Showing posts with label Exchange. Show all posts
Showing posts with label Exchange. Show all posts

Sunday, October 26, 2008

Exchange Server 2007 New Property Sets

Property sets in Exchange Server 2007 for attribute grouping enables access control for specific object properties. Property sets use one single Access Control Entry (ACE) instead of an ACE for each individual property.

Exchange Server 2007 creates two new property sets exclusively for itself and doesn’t use existing Active Directory property sets.

Exchange Server 2007 SP1 Schema Extensions
Exchange Server 2007 SP1 comes with a lot of additional Schema extensions:

ms-Exch-Foreign-Forest-Public-Folder-Admin-USG-Sid,

ms-Exch-Internal-NLB-Bypass-Host-Name,

ms-Exch-Mobile-Additional-Flags,

ms-Exch-Mobile-Allow-Bluetooth,

ms-Exch-Mobile-Allow-SMIME-Encryption-Algorithm-Negotiation,

ms-Exch-Mobile-Approved-Application-List,

ms-Exch-Mobile-Max-Calendar-Age-Filter,

ms-Exch-Mobile-Max-Email-Age-Filter,

ms-Exch-Mobile-Max-Email-Body-Truncation-Size,

ms-Exch-Mobile-Max-Email-HTML-Body-Truncation-Size,

ms-Exch-Mobile-Min-Device-Password-Complex-Characters,

ms-Exch-Mobile-Require-Encryption-SMIME-Algorithm,

ms-Exch-Mobile-Require-Signed-SMIME-Algorithm,

ms-Exch-Mobile-Unapproved-In-ROM-Application-List,

ms-Exch-Standby-Copy-Machines,

Tuesday, September 02, 2008

Completely Removing a Mailbox Enabled User's Mailbox

If an object is a mailbox enabled user with a valid mailbox, the "Delete Mailbox" option will be available only if there is a mailbox (so a distribution list would have a "Remove email address" option instead).

The "Remove Exchange Attributes" option is available for ANY type of recipient object, mail enabled or not. This option is extremely useful when there is a need to "clear" the attributes in case that some of them were damaged or not valid for some reason. Let's say there is a mailbox enabled user that had some of his attributes changed by some process, and because of that, you cannot use the "Delete Mailbox" option. You can always run AdSearch and "clear out" the values so you can start fresh with mailbox enabling that user again.

Remove Exchange Attributes removes the following attributes as long as they actually exist as available attributes of that schema object:

You can use ADSearch to report the status of each attribute by copying the list below and adding it to the objects attribute properties.

adminDisplayName
altRecipient
authOrig
autoReplyMessage (ILS Settings)
deletedItemFlags
delivContLength
deliverAndRedirect
displayNamePrintable
dLMemDefault
dLMemRejectPerms
dLMemSubmitPerms
extensionAttribute1
extensionAttribute10
extensionAttribute11
extensionAttribute12
extensionAttribute13
extensionAttribute14
extensionAttribute15
extensionAttribute2
extensionAttribute3
extensionAttribute4
extensionAttribute5
extensionAttribute6
extensionAttribute7
extensionAttribute8
extensionAttribute9
folderPathname (Outlook Web Access Server)
garbageCollPeriod
homeMDB (Exchange Mailbox Store)
homeMTA
internetEncoding
legacyExchangeDN
mail (E-Mail Address)
mailNickname (Alias)
mAPIRecipient
mDBOverHardQuotaLimit
mDBOverQuotaLimit
mDBStorageQuota
mDBUseDefaults
msExchADCGlobalNames
msExchControllingZone
msExchExpansionServerName
msExchFBURL
msExchHideFromAddressLists
msExchHomeServerName (Exchange Home Server)
msExchMailboxGuid
msExchMailboxSecurityDescriptor
msExchPoliciesExcluded
msExchPoliciesIncluded
msExchRecipLimit
msExchResourceGUID
protocolSettings
proxyAddresses (Proxy Addresses)
publicDelegates
securityProtocol
showInAddressBook
submissionContLength
targetAddress
textEncodedORAddress
unauthOrig

In addition to removing the attributes above, the Delete Mailbox option also removes the mailbox information from the dsaccess cache. Note that this actually leaves the mailbox in place with the expectation that the mailbox cleanup task will take care of it at the appropriate time. So the mailbox is actually NOT deleted (purged) from the Information Store as part of this process. Although it will be purged by the mailbox cleanup task later, or as specified by the "Deletion settings" for mailboxes on the database's Limits tab in ESM.

Thursday, October 25, 2007

Deleting Mailbox-Enabled Users

If you choose to delete a mailbox-enabled user or group, the mailbox in the message store of the Exhange 200x server will not be disabled. To disable the mailbox, you should clear the following attributes in Active Directory before deleting the account:

Attributes to Clear

homeMDB,
mail,
mailNickname,
homeMTA,
legacyExchangeDN,
msExchHomeServerName,
msExchMailboxGuid,
msExchPoliciesIncluded,
proxyAddresses,
textEncodedORAddress

By clearing these 9 attributes from the user properties before deleting the user account, Active Directory will notify the Exchange 200x server that mailbox attached to this account should be disabled.