<?xml version="1.0" encoding="iso-8859-1"?><!-- generator="b2evolution/4.0.5" -->
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:admin="http://webns.net/mvcb/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Matt's Blog</title>
		<link>http://blog.mattsampson.net/index.php?blog=1</link>
		<atom:link rel="self" type="application/rss+xml" href="http://blog.mattsampson.net/index.php?blog=1&#38;tempskin=_rss2" />
		<description></description>
		<language>en-GB</language>
		<docs>http://blogs.law.harvard.edu/tech/rss</docs>
		<admin:generatorAgent rdf:resource="http://b2evolution.net/?v=4.0.5"/>
		<ttl>60</ttl>
				<item>
			<title>Lync 2010 &#8211; Active Directory Operation Failed &#8211; Insufficient Access Rights To Perform This Operation</title>
			<link>http://blog.mattsampson.net/index.php/lync-2010-active-directory-operation?blog=1</link>
			<pubDate>Wed, 08 Feb 2012 16:05:00 +0000</pubDate>			<dc:creator>admin</dc:creator>
			<category domain="alt">Citrix ICA Client</category>
<category domain="alt">Exchange</category>
<category domain="main">Lync/OCS</category>			<guid isPermaLink="false">127@http://blog.mattsampson.net/</guid>
						<description>&lt;p&gt;&lt;strong&gt;Problem&lt;/strong&gt;&lt;br /&gt;
When editing a domain administrator in the Lync control panel you may be faced with the error below once you press the commit button to save your changes.&lt;/p&gt;

&lt;p&gt;&amp;#8212;&amp;#8211;&lt;br /&gt;
Active Directory operation failed on &amp;#8220;DC01.MYDOMAIN.COM&quot;. You cannot retry this operation: &amp;#8220;Insufficient access rights to perform the operation 00002098, problem 4003 (INSUFF_ACCESS_RIGHTS), data 0&amp;Prime;.&lt;br /&gt;
You do not have the appropriate permissions to perform this operation in Active Directory. One possible cause is that the Lync Server Control Panel and Remote Windows PowerShell cannot modify users who belong to protected security groups (for example, the Domain Admins group). To manage users in the Domain Admins group, use the Lync Server Management Shell and log on using a Domain Admins Account. There are other possible causes. For details, see Lync Server 2010 Help.&lt;br /&gt;
&amp;#8212;&amp;#8211;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Solution&lt;/strong&gt;&lt;br /&gt;
You have to go to Active Directory Users and Computers (with Advanced Features turned on in the View Menu), then go to Properties on the User that you can&amp;#8217;t enable on Lync, and in the Security tab, clic on Advanced. Then check &amp;#8220;Include Inheritable Permissions from this object&amp;#8217;s parent&quot;, accept and the problem will be instantly solved.&lt;/p&gt;


&lt;p&gt;Thanks to Matt Parkinson - &lt;a href=&quot;http://www.matt-parkinson.co.uk/notes/2011/lync-2010-active-directory-operation-failed-insufficient-access-rights-to-perform-this-operation/&quot;&gt;http://www.matt-parkinson.co.uk/notes/2011/lync-2010-active-directory-operation-failed-insufficient-access-rights-to-perform-this-operation/&lt;/a&gt; &lt;br /&gt;
and Exchange dude &lt;a href=&quot;http://www.exchangedude.net/index.php/2011/07/lync-control-panel-insufficient-access-rights-to-perform-the-operation/&quot;&gt;http://www.exchangedude.net/index.php/2011/07/lync-control-panel-insufficient-access-rights-to-perform-the-operation/&lt;/a&gt;  for help with this one.&lt;/p&gt;&lt;div class=&quot;item_footer&quot;&gt;&lt;p&gt;&lt;small&gt;&lt;a href=&quot;http://blog.mattsampson.net/index.php/lync-2010-active-directory-operation?blog=1&quot;&gt;Original post&lt;/a&gt; blogged on &lt;a href=&quot;http://b2evolution.net/&quot;&gt;b2evolution&lt;/a&gt;.&lt;/small&gt;&lt;/p&gt;&lt;/div&gt;</description>
			<content:encoded><![CDATA[<p><strong>Problem</strong><br />
When editing a domain administrator in the Lync control panel you may be faced with the error below once you press the commit button to save your changes.</p>

<p>&#8212;&#8211;<br />
Active Directory operation failed on &#8220;DC01.MYDOMAIN.COM". You cannot retry this operation: &#8220;Insufficient access rights to perform the operation 00002098, problem 4003 (INSUFF_ACCESS_RIGHTS), data 0&Prime;.<br />
You do not have the appropriate permissions to perform this operation in Active Directory. One possible cause is that the Lync Server Control Panel and Remote Windows PowerShell cannot modify users who belong to protected security groups (for example, the Domain Admins group). To manage users in the Domain Admins group, use the Lync Server Management Shell and log on using a Domain Admins Account. There are other possible causes. For details, see Lync Server 2010 Help.<br />
&#8212;&#8211;</p>

<p><strong>Solution</strong><br />
You have to go to Active Directory Users and Computers (with Advanced Features turned on in the View Menu), then go to Properties on the User that you can&#8217;t enable on Lync, and in the Security tab, clic on Advanced. Then check &#8220;Include Inheritable Permissions from this object&#8217;s parent", accept and the problem will be instantly solved.</p>


<p>Thanks to Matt Parkinson - <a href="http://www.matt-parkinson.co.uk/notes/2011/lync-2010-active-directory-operation-failed-insufficient-access-rights-to-perform-this-operation/">http://www.matt-parkinson.co.uk/notes/2011/lync-2010-active-directory-operation-failed-insufficient-access-rights-to-perform-this-operation/</a> <br />
and Exchange dude <a href="http://www.exchangedude.net/index.php/2011/07/lync-control-panel-insufficient-access-rights-to-perform-the-operation/">http://www.exchangedude.net/index.php/2011/07/lync-control-panel-insufficient-access-rights-to-perform-the-operation/</a>  for help with this one.</p><div class="item_footer"><p><small><a href="http://blog.mattsampson.net/index.php/lync-2010-active-directory-operation?blog=1">Original post</a> blogged on <a href="http://b2evolution.net/">b2evolution</a>.</small></p></div>]]></content:encoded>
								<comments>http://blog.mattsampson.net/index.php/lync-2010-active-directory-operation?blog=1#comments</comments>
			<wfw:commentRss>http://blog.mattsampson.net/index.php?blog=1&#38;tempskin=_rss2&#38;disp=comments&#38;p=127</wfw:commentRss>
		</item>
				<item>
			<title>Error opening EMC - WS Management Kerberos error</title>
			<link>http://blog.mattsampson.net/index.php/error-opening-emc-ws-management?blog=1</link>
			<pubDate>Wed, 04 Jan 2012 09:53:00 +0000</pubDate>			<dc:creator>admin</dc:creator>
			<category domain="main">Exchange</category>			<guid isPermaLink="false">126@http://blog.mattsampson.net/</guid>
						<description>&lt;p&gt;Tried to open the EMC this morning and was presented with the following error:&lt;/p&gt;

