Exchange objects not being created in AD - Outlook clients querying wrong GC
Posted on 2008-06-11
I have an issue with our exchange environment (well, a number of issues, but I suspect they are all related) and am having problems resolving them..A quick rundown on the story so far:
we have 2 local DC's, one of which is an EX03 mail box (DC1 and MAIL1), and a new remote DC (REMDC1) to handle logon requests across two domains (LOCALDOMAIN.LAN and NEWCOMPANY.LOCAL) which have a two-way trust established.
A couple of weeks ago our systems manager decided we needed an exchange 2007 server introducing into the LAN, and promptly made it so. Once it was in we discovered that EX07 and EX03 don't really like existing in a FE/BE config when the FE is EX03, and to run EX07 we'd need a third server running the CAS....the decision was then made to remove the EX07 server from the schema.
At the same time a new DC (REMDC1) was added to another site to handle logon request from one of our satellite companies which has a trust established with the domain.
On Saturday I took down our mail server (MAIL1) for some updates; now, it turns out that this was our only GC until the new remote DC was installed...also a GC. I think that while the mail server was down AD has looked for another GC, found REMDC1 and started directing clients to it. I discovered this yesterday when a user complained that mail was slow, and when I checked the GAL is pointing to REMDC1.LOCALDOMAIN.LAN on about half a dozen machines..everyone else is pointing to the local data files for outlook.
I've also discovered that when I try and create new users in AD exchange doesn't create a mailbox for them. this isn't the usual "it takes a little while for RUS to create the mailbox" or activating it etc...its been three hours and theres nothing there. Mailboxes usually appear within a few minutes. Additionally the only rights assigned in the exchange attributes are to "SELF", even though I copied the user from an existing object. However, when I logon to AD on the other box (DC1) I can see the email address displayed, as if the mailbox had been created. Tried sending mail to the user and its bouncing back (no such object).
I suspect that the issues are linked, but how much is the removal of EX07 (perhaps leaving behind some detritus in the AD schema) and how much was caused by the new GC server I don't know. I have gone through adsiedit to try and identify any irregularities, but tbh I'm about at the limit of my knowledge and experience now, so would really appreciate any help!