SlideShare a Scribd company logo
What Exchange Administrators Need to Know
about Hybrid Deployments
Michael Van Horenbeeck
Agenda
• What’s life like for an admin in a Hybrid deployment?
• Common issues and misconceptions
• Moving mailboxes: the good, the bad and the ugly
• Keeping ADFS alive
• DirSync
• What’s next?
• Q&A
What is a Hybrid deployment?
Components of a Hybrid deployment
What is a hybrid deployment?
“Two distinct cross-premises Exchange organizations, combined to ‘act’
as a single organization through a series of customizations in both
environments”
HybridArchitecture
ACTIVE DIRECTORY
OFFICE 365 TENANT
EXCHANGE ONLINE
TENANT
MICROSOFT DATA CENTER INTERNET PERIMETER
NETWORK
INTERNAL NETWORK
EXCHANGE ON-PREM ORG.
AZURE AD
ADFS
PROXY
ADFS
ACTIVE
DIRECTORY
DIRSYNC
SERVER
EXCHANGE
2013
(CAS)ORGANIZATIONAL RELATIONSHIP /
OAUTH (INTRA-ORG CONNECTOR)
EXCHANGE
2013
(MBX)
ONLINE PROTECTION
HYBRID MAIL FLOW
SMTP
EXCHANGE ONLINE
AUTHENTICATION
SERVICE
EXTERNAL USER
(O365)
SYNC
HTTP(S)
HTTPS
HTTPS
OWA USER
(O365)
HTTPS
MAIL FLOW
AUTHENTICATION
SYNCHRONIZATION
APP. ACCESS (HTTP(S))
INTERNAL USER
(O365)
EXCHANGE USER
HTTPS
INTERNAL OWA USER
(O365)
Hybrid Building Blocks
Federation DirSync Secure Transport Mailbox Moves
• Free/Busy
• Mailtips
• Message Tracking
• eDiscovery
• …
• Unified GAL
• X500 (Mailbox
Moves)
• Online Archiving
• TLS encryption
• Header
Preservation
• Cert-based
security
• Centralized mail
flow
• Mailbox
Replication
Service (MRS)
• Online Moves
• Fast / Reliable
An admin’s life in the cloud…
What tasks does an admin commonly
execute?
• Daily Exchange Management
• Identity Management
• Moving Mailboxes
• Patching
• Monitoring
• Troubleshooting
Identity Management
• All user objects are managed on-premises (through
Exchange) because of DirSync
• Account for the DirSync interval (or force DirSync to
run)
• Can be important if you want to “quickly” do things.
• Watch out for accidental deletions!
• New DirSync feature might help…
DirSync Accidental Deletion
• New in version 6765.0006 (released end of May)
• If the number of objects being deleted exceeds a configurable
threshold, DirSync won’t sync the deletions to Azure AD.
• To enable the feature:
• Set-PreventAccidentalDeletes –Enable –ObjectDeletionThreshold <value>
Monitoring Hybrid Deployments
• New architecture paradigm, requires new way of thinking about
monitoring
• You don’t care about Microsoft’s side of the story
• End-user service availability is key (but it’s always been like that,
right?)
• Consider monitoring through a series of both Active and Passive tests
• Active tests allow you to be proactive
• Passive tests give you great feedback (counters…)
What components do I need to monitor?
• Directory Synchronization
• Identity Federation (if applicable)
• Exchange Federation
• Certificates
• Connectivity
Featured as Messaging and Unified
Communications Award Finalist
Patching
• Important to stay ‘current’ with patch levels (Exchange, DirSync) in
order to remain supported
• Challenge to keep up with cloud-cadence (CU’s are typically released
every quarter…)
• You can use RSS feeds and the Office Blog to stay up to date with the
latest and the greatest. Recently released Microsoft roadmap blog
might also help: http://office.microsoft.com/en-us/products/office-
365-roadmap-FX104343353.aspx
Moving Mailboxes
Moving Mailboxes
Exchange
On-Prem
“The Internet”