&lt;p&gt;The attempt to connect to mail.test.local\PowerShell using Kerberos authentication failed. The WS-management service cannot process the request. The system load quota of 1000 request per 2 seconds has been exceeded. send future request at slower rate or raise system quota.&lt;/p&gt;

&lt;p&gt;Various solutions online surrounding the registry:&lt;/p&gt;

&lt;p&gt;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;-&lt;br /&gt;
Can you check to see if the following is present in the Registy? HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ExchangeServer\v14\Cmdlet\ProvisioningCache&lt;br /&gt;
 &lt;br /&gt;
BuildThresholdCount should be a decimal value of 5.&lt;br /&gt;
 &lt;br /&gt;
If that is the case then ensure in IIS that the Default Web Site does not have any host headers configured and the IP is set to All Unassigned. This would be found in the Bindings of the Default Web Site.&lt;br /&gt;
&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;-&lt;/p&gt;

&lt;p&gt;HOWEVER, the best solution was simply to restart the IIS service on the exchange server. I.e: CMD, iisreset.&lt;br /&gt;
Could have restarted the box, but that is not a great plan with users on a production lan so wanted to find an alternative.&lt;/p&gt;&lt;div class=&quot;item_footer&quot;&gt;&lt;p&gt;&lt;small&gt;&lt;a href=&quot;http://blog.mattsampson.net/index.php/error-opening-emc-ws-management?blog=1&quot;&gt;Original post&lt;/a&gt; blogged on &lt;a href=&quot;http://b2evolution.net/&quot;&gt;b2evolution&lt;/a&gt;.&lt;/small&gt;&lt;/p&gt;&lt;/div&gt;</description>
			<content:encoded><![CDATA[<p>Tried to open the EMC this morning and was presented with the following error:</p>

<p>The attempt to connect to mail.test.local\PowerShell using Kerberos authentication failed. The WS-management service cannot process the request. The system load quota of 1000 request per 2 seconds has been exceeded. send future request at slower rate or raise system quota.</p>

<p>Various solutions online surrounding the registry:</p>

<p>&#8212;&#8212;&#8212;&#8212;-<br />
Can you check to see if the following is present in the Registy? HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ExchangeServer\v14\Cmdlet\ProvisioningCache<br />
 <br />
BuildThresholdCount should be a decimal value of 5.<br />
 <br />
If that is the case then ensure in IIS that the Default Web Site does not have any host headers configured and the IP is set to All Unassigned. This would be found in the Bindings of the Default Web Site.<br />
&#8212;&#8212;&#8212;&#8212;-</p>

