SlideShare a Scribd company logo
Troubleshooting Exchange Hybrid Deployments 
Michael Van Horenbeeck 
A W A R D W I N N I N G E X C H A N G E M A N A G E M E N T
Michael Van Horenbeeck 
A W A R D W I N N I N G E X C H A N G E M A N A G E M E N T 
• Exchange Server MVP & MCSM 
• Director of Product Research at 
ENow Software 
• Active in the industry for the 
past 13 years 
• Frequent speaker at 
international conferences 
• Blogs at www.vanhybrid.com 
• Member of The UC Architects 
podcast
Agenda 
• Hybrid deployment – architecture overview 
• Common issues and misconceptions 
• Moving mailboxes: the good, the bad and the ugly 
• Keeping ADFS alive 
• DirSync 
• What’s next? 
• Q&A 
A W A R D W I N N I N G E X C H A N G E M A N A G E M E N T
Hybrid Deployment 
Components of a Hybrid deployment (Architecture Overview) 
A W A R D W I N N I N G E X C H A N G E M A N A G E M E N T
What is a hybrid deployment? 
“Two distinct cross-premises Exchange organizations, combined to ‘act’ 
as a single organization through a series of customizations in both 
environments” 
A W A R D W I N N I N G E X C H A N G E M A N A G E M E N T
Hybrid Architecture 
MICROSOFT DATA CENTER INTERNET PERIMETER 
O (CAS) RGANIZATIONAL RELATIONSHIP / 
OAUTH (INTRA-ORG CONNECTOR) 
A W A R D W I N N I N G E X C H A N G E M A N A G E M E N T 
EXCHANGE 
2013 
EXCHANGE 
2013 
(MBX) 
ACTIVE DIRECTORY 
OFFICE 365 TENANT 
EXCHANGE ONLINE 
TENANT 
NETWORK 
INTERNAL NETWORK 
EXCHANGE ON-PREM ORG. 
AZURE AD 
ADFS 
PROXY 
ADFS 
ACTIVE 
DIRECTORY 
DIRSYNC 
SERVER 
ONLINE PROTECTION 
HYBRID MAIL FLOW 
SMTP 
EXCHANGE ONLINE 
AUTHENTICATION 
SERVICE 
EXTERNAL USER 
(O365) 
SYNC 
HTTP(S) 
HTTPS 
HTTPS 
OWA USER 
(O365) 
HTTPS 
MAIL FLOW 
AUTHENTICATION 
SYNCHRONIZATION 
APP. ACCESS (HTTP(S)) 
INTERNAL USER 
(O365) 
EXCHANGE USER 
HTTPS 
INTERNAL OWA USER 
(O365)
Hybrid Building Blocks 
Federation DirSync Secure Transport Mailbox Moves 
• Free/Busy 
• Mailtips 
• Message Tracking 
• eDiscovery 
• … 
• Unified GAL 
• X500 (Mailbox 
Moves) 
• Online Archiving 
A W A R D W I N N I N G E X C H A N G E M A N A G E M E N T 
• TLS encryption 
• Header 
Preservation 
• Cert-based 
security 
• Centralized mail 
flow 
• Mailbox 
Replication 
Service (MRS) 
• Online Moves 
• Fast / Reliable
Common issues & misconceptions 
A W A R D W I N N I N G E X C H A N G E M A N A G E M E N T
DirSync 
• Not synchronizing…at all. 
• Synchronizing but is having issue with a subset of 
accounts due to: 
• Duplicates 
• Illegal characters (corrupted items etc…) 
A W A R D W I N N I N G E X C H A N G E M A N A G E M E N T
How DirSync works 
DirSync 
Active Directory 
METAVERSE 
A W A R D W I N N I N G E X C H A N G E M A N A G E M E N T
DEMO 
A W A R D W I N N I N G E X C H A N G E M A N A G E M E N T
Active Directory Federation Services 
• Error messages can be cryptic… 
• Troubleshooting is not easy 
• You only have “half” of the story 
• Different authentication flows 
• 3rd party tooling really needed to help figuring out 
what happen(s)(ed) 
A W A R D W I N N I N G E X C H A N G E M A N A G E M E N T
DEMO 
A W A R D W I N N I N G E X C H A N G E M A N A G E M E N T
Troubleshooting AD FS Summary 
• Not easy 
• Use tools like e.g. Fiddler 
• Enable Debug Logging in Event Viewer 
• Pair AD FS Proxy w/ ADFS for easier troubleshooting 
• Understanding different authentication flows is important 
A W A R D W I N N I N G E X C H A N G E M A N A G E M E N T
Exchange Federation 
•Many components to take a look at 
• Microsoft Federation Gateway trust 
• Organization Relationship (local) 
• Organization Relationship (remote) 
•Domain Federation Information 
• Autodiscover 
A W A R D W I N N I N G E X C H A N G E M A N A G E M E N T
How Exchange Federation works 
A W A R D W I N N I N G E X C H A N G E M A N A G E M E N T
DEMO 
A W A R D W I N N I N G E X C H A N G E M A N A G E M E N T
Avoid Troubleshooting 
Why monitoring makes sense in a clouded world… 
A W A R D W I N N I N G E X C H A N G E M A N A G E M E N T
What components do I need to monitor? 
• Directory Synchronization 
• Identity Federation (if applicable) 
• Exchange Federation 
• Certificates 
• Connectivity 
A W A R D W I N N I N G E X C H A N G E M A N A G E M E N T 
Featured as Messaging and Unified 
Communications Award Finalist
About ENow Software 
Download Mailscape for Exchange Online Free Trial: 
bit.ly/Mailscape-Hybrid 
A W A R D W I N N I N G E X C H A N G E M A N A G E M E N T
Q&A 
Thank you! 
www.enowsoftware.com 
A W A R D W I N N I N G E X C H A N G E M A N A G E M E N T