Exchange
Online
(Office 365)
MRS
Admin
Moving Mailboxes
• A trivial action, but touches many different components in Exchange
• Make sure the Mailbox Replication Service Proxy [MRS Proxy] is enabled on the
internet-facing Exchange Web Services
• Before a mailbox can be moved, certain ‘attributes’ need to be available on
the object:
• Prior to a mailbox move, check that the object have the correct attributes set (x500 +
Proxy Addresses)
• Because of the cross-premises nature of a hybrid deployment, certain
features won’t work after a mailbox move
• Watch out for permissions and large items in mailbox!
Mailbox move limitations
• Items larger than +/- 25 MB won’t be moved because of the item size
limits in place in Office 365.
• You can export them using this script
• Cross-premises permissions (currently?) are not supported. Make
sure to move associated mailboxes at the same time.
• Potential impact of your ‘pilot’ group.
Dealing with High Availability
What it takes to make a hybrid deployment highly available
What components should be highly available?
• Exchange (Hybrid Servers)
• AD FS (if deployed)
• Connectivity
“Hybrid Server” HA
• Deploy at least two hybrid servers
• Add site resiliency by deploying in two distinct physical locations
• Load balance incoming request through a LB device
Site 1 Site 2
Connectivity
Domain
Controller
Exchange
CAS/MBX
Exchange
CAS/MBX
INTERNE
T
Domain
Controller
HA Load Balancer pair
DirSync / Azure AD Sync
• No urgent need for high availability
• You can run w/o DirSync for a (short) period of time, although that would
reduce (admin-)functionality temporarily
• In case you cannot afford temporary functionality loss (SLAs?)
• Deploy a ‘standby’ DirSync server
• Consider deploying SQL (default choice for large enterprises anyway)
• Easier to backup
Active Directory Federation Services
• Critical to operations; No ADFS = No user logon possible
• Must be deployed HA – in all possible ways
• Deploy ADFS cluster; spread across sites to add site resiliency
• Can be costly…
AD FS HA
AD FS Topology
AD FS
Proxy
AD FS
Domain
Controller
INTERNET
AD FS
AD FS
Proxy
LoadBalancer
LoadBalancer
Domain
Controller
FW
FW
Troubleshooting
An overview of the most common scenarios
Troubleshooting AD FS
• Not easy.
• Use tools like e.g. Fiddler
• Enable Debug Logging in Event Viewer
• Pair AD FS Proxy w/ ADFS for easier troubleshooting
• Understanding different authentication flows is important
Enabling Debug Log
• Open Event Viewer
• Click View > Show Analytic and
Debug Logs
• Right-click Debug under AD FS
Tracing and click enable
• Reproduce issue
Exchange Federation
• Multiple areas where things can go wrong…
• Verify that Federation Information can be retrieved (get-
federationinformation)
• Test Organization Relationships (test-organizationrelationship)
• Verify Federation trust (Test-FederationTrust)
• When using oAuth: Test-oAuthConnectivity
Mailbox Moves
• Error message is critical; contains useful information
• Verify connectivity; e.g. MRS Proxy enabled?
• Use the Test-MigrationServerAvailability for more insights
DirSync
• No news = good news 
• Take a look into the console (miisclient.exe located in installation
folder)
• Check Permissions (inherit permissions enabled?)
About ENow Software
Download Mailscape
for Exchange Online
Free Trial
http://bit.ly/Mailscape-Hybrid
Q&A
Thank you!
www.enowsoftware.com

