Tuesday, December 1, 2009

Exchange Top Level Security Permissions

In order to see the top level inherited security permissions in Exchange you have to add the following reg key and restart ESM (Exchange 2003):

Hkey_Current_User/ Software/ Microsoft/ Exchange/ ExAdmin

Create a new Dword Value of "ShowSecurityPage" and give it a value of 1.

Now restart ESM and you will see the security tab at the Exchange org levele

Thursday, November 19, 2009

Messaging Records Management (MRM) Exchange 2007 Entire Mailbox

If you are using managed folder policies and would like to apply deletion rules to folders outside of the default folders such as a user that creates a folder at the root and not in the Inbox, you may have to work with "Entire Mailbox"

I have used this setting in the past and it can cause havoc. In other words it will apply to every single folder, including calendar, contacts, etc. when you use it.

The only way to ensure that it wont apply to a specific folder is to have that managed folder part of the same policy.

So if you have Entire Mailbox selected to delete emails after 90 days, everything in Outlook older than 90 days will be deleted. If you also have a Calendar managed folder policy for 120 days as part of the same policy, which includes Entire Mailbox, the 90 day rule wont apply to Calendar. The calendar items will delete after 120 days and everything else 90 days.

Another option is to choose for the Entire Mailbox policy to only delete emails and not all items. IF you do this then it will only delete emails for the entire mailbox and not items like calendar entries, tasks, etc.

Be careful.

Tuesday, November 10, 2009

Exchange 2007 File Share Witness Multi-subnet clustering

If you are placing the file share witness at the same site as your active Exchange 2007 server, when you have a primary site failure Exchange will not be able to start at the DR site. This is because it will only have 1 of 3 votes as both the quorum and the active are down.

You will have to run a /fq (net start clussvc /fq) to force the quorum to start at the secondary site.

Check this one out:
http://blogs.technet.com/timmcmic/archive/2009/04/26/file-share-witness-fsw-placement-and-the-cluster-group.aspx

Wednesday, October 21, 2009

Migrating user from Exchange 2003 to 2007 BES

Most people that I talk to suggest to restart BES services if you migrate a user between Exchange servers. I have found that all you have to do is run handheldcleanup -u. It works for me every time. Try it.

Thursday, September 17, 2009

Windows 2008, Exchange 2007 CCR Cluster multi-subnet

To decrease the fail-over time of a multi-subnet CCR cluster running Exchange 2007, decrease the TTL of the DNS record. When a fail-over occurs in a multi-subnet environment, the DNS record must change to the new IP. To make this happen faster, run the below command.

The default is 20 minutes, plus the 10 minutes it takes for the cluster to even change the record, plus the amount of time a client caches the record. This can lead to long fail-over times.

To change the TTL to 5 minutes run: Cluster.exe res /priv HostRecordTTL=300

Windows Server 2008, Cannot Create cluster

If you are having issues creating a cluster in Windows 2008, try this:

Change the value for the MS failover cluster virtual adapter
1. Open Registry Editor.
2. Locate the following registry subkey:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}
3. Under this subkey, find the subkey that holds a DriverDesc string value entry whose value is "Microsoft Failover Cluster Virtual Adapter."
4. Under the subkey that you found in step 3, add the following string value registry entry:
Name: DatalinkAddress
Value data: 02-AA-BB-CC-DD-01
5. Restart the computer.
6. Repeat step 1 through step 5 on other computers on which you experience this problem. When you do this on other computers, replace the value data of the registry with different values in order to set a unique value for each node. For example, set the value on the second node to 02-AA-BB-CC-DD-02, and set value on the third node to 02-AA-BB-CC-DD-03. If you notice this behavior on distinct clusters, make sure that you use an address for each node that is unique across all clusters.
7. Try creating the cluster again.

Exchange 2007 cannot uninstall Exchange Tools

If you cant uninstall the Exchange tools because the option is grayed out, run this command:

MsiExec.exe /X{24B2C164-DE66-44FE-B468-A46D9D5E6B31}