.tools4exchange.com/2012/07/enow-releases-foresite-a-new-sharepoint-management-solution.html" />
    <id>tag:www.tools4exchange.com,2012://13.1657</id>

    <published>2012-07-11T14:04:09Z</published>
    <updated>2012-07-15T16:32:17Z</updated>

    <summary><![CDATA[ Corona, CA &ndash; July 10, 2012 ENow, a Microsoft Independent Software Vendor specializing in the development of software to simplify Microsoft system management, announced the release of ForeSite, a SharePoint management solution.&nbsp;&nbsp;...]]></summary>
    <author>
        <name>Hans Willi Kremer</name>
        <uri>http://www.NETsec.de</uri>
    </author>
    
        <category term="Foresite" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="foresite" label="ForeSite" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="mailscape" label="Mailscape" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="sharepointmanagementsolution" label="SharePoint management solution" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://www.tools4exchange.com/">
        <![CDATA[<p align="left">
	<span style="font-size: 12px">Corona, CA &ndash; July 10, 2012 </span></p>
<p align="left">
	<span style="font-size: 12px">ENow, a Microsoft Independent Software Vendor specializing in the development of software to simplify Microsoft system management, announced the release of ForeSite, a SharePoint management solution.&nbsp;</span><span style="font-size: 12px"><font face="Calibri,Calibri"><font face="Calibri,Calibri">&nbsp;</font></font></span></p>
]]>
        <![CDATA[<p align="left">
	<span style="font-size: 12px">ENow&#39;s ForeSite is designed to help organizations proactively monitor their SharePoint infrastructure, including all of the core underlying technologies such as Microsoft Active Directory, Internet Information Server and SQL. It also includes monitoring SharePoint&rsquo;s key components including site availability, timer jobs and content databases alerting. ForeSite also includes a suite of reports that help administrators better understand how SharePoint is being </span></p>
<p align="left">
	<span style="font-size: 12px">ForeSite is built on top of the award winning ENow Management System platform which is used in over 35 countries by enterprise companies, including Facebook, NYSE, DirecTV, Blue Cross Blue Shield, and CB Richard Ellis. The product features a customizable dashboard with red, yellow, and green lights indicating the health of each monitored server. The One Look solution enables IT support staff to proactively monitor servers in real time. In addition, ENow&rsquo;s Management System platform is also popular for its customizable reporting, which gives administrators complete flexibility in not only how they create reports, but also how they disseminate the information. &quot;Traditional reporting products only allow you to email a report, resulting in static data,&quot; explains Jay Gundotra, CEO of ENow. &quot;But with ForeSite Personalized Dashboards, each key role in your organization can have access to a customized dashboard that meets their needs and automatically updates.&quot; This unique feature empowers help desk personnel to better service their users and improve response time. </span></p>
<p align="left">
	<span style="font-size: 12px">&quot;After the success of Mailscape, our Exchange Monitoring and Reporting product, we have an international customer base spanning 35 countries. These companies expressed a strong interest in having us replicate our approach for SharePoint,&quot; states Mr. Gundotra. &quot;ForeSite was created with the same core ingredients, comprehensive monitoring and reporting features combined with our personalized dashboards. This approach provides Help Desk operators with the ability to quickly diagnose a problem and deliver critical information needed to proactively manage SharePoint farms and avoid costly downtime.&quot; </span></p>
<p align="left">
	<span style="font-size: 12px"><b>About ENow </b></span></p>
<p>
	<span style="font-size: 12px"><font face="Calibri,Calibri"><font face="Calibri,Calibri">ENow is a Microsoft Silver Independent Software Vendor focused on helping companies implement the latest Microsoft technologies and developing software tools to simplify the job of an IT administrator. </font></font><br />
	<font face="Calibri,Calibri"><font face="Calibri,Calibri">The company&rsquo;s flagship product, ENow Management System (EMS), is an award winning monitoring and </font></font><font face="Calibri,Calibri"><font face="Calibri,Calibri">reporting tool that provides a dashboard view of Exchange, BlackBerry, SharePoint and Active Directory servers. For more information, call 1-877-TRY-ENOW, email us at info@enowinc.com, or visit us at www.enowinc.com.</font></font></span></p>
]]>
    </content>
</entry>

<entry>
    <title>Active Directory Object Permission Reporter - Delta reports show what changed</title>
    <link rel="alternate" type="text/html" href="http://www.tools4exchange.com/2012/07/active-directory-object-permission-reporter---delta-reports-show-what-changed.html" />
    <id>tag:www.tools4exchange.com,2012://13.1652</id>

    <published>2012-07-10T11:45:34Z</published>
    <updated>2012-07-12T15:56:46Z</updated>

    <summary> The new version 3.5 of Enterprise Permission Reporter now includes File Security Reporting who has access to folders and files? What&#39;s new - which modifications are made between 2 scans Active Directory Object Permission Reporting who has access to...</summary>
    <author>
        <name>Hans Willi Kremer</name>
        <uri>http://www.NETsec.de</uri>
    </author>
    
