<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msexchangeteam.com/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>You Had Me At EHLO...</title><link>http://msexchangeteam.com/default.aspx</link><description>aka the Microsoft Exchange Team Blog</description><dc:language>en-US</dc:language><generator>CommunityServer 2.0 (Build: 60217.2664)</generator><item><title>Exchange “How do I?” videos</title><link>http://msexchangeteam.com/archive/2010/09/08/456186.aspx</link><pubDate>Wed, 08 Sep 2010 19:31:19 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:456186</guid><dc:creator>Exchange</dc:creator><slash:comments>0</slash:comments><comments>http://msexchangeteam.com/comments/456186.aspx</comments><wfw:commentRss>http://msexchangeteam.com/commentrss.aspx?PostID=456186</wfw:commentRss><wfw:comment>http://msexchangeteam.com/rsscomments/456186.aspx</wfw:comment><description>&lt;p&gt;&lt;font size="2" face="Verdana"&gt;It has been a &lt;/font&gt;&lt;a href="http://msexchangeteam.com/archive/2010/02/01/453922.aspx"&gt;&lt;font size="2" face="Verdana"&gt;while&lt;/font&gt;&lt;/a&gt;&lt;font size="2" face="Verdana"&gt; since we mentioned the Exchange video series we have been creating. Seeing that we have been recording new ones over past months, I wanted to remind you of those as they can be an excellent resource to help you learn how to do something in Exchange.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2" face="Verdana"&gt;The general “How do I?” videos page can be found &lt;/font&gt;&lt;a href="http://technet.microsoft.com/en-us/exchange/dd314386.aspx"&gt;&lt;font size="2" face="Verdana"&gt;here&lt;/font&gt;&lt;/a&gt;&lt;font size="2" face="Verdana"&gt;. In order to be notified of new videos that we create and post, you should subscribe to the video RSS feed &lt;/font&gt;&lt;a href="http://www.microsoft.com/feeds/technet/en-us/how-to-videos/Exchange_How-to_Videos_image.xml"&gt;&lt;font size="2" face="Verdana"&gt;here&lt;/font&gt;&lt;/a&gt;&lt;font size="2" face="Verdana"&gt;.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2" face="Verdana"&gt;Here are some more recent additions to the video series:&lt;/font&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://technet.microsoft.com/en-us/exchange/ff926085.aspx"&gt;&lt;font size="2" face="Verdana"&gt;Exchange Online Screencast Part 1 - Account Logon and Domain Setup&lt;/font&gt;&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a href="http://technet.microsoft.com/en-us/exchange/ff926084.aspx"&gt;&lt;font size="2" face="Verdana"&gt;Exchange Online Screencast Part 2 - Adding and Testing Users&lt;/font&gt;&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a href="http://technet.microsoft.com/en-us/exchange/ff727932.aspx"&gt;&lt;font size="2" face="Verdana"&gt;How Do I: Size Exchange 2010&lt;/font&gt;&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a href="http://technet.microsoft.com/en-us/exchange/ff727970.aspx"&gt;&lt;font size="2" face="Verdana"&gt;How Do I: Use Exchange 2010 Performance Counters?&lt;/font&gt;&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a href="http://technet.microsoft.com/en-us/exchange/ff727931.aspx"&gt;&lt;font size="2" face="Verdana"&gt;How Do I: Build Exchange 2010 CAS Arrays?&lt;/font&gt;&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a href="http://technet.microsoft.com/en-us/exchange/ee886418.aspx"&gt;&lt;font size="2" face="Verdana"&gt;How Do I: Configure Mailbox Plan Attribute Flow?&lt;/font&gt;&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a href="http://technet.microsoft.com/en-us/exchange/ee890058.aspx"&gt;&lt;font size="2" face="Verdana"&gt;How Do I: Create and configure certificates with Exchange 2010?&lt;/font&gt;&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;font size="2" face="Verdana"&gt;There is definitely more. Enjoy!&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2" face="Verdana"&gt;- &lt;/font&gt;&lt;a href="http://msexchangeteam.com/archive/2004/01/27/63464.aspx"&gt;&lt;font size="2" face="Verdana"&gt;Nino Bilic&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://msexchangeteam.com/aggbug.aspx?PostID=456186" width="1" height="1"&gt;</description><category domain="http://msexchangeteam.com/archive/category/11164.aspx">Exchange 2010</category></item><item><title>Exchange 2010 SP1 FAQ and Known Issues </title><link>http://msexchangeteam.com/archive/2010/09/01/456094.aspx</link><pubDate>Wed, 01 Sep 2010 18:03:51 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:456094</guid><dc:creator>Exchange</dc:creator><slash:comments>68</slash:comments><comments>http://msexchangeteam.com/comments/456094.aspx</comments><wfw:commentRss>http://msexchangeteam.com/commentrss.aspx?PostID=456094</wfw:commentRss><wfw:comment>http://msexchangeteam.com/rsscomments/456094.aspx</wfw:comment><description>&lt;div style="font:normal 1.2em Calibri,Helvetica,Arial,sans-serif; padding-top:.5em; line-height:1.3em;"&gt;&lt;p&gt;Last week we released Exchange Server 2010 Service Pack 1. It has received some great feedback and reviews from customers, experts, analysts, and the Exchange community.&lt;/p&gt;  &lt;p&gt;The starting point for SP1 setup/upgrade should be the &lt;span class="bold"&gt;&lt;a title="Find out What's New in Exchange 2010 SP1" href="http://technet.microsoft.com/en-us/library/ff459257(EXCHG.141).aspx"&gt;What's New in SP1&lt;/a&gt;&lt;/span&gt;, &lt;span class="bold"&gt;&lt;a title="Read the Exchange 2010 SP1 Release Notes" href="http://technet.microsoft.com/en-us/library/ff728620(EXCHG.141).aspx"&gt;SP1 Release Notes&lt;/a&gt;&lt;/span&gt;, and &lt;span class="bold"&gt;&lt;a title="See the prerequisites for Exchange 2010 SP1" href="http://technet.microsoft.com/en-us/library/bb691354.aspx"&gt;Prerequisites&lt;/a&gt;&lt;/span&gt; docs. As with any new release, there are some frequently asked deployment questions, and known issues, or issues reported by some customers. You may not face these in your environment, but we're posting these here along with some workarounds so you're aware of them as you test and deploy SP1.&lt;/p&gt;  &lt;ol class="liststuff"&gt;&lt;li&gt;&lt;h3&gt;Upgrade order&lt;/h3&gt; &lt;p&gt;The order of upgrade from Exchange 2010 RTM to SP1 hasn’t changed from what was done in Exchange 2007. Upgrade server roles in the following order: &lt;/p&gt; &lt;ol class="shortol"&gt;&lt;li&gt;Client Access server &lt;/li&gt;&lt;li&gt;Hub Transport server &lt;/li&gt;&lt;li&gt;Unified Messaging server &lt;/li&gt;&lt;li&gt;Mailbox server&lt;/li&gt;&lt;/ol&gt; &lt;p&gt;The Edge Transport server role can be upgraded at any time; however, we recommend upgrading Edge Transport either before all other server roles have been upgraded or after all other server roles have been upgraded. For more details, see &lt;a title="More details on upgrading from Exchange 2010 RTM to Exchange 2010 SP1 in the documenation" href="http://technet.microsoft.com/en-us/library/bb629560.aspx"&gt;Upgrade from Exchange 2010 RTM to Exchange 2010 SP1&lt;/a&gt; in the documenation. &lt;/p&gt; &lt;/li&gt;&lt;li&gt;&lt;h2&gt;SP1 Prerequisites&lt;/h2&gt; &lt;/p&gt;SP1 requires the installation of 4-5 hotfixes, depending on the operating system – Windows Server 2008, or Windows Server 2008 R2. To install the Exchange 2010 SP1 administration tools on Windows 7 and Windows Vista, you requires 2 hotfixes.&lt;/p&gt;  &lt;p class="note"&gt;Note: Due to the shared code base for these updates, Windows Server 2008 and Windows Vista share the same updates. Similarly, Windows Server 2008 R2 and Windows 7 share the same updates. Make sure you &lt;span class="bold"&gt;select the x64 versions&lt;/span&gt; of each update to be installed on your Exchange 2010 servers.&lt;/p&gt;  &lt;p&gt;Here’s a matrix of the updates required, including download locations and file names.&lt;/p&gt; &lt;table style="font:.9em;" class="posttable" width="80%" border="0" cellspacing="0" cellpadding="2"&gt;   &lt;tr&gt;     &lt;th bgcolor="#C4DFEA" scope="col"&gt;Hotfix&lt;/th&gt;     &lt;th bgcolor="#C4DFEA" scope="col"&gt;Download&lt;/th&gt;     &lt;th bgcolor="#C4DFEA" scope="col"&gt;Windows Server 2008&lt;/th&gt;     &lt;th bgcolor="#C4DFEA" scope="col"&gt;Windows Server 2008 R2&lt;/th&gt;     &lt;th bgcolor="#C4DFEA" scope="col"&gt;Windows 7 &amp;amp; Windows Vista&lt;/th&gt;   &lt;/tr&gt;   &lt;tr&gt;     &lt;td&gt;&lt;div align="left"&gt;&lt;a href="http://go.microsoft.com/fwlink/?linkid=3052&amp;amp;kbid=979744"&gt;979744&lt;/a&gt;&lt;br /&gt;     A .NET Framework 2.0-based Multi-AppDomain application stops   responding when you run the application&lt;/div&gt;&lt;/td&gt;     &lt;td&gt;&lt;a href="http://code.msdn.microsoft.com/KB979744/Release/ProjectReleases.aspx?ReleaseId=3993"&gt;MSDN&lt;/a&gt;&lt;br /&gt;     or &lt;a href="http://connect.microsoft.com/VisualStudio/Downloads/DownloadDetails.aspx?DownloadID=27109"&gt;Microsoft Connect&lt;/a&gt;&lt;br /&gt;&lt;/td&gt;     &lt;td&gt;Windows6.0-KB979744-x64.msu   (CBS: Vista/Win2K8)&lt;strong&gt;&lt;br /&gt;     &lt;/strong&gt;&lt;/td&gt;     &lt;td&gt;Windows6.1-KB979744-x64.msu   (CBS: Win7/Win2K8 R2) &lt;/td&gt;     &lt;td bgcolor="#999999"&gt;&lt;div align="center"&gt;N. A.&lt;/div&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;     &lt;td&gt;&lt;div align="left"&gt;&lt;a href="http://go.microsoft.com/fwlink/?linkid=3052&amp;amp;kbid=983440"&gt;983440&lt;/a&gt; &lt;br /&gt;     An ASP.NET 2.0 hotfix rollup package is available for Windows 7   and for Windows Server 2008 R2&lt;/div&gt;&lt;/td&gt;     &lt;td&gt;&lt;a href="http://support.microsoft.com/hotfix/KBHotfix.aspx?kbnum=983440"&gt;Request from CSS&lt;/a&gt;&lt;/td&gt;     &lt;td&gt;&lt;div align="center"&gt;Yes&lt;/div&gt;&lt;/td&gt;     &lt;td&gt;&lt;div align="center"&gt;Yes&lt;/div&gt;&lt;/td&gt;     &lt;td bgcolor="#999999"&gt;&lt;div align="center"&gt;N.A.&lt;/div&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;     &lt;td&gt;&lt;div align="left"&gt;&lt;a href="http://go.microsoft.com/fwlink/?linkid=3052&amp;amp;kbid=977624"&gt;977624&lt;/a&gt;&lt;br /&gt;     AD RMS  clients do not authenticate federated identity providers in Windows Server 2008  or in Windows Vista. Without this update, Active&amp;nbsp;Directory&amp;nbsp;Rights Management  Services (AD&amp;nbsp;RMS) features may stop working&lt;/div&gt;&lt;/td&gt;     &lt;td&gt;&lt;p&gt;Request  from CSS using the “&lt;strong&gt;View and request hotfix downloads&lt;/strong&gt;” link in the KBA | &lt;a href="http://support.microsoft.com/hotfix/KBHotfix.aspx?kbnum=977624&amp;amp;kbln=en-us"&gt;US-English&lt;/a&gt;&lt;br /&gt;       &lt;a href="http://support.microsoft.com/hotfix/KBHotfix.aspx?kbnum=977624&amp;amp;kbln=en-us"&gt;&lt;/a&gt; &lt;/p&gt;    &lt;/td&gt;     &lt;td&gt;Select the download  for Windows Vista for the x64 platform.&lt;/td&gt;     &lt;td bgcolor="#999999"&gt;&lt;div align="center"&gt;N.A.&lt;/div&gt;&lt;/td&gt;     &lt;td bgcolor="#999999"&gt;&lt;div align="center"&gt;N.A.&lt;/div&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;     &lt;td&gt;&lt;div align="left"&gt;&lt;a href="http://go.microsoft.com/fwlink/?linkid=3052&amp;amp;kbid=979917"&gt;979917&lt;/a&gt; &lt;br /&gt;     Two issues  occur when you deploy an ASP.NET 2.0-based application on a server that is  running IIS 7.0 or IIS 7.5 in Integrated mode&lt;/div&gt;&lt;/td&gt;     &lt;td&gt;Request from CSS using the &lt;a href="https://support.microsoft.com/contactus/emailcontact.aspx?scid=sw;%5bLN%5d;1422&amp;amp;WS=hotfix"&gt;Hotfix Request Web Submission Form&lt;/a&gt; or by phone (no charge)&lt;/td&gt;     &lt;td&gt;&lt;div align="center"&gt;Yes&lt;/div&gt;&lt;/td&gt;     &lt;td bgcolor="#999999"&gt;&lt;div align="center"&gt;N. A.&lt;/div&gt;&lt;/td&gt;     &lt;td bgcolor="#999999"&gt;&lt;div align="center"&gt;N. A.&lt;/div&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;     &lt;td&gt;&lt;div align="left"&gt;&lt;a href="http://go.microsoft.com/fwlink/?linkid=3052&amp;amp;kbid=973136"&gt;973136&lt;/a&gt;, &lt;br /&gt;     FIX:  ArgumentNullException exception error message when a .NET Framework 2.0  SP2-based application tries to process a response with zero-length content to  an asynchronous ASP.NET Web service request: &amp;quot;Value cannot be null&amp;quot;.&lt;/div&gt;&lt;/td&gt;     &lt;td&gt;&lt;p&gt;&lt;a href="https://connect.microsoft.com/VisualStudio/Downloads/DownloadDetails.aspx?DownloadID=20922"&gt;Microsoft Connect&lt;/a&gt;&lt;/p&gt;    &lt;/td&gt;     &lt;td&gt;Windows6.0-KB973136-x64.msu&lt;/td&gt;     &lt;td bgcolor="#999999"&gt;&lt;div align="center"&gt;N.A.&lt;/div&gt;&lt;/td&gt;     &lt;td bgcolor="#999999"&gt;&lt;div align="center"&gt;N. A.&lt;/div&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;     &lt;td&gt;&lt;div align="left"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=194843"&gt;977592&lt;/a&gt;&lt;br /&gt;     RPC over HTTP clients cannot connect to the  Windows Server 2008 RPC over HTTP servers that have RPC load balancing enabled. &lt;/div&gt;&lt;/td&gt;     &lt;td&gt;&lt;p&gt;&lt;a href="http://support.microsoft.com/hotfix/KBHotfix.aspx?kbnum=977592&amp;amp;kbln=en-us"&gt;Request from  CSS&lt;/a&gt;&lt;/p&gt;    &lt;/td&gt;     &lt;td&gt;Select the download for Windows Vista (x64)&lt;/td&gt;     &lt;td bgcolor="#999999"&gt;&lt;div align="center"&gt;N.A.&lt;/div&gt;&lt;/td&gt;     &lt;td bgcolor="#999999"&gt;&lt;div align="center"&gt;N. A.&lt;/div&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;   &lt;td&gt;&lt;p align="left"&gt;&lt;a href="http://go.microsoft.com/fwlink/?linkid=3052&amp;amp;kbid=979099"&gt;979099&lt;/a&gt;&lt;br /&gt;        An update is  available to remove the application manifest expiry feature from AD RMS clients.&lt;/p&gt;&lt;/td&gt;     &lt;td&gt;&lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=87f72529-d316-42e8-bf77-a46951f66dda"&gt;Download Center&lt;/a&gt;&lt;/td&gt;     &lt;td bgcolor="#999999"&gt;&lt;div align="center"&gt;N. A.&lt;/div&gt;&lt;/td&gt;     &lt;td&gt;Windows6.1-KB979099-x64.msu&lt;/td&gt;     &lt;td bgcolor="#999999"&gt;&lt;div align="center"&gt;N. A.&lt;/div&gt;&lt;/td&gt;       &lt;/tr&gt;   &lt;tr&gt;      &lt;td&gt;&lt;p align="left"&gt;&lt;a href="http://go.microsoft.com/fwlink/?linkid=3052&amp;amp;kbid=982867" target="_blank"&gt;982867&lt;/a&gt;&lt;/p&gt;     &lt;p align="left"&gt;WCF services  that are hosted by computers together with a NLB fail in .NET Framework 3.5 SP1&lt;/p&gt;&lt;/td&gt;     &lt;td&gt;&lt;a href="http://code.msdn.microsoft.com/KB982867/Release/ProjectReleases.aspx?ReleaseId=4520"&gt;MSDN&lt;/a&gt;&lt;br /&gt;&lt;/td&gt;     &lt;td bgcolor="#999999"&gt;&lt;div align="center"&gt;N. A.&lt;/div&gt;&lt;/td&gt;     &lt;td&gt;Windows6.1-KB982867-v2-x64.msu (Win7) &lt;/td&gt;     &lt;td&gt;&lt;strong&gt;X86&lt;/strong&gt;: Windows6.1-KB982867-v2-x86.msu (Win7) &lt;br /&gt;       &lt;strong&gt;x64&lt;/strong&gt;: Windows6.1-KB982867-v2-x64.msu (Win7)&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;     &lt;td&gt;&lt;div align="left"&gt;&lt;a href="http://go.microsoft.com/fwlink/?linkid=3052&amp;amp;kbid=977020"&gt;977020&lt;/a&gt; &lt;br /&gt;     FIX: An  application that is based on the Microsoft .NET Framework 2.0 Service Pack 2  and that invokes a Web service call asynchronously throws an exception on a  computer that is running Windows 7.&lt;/div&gt;&lt;/td&gt;     &lt;td&gt;&lt;a href="http://connect.microsoft.com/VisualStudio/Downloads/DownloadDetails.aspx?DownloadID=27977"&gt;Microsoft Connect&lt;/a&gt;&lt;/td&gt;     &lt;td bgcolor="#999999"&gt;&lt;div align="center"&gt;N. A.&lt;/div&gt;&lt;/td&gt;     &lt;td bgcolor="#999999"&gt;&lt;div align="center"&gt;N. A.&lt;/div&gt;&lt;/td&gt;     &lt;td&gt;&lt;p&gt;x64: Windows6.1-KB977020-v2-x64.msu&lt;/p&gt;     X86:  Windows6.1-KB977020-v2-x86.msu&lt;/td&gt;   &lt;/tr&gt; &lt;/table&gt;  &lt;p&gt;Some of the hotfixes would have been rolled up in a Windows update or service pack. Given that the Exchange team released SP1 earlier than what was planned and announced earlier, it did not align with some of the work with the Windows platform. As a result, some hotfixes are available from MSDN/Connect, and some require that you request them online using the links in the corresponding KBAs. The administrator experience when initially downloading these hotfixes may be a little odd. However, once you download the hotfixes, and receive two of the hotfixes from CSS, you can use the same for subsequent installs on other servers. In due course, all these updates may become available on the Download Center, and also through Windows Update.&lt;/p&gt;  &lt;p class="alert"&gt;These hotfixes have been tested extensively as part of Exchange 2010 SP1 deployments within Microsoft and by our TAP customers. They are fully supported by Microsoft.&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;h2&gt;Prerequisite download pages linked from SP1 Setup are unavailable&lt;/h2&gt; &lt;p&gt;When installing Exchange Server 2010 SP1 the prereq check may turn up some required hotfixes to install. The message will include a link to click for help. Clicking this link redirects you to a page saying that the content does not exist.&lt;/p&gt;  &lt;p&gt;We're working to update the linked content.&lt;/p&gt;  &lt;p&gt;Meanwhile, please refer to the TechNet article &lt;a title="Go to 'Exchange 2010 Prerequisites' in Exchange 2010 SP1 docs" href="http://technet.microsoft.com/en-us/library/bb691354.aspx"&gt;Exchange 2010 Prerequisites&lt;/a&gt; to download and install the prerequisites required for your server version (the hotfixes are linked to in the above table, but you'll still need to install the usual prerequisites such as .Net Framework 3.5 SP1, Windows Remote Management (WinRM) 2.0, and the required OS components).&lt;/p&gt;   &lt;/li&gt;&lt;li&gt;&lt;h2&gt;The Missing Exchange Management Shell Shortcut&lt;/h2&gt; &lt;p&gt;Some customers have reported that after upgrading an Exchange Server 2010 server to Exchange 2010 SP1, the Exchange Management Shell shortcut is missing from program options. Additionally, the .ps1 script files associated with the EMS may also be missing.&lt;/p&gt;  &lt;p&gt;We’re actively investigating this issue. Meanwhile, here’s a workaround:&lt;/p&gt; &lt;ol&gt;&lt;li&gt;Verify that the following files are present in the &lt;span class="filepath"&gt;%ExchangeInstallPath%\bin&lt;/span&gt; directory: &lt;ul class="shortul" style="list-style-type:none;"&gt;&lt;li&gt;- CommonConnectFunctions.ps1 &lt;/li&gt;&lt;li&gt;- CommonConnectFunctions.strings.psd1 &lt;/li&gt;&lt;li&gt;- Connect-ExchangeServer-help.xml &lt;/li&gt;&lt;li&gt;- ConnectFunctions.ps1 &lt;/li&gt;&lt;li&gt;- ConnectFunctions.strings.psd1 &lt;/li&gt;&lt;li&gt;- RemoteExchange.ps1 &lt;/li&gt;&lt;li&gt;- RemoteExchange.strings.psd1&lt;/li&gt;&lt;/ul&gt;  &lt;p class="note"&gt;NOTE: If these files are missing, you can copy the files from the Exchange Server 2010 Service Pack 1 installation media to the %ExchangeInstallPath%\bin directory.  These files are present in the \setup\serverroles\common folder. &lt;/note&gt; &lt;/li&gt;&lt;li&gt;Click &lt;span class="command"&gt;Start -&gt; AdmiinistrativeTools -&gt;&lt;/span&gt;, right-click &lt;span class="command"&gt;Windows PowerShell Modules&lt;/span&gt;, select &lt;span class="command"&gt;Send to -&gt; Desktop (as shortcut)&lt;/span&gt;  &lt;/li&gt;&lt;li&gt;Go to the Properties of the shortcut and on &lt;span class="command"&gt;Target&lt;/span&gt; replace the path to &lt;span class="command"&gt;C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe -noexit -command ". 'C:\Program Files\Exchange Server\V14\bin\RemoteExchange.ps1'; Connect-ExchangeServer -auto"&lt;/span&gt; &lt;p class="note"&gt;Note: if the Exchange installation folder or drive name is different than the default, you need to change the path accordingly.&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;  &lt;/li&gt;&lt;li&gt;&lt;h2&gt;Upgrading Edge Transport on Forefront Threat Management Gateway (TMG) and Forefront Protection for Exchange 2010&lt;/h2&gt; &lt;p&gt;If you upgrade a server with the Edge Transport server role running with ForeFront Threat Management Gateway (TMG) and ForeFront Protection for Exchange (FPE) enabled for SMTP protection, the ForeFront TMG Managed Control Service may fail to start and E-mail policy configuration settings cannot be applied.&lt;/p&gt; &lt;p&gt;The TMG team is working on this issue. See &lt;a title="Read the post on the TMG team blog" href="http://blogs.technet.com/b/isablog/archive/2010/09/01/problems-when-installing-exchange-2010-service-pack-1-on-a-tmg-configured-for-mail-protection.aspx"&gt;Problems when installing Exchange 2010 Service Pack 1 on a TMG configured for Mail protection&lt;/a&gt; on the ForeFront TMG (ISA) Team Blog. &lt;a href="http://technet.microsoft.com/en-us/library/ff728620(EXCHG.141).aspx"&gt;Exchange 2010 SP1 Release Notes&lt;/a&gt; has been updated with the above information. &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;h2&gt;Static Address Book Service Port Configuration Changes&lt;/h2&gt; &lt;p&gt;The location for setting the port the address book service should use has changed in SP1. In Exchange 2010 RTM you had to edit the &lt;span class="filename"&gt;Microsoft.exchange.addressbook.service.exe.config&lt;/span&gt; to configure the service port. In SP1 you must use the following registry key:&lt;/br&gt; &lt;span class="bold"&gt;Path:&lt;/span&gt; &lt;span class="command"&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\MSExchangeAB\Parameters&lt;/span&gt; &lt;br&gt; &lt;span class="bold"&gt;Value name:&lt;/span&gt; &lt;span class="command"&gt;RpcTcpPort&lt;/span&gt;&lt;br&gt; &lt;span class="bold"&gt;Type:&lt;/span&gt; &lt;span class="command"&gt;REG_SZ&lt;/span&gt; (String) &lt;/p&gt;&lt;br&gt;  &lt;p&gt;When you apply SP1 to a machine where you had previously configured a static port by editing the Microsoft.exchange.addressbook.service.exe.config file, the upgrade process will not carry forward your static port assignments. Following a restart, the Address Book Service will revert to using a dynamic port instead of a static port specified in the config file. This may cause interruptions in service. &lt;/p&gt;  &lt;p&gt;As with all upgrades where servers are in load balanced pools, we recommend you perform a rolling upgrade &amp;mdash; removing servers from the pool, updating them and then moving the pool to the newly upgraded machines. Alternatively, we recommend that you upgrade an array of servers by draining connections from any one machine before you upgrade it. &lt;/p&gt;  &lt;p&gt;There are times when these approaches may not be possible. You can maintain your static port configuration, and have it take effect the moment the address book service starts for the first time following the application of the service pack, by creating the registry key BEFORE you apply SP1 to your server. The registry key has no impact pre SP1, and so by configuring it before you apply the Service Pack you can avoid the need to make changes to set the port post install, and avoid any service interruptions. &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;h2&gt;iPhone, OWA Premium and POP3 &amp; IMAP4 issues due to invalid accepted domain&lt;/h2&gt; &lt;p&gt;After applying E2010 SP1:&lt;/p&gt; &lt;ol&gt;&lt;li&gt;&lt;p&gt;iPhone users may not be able to view the content of incoming messages in their Inboxes, and when they try to open a message, they get an error saying: &lt;/p&gt; &lt;span class="command"&gt;This message has not been downloaded from the server. &lt;/span&gt; &lt;p&gt;Admins may see the following event logged in the Application Event Log on Exchange 2010 CAS Server: &lt;p class="EventId"&gt;Watson report about to be sent for process id: 1234, with parameters: E12, c-RTL-AMD64, 14.01.0218.011, AirSync, MSExchange ActiveSync, Microsoft.Exchange.Data.Storage.InboundConversionOptions.CheckImceaDomain, UnexpectedCondition:ArgumentException, 4321, 14.01.0218.015.