More Related Content

PDF
Project Sherpa: How RightScale Went All in on Docker
PDF
How IT at Getty Images Brokers Cloud Services
PDF
Beyond PaaS v.s IaaS: How to Manage Both
PDF
Cloud Orchestration with RightScale Cloud Workflow
PPTX
Vitalii Korzh "Managed Workflows or How to Master Data"
PPTX
What are clouds made from
PPTX
Migrating and modernizing your data estate to Azure with Data Migration Services
PPTX
Cloud Computing101 Azure, updated june 2017
Project Sherpa: How RightScale Went All in on Docker
How IT at Getty Images Brokers Cloud Services
Beyond PaaS v.s IaaS: How to Manage Both
Cloud Orchestration with RightScale Cloud Workflow
Vitalii Korzh "Managed Workflows or How to Master Data"
What are clouds made from
Migrating and modernizing your data estate to Azure with Data Migration Services
Cloud Computing101 Azure, updated june 2017

What's hot (18)

PDF
AWS vs. Azure vs. Google vs. SoftLayer: Network, Storage and DBaaS
PPTX
Migrate SQL Server 2008 R2 to Azure Cloud
PDF
Automating Cloud Operations: Tips from Managed Services
PDF
AWS Data migration services
PPTX
Managing your virtual environment with System Center & Windows Server 2012
PDF
What Every MSP Needs to Know for Cloud Success
PPTX
Service Fabric – building tomorrows applications today
PPTX
Windows Azure Overview for IT Professionals
PPTX
Tokyo azure meetup #12 service fabric internals
PDF
RightScale Webinar: How to Cloud Enable vSphere with RightScale
PPTX
Key Design Considerations Private and Hybrid Clouds - RightScale Compute 2013
PPTX
Serverless Patterns
PPTX
Blockchain for the DBA and Data Professional
PPTX
PaaSport to Paradise: Back to the Future with SSIS in Azure Data Factory
PDF
Cassandra-as-a-Service
PPTX
Blockchain for the DBA and Data Professional
PPTX
Configuration in azure done right
PPTX
Tokyo azure meetup #2 big data made easy
AWS vs. Azure vs. Google vs. SoftLayer: Network, Storage and DBaaS
Migrate SQL Server 2008 R2 to Azure Cloud
Automating Cloud Operations: Tips from Managed Services
AWS Data migration services
Managing your virtual environment with System Center & Windows Server 2012
What Every MSP Needs to Know for Cloud Success
Service Fabric – building tomorrows applications today
Windows Azure Overview for IT Professionals
Tokyo azure meetup #12 service fabric internals
RightScale Webinar: How to Cloud Enable vSphere with RightScale
Key Design Considerations Private and Hybrid Clouds - RightScale Compute 2013
Serverless Patterns
Blockchain for the DBA and Data Professional
PaaSport to Paradise: Back to the Future with SSIS in Azure Data Factory
Cassandra-as-a-Service
Blockchain for the DBA and Data Professional
Configuration in azure done right
Tokyo azure meetup #2 big data made easy
Ad

Similar to What Exchange Administrators Need to Know About Hybrid Deployments (20)

PPTX
Troubleshooting Exchange Hybrid Deployments
PDF
Best practices When Migrating to Office 365
PPTX
Troubleshooting Exchange Hybrid Deployments
PPTX
Take a Leap into the Connected Cloud; 3 Trending Hybrid Cloud Scenarios
PPTX
Preparing for an Exchange 2013 Hybrid
PPTX
Deploying Exchange 2013 in Hybrid Mode
PPTX
Tech days 2013 - Deploying a hybrid configuration w/ Exchange 2013
PPTX
2011 - From Zero to productivity (Tech Ed 2011)
PPTX
10135 b 13
PDF
Microsoft Exchange 2013 Platform Options
PPTX
Exchange Hybrid - Everything you need to know
PPTX
Office 365 UK User Group London 4th September 2012
PPSX
Office connect hybrid microsoft exchange
PPTX
Exchange online real world migration challenges
PPTX
office365-2-exchange deployment - blue
PPTX
Migrating Exchange - ExpertsLive 2018
PPTX
CoLabora - Hybrid inside out - Nov 2015
PPTX
Directory Synchronization Single Sign-On in Office 365
PPTX
Office 365 Fast track
PDF
Today's Unified Communications: To upgrade, coexist, or go 'all in' with the ...
Troubleshooting Exchange Hybrid Deployments
Best practices When Migrating to Office 365
Troubleshooting Exchange Hybrid Deployments
Take a Leap into the Connected Cloud; 3 Trending Hybrid Cloud Scenarios
Preparing for an Exchange 2013 Hybrid
Deploying Exchange 2013 in Hybrid Mode
Tech days 2013 - Deploying a hybrid configuration w/ Exchange 2013
2011 - From Zero to productivity (Tech Ed 2011)
10135 b 13
Microsoft Exchange 2013 Platform Options
Exchange Hybrid - Everything you need to know
Office 365 UK User Group London 4th September 2012
Office connect hybrid microsoft exchange
Exchange online real world migration challenges
office365-2-exchange deployment - blue
Migrating Exchange - ExpertsLive 2018
CoLabora - Hybrid inside out - Nov 2015
Directory Synchronization Single Sign-On in Office 365
Office 365 Fast track
Today's Unified Communications: To upgrade, coexist, or go 'all in' with the ...
Ad

Recently uploaded (20)

PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PPTX
MYSQL Presentation for SQL database connectivity
PDF
Empathic Computing: Creating Shared Understanding
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PDF
cuic standard and advanced reporting.pdf
PDF
Electronic commerce courselecture one. Pdf
PPTX
Programs and apps: productivity, graphics, security and other tools
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PPTX
Spectroscopy.pptx food analysis technology
PDF
Review of recent advances in non-invasive hemoglobin estimation
PDF
Encapsulation_ Review paper, used for researhc scholars
PPTX
Cloud computing and distributed systems.
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
MYSQL Presentation for SQL database connectivity
Empathic Computing: Creating Shared Understanding
Diabetes mellitus diagnosis method based random forest with bat algorithm
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
NewMind AI Weekly Chronicles - August'25 Week I
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
cuic standard and advanced reporting.pdf
Electronic commerce courselecture one. Pdf
Programs and apps: productivity, graphics, security and other tools
Building Integrated photovoltaic BIPV_UPV.pdf
Chapter 3 Spatial Domain Image Processing.pdf
20250228 LYD VKU AI Blended-Learning.pptx
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
Spectroscopy.pptx food analysis technology
Review of recent advances in non-invasive hemoglobin estimation
Encapsulation_ Review paper, used for researhc scholars
Cloud computing and distributed systems.

