Showing posts with label ActiveSync. Show all posts
Showing posts with label ActiveSync. Show all posts

Friday, 9 October 2015

Apply Activesync Policies to Exchange Online Mailboxes synchronisation script

A few months back I published details of my On-Premise Activesync Mailbox Policy to Exchange Online synchronisation script (it's also available to download in the Technet Gallery).

This allowed you to simply and easily copy your existing Activesync policies to your Exchange Online tenant in Office 365 rather than having to setup them up again. This was always very useful in a perpetual Hybrid environment where co-existence may be ultimately permanent, or indeed if you're just simply migrating all users and removing your Exchange on premise presence.

I am pleased to announce the next release today, ApplyEASMailboxPolicy2EXO.ps1.

This script will take your on premise users Activesync Mailbox Policy that is assigned to them, and then apply the policy once the user has been moved in a Cutover, Staged, Hybrid or third party migration to Exchange Online.

It will also check to see if the user actually has Activesync enabled, if the user is disabled, it will disable it for their Exchange Online mailbox also.

This simplifies mobile device access in a Mobile First, Cloud First Office 365 engagement.


If you are performing a 'Cutover' migration, either natively or using third party tools (you are moving all mailboxes to Exchange Online at once) simply run the script. If this is more than 1000 users you can specify a higher setting with the –ResultSize switch parameter.

If you are performing a 'Staged' migration, or moving select mailboxes in a Hybrid state or indeed select mailboxes with a third party, then you can pipe a csv file with the users that have moved using the –Staged switch parameter.

I'll run you through both scenarios.


Cutover

So first of all let's look at the Activesync Mailbox Policy applied to the users on premise. We can see that each user has a specific policy and that infact 'New User 3' has Activesync disabled.

Let's look in Exchange Online as we have just performed a Cutover Migration – all users should have the Default policy applied and be enabled for Activesync.

Ok so let's start running the script. We have already created the Activesync Mailbox Policies using my previous script here Open a PS window and run the PS1 script.


The accompanying text will explain the switches to you. As this is a Cutover (you have moved all users at once) we simply press Y to proceed.


It will now do two things. The first thing it will do is gather which Activesync Policy is applied to your on premise users. It will collate the information into a locally saved CSV file that will be created in the same location the PS1 file is run from.
Once this has been collected it will then ask for your Office 365 tenants admin credentials. Enter an account that has the necessary Exchange permissions.


It will then import the configuration file, inform you of the total number of mailboxes to configure, and start configuring your Exchange Online mailboxes.
Once it has completed, it will inform you and then disconnect your Exchange Online PS session.

It will then inform you that you can then close the PS window.

So let's look at them in Exchange Online. Has the change been implemented? You bet!


Staged

So what happens if you aren't moving all mailboxes at once? For example a staged migration? Well you can input a CSV of the mailboxes you have moved into the script. Let's take a look.
Run the script with the –Staged parameter and specify your CSV.

Specify Yes to continue.

You will this time be asked for your Staged migration CSV file.

Enter your CSV path, note that you can enter multiples if you so wish, to finish simply press Enter without adding another CSV.

Once it has informed you it has ingested the CSV file it will then make a connection to Exchange Online. Enter your tenant admin credentials with relevant Exchange Online permissions.

It will now make the connection to Exchange Online and perform the necessary changes on those specific mailboxes. Note that this time it says there's only 2 mailboxes to change. That is because only 2 mailboxes were in my staged CSV file.


And that's it! All done!


You can download the script from Technet Gallery.

It has been tested with Exchange 2007, 2010, 2013 and 2016.