&lt;/p&gt; &lt;/li&gt;&lt;li&gt;&lt;p&gt;OWA Premium users may not be able to reply or forward a message. They may see the following error in OWA: &lt;/p&gt; &lt;p class="error"&gt;An unexpected error occurred and your request couldn't be handled. Exception type: System.ArgumentException, Exception message: imceaDomain must be a valid domain name.&lt;/p&gt; &lt;/li&gt;&lt;li&gt;&lt;p&gt;POP3 &amp; IMAP4 users may also not be able to retrieve incoming mail and Admins will see the following event logged in Event Log: &lt;/p&gt; &lt;p class="EventID"&gt;ERR Server Unavailable. 21; RpcC=6; Excpt=imceaDomain must be a valid domain name.&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt; &lt;h3&gt;Resolution&lt;/h3&gt; &lt;p&gt;Please run the following command under Exchange Management Shell and verify that there is one domain marked as ‘Default’ and it's &lt;span class="parameter"&gt;DomainName&lt;/span&gt; &amp; &lt;span class="parameter"&gt;Name&lt;/span&gt; values are valid domain names. We were able to reproduce the issue by setting a domain name with a space in it, like &lt;span class="parameter"&gt;"aa bb"&lt;/span&gt;&lt;/p&gt; &lt;p class="code"&gt;Get-AcceptedDomain | fl&lt;/p&gt; &lt;p&gt;If you also have an invalid domain name there (for example, a domain name with a space in it), then removing the space and restarting the server will fix the EAS (iPhone), OWA, POP3 &amp; IMAP4 issues as mentioned above.&lt;/p&gt; &lt;p&gt;Command to run under EMS would be:&lt;/p&gt; &lt;p class="code"&gt;Set-AcceptedDomain –Identity &amp;#60;value&amp;#62; -Name “ValidSMTPDomainName”&lt;/p&gt;  &lt;p&gt;Thes examples update the Name parameter of the "My Company" and "ABC Local" accepted domains (the space is removed from both):&lt;/p&gt; &lt;p class="code"&gt;Set-AcceptedDomain –Identity “My Company” –Name “MyCompany.Com”&lt;br&gt; Set-AcceptedDomain –Identity “ABC Local” –Name “ABC.Local”&lt;/p&gt; &lt;/li&gt;&lt;li&gt;&lt;h2&gt;Error when adding or removing a mailbox database copy&lt;/h2&gt; &lt;p&gt;If a server running Exchange 2010 RTM (or Exchange 2010 SP1 Beta) is upgraded to Exchange 2010 SP1, administrators may experience an error when using the Add-MailboxdDatabaseCopy or Remove-MailboxDatabaseCopy cmdlets to add or remove &lt;acronym title="Database Availability Group"&gt;DAG&lt;/acronym&gt; members.&lt;/p&gt;  &lt;p&gt;When you try to add a DAG member, you may see the following error:&lt;/p&gt; &lt;p class="code"&gt;Add-MailboxDatabaseCopy DAG-DB0 -MailboxServer DAG-2&lt;/p&gt; &lt;p&gt;The result:&lt;/p&gt; &lt;p class="consoletext"&gt;&lt;span class="red"&gt;WARNING: An unexpected error has occurred and a Watson dump is being generated: Registry key has subkeys and recursive  removes are not supported by this method.&lt;/br&gt; &amp;nbsp;&lt;br&gt; Registry key has subkeys and recursive removes are not supported by this method. &lt;br&gt;     + CategoryInfo          : NotSpecified: (:) [Add-MailboxDatabaseCopy], InvalidOperationException &lt;br&gt;     + FullyQualifiedErrorId : System.InvalidOperationException,Microsoft.Exchange.Management.SystemConfigurationTasks. &lt;br&gt;    AddMailboxDatabaseCopy&lt;/span&gt;&lt;/p&gt;     &lt;p&gt;The command is not successful in adding the copy or updating Active Directory to show the copy was added. This happens due to presence of the &lt;span class="regkey"&gt;DumpsterInfo&lt;/span&gt; registry key.&lt;/p&gt;  &lt;p&gt;&lt;span class="bold"&gt;Workaround:&lt;/span&gt; Delete the DumpsterInfo key, as shown below.&lt;/p&gt; &lt;ol&gt;&lt;li&gt;&lt;p&gt;Identify the GUID of the database that is being added using this command:&lt;/p&gt; &lt;p class="code"&gt;Get-MailboxDatabase DAG-DB0 | fl name,GUID &lt;/p&gt; &lt;p&gt;The result:&lt;/p&gt; &lt;p class="consoletext"&gt;Name : DAG-DB0 &lt;br&gt; Guid : 8d3a9778-851c-40a4-91af-65a2c487b4cc&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p&gt;On the server specified in the add command, using the database GUID identified, remove the following registry key:&lt;br&gt; &lt;span class="regkey"&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ExchangeServer\v14\Replay\State\&lt;span class="lightyellow"&gt;&amp;#60;DB-GUID&amp;#62;&lt;/span&gt;\DumpsterInfo&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;The GUID identified in this case is &lt;span class="parameter"&gt;8d3a9778-851c-40a4-91af-65a2c487b4cc&lt;/span&gt;.  With this information you can now export and delete the &lt;span class="regkey"&gt;DumpsterInfo&lt;/span&gt; key on the server where you are attempting to add the mailbox database copy. This can be easily done using the registry editor, but if you have more than a handful of DAG members, this is best automated using the Shell.&lt;/p&gt;  &lt;p&gt;This example removes the DumpsterInfo key from the 8d3a9778-851c-40a4-91af-65a2c487b4cc key:&lt;/p&gt; &lt;p class="code"&gt;Remove-Item HKLM:\Software\Microsoft\ExchangeServer\Replay\State\8d3a9778-851c-40a4-91af-65a2c487b4cc\DumpsterInfo&lt;/p&gt;  &lt;p&gt;To automate this across all servers in your organization, use the &lt;span class="command lightyellow"&gt;DeleteDumpsterRegKey.ps1&lt;/a&gt;&lt;/span&gt; script.&lt;/p&gt; &lt;div class="download"&gt; &lt;span class="bold"&gt;File:&lt;/span&gt; &lt;a href="http://msexchangeteam.com/files/12/attachments/entry456090.aspx"&gt;deletedumpsterregkey_ps1.txt&lt;/a&gt;&lt;br&gt; &lt;span class="bold"&gt;Description:&lt;/span&gt; The DeleteDumpsterRegkey.ps1 script can be used to delete the offending DumpsterInfo registry keys that can cause this problem on all mailbox servers in the organization. Rename the file to DeleteDumpsterRegkey.ps1 (remove the &lt;span class="filename"&gt;.txt&lt;/span&gt; extension).&lt;/div&gt; &lt;p&gt;For more info, see Tim McMichael’s blog post &lt;a title="Read 'Exchange 2010 SP1: Error when adding or removing a mailbox database copy' on Tim's blog" href="http://blogs.technet.com/b/timmcmic/archive/2010/08/29/exchange-2010-sp1
-error-when-adding-or-removing-a-mailbox-database-copy.aspx
"&gt;Exchange 2010 SP1: Error when adding or removing a mailbox database copy&lt;/a&gt;.&lt;/p&gt; &lt;/li&gt;&lt;/ol&gt; &lt;/ol&gt;  &lt;p&gt;Thanks to all the folks in CSS and Exchange teams who helped identify, validate and provide workarounds for some of the issues mentioned above, and to the Exchange community and MVPs for their feedback.&lt;/p&gt;  &lt;p&gt;&lt;span class="author"&gt;&lt;a href="http://msexchangeteam.com/articles/449351.aspx"&gt;Bharat Suneja&lt;/a&gt;&lt;/span&gt;, &lt;span class="author"&gt;&lt;a href="http://msexchangeteam.com/archive/2004/01/27/63464.aspx"&gt;Nino Bilic&lt;/a&gt;&lt;/span&gt;&lt;br&gt; M. Amir Haque, &lt;a href="http://msexchangeteam.com/archive/2008/12/01/450205.aspx"&gt;Greg Taylor&lt;/a&gt;, &lt;br&gt; &amp; Tim McMichael&lt;/p&gt;  &lt;h4&gt;Updates:&lt;/h4&gt; &lt;/ul&gt;&lt;li&gt;9/7/2010: Updated list of files for the missing Exchange Management Shell shortcut issue &lt;/li&gt;&lt;/ul&gt;  &lt;/div&gt;&lt;img src="http://msexchangeteam.com/aggbug.aspx?PostID=456094" width="1" height="1"&gt;</description><category domain="http://msexchangeteam.com/archive/category/11164.aspx">Exchange 2010</category><category domain="http://msexchangeteam.com/archive/category/3308.aspx">Setup</category></item><item><title>Exchange 2010 SP1 and Support for FIPS Compliant Algorithms</title><link>http://msexchangeteam.com/archive/2010/08/30/456070.aspx</link><pubDate>Mon, 30 Aug 2010 11:50:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:456070</guid><dc:creator>Exchange</dc:creator><slash:comments>1</slash:comments><comments>http://msexchangeteam.com/comments/456070.aspx</comments><wfw:commentRss>http://msexchangeteam.com/commentrss.aspx?PostID=456070</wfw:commentRss><wfw:comment>http://msexchangeteam.com/rsscomments/456070.aspx</wfw:comment><description>&lt;div style="font:normal 1.2em 'Calibri',Helvetica,Arial,sans-serif; margin:1em 0 1em 0;"&gt; &lt;p&gt;&lt;span class="question"&gt;When will Exchange Server 2010 support FIPS compliance? &lt;/span&gt; &lt;br&gt; Exchange Server 2010 SP1 provides for the ability to disable algorithms which are not &lt;acronym title="Federal Information Processing Standards"&gt;FIPS&lt;/acronym&gt; 140-2 compliant. These algorithms are used for encryption, hashing, and signing within the Windows Server 2008 and Windows Server 2008 R2 operating systems that support Exchange Server 2010. When the &lt;span class="bold"&gt;&lt;a title="Read KBA 811833" href="http://support.microsoft.com/kb/811833"&gt;System cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing&lt;/a&gt;&lt;/span&gt; setting is enabled in a Group Policy or Local Policy, it disables the use of non-FIPS compliant algorithms such as RC-4. In Exchange 2010 RTM, it caused certain functions to fail. The most notable issue was in Outlook Web App (OWA), as documented in Microsoft Knowledge Base Article &lt;a title="Read KBA 977961" href="http://support.microsoft.com/kb/977961"&gt;KB977961&lt;/a&gt;, and in the web-based Exchange Control Panel (ECP). &lt;/p&gt; &lt;p&gt;&lt;span class="question"&gt;What is FIPS?&lt;/span&gt; &lt;br&gt; Federal Information Processing Standards (FIPS) are standards utilized to define security and interoperability requirements for cryptographic algorithms that the US Government uses. The FIPS 140-2 publication and standard (&lt;span class="italic"&gt;Security Requirements for Cryptographic Modules&lt;/span&gt; - &lt;a title="Download the publication from NIST" href="http://csrc.nist.gov/publications/fips/fips140-2/fips1402.pdf"&gt;PDF&lt;/a&gt;) defines the cryptographic algorithms as well as standards for key generation and key management. There are several FIPS publications which define how to further secure information systems and provide a standard upon which systems can be evaluated. &lt;/p&gt; &lt;p&gt;For more information on how Microsoft products and libraries comply with FIPS 140, see &lt;a title="Find out how Microsoft products and libraries comply with FIPS 140" href="http://technet.microsoft.com/en-us/library/cc750357.aspx"&gt;FIPS 140 Evaluation&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;&lt;span class="question"&gt;The importance of FIPS compliance to specific customers &lt;/span&gt; &lt;br&gt; Within the United States our customers utilize several guidelines, checklists, and requirements for securing systems, all which call for this policy setting to be enabled on the application’s host operating system (OS). In addition we have customers that do business with the US Government or work in industries where there is significant government oversight. &lt;p&gt;This policy setting ensures that the host OS, Windows Server 2008 SP2 or greater and Windows Server 2008 R2 or greater, in this case, only utilizes cryptographic algorithms that have passed the Cryptographic Module Validation Program and have been certified by the National Institute for Standards and Technology. Try saying that really fast three times. &lt;p&gt;The Windows Server OS, specifically the Windows Cryptographic Service Provider (CSP) is responsible for leveraging FIPS compliant algorithms for cipher, hashing, signing and encryption and we don’t actually need to enable anything within Exchange Server 2010. Exchange 2010 does have to know how to process the information provided via the &lt;acronym title="Operating System"&gt;OS&lt;/acronym&gt;, OS components such as Internet Information Server (IIS), and the Windows &lt;acronym title="Cryptograpic Service Provider"&gt;CSP&lt;/acronym&gt;. Exchange 2010 was released without support for servers which had this setting enabled, but had support and testing aligned for release with Exchange 2010 SP1. &lt;/p&gt; &lt;p&gt;&lt;span class="question"&gt;What happens when this policy setting is enabled?&lt;/span&gt; &lt;br&gt; In Exchange 2010 RTM, when the policy setting &lt;span class="bold"&gt;System cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing &lt;/span&gt;is enabled on the Windows Server 2008 or Windows Server 2008 R2 OS, the Schannel Security Provider (SSP) disables Secure Sockets Layer (SSL) protocols which are not part of the FIPS 140 standard. When this policy setting is enabled only FIPS 140-2 approved cryptographic algorithms are utilized. Examples of FIPS 140-2 compliant algorithms are the Triple Data Encryption Standard (3DES) and Triple Data Encryption Algorithm (TDEA) cipher, Advanced Encryption Standard (AES) algorithm and the Secure Hashing Algorithm (SHA) for hashing. In addition only the Transport Layer Security for Secure Sockets Layer (TLS/SSL) protocols will be utilized. &lt;/p&gt; &lt;p&gt;For those of you who have enabled the &lt;span class="bold"&gt;System cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing&lt;/span&gt; setting on an Exchange 2010 server, you may have discovered two distinct issues. The first is that Outlook Web App on your Client Access Servers (CAS) appears to work but generates errors once the customer provides their username and password or smartcard PIN. &lt;/p&gt; &lt;p&gt;For those of us that have customers using Kerberos constrained delegation (KCD), OWA errors out with:&lt;br&gt; &lt;span class="command" style="color:#333;"&gt;! An unexpected error occurred and your request couldn’t be handled&lt;/span&gt;&lt;/p&gt; &lt;p&gt;Expanding the &lt;span class="bold"&gt;Show Details&lt;/span&gt; link provides additional detail, specifically an exception message stating:&lt;br&gt; &lt;span class="command"&gt;The type initializer for ‘Microsoft.Exchange.Data.Storage.GccUtils’ threw an exception&lt;/span&gt;&lt;/p&gt; &lt;p&gt;Additionally, an error event (Event ID 4999&lt;/span&gt;, Source: MSExchange Common) will be logged in the Application event log on the Exchange CAS.&lt;/p&gt; &lt;p&gt;The second issue is near-identical where the web-based &lt;acronym title="Exchange Control Panel"&gt;ECP&lt;/acronym&gt; functionality, also provided by the CAS, will fail. &lt;/p&gt; &lt;p&gt;&lt;span class="question"&gt;How will this be fixed?&lt;/span&gt; &lt;br&gt; In Exchange 2010 SP1, changes have been made to the code base, tested and verified, to support this setting. Exchange 2010 SP1 operates with support for FIPS 140-2 algorithms if the Windows Server 2008 SP2 and Windows Server 2008 R2 operating systems are configured to utilize the FIPS 140-2 algorithms for system cryptography. &lt;/p&gt; &lt;p&gt;&lt;span class="question"&gt;My agency/organization/customer/co-worker asked about this support yesterday. When will Exchange Server 2010 SP1 be released?&lt;/span&gt; &lt;br&gt; Exchange 2010 SP1 has been released and can be downloaded &lt;a title="Download Exchange 2010 SP1" href="http://go.microsoft.com/fwlink/?LinkID=199950"&gt;here&lt;/a&gt;. &lt;/p&gt; &lt;p&gt;Thanks for your time and my customers and I look forward to it as well! &lt;p&gt;&lt;span class="author"&gt;Bob Christian II&lt;/span&gt;&lt;/p&gt; &lt;/div&gt;&lt;img src="http://msexchangeteam.com/aggbug.aspx?PostID=456070" width="1" height="1"&gt;</description><category domain="http://msexchangeteam.com/archive/category/11164.aspx">Exchange 2010</category><category domain="http://msexchangeteam.com/archive/category/11152.aspx">Security</category></item><item><title>Effects of Throttling on Your Deployment in Exchange 2010 SP1</title><link>http://msexchangeteam.com/archive/2010/08/27/456040.aspx</link><pubDate>Fri, 27 Aug 2010 21:52:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:456040</guid><dc:creator>Exchange</dc:creator><slash:comments>4</slash:comments><comments>http://msexchangeteam.com/comments/456040.aspx</comments><wfw:commentRss>http://msexchangeteam.com/commentrss.aspx?PostID=456040</wfw:commentRss><wfw:comment>http://msexchangeteam.com/rsscomments/456040.aspx</wfw:comment><description>&lt;div style="font:normal 1.2em 'Calibri',Helvetica,Arial,sans-serif; margin:1em 0 1em 0;"&gt;&lt;p&gt;Exchange 2010 features a new resource protection mechanism - user throttling. This feature is designed to limit the amount of resources a single user or application can take up on a &lt;acronym title="Client Access Server"&gt;CAS&lt;/acronym&gt; to prevent poorly written applications from causing denial of service (DoS) to the rest of the users. You can read about throttling in &lt;a href="http://technet.microsoft.com/en-us/library/dd297964.aspx"&gt;Understanding Client Throttling Policies&lt;/a&gt;. If any of the terminology in this post sounds unfamiliar, please refer to this documentation.&lt;/p&gt; &lt;p&gt;While Exchange 2010 &lt;acronym title="Release to Manufacturing"&gt;RTM&lt;/acronym&gt; shipped with user throttling "off" by default (most limits were set to infinite), after more testing in Exchange 2010 SP1, we've come up with a tighter set of limits for the throttling policies, and have thus turned user throttling &lt;b&gt;on &lt;/b&gt;by default. &lt;/p&gt; &lt;p&gt;We have also changed what happens when users exceed their budget in some cases. In Exchange 2010 RTM version, Exchange &lt;b&gt;rejected&lt;/b&gt; any Exchange Web Service (EWS), Exchange ActiveSync (EAS) and Outlook Web App (OWA) requests made by users who exceeded their budget. We've improved on this idea in SP1 in the EWS and ActiveSync protocols, by instead &lt;b&gt;delaying&lt;/b&gt; the call just enough for the budget to recharge back into the positive and then execute the request. This means that end users will generally see fewer errors from the ActiveSync client or EWS application. In some rare conditions, such as if the caller is exceeding max number of connections or subscriptions in EWS,  we'll still reject the request.&lt;/p&gt; &lt;p&gt;The longest a single request can be delayed is a minute, but this would be an extreme case and one that would signify that something is out of place either on the server, or with the caller. Typically, users and applications will not encounter throttling (except maybe if the user is doing a sync of the whole mailbox).&lt;b&gt; However, some resource-heavy applications may start to get throttled in SP1.&lt;/b&gt; If throttling does kick in, the delays will be short enough that users won't notice any effect. However, we've provided ways to gain an insight into what is the user's experience is like due to throttling. &lt;/p&gt; &lt;p&gt;There are two main ways to monitor throttling - by monitoring perf counters and by looking at &lt;acronym title="Internet Information Services"&gt;IIS&lt;/acronym&gt; logs. First, SP1 offers the following useful perf counters (instance is per CAS process) to monitor throttling under the &lt;b&gt;MSExchange Throttling&lt;/b&gt; category on a CAS:  &lt;ul&gt; &lt;li&gt;&lt;b&gt;Max Delay Per Minute&lt;/b&gt; - this value represents the longest amount of time in msec that anyone was delayed due to throttling in the past minute.   &lt;/li&gt;&lt;li&gt;&lt;b&gt;Max Effective Time In *&lt;/b&gt; - this set of counters say that &lt;b&gt;if&lt;/b&gt; the throttling policy was set to the counter values, then all requests that have been encountered in the past minute would all go through unthrottled.   &lt;/li&gt;&lt;li&gt;&lt;b&gt;Users Delayed X Milliseconds &lt;/b&gt;- the number of users who saw delays greater than "X" (see Delay Time Threshold) milliseconds in the past minute.   &lt;/li&gt;&lt;li&gt;&lt;b&gt;Users X Times OverBudget&lt;/b&gt; - the number of users whose requests were rejected more than "X" times in the past minute (see OverBudgetThreshold).   &lt;/li&gt;&lt;li&gt;&lt;b&gt;OverBudgetThreshold&lt;/b&gt; - the "X" value for the "Users X Times OverBudget" counter.   &lt;/li&gt;&lt;li&gt;&lt;b&gt;Delay Time Threshold&lt;/b&gt; - the "X" value for the "Users Delayed X Milliseconds" counter.   &lt;/li&gt;&lt;li&gt;&lt;b&gt;Total Unique Budgets&lt;/b&gt; - number of unique budgets (ie callers/users) seen in the past minute   &lt;/li&gt;&lt;li&gt;&lt;b&gt;Unique Budgets OverBudget&lt;/b&gt; - number of unique budgets that went over budget in the past minute&lt;/li&gt;&lt;/ul&gt;  &lt;p&gt;The general rule is that if the "Unique Budgets OverBudget" counter is graphing a line that's close to the "Total Unique Budgets" line, then most of the users in your system are getting throttled. You can further refine that by checking how many users are seeing rejections vs how many are getting delayed by viewing the appropriate "Users X times ..." counter. Finally, you can see if and how much users are delayed by viewing the "Max Delay Per Minute" counter. Also, all of these counters are saved off to SCOM once every minute.  &lt;p&gt;If you do determine that many of your users are getting throttled, you may further try to understand why by digging into IIS logs. As of SP1, only ActiveSync, OWA and EWS log throttling info to IIS. By searching IIS for users or the string "overbudget", you can view which requests they have been making and which have been going over budget. You can refer to &lt;a href="http://blogs.msdn.com/b/exchangedev/archive/2010/03/10/budget-snapshots-in-the-iis-logs.aspx"&gt;Budget Snapshots in the IIS Logs&lt;/a&gt; for a breakdown of the different parts of the budget.  &lt;/p&gt; &lt;p&gt;If you do determine that your users or applications are throttled too much by your standards and their scenarios are in fact legitimate, then you can tweak the throttling settings to reflect your environment's use by:   &lt;ol&gt; &lt;li&gt;Turning throttling off  &lt;li&gt;Running your regular traffic through Exchange   &lt;/li&gt;&lt;li&gt;Watching what the "Max Effective Time In *" counters report over the course of a few days   &lt;/li&gt;&lt;li&gt;Setting the throttling policies to that value. To do this, call Get-ThrottlingPolicy ?