Solved

exchange 2007

Posted on 2016-09-27
24
59 Views
Last Modified: 2016-09-27
I have EXCHNAGE 2007 ENVIRONMENT


we have resource forest setup where mail.lan is exchange forest linked to another AD account forest. exchange mailboxes are linked mailboxes .

my boss asked me below to find out , any guesses what is he trying to ask and where should I find it

 "how are the users in the mail.lan domain linked back to their primary domain? Which attribute?"
0
Comment
Question by:pramod1
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 13
  • 10
24 Comments
 
LVL 49

Expert Comment

by:Akhater
ID: 41818715
The info you are looking for is here

http://hasslauer.com/blog/?p=143

What he wants to know is the relationship between the A user in the account forest and the AD user in the resource forest
0
 
LVL 49

Expert Comment

by:Akhater
ID: 41818716
The info you are looking for is here

http://hasslauer.com/blog/?p=143

What he wants to know is the relationship between the A user in the account forest and the AD user in the resource forest
0
 

Author Comment

by:pramod1
ID: 41818726
cant I check the attribute of exchange users through GUI like mine is on disabled AD

like my properties
0
Office 365 Training for Admins - 7 Day Trial

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

 
LVL 6

Expert Comment

by:Obi Wan
ID: 41818734
Its the Sid mate, in the doc above its the AccountDomainSid
0
 
LVL 49

Expert Comment

by:Akhater
ID: 41818751
Did you read the article? Everything you need is there with screenshots
0
 

Author Comment

by:pramod1
ID: 41818779
I can see the commands clear, can you somehow enlarge it and send
0
 
LVL 49

Expert Comment

by:Akhater
ID: 41818785
I'm not the author of the article I don't have the screen shots
0
 

Author Comment

by:pramod1
ID: 41818793
or can you write in the scripts
0
 

Author Comment

by:pramod1
ID: 41818798
can t load AD module in Exchange management shell
0
 
LVL 49

Expert Comment

by:Akhater
ID: 41818830
man you lost me you asked about the linked properties and it is clearly written in the article i sent you

LinkedMasterAccount
msExchMasterAccountSid

and the SID of the user in the account forest is giving full permission on the mailbox in the resource forest
0
 

Author Comment

by:pramod1
ID: 41818852
I cant read the script properly from screen shot, can u put in text
0
 

Author Comment

by:pramod1
ID: 41818884
in EMS it says cant load any AD module
0
 
LVL 49

Expert Comment

by:Akhater
ID: 41818894
You don't need it

Get-Mailbox  username | fl

Will show you the LinkedMasterAccount

And you can use ad users and computers for msExchMasterAccountSid as shown in the picture below

http://www.msexchange.org/img/upl/image0041141045519890.jpg

Picture taken from http://m.msexchange.org/articles-tutorials/exchange-server-2003/management-administration/Understanding-External-Associated-Account-Windows-Server-2003-Exchange-2003.html which shows you how to check the permissions too
0
 

Author Comment

by:pramod1
ID: 41818898
I am seeing in attribute additor it is in hexa decimal
0
 

Author Comment

by:pramod1
ID: 41818902
akhater:

I see in attribute editor some hexadecimal figure, what should I give him
0
 
LVL 49

Expert Comment

by:Akhater
ID: 41818903
What are you trying to do?
0
 
LVL 49

Expert Comment

by:Akhater
ID: 41818905
You don't need to give him the sid

The attributes he asked for are

LinkedMasterAccount
msExchMasterAccountSid

These are the attributes their values will change for every user
0
 

Author Comment

by:pramod1
ID: 41818907
he asked me below question

how are the users in the mail.lan domain linked back to their primary domain? Which attribute?"

I ran get-mailbox identity my name | ft name, linked master account I got the result

what attribute should I tell him
0
 

Author Comment

by:pramod1
ID: 41818909
so I should tell him

these are below

LinkedMasterAccount
 msExchMasterAccountSid

am I correct?
0
 
LVL 49

Accepted Solution

by:
Akhater earned 500 total points
ID: 41818910
Yes

LinkedMasterAccount points to the account in the users forest

msExchMasterAccountSid points to the sid of that account

Finally that account has full access to the mailbox

That's it
0
 

Author Comment

by:pramod1
ID: 41818912
msexchange master account sid points to account forest and not exchange forest
0
 

Author Comment

by:pramod1
ID: 41818914
2)      The disabled account in the resource forest has an attribute called msExchMasterAccountSid that stores the value of the objectSid attribute of the corresponding user in the account forest.
0
 

Author Comment

by:pramod1
ID: 41818915
got it
0
 
LVL 49

Expert Comment

by:Akhater
ID: 41818916
Exactly
0

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In-place Upgrading Dirsync to Azure AD Connect
This article shows the method of using the Resultant Set of Policy Tool to locate Group Policy that applies a particular setting.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

732 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question