More Related Content

PPTX
CoLabora - Hybrid inside out - Nov 2015
PPTX
Microsoft SharePoint Cloud presentation
PPTX
What Exchange Administrators Need to Know About Hybrid Deployments
PPTX
Office 365: How to Get a Foothold in the Cloud
PPTX
Mct summit na deploying a hybrid exchange 2010-office365 platform
PPTX
Azure Active Directory Identity
PPTX
Tips and Tricks for Migrating to Exchange Online
PPTX
SharePoint for Government
CoLabora - Hybrid inside out - Nov 2015
Microsoft SharePoint Cloud presentation
What Exchange Administrators Need to Know About Hybrid Deployments
Office 365: How to Get a Foothold in the Cloud
Mct summit na deploying a hybrid exchange 2010-office365 platform
Azure Active Directory Identity
Tips and Tricks for Migrating to Exchange Online
SharePoint for Government

What's hot (20)

PDF
Microsoft OneDrive For Business
PDF
Factsheet_RS
PPTX
Microsoft Flow : what you need to know before starting a real project
PPTX
Hybrid connectivity options with the microsoft cloud
PDF
Toni bernal citrix day 2012 overview v2
PPTX
Exchange online real world migration challenges
PPTX
JAXSPUG April 2016 - Staying in the Know with Office 365
PPTX
Connecting Mobile Services to On-Premises Resources Using Hybrid Connections
PPTX
SPSVienna Office 365 Tenant to Tenant Migration - a complete Survial Guide
PPTX
Managing OneDrive for Business
PPTX
Introduction to Hybrid Connections
PPTX
Hybrid integration and the power of Azure services (Jon Fancey at CONNECT17)
PPTX
Microservices & Streaming Data
PDF
GWAVACon - Migration into Office 365 Cloud
PPTX
Hybrid Integration with SAP
PPTX
Ensuring Successful Office 365 Tenant to Tenant Migration SPS Cambridge 2017...
ODP
Open-Xchange - OX App Suite: Email und Kollaboration
PDF
Cloud Trends for 2017 and Actions You Can Take Now
PPTX
Building your microsite with Documents & Sites
PDF
How to Manage VMware vSphere Like AWS and Azure
Microsoft OneDrive For Business
Factsheet_RS
Microsoft Flow : what you need to know before starting a real project
Hybrid connectivity options with the microsoft cloud
Toni bernal citrix day 2012 overview v2
Exchange online real world migration challenges
JAXSPUG April 2016 - Staying in the Know with Office 365
Connecting Mobile Services to On-Premises Resources Using Hybrid Connections
SPSVienna Office 365 Tenant to Tenant Migration - a complete Survial Guide
Managing OneDrive for Business
Introduction to Hybrid Connections
Hybrid integration and the power of Azure services (Jon Fancey at CONNECT17)
Microservices & Streaming Data
GWAVACon - Migration into Office 365 Cloud
Hybrid Integration with SAP
Ensuring Successful Office 365 Tenant to Tenant Migration SPS Cambridge 2017...
Open-Xchange - OX App Suite: Email und Kollaboration
Cloud Trends for 2017 and Actions You Can Take Now
Building your microsite with Documents & Sites
How to Manage VMware vSphere Like AWS and Azure
Ad

Similar to Troubleshooting Exchange Hybrid Deployments (20)

