Hybrid Deployment - Architecture Overview
Common Issues and Misconceptions
Moving Mailboxes: The Good, the Bad the Ugly
Keeping ADFS Alive
DirSync / AADSync / AADConnect / Password Synchronization
Monitoring in a Hybrid Deployment
2. Michael Van Horenbeeck
⢠Exchange Server MVP & MCSM
⢠Director of Product Research at
ENow Software
⢠Active in the industry for the
past 13 years
⢠Frequent speaker at
international conferences
⢠Blogs at www.vanhybrid.com
⢠Member of The UC Architects
podcast
3. Agenda
⢠Hybrid deployment â architecture overview
⢠Common issues and misconceptions
⢠Moving mailboxes: the good, the bad and the ugly
⢠Keeping ADFS alive
⢠DirSync / AADSync / AADConnect / Password Synchronization
⢠Monitoring in a hybrid deployment
⢠Q&A
5. What is a hybrid deployment?
âTwo distinct cross-premises Exchange organizations, combined to âactâ
as a single organization through a series of customizations in both
environmentsâ
9. DirSync
⢠Not synchronizingâŚat all.
⢠Synchronizing but is having issues with a subset of
accounts due to:
⢠Duplicates
⢠Illegal characters (corrupted items etcâŚ)
⢠Attributes not written back properly
12. Active Directory Federation Services
⢠Error messages can be crypticâŚ
⢠Troubleshooting is not easy
⢠You only have âhalfâ of the story
⢠Different authentication flows
⢠3rd party tooling needed to help figuring out what
happen(s)(ed)
14. Troubleshooting AD FS Summary
⢠Not easy
⢠Use tools like e.g. Fiddler
⢠Enable Debug Logging in Event Viewer
⢠Pair AD FS Proxy w/ ADFS for easier troubleshooting
⢠Understanding different authentication flows is important
15. Exchange Federation
⢠Many components to take a look at
⢠Microsoft Federation Gateway trust
⢠Organization Relationship (local)
⢠Organization Relationship (remote)
⢠Domain Federation Information
⢠Autodiscover
⢠OAUTH (ânewâ since Exchange 2013 CU5)
19. Monitoring Exchange Hybrid
⢠Change in monitoring paradigm:
⢠Itâs no longer about the server(s), rather about the service!
⢠Allows you to identify faster where the problem is located:
⢠proactively communicate to your user base (and management)
⢠Faster resolution time in case problem is caused on-prem
⢠Escalate issues to support earlier
⢠No need to âwaitâ for updated dashboard
20. What components do I need to monitor?
⢠Directory Synchronization
⢠Identity Federation (if applicable)
⢠Exchange Federation
⢠Mail Flow
⢠Certificates
⢠Connectivity
Featured as Messaging and Unified
Communications Award Finalist