| { $_.IsDefault} | Set-ThrottlingPolicy &amp;lt;new param values&amp;gt;&lt;/li&gt;&lt;/ol&gt;&lt;/p&gt; &lt;p&gt;Alternatively, if it is an EWS application using a service account that becomes throttled, and you determine that it is not resource intensive to the Exchange server, you should create a new, custom throttling policy for it. To do this: &lt;ol&gt; &lt;li&gt;Call New-ThrottlingPolicy and set the proper parameters (refer to Exchange documentation at the top of the document for explanation of the parameters)   &lt;/li&gt;&lt;li&gt;Call Get-Mailbox &amp;lt;mailbox of service account that the app is using) | Set-Mailbox -ThrottlingPolicy:&amp;lt;your policy that you just created&amp;gt;&lt;/li&gt;&lt;/ol&gt;&lt;/p&gt;  &lt;p&gt;The changes will be picked up within 15 minutes, or immediately after you recycle the EWS app pool in IIS. Please note that custom policies are meant as &lt;b&gt;one-off&lt;/b&gt; solutions when a few applications or users are getting throttled and the load they are putting on the system is actually legitimate. You shouldn't update everyone's link to a custom policy - if you need to change throttling settings for the majority of your users, edit the default policy. For more information on throttling please refer to the official documentation linked at the top of this article.  &lt;/p&gt; &lt;p&gt;&lt;span class="author"&gt;&lt;a href="http://msexchangeteam.com/articles/455912.aspx"&gt;Andrew Salamatov&lt;/a&gt;&lt;/span&gt;&lt;/p&gt; &lt;/div&gt;&lt;img src="http://msexchangeteam.com/aggbug.aspx?PostID=456040" width="1" height="1"&gt;</description><category domain="http://msexchangeteam.com/archive/category/11156.aspx">Client Access</category><category domain="http://msexchangeteam.com/archive/category/11164.aspx">Exchange 2010</category><category domain="http://msexchangeteam.com/archive/category/11152.aspx">Security</category></item><item><title>The Future of Exchange Starts Here: Exchange Server 2010 SP1 Is Now Available</title><link>http://msexchangeteam.com/archive/2010/08/25/455861.aspx</link><pubDate>Wed, 25 Aug 2010 13:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:455861</guid><dc:creator>Exchange</dc:creator><slash:comments>124</slash:comments><comments>http://msexchangeteam.com/comments/455861.aspx</comments><wfw:commentRss>http://msexchangeteam.com/commentrss.aspx?PostID=455861</wfw:commentRss><wfw:comment>http://msexchangeteam.com/rsscomments/455861.aspx</wfw:comment><description>&lt;div style="font:normal 1.2em 'Calibri',Helvetica,Arial,sans-serif; margin:1em 0 1em 0;"&gt;&lt;div class="resources" style="width:175px;"&gt; &lt;ul style="font-size:1.2em;color:#3b79cc;list-style-type:none;list-style-position:outside;margin-left:.5em;"&gt;&lt;li&gt;&lt;a title="Download Exchange 2010 SP1" href="http://go.microsoft.com/fwlink/?LinkID=199950"&gt;download&lt;/a&gt; &lt;/li&gt;&lt;li&gt;&lt;a title="Find out What's New in Exchange 2010 SP1" href="http://technet.microsoft.com/en-us/library/ff459257(EXCHG.141).aspx"&gt;what's new&lt;/a&gt; &lt;/li&gt;&lt;li&gt;&lt;a title="Read the Exchange 2010 SP1 Release Notes" href="http://technet.microsoft.com/en-us/library/ff728620(EXCHG.141).aspx"&gt;release notes&lt;/a&gt; &lt;/li&gt;&lt;li&gt;&lt;a title="See the prerequisites for Exchange 2010 SP1" href="http://technet.microsoft.com/en-us/library/bb691354.aspx"&gt;prerequisites&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;p style="font-size:1.3em;line-height:1.4em;"&gt;You have been eagerly waiting, and we have been working hard over the summer to deliver the latest Exchange Server 2010 enhancements as soon as possible.  I am extremely happy to announce the availability of Exchange Server 2010 Service Pack 1, ready for download &lt;a title="Download Exchange Server 2010 Service Pack 1" href="http://go.microsoft.com/fwlink/?LinkID=199950"&gt;here&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;We released the SP1 beta at Tech Ed North America in June.  We also shared some of the SP1 enhancements in &lt;a style="font-weight:bold;" title="More details about SP1 features in 'Yes virginia, there is an Exchange Server 2010 SP1'" href="http://msexchangeteam.com/archive/2010/04/07/454533.aspx"&gt;Yes Virginia, there is an Exchange Server 2010 SP1&lt;/a&gt; back in April.  Since then, almost 500,000 SP1 mailboxes have gone into production in Technology Adoption Program (TAP) customer environments.&lt;/p&gt;  &lt;p&gt;Rather than recap all the SP1 features, I want to let a few of our Exchange TAP customers tell you what they loved.&lt;/p&gt; &lt;blockquote class="blockquote3"&gt; Exchange has been the most resilient and trusted solution for enterprise Email for many years now and when Exchange 2010 originally RTM’ed, I thought, what else could be improved…  But the Exchange product group and the TAP group members have done just that in Service Pack 1.  &lt;br&gt;&lt;br&gt; From improvements to manageability for both administrators and users to better control and resiliency within the SMTP stack, and fantastic improvements in Unified Messaging, the list of improvements and features in Service Pack 1 amazes even an old Exchange guy like me (who has worked on Exchange since early 4.0 days).   Of all the improvements in SP1, my favorite so far is the Audit Logging improvements available in the Exchange Management Shell and the Exchange Control Panel. &lt;br&gt;&lt;br&gt; All I can say is, “Great job Microsoft Exchange Product Group on another fantastic product!” &lt;br&gt; &lt;p class="citation"&gt;&lt;span class="author"&gt;Gary Cooper&lt;/span&gt;, Horizons Consulting&lt;/p&gt;&lt;/blockquote&gt; &lt;blockquote class="blockquote3"&gt;Calendar publishing is awesome.  When working with people outside our organization, instead of fumbling around in multiple emails or phone calls “Is Tuesday at 3 PM good?  How about next Wednesday at 9:30?” I can just send them a link to my calendar.  Now if more organizations would get to Exchange 2010 and federate their free\busy (including Microsoft).... &lt;br&gt; &lt;p class="citation"&gt;&lt;span class="author"&gt;Joseph Nguyen&lt;/span&gt;, University of Oklahoma&lt;/p&gt;&lt;/blockquote&gt; &lt;blockquote class="blockquote3"&gt;One of the most common criticisms from our customers regarding Exchange and OWA had been its lack of cross-browser and open systems support. Although we saw major improvements in Exchange 2010, SP1 has built upon this and taken things to the next level. SP1’s OWA experience is now class-leading and the addition of open standards calendar sharing is a feature we’ve been asked for many times - and have now been able to deliver. With SP1, our users can choose to share their Calendar in HTML and iCal formats, enabling real time sharing with external colleagues or access to their calendar from platforms and clients without Exchange support.  &lt;br&gt;&lt;br&gt; In addition to the OWA improvements, we’ve been delighted with some of the other new features. On the client side features like auto mapping of shared mailboxes to user’s Outlook 2010 profiles will remove a support headache.&lt;br&gt;&lt;br&gt; In the datacentre, the support for online archives on a separate database from the primary mailbox is the green light for archiving implementation.  Finally the ability to import and export PSTs without needing Outlook installed are a welcome addition and will be particularly useful when we begin importing archive PSTs back into Exchange for online archiving. &lt;br&gt; &lt;p class="citation"&gt;&lt;span class="author"&gt;Steve Goodman&lt;/span&gt;, Aston University&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;And a word from Dimension Data, one of Exchange’s Global Partners.&lt;/p&gt; &lt;blockquote class="blockquote3"&gt;Exchange 2010 SP1 is a great example of how Microsoft is rapidly responding to customer and partner feedback. We believe these new enhancements to the archiving functionality, improved Outlook Web App experiences, and expanded mobility capabilities can only accelerate the already strong customer demand we’ve seen for upgrades. And, the continual innovation delivered by Microsoft Exchange enables our business to maintain strong relationships with our customers by always having the ability to offer them new, next generation scenarios to consider and deploy. &lt;br&gt; &lt;p class="citation"&gt;&lt;span class="author"&gt;Peter Menadue&lt;/span&gt;, Group General Manager, Microsoft Solutions at Dimension Data&lt;/p&gt;&lt;/blockquote&gt;  &lt;p&gt;Once again, a huge thank you to all of our customers, TAP participants, and EHLO readers for downloading the SP1 Beta, and the constant stream of great feedback.  We couldn’t have done it without you!&lt;/p&gt;  &lt;p&gt;&lt;span class="author"&gt;Kevin Allison&lt;/span&gt;&lt;br&gt; GM – Exchange Customer Experience&lt;/p&gt;   &lt;/div&gt;&lt;img src="http://msexchangeteam.com/aggbug.aspx?PostID=455861" width="1" height="1"&gt;</description><category domain="http://msexchangeteam.com/archive/category/11163.aspx">Announcements</category><category domain="http://msexchangeteam.com/archive/category/11164.aspx">Exchange 2010</category></item><item><title>Exchange 2010 SP1: Database Integrity checking</title><link>http://msexchangeteam.com/archive/2010/08/23/455899.aspx</link><pubDate>Mon, 23 Aug 2010 19:36:02 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:455899</guid><dc:creator>Exchange</dc:creator><slash:comments>15</slash:comments><comments>http://msexchangeteam.com/comments/455899.aspx</comments><wfw:commentRss>http://msexchangeteam.com/commentrss.aspx?PostID=455899</wfw:commentRss><wfw:comment>http://msexchangeteam.com/rsscomments/455899.aspx</wfw:comment><description>&lt;div style="font:normal 1.2em 'Calibri',Helvetica,Arial,sans-serif; margin:1em 0 1em 0;"&gt;&lt;p style="font-size:1.1em;line-height:1.4em;"&gt;Since the earliest versions of Exchange Server, the &lt;a title="More about ISInteg in Exchange Server documenation" href="http://technet.microsoft.com/en-us/library/bb125144(EXCHG.80).aspx"&gt;Information Store Integrity Checker&lt;/a&gt; (ISInteg) has offered Exchange administrators a way to check mailbox and public folder database integrity. ISInteg checks and fixes Exchange database errors that may prevent the database from mounting, prevent the user from logging on or from receiving, opening or deleting email. Curious to know what changes are coming to ISInteg in Exchange 2010 SP1? Let's take a look.&lt;/p&gt; &lt;div class="importantnote"&gt;&lt;p style="font-size:1.2em;font-weight:bold;"&gt;In Exchange 2010 SP1, ISInteg is no longer a standalone program.&lt;/p&gt; &lt;p&gt;The functionality provided by the ISInteg tool has been rolled into two new Exchange Management Shell cmdlets: &lt;ul style="font-size:1.1em;"&gt;&lt;li&gt;&lt;span class="cmdlet" style="font-weight:normal !important;"&gt;New-MailboxRepairRequest&lt;/span&gt; &lt;/li&gt;&lt;li&gt;&lt;span class="cmdlet" style="font-weight:normal !important;"&gt;New-PublicFolderDatabaseRepairRequest&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;span class="bold"&gt;Note:&lt;/span&gt; Like other Shell cmdlets, these are subject to Role-Based Access Control (RBAC) scoping restrictions. For details, see &lt;a title="Go to 'Understanding Management Role Scopes' in Exchange 2010 documenation" href="http://technet.microsoft.com/en-us/library/dd335146.aspx"&gt;Understanding Management Role Scopes&lt;/a&gt;.&lt;/div&gt;  &lt;h2&gt;Cool Features&lt;/h2&gt; These new ISInteg cmdlets come with some cool new functionality!  &lt;ul&gt;&lt;li&gt;The cmdlets work with the database mounted. It's no longer required to unmount the database to perform an integrity check or fix database errors. &lt;/li&gt;&lt;li&gt;You can repair logical corruption at the mailbox level. &lt;/li&gt;&lt;li&gt;You can fix corrupt search folders. &lt;/li&gt;&lt;li&gt;You can fix the Provisional Fid. &lt;/li&gt;&lt;li&gt;You can fix Aggregate Counts.&lt;/li&gt;&lt;/ul&gt; &lt;h3&gt;ISInteg can now work at the database or mailbox level &lt;/h3&gt; &lt;p&gt;How does it do that? Well, the new schema in Exchange 2010 effectively partitions the database by mailbox. So the top problems fixed by ISInteg are now mostly limited to the affected mailboxes only. Previous versions of ISInteg required the database to be offline while validation and fixing are in progress. In Exchange 2010 SP1, the ability to do these checks at the mailbox level removes the need to dismount the database. It is actually required to have ISInteg operate against an online database! &lt;/p&gt; &lt;h2&gt;New-MailboxRepairRequest&lt;/h2&gt; The New-MailboxRepairRequest cmdlet detects and fixes the following types of mailbox corruptions:  &lt;ul&gt;&lt;li&gt;&lt;span style="font-weight:bold;"&gt;Search folder corruptions (&lt;span class="parameter lightyellow"&gt;SearchFolder&lt;/span&gt;): &lt;/span&gt; Repair tasks now look for all folders named in ptagSearchBacklinks, ptagSearchFIDs, and ptagRecursiveSearchFIDs and verifies that each folder exists. If the folder no longer exists, then it will remove that folder from the list.  &lt;/li&gt;&lt;li&gt;&lt;span style="font-weight:bold;"&gt;Aggregate counts on folders that aren't reflecting correct values (&lt;span class="parameter lightyellow"&gt;AggregateCounts&lt;/span&gt;):&lt;/span&gt; Repair tasks tally all messages in a folder and keep a running total of various counts and sizes. Once the iteration is complete, it will verify the computed counts against the persisted counts on the Folders table record for the folder. If there is a discrepancy, it will update the persisted counts to reflect the computed counts.  &lt;/li&gt;&lt;li&gt;&lt;span style="font-weight:bold;"&gt;Views on folders that aren't returning correct contents (&lt;span class="parameter lightyellow"&gt;FolderView&lt;/span&gt;):&lt;/span&gt; Repair tasks will iterate over all views for a folder and for each one, bring the view fully up to date and then reconstruct a temp copy. If there is a discrepancy between the existing view and the contents of the temp table, it will delete the view so it can be rebuilt from scratch the next time it is requested.  &lt;/li&gt;&lt;li&gt;&lt;span style="font-weight:bold;"&gt;Provisioned folders that are incorrectly pointing into unprovisioned parent folders (&lt;span class="parameter lightyellow"&gt;ProvisionedFolder&lt;/span&gt;):&lt;/span&gt; Repair tasks can fix Provisioned folders incorrectly pointing into unprovisioned parents or vice versa. &lt;/li&gt;&lt;/ul&gt; &lt;h3&gt;Syntax&lt;/h3&gt; &lt;p class="code"&gt;New-MailboxRepairRequest -Mailbox &amp;#60;MailboxIdParameter&amp;#62; -CorruptionType &amp;#60;MailboxStoreCorruptionType[]&amp;#62; [-Archive &amp;#60;SwitchParameter&amp;#62;] [-Confirm [&amp;#60;SwitchParameter&amp;#62;]] [-DetectOnly &amp;#60;SwitchParameter&amp;#62;] [-DomainController &amp;#60;Fqdn&amp;#62;] [-WhatIf [&amp;#60;SwitchParameter&amp;#62;]]&lt;/p&gt; &lt;p class="code"&gt;New-MailboxRepairRequest -Database &amp;#60;DatabaseIdParameter&amp;#62; -CorruptionType &amp;#60;MailboxStoreCorruptionType[]&amp;#62; [-Confirm [&amp;#60;SwitchParameter&amp;#62;]] [-DetectOnly &amp;#60;SwitchParameter&amp;#62;] [-DomainController &amp;#60;Fqdn&amp;#62;] [-WhatIf [&amp;#60;SwitchParameter&amp;#62;]] &lt;/p&gt; &lt;h3&gt;Parameters&lt;/h3&gt; &lt;li&gt;&lt;span class="parameter"&gt;Database&lt;/span&gt;, &lt;span class="parameter"&gt;Mailbox&lt;/span&gt; and &lt;span class="parameter"&gt;Archive&lt;/span&gt;: You can repair an &lt;span class="bold"&gt;entire mailbox database&lt;/span&gt; or a specified &lt;span class="bold"&gt;mailbox&lt;/span&gt; by specifying either the Database or the Mailbox parameter. You can't use both. To repair the archive mailbox for the specified user, use the Archive switch. &lt;li&gt;&lt;span class="parameter"&gt;CorruptionType&lt;/span&gt;: (at least 1 required) you are already familiar with, we discussed them above:  &lt;ul&gt;&lt;li&gt;&lt;span class="parameter"&gt;SearchFolder&lt;/span&gt;  &lt;/li&gt;&lt;li&gt;&lt;span class="parameter"&gt;AggregateCounts&lt;/span&gt;  &lt;/li&gt;&lt;li&gt;&lt;span class="parameter"&gt;ProvisionedFolder&lt;/span&gt;  &lt;/li&gt;&lt;li&gt;&lt;span class="parameter"&gt;FolderView&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;p&gt;You can run a repair task with multiple parameters if you separate them with a comma (as shown in the Examples section below). &lt;/p&gt; &lt;/li&gt;&lt;li&gt;&lt;span class="parameter"&gt;DetectOnly:&lt;/span&gt; (Optional) The &lt;span class="parameter"&gt;DetectOnly&lt;/span&gt; switch secifies that you want this command to report errors, but not fix them. You don't have to specify a value with this switch.  &lt;/li&gt;&lt;li&gt;Other Optional Parameters: This cmdlet supports the common parameters: Verbose, Debug, ErrorAction, ErrorVariable, WarningAction, WarningVariable, OutBuffer and OutVariable. For more information, type "get-help about_commonparameters". &lt;/li&gt;&lt;/ul&gt;  &lt;h2&gt;New-PublicFolderDatabaseRepairRequest&lt;/h2&gt; &lt;p&gt;The New-PublicFolderDatabaseRepairRequest cmdlet detects and fixes Public Folder replication state problems. &lt;/p&gt; &lt;h3&gt;Syntax&lt;/h3&gt; &lt;p class="code"&gt;New-PublicFolderDatabaseRepairRequest -Database &amp;#60;DatabaseIdParameter&amp;#62; -CorruptionType &amp;#60;PublicFolderDatabaseCorruptionType[]&amp;#62; [-Confirm [&amp;#60;SwitchParameter&amp;#62;]] [-DetectOnly &amp;#60;SwitchParameter&amp;#62;] [-DomainController &amp;#60;Fqdn&amp;#62;] [-WhatIf [&amp;#60;SwitchParameter&amp;#62;]]&lt;/p&gt; &lt;h3&gt;Parameters&lt;/h3&gt; &lt;ul&gt;&lt;li&gt;&lt;span class="parameter"&gt;Database&lt;/span&gt;: (required) Specifies the Public Folder database on which you will run this command. You can use one of the following values:  &lt;ul&gt;&lt;li&gt;GUID of the database &lt;/li&gt; &lt;/li&gt;&lt;li&gt;Database name &lt;/li&gt;&lt;/ul&gt; &lt;/li&gt;&lt;li&gt;&lt;span class="parameter"&gt;CorruptionType&lt;/span&gt;: (required) Pretty easy, there's only one value.  &lt;ul&gt;&lt;li&gt;ReplState &lt;/li&gt;&lt;/ul&gt; &lt;/li&gt;&lt;li&gt;&lt;span class="parameter"&gt;DetectOnly&lt;/span&gt;: (optional) Specifies that you want this command to report errors, but not fix them. You don't have to specify a value with this parameter.  &lt;/li&gt;&lt;li&gt;Other Optional Parameters: This cmdlet supports the common parameters: Verbose, Debug, ErrorAction, ErrorVariable, WarningAction, WarningVariable, OutBuffer and OutVariable. For more information, type "get-help about_commonparameters". &lt;/li&gt;&lt;/ul&gt; &lt;/li&gt;&lt;/ul&gt;  &lt;h2&gt;Examples&lt;/h2&gt; &lt;p class="code"&gt;New-MailboxRepairRequest -Mailbox administrator@contoso.com -CorruptionType SearchFolder, AggregateCounts, ProvisionedFolder, FolderView &lt;/p&gt;   &lt;p class="code"&gt;New-MailboxRepairRequest -Mailbox administrator -CorruptionType SearchFolder, AggregateCounts, ProvisionedFolder, FolderView -WhatIf &lt;/p&gt;   &lt;p class="code"&gt;New-PublicFolderDatabaseRepairRequest -Database PFD01 -CorruptionType ReplState -DetectOnly &lt;/p&gt;  &lt;p&gt;Some additional examples are provided in the cmdlet help. You can retrieve them using the following commands, or refer to &lt;a title="Go to New-MailboxRepairRequest cmdlet reference in Exchange 2010 SP1 docs" href="http://technet.microsoft.com/en-us/library/ff625226(EXCHG.141).aspx "&gt;New-MailboxRepairRequest&lt;/a&gt; and &lt;a title="Go to New-MailboxRepairRequest cmdlet reference in Exchange 2010 SP1 docs" href="http://technet.microsoft.com/en-us/library/ff718234(EXCHG.141).aspx"&gt;New-PublicFolderDatabaseRepairRequest&lt;/a&gt; cmdlet reference:&lt;/p&gt; &lt;p class="code"&gt;Get-help New-MailboxRepairRequest -examples &lt;br&gt; Get-help New-PublicFolderDatabaseRepairRequest -examples &lt;/p&gt;  &lt;p&gt;I recommend that you get to know the cmdlets by using the cmdlet reference docs, or by using the following commands to retrieve detailed help from the shell:&lt;/p&gt; &lt;p class="code"&gt;Get-help New-MailboxRepairRequest -detailed (or -full) &lt;br&gt; Get-help New-PublicFolderDatabaseRepairRequest -detailed (or -full) &lt;/p&gt;  &lt;h2&gt;Event Reporting&lt;/h2&gt; &lt;p&gt;After submitting the Mailbox or Public Folder repair request, you can monitor its progress with the Event Viewer. That's right, no more text logs to weed through. The events are logged under the MSExchangeIS Mailbox Store source. &lt;/p&gt; &lt;p&gt;The following event IDs will be logged for repair requests: &lt;/p&gt; &lt;ul&gt;&lt;li&gt;10047 A mailbox-level repair request started  &lt;/li&gt;&lt;li&gt;10064 A Public Folder repair request started  &lt;/li&gt;&lt;li&gt;10048 The repair request successfully completed.  &lt;/li&gt;&lt;li&gt;10050 The mailbox repair request task skipped a mailbox .  &lt;/li&gt;&lt;li&gt;10059 A database-level repair request started.  &lt;/li&gt;&lt;li&gt;10062 Corruption was detected. &lt;/li&gt;&lt;/ul&gt;  &lt;img src="http://msexchangeteam.com/photos/postpictures4/images/455900/original.aspx"&gt;&lt;br&gt; &lt;span class="caption"&gt;&lt;span class="bold"&gt;Figure 1:&lt;/span&gt; Mailbox or Public Folder database repair request events are logged in the Application event log&lt;/span&gt;  &lt;div class="note"&gt;&lt;p&gt;&lt;span class="bold"&gt;Note:&lt;/span&gt; the repair events will only show up on the mailbox server where the mailbox or Public Folder is located. &lt;/p&gt; &lt;p&gt;This is very important to remember. Just because you fired off a repair task on a mailbox server does not mean the events will show up on that server. The repair task will be run on the database where the mailbox itself is, and the events will be in the event log on that mailbox server and that server alone. &lt;/p&gt;&lt;/div&gt; &lt;p&gt;Things to remember: &lt;/p&gt; &lt;ul&gt;&lt;li&gt;Only 1 active repair task is permitted to be running per server if the active task is a database level repair.  &lt;/li&gt;&lt;li&gt;Only 100 mailbox level active repair tasks are permitted to be running at once per server.  &lt;/li&gt;&lt;li&gt;There is no -Server parameter to do all databases or mailboxes on a server.  &lt;/li&gt;&lt;li&gt;The repair task dies on database dismount or store stop/crash.  &lt;/li&gt;&lt;li&gt;The only way to stop a repair is to stop the store or dismount the database.  &lt;/li&gt;&lt;li&gt;Mailbox access will be disrupted for the mailbox that is being repaired.  &lt;/li&gt;&lt;li&gt;Repair for a mailbox will skip a mailbox if it has been quarantined.  &lt;/li&gt;&lt;li&gt;Repair will cause a move-mailbox operation to be delayed until the repair is completed.&lt;/li&gt;&lt;/ul&gt;  &lt;p&gt;&lt;span class="author"&gt;&lt;a href="http://msexchangeteam.com/articles/455856.aspx"&gt;Steve Bryant&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;    &lt;/div&gt;&lt;img src="http://msexchangeteam.com/aggbug.aspx?PostID=455899" width="1" height="1"&gt;</description><category domain="http://msexchangeteam.com/archive/category/3648.aspx">Administration</category><category domain="http://msexchangeteam.com/archive/category/11164.aspx">Exchange 2010</category><category domain="http://msexchangeteam.com/archive/category/11154.aspx">Mailbox</category><category domain="http://msexchangeteam.com/archive/category/3306.aspx">Troubleshooting</category></item><item><title>Geek Out with Perry on More Exchange Archiving and Storage</title><link>http://msexchangeteam.com/archive/2010/08/20/455881.aspx</link><pubDate>Fri, 20 Aug 2010 15:08:35 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:455881</guid><dc:creator>Exchange</dc:creator><slash:comments>4</slash:comments><comments>http://msexchangeteam.com/comments/455881.aspx</comments><wfw:commentRss>http://msexchangeteam.com/commentrss.aspx?PostID=455881</wfw:commentRss><wfw:comment>http://msexchangeteam.com/rsscomments/455881.aspx</wfw:comment><description>&lt;p&gt;&lt;font size="2"&gt;We have received some great feedback and questions from last month's &lt;/font&gt;&lt;a href="http://blogs.technet.com/b/perryclarke/archive/2010/07/09/exchange-archiving.aspx"&gt;&lt;font size="2"&gt;post on Perry Clarke's blog&lt;/font&gt;&lt;/a&gt;&lt;font size="2"&gt; and &lt;b&gt;Geek Out with Perry&lt;/b&gt; series of videos on e-mail archiving.&amp;nbsp; This has been a hot and somewhat controversial topic that comes up often amongst our customers and partners so we wanted to share the latest edition of &lt;b&gt;Geek out with Perry&lt;/b&gt; with you.&lt;/font&gt; &lt;p&gt;&lt;font size="2"&gt;In this &lt;/font&gt;&lt;a href="http://blogs.technet.com/b/perryclarke/archive/2010/08/13/archiving-questions-do-tiered-storage-and-stubbing-make-sense.aspx"&gt;&lt;font size="2"&gt;next installment,&lt;/font&gt;&lt;/a&gt;&lt;font size="2"&gt; Perry addresses two main items: tiered storage as a method to help customers reduce costs and the use of stubbing in archives.&amp;nbsp; Do these two approaches make sense for archives? Check out this new video and blog post to see what Perry thinks about these subjects and share your thoughts and questions with us.&amp;nbsp; &lt;/font&gt; &lt;p&gt;&lt;font size="2"&gt;- Ann Vu&lt;/font&gt; &lt;p&gt;&lt;font size="2"&gt;&lt;/font&gt;&lt;/p&gt;&lt;img src="http://msexchangeteam.com/aggbug.aspx?PostID=455881" width="1" height="1"&gt;</description><category domain="http://msexchangeteam.com/archive/category/11164.aspx">Exchange 2010</category><category domain="http://msexchangeteam.com/archive/category/11154.aspx">Mailbox</category><category domain="http://msexchangeteam.com/archive/category/3303.aspx">Storage</category><category domain="http://msexchangeteam.com/archive/category/3307.aspx">Tips 'n Tricks</category></item><item><title>Exchange Circular Logging and VSS Backups</title><link>http://msexchangeteam.com/archive/2010/08/18/455857.aspx</link><pubDate>Wed, 18 Aug 2010 13:10:34 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:455857</guid><dc:creator>Exchange</dc:creator><slash:comments>9</slash:comments><comments>http://msexchangeteam.com/comments/455857.aspx</comments><wfw:commentRss>http://msexchangeteam.com/commentrss.aspx?PostID=455857</wfw:commentRss><wfw:comment>http://msexchangeteam.com/rsscomments/455857.aspx</wfw:comment><description>&lt;p&gt;&lt;font size="2"&gt;In discussions with some of our friends over in the DPM team (System Center Data Protection Manager), we’ve found that there is a rather high incidence of VSS errors in installations where DPM is being used to back up Exchange 2010. Turns out that in many instances, this is because of an incorrect configuration of circular logging on the mailbox databases being backed up, so we thought we would quickly discuss circular logging, what it is, and how it affects VSS backup scenarios.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;Circular logging has been around for a long time in the Exchange world. I found &lt;/font&gt;&lt;a href="http://support.microsoft.com/kb/147524"&gt;&lt;font size="2"&gt;KB147524&lt;/font&gt;&lt;/a&gt;&lt;font size="2"&gt;, which references Exchange 4.0, and discusses circular logging. When you configure an Exchange database with circular logging turned on, Exchange doesn’t wait until a backup occurs to truncate transaction log files. Rather, as soon as the log files have been played forward into the database, Exchange is free to delete those transaction logs. In Exchange 2003 and before, this was always handled by the Information Store service.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;With Exchange 2007 and later there is actually another form of circular logging, known as continuous replication circular logging (CRCL). There is a great discussion of this in the &lt;/font&gt;&lt;a href="http://technet.microsoft.com/en-us/library/cc535020(EXCHG.80).aspx"&gt;&lt;font size="2"&gt;Continuous Replication Deep Dive&lt;/font&gt;&lt;/a&gt;&lt;font size="2"&gt; white paper, so I’m not going to delve into the mechanics of how it works, other than to state that the system ensures that logs are not truncated on the source until all copies agree with the deletion.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;Circular Logging is useful in a few scenarios:&lt;/font&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;font size="2"&gt;Customers leverage circular logging on mailbox databases that do not contain any user data.&lt;/font&gt;&lt;/li&gt; &lt;li&gt;&lt;font size="2"&gt;Customers leverage circular logging on mailbox databases within lab environments.&lt;/font&gt;&lt;/li&gt; &lt;li&gt;&lt;font size="2"&gt;Customers leverage circular logging on mailbox databases in Exchange 2010 when they utilize the Exchange Native Data Protection built into the product because there is no traditional VSS backup solution used to manage the log file truncations.&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;font size="2"&gt;Customers occasionally leverage circular logging on mailbox databases when performing mass mailbox moves to a single mailbox database target within a small period of time to minimize the capacity impacts that could cause an outage event on the target database. If you are deploying an Exchange solution that will continue to leverage a VSS backup infrastructure and enable circular logging it is imperative that you remember to disable circular logging prior to your next backup window, otherwise your next full or incremental backup will fail. For example, some VSS solutions perform incremental backups of Exchange data by capturing the transaction log files generated since the previous backup that managed/truncated the transaction logs (a full backup, or the previous incremental backup). If you have circular logging turned on, when the incremental backup is performed, the log files that are expected to be there since the previous backup are not there – they have been truncated – causing the backup to fail.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;So, what are we saying here? We know that there are some valid and supported scenarios where circular logging is very useful. The idea here we want to reinforce is that when you are performing VSS backups that rely on the transaction logs, make sure that your normal run state is with circular logging turned off. If you have a reason to turn circular logging on when utilizing VSS incremental backups that rely on the transaction log files, remember to turn it back off as soon as reasonable, and understand that while circular logging is on that your incremental backups will fail to complete as expected!&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;-- &lt;a href="http://msexchangeteam.com/archive/2008/04/24/448769.aspx"&gt;Robert Gillies&lt;/a&gt;&lt;/font&gt;&lt;/p&gt;&lt;img src="http://msexchangeteam.com/aggbug.aspx?PostID=455857" width="1" height="1"&gt;</description><category domain="http://msexchangeteam.com/archive/category/8162.aspx">All Posts</category><category domain="http://msexchangeteam.com/archive/category/10058.aspx">Exchange 2007</category><category domain="http://msexchangeteam.com/archive/category/11164.aspx">Exchange 2010</category><category domain="http://msexchangeteam.com/archive/category/3307.aspx">Tips 'n Tricks</category></item><item><title>White Paper: Understanding the Relative Costs of Client Access Server Workloads In Exchange Server 2010</title><link>http://msexchangeteam.com/archive/2010/08/16/455841.aspx</link><pubDate>Mon, 16 Aug 2010 19:06:02 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:455841</guid><dc:creator>Exchange</dc:creator><slash:comments>5</slash:comments><comments>http://msexchangeteam.com/comments/455841.aspx</comments><wfw:commentRss>http://msexchangeteam.com/commentrss.aspx?PostID=455841</wfw:commentRss><wfw:comment>http://msexchangeteam.com/rsscomments/455841.aspx</wfw:comment><description>&lt;p&gt;&lt;font size="2"&gt;Just a quick heads-up that we have published a new Exchange 2010 whitepaper:&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;White Paper: Understanding the Relative Costs of Client Access Server Workloads In Exchange Server 2010&lt;br&gt;&lt;/font&gt;&lt;a href="http://technet.microsoft.com/en-us/library/ff803560(EXCHG.141).aspx"&gt;&lt;font size="2"&gt;http://technet.microsoft.com/en-us/library/ff803560(EXCHG.141).aspx&lt;/font&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;Here is what it is about:&lt;/font&gt;&lt;/p&gt; &lt;blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;&lt;em&gt;Estimating your Exchange Server 2010 Client Access server capacity needs is a critical setup task. The Client Access server is the entry point for all users. In addition, the Client Access server hosts important services used by the other Exchange server roles. This white paper presents an estimate of the relative CPU weights of the different protocols on the Client Access server that can be used to produce a more detailed estimate of hardware needs when you design a new Exchange 2010 deployment or expand an existing one. As part of the testing performed while researching this white paper, the effect of MailTips and the cost of NTML versus Basic authentication were also compared.&lt;/em&gt;&lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;- &lt;a href="http://msexchangeteam.com/archive/2004/01/27/63464.aspx"&gt;Nino Bilic&lt;/a&gt;&lt;/font&gt;&lt;/p&gt;&lt;img src="http://msexchangeteam.com/aggbug.aspx?PostID=455841" width="1" height="1"&gt;</description><category domain="http://msexchangeteam.com/archive/category/11156.aspx">Client Access</category><category domain="http://msexchangeteam.com/archive/category/4981.aspx">Documentation</category><category domain="http://msexchangeteam.com/archive/category/11164.aspx">Exchange 2010</category></item><item><title>Summer reading fun</title><link>http://msexchangeteam.com/archive/2010/08/12/455800.aspx</link><pubDate>Thu, 12 Aug 2010 18:42:59 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:455800</guid><dc:creator>Exchange</dc:creator><slash:comments>10</slash:comments><comments>http://msexchangeteam.com/comments/455800.aspx</comments><wfw:commentRss>http://msexchangeteam.com/commentrss.aspx?PostID=455800</wfw:commentRss><wfw:comment>http://msexchangeteam.com/rsscomments/455800.aspx</wfw:comment><description>&lt;p&gt;&lt;font size="2"&gt;As many of you know I review Exchange books for fun (yea... an odd hobby of mine), and I always look forward to new Exchange books coming out. Today it is my pleasure to note that two of our very own TAPs (Siegfried Jagott and Joel Stidley) had a new book coming out that covers Exchange 2010 SP1! You can order it &lt;/font&gt;&lt;a href="http://www.amazon.com/Microsoft-Exchange-Server-2010-Practices/dp/0735627193/ref=sr_1_1?s=books&amp;amp;ie=UTF8&amp;amp;qid=1279235545&amp;amp;sr=1-1"&gt;&lt;font size="2"&gt;here&lt;/font&gt;&lt;/a&gt;&lt;font size="2"&gt;. I can tell you it's a good read, having reviewed the book myself! But don't just take my word for it; Tony Redmond (also a noted Exchange author) also reviewed the book as well.&amp;nbsp; And if that was not enough - many TAPs and others wrote interesting sidebars that added interesting short topics to the book. TAP names you can recognize like Gary Cooper, Henrik Walther and Brian Day. A host of internal Exchange folks as well - like Kristian Andaker, Ross Smith, Todd Luttinen, Ed Banti, Greg Taylor, Andrew Ehrensing, and many, many more (see the acknowledgment page for a complete list).&amp;nbsp; &lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;If you are wondering about what the "TAPs" are and want to get a little bit more about the people behind this book, here is an excerpt from the book Foreword that I wrote for it:&lt;/font&gt;&lt;/p&gt; &lt;blockquote&gt; &lt;p&gt;&lt;i&gt;&lt;font size="2"&gt;Microsoft's Technology Adoption Program is designed to validate new versions of Exchange by having customers test and run production deployments of pre-release builds of the next version of Exchange. This gives participants the opportunity to provide real-time design feedback to the Exchange product development team. Microsoft deployed the first production Exchange 2010 server on April 16, 2007 and on January of 2008 released bits to TAP customers and partners for review. Shortly thereafter, the authors and other customers were running Exchange 2010 in their production deployments. When Microsoft officially shipped Exchange 2010 on November 9th, 2009, TAPs had already deployed over 200,000 mailboxes into production! Through this preliminary process, the authors were there every step of the final design, gaining valuable experience with each TAP release for deployment. During this TAP deployment phase, all TAPS work together with Microsoft to find the best product and best ways to deploy. Here is what one TAP had to say on this process: &lt;/font&gt;&lt;/i&gt;&lt;/p&gt;&lt;i&gt;&lt;/i&gt; &lt;p&gt;&lt;i&gt;&lt;font size="2"&gt;"We have learned a lot through this process and not only about Exchange 2010. By interacting with other TAP members and the product group on a daily basis we have been able to remove the blinders we sometimes wear from administering the same system day in and day out. This has allowed us to consider alternate approaches we could take to improve our system overall and to identify where some of our own shortcomings are. I've seen things posted I've never even thought of before and hope that our contributions have done the same..."&lt;/font&gt;&lt;/i&gt;&lt;/p&gt;&lt;i&gt;&lt;/i&gt; &lt;p&gt;&lt;i&gt;&lt;font size="2"&gt;Individually and collectively the authors who wrote this book have been working with Exchange 2010 for as long as many senior developers at Microsoft. They have done an awesome job of providing readers with the ins and outs of the full range of features of Exchange 2010, which will help you get the most out of the product. Exchange administrators will find the experienced hands-on approach of this book invaluable in designing and deploying Exchange 2010. You wouldn't want a book that only skimmed and introduced new features. Fortunately for you, this book is based on the experience of years of successful deployments in complex environments and a teamwork approach to the final design process. Microsoft and TAPS have built a product that we are truly proud of, and this book brings you the right way to walk through it. This book definitely belongs on the shelf of every serious Exchange Administrator or IT Manager.&lt;/font&gt;&lt;/i&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;So, if you are looking for some good summer reading, look no further! &lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;- &lt;/font&gt;&lt;a href="http://msexchangeteam.com/archive/2005/11/18/414795.aspx"&gt;&lt;font size="2"&gt;David Espinoza&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://msexchangeteam.com/aggbug.aspx?PostID=455800" width="1" height="1"&gt;</description><category domain="http://msexchangeteam.com/archive/category/5472.aspx">Community</category><category domain="http://msexchangeteam.com/archive/category/11164.aspx">Exchange 2010</category></item><item><title>Exchange 2010 Cross-Forest Mailbox Moves</title><link>http://msexchangeteam.com/archive/2010/08/10/455779.aspx</link><pubDate>Tue, 10 Aug 2010 19:50:37 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:455779</guid><dc:creator>Exchange</dc:creator><slash:comments>23</slash:comments><comments>http://msexchangeteam.com/comments/455779.aspx</comments><wfw:commentRss>http://msexchangeteam.com/commentrss.aspx?PostID=455779</wfw:commentRss><wfw:comment>http://msexchangeteam.com/rsscomments/455779.aspx</wfw:comment><description>&lt;p&gt;&lt;font size="2"&gt;&lt;font color="#ff0000"&gt;&lt;strong&gt;EDIT 8/12/2010:&lt;/strong&gt; Added a note about the necessity to manually enable MSProxy in remote forest&lt;/font&gt;.&lt;/font&gt; &lt;p&gt;&lt;font size="2"&gt;We are seeing some trends where quite a few customers are migrating mailboxes to a new Exchange organization, in a different Active Directory (AD) forest. This blog post is aimed at helping to explain the fundamentals of what is required to move mailboxes across forests so that you can be prepared with the correct data, make better plans, and successfully perform a migration without encountering painful problems. The blog post doesn't cover how to setup and configure shared address space or Free/busy.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;After reading this blog post, you should have better understanding of:&lt;/font&gt;  &lt;ul&gt; &lt;li&gt;&lt;font size="2"&gt;How to plan your migration by understanding your current forest configuration and your desired configuration.&lt;/font&gt;  &lt;li&gt;&lt;font size="2"&gt;Different ways for you to synchronize user data between different AD forests.&lt;/font&gt;  &lt;li&gt;&lt;font size="2"&gt;Networking and Administrator permissions required to perform a successful cross-forest mailbox move.&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;font size="2"&gt;The trends we are seeing currently show that companies are having more trouble understanding the different scenarios than performing the migration. There are several scenarios here, and Microsoft has tools, documentation, and scripts to assist in each one of them.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;There are many reasons companies choose to have multiple forests or maybe find themselves with multiple forests, requiring cross-forest moves of users and mailboxes. For instance:&lt;/font&gt;  &lt;ol&gt; &lt;li&gt;&lt;font size="2"&gt;Companies that merge, are bought out, or have absorbed another company in some manner.&lt;/font&gt;  &lt;li&gt;&lt;font size="2"&gt;Companies who want to start fresh and leave a lot of legacy issues behind. &lt;/font&gt; &lt;li&gt;&lt;font size="2"&gt;Companies that have subsidiaries; segment their environment by Department, Geography, or for Security considerations. &lt;/font&gt;&lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;font size="2"&gt;The common Active Directory topologies that are supported in Exchange 2010 are as follows:&lt;/font&gt;  &lt;ul&gt; &lt;li&gt;&lt;font size="2"&gt;Single forest, single Active Directory site&lt;/font&gt;  &lt;li&gt;&lt;font size="2"&gt;Single forest, multiple Active Directory sites&lt;/font&gt;  &lt;li&gt;&lt;font size="2"&gt;Multiple forest, multiple Active Directory sites&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;font size="2"&gt;Exchange deployment topologies vary due to organizational size and business complexity. Variations may include Single Forest, Resource Forest, Hybrid Forest, and Cross Forest topology. For purposes of discussion the following forest definitions will be used going forward:&lt;/font&gt;&lt;/p&gt; &lt;blockquote&gt; &lt;p&gt; &lt;table border="1" cellspacing="0" cellpadding="0"&gt; &lt;tbody&gt; &lt;tr&gt; &lt;td valign="top" width="150"&gt; &lt;p&gt;&lt;b&gt;&lt;font size="2"&gt;Forest Name&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;&lt;/td&gt; &lt;td valign="top" width="162"&gt; &lt;p&gt;&lt;b&gt;&lt;font size="2"&gt;Active Directory user object status&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;&lt;/td&gt; &lt;td valign="top" width="162"&gt; &lt;p&gt;&lt;b&gt;&lt;font size="2"&gt;Mailbox Status&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr&gt; &lt;td valign="top" width="150"&gt; &lt;p&gt;&lt;font size="2"&gt;Exchange Forest&lt;/font&gt;&lt;/p&gt;&lt;/td&gt; &lt;td valign="top" width="162"&gt; &lt;p&gt;&lt;font size="2"&gt;Enabled User Object&lt;/font&gt;&lt;/p&gt;&lt;/td&gt; &lt;td valign="top" width="162"&gt; &lt;p&gt;&lt;font size="2"&gt;Mailbox Enabled&lt;/font&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr&gt; &lt;td valign="top" width="150"&gt; &lt;p&gt;&lt;font size="2"&gt;Account Forest&lt;/font&gt;&lt;/p&gt;&lt;/td&gt; &lt;td valign="top" width="162"&gt; &lt;p&gt;&lt;font size="2"&gt;Enabled User Object&lt;/font&gt;&lt;/p&gt;&lt;/td&gt; &lt;td valign="top" width="162"&gt; &lt;p&gt;&lt;font size="2"&gt;No mailbox enabled objects&lt;/font&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr&gt; &lt;td valign="top" width="150"&gt; &lt;p&gt;&lt;font size="2"&gt;Resource Forest&lt;/font&gt;&lt;/p&gt;&lt;/td&gt; &lt;td valign="top" width="162"&gt; &lt;p&gt;&lt;font size="2"&gt;Disabled User Object (linked to a separate enabled user object in an Account Forest)&lt;/font&gt;&lt;/p&gt;&lt;/td&gt; &lt;td valign="top" width="162"&gt; &lt;p&gt;&lt;font size="2"&gt;Mailbox Enabled&lt;/font&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr&gt; &lt;td valign="top" width="150"&gt; &lt;p&gt;&lt;font size="2"&gt;Hybrid Forest&lt;/font&gt;&lt;/p&gt;&lt;/td&gt; &lt;td valign="top" width="162"&gt; &lt;p&gt;&lt;font size="2"&gt;Both &lt;/font&gt; &lt;p&gt;&lt;font size="2"&gt;1.) AD Enabled Mailbox Enabled&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;2.) AD Disabled Mailbox Enabled&lt;/font&gt;&lt;/p&gt;&lt;/td&gt; &lt;td valign="top" width="162"&gt; &lt;p&gt;&lt;font size="2"&gt;Both mailbox enabled and disabled objects&lt;/font&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;Most of the Cross-Org Move Mailbox scenarios are closely related to the Active Directory Forests involved in the migration. There are 3 major scenarios to be considered:&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;1. Move from Exchange Forest A to Exchange Forest B. This means that the user is a security principal in forest A and after he is moved to forest B, he is a security principal in forest B as well.