<p>HOWEVER, the best solution was simply to restart the IIS service on the exchange server. I.e: CMD, iisreset.<br />
Could have restarted the box, but that is not a great plan with users on a production lan so wanted to find an alternative.</p><div class="item_footer"><p><small><a href="http://blog.mattsampson.net/index.php/error-opening-emc-ws-management?blog=1">Original post</a> blogged on <a href="http://b2evolution.net/">b2evolution</a>.</small></p></div>]]></content:encoded>
								<comments>http://blog.mattsampson.net/index.php/error-opening-emc-ws-management?blog=1#comments</comments>
			<wfw:commentRss>http://blog.mattsampson.net/index.php?blog=1&#38;tempskin=_rss2&#38;disp=comments&#38;p=126</wfw:commentRss>
		</item>
				<item>
			<title>Lync 2010 - Error connecting to "fqdnpath" while installing "MonitoringStore" database</title>
			<link>http://blog.mattsampson.net/index.php/error-connecting-to-fqdnpath-while?blog=1</link>
			<pubDate>Sat, 08 Oct 2011 11:12:00 +0000</pubDate>			<dc:creator>admin</dc:creator>
			<category domain="main">Tech Stuff</category>
<category domain="alt">Citrix ICA Client</category>			<guid isPermaLink="false">123@http://blog.mattsampson.net/</guid>
						<description>&lt;p&gt;Installing Lync 2010 in my development network I got to the point in the Setup or Remove Lync Server Components where it installs the databases.&lt;br /&gt;It runs a powershell command - Install-CSDatabase -Confirm:$false -Verbose -LocalDatabases -Report &amp;#8220;C:\Users\username\AppData\Local\Temp\Install-CSDatabase-[date][time].html&amp;#8221;&lt;/p&gt;
&lt;p&gt;However, I had enabled the Monitoring Store in the installation and the error below was displayed&amp;#8230;..&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Error: Error connecting to &amp;#8220;fqdn&amp;#8221; while installing &amp;#8220;MonitoringStore&quot;. Verify that the SQL instance is running, connections are not being blocked by a firewall, and that you have SQL administrator permissions. For details, see the following log file: &amp;#8220;C:\Users\username\AppData\Local\Temp\Create-MonitoringStore-fqdnpath-[date][time].log&amp;#8221;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&amp;#160;I tried changing this in the Topology builder, but then could&amp;#8217;nt get it to apply. (Thanks to RobMorales for solving that one) :&lt;/p&gt;
&lt;p&gt;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8211;&lt;br /&gt;In my case I choose to install the Monitoring Server, however removing it or even pointing it to a SQL server did not work it was like configuration was never refreshedand got stuck with the initial parametters. So I did the following:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Open Lync Management Shell &lt;/li&gt;
&lt;li&gt;Export Configuration from Central Management Store (&lt;strong&gt;&lt;em&gt;Export-CSConfiguration -FileName C:\Config.zip&lt;/em&gt;&lt;/strong&gt;)&lt;/li&gt;
&lt;li&gt;Import the configuration into the Local Store (&lt;strong&gt;&lt;em&gt;Import-CSConfiguration -FileName C:\Config.zip -LocalStore&lt;/em&gt;&lt;/strong&gt;)&lt;/li&gt;
&lt;li&gt;Run Setup Again &lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8211;&lt;/p&gt;
&lt;p&gt;However, the better solution for me was to get the SQL database readable by Lync.&lt;br /&gt;It was a local instance that I setup called &amp;#8220;lync-01\lyncmonitordb&quot;. I could talk to it from my desktop using Visual Studio, but not from within Lync.&lt;br /&gt;After some googling I tried the following:&lt;/p&gt;
&lt;p&gt;Open &amp;#8220;SQL Server Configuration Management&quot;&amp;#160;on the server that your DB is on,&amp;#160;expand &amp;#8220;SQL Server Network Configuration&amp;#8221; and click on &amp;#8220;Protocols for &amp;lt;lyncmonitordb&amp;gt;&quot;. &lt;br /&gt;Then&amp;#160;go to&amp;#160;Properties of TCP\IP protocol.&lt;/p&gt;
&lt;p&gt;Enable TCP\IP, and in the IP Addresses tab.&lt;br /&gt;You could&amp;#160;&amp;#160;set the port 1433 for IP address if you wanted/needed to.&lt;/p&gt;
&lt;p&gt;Restart the SQL Server instance, and try to start Setup of Archiving\Monitoring again.&lt;/p&gt;
&lt;p&gt;This worked for me.&lt;/p&gt;
&lt;p&gt;&amp;#160;&lt;/p&gt;
&lt;p&gt;&amp;#160;&lt;/p&gt;&lt;div class=&quot;item_footer&quot;&gt;&lt;p&gt;&lt;small&gt;&lt;a href=&quot;http://blog.mattsampson.net/index.php/error-connecting-to-fqdnpath-while?blog=1&quot;&gt;Original post&lt;/a&gt; blogged on &lt;a href=&quot;http://b2evolution.net/&quot;&gt;b2evolution&lt;/a&gt;.&lt;/small&gt;&lt;/p&gt;&lt;/div&gt;</description>
			<content:encoded><![CDATA[<p>Installing Lync 2010 in my development network I got to the point in the Setup or Remove Lync Server Components where it installs the databases.<br />It runs a powershell command - Install-CSDatabase -Confirm:$false -Verbose -LocalDatabases -Report &#8220;C:\Users\username\AppData\Local\Temp\Install-CSDatabase-[date][time].html&#8221;</p>
<p>However, I had enabled the Monitoring Store in the installation and the error below was displayed&#8230;..</p>
<p><em>Error: Error connecting to &#8220;fqdn&#8221; while installing &#8220;MonitoringStore". Verify that the SQL instance is running, connections are not being blocked by a firewall, and that you have SQL administrator permissions. For details, see the following log file: &#8220;C:\Users\username\AppData\Local\Temp\Create-MonitoringStore-fqdnpath-[date][time].log&#8221;</em></p>
<p>&#160;I tried changing this in the Topology builder, but then could&#8217;nt get it to apply. (Thanks to RobMorales for solving that one) :</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />In my case I choose to install the Monitoring Server, however removing it or even pointing it to a SQL server did not work it was like configuration was never refreshedand got stuck with the initial parametters. So I did the following:</p>
<ol>
<li>Open Lync Management Shell </li>
<li>Export Configuration from Central Management Store (<strong><em>Export-CSConfiguration -FileName C:\Config.zip</em></strong>)</li>
<li>Import the configuration into the Local Store (<strong><em>Import-CSConfiguration -FileName C:\Config.zip -LocalStore</em></strong>)</li>
<li>Run Setup Again </li>
</ol>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>However, the better solution for me was to get the SQL database readable by Lync.<br />It was a local instance that I setup called &#8220;lync-01\lyncmonitordb". I could talk to it from my desktop using Visual Studio, but not from within Lync.<br />After some googling I tried the following:</p>
<p>Open &#8220;SQL Server Configuration Management"&#160;on the server that your DB is on,&#160;expand &#8220;SQL Server Network Configuration&#8221; and click on &#8220;Protocols for &lt;lyncmonitordb&gt;". <br />Then&#160;go to&#160;Properties of TCP\IP protocol.</p>
<p>Enable TCP\IP, and in the IP Addresses tab.<br />You could&#160;&#160;set the port 1433 for IP address if you wanted/needed to.</p>
<p>Restart the SQL Server instance, and try to start Setup of Archiving\Monitoring again.</p>
<p>This worked for me.</p>
<p>&#160;</p>
<p>&#160;</p><div class="item_footer"><p><small><a href="http://blog.mattsampson.net/index.php/error-connecting-to-fqdnpath-while?blog=1">Original post</a> blogged on <a href="http://b2evolution.net/">b2evolution</a>.</small></p></div>]]></content:encoded>
								<comments>http://blog.mattsampson.net/index.php/error-connecting-to-fqdnpath-while?blog=1#comments</comments>
			<wfw:commentRss>http://blog.mattsampson.net/index.php?blog=1&#38;tempskin=_rss2&#38;disp=comments&#38;p=123</wfw:commentRss>
		</item>
				<item>
			<title>Exchange hogging DC's and GC's</title>
			<link>http://blog.mattsampson.net/index.php/exchange-hogging-dc-s-and?blog=1</link>
			<pubDate>Fri, 02 Sep 2011 18:57:00 +0000</pubDate>			<dc:creator>admin</dc:creator>
			<category domain="alt">Tech Stuff</category>
<category domain="alt">Server Stuff</category>
<category domain="main">Exchange</category>			<guid isPermaLink="false">122@http://blog.mattsampson.net/</guid>
						<description>&lt;p&gt;Wanted to demote a DC but exchange was hogging it and using it as the DC.&lt;br /&gt;When we disabled GC on the specific DC Exchange would fail and wouldn&amp;#8217;t restart the Microsoft Exchange Active Directory Topology Service.&lt;/p&gt;