        <category term="Permission Reporter" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="accesscontrol" label="Access Control" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="activedirectorygroupmembershipwatcher" label="Active Directory Group Membership Watcher" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="activedirectoryobjectpermissionreporting" label="Active Directory Object Permission Reporting" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="activedirectorypermissionreporter" label="Active Directory Permission Reporter" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="changes" label="changes" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="deltareports" label="delta reports" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="differences" label="differences" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="fda" label="FDA" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="filesecurityreporting" label="File Security Reporting" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="groupmembershiptracker" label="Groupmembership tracker" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="hipaa" label="HIPAA" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="modificatens" label="modificatens" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="monitoring" label="Monitoring" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="pci" label="PCI" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="reporting" label="Reporting" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="sox" label="SOX" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="watcher" label="watcher" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://www.tools4exchange.com/">
        <![CDATA[<p>
	<img alt="eprlogo.jpg" class="mt-image-none" height="35" src="http://www.tools4exchange.com/eprlogo.jpg" width="230" /></p>
<p>
	The new version 3.5 of Enterprise Permission Reporter now includes</p>
<ul>
	<li>
		File Security Reporting<br />
		who has access to folders and files? What&#39;s new - which modifications are made between 2 scans</li>
	<li>
		Active Directory Object Permission Reporting<br />
		who has access to AD objects like OUs, users groups?&nbsp;&nbsp;What&#39;s new - which modifications are made between 2 scans?</li>
	<li>
		Active Directory Group Membership Watcher<br />
		who is added or removed from a certain important group? Real-time reports.</li>
</ul>
<p>
	EPR v3.5 combines basic reports which scan and document all found entries and DELTA reports which contain only the difference made.</p>
<p>
	The&nbsp;security administrator, the department or the group which is responsible for auditing gets only the information it needs. The IT administrators setup the software, define the policies and send the reports to the responsibles. That&#39;s all for the IT!</p>
<p>
	In this blog I describe shortly how the Active Directory Object Permission Reporting works.</p>
]]>
        <![CDATA[<p>
	<img alt="EPRADPR00.PNG" class="mt-image-none" height="342" src="http://www.tools4exchange.com/EPRADPR00.PNG" width="300" /></p>
<p>
	The configuration of a Report Definition is devided in 5 steps.</p>
<p>
	1. General<br />
	Configure name and description.</p>
<p>
	<a href="http://www.tools4exchange.com/EPRADPR01.PNG"><img alt="EPRADPR01.PNG" class="mt-image-none" height="233" src="http://www.tools4exchange.com/assets_c/2012/07/EPRADPR01-thumb-453x233-584.png" width="453" /></a></p>
<p>
	2. Analyze<br />
	Choose an Organizational Unit or select other Active Directory objects like users, contacts, groups, mail-enabled Public Folders.</p>
<p>
	<a href="http://www.tools4exchange.com/EPRADPR02.PNG"><img alt="EPRADPR02.PNG" class="mt-image-none" height="170" src="http://www.tools4exchange.com/assets_c/2012/07/EPRADPR02-thumb-533x170-586.png" width="533" /></a></p>
<p>
	3. Storage<br />
	Running the trial you might want to store the results in your file system. In production we recommend to use a database.</p>
<p>
	<a href="http://www.tools4exchange.com/EPRADPR03.PNG"><img alt="EPRADPR03.PNG" class="mt-image-none" height="530" src="http://www.tools4exchange.com/assets_c/2012/07/EPRADPR03-thumb-533x530-588.png" width="533" /></a></p>
<p>
	4. Notification<br />
	A summary and the result of the report can be set to any recipient you want.</p>
<p>
	<a href="http://www.tools4exchange.com/assets_c/2012/07/EPRMW04-thumb-539x572-558.png"><img alt="Vorschaubild für EPRMW04.PNG" class="mt-image-none" height="565" src="http://www.tools4exchange.com/assets_c/2012/07/EPRMW04-thumb-539x572-558-thumb-533x565-559.png" width="533" /></a></p>
<p>
	5. Scheduling<br />
	Schedule when the report should be executed.</p>
<p>
	<a href="http://www.tools4exchange.com/EPRADPR04.PNG"><img alt="EPRADPR04.PNG" class="mt-image-none" height="650" src="http://www.tools4exchange.com/assets_c/2012/07/EPRADPR04-thumb-533x650-590.png" width="533" /></a></p>
]]>
    </content>
</entry>

<entry>
    <title>Active Directory Group Membership Watcher</title>
    <link rel="alternate" type="text/html" href="http://www.tools4exchange.com/2012/07/active-directory-group-membership-watcher.html" />
    <id>tag:www.tools4exchange.com,2012://13.1643</id>

    <published>2012-07-02T07:08:03Z</published>
    <updated>2012-07-30T17:48:15Z</updated>

    <summary><![CDATA[ &nbsp;Welcome to our new version of Enterprise Permissions Reporting. EPR will assist you to meet all challenges you may face regarding regulatory compliances such as HIPAA, FDA, PCI or SOX.&nbsp; EPR can generate continuous reports for SOX/PCI audits. One...]]></summary>
    <author>
        <name>Hans Willi Kremer</name>
        <uri>http://www.NETsec.de</uri>
    </author>
    