&lt;/font&gt;  &lt;ul&gt; &lt;li&gt;&lt;font size="2"&gt;This may be a hybrid-forest scenario, typical during inter-forest migrations, because the user is security principal in both.&lt;/font&gt;  &lt;li&gt;&lt;font size="2"&gt;Hybrid is when there are both enabled and disabled users in the same forest.&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;font size="2"&gt;2. Move from Account Forest to Exchange Resource Forest. &lt;/font&gt; &lt;ul&gt; &lt;li&gt;&lt;font size="2"&gt;Company is splitting Exchange off to its own forest. Maybe due to outsourcing it, complex business organization, or desire to de-couple the Exchange org (e.g. messaging services) from the other infrastructure.&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;font size="2"&gt;3. Move from Exchange Resource Forest to Account Forest. This is the reverse of #2.&lt;/font&gt;&lt;a name="_Toc233195553"&gt;&lt;/a&gt;  &lt;ul&gt; &lt;li&gt;&lt;font size="2"&gt;Company is bringing Exchange back into the same forest for simplicity, to better integrate with OCS (though they are not required to be in the same forest), or collapsing/consolidating previously separate Exchange orgs into one user forest.&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;font size="2"&gt;Cross-forest is when all users from the same organization are only contacts or mail enabled user objects in the other forest.&lt;/font&gt;  &lt;ul&gt; &lt;li&gt;&lt;font size="2"&gt;This is not referenced as a common scenario because it's usually in place between two separate legal entities and there would not be much movement (e.g. migrations) between them.&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt; &lt;h5&gt;&lt;font color="#0000ff"&gt;Active Directory Forest Configuration examples:&lt;/font&gt;&lt;/h5&gt; &lt;p&gt;&lt;font size="2"&gt;Below are some AD forest configuration examples. The forest scenarios don't necessarily imply there is a "move" or migration going on, some are long-term configurations.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;&lt;em&gt;&lt;b&gt;Resource Forest&lt;/b&gt;&lt;b&gt;&lt;/b&gt;&lt;/em&gt;&lt;/font&gt;  &lt;p&gt;&lt;img src="http://msexchangeteam.com/photos/postpictures4/images/455774/original.aspx"&gt;  &lt;p&gt;&lt;font size="2"&gt;A Resource Forest scenario is a deployment that has at least one Exchange Resource Forest that hosts user mailboxes (but not active user accounts or enabled user accounts) and at least one other forest that hosts the AD user accounts. In other words, Exchange is installed into an AD forest which is separate from the "user account" AD forest.&lt;/font&gt;  &lt;ul&gt; &lt;li&gt;&lt;font size="2"&gt;A one-way forest trust where the resource forest trusts the account forest is created.&lt;/font&gt;  &lt;li&gt;&lt;font size="2"&gt;Each mailbox in the Exchange forest must have a corresponding user in the account forest, which is granted access to logon to the mailbox. This is referred to as a "Linked Mailbox".&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;font size="2"&gt;The user objects in the Exchange forest are never logged onto by an end user and are disabled. &lt;/font&gt; &lt;p&gt;&lt;b&gt;&lt;font size="2"&gt;&lt;em&gt;Hybrid Forest&lt;/em&gt;&lt;/font&gt;&lt;/b&gt;  &lt;p&gt;&lt;img src="http://msexchangeteam.com/photos/postpictures4/images/455775/original.aspx"&gt;  &lt;p&gt;&lt;font size="2"&gt;Typically this scenario is maintained initially for co-existence while migrating and decommissioning a forest. It is different from a typical cross-forest scenario because there may be both enabled and disabled users in both forests for the same organization. In some cases, an organization may actually need to maintain the Hybrid Forest scenario over the long-term. While this is a supported scenario, it comes with additional complexity that must be addressed:&lt;/font&gt;  &lt;ul&gt; &lt;li&gt;&lt;font size="2"&gt;Mastering User and Exchange attributes occurs on both sides.&lt;/font&gt;  &lt;li&gt;&lt;font size="2"&gt;A tool such as Forefront Identity Manager (FIM), is needed to maintain consistent data on both sides, including the GAL.&lt;/font&gt;  &lt;li&gt;&lt;font size="2"&gt;Free/Busy and Public Folder access requires additional configuration, tools, and in some cases maintaining an Exchange 2007 server. (Please note that the IOREPL tool isn't currently supported with Exchange 2010 as a target server and in fact follows the Exchange 2003 Product support life cycle.)&lt;/font&gt;  &lt;li&gt;&lt;font size="2"&gt;Free/Busy, over the long-term will be best managed using the new Federation services (Microsoft Federation Gateway)&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;font size="2"&gt;For more information refer to &lt;/font&gt;&lt;a href="http://technet.microsoft.com/en-us/library/dd335047.aspx"&gt;&lt;font size="2"&gt;Understanding Federation&lt;/font&gt;&lt;/a&gt;  &lt;p&gt;&lt;b&gt;&lt;font size="2"&gt;&lt;em&gt;Cross-forest&lt;/em&gt;&lt;/font&gt;&lt;/b&gt;  &lt;p&gt;&lt;img src="http://msexchangeteam.com/photos/postpictures4/images/455776/original.aspx"&gt;  &lt;p&gt;&lt;font size="2"&gt;Both forests contain mailboxes and user accounts and contacts. This type of configuration has user accounts always enabled and mailbox enabled, with a corresponding contact in the other forest. The following diagram depicts how different objects are represented in the corresponding forest:&lt;/font&gt;  &lt;p&gt;&lt;img src="http://msexchangeteam.com/photos/postpictures4/images/455777/original.aspx"&gt;  &lt;p&gt;&lt;font size="2"&gt;For more information on forests related to Cross Org migrations, refer to &lt;/font&gt;&lt;a href="http://msexchangeteam.com/archive/2006/11/02/430289.aspx"&gt;&lt;font size="2"&gt;http://msexchangeteam.com/archive/2006/11/02/430289.aspx&lt;/font&gt;&lt;/a&gt;&lt;font size="2"&gt; &lt;b&gt;&lt;/b&gt;&lt;/font&gt; &lt;h5&gt;&lt;font color="#0000ff"&gt;Three Migration paths you need to choose from:&lt;/font&gt;&lt;/h5&gt; &lt;p&gt;&lt;font size="2"&gt;Depending on the current topology you have employed, you may find yourself planning to move users into the new forest and then following with moving their mailboxes as well. There are essentially three ways of planning to move your resources:&lt;/font&gt;  &lt;ol&gt; &lt;li&gt;&lt;font size="2"&gt;A customized deployment in which you write ILM rules extension code to create the target Mail Enabled User (MEU). You should already have a custom ILM deployment for cross forest GALSync. Microsoft Identity Lifecycle Manager Service Pack 1 Feature Pack 1 (ILM 2007 SP1 FP1) GALSync Management Agent (MA) doesn't include several attributes now required in Exchange 2010, most importantly, msExchMailboxGUID. The out of the box GALSync MA cannot be used since it creates contact object instead of user object required for Online Mailbox Move. The ILM sample code demonstrates how to sync source mailbox as Mail Enabled Users (MEU). &lt;/font&gt;&lt;/li&gt;&lt;/ol&gt; &lt;blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;&lt;b&gt;Note&lt;/b&gt;: Customers using "out of the box" GALSync MA may probably not know how to customize ILM.&lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;ol start="2"&gt; &lt;li&gt;&lt;font size="2"&gt;Use Prepare-MoveRequest.ps1 script to create the target MEU. It is important to note that the PrepareMoveRequest script works in conjunction with "out of the box" Exchange GALSync MA for ILM (or FIM). This means the script has built-in logic to convert target Mail Enabled Contact (MEC) created by ILM GALSync MA into the required MEU. &lt;/font&gt; &lt;li&gt;&lt;font size="2"&gt;Use Prepare-MoveRequest.ps1 script and then use ADMT to migrate the other attributes on the user object. &lt;/font&gt;&lt;/li&gt;&lt;/ol&gt; &lt;blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;&lt;b&gt;Important Note&lt;/b&gt;: Our recommendation on working with ADMT is to rely on the PrepareMoveRequest script to create the local user object for mailbox move, and then use ADMT to migrate SIDHistory and password and merge this into the MEU created by PrepareMoveRequest.ps1 script.&lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;The point of doing ILM or the script first is to ensure the MEUs are all created with the correct msExch* attributes. This also ensures the following benefits:&lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;ol&gt; &lt;ol&gt; &lt;li&gt;&lt;font size="2"&gt;A correct GAL immediately for co-existence (short or long-term) &lt;/font&gt; &lt;li&gt;&lt;font size="2"&gt;Permissions for delegates and mailbox access are preserved during the move using the msExchMailboxGUID attribute. Since this is populated on the target object with PrepareMoveRequest.ps1 the permissions will be maintained in the cross-forest move.&lt;/font&gt;&lt;/li&gt;&lt;/ol&gt;&lt;/ol&gt; &lt;blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;At this point it doesn't matter if ADMT is used to migrate/merge the user objects all at once or in "batches" of user objects. ADMT can be controlled better to ensure only merging of SIDhistory and certain other mandatory attributes if it's not already populated.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;Running ADMT first, without ensuring exclusions on msExch* attributes, can cause corrupted objects which the script cannot correctly convert with the -UseLocalObject switch.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;&lt;b&gt;Important Note&lt;/b&gt;: When SP1 ships, we will support running ADMT first and then the PrepareMoveRequest script later. &lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;h5&gt;&lt;font color="#0000ff"&gt;ILM and PrepareMoveRequest Scenarios broken-down: &lt;/font&gt;&lt;/h5&gt; &lt;p&gt;&lt;font size="2"&gt;There are basically 5 steps involved with moving a mailbox across a forest in Exchange 2010. They are: Preparing Active Directory, Network Prerequisites, Administrator Permissions, Moving Mailboxes and Clean-up. Each of these steps is series of smaller steps that need to be taken in order to move a mailbox from one Exchange forest to and Exchange 2010 forest.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;The first step in Cross Forest mailbox moves is preparing Active Directory. In the target forest a mail enabled user account must be created with certain attributes. The method used for creating the target account and setting the mandatory attributes is up to the organization administrator. ADMT and ILM can be used to synchronize/pull over the attributes from the source forest. &lt;/font&gt; &lt;p&gt;&lt;b&gt;&lt;font size="2"&gt;Exchange Provisioning using ILM 2007&lt;/font&gt;&lt;/b&gt;  &lt;p&gt;&lt;font size="2"&gt;If you deployed ILM for cross-forest global address list (GAL) synchronization, the recommended approach to creating the mail-enabled user is to use ILM 2007 Service Pack 1 (SP1) Feature Pack 1 (FP1) or Forefront Identity Manager 2010 (FIM) GALSync MA. We've created sample code that you can use to learn how to customize ILM to synchronize the source mailbox user and target mail user. &lt;/font&gt; &lt;p&gt;&lt;font size="2"&gt;For more information, including how to download the sample code, refer to this &lt;/font&gt;&lt;a href="http://technet.microsoft.com/en-us/library/ee861124.aspx"&gt;&lt;font size="2"&gt;link&lt;/font&gt;&lt;/a&gt;&lt;font size="2"&gt;.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;To deploy Exchange 2010 in a cross-forest topology, you must first install Exchange 2010 in the new forest. Then, provision the mail-enabled users representing the source mailboxes so that Exchange 2010 can move the mailbox and migrated users can see all addresses.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;Deployment steps: &lt;/font&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://technet.microsoft.com/en-us/library/aa998597.aspx"&gt;&lt;font size="2"&gt;Deploy Exchange 2010 in a cross-forest topology&lt;/font&gt;&lt;/a&gt;&lt;font size="2"&gt; with ILM 2007 FP1 SP1.&lt;/font&gt;  &lt;li&gt;&lt;font size="2"&gt;Import and install the ILM sample code from &lt;/font&gt;&lt;a href="http://technet.microsoft.com/en-us/library/ee861124.aspx"&gt;&lt;font size="2"&gt;Prepare Mailboxes for Cross-Forest Moves Using Sample Code&lt;/font&gt;&lt;/a&gt;&lt;font size="2"&gt;.&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt; &lt;blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;&lt;b&gt;Note&lt;/b&gt;: The main purpose of the sample code is to encourage customers to customize, or add more functions to the sample code. The sample code is very basic and it only copies very basic attributes. Customers who rely on this sample code may find many attributes missing.&lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;ul&gt; &lt;li&gt;&lt;font size="2"&gt;Configure the Mail-Enabled User provisioning Management Agents for each forest. This allows the mailboxes in the source forest to be created as MEU in the target forest and ensure a common GAL.&lt;/font&gt;  &lt;li&gt;&lt;a href="http://technet.microsoft.com/en-us/library/aa997285.aspx"&gt;&lt;font size="2"&gt;Create an SMTP Send connector&lt;/font&gt;&lt;/a&gt;&lt;font size="2"&gt; in each forest and configure SMTP namespace sharing (&lt;/font&gt;&lt;a href="http://technet.microsoft.com/en-us/library/bb676395.aspx"&gt;&lt;font size="2"&gt;http://technet.microsoft.com/en-us/library/bb676395.aspx&lt;/font&gt;&lt;/a&gt;&lt;font size="2"&gt;).&lt;/font&gt;  &lt;li&gt;&lt;font size="2"&gt;In each forest, enable the Availability service so that users in each forest can view free/busy data about users in the other forest. For more information, see &lt;/font&gt;&lt;a href="http://technet.microsoft.com/en-us/library/bb125158.aspx"&gt;&lt;font size="2"&gt;Managing the Availability Service&lt;/font&gt;&lt;/a&gt;&lt;font size="2"&gt;.&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt; &lt;blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;&lt;b&gt;Note&lt;/b&gt;: The Availability service is supported only for Outlook 2007 clients and newer. If Outlook 2003 clients still exist in one of the forests, the only solution will be to deploy Exchange 2007 first in the Exchange 2010 organization (because adding it late is not possible if Exchange 2010 is deployed first) and implement the IOREPL tool to replicate Free/Busy system public folders to the Exchange 2007 server. The Free/Busy system public folder replicas can then be replicated using PF replication to your Exchange 2010 server. IOREPL will not replicate a public/system folder directly to an Exchange 2010 server.&lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;For more information review:&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;Exchange Provisioning using ILM 2007 and FIM 2010&lt;br&gt;&lt;/font&gt;&lt;a href="http://technet.microsoft.com/en-us/magazine/ff472471.aspx"&gt;&lt;font size="2"&gt;http://technet.microsoft.com/en-us/magazine/ff472471.aspx&lt;/font&gt;&lt;/a&gt;  &lt;p&gt;&lt;b&gt;&lt;font size="2"&gt;&lt;/font&gt;&lt;/b&gt; &lt;p&gt;&lt;b&gt;&lt;font size="2"&gt;Prepare-MoveRequest.ps1&lt;/font&gt;&lt;/b&gt;  &lt;p&gt;&lt;font size="2"&gt;It may be difficult for some customers to synchronize the prerequisite attributes for performing mailbox moves without using ILM. You may have some other solution in place that does not synchronize the required attributes, and does not allow customization. Small companies may not have a solution at all and simply wish to transition users from an existing forest (that is set to be obsolete) to a new, clean Exchange 2010 forest.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;To solve this problem, the PrepareMoveRequest script has been written to prepare the AD target object and synchronize the required attributes for cross-forest moves to work. The script creates the target MEU if necessary, or synchronizes an existing MEU when possible.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;The PrepareMoveRequest script prepares Exchange 2003, Exchange 2007, and Exchange 2010 mailbox users for migration to an Exchange 2010 forest.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;For more information about using the sample script, refer to the following &lt;/font&gt;&lt;a href="http://technet.microsoft.com/en-us/library/ee861103.aspx"&gt;&lt;font size="2"&gt;link&lt;/font&gt;&lt;/a&gt;&lt;font size="2"&gt;.&lt;b&gt;&lt;/b&gt;&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;The PrepareMoveRequest script supports 2 scenarios:&lt;/font&gt;  &lt;ol&gt; &lt;li&gt;&lt;font size="2"&gt;Creating a brand new user in the local forest where the MBX will be moved to. &lt;/font&gt; &lt;li&gt;&lt;font size="2"&gt;A local recipient, either a MEU or MEC already exists, created by an external agent such as ILM - If the local forest object is a mail contact, the script will convert the mail contact to a mail user while persisting the contact's existing exchange-related attributes. If the local forest object is a MEU, the script will reuse this mail user and stamp the essential attributes on the local mail user object. The administrator must specify the -UserLocalObject switch in order to tell the script to use this scenario. &lt;/font&gt;&lt;/li&gt;&lt;/ol&gt; &lt;blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;&lt;b&gt;Note&lt;/b&gt;: The scenario that the script doesn't support is that some external process created a local user object and relies on the script to copy all the attributes and links from the remote MBX to the local user. This is the ADMT scenario described after this scenario.&lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;In order to run New-MoveRequest cmdlet to move a mailbox from an Exchange 2003/2007/2010 source forest to an Exchange2010 target forest, the target forest must contain a valid MEU account with the set of AD attributes described in this section. These attributes are synchronized by the PrepareMoveRequest script.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;There are certain mandatory attributes that should be present on the target mail user for New-MoveRequest to run properly. These attributes are always set by the PrepareMoveRequest script, either as they are taken from the source MBX, or as determined by the script. The attributes are listed here &lt;/font&gt;&lt;a href="http://technet.microsoft.com/en-us/library/ee861103.aspx"&gt;&lt;font size="2"&gt;http://technet.microsoft.com/en-us/library/ee861103.aspx&lt;/font&gt;&lt;/a&gt;&lt;font size="2"&gt;.&lt;/font&gt;  &lt;p&gt;&lt;b&gt;&lt;i&gt;&lt;font size="2"&gt;Process Overview: Run PrepareMoveRequest script first and then ADMT&lt;/font&gt;&lt;/i&gt;&lt;/b&gt;  &lt;ul&gt; &lt;li&gt;&lt;font size="2"&gt;Prepare MEU&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt; &lt;blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;To create the target mail enabled user account in an Exchange 2010 forest from the source mailbox enabled account in the source Exchange forest, the PrepareMoveRequest script must be executed in the target Exchange 2010 forest. The script pulls the mailbox enabled account attributes from the source forest.&lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;The script can be used to provision one target MEU account at a time, but can also take data that is passed by pipeline as input to provision MEUs in bulk.&lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;Since PrepareMoveRequest script relies on &lt;i&gt;Update-Recipient&lt;/i&gt; task that exists only in Exchange Management Shell, all the below commands need to be run in Exchange Management Shell. Running in PowerShell will only result in error.&lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;ul&gt; &lt;li&gt;&lt;font size="2"&gt;Run the below commands in the target forest&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt; &lt;blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;$Local = Get-Credential&lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;Input the target forest's Administrator Credentials in "Domain\User" and Password format.&lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;&lt;b&gt;Note&lt;/b&gt;: The account used should have permissions to call Update-Recipient which is available only to Exchange Enterprise Admin.&lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;$Remote = Get-Credential&lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;Input the Source forest's Administrator Credentials in "Domain\User" and Password format.&lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;&lt;b&gt;Note&lt;/b&gt;: Since the PrepareMoveRequest script will also update the source object's proxyAddresses to include the target object's legacyDN as X500 address, the account used to run this command should have Read and Write access for the source forest.&lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;ul&gt; &lt;li&gt;&lt;font size="2"&gt;Run the PrepareMoveRequest script in the target forest&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt; &lt;blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;[PS] C:\&amp;gt;.\Prepare-MoveRequest.Ps1 -Identity "DN of a user from SourceForest" -RemoteForestDomainController "FQDN of Source DC" -RemoteForestCredential $Remote -LocalForestDomainController "FQDN of Target Forest DC" -LocalForestCredential $Local -TargetMailUserOU "Distinguished name of OU in TargetForest" -UseLocalObject&lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;&lt;b&gt;Note 1&lt;/b&gt;: You can use the -Verbose flag to check which attributes have been set if you want to get a detailed list of the attributes that were touched.&lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;&lt;b&gt;Note 2&lt;/b&gt;: You can use the -&lt;i&gt;UseLocalObject parameter &lt;/i&gt;here. &lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;ul&gt; &lt;ul&gt; &lt;li&gt;&lt;font size="2"&gt;If the local matching object is found, then the local object will be used.&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt; &lt;blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;&lt;b&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Note&lt;/b&gt;: If the local matching object is found and UseLocalObject is not defined, the script will throw an error. &lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;ul&gt; &lt;ul&gt; &lt;li&gt;&lt;font size="2"&gt;If the local object doesn't exist, even if UseLocalObject is specified, the script will still create a new one.