Solved

exchange 2007

Posted on 2016-09-27
24
60 Views
Last Modified: 2016-09-27
I have EXCHNAGE 2007 ENVIRONMENT


we have resource forest setup where mail.lan is exchange forest linked to another AD account forest. exchange mailboxes are linked mailboxes .

my boss asked me below to find out , any guesses what is he trying to ask and where should I find it

 "how are the users in the mail.lan domain linked back to their primary domain? Which attribute?"
0
Comment
Question by:pramod1
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 13
  • 10
24 Comments
 
LVL 49

Expert Comment

by:Akhater
ID: 41818715
The info you are looking for is here

http://hasslauer.com/blog/?p=143

What he wants to know is the relationship between the A user in the account forest and the AD user in the resource forest
0
 
LVL 49

Expert Comment

by:Akhater
ID: 41818716
The info you are looking for is here

http://hasslauer.com/blog/?p=143

What he wants to know is the relationship between the A user in the account forest and the AD user in the resource forest
0
 

Author Comment

by:pramod1
ID: 41818726
cant I check the attribute of exchange users through GUI like mine is on disabled AD

like my properties
0
Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

 
LVL 6

Expert Comment

by:Obi Wan
ID: 41818734
Its the Sid mate, in the doc above its the AccountDomainSid
0
 
LVL 49

Expert Comment

by:Akhater
ID: 41818751
Did you read the article? Everything you need is there with screenshots
0
 

Author Comment

by:pramod1
ID: 41818779
I can see the commands clear, can you somehow enlarge it and send
0
 
LVL 49

Expert Comment

by:Akhater
ID: 41818785
I'm not the author of the article I don't have the screen shots
0
 

Author Comment

by:pramod1
ID: 41818793
or can you write in the scripts
0
 

Author Comment

by:pramod1
ID: 41818798
can t load AD module in Exchange management shell
0
 
LVL 49

Expert Comment

by:Akhater
ID: 41818830
man you lost me you asked about the linked properties and it is clearly written in the article i sent you

LinkedMasterAccount
msExchMasterAccountSid

and the SID of the user in the account forest is giving full permission on the mailbox in the resource forest
0
 

Author Comment

by:pramod1
ID: 41818852
I cant read the script properly from screen shot, can u put in text
0
 

Author Comment

by:pramod1
ID: 41818884
in EMS it says cant load any AD module
0
 
LVL 49

Expert Comment

by:Akhater
ID: 41818894
You don't need it

Get-Mailbox  username | fl

Will show you the LinkedMasterAccount

And you can use ad users and computers for msExchMasterAccountSid as shown in the picture below

http://www.msexchange.org/img/upl/image0041141045519890.jpg

Picture taken from http://m.msexchange.org/articles-tutorials/exchange-server-2003/management-administration/Understanding-External-Associated-Account-Windows-Server-2003-Exchange-2003.html which shows you how to check the permissions too
0
 

Author Comment

by:pramod1
ID: 41818898
I am seeing in attribute additor it is in hexa decimal
0
 

Author Comment

by:pramod1
ID: 41818902
akhater:

I see in attribute editor some hexadecimal figure, what should I give him
0
 
LVL 49

Expert Comment

by:Akhater
ID: 41818903
What are you trying to do?
0
 
LVL 49

Expert Comment

by:Akhater
ID: 41818905
You don't need to give him the sid

The attributes he asked for are

LinkedMasterAccount
msExchMasterAccountSid

These are the attributes their values will change for every user
0
 

Author Comment

by:pramod1
ID: 41818907
he asked me below question

how are the users in the mail.lan domain linked back to their primary domain? Which attribute?"

I ran get-mailbox identity my name | ft name, linked master account I got the result

what attribute should I tell him
0
 

Author Comment

by:pramod1
ID: 41818909
so I should tell him

these are below

LinkedMasterAccount
 msExchMasterAccountSid

am I correct?
0
 
LVL 49

Accepted Solution

by:
Akhater earned 500 total points
ID: 41818910
Yes

LinkedMasterAccount points to the account in the users forest

msExchMasterAccountSid points to the sid of that account

Finally that account has full access to the mailbox

That's it
0
 

Author Comment

by:pramod1
ID: 41818912
msexchange master account sid points to account forest and not exchange forest
0
 

Author Comment

by:pramod1
ID: 41818914
2)      The disabled account in the resource forest has an attribute called msExchMasterAccountSid that stores the value of the objectSid attribute of the corresponding user in the account forest.
0
 

Author Comment

by:pramod1
ID: 41818915
got it
0
 
LVL 49

Expert Comment

by:Akhater
ID: 41818916
Exactly
0

Featured Post

Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A hard and fast method for reducing Active Directory Administrators members.
Uncontrolled local administrators groups within any organization pose a huge security risk. Because these groups are locally managed it becomes difficult to audit and maintain them.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…

717 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question