Monday, March 9, 2015

collaboration mailbox types

site mailboxes, public folders, shared mailboxes for collaboration


site mailbox - requires exchange 2013 for emails and sharepoint for document storage portion

documents viewable via outlook 2013 or sharepoint vis web

The emails and documents kept in separate storage locations are accessible through the same client interface.


  • a site mailbox has sharepoint 2013 site membership (owners and members)
  • shareed storage through exchange and sharepoint
  • end-user clients using outlook 2013 or shaerpoint 2013 but not OWA

shared mailboxes













_Public Folder mailbox

became dumping ground for data

with exchange 2013 you need to first create a public folder mailbox

  • legacy exchnage required the creation of public folder database

within the publlc folder mailbox you create public folders that contain the actual content

replication of public folder not needed. Can't bring public folders to close to users.   User access public folder mailbox on the exchange server it resides..   Now, DAG protects mailbox.


the first public folder mailbox contains the master heirchy information

you can mail enable a public folder so that email can be sent directly to it and establish quotas.



scenario

create public folder mailbox and 3 public folders based on location (Trindad, Miami, London),. Mail-enable Trinidad public folder.



 Note that this public folder mailbox contains the primary heirarchy information.


default quota will be based off the mailbox database so if it is tied to the user mailbox database the default quota maybe too small for a public folders.  A seperate mailbox database could be creaated to be used for public folder mailbox with appropriate quota.










create public folders


Now you can create sub-folders

public folder permissions

delegate and establish administrative level of the folder






Now a user can create and manage public folder.















Outlook access to the public folder



user has owner permissions

























Clients and mobile management

client management = policies

exchange includes a variety of different methods to control features for example through virtual directories or through polices (outlook web app policies and Mobile Device Mailbox policies)


virtual directories

client protocls used for access to 2013 can be controlled through virtual directories

a virtual directory is used by IIS to control access through ActiveSync connections, OWA, Autodisciover and so on.

You can manage authentication, security and reporting settigs

you can mamage virtual directoired through the EAC, EMC, IIS Manager (depending on task)


Virtual directory settings vs Policy Settings

virtual directory settings are made through the servers feature

policies might be under the permissions feature for OWA or Mobile feature for Mobile Device Mailbox policies


  • polices override virtual directory settings
  • no authentication confilcts
  • there are default OWA and ActiveSync (aka Mobile Device) policies created when you install Exchange
  • Only one policy (one for OWA and one for ActiveSync) can be applied to a mailbox at a time and if no policy is applied the virtual directory settings apply
Outlook Web App Virtual Directory and Policy Features

conflicts may occur


virtual Directory Property Tabs


  • general
  • authentication
  • features
  • file access

Policy Settings Tabs


  • General
  • features
  • file access (email attachemnts) . cab be configured on per outlook web app mailbox policy basis
    • direct file access - (allow/deny access to files)
    • webready document viewing - view in web browser instead.


  • offline access



Mobile Device Mailbox Policies

Virtual directory Porperty tabs


  • general 
  • authentication


Policy Settings tabs


  • general 
    • allow non-provisionable devices (now called "allow mobile devices that dont fully support these policies to synchronize")
  • security






Virtual directory settings











Virtual directory settings for the ActiveSync






OWA policies


default polciies settings





\
Mobile device policies








Friday, March 6, 2015

certificates

Exchange uses self-signed certs by default.  not appropriate for production environment.








Configuring a domain to uise a CA SAN/UCC certificate form GoDaddy

1. use the Exchange Certificate Wizard to obtain a Certificate Signing Request (CSR)

2. use the CSR to complete the GoDaddy certificate process

3. download the certificate and complete the pending certificate wizard

4. assign the IIS service to the new certificate and demonstrate that it works



Error when using self signed certificates





Create a CSR



Pending state of the certificate




Certificate request text file (CRF)



paste into domain register's request form

Make sure common name is correct



intermediate and root certification



Now, in exchange Admin center you can complete the certificate request
point UNC path to new certificate

Now certificate is considered valid CA signed certificate

assign services to certificate




if there are other exchange servers needing the certificate, you can import and export it