        <category term="Permission Reporter" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="activedirectory" label="Active Directory" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="activedirectoryaudit" label="Active Directory Audit" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="activedirectorygroupmembershipchangetracker" label="Active Directory Group membership Change tracker" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="activedirectorymaintenance" label="Active Directory Maintenance" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="activedirectoryreports" label="Active Directory Reports" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="compliance" label="compliance" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="fda" label="FDA" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="groupmembership" label="Group Membership" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="hipaa" label="HIPAA" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="pci" label="PCI" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="regulatory" label="regulatory" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="sox" label="SOX" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://www.tools4exchange.com/">
        <![CDATA[<p>
	<span style="font-size: 12px"><span style="font-family: arial,helvetica,sans-serif"><span style="font-family: arial,helvetica,sans-serif"><img alt="eprlogo.jpg" class="mt-image-none" height="35" src="http://www.tools4exchange.com/eprlogo.jpg" width="230" />&nbsp;Welcome to our new version of Enterprise Permissions Reporting. EPR will assist you to meet all challenges you may face regarding regulatory compliances such as HIPAA, FDA, PCI or SOX.&nbsp; EPR can generate continuous reports for SOX/PCI audits. </span></span></span></p>
<p>
	<span style="font-size: 12px"><span style="font-family: arial,helvetica,sans-serif"><span style="font-family: arial,helvetica,sans-serif">One of the new&nbsp;features is called&nbsp;&nbsp;<em>Active Directory Group Membership Watcher </em>and <strong>monitors all changes </strong>which are made against a selected Active Directory group.</span></span></span></p>
<p>
	<span style="font-size: 12px"><span style="font-family: arial,helvetica,sans-serif"><span style="font-family: arial,helvetica,sans-serif"><a href="http://www.tools4exchange.com/EPRMW05.PNG"><img alt="EPRMW05.PNG" class="mt-image-none" height="76" src="http://www.tools4exchange.com/assets_c/2012/07/EPRMW05-thumb-533x76-622.png" width="533" /></a></span></span></span></p>
<p>
	<br />
	<span style="font-size: 12px"><span style="font-family: arial,helvetica,sans-serif"><span style="font-family: arial,helvetica,sans-serif">If someone adds or removes a member to a group then a delta report is created. So you get only the modifications. You can monitor these changes at the grafical user interface or send an automatical report to an independent manager.<br />
	A Windows service is executed as often as you want to check modifications.</span></span></span></p>
<p>
	<span style="font-size: 12px"><span style="font-family: arial,helvetica,sans-serif"><span style="font-family: arial,helvetica,sans-serif"><span style="font-size: 12px"><span style="font-family: arial,helvetica,sans-serif">In more detail I&#39;ll show you how to create a membership Watch Report Definition.</span></span> Here is the <a href="http://www.netsec.de/en/products/permission-reporter/?gclid=CKW0pfHE-rACFdHJzAod4j7p0w" target="_blank">trial</a>!</span></span></span></p>
]]>
        <![CDATA[<p>
	<br />
	You can track membership modifications through the entire forest. (No special license is needed for multiple domains or sites or number of installations).</p>
<p>
	<span style="font-size: 12px"><span style="font-family: arial,helvetica,sans-serif"><img alt="EPRMW00.PNG" class="mt-image-none" height="241" src="http://www.tools4exchange.com/EPRMW00.PNG" width="334" /></span></span></p>
<p>
	&nbsp;<span style="font-size: 12px"><span style="font-family: arial,helvetica,sans-serif">The configuration of this <em>Active Directory Group membership Change tracker tool </em>is divided into 4 sections</span></span></p>
<p>
	<span style="font-family: arial,helvetica,sans-serif"><span style="font-size: 12px"><strong>1. General</strong><br />
	Here you configure the name of the definition and how often the watcher should run.</span></span></p>
<p>
	&nbsp;<a href="http://www.tools4exchange.com/EPRMW01.PNG"><img alt="EPRMW01.PNG" class="mt-image-none" height="415" src="http://www.tools4exchange.com/assets_c/2012/07/EPRMW01-thumb-330x415-551.png" width="330" /></a></p>
<p>
	<br />
	<span style="font-family: arial,helvetica,sans-serif"><span style="font-size: 12px"><strong>2. Anaylze</strong><br />
	Choose a group from your entire forest list. If you click &quot;Show Current List&quot; all members of the selected group are enumerated.</span></span></p>
<p>
	<a href="http://www.tools4exchange.com/EPRMW02.PNG"><img alt="EPRMW02.PNG" class="mt-image-none" height="195" src="http://www.tools4exchange.com/assets_c/2012/07/EPRMW02-thumb-443x195-554.png" width="443" /></a></p>
<p>
	<br />
	<span style="font-family: arial,helvetica,sans-serif"><span style="font-size: 12px"><strong>3. Storage</strong><br />
	For testing purposes you might stored the results file based. We recommend to use a database.</span></span></p>
<p>
	&nbsp;<a href="http://www.tools4exchange.com/EPRMW03.PNG"><img alt="EPRMW03.PNG" class="mt-image-none" height="559" src="http://www.tools4exchange.com/assets_c/2012/07/EPRMW03-thumb-536x559-556.png" width="536" /></a></p>
<p>
	<br />
	<span style="font-family: arial,helvetica,sans-serif"><span style="font-size: 12px"><strong>4. Notification</strong><br />
	The result or a summary can be sent to the security manager or an independent quality monitoring.</span></span></p>
<p>
	&nbsp;<a href="http://www.tools4exchange.com/EPRMW04.PNG"><img alt="EPRMW04.PNG" class="mt-image-none" height="572" src="http://www.tools4exchange.com/assets_c/2012/07/EPRMW04-thumb-539x572-558.png" width="539" /></a></p>
<p>
	That&#39;s it - take a trial and have a look . . .</p>
<p>
	<strong>Note</strong>: if you configure a membership wathc report the first time you have to make 2 changes to the group. The first change will not be reportet because it is &quot;point zero&quot;.</p>
]]>
    </content>
</entry>