&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt; &lt;blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;If you are sure that you didn't prepare local object before, you could remove this parameter to ensure accidental overriding.&lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;ul&gt; &lt;li&gt;&lt;font size="2"&gt;In the target forest, we get a new disabled mail-enabled user AD object created with some of the following Exchange attributes:&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt; &lt;blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;legacyExchangeDN, mail, mailnickname, msExchmailboxGuid, proxyAddresses, X500, targetAddress, userAccountControl, userprincipalName&lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;ul&gt; &lt;li&gt;&lt;font size="2"&gt;SIDHistory is empty. This is expected because Exchange doesn't migrate SIDs. At this point all of the required attributes to perform a mailbox move have been synced into the target forest.&lt;/font&gt;  &lt;li&gt;&lt;font size="2"&gt;Run ADMT in the target forest.&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt; &lt;blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;&lt;b&gt;Note&lt;/b&gt;: Currently the Active Directory Migration Tool (ADMT) v3.1 is not supported on Windows 2008 R2 Servers. If you plan to use ADMT v3.1, it must be installed on Windows 2008 server.&lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;ul&gt; &lt;li&gt;&lt;font size="2"&gt;Check the results in the target forest: The user should now have SIDHistory matching the objectSid of the source object (all other attributes are left untouched)&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt; &lt;h5&gt;&lt;font color="#0000ff"&gt;Gotchas running ADMT first and then PrepareMoveRequest script:&lt;/font&gt;&lt;/h5&gt; &lt;p&gt;&lt;font size="2"&gt;Currently, several customers are running ADMT first and then running the PrepareMoveRequest script. When a user is created via ADMT, the PrepareMoveRequest script doesn't work since there are no proxyAddresses for the script to match the source forest user with the target forest user.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;The recommended approach is to copy at least 1 proxy address using ADMT. However, if you use the -&lt;b&gt;&lt;i&gt;UseLocalObject&lt;/i&gt;&lt;/b&gt; parameter, the script will only copy the 3 mandatory parameters (msExchMailboxGUID, msExchArchiveGUID, msExchArchiveName). This is not very useful. Customers can simply copy these 3 themselves.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;&lt;b&gt;Important Note&lt;/b&gt;: In SP1, we are adding the O&lt;i&gt;verwriteLocalObject&lt;/i&gt; parameter. This is designed for the ADMT case. ADMT can copy the SIDhistory, password, and proxyAddresses, and the PrepareMoveRequest script can sync the other email attributes. In this case, it will copy attributes from source to target, so it's the opposite of UseLocalObject.&lt;/font&gt;  &lt;p&gt;&lt;b&gt;&lt;font size="2"&gt;&lt;/font&gt;&lt;/b&gt; &lt;p&gt;&lt;b&gt;&lt;font size="2"&gt;ADMT and Exchange Attributes&lt;/font&gt;&lt;/b&gt;  &lt;p&gt;&lt;b&gt;&lt;font size="2"&gt;&lt;/font&gt;&lt;/b&gt; &lt;p&gt;&lt;font size="2"&gt;ADMT transfers Exchange attributes (e.g. homeMDB, homeMTA, showInAddressBook, msExch*) which make the target user look like a legacy mailbox in the target domain. This leaves the target account in an invalid state (e.g. homeMDB still points to the old forest) which is unexpected for the &lt;/font&gt; &lt;p&gt;&lt;font size="2"&gt;PrepareMoveRequest.ps1 script. To prevent this, Exchange attributes are excluded from ADMT.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;The PrepareMoveRequest.ps1 script can identify and match existing accounts in the target forest based on their SMTP address (proxyAddresses attribute).&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;&lt;b&gt;Note&lt;/b&gt;: It can also do this based on the MasterAccountSid, but this is only populated for accounts in a resource forest scenario.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;More precisely, the script will use the existing target accounts if the following are true:&lt;/font&gt;  &lt;ul&gt; &lt;li&gt;&lt;font size="2"&gt;The target account has a value in proxyAddresses which matches one of the proxyAddresses of the source account. &lt;/font&gt; &lt;li&gt;&lt;font size="2"&gt;The target account is a mail enabled user i.e. you can retrieve it with the Get-Recipient command. For this to succeed, it needs to have mail attributes like 'mail', 'targetAddress' etc.&lt;/font&gt;  &lt;li&gt;&lt;font size="2"&gt;You need to specify the -UseLocalObject parameter in the script&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;font size="2"&gt;If all these are true, the script will copy further attributes needed (especially msExchMailboxGUID) to the target account so that the move request can process the accounts.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;By default, ADMT 3.1 does NOT migrate "mail", "msExchMailboxGuid" and "proxyAddresses" attributes&amp;nbsp; because of security reasons. This is documented in the below article under "&lt;i&gt;System attribute exclusion list&lt;/i&gt;"&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;Managing Users, Groups, and User Profiles&lt;br&gt;&lt;/font&gt;&lt;a href="http://technet.microsoft.com/en-us/library/cc974331(WS.10).aspx"&gt;&lt;font size="2"&gt;http://technet.microsoft.com/en-us/library/cc974331(WS.10).aspx&lt;/font&gt;&lt;/a&gt;  &lt;p&gt;&lt;font size="2"&gt;&lt;b&gt;Important Note&lt;/b&gt;: When running ADMT &lt;u&gt;second&lt;/u&gt; after ILM due to both forests having the same schema (attributes), unexpected Exchange attributes are brought over.&amp;nbsp; This can cause issues.&amp;nbsp; HomeMDB for example is brought over and causes the MEU to look like a legacy mailbox, and is unusable.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;To resolve the problem of ADMT being run first, and leaving the user in an invalid state for the PrepareMoveRequest.ps1 script, you can create the following VB script/ADMT COM object model to exclude all Exchange attributes from being migrated by ADMT.&lt;/font&gt;  &lt;blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;Set O = CreateObject("ADMT.Migration"). &lt;br&gt;&lt;/font&gt;&lt;font size="2"&gt;o.SystemPropertiesToExclude = " HomeMDB,HomeMTA,showInAddressBook,msExchHomeServerName, mail, proxyAddresses, msExch*"&lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;This allows update-recipient to find the target object and match it with the source account and merge the two together.&amp;nbsp; For more information, refer to the below article:&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;You will find that several custom attributes are missing when you use ADMT to migrate users between two forests&lt;/font&gt;  &lt;p&gt;&lt;a href="http://support.microsoft.com/kb/937537"&gt;&lt;font size="2"&gt;http://support.microsoft.com/kb/937537&lt;/font&gt;&lt;/a&gt;  &lt;h5&gt;&lt;font color="#0000ff"&gt;Network Prerequisites&lt;/font&gt;&lt;/h5&gt; &lt;p&gt;&lt;font size="2"&gt;When mailboxes are moved from one Exchange 2010 forest to another Exchange 2010 forest, the process is handled through Exchange 2010 Client Access Servers using the MRSProxy service. The only port required to be open between the forests for MRSProxy to use HTTPS traffic is port 443. This works even if the source mailboxes are on 2003 or 2007 MBX servers as long as an Exchange 2010 CAS server exists in both organizations.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;&lt;b&gt;Note&lt;/b&gt;: The whole forest doesn't need to be Exchange 2010 in order to use the MRSProxy. If there is at least one Exchange 2010 CAS in the forest (with access to the Mailbox Servers and AD), it can be used as the MRS Proxy for moves from a mostly Exchange 2003 or Exchange 2007 forest. This can be called the "Remote" scenario (or the "MRSProxy" scenario). By default, MRSProxy is disabled. To start MRSProxy on the Client Access server in the remote forest, you must modify the Client Access server's Web.config file. For more information refer to &lt;a href="http://technet.microsoft.com/en-us/library/ee732395.aspx"&gt;http://technet.microsoft.com/en-us/library/ee732395.aspx&lt;/a&gt;. If CAS servers are behind the NLB, you should do this on all servers that can take the load.&lt;/font&gt; &lt;p&gt;&lt;font size="2"&gt;If the mailbox is being moved from legacy Exchange forest then the mailbox replication service will need to have the same TCP ports open that is needed for a normal local mailbox move. Listed are the TCP ports that are needed for a local mailbox move. These ports will be needed to be open both ways for mailboxes to be moved.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;&lt;b&gt;Note&lt;/b&gt;: This is more of the "Remote Legacy" scenario, but it can be used between two Exchange 2010 forests as well as between one Exchange 2010 forest and one Exchange 2003/2007 forest.&lt;/font&gt;&lt;/p&gt; &lt;blockquote&gt; &lt;p&gt; &lt;table border="1" cellspacing="0" cellpadding="0"&gt; &lt;tbody&gt; &lt;tr&gt; &lt;td valign="top" width="105"&gt; &lt;p&gt;&lt;b&gt;&lt;font size="2"&gt;Port &lt;/font&gt;&lt;/b&gt;&lt;/p&gt;&lt;/td&gt; &lt;td valign="top" width="344"&gt; &lt;p&gt;&lt;b&gt;&lt;font size="2"&gt;Protocol&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr&gt; &lt;td valign="top" width="105"&gt; &lt;p&gt;&lt;font size="2"&gt;808 (TCP)&lt;/font&gt;&lt;/p&gt;&lt;/td&gt; &lt;td valign="top" width="344"&gt; &lt;p&gt;&lt;font size="2"&gt;Mailbox Replication Service uses to communicate &lt;/font&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr&gt; &lt;td valign="top" width="105"&gt; &lt;p&gt;&lt;font size="2"&gt;53 (TCP)&lt;/font&gt;&lt;/p&gt;&lt;/td&gt; &lt;td valign="top" width="344"&gt; &lt;p&gt;&lt;font size="2"&gt;DNS &lt;/font&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr&gt; &lt;td valign="top" width="105"&gt; &lt;p&gt;&lt;font size="2"&gt;135 (TCP)&lt;/font&gt;&lt;/p&gt;&lt;/td&gt; &lt;td valign="top" width="344"&gt; &lt;p&gt;&lt;font size="2"&gt;RPC End Point &lt;/font&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr&gt; &lt;td valign="top" width="105"&gt; &lt;p&gt;&lt;font size="2"&gt;389 (TCP)&lt;/font&gt;&lt;/p&gt;&lt;/td&gt; &lt;td valign="top" width="344"&gt; &lt;p&gt;&lt;font size="2"&gt;LDAP &lt;/font&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr&gt; &lt;td valign="top" width="105"&gt; &lt;p&gt;&lt;font size="2"&gt;3268&lt;/font&gt;&lt;/p&gt;&lt;/td&gt; &lt;td valign="top" width="344"&gt; &lt;p&gt;&lt;font size="2"&gt;LDAP&lt;/font&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr&gt; &lt;td valign="top" width="105"&gt; &lt;p&gt;&lt;font size="2"&gt;1024 &amp;gt; (TCP)&lt;/font&gt;&lt;/p&gt;&lt;/td&gt; &lt;td valign="top" width="344"&gt; &lt;p&gt;&lt;font size="2"&gt;if mailbox store is not statically configured then 1024 higher ports need to be open &lt;/font&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr&gt; &lt;td valign="top" width="105"&gt; &lt;p&gt;&lt;font size="2"&gt;88 (TCP)&lt;/font&gt;&lt;/p&gt;&lt;/td&gt; &lt;td valign="top" width="344"&gt; &lt;p&gt;&lt;font size="2"&gt;Kerberos&lt;/font&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr&gt; &lt;td valign="top" width="105"&gt; &lt;p&gt;&lt;font size="2"&gt;445 (TCP)&lt;/font&gt;&lt;/p&gt;&lt;/td&gt; &lt;td valign="top" width="344"&gt; &lt;p&gt;&lt;font size="2"&gt;Microsoft-DS Service &lt;/font&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr&gt; &lt;td valign="top" width="105"&gt; &lt;p&gt;&lt;font size="2"&gt;443 (TCP)&lt;/font&gt;&lt;/p&gt;&lt;/td&gt; &lt;td valign="top" width="344"&gt; &lt;p&gt;&lt;font size="2"&gt;Mailbox Replication Proxy service uses port 443 to communicate with other Exchange 2010 client access server via HTTPS. &lt;/font&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;Also it is necessary for servers in both forests to successfully perform name resolution using DNS.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;For cross forest mailbox moves via the MRSProxy service, the source and target servers use certificates to encrypt the HTTPS traffic. The CAS Servers in the source and target forests must have installed a valid certificate that has been issued by a trusted certificate authority recognized by the server in the opposite forest.&lt;/font&gt;  &lt;h5&gt;&lt;font color="#0000ff"&gt;Administrator Permissions&lt;/font&gt;&lt;/h5&gt; &lt;p&gt;&lt;font size="2"&gt;In order to move mailboxes across different Exchange forests the account used to initiate the move request in the target forest and the account used to access the mailbox and directory in the source forest must have the proper permissions. The permissions that are needed for the account in the source forest depend on the type of move.&lt;/font&gt;  &lt;h6&gt;&lt;b&gt;&lt;font size="2"&gt;Remote &lt;/font&gt;&lt;/b&gt;&lt;/h6&gt; &lt;p&gt;&lt;font size="2"&gt;The account must have the privileges made available by membership in the &lt;b&gt;Recipient Administrators&lt;/b&gt; group.&lt;/font&gt;  &lt;h6&gt;&lt;b&gt;&lt;font size="2"&gt;Remote Legacy&lt;/font&gt;&lt;/b&gt;&lt;/h6&gt; &lt;p&gt;&lt;font size="2"&gt;The migration account must have the following permissions. &lt;/font&gt; &lt;ul&gt; &lt;li&gt;&lt;font size="2"&gt;Exchange Server Administrators role&lt;/font&gt;  &lt;li&gt;&lt;font size="2"&gt;Exchange Recipient Administrators role&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt; &lt;h6&gt;&lt;b&gt;&lt;font size="2"&gt;Destination Forest Permissions &lt;/font&gt;&lt;/b&gt;&lt;/h6&gt; &lt;p&gt;&lt;font size="2"&gt;In the target Exchange 2010 organization the account used to create and manage the move request must be a member of the &lt;b&gt;Organization Management&lt;/b&gt; or &lt;b&gt;Recipient Management&lt;/b&gt; role groups, or have the following RBAC roles assigned either directly or through group membership: &lt;/font&gt; &lt;ul&gt; &lt;li&gt;&lt;font size="2"&gt;Move Mailboxes role&lt;/font&gt;  &lt;li&gt;&lt;font size="2"&gt;Mail Recipients role&lt;/font&gt;  &lt;li&gt;&lt;font size="2"&gt;Mail Recipient Creation role &lt;/font&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;font size="2"&gt;Only the Move Mailbox role is required to have access to the New-MoveRequest command. However, the Mail Recipients and Mail Recipient Creation roles may also be required to creating and managing target accounts in preparation for mailbox moves.&lt;/font&gt;  &lt;h5&gt;&lt;font color="#0000ff"&gt;Moving the mailbox&lt;/font&gt;&lt;/h5&gt; &lt;p&gt;&lt;font size="2"&gt;There are two methods to move a mailbox across forests using Exchange 2010. The method used depends on the type of cross forest move. Both Remote and Remote Legacy cross forest moves can be performed from the Exchange Management Shell, but only Remote moves can be performed from the Exchange Management Console.&lt;/font&gt;  &lt;h6&gt;&lt;b&gt;&lt;font size="2"&gt;Exchange Management Console &lt;/font&gt;&lt;/b&gt;&lt;/h6&gt; &lt;p&gt;&lt;font size="2"&gt;To create a new move request for a cross forest move using Exchange Management Console (EMC), the console must have a session open to both the target and source forests at the same time using the feature &lt;i&gt;Add Exchange Forest&lt;/i&gt;. This makes it possible to maintain a connection to an Exchange 2010 server in the source forest, and an Exchange 2010 server in the target forest. With a connection to servers in both source and target organizations via the EMC, you will be able to identify a mailbox that is to be moved from the source forest, while initiating the move request on an Exchange 2010 server in the target forest.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;To initiate a cross forest move with the Exchange Management Console, navigate to the Mailboxes folder in the Recipient Configuration node of the source forest, select the mailbox(es) to be moved, and then select &lt;i&gt;New Remote Move Request&lt;/i&gt;. This starts the New Remote Move Request.&lt;/font&gt;  &lt;h6&gt;&lt;b&gt;&lt;font size="2"&gt;Exchange Management Shell &lt;/font&gt;&lt;/b&gt;&lt;/h6&gt; &lt;p&gt;&lt;font size="2"&gt;To initiate a cross forest mailbox move in the Exchange Management Shell a New-MoveRequest command must be issued with Remote* parameters. Move requests issued without Remote* parameters are local moves within the same Exchange forest.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;The New-MoveRequest cmdlet requires certain attributes to be synchronized between the source MBX account and the target MEU account in order for the mailbox move to succeed. This is described in the previous steps.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;In the target domain, perform the move request by running the below cmdlet&lt;/font&gt;  &lt;blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;New-MoveRequest -Identity "Distinguished name of User in Target Forest" -RemoteLegacy -TargetDatabase "E2K10 Mailbox Database Name" -RemoteGlobalCatalog "FQDN of Source DC" -RemoteCredential $Remote -TargetDeliveryDomain "Target domain name"&lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;After the move completes, the proxyAddresses and targetAddress attributes should have changed in the target forest. If the accounts are disabled in the target forest, enable it, set a password and log into OWA and test.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;After Online Mailbox Move (OMM), the source object is changed from MBX to MEU and target object is changed from MEU to MBX&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;For more information on performing cross forest moves in Exchange 2010, refer to &lt;/font&gt;&lt;a href="http://technet.microsoft.com/en-us/library/bb124797.aspx"&gt;&lt;font size="2"&gt;Managing Move Requests&lt;/font&gt;&lt;/a&gt;  &lt;h5&gt;&lt;font color="#0000ff"&gt;Clean-up&lt;/font&gt;&lt;/h5&gt; &lt;p&gt;&lt;font size="2"&gt;When the MRS completes the moving of mailbox data from the source forest to the destination forest it mailbox enables the target user account. If the user account is disabled it leaves the account disabled. The MRS mailbox disables the source account, and converts it into a MEU account with a target address that refers to the primary SMTP address of the target mailbox account. The New-MoveRequest takes the TargetDeliveryDomain parameter. This is what determines which targetAddress to stamp. MRS checks the list of proxyAddresses for one (not necessarily the primary SMTP) that matches the FQDN specified in the TargetDeliveryDomain. The MRS will stamp this address as the targetAddress on the MEU. We moved away from using the primary SMTP address because there is a need to maintain the primary STMP when moving mailboxes cross-forest since this is part of a user's identity. When the primary SMTP address is the same on both forests, mail flow becomes more difficult&lt;b&gt;.&lt;/b&gt;&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;If the source account is to be retired and removed from the source forest, the administrator must plan for this manual operation outside of the mailbox move operation.&lt;/font&gt;  &lt;h5&gt;&lt;font color="#0000ff"&gt;What's coming in Exchange 2010 SP1&lt;/font&gt;&lt;/h5&gt; &lt;p&gt;&lt;font size="2"&gt;As mentioned earlier, SP1, will include the PrepareMoveRequest script as part of the install. Additionally, we are fixing a couple of issues with that script:&lt;/font&gt;  &lt;ol&gt; &lt;li&gt;&lt;font size="2"&gt;Requiring separate local and remote credentials to run the script. &lt;/font&gt; &lt;li&gt;&lt;font size="2"&gt;LegacyExchangeDN not set on the new user object after converting local contact to local user. &lt;/font&gt; &lt;li&gt;&lt;font size="2"&gt;When specifying TargetMailUserOU, we will only search OUs (instead of other object class). &lt;/font&gt;&lt;/li&gt;&lt;/ol&gt; &lt;h5&gt;&lt;font color="#0000ff"&gt;Common Issues&lt;/font&gt;&lt;/h5&gt; &lt;p&gt;&lt;font size="2"&gt;The most common issues related to PrepareMoveRequest script are listed below. These are not relevant if you have deployed the customized ILM, or if you have already run PrepareMoveRequest.&lt;/font&gt;  &lt;ol&gt; &lt;li&gt;&lt;font size="2"&gt;Not able to match source forest user with target forest user. This is mainly due to the fact the script relies on proxyAddresses to match objects, so the target forest user needs to have at least 1 proxy address that matches the source&lt;/font&gt;  &lt;li&gt;&lt;font size="2"&gt;Inadequate AD permission to delete/add recipient objects. The script manipulates AD directly and invokes the Update-Recipient cmdlet at the end, so you need to have the appropriate permission to change AD and call Update-Recipient. Another thing you can check is whether the TargetMailUserOU is set correctly.&lt;/font&gt;  &lt;li&gt;&lt;font size="2"&gt;The current script does not have good support for users created by ADMT. The updated PrepareMoveRequest script in SP1 will support a new parameter "OverwriteLocalObject" for users created by ADMT and it will copy attributes from the source forest user to the target user.&lt;/font&gt;  &lt;li&gt;&lt;font size="2"&gt;"UseLocalObject" - This is the script logic where we assume ILM has already created the target forest MEC or MEU, and you want to keep the target forest attributes. So the script will convert the target forest MEU or MEC to the required MEU for MBX move. &lt;/font&gt;&lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;font size="2"&gt;Finally, a few words of thanks:&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;I had the privilege of working with several SMEs from the Product Group, Consulting, UE and Support who helped me visualize, plan, develop and complete this blog. I would like to call out Ian Liu (Program Manager) who was instrumental in sharing his vision and being accessible at all times while writing this blog. I also want to thank Daniel Talbot for his expertise on this subject and his many contributions to the blog. Other contributors that I'd like to express gratitude are Andrew Ehrensing and Huangjian Guo. Thanks to Ying Zhang, Ramon Infante, Jeff Kizner, Kweku Ako-Adjei , Ben Winzenz, Kristi Simmons, Bill Haenlin, Laura La Fleur, Nino Bilic, Jonathan Runyon and Ayla Kol for their review and feedback. Last but not the least, I'd like to thank William Rall for his innumerable thorough reviews and feedback that helped shape this blog.