Quantcast
Channel: Exchange Online migration and hybrid deployments - Recent Threads
Viewing all 2330 articles
Browse latest View live

Error sending to O365 from a specific IP: SubjectMismatch: Access Denied

0
0

Hi all,


We are configuring a web server to be able to send email to the accounts in our hybrid development.


The server has a functional TLS certificate on for its SMTP client, and we have verified the validity of the certificate in multiple ways.


The issue we are facing is that we receive the following SMTP error from the Exchange server after the RCPT TO command:

454 4.7.0 Failed to establish appropriate TLS channel: SubjectMismatch: Access Denied


Interestingly, when trying the same certificates and the same EHLO/FROM/TO combination from *any other host*, we get the response 250 2.1.5 Recipient OK. Note that this we are not trying to sent authenticated mail, or mail that appears to be coming from the domains serviced by Exchange. We're simply trying to deliver email to the Exchange server.


After trying other known good certificates and mail/TLS clients, I concluded that this error must be because the Office Server expects either a specific hostname or a specific certificate from that IP address.  Could you provide some guideline as to what setting might be causing this problem? My intuition is that a setting which was supposed to enforce a policy around the on-premise Exchange server accidentally also included the IP of the web server, which is on the subnet mask.


Thanks for your help.


See below for output: 


openssl s_client -starttls smtp -crlf -cert mydomain.com.crt -key mydomain.com.key -connect mydomain-com.mail.eo.outlook.com:25
[TLS negotiation]
250 CHUNKING
EHLO subdomain.mydomain.com
250-CH1EHSMHS022.bigfish.com Hello [38.105.83.46]
250-SIZE 157286400
250-PIPELINING
250-ENHANCEDSTATUSCODES
250-AUTH
250-8BITMIME
250-BINARYMIME
250 CHUNKING
250 2.1.0 Sender OK

MAIL FROM:mailbox@subdomain.mydomain.com

250 2.1.0 Sender OK

rcpt to:mailbox@mydomain.com

454 4.7.0 Failed to establish appropriate TLS channel: SubjectMismatch: Access Denied



Re: Where to start?

0
0

Hi WiseQT,

Thanks for your post here.

I understand that you’ve got an on-premises Exchange 2003 server which is not compatible with Outlook 2011 in Mac, and you want to know if you can solve the issue using Office 365 without upgrade your on-premises environment.

In regard to the issue, if the mailboxes in your organization is less than 1000, it’s a better option to use staged migration instead of hybrid environment. This type of migration will allow you to maintain short- or long-term coexistence between your on-premises and cloud-based e-mail organizations. In this scenario, you can migrate some mailboxes to the cloud while maintaining the rest of the mailboxes in your on-premises mail environment. For more details, please refer to: Migrate Mailboxes to the Cloud with a Staged Exchange Migration

However, if you still want to perform a hybrid deployment for your organization, you’ll need to install a minimal Exchange 2010 hybrid server in your organization since a hybrid deployment requires Exchange server 2010. Also, please note that both the staged migration and hybrid deployment is not available in P plan(Office 365 for Professional and Small Business subscription).

For more details, please refer to the links below:

 Compare the types of migration

 Exchange Hybrid Deployment and Migration with Office 365

Please feel free to post your updates here at your convenient time.

Re: Deleted and Sent email folders no longer have all emails

0
0

Hi Derek,

Thanks for your reply.

According to your description, I found the PowerShell command you typed have some format problem.
The “<” characters should be took out.
For example:
If the email account is derekalldaffer@contoso.com the right command is:
get-mailbox derekalldaffer |fl *retention*

Regards,
Wilfred Ying

Re: Migrate Users to O365 email from Exchange but with new domain name

0
0

Hi rglover,

How are things going?

Please feel free to post your updates here at your convenient time.

Office 365 and Exch 2010 for two different exch. organization.

0
0
Hi,
We have a scenario here.