<entry>
    <title>ENow Management System 4.7 Provides Updated Exchange Monitoring and Reporting Features</title>
    <link rel="alternate" type="text/html" href="http://www.tools4exchange.com/2012/06/enow-management-system-47-provides-updated-exchange-monitoring-and-reporting-features.html" />
    <id>tag:www.tools4exchange.com,2012://13.1639</id>

    <published>2012-06-28T08:19:59Z</published>
    <updated>2012-06-28T11:09:07Z</updated>

    <summary><![CDATA[ &nbsp;Corona, CA &ndash; June 28, 2012 ENow, a Microsoft Independent Software Vendor specializing in the development of software to simplify Microsoft system management, announced the release of ENow Management System 4.7, the award-winning product suite for Exchange, Active Directory,...]]></summary>
    <author>
        <name>Hans Willi Kremer</name>
        <uri>http://www.NETsec.de</uri>
    </author>
    
        <category term="Exchange 2007" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Exchange 2010" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Mailscape" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="blackberrymonitoring" label="Blackberry Monitoring" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="exchangemonitoring" label="Exchange Monitoring" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="sharepointmonitoring" label="Sharepoint Monitoring" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://www.tools4exchange.com/">
        <![CDATA[<p align="left">
	<span style="font-family:arial,helvetica,sans-serif;"><span style="font-size: 12px;">&nbsp;<b>Corona, CA &ndash; June 28, 2012 </b></span></span></p>
<p>
	<span style="font-family:arial,helvetica,sans-serif;"><span style="font-size: 12px;">ENow, a Microsoft Independent Software Vendor specializing in the development of software to simplify Microsoft system management, announced the release of ENow Management System 4.7, the award-winning product suite for Exchange, Active Directory, and SharePoint management. </span></span></p>
]]>
        <![CDATA[<p align="left">
	<span style="font-size:12px;">ENow&#39;s Mailscape Exchange Server product is used in over 35 countries by enterprise companies, including Facebook, NYSE, DirecTV, Blue Cross Blue Shield, and CB Richard Ellis. The product features a dashboard with red, yellow, and green lights indicating the health of each monitored server. The Mailscape solution enables IT support staff to proactively monitor servers in real time. It also provides mobile device reporting for iPads, iPhones, Androids, Blackberries, and other mobile devices. </span></p>
<p>
	<span style="font-size:12px;">The ENow Management system is comprised of Exchange, Active Directory and SharePoint modules. The Exchange module, Mailscape, is an innovative tool that combines all the key elements for Exchange reporting and monitoring in a single solution. ENow&rsquo;s Compass product is a Microsoft Active Directory management solution, and ForeSite is designed to help organizations proactively monitor their SharePoint infrastructure. </span></p>
<p>
	<span style="font-size:12px;">ENow Management System 4.7 includes new enhancements to help IT administrators. Some of the highlights in this release include enhanced Exchange DAG monitoring features that will make it easier for administrators to ensure their high availability Exchange 2010 servers are functional. Several new Active Directory reports were added that will give Active Directory administrators the ability to track down potential security issues and to better understand their topology. In addition, this new release includes a brand new SharePoint module that automatically tests critical SharePoint services, such as Site Availability, Timer Jobs, Search &amp; Index service and content databases. All of SharePoint&rsquo;s underlying core technologies including IIS, Active Directory and SQL are also monitored with ForeSite. </span></p>
<p>
	<span style="font-size:12px;"><b>About ENow </b></span></p>
<p>
	<span style="font-size:12px;">ENow is a Microsoft Silver Independent Software Vendor focused on helping companies implement the latest Microsoft technologies and developing software tools to simplify the job of an IT administrator. The company&rsquo;s flagship product, ENow Management System (EMS), is an award winning monitoring and reporting tool that provides a dashboard view of Exchange, BlackBerry, SharePoint and Active Directory servers. </span></p>
<p>
	<span style="font-size:12px;">For more information:</span></p>
<p>
	<span style="font-size:12px;">Achim Cremer<br />
	NETsec GmbH &amp; Co. KG<br />
	Schillingsstrasse 117,&nbsp; Germany - 52335 D&uuml;ren<br />
	+49 (2421) 998 78 20</span></p>
<p>
	&nbsp;</p>
]]>
    </content>
</entry>

<entry>
    <title>GALsync recommended by MVP Peter Bruzzese</title>
    <link rel="alternate" type="text/html" href="http://www.tools4exchange.com/2012/06/galsync-recommended-by-mvp-peter-bruzzese.html" />
    <id>tag:www.tools4exchange.com,2012://13.1521</id>

    <published>2012-06-12T10:22:12Z</published>
    <updated>2012-06-28T06:04:04Z</updated>

    <summary><![CDATA[ &quot;GALsync is one of those products that does exactly what it advertises. In fact, with the ability to handle free/busy information, combined with so many necessary features (everything from method of export/import to encryption options to specific attribute export...]]></summary>
    <author>
        <name>Hans Willi Kremer</name>
        <uri>http://www.NETsec.de</uri>
    </author>
    