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;- &lt;/font&gt;&lt;a href="http://msexchangeteam.com/archive/2006/02/21/420125.aspx"&gt;&lt;font size="2"&gt;Nagesh Mahadev&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://msexchangeteam.com/aggbug.aspx?PostID=455779" width="1" height="1"&gt;</description><category domain="http://msexchangeteam.com/archive/category/11156.aspx">Client Access</category><category domain="http://msexchangeteam.com/archive/category/4981.aspx">Documentation</category><category domain="http://msexchangeteam.com/archive/category/11164.aspx">Exchange 2010</category><category domain="http://msexchangeteam.com/archive/category/11154.aspx">Mailbox</category><category domain="http://msexchangeteam.com/archive/category/3307.aspx">Tips 'n Tricks</category></item><item><title>What is Exchange 2010 automatic mailbox distribution? </title><link>http://msexchangeteam.com/archive/2010/08/09/455756.aspx</link><pubDate>Mon, 09 Aug 2010 10:28:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:455756</guid><dc:creator>Exchange</dc:creator><slash:comments>9</slash:comments><comments>http://msexchangeteam.com/comments/455756.aspx</comments><wfw:commentRss>http://msexchangeteam.com/commentrss.aspx?PostID=455756</wfw:commentRss><wfw:comment>http://msexchangeteam.com/rsscomments/455756.aspx</wfw:comment><description>&lt;div style="font:normal 1.2em Calibri,Helvetica,Arial,sans-serif; padding-top:.5em; line-height:1.3em;"&gt;&lt;p&gt;Have you ever wondered why, in Exchange 2010, you can create a new mailbox and you don't have to tell Exchange in what mailbox database it should be created? Or had an administrator in one department create a mailbox, and the mailbox is created in a database that their department isn't assigned? If you've answered 'yes' to either of those questions, you'll want to check out a new article that was just posted today. &lt;/p&gt;  &lt;p&gt;&lt;a title="Go to 'Where Did That New Exchange 2010 Mailbox Go?' on TechNet" href="http://go.microsoft.com/fwlink/?LinkId=198965"&gt;Where Did That New Exchange 2010 Mailbox Go?&lt;/a&gt; introduces you to automatic mailbox distribution, which is a new feature added to Exchange 2010. The article talks about how automatic mailbox distribution works, steps you through the selection process, and shows you how you can control it using exclusions, Active Directory sites, and (in Exchange 2010 SP1) database scopes. &lt;/p&gt;  &lt;p&gt;Take a look at the article and let us know what you think of this new feature. &lt;/p&gt;  &lt;p&gt;&lt;span class="author"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=198277"&gt;David Strome&lt;/a&gt;&lt;/span&gt;&lt;/p&gt; &lt;/div&gt;&lt;img src="http://msexchangeteam.com/aggbug.aspx?PostID=455756" width="1" height="1"&gt;</description><category domain="http://msexchangeteam.com/archive/category/3648.aspx">Administration</category><category domain="http://msexchangeteam.com/archive/category/11164.aspx">Exchange 2010</category><category domain="http://msexchangeteam.com/archive/category/11154.aspx">Mailbox</category></item><item><title>Understanding Remote Mailbox Move and Unified Messaging</title><link>http://msexchangeteam.com/archive/2010/08/05/455732.aspx</link><pubDate>Thu, 05 Aug 2010 20:41:52 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:455732</guid><dc:creator>Exchange</dc:creator><slash:comments>4</slash:comments><comments>http://msexchangeteam.com/comments/455732.aspx</comments><wfw:commentRss>http://msexchangeteam.com/commentrss.aspx?PostID=455732</wfw:commentRss><wfw:comment>http://msexchangeteam.com/rsscomments/455732.aspx</wfw:comment><description>&lt;div style="font:normal 1.2em Calibri,Helvetica,Arial,sans-serif; padding-top:.5em; line-height:1.3em;"&gt;&lt;p&gt;Remote mailbox move (a.k.a. cross-forest mailbox move) refers to the process of migrating an Exchange mailbox from one Active Directory forest to another. Exchange 2010 supports remote mailbox moves via the MoveRequest cmdlets. Here are some of the considerations for performing remote mailbox moves on mailboxes which are enabled for Unified Messaging (UM). This article assumes that readers are familiar with &lt;a title="Go to 'Understanding Unified Messaging' in Exchange 2010 docs" href="http://technet.microsoft.com/en-us/library/dd351090.aspx"&gt;Unified Messaging&lt;/a&gt; and how &lt;a title="Go to 'Understanding Move Requests' in Exchange 2010 docs" href="http://technet.microsoft.com/en-us/library/dd298174.aspx"&gt;remote mailbox move&lt;/a&gt; operates in general.&lt;/p&gt; &lt;h2&gt;So... why do you care? &lt;/h2&gt; &lt;p&gt;Prior to Exchange 2010 SP1, if you want to perform remote mailbox move on a UM-enabled mailbox, you need to do the following: &lt;/p&gt; &lt;ol&gt; &lt;li&gt;Prior to the move, UM-disable the mailbox in the source forest  &lt;li&gt;Execute move request on the mailbox  &lt;li&gt;After the move completes, UM-enable the mailbox in the target forest &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;In addition, you need to update the telephony configuration for the corresponding phone set so that all phone calls for the mailbox owner are correctly covered by the telephony system to the UM servers in the target forest. &lt;/p&gt; &lt;p&gt;This process poses several pain points, most importantly: &lt;/p&gt; &lt;ul&gt; &lt;li&gt;Admin hassle - The admin having to manually disable and re-enable the mailbox for UM every time a UM-enabled mailbox is moved.  &lt;li&gt;User hassle - Voice Mail stops working for the user whose mailbox is being moved for the entire duration of the move process since the mailbox is UM-disabled. This is problematic for users with large mailboxes where the move process can take a long time to complete. &lt;/li&gt;&lt;/ul&gt; &lt;p&gt;In Exchange 2010 SP1, we've extended the MoveRequest cmdlets to alleviate these pain points by removing the need for an admin to UM-disable/re-enable the mailbox and reduce voice mail downtime. &lt;/p&gt; &lt;h2&gt;How it works &lt;/h2&gt; &lt;p&gt;For this to work correctly, you need to "map" the UMMailboxPolicy objects in the source forest to the UMMailboxPolicy objects in the target forest. This is achieved by stamping the name of the UMMailboxPolicy object in the source forest on the SourceForestPolicyNames attribute on the UMMailboxPolicy object in the target forest. Here's an example to explain what I mean: &lt;/p&gt; &lt;ol&gt; &lt;li&gt;Suppose you have some mailboxes which are UM-enabled in the source forest and are associated with UMMailboxPolicy object (Policy S). You would like these mailboxes to be UM-enabled and associated with UMMailboxPolicy object (Policy T) in the target forest after the move completes.  &lt;li&gt;Prior to executing the &lt;span class="command"&gt;New-MoveRequest&lt;/span&gt; on these mailboxes, you need to stamp the name of Policy A on Policy B's &lt;span class="parameter"&gt;SourceForestPolicyNames&lt;/span&gt; attribute by running the following Exchange cmdlet in the target forest:  &lt;p class="code"&gt;Set-UMMailboxPolicy -identity "Policy B" -SourceForestPolicyNames "Policy A" &lt;/p&gt; &lt;li&gt;Once the mapping is created, you can start moving the mailboxes by executing the New-MoveRequest cmdlet without having to UM-disable the mailbox first. &lt;span class="highlightyellow"&gt;While the move is in progress, UM continues to operate for these mailboxes in the source forest&lt;/span&gt; since the mailboxes are still UM-enabled. As the move request completes for a particular mailbox, the following happens:  &lt;ul&gt; &lt;li&gt;In the target forest:  &lt;ol&gt; &lt;li&gt;Upon detecting that the mailbox is UM-enabled, the migration process obtains the name of the &lt;span class="command"&gt;UMMailboxPolicy&lt;/span&gt; object which the mailbox is associated with in the source forest. It then looks for a corresponding UMMailboxPolicy object in the target forest whose &lt;span class="parameter"&gt;SourceForestPolicyNames&lt;/span&gt; attribute contains this name.  &lt;li&gt;The migration process also figures out what UM extensions are currently assigned to the mailbox in the source forest. Using these extensions and the UMMailboxPolicy object found earlier, the migration then UM-enables the mailbox in the target forest.  &lt;li&gt;The migration process also copies over information about the user's UM PIN into the target forest, ensuring the user's existing UM PIN is preserved during migration.  &lt;li&gt;A UM welcome message is then sent to the user, showing the access telephone number for the UMDialPlan in the target forest. Access telephone number is what users dial on their phone to get to Outlook Voice Access. &lt;/li&gt;&lt;/ol&gt; &lt;li&gt;In the source forest:  &lt;ol&gt; &lt;li&gt;As part of move request, the Active Directory mailbox object is updated into a Mail-Enabled User (MEU) object. All UM configuration on the MEU object is automatically removed. &lt;/li&gt;&lt;/ol&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ol&gt; &lt;p&gt;Once the migration process completes, voice mail outage begins. This is because your telephony system is still sending calls to the UM servers in the source forest. Voice Mail outage continues until the telephony configuration for the corresponding phone set is updated to cover calls to the UM servers in the target forest. &lt;/p&gt; &lt;h2&gt;Further reducing voice mail downtime &lt;/h2&gt; &lt;p&gt;If you want to reduce the amount of downtime even further, this is what you can do:  &lt;ol&gt; &lt;li&gt;Make sure the name of the UMMailboxPolicy object in the source forest is correctly stamped on the SourceForestPolicyNames attribute of the UMMailboxPolicy object in the target forest.  &lt;li&gt;Execute New-MoveRequest with &lt;span class="parameter"&gt;SuspendWhenReadyToComplete&lt;/span&gt; parameter set to &lt;span class="parameter"&gt;$true&lt;/span&gt;. This ensures that the New-MoveRequest pauses right before finalization occurs.  &lt;li&gt;As you resume the move request by running &lt;span class="command"&gt;Resume-MoveRequest&lt;/span&gt;, you also update your PBX configuration. &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;As the mailbox move finalizes, the mailbox in the source forest is deleted and the mailbox in the target forest becomes functional. If you update your telephony configuration as the mailbox move finalizes, you can reduce the window of voice mail outage. Note that this method can be cumbersome since it requires precise coordination between your Exchange admin and your telephony admin. &lt;/p&gt; &lt;h2&gt;SourceForestPolicyNames Attribute &lt;/h2&gt; &lt;p&gt;The &lt;span class="parameter"&gt;SourceForestPolicyNames&lt;/span&gt; attribute on the UMMailboxPolicy object is part of Exchange 2010 SP1 schema. It bears the following characteristics:  &lt;ol&gt; &lt;li&gt;Multi-valued - This means that you can have multiple UMMailboxPolicy objects in the source forest mapped to a single UMMailboxPolicy object in the target forest.  &lt;li&gt;Unique - No two UMMailboxPolicy objects in the same forest can have the same value stamped in their SourceForestPolicyNames attribute. This prevents you from stamping the name of a single UMMailboxPolicy object in the source forest on multiple UMMailboxPolicy objects in the target forest. This is needed to avoid any ambiguity when the migration process looks for a matching policy object in the target forest.  &lt;li&gt;By default, when you create a new UMMailboxPolicy object using Exchange 2010 SP1 cmdlets or admin console, its SourceForestPolicyNames attribute is automatically populated with its own name. An easy way to handle remote mailbox moves is to create UMMailboxPolicy objects in both source and target forests with the same name, thereby avoiding the need to manually configure the SourceForestPolicyNames attribute. &lt;/li&gt;&lt;/ol&gt; &lt;h2&gt;Other considerations &lt;/h2&gt; &lt;ol&gt; &lt;li&gt;If the mailbox is UM-enabled in the source forest but you don't want the mailbox to be UM-enabled in the target forest, you should UM-disable the mailbox prior to the move. Conversely, if the mailbox isn't UM-enabled in the source forest but you want to UM-enable the mailbox in the target forest, you should UM-enable the mailbox in the target forest after the move. Doing so helps to reduce complexity in managing the move request since you don't have to take UM configuration into account.  &lt;li&gt;When you first execute New-MoveRequest, the migration process will perform a series of UM-specific validation up front if mailbox is UM-enabled, including looking for a matching UMMailboxPolicy object in the target forest as well as validating that the UM extensions assigned to the mailbox are unique in the target forest. If the validation fails, New-MoveRequest will return an error immediately.  &lt;li&gt;Under rare circumstances, the UM-specific validation may succeed up front when New-MoveRequest cmdlet is executed but the migration process fails to UM-enable the mailbox as the mailbox move finalizes. When this occurs, the mailbox move will complete with warning and the mailbox will not be UM-enabled in the target forest. You will need to manually UM-enable the mailbox in the target forest. The corresponding warning message, which can be obtained through Get-MoveRequestStatistics cmdlet, looks like this:  &lt;p class="alert" style="margin-top:1em; background: lightyellow; border: 1px solid #e5e597; padding:1em;"&gt;Warning: User 'John Doe' can't be enabled for Unified Messaging in the target forest for the following reason: Extension 12345 is already assigned to another user on dialplan DP1 or an equivalent dial plan. Please fix the problem and enable the user for Unified Messaging manually. &lt;/p&gt; &lt;p&gt;An example of how this can happen is that the UM extension assigned to the mailbox was available in the target forest when the UM-specific validation occurred but is no longer so right when the move finalizes. &lt;/p&gt; &lt;li&gt;A UM-enabled mailbox may be assigned extensions from multiple UMDialPlan objects in the source forest. Only extensions from the primary UMDialPlan will be used to UM-enable the mailbox in the target forest. Extensions from secondary UMDialPlan(s) will not be preserved. &lt;/li&gt;&lt;/ol&gt; &lt;p&gt;&lt;span class="author"&gt;&lt;a href="http://msexchangeteam.com/archive/2010/07/26/455646.aspx"&gt;Chun Yong Chua&lt;/a&gt;&lt;/span&gt;&lt;/p&gt; &lt;/div&gt;&lt;img src="http://msexchangeteam.com/aggbug.aspx?PostID=455732" width="1" height="1"&gt;</description><category domain="http://msexchangeteam.com/archive/category/3648.aspx">Administration</category><category domain="http://msexchangeteam.com/archive/category/11164.aspx">Exchange 2010</category><category domain="http://msexchangeteam.com/archive/category/11154.aspx">Mailbox</category><category domain="http://msexchangeteam.com/archive/category/11150.aspx">Unified Messaging</category></item><item><title>Throttling Policy Associations in Exchange 2010 SP1</title><link>http://msexchangeteam.com/archive/2010/08/02/455707.aspx</link><pubDate>Mon, 02 Aug 2010 15:24:48 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:455707</guid><dc:creator>Exchange</dc:creator><slash:comments>0</slash:comments><comments>http://msexchangeteam.com/comments/455707.aspx</comments><wfw:commentRss>http://msexchangeteam.com/commentrss.aspx?PostID=455707</wfw:commentRss><wfw:comment>http://msexchangeteam.com/rsscomments/455707.aspx</wfw:comment><description>&lt;p&gt;&lt;font size="2"&gt;Exchange 2010 SP1 introduces two new throttling cmdlets: get-ThrottlingPolicyAssociation and set-ThrottlingPolicyAssociation. In Exchange 2010 RTM, in order to determine which throttling policy was associated with a given user, you would use something like:&lt;/font&gt;  &lt;blockquote&gt; &lt;p&gt;&lt;font size="2" face="Courier New"&gt;Get-Mailbox JohnDoe | fl ThrottlingPolicy&lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;To assign a non-default throttling policy to a user you would call &lt;/font&gt; &lt;blockquote&gt; &lt;p&gt;&lt;font size="2" face="Courier New"&gt;set-Mailbox JohnDoe -ThrottlingPolicy Foo&lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;One thing that should stand out with these two CMDlets is that policies could only be associated with &lt;b&gt;mailbox accounts. &lt;/b&gt;Why would you ever want throttling policies associated with anything else? I'm glad you asked. There are at least two valid scenarios to consider:&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;&lt;b&gt;Scenario 1 - A machine account:&lt;/b&gt; Let's say you write a web site that uses Exchange Impersonation to call into EWS and perform actions on behalf of a user that logged onto your web site. Further assuming that your web site is configured to run as Network Service, the EWS call will come from the &lt;b&gt;*machine*&lt;/b&gt; account (such as MyDomain/MyMachine$). When such a call is encountered by EWS, it tries to determine which throttling policy to apply to the machine account. Given that set-Mailbox is not applicable to Active Directory Computer objects, and given that a computer is not *in* any of the organizations defined in the Active Directory, the throttling framework must use the fallback policy for the computer account. Given that the fallback policy is hardcoded within the Exchange binaries, you have no control over reducing or increasing its policy values.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;&lt;b&gt;Scenario 2 - A cross forest contact: &lt;/b&gt;In cross forest scenarios, you have the option of creating a linked mailbox in the Exchange forest or a linked contact. If an account from user forest A is given Exchange Impersonation rights and needs custom throttling values defined, your only option in Exchange 2010 RTM is to use a linked mailbox so that you can assign a non-default throttling policy using the set-Mailbox cmdlets. When a cross forest account calls into Exchange via EWS, the user is authenticated via the user forest (via the trust), but the Active Directory object that Exchange uses to gather "Exchange" information is contained in the Exchange forest. If that Exchange object is a linked contact, the throttling framework must use the fallback policy to throttle the call, which as mentioned above cannot be modified since it is hardcoded.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;To cover these scenarios, we added the get/set-ThrottlingPolicyAssociation cmdlets which operate on "virtual" ThrottlingPolicyAssociation objects. By virtual, I mean that there is no ThrottlingPolicyAssociation class in the Active Directory schema. The association represents the link between some "account" and its throttling policy. And what is an "account"? Well, it could be a mailbox, a computer object or a contact.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;So let's see how this works. I created a factious mailbox account for JohnDoe. Let's call get-ThrottlingPolicyAssociation on JohnDoe and see what happens.&lt;/font&gt;  &lt;blockquote&gt; &lt;p&gt;&lt;font size="2" face="Courier New"&gt;[PS] D:\Windows\system32&amp;gt;&lt;b&gt;get-throttlingPolicyAssociation&lt;/b&gt; JohnDoe&lt;/font&gt;  &lt;p&gt;&lt;font size="2" face="Courier New"&gt;RunspaceId : b84e9a5e-b4c9-4e58-ad86-26d2fffd9b32&lt;br&gt;ObjectId : MyDomain/Users/JohnDoe&lt;br&gt;&lt;font color="#ff0000"&gt;ThrottlingPolicyId :&lt;br&gt;Name : JohnDoe&lt;/font&gt;&lt;br&gt;IsValid : True&lt;br&gt;ExchangeVersion : 0.10 (14.0.100.0)&lt;br&gt;DistinguishedName : CN=JohnDoe,CN=Users,DC=MyDomain&lt;br&gt;Identity : MyDomain/Users/JohnDoe&lt;br&gt;Guid : 4f617494-2542-480d-9db1-2720ddf3c013&lt;br&gt;ObjectCategory : MyDomain/Configuration/Schema/Person&lt;br&gt;ObjectClass : {top, person, organizationalPerson, user}&lt;br&gt;WhenChanged : 7/26/2010 8:13:48 AM&lt;br&gt;WhenCreated : 7/26/2010 8:13:48 AM&lt;br&gt;WhenChangedUTC : 7/26/2010 3:13:48 PM&lt;br&gt;WhenCreatedUTC : 7/26/2010 3:13:48 PM&lt;br&gt;OrganizationId :&lt;br&gt;OriginatingServer : MyServer.MyDomain&lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;The association is embodied in the &lt;b&gt;ThrottlingPolicyId &lt;/b&gt;and &lt;b&gt;Name&lt;/b&gt; properties (in &lt;font color="#ff0000"&gt;red&lt;/font&gt; above). If you look closely at the other properties that were returned, they are all properties on the user object. In fact, all of that data is coming from the mailbox object and not from the throttling policy. Now, let's try a mail contact. This time, I will only ask for interesting properties to save on space.&lt;/font&gt;  &lt;blockquote&gt; &lt;p&gt;&lt;font size="2" face="Courier New"&gt;[PS] D:\Windows\system32&amp;gt;get-throttlingPolicyAssociation &lt;b&gt;MyContact&lt;/b&gt; | fl ThrottlingPolicyId, Name, DistinguishedName, Identity, ObjectCategory, ObjectClass&lt;/font&gt;  &lt;p&gt;&lt;font size="2" face="Courier New"&gt;&lt;font color="#ff0000"&gt;ThrottlingPolicyId :&lt;br&gt;Name : MyContact&lt;/font&gt;&lt;br&gt;DistinguishedName : CN=MyContact,CN=Users,DC=MyDomain &lt;br&gt;Identity : MyDomain/Users/MyContact&lt;br&gt;ObjectCategory : MyDomain/Configuration/Schema/Person&lt;br&gt;ObjectClass : {top, person, organizationalPerson, &lt;b&gt;contact&lt;/b&gt;}&lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;And of course, we can't forget about computers.&lt;/font&gt;  &lt;blockquote&gt; &lt;p&gt;&lt;font size="2" face="Courier New"&gt;[PS] D:\Windows\system32&amp;gt;get-throttlingPolicyAssociation &lt;b&gt;MyComputer&lt;/b&gt; | fl ThrottlingPolicyId, Name, DistinguishedName, Identity, ObjectCategory, ObjectClass&lt;/font&gt;  &lt;p&gt;&lt;font size="2" face="Courier New"&gt;&lt;font color="#ff0000"&gt;ThrottlingPolicyId :&lt;br&gt;Name : MyComputer&lt;/font&gt;&lt;br&gt;DistinguishedName : CN=MyComputer,OU=&lt;b&gt;Domain Controllers&lt;/b&gt;,DC=MyDomain&lt;br&gt;Identity : MyDomain/&lt;b&gt;Domain Controllers&lt;/b&gt;/MyComputer&lt;br&gt;ObjectCategory : MyDomain/Configuration/Schema/&lt;b&gt;Computer&lt;/b&gt;&lt;br&gt;ObjectClass : {top, person, organizationalPerson, user, &lt;b&gt;computer&lt;/b&gt;}&lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;The magic comes from the fact that the throttling policy "stamp" is made available on users, contacts and computers via the mailRecipient auxiliary class in the Active Directory schema. The attribute was actually available in Exchange 2010 RTM on users, contacts and computers, but it was not "PowerShell" accessible until these new cmdlets were added. To change the throttling policy association for a user, contact or computer, simply call set-throttlingPolicyAssociation with the identity of the account to change and the throttling policy identity to associate it with:&lt;/font&gt;  &lt;blockquote&gt; &lt;p&gt;&lt;font size="2" face="Courier New"&gt;set-throttlingPolicyAssociation JohnDoe -ThrottlingPolicy Foo&lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;In fact, we can assign users, contacts and computers in one shot:&lt;/font&gt;  &lt;blockquote&gt; &lt;p&gt;&lt;font size="2" face="Courier New"&gt;[PS] D:\Windows\system32&amp;gt;$identity = "JohnDoe", "MyContact", "MyMachine"&lt;/font&gt;  &lt;p&gt;&lt;font size="2" face="Courier New"&gt;[PS] D:\Windows\system32&amp;gt;foreach ($id in $identity){set-throttlingPolicyAssociation $id -&lt;b&gt;ThrottlingPolicy&lt;/b&gt; Foo}&lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;And just to confirm that it did indeed work:&lt;/font&gt;  &lt;blockquote&gt; &lt;p&gt;&lt;font size="2" face="Courier New"&gt;[PS] D:\Windows\system32&amp;gt;foreach ($id in $identity){get-throttlingPolicyAssociation $id | fl Name, &lt;b&gt;ThrottlingPolicyId&lt;/b&gt;}&lt;/font&gt;  &lt;p&gt;&lt;font size="2" face="Courier New"&gt;Name : JohnDoe&lt;br&gt;ThrottlingPolicyId : Foo&lt;/font&gt;  &lt;p&gt;&lt;font size="2" face="Courier New"&gt;Name : MyContact&lt;br&gt;ThrottlingPolicyId : Foo&lt;/font&gt;  &lt;p&gt;&lt;font size="2" face="Courier New"&gt;Name : MyMachine&lt;br&gt;ThrottlingPolicyId : Foo&lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;You may be relieved to know that getting and setting the throttling policy for a mailbox still works through get/set-Mailbox. However, for new scripts moving forward, we suggest you use the new, shiny get/set-ThrottlingPolicyAssociation cmdlets.