1. Company 1:

Exchange /AD : In-house

Lync Server: Office 365

2. Company 2:

Exchange / Lync: Office 365

 

With some kind of Sync on Office 365, they can see each other on Lync. However, they can’t see each other on Exchange and hence cant lookup in GAL or Calendars.

Requirement is to sync Exchange (between in house Exchange of Company 1 and office 365 of Company2). They are entirely two different Organizations and merger is in progress.

What can be the best solution here? They already have a Federation server running to sync the Lync users.

 

Also, Company2 will have new email address with company1 as there new SMTP Domain.

Re: Failure running the Hybrid configuratoin wizard.

0
0

Hello Labrat,

Thansk for your reply.

Could you kindly run the command: Get-HybridConfiguration using EMS and post the result here?

Best Regards,

Emma Li

Re: Gradual move fro on premise Exchange to Outlook365

0
0

Hi mathiashansson,

Sorry for my misunderstanding and thank you for the update.

I know that you need to manage users both from Exchange Online and Exchange On-premise server.
For this scenario, to provide the smoothest migration to the Office 365 environment, or to keep a mix of on-premises mail users and Office 365 mail users for an extended period of time, organizations can configure an Exchange hybrid deployment.
Detailed information:
http://help.outlook.com/140/ff633682.aspx
http://technet.microsoft.com/en-us/library/hh852414.aspx

Thanks,
Bourne Zhang

Re: Failure running the Hybrid configuratoin wizard.

0
0

RunspaceId                      : 6f10f44c-7ee2-4242-8305-6fb1f637b869

ClientAccessServers             : {EX01}

TransportServers                : {EX01}

SecureMailCertificateThumbprint : 1934921A79BA73C67932D5A27E13F3D0527F9301

OnPremisesSmartHost             : mail.i*******t.se

Domains                         : {i******t.se}

Features                        : {FreeBusy, MoveMailbox, Mailtips, MessageTracking, OwaRedirection, OnlineArchive, SecureMail}

ExternalIPAddresses             : {90.231.251.98}

AdminDisplayName                :

ExchangeVersion                 : 0.10 (14.0.100.0)

Name                            : Hybrid Configuration

DistinguishedName               : CN=Hybrid Configuration,CN=Hybrid Configuration,CN=i******t,CN=Microsoft Exchange,CN=Services,CN=Configuration,

                                 DC=ad,DC=i******t,DC=se

Identity                        : Hybrid Configuration

Guid                            : 3d6e2664-5a99-4815-b321-e8b9ae383649

ObjectCategory                  : ad.i*******t.se/Configuration/Schema/ms-Exch-Coexistence-Relationship

ObjectClass                     : {top, msExchCoexistenceRelationship}

WhenChanged                     : 2012-10-25 12:23:03

WhenCreated                     : 2012-10-22 11:10:55

WhenChangedUTC                  : 2012-10-25 10:23:03

WhenCreatedUTC                  : 2012-10-22 09:10:55

OrganizationId                  :

OriginatingServer               : DC01.ad.i*******t.se

IsValid                         : True


Re: 2 domains different companies

0
0

Hi John,

I’d like to confirm the following information.

1.You have a new b.com domain. And currently, the MX record of b.com is pointed to another site.

2.There is hybrid deployment for a.com.

3.Now you prefer to let the user in A.com have the ability to send and receive mails by user@b.com address.

4.The mail service of B.com is still hosted in another service.

If I have misunderstood anything, please feel free to let me know.

You need to add the b.com domain to the local Exchange service as an alternative domain. For the detailed steps, you can refer this article.
http://technet.microsoft.com/en-us/library/aa996314.aspx

B.com must be added to Office 365 tenant and all users’ changing will be synced to Office 365 side.

Thanks,
Ray Yang

Re: Manage Hybrid Configuration Error - Federation information could not be received from the external organization

0
0

Hi Scott,

Do you mean you prefer to deploy On-Premises Exchange server with Online-Archive? And do you receive the same error message as the first post showed?