&lt;p&gt;Tried the quick changing of the Domain controller in the GUI - &lt;br /&gt;1.Open Exchange management console&lt;br /&gt;2.Right click on &amp;#8220;organization configuration&amp;#8221; or &amp;#8220;server configuration&amp;#8221;&lt;br /&gt;3.Select &amp;#8220;modify configuration domain controller&amp;#8221;&lt;/p&gt;
&lt;p&gt;This didn&amp;#8217;t solve it as when you go to System Settings within Organization or Server area it would still show up as the old server it was using for DC and GC.&lt;br /&gt;I thought it was strange that it was only showing one server, even though there were 4 DC&amp;#8217;s all with GC enabled.&lt;/p&gt;
&lt;p&gt;However,&amp;#160; Googling further I came across a technet discussion which culminated in trying various things below:&lt;br /&gt;(&lt;a href=&quot;http://social.technet.microsoft.com/Forums/en-US/exchange2010/thread/a3076a25-3bc7-494c-ad63-94ec79c90c6c/&quot;&gt;http://social.technet.microsoft.com/Forums/en-US/exchange2010/thread/a3076a25-3bc7-494c-ad63-94ec79c90c6c/&lt;/a&gt;)&lt;/p&gt;
&lt;p&gt;On Exchange 2010&lt;br /&gt;1. Check DNS-Settings on EX2010&lt;br /&gt;2. CMD &amp;#8211;&amp;gt; nltest/DSGETDC /GC&lt;br /&gt;3. CMD &amp;#8211;&amp;gt; nltest /dsgetsite&lt;br /&gt;3. CMD &amp;#8211;&amp;gt; netdom query fsmo&lt;/p&gt;
&lt;p&gt;Global Catalog Server&lt;br /&gt;1. CMD &amp;#8211;&amp;gt; dcdiag&lt;br /&gt;2. CMD &amp;#8211;&amp;gt; nltest&lt;/p&gt;
&lt;p&gt;In the end it came down to trawling through the Event Logs.&lt;br /&gt;I came across this:&lt;/p&gt;
&lt;p&gt;Process MSEXCHANGEADTOPOLOGYSERVICE.EXE (PID=1111). &lt;br /&gt;Exchange Active Directory Provider has discovered the following servers with the following characteristics: &lt;br /&gt;(Server name | Roles | Enabled | Reachability | Synchronized | GC capable | PDC | SACL right | Critical Data | Netlogon | OS Version) &lt;br /&gt;In-site:&lt;br /&gt;DC-OLD.school.local CDG 1 7 7 1 0 1 1 7 1&lt;br /&gt;DC01.school.local&amp;#160;CDG 1 7 7 1 0 0 1 7 1&lt;br /&gt;DC02.school.local CDG 1 7 7 1 0 0 1 7 1&lt;br /&gt;DC03.school.local CDG 1 7 7 1 0 0 1 7 1&lt;/p&gt;
&lt;p&gt;Looking closely at this the SACL right was set to&amp;#160;&quot;1&amp;Prime; on the OLD DC I wanted to remove, and the&amp;#160;new DCs were set to &amp;#8220;0&amp;Prime; ZERO.&lt;br /&gt;So I read up and found that if the value is 0 then an Exchange server cannot use that GC / DC, which would explain why Exchange was not functioning when the DC-OLD server was not running as a GC.&lt;/p&gt;
&lt;p&gt;In the Default Domain Controller policy AND the Default Domain Policy under Windows Settings &amp;#8211;&amp;gt; Security Settings &amp;#8211;&amp;gt; Local Policies &amp;#8211;&amp;gt; User Rights Assignment, the policy &amp;#8220;Manage auditing and security log&amp;#8221; must have the Exchange Servers group added. This was not added in this environment. Once this was added the SACL as above changed to &amp;#8220;1&amp;Prime; and the Exchange services started correctly.&lt;/p&gt;
&lt;p&gt;Once this was set and I&amp;#8217;d done a gpupdate /force on the DCs, I could see all the DCs and GCs servers available in the Exchange GUI in Server Configuration Properties -&amp;gt; System Settings. Whereas before it was only showing one server - the only one where SACL was set to &amp;#8220;1&amp;Prime;.&lt;/p&gt;
&lt;p&gt;If you don&amp;#8217;t have a Default Domain Controller Policy or a Default Domain Policy - WHY NOT!!!!&lt;br /&gt;If you still don&amp;#8217;t have one, then you can simply create a policy called &amp;#8220;Exchange SACL Rights&amp;#8221; and set the Manage auditing and security log settings as the single use for this policy, set it to authenticated users and domain computers and put it as enforced at the top root of your AD tree.&lt;/p&gt;
&lt;p&gt;&amp;#160;&lt;/p&gt;
&lt;p&gt;Experts Exchange was very helpful with solving this one, as was this spiceworks discussion (&lt;a href=&quot;http://community.spiceworks.com/topic/134941-exchange-2010-ad-topology-failures-all-domain-controllers-unavailable?page=1&quot;&gt;http://community.spiceworks.com/topic/134941-exchange-2010-ad-topology-failures-all-domain-controllers-unavailable?page=1&lt;/a&gt;)&lt;/p&gt;&lt;div class=&quot;item_footer&quot;&gt;&lt;p&gt;&lt;small&gt;&lt;a href=&quot;http://blog.mattsampson.net/index.php/exchange-hogging-dc-s-and?blog=1&quot;&gt;Original post&lt;/a&gt; blogged on &lt;a href=&quot;http://b2evolution.net/&quot;&gt;b2evolution&lt;/a&gt;.&lt;/small&gt;&lt;/p&gt;&lt;/div&gt;</description>
			<content:encoded><![CDATA[<p>Wanted to demote a DC but exchange was hogging it and using it as the DC.<br />When we disabled GC on the specific DC Exchange would fail and wouldn&#8217;t restart the Microsoft Exchange Active Directory Topology Service.</p>
<p>Tried the quick changing of the Domain controller in the GUI - <br />1.Open Exchange management console<br />2.Right click on &#8220;organization configuration&#8221; or &#8220;server configuration&#8221;<br />3.Select &#8220;modify configuration domain controller&#8221;</p>
<p>This didn&#8217;t solve it as when you go to System Settings within Organization or Server area it would still show up as the old server it was using for DC and GC.<br />I thought it was strange that it was only showing one server, even though there were 4 DC&#8217;s all with GC enabled.</p>
<p>However,&#160; Googling further I came across a technet discussion which culminated in trying various things below:<br />(<a href="http://social.technet.microsoft.com/Forums/en-US/exchange2010/thread/a3076a25-3bc7-494c-ad63-94ec79c90c6c/">http://social.technet.microsoft.com/Forums/en-US/exchange2010/thread/a3076a25-3bc7-494c-ad63-94ec79c90c6c/</a>)</p>
<p>On Exchange 2010<br />1. Check DNS-Settings on EX2010<br />2. CMD &#8211;&gt; nltest/DSGETDC /GC<br />3. CMD &#8211;&gt; nltest /dsgetsite<br />3. CMD &#8211;&gt; netdom query fsmo</p>
<p>Global Catalog Server<br />1. CMD &#8211;&gt; dcdiag<br />2. CMD &#8211;&gt; nltest</p>
<p>In the end it came down to trawling through the Event Logs.<br />I came across this:</p>
<p>Process MSEXCHANGEADTOPOLOGYSERVICE.EXE (PID=1111). <br />Exchange Active Directory Provider has discovered the following servers with the following characteristics: <br />(Server name | Roles | Enabled | Reachability | Synchronized | GC capable | PDC | SACL right | Critical Data | Netlogon | OS Version) <br />In-site:<br />DC-OLD.school.local CDG 1 7 7 1 0 1 1 7 1<br />DC01.school.local&#160;CDG 1 7 7 1 0 0 1 7 1<br />DC02.school.local CDG 1 7 7 1 0 0 1 7 1<br />DC03.school.local CDG 1 7 7 1 0 0 1 7 1</p>
<p>Looking closely at this the SACL right was set to&#160;"1&Prime; on the OLD DC I wanted to remove, and the&#160;new DCs were set to &#8220;0&Prime; ZERO.<br />So I read up and found that if the value is 0 then an Exchange server cannot use that GC / DC, which would explain why Exchange was not functioning when the DC-OLD server was not running as a GC.</p>
<p>In the Default Domain Controller policy AND the Default Domain Policy under Windows Settings &#8211;&gt; Security Settings &#8211;&gt; Local Policies &#8211;&gt; User Rights Assignment, the policy &#8220;Manage auditing and security log&#8221; must have the Exchange Servers group added. This was not added in this environment. Once this was added the SACL as above changed to &#8220;1&Prime; and the Exchange services started correctly.</p>
<p>Once this was set and I&#8217;d done a gpupdate /force on the DCs, I could see all the DCs and GCs servers available in the Exchange GUI in Server Configuration Properties -&gt; System Settings. Whereas before it was only showing one server - the only one where SACL was set to &#8220;1&Prime;.</p>
<p>If you don&#8217;t have a Default Domain Controller Policy or a Default Domain Policy - WHY NOT!!!!<br />If you still don&#8217;t have one, then you can simply create a policy called &#8220;Exchange SACL Rights&#8221; and set the Manage auditing and security log settings as the single use for this policy, set it to authenticated users and domain computers and put it as enforced at the top root of your AD tree.</p>
<p>&#160;</p>