        <category term="GALsync" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://www.tools4exchange.com/">
        <![CDATA[<p>
	&quot;GALsync is one of those products that does exactly what it advertises. In fact, with the ability to handle free/busy information, combined with so many necessary features (everything from method of export/import to encryption options to specific attribute export selection) it goes above and beyond what I expected based on first glance.&quot;</p>
<p>
	says J. Peter Bruzzese&nbsp;at msexchange.org, taking a look at NETsec&#39;s GALsync.</p>
<p>
	<img alt="MSE_Gold_120x701224531037562.gif" class="mt-image-none" height="70" src="http://www.tools4exchange.com/MSE_Gold_120x701224531037562.gif" width="120" /></p>
]]>
        <![CDATA[<p>
	Peter Bruzzese (Triple-MCSE, MCT, MCITP) an Exchange MVP, is the co-founder of ClipTraining, an Exchange and SharePoint Instructor for Train Signal, a well-known technical author for Que/Sams and others, a technical speaker for Techmentor, Connections and, at times, TechEd&hellip; and the Enterprise Windows columnist for InfoWorld.</p>
<p>
	Link:</p>
<p>
	<a href="http://www.msexchange.org/articles_tutorials/product-reviews/product-review-netsecs-galsync.html">http://www.msexchange.org/articles_tutorials/product-reviews/product-review-netsecs-galsync.html</a></p>
<p>
	&nbsp;</p>
]]>
    </content>
</entry>

<entry>
    <title>Creating a shared address space for two different forests.</title>
    <link rel="alternate" type="text/html" href="http://www.tools4exchange.com/2012/06/creating-a-new-e-mail-address-for-two-domains-and-sync-with-galsync.html" />
    <id>tag:www.tools4exchange.com,2012://13.1512</id>

    <published>2012-06-04T06:21:38Z</published>
    <updated>2012-06-04T12:11:46Z</updated>

    <summary><![CDATA[ This Tutorial describes all steps to create a new shared E-Mail address for two different domains. We use GALsync for sychronizing objects, a script to modify the SMTP-addresses and built-in Exchange 2010&nbsp;features. &nbsp;...]]></summary>
    <author>
        <name>Hans Willi Kremer</name>
        <uri>http://www.NETsec.de</uri>
    </author>
    