What Exchange Administrators Need to Know About Hybrid Deployments

  • 1. What Exchange Administrators Need to Know about Hybrid Deployments Michael Van Horenbeeck
  • 2. Agenda • What’s life like for an admin in a Hybrid deployment? • Common issues and misconceptions • Moving mailboxes: the good, the bad and the ugly • Keeping ADFS alive • DirSync • What’s next? • Q&A
  • 3. What is a Hybrid deployment? Components of a Hybrid deployment
  • 4. What is a hybrid deployment? “Two distinct cross-premises Exchange organizations, combined to ‘act’ as a single organization through a series of customizations in both environments”
  • 5. HybridArchitecture ACTIVE DIRECTORY OFFICE 365 TENANT EXCHANGE ONLINE TENANT MICROSOFT DATA CENTER INTERNET PERIMETER NETWORK INTERNAL NETWORK EXCHANGE ON-PREM ORG. AZURE AD ADFS PROXY ADFS ACTIVE DIRECTORY DIRSYNC SERVER EXCHANGE 2013 (CAS)ORGANIZATIONAL RELATIONSHIP / OAUTH (INTRA-ORG CONNECTOR) EXCHANGE 2013 (MBX) ONLINE PROTECTION HYBRID MAIL FLOW SMTP EXCHANGE ONLINE AUTHENTICATION SERVICE EXTERNAL USER (O365) SYNC HTTP(S) HTTPS HTTPS OWA USER (O365) HTTPS MAIL FLOW AUTHENTICATION SYNCHRONIZATION APP. ACCESS (HTTP(S)) INTERNAL USER (O365) EXCHANGE USER HTTPS INTERNAL OWA USER (O365)
  • 6. Hybrid Building Blocks Federation DirSync Secure Transport Mailbox Moves • Free/Busy • Mailtips • Message Tracking • eDiscovery • … • Unified GAL • X500 (Mailbox Moves) • Online Archiving • TLS encryption • Header Preservation • Cert-based security • Centralized mail flow • Mailbox Replication Service (MRS) • Online Moves • Fast / Reliable
  • 7. An admin’s life in the cloud…
  • 8. What tasks does an admin commonly execute? • Daily Exchange Management • Identity Management • Moving Mailboxes • Patching • Monitoring • Troubleshooting
  • 9. Identity Management • All user objects are managed on-premises (through Exchange) because of DirSync • Account for the DirSync interval (or force DirSync to run) • Can be important if you want to “quickly” do things. • Watch out for accidental deletions! • New DirSync feature might help…
  • 10. DirSync Accidental Deletion • New in version 6765.0006 (released end of May) • If the number of objects being deleted exceeds a configurable threshold, DirSync won’t sync the deletions to Azure AD. • To enable the feature: • Set-PreventAccidentalDeletes –Enable –ObjectDeletionThreshold <value>
  • 11. Monitoring Hybrid Deployments • New architecture paradigm, requires new way of thinking about monitoring • You don’t care about Microsoft’s side of the story • End-user service availability is key (but it’s always been like that, right?) • Consider monitoring through a series of both Active and Passive tests • Active tests allow you to be proactive • Passive tests give you great feedback (counters…)
  • 12. What components do I need to monitor? • Directory Synchronization • Identity Federation (if applicable) • Exchange Federation • Certificates • Connectivity Featured as Messaging and Unified Communications Award Finalist
  • 13. Patching • Important to stay ‘current’ with patch levels (Exchange, DirSync) in order to remain supported • Challenge to keep up with cloud-cadence (CU’s are typically released every quarter…) • You can use RSS feeds and the Office Blog to stay up to date with the latest and the greatest. Recently released Microsoft roadmap blog might also help: http://office.microsoft.com/en-us/products/office- 365-roadmap-FX104343353.aspx
  • 16. Moving Mailboxes • A trivial action, but touches many different components in Exchange • Make sure the Mailbox Replication Service Proxy [MRS Proxy] is enabled on the internet-facing Exchange Web Services • Before a mailbox can be moved, certain ‘attributes’ need to be available on the object: • Prior to a mailbox move, check that the object have the correct attributes set (x500 + Proxy Addresses) • Because of the cross-premises nature of a hybrid deployment, certain features won’t work after a mailbox move • Watch out for permissions and large items in mailbox!
  • 17. Mailbox move limitations • Items larger than +/- 25 MB won’t be moved because of the item size limits in place in Office 365. • You can export them using this script • Cross-premises permissions (currently?) are not supported. Make sure to move associated mailboxes at the same time. • Potential impact of your ‘pilot’ group.
  • 18. Dealing with High Availability What it takes to make a hybrid deployment highly available
  • 19. What components should be highly available? • Exchange (Hybrid Servers) • AD FS (if deployed) • Connectivity
  • 20. “Hybrid Server” HA • Deploy at least two hybrid servers • Add site resiliency by deploying in two distinct physical locations • Load balance incoming request through a LB device Site 1 Site 2 Connectivity Domain Controller Exchange CAS/MBX Exchange CAS/MBX INTERNE T Domain Controller HA Load Balancer pair
  • 21. DirSync / Azure AD Sync • No urgent need for high availability • You can run w/o DirSync for a (short) period of time, although that would reduce (admin-)functionality temporarily • In case you cannot afford temporary functionality loss (SLAs?) • Deploy a ‘standby’ DirSync server • Consider deploying SQL (default choice for large enterprises anyway) • Easier to backup
  • 22. Active Directory Federation Services • Critical to operations; No ADFS = No user logon possible • Must be deployed HA – in all possible ways • Deploy ADFS cluster; spread across sites to add site resiliency • Can be costly…
  • 23. AD FS HA AD FS Topology AD FS Proxy AD FS Domain Controller INTERNET AD FS AD FS Proxy LoadBalancer LoadBalancer Domain Controller FW FW
  • 24. Troubleshooting An overview of the most common scenarios
  • 25. Troubleshooting AD FS • Not easy. • Use tools like e.g. Fiddler • Enable Debug Logging in Event Viewer • Pair AD FS Proxy w/ ADFS for easier troubleshooting • Understanding different authentication flows is important
  • 26. Enabling Debug Log • Open Event Viewer • Click View > Show Analytic and Debug Logs • Right-click Debug under AD FS Tracing and click enable • Reproduce issue
  • 27. Exchange Federation • Multiple areas where things can go wrong… • Verify that Federation Information can be retrieved (get- federationinformation) • Test Organization Relationships (test-organizationrelationship) • Verify Federation trust (Test-FederationTrust) • When using oAuth: Test-oAuthConnectivity
  • 28. Mailbox Moves • Error message is critical; contains useful information • Verify connectivity; e.g. MRS Proxy enabled? • Use the Test-MigrationServerAvailability for more insights
  • 29. DirSync • No news = good news  • Take a look into the console (miisclient.exe located in installation folder) • Check Permissions (inherit permissions enabled?)
  • 30. About ENow Software Download Mailscape for Exchange Online Free Trial http://bit.ly/Mailscape-Hybrid

Editor's Notes

  • #11: http://social.technet.microsoft.com/wiki/contents/articles/24544.how-to-avoid-syncing-accidental-deletes-to-the-cloud-directory.aspx