<p>Experts Exchange was very helpful with solving this one, as was this spiceworks discussion (<a href="http://community.spiceworks.com/topic/134941-exchange-2010-ad-topology-failures-all-domain-controllers-unavailable?page=1">http://community.spiceworks.com/topic/134941-exchange-2010-ad-topology-failures-all-domain-controllers-unavailable?page=1</a>)</p><div class="item_footer"><p><small><a href="http://blog.mattsampson.net/index.php/exchange-hogging-dc-s-and?blog=1">Original post</a> blogged on <a href="http://b2evolution.net/">b2evolution</a>.</small></p></div>]]></content:encoded>
								<comments>http://blog.mattsampson.net/index.php/exchange-hogging-dc-s-and?blog=1#comments</comments>
			<wfw:commentRss>http://blog.mattsampson.net/index.php?blog=1&#38;tempskin=_rss2&#38;disp=comments&#38;p=122</wfw:commentRss>
		</item>
				<item>
			<title>ActiveSync issues with iPhone &#38; Exchange 2010</title>
			<link>http://blog.mattsampson.net/index.php/activesync-issues-with-iphone-3gs?blog=1</link>
			<pubDate>Wed, 17 Aug 2011 16:27:00 +0000</pubDate>			<dc:creator>admin</dc:creator>
			<category domain="alt">Tech Stuff</category>
<category domain="alt">Server Stuff</category>
<category domain="main">Exchange</category>			<guid isPermaLink="false">121@http://blog.mattsampson.net/</guid>
						<description>&lt;div&gt;Unable to sync with my iPhone 3Gs - seems to be a permissions issue ?&lt;/div&gt;
&lt;div&gt;Log Name: Application&lt;/div&gt;
&lt;div&gt;Source: MSExchange ActiveSync&lt;/div&gt;
&lt;div&gt;Date: 14/03/2011 14:31:29&lt;/div&gt;
&lt;div&gt;Event ID: 1053&lt;/div&gt;
&lt;div&gt;Task Category: Configuration&lt;/div&gt;
&lt;div&gt;Level: Error&lt;/div&gt;
&lt;div&gt;Keywords: Classic&lt;/div&gt;
&lt;div&gt;User: N/A&lt;/div&gt;
&lt;div&gt;Computer: mail-01.test.local&lt;/div&gt;
&lt;div&gt;Description:&lt;/div&gt;
&lt;div&gt;The Exchange ActiveSync doesn&amp;#8217;t have enough permissions to create &amp;#8220;CN=Matt,OU=Users,DC=test,DC=local&amp;#8221; container under AD user &amp;#8220;Active Directory operation failed on&amp;#160;dc-01.test.local This error is not retriable. Additional information: Access is denied.&lt;/div&gt;
&lt;div&gt;Active directory response: 00000005: SecErr: DSID-03152492, problem 4003 (INSUFF_ACCESS_RIGHTS), data 0&lt;/div&gt;
&lt;div&gt;&amp;#8220;.&lt;/div&gt;
&lt;div&gt;Make sure the user has inherited permission granted to domain\Exchange Servers to allow List, Create child, Delete child of object type &amp;#8220;msExchangeActiveSyncDevices&amp;#8221; and doesn&amp;#8217;t have any deny permissions blocking such operartions.&lt;/div&gt;
&lt;div&gt;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;-&lt;/div&gt;
&lt;div&gt;&lt;strong&gt;Answer!&lt;/strong&gt;&lt;/div&gt;
&lt;div&gt;Bring up Properties/Security of the user account, click on Advanced and enable the checkbox &amp;#8220;Include inheritable permissions from this object&amp;#8217;s parent&amp;#8221;&lt;/div&gt;
&lt;div&gt;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;&amp;#8212;-&lt;/div&gt;
&lt;div&gt;Sourced from:&amp;#160; &lt;a href=&quot;http://social.technet.microsoft.com/Forums/en/exchange2010/thread/37a1cb86-d4e3-4851-b41b-f8e42997dd6c&quot;&gt;http://social.technet.microsoft.com/Forums/en/exchange2010/thread/37a1cb86-d4e3-4851-b41b-f8e42997dd6c&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;item_footer&quot;&gt;&lt;p&gt;&lt;small&gt;&lt;a href=&quot;http://blog.mattsampson.net/index.php/activesync-issues-with-iphone-3gs?blog=1&quot;&gt;Original post&lt;/a&gt; blogged on &lt;a href=&quot;http://b2evolution.net/&quot;&gt;b2evolution&lt;/a&gt;.&lt;/small&gt;&lt;/p&gt;&lt;/div&gt;</description>
			<content:encoded><![CDATA[<div>Unable to sync with my iPhone 3Gs - seems to be a permissions issue ?</div>
<div>Log Name: Application</div>
<div>Source: MSExchange ActiveSync</div>
<div>Date: 14/03/2011 14:31:29</div>
<div>Event ID: 1053</div>
<div>Task Category: Configuration</div>
<div>Level: Error</div>
<div>Keywords: Classic</div>
<div>User: N/A</div>
<div>Computer: mail-01.test.local</div>
<div>Description:</div>
<div>The Exchange ActiveSync doesn&#8217;t have enough permissions to create &#8220;CN=Matt,OU=Users,DC=test,DC=local&#8221; container under AD user &#8220;Active Directory operation failed on&#160;dc-01.test.local This error is not retriable. Additional information: Access is denied.</div>
<div>Active directory response: 00000005: SecErr: DSID-03152492, problem 4003 (INSUFF_ACCESS_RIGHTS), data 0</div>
<div>&#8220;.</div>
<div>Make sure the user has inherited permission granted to domain\Exchange Servers to allow List, Create child, Delete child of object type &#8220;msExchangeActiveSyncDevices&#8221; and doesn&#8217;t have any deny permissions blocking such operartions.</div>
<div>&#8212;&#8212;&#8212;&#8212;&#8212;-</div>
<div><strong>Answer!</strong></div>
<div>Bring up Properties/Security of the user account, click on Advanced and enable the checkbox &#8220;Include inheritable permissions from this object&#8217;s parent&#8221;</div>
<div>&#8212;&#8212;&#8212;&#8212;&#8212;-</div>
<div>Sourced from:&#160; <a href="http://social.technet.microsoft.com/Forums/en/exchange2010/thread/37a1cb86-d4e3-4851-b41b-f8e42997dd6c">http://social.technet.microsoft.com/Forums/en/exchange2010/thread/37a1cb86-d4e3-4851-b41b-f8e42997dd6c</a></div><div class="item_footer"><p><small><a href="http://blog.mattsampson.net/index.php/activesync-issues-with-iphone-3gs?blog=1">Original post</a> blogged on <a href="http://b2evolution.net/">b2evolution</a>.</small></p></div>]]></content:encoded>
								<comments>http://blog.mattsampson.net/index.php/activesync-issues-with-iphone-3gs?blog=1#comments</comments>
			<wfw:commentRss>http://blog.mattsampson.net/index.php?blog=1&#38;tempskin=_rss2&#38;disp=comments&#38;p=121</wfw:commentRss>
		</item>
				<item>
			<title>List of Powershell Commands and what tasks they perform</title>
			<link>http://blog.mattsampson.net/index.php/list-of-powershell-commands-and-what-tasks-they-perform?blog=1</link>
			<pubDate>Sun, 14 Aug 2011 19:00:43 +0000</pubDate>			<dc:creator>admin</dc:creator>
			<category domain="main">Tech Stuff</category>
<category domain="alt">Sharepoint (MOSS)</category>
<category domain="alt">Server Stuff</category>
<category domain="alt">Exchange</category>
<category domain="alt">IIS</category>			<guid isPermaLink="false">120@http://blog.mattsampson.net/</guid>
						<description>&lt;p&gt;&lt;a href=&quot;http://www.techieshelp.com/powershell-commands-and-what-they-do/&quot;&gt;http://www.techieshelp.com/powershell-commands-and-what-they-do/ &lt;/a&gt;&lt;/p&gt;&lt;div class=&quot;item_footer&quot;&gt;&lt;p&gt;&lt;small&gt;&lt;a href=&quot;http://blog.mattsampson.net/index.php/list-of-powershell-commands-and-what-tasks-they-perform?blog=1&quot;&gt;Original post&lt;/a&gt; blogged on &lt;a href=&quot;http://b2evolution.net/&quot;&gt;b2evolution&lt;/a&gt;.&lt;/small&gt;&lt;/p&gt;&lt;/div&gt;</description>
			<content:encoded><![CDATA[<p><a href="http://www.techieshelp.com/powershell-commands-and-what-they-do/">http://www.techieshelp.com/powershell-commands-and-what-they-do/ </a></p><div class="item_footer"><p><small><a href="http://blog.mattsampson.net/index.php/list-of-powershell-commands-and-what-tasks-they-perform?blog=1">Original post</a> blogged on <a href="http://b2evolution.net/">b2evolution</a>.</small></p></div>]]></content:encoded>
								<comments>http://blog.mattsampson.net/index.php/list-of-powershell-commands-and-what-tasks-they-perform?blog=1#comments</comments>
			<wfw:commentRss>http://blog.mattsampson.net/index.php?blog=1&#38;tempskin=_rss2&#38;disp=comments&#38;p=120</wfw:commentRss>
		</item>
				<item>
			<title>How to setup a Routing Group Connector between Exchange 2003 and 2010</title>
			<link>http://blog.mattsampson.net/index.php/how-to-setup-a-routing-group-connector-between-exchange-2003-and-2010?blog=1</link>
			<pubDate>Sun, 14 Aug 2011 18:58:42 +0000</pubDate>			<dc:creator>admin</dc:creator>
			<category domain="alt">Tech Stuff</category>
<category domain="alt">Server Stuff</category>
<category domain="main">Exchange</category>			<guid isPermaLink="false">119@http://blog.mattsampson.net/</guid>
						<description>&lt;p&gt;I recently had to add an exchange 2010 server into a 2003 organization. As part of the installation a routing group connector is created but for some reason it was not created correctly created. Here is how to create a routing group connector in powershell from exchange 2003 to exchange 2010.&lt;/p&gt;