Please post the result of the Cmdlet Get-FederationInformation –domainname yourdomain.com and Get-FederationInformation –domainname yourdomain.onmicrosoft.com.

Thanks,

Ray Yang

Getting bounce back email on partner's email server whenever they reply to my emails

0
0

Hi, 


Recently we moved from hosted gmail account to MS365 using the same domain name. (www.singaporegamescentral.com)

I migrated our domain and our webpages to MS365 from gmail and now mails are flowing correctly. 


However one of our partners, how are using exchange (www.e-clubmalaysia.com) keeps getting bounced back email with the error code.  This happens when we send them an email but when they reply to the email, their mail server (i suppose) is returning a delivery failure message.  


This is an automatically generated delivery status notification. 
Delivery to the following recipient(s) failed: 
gregory.ong@singaporegamescentral.com : 550-Please turn on SMTP Authentication in your mail client. 550-mail.e-clubmalaysia.com [202.73.10.170]:1420 is not perm 

I check my DNS settings under singaporegamescentral MS365 and this is what I got. 


DNS records for Microsoft Office 365 
These are the DNS records for your Microsoft Office 365 services. They are displayed for your information and cannot be modified.
Type Priority Host name Points to address TTL
MX 0 @ singaporegamescentral-com.mail.eo.outlook.com 1 Hour
CNAME - autodiscover autodiscover.outlook.com 1 Hour
CNAME - sip.singaporegamescentral.com sipdir.online.lync.com 1 Hour
CNAME - lyncdiscover.singaporegamescentral.com webdir.online.lync.com 1 Hour
Type TXT Name TXT Value TTL
TXT @ v=spf1 include:outlook.com ~all 1 Hour
Type Service Protocol Port Weight Priority Target Name TTL
SRV _sipfederationtls _tcp 5061 1 100 sipfed.online.lync.com singaporegamescentral.com 1 Hour
SRV _sip _tls 443 1 100 sipdir.online.lync.com singaporegamescentral.com 1 Hour


In their e-clubmalaysia DNS setting they have


Lookup has started…

Trying "e-clubmalaysia.com"

;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 40449

;; flags: qr rd ra; QUERY: 1, ANSWER: 7, AUTHORITY: 0, ADDITIONAL: 0

;; QUESTION SECTION:

;e-clubmalaysia.com. IN ANY

;; ANSWER SECTION:

e-clubmalaysia.com. 599 IN A 203.116.80.221

e-clubmalaysia.com. 599 IN MX 10 mail.e-clubmalaysia.com.

e-clubmalaysia.com. 599 IN MX 20 mailgb.e-clubmalaysia.com.

e-clubmalaysia.com. 1199 IN TXT "i=202&m=domains-mx2-p10"

e-clubmalaysia.com. 43199 IN NS yns2.yahoo.com.

e-clubmalaysia.com. 43199 IN NS yns1.yahoo.com.

e-clubmalaysia.com. 1199 IN SOA no-dyn-updates.san.yahoo.com. postmaster.san.yahoo.com. 2012092501 10800 3600 7084000 28800


Received 242 bytes from 8.8.8.8#53 in 202 ms


I am suspecting that there is a trust issue involving SPF between the outgoing server at e-clubmalaysia and that is probably why we are getting a outgoing bounce back error. 


Question is, how can i fix this issue? 


Thanks

Greg




Re: New-RemoteMoveRequest faild Exception has been thrown by the target of an invocation

0
0

Hi Juancho,

How are things going?

If you have any other questions or concerns, please do not hesitate to contact us. It is always our pleasure to be of assistance.

Thanks,

Ray Yang

Re: free/busy visible, but not subject and location

0
0

Hi hellbound41,

Just checking in to see if you have any other related questions.

