How to secure Exchange 2016 with Azure AD – Part 3 – Azure Application Proxy

In Part 1 I configured my Exchange 2016 virtual directories for OWA and ECP to authenticate using Kerberos, more on this shortly. In Part 2 I configured Hybrid Modern Authentication to begin using Azure AD to authenticate Exchange on-premises services. Part 1 is a hard requirement for this to work, so if you haven’t already, check it out! In this final part I will now move on to publishing OWA and ECP using the Azure Application Proxy to also secure these final services with Azure AD. … More How to secure Exchange 2016 with Azure AD – Part 3 – Azure Application Proxy

How to fix being unable to add Exchange Hybrid features to AAD Connect configuration

If you are in the situation where you are migrating from a non-Microsoft mail system (e.g. Domino Lotus Notes, Google) or a hosted Exchange platform you may be in the situation where you have set up AAD Connect before extending your Active Directory Schema to include the Microsoft Exchange attributes. This can cause problems when … More How to fix being unable to add Exchange Hybrid features to AAD Connect configuration

How To: Filter out msExchMailboxGuid from AAD Connect Sync

When migrating from Exchange on-premises to Office 365 with a Third-Party tool such as Migration Wiz from BitTitan you need to remove the msExchMailboxGuid from the synchronised attributes otherwise you will get the following error: This is because Exchange Online recognises that the msExchMailboxGUID attached to the user is an Exchange on-premises mailbox, and so … More How To: Filter out msExchMailboxGuid from AAD Connect Sync

How To: Set up AAD Connect multi-forest sync with untrusted forests – Part 1, DNS

I ran in to a problem with AAD Connect this week where I had a customer with two completely separate forests – the main forest had ~400 users and was based in the UK and one with ~50 users in Australia. Before we started there was not even network connectivity between the networks so we … More How To: Set up AAD Connect multi-forest sync with untrusted forests – Part 1, DNS

AD Sync Error – missing-partition-for-run-step

I have been doing quite a few deployments of AAD Connect recently, and I have run across the error when synchronising the local directory “missing-partition-for-run-step” a couple of times. This will occur when you are synchronising a Forest where not all of the domains in the Forest will be synchronised, and you have removed them from the local … More AD Sync Error – missing-partition-for-run-step

AAD Sync Error: Deletion Threshold Reached

Ran in to a problem today with a customer running AAD Connect when trying to Export to the Azure Active Directory, the status of the Connector Operations showed “stopped-server-down” (See Below). At the same time, I was called by the technical contact at the customer who said he had received a strange email from MSOnlineServicesTeam … More AAD Sync Error: Deletion Threshold Reached

AAD Sync/AAD Connect – Passwords not syncing with attribute filtering

After the release of AAD Sync and now AAD Connect we have noticed several customers using Attribute Filtering are experiencing an error when bringing people into the scope of synchronisation with the appropriate attribute. Microsoft describe this here as expected behaviour. Users are moved between filtered and unfiltered scopes In this scenario, the user is … More AAD Sync/AAD Connect – Passwords not syncing with attribute filtering