&lt;p&gt;I wasn&amp;#8217;t quite sure what routes were setup automatically, so to find this out:&lt;br /&gt;
On the Exchange 2010 server, go into the Exchange Powershell.&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;NOTE: This is different from Windows Powershell.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;Type: &lt;em&gt;Get-RoutingGroupConnector&lt;/em&gt;&lt;br /&gt;
This will show you all the routing groups setup in your Exchange system.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;To setup a new one:&lt;/strong&gt;&lt;br /&gt;
Then copy and paste the code below into the command line within powershell.&lt;br /&gt;
Change the names though!&lt;/p&gt;

&lt;p&gt;&lt;em&gt;New-RoutingGroupConnector -Name &amp;#8220;Exchange RGC&amp;#8221; -SourceTransportServers &amp;#8220;Ex2010Hub1.contoso.com&amp;#8221; -TargetTransportServers &amp;#8220;Ex2003BH1.contoso.com&amp;#8221; -Cost 10 -Bidirectional $true -PublicFolderReferralsEnabled $true&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;We&amp;#8217;ve asked here to create a bidirectional route between these servers, so two routes will be created.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;To Remove the routing group:&lt;/strong&gt;&lt;br /&gt;
Check to see what the name of the RGC you want to delete first:  &lt;em&gt;Get-RoutingGroupConnector&lt;/em&gt;&lt;br /&gt;
Then use that to delete the connector.&lt;br /&gt;
&lt;em&gt;remove-routinggroupconnector -identity &amp;#8220;Exchange RGC&amp;#8221;&lt;/em&gt;&lt;/p&gt;&lt;div class=&quot;item_footer&quot;&gt;&lt;p&gt;&lt;small&gt;&lt;a href=&quot;http://blog.mattsampson.net/index.php/how-to-setup-a-routing-group-connector-between-exchange-2003-and-2010?blog=1&quot;&gt;Original post&lt;/a&gt; blogged on &lt;a href=&quot;http://b2evolution.net/&quot;&gt;b2evolution&lt;/a&gt;.&lt;/small&gt;&lt;/p&gt;&lt;/div&gt;</description>
			<content:encoded><![CDATA[<p>I recently had to add an exchange 2010 server into a 2003 organization. As part of the installation a routing group connector is created but for some reason it was not created correctly created. Here is how to create a routing group connector in powershell from exchange 2003 to exchange 2010.</p>