PPTX
The Future of Exchange (Online)
PDF
SOA Latam 2015
PPTX
Troubleshooting Exchange Hybrid Deployments
PDF
How to Transform Into a Data-Driven Organization
PDF
Service mesh in Microservice World to Manage end to end service communications
PDF
[Partner TechShift 2017] AWS와 함께하는 글로벌 클라우드 소프트웨어 사업
PDF
Everything you want to know about microservices
PPTX
Azure Comsos DB Use Cases
PDF
Webinar - How and Why Your Library Should Move to HTTPS 2018-07-17
PDF
Raleigh Kafka Meetup - DDD, ES, and CQRS
PPTX
Deploy exchange 2016 on prem hybrid final
PDF
SAI - Serverless Integration Architectures - 09/2019
PPTX
Introducing Hyperleger
PPTX
Introduction to Microsoft Flow - Introduction & advanced scenarios
PDF
Brighttalk understanding the promise of sde - final
PPTX
Building Event Driven Architectures with Kafka and Cloud Events (Dan Rosanova...
PPSX
RISC Networks CloudScape Product Overview
PDF
New Era of Software with modern Application Security v1.0
PPTX
Neo4j GraphTalk Florence - Introduction to the Neo4j Graph Platform
PDF
PLNOG23 - Jarosław Zieliński - AI w praktyce – jak zachęciłem sztuczną inteli...
The Future of Exchange (Online)
SOA Latam 2015
Troubleshooting Exchange Hybrid Deployments
How to Transform Into a Data-Driven Organization
Service mesh in Microservice World to Manage end to end service communications
[Partner TechShift 2017] AWS와 함께하는 글로벌 클라우드 소프트웨어 사업
Everything you want to know about microservices
Azure Comsos DB Use Cases
Webinar - How and Why Your Library Should Move to HTTPS 2018-07-17
Raleigh Kafka Meetup - DDD, ES, and CQRS
Deploy exchange 2016 on prem hybrid final
SAI - Serverless Integration Architectures - 09/2019
Introducing Hyperleger
Introduction to Microsoft Flow - Introduction & advanced scenarios
Brighttalk understanding the promise of sde - final
Building Event Driven Architectures with Kafka and Cloud Events (Dan Rosanova...
RISC Networks CloudScape Product Overview
New Era of Software with modern Application Security v1.0
Neo4j GraphTalk Florence - Introduction to the Neo4j Graph Platform
PLNOG23 - Jarosław Zieliński - AI w praktyce – jak zachęciłem sztuczną inteli...
Ad

Recently uploaded (20)

PPT
Teaching material agriculture food technology
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PPTX
Spectroscopy.pptx food analysis technology
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PPTX
Cloud computing and distributed systems.
PDF
Electronic commerce courselecture one. Pdf
PDF
Review of recent advances in non-invasive hemoglobin estimation
PDF
Machine learning based COVID-19 study performance prediction
PPTX
sap open course for s4hana steps from ECC to s4
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
Approach and Philosophy of On baking technology
PPTX
Programs and apps: productivity, graphics, security and other tools
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
Teaching material agriculture food technology
Digital-Transformation-Roadmap-for-Companies.pptx
Unlocking AI with Model Context Protocol (MCP)
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Network Security Unit 5.pdf for BCA BBA.
Reach Out and Touch Someone: Haptics and Empathic Computing
Spectroscopy.pptx food analysis technology
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Cloud computing and distributed systems.
Electronic commerce courselecture one. Pdf
Review of recent advances in non-invasive hemoglobin estimation
Machine learning based COVID-19 study performance prediction
sap open course for s4hana steps from ECC to s4
Mobile App Security Testing_ A Comprehensive Guide.pdf
Dropbox Q2 2025 Financial Results & Investor Presentation
Encapsulation_ Review paper, used for researhc scholars
Approach and Philosophy of On baking technology
Programs and apps: productivity, graphics, security and other tools
NewMind AI Weekly Chronicles - August'25 Week I
Profit Center Accounting in SAP S/4HANA, S4F28 Col11

