DAVTON ENTERPRISE SYNC SET-UP MS EXCHANGE 2010
CREATE A WINDOWS ACCOUNT THAT HAS A MICROSOFT EXCHANGE 2010 MAILBOX
You must create a Windows® account that has a Microsoft® Exchange 2010 mailbox so that the Windows account can authenticate with the Microsoft® Exchange Server. This account must be a domain user only- and not be given any additional administrator privileges except as described below. ( Additional privileges such as domain admin have 'deny' permissions which will stop the account working as required. )
- On the computer that hosts Microsoft Exchange, log in using an administrator account that has the correct permission to create accounts.
- Open the Microsoft Exchange Management Console.
- Create an account and mailbox with the name SyncService.
- Give the SyncService account Owner permissions on the Public Folders you will be accessing. (Owner is required to set up certain custom fields.)
- Whilst still on the server, configure the Domain Security Policy to allow this account to Log on as a Service.
CONFIGURE MICROSOFT EXCHANGE 2010 PERMISSIONS FOR THE WINDOWS ACCOUNT
- Verify the domain name in Microsoft® Active Directory®. When you set the permissions, you will need to match the domain name exactly as it is in Microsoft Active Directory.
- On a computer that hosts the Microsoft® Exchange Management Shell, open the Microsoft Exchange Management Shell.
Get-MailboxDatabase | Add-ADPermission -User "SyncService" -AccessRights ExtendedRight -ExtendedRights Receive-As, ms-Exch-Store-Admin.
- Type: Add-RoleGroupMember "View-Only Organization Management" -Member "SyncService".
- Find the correct identity* for your new SyncService account and then set permissions at common name (or organizational) level:
- To set the permissions at the common name level, type the following command:
Add-ADPermission -InheritedObjectType User -InheritanceType Descendents -ExtendedRights Send-As - User "SyncService" -Identity "CN=<common_name>,DC=<domain_1>,DC=<domain_2>,DC=<domain_3>"
- To set the permissions at the organizational unit level, type the following command:
Add-ADPermission -InheritedObjectType User -InheritanceType Descendents -ExtendedRights Send-As -User "SyncService" -Identity "OU=<organizational_unit>,DC=<domain_1>,DC=<domain_2>,DC=<domain_3>"
How to Find the Correct Identity
*The correct identity is the exact AD address for the user you created. To find this:
a) Open Active Directory Users & Computers
b) In the Menu bar up the top, open View and the select Advanced Features
c) Browse to your SyncService user, and open the users properties by double clicking
d) Now select the tab named Attribute Editor. Scroll through the list until you get to distinguishedName and double click it to view its properties.This will say something like: CN=SyncService,CN=Users,DC=mydomain,DC=local
For this example the command to type would be would be:
Add-ADPermission -InheritedObjectType User -InheritanceType Descendents -ExtendedRights Send-As -User "BESAdmin" -Identity "CN=BESAdmin, CN=Users,DC=mydomain,DC=local”
ALLOW SYNCSERVICE TO LOG ON AS A SERVICE
This permission should be granted when you install your service, but we have found that sometimes it is not granted.
- Click Start > Administrative Tools > Local Security Policy. NOTE: If the computer is a Domain Controller, click Start > Administrative Tools > Domain Controller Security Policy.
- In the Local Securities window, click Local Policies > User Rights Assignment.
- Perform one of the following steps:
- For Windows Server 2000, double-click Log on Locally.
- For Windows Server 2003 and 2008, double-click Allow Log on Locally.
- Click Add User or Group.
- Select the Davton Enterprise Sync Service account name, and then click Add.
- Click OK.
- Similarly (still in User Rights Assignment) , double-click Log On As a Service.
- Click Add User or Group and then select the Davton Enterprise Sync Service account.
- Click OK.
LOG-OFF THE SERVER AND LOG BACK ON USING YOUR NEW SYNCSERVICE ACCOUNT
You should now log off the server and complete the rest of the installation and configuration using your newly set up SyncService account.