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;One important thing to note is that you use the &lt;b&gt;ThrottlingPolicy &lt;/b&gt;parameter in set-ThrottlingPolicyAssociation whereas the property that is returned in get-ThrottlingPolicyAssociation is called &lt;b&gt;ThrottlingPolicyId&lt;/b&gt;. This difference continues to trip me up when using these cmdlets, so when you encounter this difference, know that you are in good company.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;- &lt;/font&gt;&lt;a href="http://msexchangeteam.com/archive/2008/03/24/448499.aspx"&gt;&lt;font size="2"&gt;David Sterling&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://msexchangeteam.com/aggbug.aspx?PostID=455707" width="1" height="1"&gt;</description><category domain="http://msexchangeteam.com/archive/category/11156.aspx">Client Access</category><category domain="http://msexchangeteam.com/archive/category/4981.aspx">Documentation</category><category domain="http://msexchangeteam.com/archive/category/11164.aspx">Exchange 2010</category><category domain="http://msexchangeteam.com/archive/category/3307.aspx">Tips 'n Tricks</category></item><item><title>Confused About Named Properties Quotas in Exchange 2003 and Exchange 2007? Join the Club!</title><link>http://msexchangeteam.com/archive/2010/07/29/455687.aspx</link><pubDate>Thu, 29 Jul 2010 17:00:21 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:455687</guid><dc:creator>Exchange</dc:creator><slash:comments>24</slash:comments><comments>http://msexchangeteam.com/comments/455687.aspx</comments><wfw:commentRss>http://msexchangeteam.com/commentrss.aspx?PostID=455687</wfw:commentRss><wfw:comment>http://msexchangeteam.com/rsscomments/455687.aspx</wfw:comment><description>&lt;p&gt;&lt;font size="2"&gt;One of my favorite things about my job is that I get to learn new stuff everyday! It's like being in school all of the time! And yes, I was that person in class that always ruined the curve for everyone else.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;If you have been using either Exchange 2003 or Exchange 2007 for any length of time, you may have experienced the dreaded &lt;b&gt;Named Properties Depletion&lt;/b&gt; warning in your Application Event log. If you haven't, they look like this:&lt;/font&gt;  &lt;p&gt;&lt;b&gt;&lt;font size="2"&gt;Named Properties Warning for Mailbox Databases:&lt;/font&gt;&lt;/b&gt;  &lt;blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;Event ID: 9666&lt;br&gt;Type: Warning&lt;br&gt;Category: General&lt;br&gt;Source: msgidNamedPropsQuotaWarning&lt;br&gt;Description: The number of named properties created for database "&amp;lt;&lt;i&gt;database name&lt;/i&gt;&amp;gt;" is close to quota limit. Current number of named properties: &amp;lt;&lt;i&gt;number of named properties&lt;/i&gt;&amp;gt;. Quota limit for named properties: &amp;lt;&lt;i&gt;configured quota&lt;/i&gt;&amp;gt;. User attempting to create the named property: &amp;lt;&lt;i&gt;user name&lt;/i&gt;&amp;gt;. Named property GUID: &amp;lt;&lt;i&gt;GUID of named property&lt;/i&gt;&amp;gt;. Named property name/id: &amp;lt;&lt;i&gt;name of named property&lt;/i&gt;&amp;gt;.&lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;&lt;strong&gt;Note:&lt;/strong&gt; Event ID 9666 can refer to Authenticated Users (MAPI) and Non-Authenticated Users (Non-MAPI) creation of named properties. For a more in-depth explanation of the difference between &lt;b&gt;Authenticated Users (MAPI)&lt;/b&gt; and &lt;b&gt;Non-Authenticated Users (Non-MAPI)&lt;/b&gt;, please see Jason Nelson's blog about &lt;b&gt;Named Properties, X-Headers, and You &lt;/b&gt;&lt;/font&gt;&lt;font size="2"&gt;(&lt;a href="http://msexchangeteam.com/archive/2009/04/06/451003.aspx"&gt;http://msexchangeteam.com/archive/2009/04/06/451003.aspx&lt;/a&gt;&lt;/font&gt;&lt;font size="2"&gt;)&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;Even worse is getting the error events.&lt;/font&gt;  &lt;p&gt;&lt;b&gt;&lt;font size="2"&gt;Named Properties Error for Mailbox Databases:&lt;/font&gt;&lt;/b&gt;  &lt;blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;Event ID: 9667&lt;br&gt;Type: Error&lt;br&gt;Category: General&lt;br&gt;Source: msgidNamedPropsQuotaError&lt;br&gt;Description: Failed to create a new named property for database "&amp;lt;&lt;i&gt;database name&lt;/i&gt;&amp;gt;" because the number of named properties reached the quota limit (&amp;lt;&lt;i&gt;configured quota&lt;/i&gt;&amp;gt;). User attempting to create the named property: &amp;lt;&lt;i&gt;user name&lt;/i&gt;&amp;gt;. Named property GUID: &amp;lt;&lt;i&gt;GUID of named property&lt;/i&gt;&amp;gt;. Named property name/id: &amp;lt;&lt;i&gt;name of named property&lt;/i&gt;&amp;gt;.&lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;&lt;strong&gt;Note:&lt;/strong&gt; Event ID 9667 can refer to Authenticated Users (MAPI) and Non-Authenticated Users (Non-MAPI) creation of named properties. For a more in-depth explanation of the difference between &lt;b&gt;Authenticated Users (MAPI)&lt;/b&gt; and &lt;b&gt;Non-Authenticated Users (Non-MAPI)&lt;/b&gt;, please see Jason Nelson's blog about &lt;b&gt;Named Properties, X-Headers, and You&lt;/b&gt; &lt;/font&gt;&lt;a href="http://msexchangeteam.com/archive/2009/04/06/451003.aspx"&gt;&lt;font size="2"&gt;(http://msexchangeteam.com/archive/2009/04/06/451003.aspx&lt;/font&gt;&lt;/a&gt;&lt;font size="2"&gt;)&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;By the time the error is recorded, you are probably getting calls from your end users wanting to know why they can't send or receive mail. I am not going to explain the history and impact of Named Properties since &lt;b&gt;&lt;a href="http://msexchangeteam.com/archive/2004/04/20/117016.aspx" target="_blank"&gt;Jason Nelson&lt;/a&gt;&lt;/b&gt; wrote several excellent blogs on this (which I use all the time). Check them out here:&lt;/font&gt;  &lt;blockquote&gt; &lt;p&gt;&lt;b&gt;&lt;font size="2"&gt;Named Properties, X-Headers, and You&lt;br&gt;&lt;/font&gt;&lt;/b&gt;&lt;a href="http://msexchangeteam.com/archive/2009/04/06/451003.aspx"&gt;&lt;font size="2"&gt;http://msexchangeteam.com/archive/2009/04/06/451003.aspx&lt;/font&gt;&lt;/a&gt;  &lt;p&gt;&lt;b&gt;&lt;font size="2"&gt;Named Properties, Round 2: What lies Ahead&lt;br&gt;&lt;/font&gt;&lt;/b&gt;&lt;a href="http://msexchangeteam.com/archive/2009/06/12/451596.aspx"&gt;&lt;font size="2"&gt;http://msexchangeteam.com/archive/2009/06/12/451596.aspx&lt;/font&gt;&lt;/a&gt;  &lt;p&gt;&lt;b&gt;&lt;font size="2"&gt;Service Pack 2 Preview: Get-NamedProperty&lt;br&gt;&lt;/font&gt;&lt;/b&gt;&lt;a href="http://msexchangeteam.com/archive/2009/08/06/451948.aspx"&gt;&lt;font size="2"&gt;http://msexchangeteam.com/archive/2009/08/06/451948.aspx&lt;/font&gt;&lt;/a&gt;  &lt;p&gt;&lt;b&gt;&lt;font size="2"&gt;Understanding how Outlook, CDO, MAPI, and Providers work together&lt;br&gt;&lt;/font&gt;&lt;/b&gt;&lt;a href="http://msexchangeteam.com/archive/2005/04/08/403512.aspx"&gt;&lt;font size="2"&gt;http://msexchangeteam.com/archive/2005/04/08/403512.aspx&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;Now to clear up the biggest misconception about setting quota limits for named properties for an Exchange 2003 or Exchange 2007 databases:&lt;/font&gt;  &lt;blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;Setting the quota limits &lt;font color="#ff0000"&gt;&lt;b&gt;&lt;i&gt;does not increase the number of named properties that can be created&lt;/i&gt;&lt;/b&gt; &lt;/font&gt;&lt;b&gt;&lt;i&gt;&lt;font color="#ff0000"&gt;in an Exchange 2003 or Exchange 2007 database&lt;/font&gt;.&lt;/i&gt;&lt;/b&gt;&lt;/font&gt;  &lt;p&gt;&lt;b&gt;&lt;i&gt;&lt;font color="#ff0000" size="2"&gt;The number of named properties that can be created in an Exchange 2003 or Exchange 2007 database is a limitation of the size of the data type.&lt;/font&gt;&lt;/i&gt;&lt;/b&gt;  &lt;p&gt;&lt;font size="2"&gt;Setting the quota limits for named properties for an Exchange 2003 or Exchange 2007 database &lt;b&gt;&lt;i&gt;&lt;font color="#ff0000"&gt;increases the threshold&lt;/font&gt;&lt;/i&gt;&lt;/b&gt; of when you are going to get the warning and error messages in the Application Event log.&lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;Please read the above again; it's kind of important.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;For Exchange 2003 and 2007, the &lt;b&gt;maximum number of named properties &lt;/b&gt;that can ever be created is &lt;b&gt;&lt;i&gt;32,767&lt;/i&gt;&lt;/b&gt; per database. &lt;/font&gt; &lt;p&gt;&lt;font size="2"&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;&lt;font color="#ff0000"&gt;There is not a way to ever increase the number&lt;/font&gt;&lt;/u&gt;&lt;/i&gt;&lt;/b&gt; of named properties that can be created in Exchange 2003 or Exchange 2007 database is a limitation of the size of the data type.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;It took me several readings of all KB and TechNet articles before I picked up on that. So if you didn't get it, please do not feel bad. I spent a lot of time with one of our Senior Escalation Engineers trying to understand it. Right before I wore out their last nerve, a light bulb went on over my head and I finally understood it. Now I explain it to my colleagues and customers, my cat Spike and strangers at the gas station.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;And now for something completely different or a little more in-depth view of NamedProps:&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;The way this really works is that we have a table in the database called NamedProps. Every Named Property that gets added to the database gets its own row in this table. The limit on the NamedProps table is a limit on the number of rows in the table, which are 32,767.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;The quotas, of course, are set much lower than that, so that you have some warning before you run out of rows. It doesn't matter if the user is authenticated or not - they all go into the same NamedProps table. So you could have 32k created all by authenticated users, or 32k all created by unauthenticated users, or 10k created by unauthenticated and 22k by authenticated, or whatever... it doesn't matter who created them, the bottom line is that the maximum is 32k rows in that table.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;Once your table passes 8k rows (by default), we stop allowing new named props from unauthenticated clients. It's entirely possible that those 8k rows were all created by authenticated clients, but it doesn't matter. We continue allowing new names from auth clients until we hit 16k, and then we deny them as well. This is assuming the quotas are at the default of 8k/16k.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;Below is a table with the named properties quota limits:&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;&lt;/font&gt;&amp;nbsp;&lt;/p&gt; &lt;table border="1" cellspacing="0" cellpadding="0"&gt; &lt;tbody&gt; &lt;tr&gt; &lt;td valign="top" width="79"&gt; &lt;p&gt;&lt;b&gt;&lt;font size="2"&gt;Exchange Version&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;&lt;/td&gt; &lt;td valign="top" width="120"&gt; &lt;p&gt;&lt;b&gt;&lt;font size="2"&gt;Maximum size of the data type&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;&lt;/td&gt; &lt;td valign="top" width="126"&gt; &lt;p&gt;&lt;b&gt;&lt;font size="2"&gt;Default Quota&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;&lt;/td&gt; &lt;td valign="top" width="120"&gt; &lt;p&gt;&lt;b&gt;&lt;font size="2"&gt;Default Warning Issued&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;&lt;/td&gt; &lt;td valign="top" width="108"&gt; &lt;p&gt;&lt;b&gt;&lt;font size="2"&gt;Default Error Issued&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr&gt; &lt;td valign="top" width="79"&gt; &lt;p&gt;&lt;b&gt;&lt;font color="#ff0000" size="2"&gt;2003 Mailbox Store&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;&lt;/td&gt; &lt;td valign="top" width="120"&gt; &lt;p&gt;&lt;font size="2"&gt;&lt;b&gt;&lt;i&gt;Authenticated Users &amp;amp; Non-Authenticated Users &lt;/i&gt;&lt;/b&gt;&lt;font color="#ff0000"&gt;32,767&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;/td&gt; &lt;td valign="top" width="126"&gt; &lt;p&gt;&lt;font size="2"&gt;&lt;b&gt;&lt;i&gt;Authenticated Users:&lt;/i&gt;&lt;/b&gt; &lt;font color="#ff0000"&gt;16,384&lt;/font&gt;&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;&lt;b&gt;&lt;i&gt;Non-Authenticated Users:&lt;/i&gt;&lt;/b&gt; &lt;font color="#ff0000"&gt;8,192&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;/td&gt; &lt;td valign="top" width="120"&gt; &lt;p&gt;&lt;b&gt;&lt;i&gt;&lt;font size="2"&gt;Authenticated Users:&lt;/font&gt;&lt;/i&gt;&lt;/b&gt;  &lt;p&gt;&lt;font color="#ff0000" size="2"&gt;16,364&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;&lt;b&gt;&lt;i&gt;Non-Authenticated Users: &lt;/i&gt;&lt;/b&gt;&lt;font color="#ff0000"&gt;8,172&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;/td&gt; &lt;td valign="top" width="108"&gt; &lt;p&gt;&lt;b&gt;&lt;i&gt;&lt;font size="2"&gt;Authenticated Users:&lt;/font&gt;&lt;/i&gt;&lt;/b&gt;  &lt;p&gt;&lt;font color="#ff0000" size="2"&gt;16,384&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;&lt;b&gt;&lt;i&gt;Non-Authenticated Users:&lt;/i&gt;&lt;/b&gt; &lt;font color="#ff0000"&gt;8,192&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr&gt; &lt;td valign="top" width="79"&gt; &lt;p&gt;&lt;b&gt;&lt;i&gt;&lt;font color="#ff0000" size="2"&gt;2007 Mailbox Store&lt;/font&gt;&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;&lt;/td&gt; &lt;td valign="top" width="120"&gt; &lt;p&gt;&lt;font size="2"&gt;&lt;b&gt;&lt;i&gt;Authenticated Users &amp;amp; Non-Authenticated Users &lt;/i&gt;&lt;/b&gt;&lt;font color="#ff0000"&gt;32,767&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;/td&gt; &lt;td valign="top" width="126"&gt; &lt;p&gt;&lt;font size="2"&gt;&lt;b&gt;&lt;i&gt;Authenticated Users:&lt;/i&gt;&lt;/b&gt; &lt;font color="#ff0000"&gt;16,384&lt;/font&gt;&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;&lt;b&gt;&lt;i&gt;Non-Authenticated Users:&lt;/i&gt;&lt;/b&gt; &lt;font color="#ff0000"&gt;8,192&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;/td&gt; &lt;td valign="top" width="120"&gt; &lt;p&gt;&lt;b&gt;&lt;i&gt;&lt;font size="2"&gt;Authenticated Users:&lt;/font&gt;&lt;/i&gt;&lt;/b&gt;  &lt;p&gt;&lt;font color="#ff0000" size="2"&gt;16,364&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;&lt;b&gt;&lt;i&gt;Non-Authenticated Users:&lt;/i&gt;&lt;/b&gt; &lt;font color="#ff0000"&gt;8,172&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;/td&gt; &lt;td valign="top" width="108"&gt; &lt;p&gt;&lt;b&gt;&lt;i&gt;&lt;font size="2"&gt;Authenticated Users:&lt;/font&gt;&lt;/i&gt;&lt;/b&gt;  &lt;p&gt;&lt;font color="#ff0000" size="2"&gt;16,384&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;&lt;b&gt;&lt;i&gt;Non-Authenticated Users:&lt;/i&gt;&lt;/b&gt; &lt;font color="#ff0000"&gt;8,192&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt; &lt;p&gt;&lt;font size="2"&gt;For a more in-depth explanation of the difference between &lt;b&gt;Authenticated Users (MAPI)&lt;/b&gt; and &lt;b&gt;Non-Authenticated Users (Non-MAPI)&lt;/b&gt;, please see Jason Nelson's blog about &lt;b&gt;Named Properties, X-Headers, and You&lt;/b&gt; (&lt;/font&gt;&lt;a href="http://msexchangeteam.com/archive/2009/04/06/451003.aspx"&gt;&lt;font size="2"&gt;http://msexchangeteam.com/archive/2009/04/06/451003.aspx&lt;/font&gt;&lt;/a&gt;&lt;font size="2"&gt;)&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;You can increase the thresholds so you don't get the warnings until, say 22,000. We don't recommend setting the warning quota any higher than 16,000 so you will have adequate time to take action.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;And we definitely don't recommend setting the error quota to 32,767 because at that point everyone in your Exchange organization is miffed with you and you find yourself uploading your resume to a popular job site on the Internet.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;You may ask yourself "where is my beautiful..."; hold on, wrong question&lt;b&gt;. &lt;/b&gt;&lt;/font&gt; &lt;p&gt;&lt;b&gt;&lt;font size="2"&gt;Is there a way to suppress the creation of future for named properties for an Exchange 2003 or Exchange 2007 database? And what about Exchange 2010?&lt;/font&gt;&lt;/b&gt;  &lt;p&gt;&lt;font size="2"&gt;I am glad that you asked!&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;For &lt;b&gt;Exchange 2007 SP1 RU1 - RU7&lt;/b&gt;, there is a transport agent named &lt;b&gt;&lt;i&gt;HeadFilterAgent&lt;/i&gt;&lt;/b&gt; that is available for download at:&lt;/font&gt;  &lt;blockquote&gt; &lt;p&gt;&lt;a href="http://headerfilteragent.codeplex.com/"&gt;&lt;font size="2"&gt;http://headerfilteragent.codeplex.com/&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;&lt;b&gt;Exchange 2007 RU 8 for Service Pack 1&lt;/b&gt; and &lt;b&gt;Service Pack 2&lt;/b&gt; (and later) have new code that prevents future promotion of named properties. And this code is already in Exchange 2010 so no action is needed on your part.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;For &lt;b&gt;Exchange 2003&lt;/b&gt;, we have a &lt;b&gt;hot fix for Service Pack 2&lt;/b&gt; that enables the control for the creation of x-headers for named properties using a Registry Editor entry:&lt;/font&gt;  &lt;blockquote&gt; &lt;p&gt;&lt;b&gt;&lt;font size="2"&gt;972077 "Outlook cannot display this view. Unknown Error" error message is generated in Outlook client and Event ID 9667 is logged on an Exchange Server 2003 server&lt;br&gt;&lt;/font&gt;&lt;/b&gt;&lt;a href="http://support.microsoft.com/default.aspx?scid=kb;EN-US;972077"&gt;&lt;font size="2"&gt;http://support.microsoft.com/default.aspx?scid=kb;EN-US;972077&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;After you apply this fix, you may follow these steps to set a registry entry to control the promotion of X-headers for named properties: &lt;/font&gt; &lt;blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;1. Click &lt;b&gt;Start&lt;/b&gt; , click &lt;b&gt;Run&lt;/b&gt; , type &lt;b&gt;regedit&lt;/b&gt; , and then click &lt;b&gt;OK&lt;/b&gt; .&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;2. Locate and then click the following registry subkey: &lt;/font&gt; &lt;p&gt;&lt;b&gt;&lt;font size="2"&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSExchangeIS&lt;/font&gt;&lt;/b&gt;  &lt;p&gt;&lt;b&gt;&lt;font size="2"&gt;\ParametersSystem\InternetContent &lt;/font&gt;&lt;/b&gt; &lt;p&gt;&lt;font size="2"&gt;3. On the &lt;b&gt;Edit&lt;/b&gt; menu, point to &lt;b&gt;New&lt;/b&gt; , and then click &lt;b&gt;DWORD&lt;/b&gt; Value .&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;4. Type &lt;b&gt;GenerateNamedProperties&lt;/b&gt; , and then press &lt;b&gt;ENTER&lt;/b&gt; .&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;5. Quit Registry Editor.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;A &lt;b&gt;0&lt;/b&gt; value of the &lt;b&gt;GenerateNamedProperties&lt;/b&gt; attribute will not generate new named properties. &lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;&lt;font size="2"&gt;The default behavior (of the promotion of X-headers for named properties) is true when this registry entry is not found or set to 1.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;Let's recap:&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;Setting the quota limits &lt;b&gt;&lt;font color="#ff0000"&gt;does not increase the number&lt;/font&gt;&lt;/b&gt; of named properties that can be created in an Exchange 2003 or Exchange 2007 database.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;&lt;font color="#ff0000"&gt;There is not a way to ever increase the number&lt;/font&gt;&lt;/u&gt;&lt;/i&gt;&lt;/b&gt; of named properties that can be created in Exchange 2003 or Exchange 2007 database is a limitation of the size of the data type.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;You can suppress the promotion of named properties in &lt;b&gt;Exchange 2007 SP1 RU1 - RU7&lt;/b&gt; using the transport agent named &lt;b&gt;&lt;i&gt;HeadFilterAgent&lt;/i&gt;&lt;/b&gt; . Or by applying &lt;b&gt;Exchange 2007 SP1 RU8 or Exchange 2007 SP2&lt;/b&gt;. For &lt;b&gt;Exchange 2003 SP2&lt;/b&gt;, a &lt;b&gt;hot fix&lt;/b&gt; is available that utilizes a registry setting to suppress the promotion.&lt;/font&gt;  &lt;p&gt;&lt;font size="2"&gt;- &lt;/font&gt;&lt;a href="http://msexchangeteam.com/archive/2007/03/22/437237.aspx"&gt;&lt;font size="2"&gt;Eileen O'Rourke&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://msexchangeteam.com/aggbug.aspx?PostID=455687" width="1" height="1"&gt;</description><category domain="http://msexchangeteam.com/archive/category/4981.aspx">Documentation</category><category domain="http://msexchangeteam.com/archive/category/10058.aspx">Exchange 2007</category><category domain="http://msexchangeteam.com/archive/category/3307.aspx">Tips 'n Tricks</category><category domain="http://msexchangeteam.com/archive/category/3306.aspx">Troubleshooting</category></item></channel></rss>