        <category term="Exchange 2010" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="GALsync" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://www.tools4exchange.com/">
        <![CDATA[<p>
	<br />
	This Tutorial describes all steps to create a new shared E-Mail address for two different domains.</p>
<p>
	We use GALsync for sychronizing objects, a script to modify the SMTP-addresses and built-in Exchange 2010&nbsp;features.</p>
<p>
	&nbsp;</p>
]]>
        <![CDATA[<h2>
	<strong>Test enviroment</strong></h2>
<p>
	4 server machines Windows 2008 R2 Standard Edition English (most recent updates)</p>
<table border="1" cellpadding="1" cellspacing="1" style="width: 450px;">
	<tbody>
		<tr>
			<td>
				FQDN-Server</td>
			<td>
				Funktion</td>
			<td>
				IP-Nummer</td>
			<td>
				Local Firewall</td>
		</tr>
		<tr>
			<td>
				ADC.ForestA.com</td>
			<td>
				<p>
					DC/GC/DNS/</p>
				<p>
					Exchange 2010 SP2</p>
			</td>
			<td>
				172.20.25.100</td>
			<td>
				&nbsp;deactivated</td>
		</tr>
		<tr>
			<td>
				AGS.ForestA.com</td>
			<td>
				&nbsp;GALsync Application</td>
			<td>
				172.20.25.101</td>
			<td>
				&nbsp;deactivated<span style="display: none;">&nbsp;</span></td>
		</tr>
		<tr>
			<td>
				ACL.ForestA.com</td>
			<td>
				Outlook 2010 Client</td>
			<td>
				172.20.25.104</td>
			<td>
				&nbsp;deactivated<span style="display: none;">&nbsp;</span></td>
		</tr>
		<tr>
			<td>
				BDC.ForestB.com</td>
			<td>
				<p>
					&nbsp;DC/GC/DNS/</p>
				<p>
					Exchange 2010 SP2</p>
			</td>
			<td>
				172.20.25.102</td>
			<td>
				&nbsp;deactivated<span style="display: none;">&nbsp;</span></td>
		</tr>
		<tr>
			<td>
				BGS.ForestB.com</td>
			<td>
				GALsync Application</td>
			<td>
				172.20.25.103</td>
			<td>
				&nbsp;deactivated<span style="display: none;">&nbsp;</span></td>
		</tr>
		<tr>
			<td>
				BCL.ForestB.com</td>
			<td>
				Outlook 2010 Client</td>
			<td>
				172.20.25.105</td>
			<td>
				&nbsp;deactivated<span style="display: none;">&nbsp;</span></td>
		</tr>
	</tbody>
</table>
<p>
	&nbsp;</p>
<h2>
	<strong>Setup</strong></h2>
<p>
	In the first step we will setup two different mail organizations. In each mail organization we</p>
<p>
	create some mailbox-enabled user objects, mail-enabled contacts and groups. As well the mail flow is configured between the two organizations.</p>
<p>
	<strong><img alt="bild1_450x313.jpg" class="mt-image-none" height="313" src="http://www.tools4exchange.com/bild1_450x313.jpg" width="450" /></strong></p>
<h3>
	<strong>Configurations</strong></h3>
<p>
	1.Configure Exchange 2010 in forestA a Send-Connector to the other mail organization.</p>
<p>
	2.Configure Exchange 2010 in forestB a Send-Connector to the other mail organization.</p>
<p>
	3.Create an OU Called &quot;GALsyncInternalAccountsA&quot; in forestA, here you create all new objects.</p>
<p>
	4.Create an OU called &sect;forestBImport&quot; in forestA, here you will place all objects from forest.</p>
<p>
	5. Create a mailbox-enabled GALsyncA account in forestA</p>
<p>
	6.Make the GALsyncA Account member of the local admin group on AGS server.</p>
<p>
	7.Create 10 mailbox-activated users in forestA (i.e. UserA01, UserA02...)</p>
<p>
	8.Create 1 mail-activated universal security group: groupA01 in forestA (members: UserA01, UserA02)</p>
<p>
	9.Create 1 mail-activated universal distribution group: groupA02 in forestA (members: UserA03, UserA04)</p>
<p>
	10.Create 1 mail-activated contact: ContactA01 in forestA with an external SMTP address</p>
<p>
	11.Create 1 mail-activated mailbox: Info in forestA (and the SAME name in forestB)</p>
<p>
	12.Confugure Exchange 2010 to Route Messages between ForestA and ForestB; a Send-Connector to the Internet (if wanted) and a Send-Connector to ForestB (required).</p>
<p>
	&nbsp;</p>
<h3>
	<strong>Checks</strong></h3>
<p>
	1. GALsyncA Login with OWA and send mail to the account itself</p>
<p>
	<img alt="bild2_450x413.jpg" class="mt-image-none" height="413" src="http://www.tools4exchange.com/bild2_450x413.jpg" width="450" /></p>
<p>
	2. GALsyncA&nbsp;Login with OWA and send mail to UserA01 (and response)</p>
<p>
	3.GALsyncA Login with Outlook and send mail to ContactA01</p>
<p>
	4.GALsyncA Login with Outlook and send mail to GALsyncB (and response)</p>
<p>
	5.Check if the recipient addresses are stored in MailTo cache of Outlook</p>
<p>
	6.Check if the recipient address is stored in MailTo cache of OWA</p>
<p>
	&nbsp;</p>
<p>
	<em>Do the same with forestB</em></p>
<p>
	&nbsp;</p>
<h2>
	<strong>GALsync</strong></h2>
<p>
	In the second step we setup GALsync and synchronize the directories between both organizations.</p>
<h3>
	Configurations</h3>
<p>
	1. Install GALsync on AGS/BGS (following vendors setup instructions)</p>
<p>
	2. Configure an export of all USERA-objects to the partner forest (using mail as transport)</p>
<p>
	<img alt="bild3_450x256.jpg" class="mt-image-none" height="256" src="http://www.tools4exchange.com/bild3_450x256.jpg" width="450" /></p>
<p>
	3. Configure an import of all USERB-objects to the partner forest (using mail as transport)</p>
<p>
	<img alt="bild4_450x382.jpg" class="mt-image-none" height="382" src="http://www.tools4exchange.com/bild4_450x382.jpg" width="450" /></p>
<p>
	4. Perform an export/import</p>
<p>
	<img alt="bild5_362x600.jpg" class="mt-image-none" height="600" src="http://www.tools4exchange.com/bild5_362x600.jpg" style="width: 382px; height: 402px;" width="362" /></p>
<p>
	<img alt="bild6_383x600.jpg" class="mt-image-none" height="600" src="http://www.tools4exchange.com/bild6_383x600.jpg" style="width: 383px; height: 395px;" width="383" /></p>
<h3>
	<strong>Checks</strong></h3>
<p>
	1. UserA10 sends a mail with Outlook to contactB10 and UserA09 -check results</p>
<p>
	2. UserA08 sends a mail with Outlook to groupB01 and groupA01 - check results</p>
<p>
	3. Check nickname cache in Outlook-UserA10 and OLK-UserA08</p>
<p>
	&nbsp;</p>
<p>
	<em>Do the same with forestB</em></p>
<p>
	&nbsp;</p>
<h2>
	<strong>Adding new common SMTP as secondary proxyaddress</strong></h2>
<p>
	The new shared address will be @new.com</p>
<p>
	1. Configure Exchange 2010 in forestA an accepted domain for @new.com as internal relay domain</p>