<p>I wasn&#8217;t quite sure what routes were setup automatically, so to find this out:<br />
On the Exchange 2010 server, go into the Exchange Powershell.</p>
<blockquote><p>NOTE: This is different from Windows Powershell.</p></blockquote>
<p>Type: <em>Get-RoutingGroupConnector</em><br />
This will show you all the routing groups setup in your Exchange system.</p>

<p><strong>To setup a new one:</strong><br />
Then copy and paste the code below into the command line within powershell.<br />
Change the names though!</p>

<p><em>New-RoutingGroupConnector -Name &#8220;Exchange RGC&#8221; -SourceTransportServers &#8220;Ex2010Hub1.contoso.com&#8221; -TargetTransportServers &#8220;Ex2003BH1.contoso.com&#8221; -Cost 10 -Bidirectional $true -PublicFolderReferralsEnabled $true</em></p>

<p>We&#8217;ve asked here to create a bidirectional route between these servers, so two routes will be created.</p>

<p><strong>To Remove the routing group:</strong><br />
Check to see what the name of the RGC you want to delete first:  <em>Get-RoutingGroupConnector</em><br />
Then use that to delete the connector.<br />
<em>remove-routinggroupconnector -identity &#8220;Exchange RGC&#8221;</em></p><div class="item_footer"><p><small><a href="http://blog.mattsampson.net/index.php/how-to-setup-a-routing-group-connector-between-exchange-2003-and-2010?blog=1">Original post</a> blogged on <a href="http://b2evolution.net/">b2evolution</a>.</small></p></div>]]></content:encoded>
								<comments>http://blog.mattsampson.net/index.php/how-to-setup-a-routing-group-connector-between-exchange-2003-and-2010?blog=1#comments</comments>
			<wfw:commentRss>http://blog.mattsampson.net/index.php?blog=1&#38;tempskin=_rss2&#38;disp=comments&#38;p=119</wfw:commentRss>
		</item>
				<item>
			<title>A configuration error in the e-mail system caused the message to bounce between two servers or to be forwarded between two recipients.</title>
			<link>http://blog.mattsampson.net/index.php/a-configuration-error-in-the-e-mail-system-caused-the-message-to-bounce-between-two-servers-or-to-be-forwarded-between-two-recipients?blog=1</link>
			<pubDate>Sun, 14 Aug 2011 18:48:40 +0000</pubDate>			<dc:creator>admin</dc:creator>
			<category domain="alt">Tech Stuff</category>
<category domain="alt">Server Stuff</category>
<category domain="main">Exchange</category>			<guid isPermaLink="false">118@http://blog.mattsampson.net/</guid>
						<description>&lt;p&gt;Setting up Exchange 2003 to Migrate to Exchange 2010.&lt;br /&gt;
Routing group setup by Exchange 2010 install.&lt;br /&gt;
Messages sent between servers come up as:&lt;/p&gt;


&lt;blockquote&gt;&lt;p&gt;Your message did not reach some or all of the intended recipients. Subject: s1 Sent: 12/02/2011 18:21 The following recipient(s) could not be reached: &lt;/p&gt;

&lt;p&gt;  testuser on 12/02/2011 18:22&lt;br /&gt;
  A configuration error in the e-mail system caused the message to bounce between two servers or to be forwarded between two recipients. Contact your administrator.&lt;br /&gt;
  exch03.testdomain.local #5.3.5 &lt;/p&gt;&lt;/blockquote&gt;

&lt;p&gt;This was caused because both servers had an SMTP connector to the web, which is fine in some circumstances, however both these servers were using DNS to send MX records rather than using a smarthost.&lt;/p&gt;

