Beruflich Dokumente
Kultur Dokumente
Microsoft Active Directory Connector Installation Deploying connection agreements Administering connection agreements Matching rules Attribute mapping
Introduction
Exchange server 5.5 runs in windows NT platform It maintain its own directory in its enviroment We require ADC connector tool to different exchange versions
ADVANTAGE PRO Chennais Premier Networking Training Centre
ADC Components
Connection Agreements Define replication characteristics Servers, credentials, schedule, export/import container, etc. ADC Policy Defines how objects get matched Defines how attributes flow Service Executes configured settings
ADVANTAGE PRO Chennais Premier Networking Training Centre
ADC Components
Exchange 5.5 ADC
Active Directory
ADVANTAGE PRO Chennais Premier Networking Training Centre
ADC Connector
Type of ADC Connectors Windows Server 2000 Version Exchange 2000 Version Exchange 2003 Version
ADC Installation
Consideration before installing ADC Connector The account should be member of Schema and Enterprise Admin group You should run forestprep and domain prep to install ADC
Diagnostic Logging
Diagnostic Logging is a useful tool for troubleshooting the ADC The Logging categories are as follows Replication Account management] Attribute mapping Service Controller LDAP Operations
ADVANTAGE PRO Chennais Premier Networking Training Centre
Permissions required to run Setup Schema Administrator Enterprise Administrator Service account permissions Exchange 2000 Full Administrator (delegated from the organization level) Member of the Built-In\Administrators group for the domain to which the server belongs
Location of existing user objects associated to mailboxes The OU where ADC will create non-existing recipient objects replicated from Exchange 5.5 Domain Administrator account for each domain
Associated-NT-Account Mapping
User D
ADVANTAGE PRO Chennais Premier Networking Training Centre
Definition Multiple mailboxes with same primary Windows NT account Issue How to link the correct mailbox to the corresponding user object when one is a personal mailbox and the other is the resource mailbox ADC should map personal mailbox to Windows NT account
Associated-NT-Account Mapping
User D
ADVANTAGE PRO Chennais Premier Networking Training Centre
Set extension-attribute-10 with the value NTDSNoMatch on ALL resource mailboxes Run ntdsatrb tool Formerly known as NTDSNoMatch Searches Exchange 5.5 directory for ambiguous associated-nt-accounts Creates CSV file for import back into Exchange 5.5 Knowledge Base article Q274173 Included in the Exchange 2000 Resource Kit
Cannot administer mailbox security on Exchange 2000 mailboxes from Exchange 5.5 Two-way connection agreements Mailbox management can occur from any directory Cannot administer mailbox security on Exchange 2000 mailboxes from Exchange 5.5
ADVANTAGE PRO Chennais Premier Networking Training Centre
Active Directory Primary connection agreements create objects if they dont already exist in the Active Directory Exchange 5.5 Primary connection agreements create objects if no legacy DN is specified on the Active Directory object
Domain B User D
ADVANTAGE PRO Chennais Premier Networking Training Centre
Export only read/write replicas from Exchange 5.5 into the Active Directory Advantages Manage recipients anywhere Less replication latency for Address Book updates within Active Directory Disadvantages Too many connection agreements to create and manage!
Domain B User D
ADVANTAGE PRO Chennais Premier Networking Training Centre
The Active Directory Connector Management node allows you to: Customize attribute mapping rules Customize object matching rules assoc-nt-account = object-sid/sid-history
(Exchange 5.5 Active Directory)
object-sid = assoc-nt-account
(Active Directory Exchange 5.5)
Attribute Mapping
Attribute Mapping
Attribute maps can be stored on both the ADC policy and connection agreement msExchServer1SchemaMap (AD->Ex) msExchServer2SchemaMap (Ex->AD) Local.map and remote.map files on the ADC installation media Maps from both the policy and CA are merged
Leaving this blank assumes all object-classes Source and target attribute LDAP-display-name of attribute Prefix Common value appended to source value Syntax DN Should always be used when mapping to a target attribute which is of type DN syntaxed
ADVANTAGE PRO Chennais Premier Networking Training Centre
The UI allows you to match objects with the following attributes Exchange 5.5 (19 attributes) object-guid, assoc-nt-account, mail-nickname, targetaddress, extension-attribute-1 15 Active Directory (22 attributes) object-guid, legacy-exchange-dn, object-sid, samaccount-name, sid-history, smtp mail address, user principal name (upn), extension-attribute-1 15
Diagnostics Logging
Enable diagnostic logging Replication, account management, attribute mapping, service controller, LDAP operations Registry key
HKLM\SYSTEM\CurrentControlSet\Services\MSADC\Diagn ostics (DWORD) 1 = minimum, 3 = medium, 5 = maximum TIP: To assist in troubleshooting, disable all CAs except the one you are concerned with. (Minimizes log output.)