If so, please do not hesitate to contact us. It is always our pleasure to be of assistance.

Thanks,
Linda Wang

Re: Migrate domian and email from Network Solutions to 365

0
0

Hi jwright,

How are things going?

If you have any other questions or concerns, please do not hesitate to post in the forum. It is always our pleasure to be of assistance.

Thanks,

Kent Gu

Re: Error when move mailbox to Office 365 in Hybrid scenario

0
0
Hi JMMC_1,

How are things going?
If you have any other questions or concerns, please do not hesitate to contact us.
It is always our pleasure to be of assistance.

Thanks,
Eric Sun

Re: Office 365 and Exch 2010 for two different exch. organization.

0
0

Hi Rajnish,

Do you mean that you prefer to let company1 and company2 can see others in GAL after the users in company2 using company1’s domain as their new SMTP domain?

If so, after company2 use company1’s domain as its SMTP domain, you can set up a hybrid environment. I suggest running Exchange Server Deployment Assistant. If any error message appears during the process, please capture a screenshot for further research. After running it successfully, you can check the issue again.  
 
Here is some reference for the situation:
================================
Exchange Hybrid Deployment and Migration with Office 365
http://help.outlook.com/en-us/140/ff633682.aspx

Create a New Hybrid Deployment
http://technet.microsoft.com/en-us/library/hh529940.aspx

Manage a Hybrid Deployment
http://technet.microsoft.com/en-us/library/hh529933.aspx

Meanwhile, if anyone in community has a suggestion, you can also share it with Rajnish in this post. If you have a suggested answer, don’t forget to check “This is a suggested answer” when you post your suggestions in forum so others can find it easily and Community can benefit.

Thanks,
Monica Tong

Re: Office 365 and Exch 2010 for two different exch. organization.

0
0

Thank you very much Monica for the reply. Thats exactly what I am looking for. End result that I am looking for is that both the exchange (office 365 for company 2 and Exchange on premise for company 1) can do GAL lookup and can share there schedule free busy information with each other.

If this is possible by any other method, will be of real help.

Re: How do I move from GroupWise to Office 365?

Re: Manage Hybrid Configuration Error - Federation information could not be received from the external organization

0
0

Ray,

Yes, that is what I am trying to do. I already have Exchange 2010 SP2  installed and patched to latest. I have been running on it for 8 months now. Now I am trying to get online archiving setup. I went through the Deployment Assistant and selected Exchange Archive Only deployment. Downloaded the document and have gone through the steps in it. When I try to setup the hybrid config wizard the error is what i have posted I have also tried it through EMS with only Online Archiving. I get the same error as above.

 

I have been doing some digging throught the logs and thought that it was wierd that it could not create the Org Relationship for the On Premises to Exchange Online Org. I tried to view the properties of it and recieved an error that it could not find information on it. I tried to delete it through EMC and it would error out so i deleted it through EMS. I was able to create the On Premises to Exchange Omline Organization Relationship through the EMC.

 

As I am writing this reply the Get-FederationInformation that I posted yesterday just recieved approval to be posted. The information is up a couple posts.

 

Thanks,

Scott

Re: connect Exchange UM on-premise with Exchange online

0
0

Hi Richard,

 

Thank you for your post.

 

Currently, it is not supported to have an Exchange Online mailbox but with Unified Messaging on-premise or have an on-premise mailbox with Unified Messaging in the cloud.

 

However, on-premises voicemail solutions from third-party providers can interoperate with Exchange Online if they can forward voicemails through SMTP or if they support Microsoft Exchange Web Services.

 

For the detailed information, you can refer the following links:

1.Page 32 and page 33 in Microsoft Exchange Online for Enterprises Service Description.

2.What is the difference between Exchange Online Unified Messaging and Exchange 2010 on prem Unified Messaging?

 

Thanks,
Jolin Qiao

 
Viewing all 2330 articles
Browse latest View live




Latest Images