Troubleshooting Exchange Hybrid Deployments

  • 1. Troubleshooting Exchange Hybrid Deployments Michael Van Horenbeeck A W A R D W I N N I N G E X C H A N G E M A N A G E M E N T
  • 2. Michael Van Horenbeeck A W A R D W I N N I N G E X C H A N G E M A N A G E M E N T • Exchange Server MVP & MCSM • Director of Product Research at ENow Software • Active in the industry for the past 13 years • Frequent speaker at international conferences • Blogs at www.vanhybrid.com • Member of The UC Architects podcast
  • 3. Agenda • Hybrid deployment – architecture overview • Common issues and misconceptions • Moving mailboxes: the good, the bad and the ugly • Keeping ADFS alive • DirSync • What’s next? • Q&A A W A R D W I N N I N G E X C H A N G E M A N A G E M E N T
  • 4. Hybrid Deployment Components of a Hybrid deployment (Architecture Overview) A W A R D W I N N I N G E X C H A N G E M A N A G E M E N T
  • 5. What is a hybrid deployment? “Two distinct cross-premises Exchange organizations, combined to ‘act’ as a single organization through a series of customizations in both environments” A W A R D W I N N I N G E X C H A N G E M A N A G E M E N T
  • 6. Hybrid Architecture MICROSOFT DATA CENTER INTERNET PERIMETER O (CAS) RGANIZATIONAL RELATIONSHIP / OAUTH (INTRA-ORG CONNECTOR) A W A R D W I N N I N G E X C H A N G E M A N A G E M E N T EXCHANGE 2013 EXCHANGE 2013 (MBX) ACTIVE DIRECTORY OFFICE 365 TENANT EXCHANGE ONLINE TENANT NETWORK INTERNAL NETWORK EXCHANGE ON-PREM ORG. AZURE AD ADFS PROXY ADFS ACTIVE DIRECTORY DIRSYNC SERVER ONLINE PROTECTION HYBRID MAIL FLOW SMTP EXCHANGE ONLINE AUTHENTICATION SERVICE EXTERNAL USER (O365) SYNC HTTP(S) HTTPS HTTPS OWA USER (O365) HTTPS MAIL FLOW AUTHENTICATION SYNCHRONIZATION APP. ACCESS (HTTP(S)) INTERNAL USER (O365) EXCHANGE USER HTTPS INTERNAL OWA USER (O365)
  • 7. Hybrid Building Blocks Federation DirSync Secure Transport Mailbox Moves • Free/Busy • Mailtips • Message Tracking • eDiscovery • … • Unified GAL • X500 (Mailbox Moves) • Online Archiving A W A R D W I N N I N G E X C H A N G E M A N A G E M E N T • TLS encryption • Header Preservation • Cert-based security • Centralized mail flow • Mailbox Replication Service (MRS) • Online Moves • Fast / Reliable
  • 8. Common issues & misconceptions A W A R D W I N N I N G E X C H A N G E M A N A G E M E N T
  • 9. DirSync • Not synchronizing…at all. • Synchronizing but is having issue with a subset of accounts due to: • Duplicates • Illegal characters (corrupted items etc…) A W A R D W I N N I N G E X C H A N G E M A N A G E M E N T
  • 10. How DirSync works DirSync Active Directory METAVERSE A W A R D W I N N I N G E X C H A N G E M A N A G E M E N T
  • 11. DEMO A W A R D W I N N I N G E X C H A N G E M A N A G E M E N T
  • 12. Active Directory Federation Services • Error messages can be cryptic… • Troubleshooting is not easy • You only have “half” of the story • Different authentication flows • 3rd party tooling really needed to help figuring out what happen(s)(ed) A W A R D W I N N I N G E X C H A N G E M A N A G E M E N T
  • 13. DEMO A W A R D W I N N I N G E X C H A N G E M A N A G E M E N T
  • 14. Troubleshooting AD FS Summary • Not easy • Use tools like e.g. Fiddler • Enable Debug Logging in Event Viewer • Pair AD FS Proxy w/ ADFS for easier troubleshooting • Understanding different authentication flows is important A W A R D W I N N I N G E X C H A N G E M A N A G E M E N T
  • 15. Exchange Federation •Many components to take a look at • Microsoft Federation Gateway trust • Organization Relationship (local) • Organization Relationship (remote) •Domain Federation Information • Autodiscover A W A R D W I N N I N G E X C H A N G E M A N A G E M E N T
  • 16. How Exchange Federation works A W A R D W I N N I N G E X C H A N G E M A N A G E M E N T
  • 17. DEMO A W A R D W I N N I N G E X C H A N G E M A N A G E M E N T
  • 18. Avoid Troubleshooting Why monitoring makes sense in a clouded world… A W A R D W I N N I N G E X C H A N G E M A N A G E M E N T
  • 19. What components do I need to monitor? • Directory Synchronization • Identity Federation (if applicable) • Exchange Federation • Certificates • Connectivity A W A R D W I N N I N G E X C H A N G E M A N A G E M E N T Featured as Messaging and Unified Communications Award Finalist
  • 20. About ENow Software Download Mailscape for Exchange Online Free Trial: bit.ly/Mailscape-Hybrid A W A R D W I N N I N G E X C H A N G E M A N A G E M E N T
  • 21. Q&A Thank you! www.enowsoftware.com A W A R D W I N N I N G E X C H A N G E M A N A G E M E N T

Editor's Notes

  • #16: http://social.technet.microsoft.com/wiki/contents/articles/24544.how-to-avoid-syncing-accidental-deletes-to-the-cloud-directory.aspx