Enjoy and take care,

Oliver Moazzezi – MVP Exchange Server
Twitter: @Olivermoazzezi



Monday, 1 June 2015

ActiveSync Mailbox Policy to Exchange Online synchronisation script


When moving to Office 365 you haven't just got the mailbox data to worry about, but also a variety of other issues like ensuring your on premise configuration and policies are understood and carried over to Exchange Online.
In a Cutover, Staged, Hybrid or third party migration you may want to prep many policies prior to moving the first mailbox to Office 365.
One of the policies you may want to configure prior to moving the first mailbox is Activesync Mailbox Policies. If you have many policies, auditing them and then creating them in Office 365 can be a time consuming task. Luckily I have written a script to help with this.
The script will do the following actions:
Check to see if any of your policies has a null field for the password device length. This should be between 1 and 16. If any are indeed null the script will inform you the policies that are at fault and halt
Export all of your Activesync Mailbox policies (including your default policy if you include –ModifyDefaultPolicy) – it will create local files from where the ps1 file is run from
Connect to Exchange Online in the powershell session (it will prompt for username and password)
Create all Activesync Mailbox policies with the on premises names and configuration settings
Clean up any local files it created when performing the export process
Disconnect any powershell sessions it has open
Inform you the process has completed successfully.
The script works well, but it is designed to be used prior to moving the first mailboxes, not that it will cause an issue if it is ran later than that of course, but because an Administrator may have already started to make changes or even set up policies using the same names as the on premise ones.
If you do run into this condition it will simply fail on creating that policy, similarly if you run the script again it will complete successfully but will fail on creating new policies as they are already created.
If you have decided to include the –ModifyDefaultPolicy switch it will also gather your default policy settings and then export them and configure the existing Office 365 default policy with the settings it has exported.
Let's take a look at it in action. Logging onto my new Office 365 tenant I can see I just have the default policy with default out of the box settings:



If I look at my on premise configuration you can see I have multiple Activesync Mailbox policies in use:



Each policy has different configuration settings. You can see in the Office 365 EAC my default policy is set with default settings and doesn't require a password. However my on premise default policy does with a minimum password length of 6 characters:



I have opened a Powershell session and I will run .\ImportEASPolicies2EXO.ps1 –ModifyDefaultPolicy



It will first check to see if there are any policies with an incorrect, or null, password length and advise you of them:



Providing that is fine, it will continue and export the on premise policies before making a connection to Exchange Online. It will prompt for your tenant credentials:





Once connected it will start creating the policies, and modify the default policy if you selected to do this (like I am in my example):




Once completed you can close the window. It will disconnect any PS Sessions it has created and also clean up any files created during the process.



So let's take a look back in the Office 365 tenant EAC



You can see the policies have been created and the Default policy has been modified successfully.
Once the *-ActivesyncMailboxPolicy cmdlets no longer work I will update the script to a version 2 making use of *-MobileDeviceMailboxPolicy. But this won't be for some time.
Until that time using the older cmdlet makes things easier.
You can grab the script HERE.
Have fun!


Oliver Moazzezi – MVP Exchange Server
Twitter: @Olivermoazzezi


Wednesday, 15 July 2009

Nokia N97 review - ActiveSync, Applications and you can make calls too.

So everyone is drinking the iPhone koolaid, I even have an Apple iPod - but traditionally i've always gone for Nokia phones. Notably I love the Symbian OS and the fact you can install Apps on your mobile from any Developer.

Choosing my new phone has been no different, except I have read wildy varied reviews on the Nokia N97 - but I still decided to take the plunge.

After using it for 24 hours I am seriously impressed. Activesync works like a charm - and Administrator enforced Mobile policies are enforced - for example I had to agree to put a 5 digit lock code with 15 minute timeout on my N97 (forced from policy) before I could sync. Sync'ing in the latest release of Mail for Exchange is great and all bugs from previous versions appear to have been ironed out. You still cannot see other folders than your inbox but hopefully this will be resolved in a future update.

I haven't got a Symbian S60 emulator so if you need detailed instructions on setting up your N97 check:

http://blog.brightpointuk.co.uk/setting-mail-exchange-nokia-n97


I should also note that the N97 version of Activesync supports Autodiscover so it can grab all your Activesync details and you just need to enter your username and password.

There are some other useful default Apps too.

Qik - this allows you to stream video from your mobile in real time over the Internet, very very cool.

BBC iPlayer - again very cool, catch up on missed TV on this App designed for the N97.

Facebook - again honed for the Nokia phone. I found it particularly interested you can snap a pic when in the Applications and immediately tag, name and then upload into a photo album of your choice. Great feature.

Nokia appears to be countering the iTunes store with Ovi.

Ovi has a great intuitive 'App bar' across the top of the screen that allows you to swipe your finger and move through Recommened, Games, Audio and Video and Personal.

It obviously hasn't got the pace or support of iTunes yet but it appears to be trying hard to do just that.

The ultimate feature is that the N97 can be used as a VOIP phone, with full SIP connectivity support, you could use it as an OCS phone and really work from anywhere!


Oliver Moazzezi

MVP - Exchange Server

Friday, 15 May 2009

ActiveSync (beta) for Andriod HTC Magic

If you have bought a HTC Magic or HTC Dream you can get a free beta ActiveSync client from http://www.dataviz.com/products/roadsync/android/.

You get Push email with HTML formatting, calendarand contact synchronisation including caller photo ID integration.

For the security conscious a remote wipe can be initiated from Exchange Server should the device go missing. The beta ends on 30 May 2009

Daniel
twitter.com/dannoakes