<p>
	<img alt="bild7_450x507.jpg" class="mt-image-none" height="507" src="http://www.tools4exchange.com/bild7_450x507.jpg" width="450" /></p>
<p>
	2.Configure Exchange 2010 in forestA to Route Messages fot the Shared Address Space to forestB (add @new.com to the Send-Connector)</p>
<p>
	<img alt="bild8_450x505.jpg" class="mt-image-none" height="505" src="http://www.tools4exchange.com/bild8_450x505.jpg" width="450" /></p>
<p>
	3. Configure Exchange</p>
<p>
	<img alt="accepteddomainnewB_450x254.jpg" class="mt-image-none" height="254" src="http://www.tools4exchange.com/accepteddomainnewB_450x254.jpg" width="450" /></p>
<p>
	4. Add @new.com as secondary address to all mail-enabled objects in forestA (if you use Address Policies, you will NOT modify contacts which have been synched by GALsync!</p>
<p>
	This is because GALsync deactivates the option &quot;automatically update email addresses based on Email address policy&quot;)#</p>
<p>
	<img alt="addnew_450x521.jpg" class="mt-image-none" height="521" src="http://www.tools4exchange.com/addnew_450x521.jpg" width="450" /></p>
<p>
	5. Add @new.com as secondary address to all mail-enabled objects in forestB (if you use Address Policies, you will NOT modify contacts which have been synched by GALsync!</p>
<p>
	This ist becuase GALsync deactivates the option &quot;automatically update email addresses based on Email address policy&quot;)</p>
<p>
	6.With a new GALsync sync the secondary addresses are also transferred (in default configuration)</p>
<p>
	&nbsp;</p>
<h3>
	<strong>Checks</strong></h3>
<p>
	1.UserA01 sends a mail to Internet address - expected result: should have primary address as senders address</p>
<p>
	2.UserB01 sends a mail to Internet address - expected result: should have primary address as senders address</p>
<p>
	&nbsp;</p>
<h3>
	<strong>Comments</strong></h3>
<p>
	You are able with this confuguration to send mail to a <a href="mailto:mailbox@new.com">mailbox@new.com</a> existing in forestA or in forestB. You are NOT able to send a mail from forest to a <a href="mailto:mailbox@new.com">mailbox@new.com</a> which is placed in forestA.</p>
<p>
	If you configure in forestB @new.com as internal relay domain as well pointing to mailserver in forestA, you will produce a loop if someone sends a mail to @new.com-SMTP Address which does neither exist in forestA nor in forestB</p>
<p>
	&nbsp;</p>
<h3>
	<strong>Upcoming Question: How can a user in forestB send mail to a user in forestA?</strong></h3>
<p>
	Answer: As long as on both sides the primary address is forestA or forestB, GALsync uses this address as targetaddress.</p>
<p>
	After the secondary new.com address was made on both sides to the primary SMTP address, the following happens:</p>
<p>
	When performing from source to destination GALsync without changing the configuration, then the objects deleted in the target (as the primary address was [old SMTP]&nbsp; and the objects are completely regerated with their new primary SMTP address.</p>
<p>
	Similarly, the Target Address is set tp the new SMTP address, but should ne the old address as the destination is not able to send back to new.com</p>
<p>
	&nbsp;</p>
<h3>
	<strong>Attention:</strong></h3>
<p>
	It has to be sure, that the Target address is foresta.com or forestb.com and NOT new.com.</p>
<p>
	Rule for the Export from ForestA to ForestB: The Option &quot;Modify target address with domain&quot; (Import-Policy [ForestB], Directory Setting, EmailAddresses) has to be changed in ForestA.com</p>
<p>
	&nbsp;</p>
<p>
	This means: The object having the target address <a href="mailto:xy@neu.com">xy@new.com</a> is sychronized from ForestA to ForestB, but then it gets through the Import Policy in ForestB a target address domain, for which Exchange creates a SendConnector to ForestA.</p>
<p>
	&nbsp;</p>
<h2>
	Script</h2>
<p>
	Write a script that exchanges in the import OU primary against secondary address. You can download a script which does this job here :&nbsp;<a href="http://www.tools4exchange.com/smtpreplace.ps1.txt">smtpreplace.ps1.txt</a>.</p>
<p>
	&nbsp;</p>
<p>
	After the script was created, it is VERY important that you deactivate GALsync. This has to happen because if auto-sync is activated GALsync will replace <a href="mailto:User@foresta.com">User@foresta.com</a> with <a href="mailto:user@new.com">user@new.com</a></p>
<p>
	This would be the worst case and should not happen.</p>
<p>
	Then you can start the Script on ForestA and ForestB. The script will change the secondary smtp address (new.com) with the primary SMTP-Address.</p>
<p>
	<img alt="scriptrun_450x169.jpg" class="mt-image-none" height="169" src="http://www.tools4exchange.com/scriptrun_450x169.jpg" width="450" /></p>
<p>
	NOTE: This method does not work if you have users with the same local part in ForestA and ForestB. You have to check this before running the script because it will fail for this object.</p>
<p>
	After changing the secondary smtp-address and the primary SMTP-address of all GALsync-objects in a defined OU, the Import-Policy of GALsync has to be modified.</p>
<p>
	The Import-Policy has a feature called &ldquo;Modify Target Address&rdquo;, and you have to check this feature and enter the external Domain Part.</p>
<p>
	<img alt="letztes_450x264.jpg" class="mt-image-none" height="264" src="http://www.tools4exchange.com/letztes_450x264.jpg" width="450" /></p>
<p>
	&nbsp;</p>
<p>
	If you did all this steps, you are able to run GALsync without deleting the external SMTP-address of the objects.</p>
<p>
	&nbsp;</p>
<h3>
	Lessons learned</h3>
<p>
	We have learned what we need to create a shared address space for two different forests and which problems exist.</p>
<p>
	Very important is to note, that it is not possible to do this that users in both forest can not have the same user name.</p>
<p>
	&nbsp;</p>
<p>
	&nbsp;</p>
<p>
	&nbsp;</p>
<p>
	&nbsp;</p>
<p>
	&nbsp;</p>
<p>
	&nbsp;</p>
<p>
	&nbsp;</p>
<p>
	&nbsp;</p>
<p>
	&nbsp;</p>
<p>
	&nbsp;</p>
<p>
	&nbsp;</p>
<p>
	&nbsp;</p>
<p>
	&nbsp;</p>
<p>
	&nbsp;</p>
<p>
	&nbsp;</p>
<p>
	&nbsp;</p>
<p>
	&nbsp;</p>
<p>
	&nbsp;</p>
]]>
    </content>
</entry>

