?
Solved

Solving the X-500 Issue with inter-tenancy migration of Office365.

Posted on 2014-10-15
7
Medium Priority
?
1,373 Views
Last Modified: 2014-11-05
We are migrating a number of domains from one tenancy to another within Office 365.
Tenancy 1 has 18 domains and we cannot migrate all at once.

One major issue we have hit migrating from  T1 (Tenancy 1) to T2 (Tenancy 2) is NDR's.
If you migrate a user to T2 and they reply to a mail of a user on T1 they get an NDR.
This appears to be because of the use of X500 (not smtp) to relay mail.
The user can send a new mail OK (they search GAL for user and see a contact for user on T1 which relays mail across)
However any reply to a mail pre-migration produces a NDR as it uses X-500 which will not work in T2.

Is there any way to avoid this issue ?

Cheers..

p.
0
Comment
Question by:paologiorgio
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
7 Comments
 
LVL 42

Expert Comment

by:Vasil Michev (MVP)
ID: 40382214
In theory, all you need to do is add the LegacyDN value for the old tenant object as X500 alias for the new object. In practice, never done this for migration between two O365 tenants, so cannot guarantee it will work. Give it a try and report back? :)
0
 

Author Comment

by:paologiorgio
ID: 40382932
Hi Vasil (you are being a great help on this project by the way !!!)

To Confirm Scenario:

Dave is user who migrated to T2
Dave migrated to T2 Today

Mary is user who is still on T1

What's happening now:
Dave sent Mary a mail yesterday.
Both were on T1.
Dave has been migrated to T2 today.
Today Mary Replies to Dave's Mail.
She Get's A NDR as O365 uses X-500 to reply but that is longer active as Dave has migrated.

What you are suggesting will fix issue:
Add X-500 to Dave's T2 Account
Mary replies to mail Dave sent yesterday.
Mail get's delivered to new tenancy as that's where relevant X-500 is.


Is this what you are suggesting ?

Paul.
0
 
LVL 42

Accepted Solution

by:
Vasil Michev (MVP) earned 2000 total points
ID: 40383028
Yup, let Dave be the test bunny, should work in theory.

If it works OK, it will be best to adjust your migration steps to create the new X500 alias immediately after creating the mailbox in the new tenant.
0
Get real performance insights from real users

Key features:
- Total Pages Views and Load times
- Top Pages Viewed and Load Times
- Real Time Site Page Build Performance
- Users’ Browser and Platform Performance
- Geographic User Breakdown
- And more

 

Author Comment

by:paologiorgio
ID: 40386984
Vasil,

I need to add the x500 via powershell but not sure if i have my script correct (the last one).  

Syntax i have is....

$User= Get-Mailbox  $User.EmailAddresses+="X500: /O=ORG /OU=FIRST ADMINISTRATIVE GROUP/CN=RECIPIENTS/CN=XX" Set-Mailbox  –EmailAddresses $User.EmailAddresses

Open in new window


Example i have is....

$User=Get-Mailbox John $User.EmailAddresses+="X500:/O=ORG /OU=FIRST ADMINISTRATIVE GROUP/CN=RECIPIENTS/CN=XX"  Set-Mailbox John –EmailAddresses $User.EmailAddresses

Open in new window


What i am using is....

$User=Get-Mailbox aherbert@healthcare.ie $User.EmailAddresses+="X500:/o=ExchangeLabs/ou=Exchange Administrative Group (FYDIBOHF23SPDLT)/cn=Recipients/cn=c858c94b45794aee8894aeab18339b48-aherbert"  Set-Mailbox aherbert@healthcare.ie –EmailAddresses $User.EmailAddresses

Open in new window

0
 
LVL 42

Expert Comment

by:Vasil Michev (MVP)
ID: 40387018
It's correct, just make sure those are new lines or put ";" in between them. And of course, always test with a single user first :)
0
 

Author Comment

by:paologiorgio
ID: 40395082
Vasil, because dirsync is in use, it won't let me add X500 via powershell and it says i need to change via on-premise AD.

This is something i wanted to avoid as i don't have complete access to AD and need to go through someone to get to it.

However I have made changes on-premise using ADSIEDIT (as its windows 2003) but it's not showing up on Office365 even after force sync. Any ideas as to why this may be the case ?
0
 
LVL 42

Expert Comment

by:Vasil Michev (MVP)
ID: 40395327
Syncing X500 addresses should not be a problem. Check in the MIISClient if the attribute change is actually picked up by the dirsync process? Also check for any errors with the sync, etc.
0

Featured Post

Office 365 Training for Admins - 7 Day Trial

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

There are times when we need to generate a report on the inbox rules, where users have set up forwarding externally in their mailbox. In this article, I will be sharing a script I wrote to generate the report in CSV format.
In this article I discuss my selections of the Top Four free Outlook OST File Viewers available. Open, view and read even damaged OST files by using these tools. They all provide a clear preview of all data such as emails, notes, tasks, calendars, e…
how to add IIS SMTP to handle application/Scanner relays into office 365.
Many of my clients call in with monstrous Gmail overloading issues with Outlook. A quick tip is to turn off the All Mail and Important folders from synching. Here is a quick video I made to show you how to turn off these and other folders in Gmail s…
Suggested Courses

801 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question