&lt;p&gt;To resolve this issue, follow these steps:&lt;/p&gt;

&lt;p&gt; 1. Start Exchange System Manager, and then expand the Connectors container.&lt;/p&gt;

&lt;blockquote&gt;&lt;p&gt;Note By default, the SMTP connector is named &amp;#8220;SmallBusiness SMTP Connector&amp;#8221; in Small Business Server 2000 and Windows Small Business Server 2003. If you created an SMTP connector, the connector may not have this name. In this case, select the named SMTP connector instead.&lt;/p&gt;&lt;/blockquote&gt;

&lt;p&gt; 2. Right-click SmallBusiness SMTP Connector, and then click Properties.&lt;br /&gt;
 3. On the General tab, click either Use DNS to route to each address space on this connector or Forward all mail through this connector to the following smart hosts.&lt;br /&gt;
 4. If you click Forward all mail through this connector to the following smart hosts, verify the following items:&lt;/p&gt;

&lt;p&gt;Make sure that smart host or hosts that appear in the window are those that are authorized by the Internet service provider (ISP) to relay mail for the Exchange Server e-mail domain. The smart hosts may be listed by fully qualified domain name (such as mailserver.domain.net) or by IP address.&lt;br /&gt;
Verify the accuracy of the fully qualified domain names (FQDNs) or IP addresses with the ISP.&lt;br /&gt;
Make sure that the smart hosts do not include the Exchange Server FQDN, its public IP address, or its private IP address.&lt;/p&gt;



&lt;p&gt;Another way to solve this in the Exchange 2003 System Manager is to:&lt;/p&gt;

&lt;p&gt;1. In the properties of routing connectors select option &amp;#8220;Any local server can send email over this connector&amp;#8221;&lt;br /&gt;
2. In the properties of SMTP Virtual Server, change IP from &amp;#8220;All Unassigned&amp;#8221; to current IP address.&lt;/p&gt;


&lt;p&gt;Helpful websites:&lt;/p&gt;

&lt;p&gt; - &lt;a href=&quot;http://support.microsoft.com/kb/326304&quot;&gt;http://support.microsoft.com/kb/326304&lt;/a&gt; &lt;br /&gt;
 - &lt;a href=&quot;http://www.petri.co.il/forums/showthread.php?t=7285&quot;&gt;http://www.petri.co.il/forums/showthread.php?t=7285&lt;/a&gt;&lt;/p&gt;&lt;div class=&quot;item_footer&quot;&gt;&lt;p&gt;&lt;small&gt;&lt;a href=&quot;http://blog.mattsampson.net/index.php/a-configuration-error-in-the-e-mail-system-caused-the-message-to-bounce-between-two-servers-or-to-be-forwarded-between-two-recipients?blog=1&quot;&gt;Original post&lt;/a&gt; blogged on &lt;a href=&quot;http://b2evolution.net/&quot;&gt;b2evolution&lt;/a&gt;.&lt;/small&gt;&lt;/p&gt;&lt;/div&gt;</description>
			<content:encoded><![CDATA[<p>Setting up Exchange 2003 to Migrate to Exchange 2010.<br />
Routing group setup by Exchange 2010 install.<br />
Messages sent between servers come up as:</p>


<blockquote><p>Your message did not reach some or all of the intended recipients. Subject: s1 Sent: 12/02/2011 18:21 The following recipient(s) could not be reached: </p>

<p>  testuser on 12/02/2011 18:22<br />
  A configuration error in the e-mail system caused the message to bounce between two servers or to be forwarded between two recipients. Contact your administrator.<br />
  exch03.testdomain.local #5.3.5 </p></blockquote>

<p>This was caused because both servers had an SMTP connector to the web, which is fine in some circumstances, however both these servers were using DNS to send MX records rather than using a smarthost.</p>

<p>To resolve this issue, follow these steps:</p>

<p> 1. Start Exchange System Manager, and then expand the Connectors container.</p>

<blockquote><p>Note By default, the SMTP connector is named &#8220;SmallBusiness SMTP Connector&#8221; in Small Business Server 2000 and Windows Small Business Server 2003. If you created an SMTP connector, the connector may not have this name. In this case, select the named SMTP connector instead.</p></blockquote>

<p> 2. Right-click SmallBusiness SMTP Connector, and then click Properties.<br />
 3. On the General tab, click either Use DNS to route to each address space on this connector or Forward all mail through this connector to the following smart hosts.<br />
 4. If you click Forward all mail through this connector to the following smart hosts, verify the following items:</p>

<p>Make sure that smart host or hosts that appear in the window are those that are authorized by the Internet service provider (ISP) to relay mail for the Exchange Server e-mail domain. The smart hosts may be listed by fully qualified domain name (such as mailserver.domain.net) or by IP address.<br />
Verify the accuracy of the fully qualified domain names (FQDNs) or IP addresses with the ISP.<br />
Make sure that the smart hosts do not include the Exchange Server FQDN, its public IP address, or its private IP address.</p>



<p>Another way to solve this in the Exchange 2003 System Manager is to:</p>

<p>1. In the properties of routing connectors select option &#8220;Any local server can send email over this connector&#8221;<br />
2. In the properties of SMTP Virtual Server, change IP from &#8220;All Unassigned&#8221; to current IP address.</p>


<p>Helpful websites:</p>

<p> - <a href="http://support.microsoft.com/kb/326304">http://support.microsoft.com/kb/326304</a> <br />
 - <a href="http://www.petri.co.il/forums/showthread.php?t=7285">http://www.petri.co.il/forums/showthread.php?t=7285</a></p><div class="item_footer"><p><small><a href="http://blog.mattsampson.net/index.php/a-configuration-error-in-the-e-mail-system-caused-the-message-to-bounce-between-two-servers-or-to-be-forwarded-between-two-recipients?blog=1">Original post</a> blogged on <a href="http://b2evolution.net/">b2evolution</a>.</small></p></div>]]></content:encoded>
								<comments>http://blog.mattsampson.net/index.php/a-configuration-error-in-the-e-mail-system-caused-the-message-to-bounce-between-two-servers-or-to-be-forwarded-between-two-recipients?blog=1#comments</comments>
			<wfw:commentRss>http://blog.mattsampson.net/index.php?blog=1&#38;tempskin=_rss2&#38;disp=comments&#38;p=118</wfw:commentRss>
		</item>
			</channel>
</rss>