<entry>
    <title>Enterprise Permission Reporter controls, documents and reviews all your file system permissions </title>
    <link rel="alternate" type="text/html" href="http://www.tools4exchange.com/2012/04/enterprise-permission-reporter-controls-documents-and-reviews-all-your-file-system-permissions.html" />
    <id>tag:www.tools4exchange.com,2012://13.1502</id>

    <published>2012-04-30T09:50:26Z</published>
    <updated>2012-07-12T15:58:50Z</updated>

    <summary> EPR (Enterprise Permission Reporter) is our NTFS permissions reporting solution. EPR will assist you to meet all challenges you may face regarding regulatory compliances such as HIPAA, FDA, PCI or SOX. EPR lets your control, document and review all...</summary>
    <author>
        <name>Hans Willi Kremer</name>
        <uri>http://www.NETsec.de</uri>
    </author>
    
        <category term="Permission Reporter" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="filesystemreports" label="File System Reports" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="permissionreporter" label="Permission Reporter" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="permissions" label="permissions" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="rights" label="rights" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://www.tools4exchange.com/">
        <![CDATA[<p>
	<span style="font-family: arial,helvetica,sans-serif"><span style="font-size: 12px"><img alt="eprlogo.jpg" class="mt-image-none" height="35" src="http://www.tools4exchange.com/eprlogo.jpg" width="230" /></span></span></p>
<ul>
	<li>
		<span style="font-family: arial,helvetica,sans-serif"><span style="font-size: 12px">EPR (Enterprise Permission Reporter) is our NTFS permissions reporting solution. </span></span></li>
	<li>
		<span style="font-family: arial,helvetica,sans-serif"><span style="font-size: 12px">EPR will assist you to meet all challenges you may face regarding regulatory compliances such as HIPAA, FDA, PCI or SOX. </span></span></li>
	<li>
		<span style="font-family: arial,helvetica,sans-serif"><span style="font-size: 12px">EPR lets your control, document and review all your file system permissions with ease. </span></span></li>
</ul>
]]>
        <![CDATA[<p>
	<span style="font-family: arial,helvetica,sans-serif"><span style="font-size: 12px">The new version of EPR has several enhanced features compared to the old version and has been completely redesigned.</span></span></p>
<p>
	<span style="font-family: arial,helvetica,sans-serif"><span style="font-size: 12px"><strong>Generate Just-In-Time or Scheduled based Reports for your File system</strong></span></span></p>
<ul>
	<li>
		<span style="font-family: arial,helvetica,sans-serif"><span style="font-size: 12px">Includes EVERY Permission set to the folders</span></span></li>
	<li>
		<span style="font-family: arial,helvetica,sans-serif"><span style="font-size: 12px">Breaks down every access to user level, including nested Groups</span></span></li>
</ul>
<p>
	<span style="font-family: arial,helvetica,sans-serif"><span style="font-size: 12px"><strong>Generate Just-In-Time or schedule based reports on the changes between two certain reports</strong></span></span></p>
<ul>
	<li>
		<span style="font-family: arial,helvetica,sans-serif"><span style="font-size: 12px">Scheduled delta reports enables you to report permission changes within a week, month, or any other timespan</span></span></li>
</ul>
<p>
	<span style="font-family: arial,helvetica,sans-serif"><span style="font-size: 12px"><strong>Store your Reports in</strong></span></span></p>
<ul>
	<li>
		<span style="font-family: arial,helvetica,sans-serif"><span style="font-size: 12px">XML - Data will be stored in Excel-Friendly XML Files on your File system</span></span></li>
	<li>
		<span style="font-family: arial,helvetica,sans-serif"><span style="font-size: 12px">SQL - Data will be stored in any SQL Server in your Network</span></span></li>
</ul>
<p>
	&nbsp;</p>
<p>
	<span style="font-family: arial,helvetica,sans-serif"><span style="font-size: 12px"><strong>EPR Structure</strong></span></span></p>
<p>
	<span style="font-family: arial,helvetica,sans-serif"><span style="font-size: 12px">The Main Element in EPR is the Report Definition. This element describes what should be reported, where it should be stored, and what should be send. A Report Definition may also contain several Reports (One Report equals one Run of the Definition) and many Delta Definitions.</span></span></p>
<p>
	<span style="font-family: arial,helvetica,sans-serif"><span style="font-size: 12px"><a href="http://www.netsec.de/en/documents/permission-reporter/">Download manual</a></span></span></p>
<p>
	<span style="font-family: arial,helvetica,sans-serif"><span style="font-size: 12px"><a href="http://www.netsec.de/en/documents/solutions/references/">Some references</a></span></span></p>
<p>
	<span style="font-family: arial,helvetica,sans-serif"><span style="font-size: 12px"><a href="http://www.netsec.de/en/documents/solutions/screenshots/">Some screenshots</a></span></span></p>
<p>
	&nbsp;</p>
<p>
	&nbsp;</p>
<p>
	&nbsp;</p>
]]>
    </content>
</entry>

</feed>
