Monday, November 30, 2015

New Functionality of AD-RMS in Windows Server 2012

New Functionality of AD-RMS in Windows Server 2012


Hello Friends, I am back with one of my article on AD-RMS enhancements in Windows Server 2012. I hope you like my articles, so I request you kindly subscribe my blog and leave your valuable comments so I can improve required changes in my new articles.

Microsoft made significant changes to AD RMS in Windows Server 2012. These changes included an updated set of SQL Server requirements, Server Core support, a remote deployment option and an option to deploy with powershell commands.
For Windows Server 2012, AD RMS now has the following requirements for access to SQL Server.
  • The AD RMS installer account must have sysadmin permissions in the SQL Server installation.
  • The SQL Server Browser service must be running to locate available SQL instances.
  • Firewall exceptions should be enabled on the SQL server computer for ports that will be used by AD RMS setup. The TCP port for the SQL instance that will host the AD RMS databases should be enabled. The UDP port for the SQL Server Browser service should also be enabled. For example, the default ports are usually TCP port 1433 for the SQL Server instance and UDP port 1434 for the SQL Server Browser service.
In addition to the previous access requirements, for Windows Server 2012 the following versions of Microsoft SQL Server have been tested and are supported for use with AD RMS deployment.
  • SQL Server 2005 Service Pack 3
  • SQL Server 2008 Service Pack 3
  • SQL Server 2008 R2 Service Pack 1
  • SQL Server 2012
In previous releases, AD RMS Setup supported only deployment at the same server computer where AD RMS was to be installed. Based on customer feedback, this has been changed. For Windows Server 2012, AD RMS now supports remote deployment at targeted server computers. In previous releases, AD RMS Setup supported only deployment at the same server computer where AD RMS was to be installed. Based on customer feedback, this has been changed. For Windows Server 2012, AD RMS now supports remote deployment at targeted server computers.
For Windows Server 2012, Server Manager has been redesigned to provide support for remote deployment of AD RMS as part of a two-step process that can be summarized as follows:
  1. Launch the Add Roles and Features Wizard in Server Manager to add the AD RMS role. This will add and install the files necessary for AD RMS.
  2. After adding the AD RMS role, launch the AD RMS Configuration wizard to select deployment options and configure the AD RMS cluster.
When the AD RMS configuration wizard first launches, if you are installing AD RMS on a remote server you will be prompted for the credentials needed to complete AD RMS configuration.
The requirements for selecting the credentials that you enter here are as follows:
  • The account used to deploy AD RMS must have membership in the local Administrators group on the server computer where you are installing and configuring AD RMS.
  • The account used must also have sysadmin permissions on the server that hosts the configuration database for the AD RMS cluster.
 AD RMS now supports mobile devices when you install and configure AD-RMS mobile device extention, like for MAC computers
AD RMS fails to install if multiple installations are active simultaneously in Server Manager
In previous releases of AD RMS included with Windows Server® 2008 and Windows Server® 2008 R2 it was not possible to launch more than a single instance of the AD RMS Configuration wizard to install or update multiple AD RMS deployments from the same server computer. Because of design changes to Server Manager for Windows Server 2012, multiple instances of the Add Roles and Features Wizard can now be run simultaneously, making it possible to launch two or more instances of the AD RMS Configuration wizard.
Server Core Support for AD RMS
For Windows Server 2012, AD RMS now joins the list of server roles such as Active Directory Domain Services (AD DS) and Active Directory Certificate Services (AD CS) that are supported for Server Core deployment. Server Core is an installation option that enables you to perform a minimal installation of the Windows Server operating system which can be useful for reducing total cost of ownership (TCO) in deploying and managing servers.

Wednesday, November 18, 2015

What is new in Microsoft Exchange Server 2016


  What is new in Microsoft Exchange Server 2016

Thanks for liking my first article of this series, in second article of this series, I am going to introduce you about the brand new features of Exchange Server 2016, which were not available in previous versions.

Exchange 2016 have lots of new exciting features which helps IT administrator to make more powerful, secure and highly available Exchange organization.
In this article we will discuss about all the new features which was not available in Exchange 2010 and as well Exchange 2013

New Functionality/ features from Exchange 2010:
Exchange Server 2016 have a number of new features which was not available in Exchange Serve 2010, here is list of new features.

Exchange Admin Center: Exchange 2016 provides a single unified management console that allows for managing your on-premises, Office 365 and hybrid deployments. The Exchange admin center (EAC) in Exchange 2016 replaces the Exchange 2010 Exchange Management Console (EMC) and the Exchange Control Panel (ECP), but still we have ECP as a virtual directory which used by EAC.

 Exchange Server 2016 Architecture: As we know Exchange Server 2010 have 5 different roles for different functionality, but in Exchange 2016 Microsoft reduce the Server roles and now Microsoft include all the functionality in a single server role (excluding Edge Server role).

  •  Mailbox Service includes all the server components in Exchange Server 2010, like: MBX Role, CAS Protocol, Transport Service, Mailbox databases and UM services.
  •  CAS service provide all the authentication, limited redirection and proxy related services. It also offer all client access protocol, like: HTTP, POP, IMAP and SMTP.


Note: Edge is a separate role and installed in DMZ zone, which is outside of your AD network, so you can use Edge server role, if required for your organization or you can go any other Anti spamming solution for your organization, like: EOP or any other third party which suites with your organization requirements. 

Managed Store: In Exchange 2016, the Managed Store is the name of the Information Store processes, Microsoft.Exchange.Store.Service.exe and Microsoft.Exchange.Store.Worker.exe. The new Managed Store is written in C# and tightly integrated with the Microsoft Exchange Replication service (MSExchangeRepl.exe) to provide higher availability through improved resiliency.  

The Managed Store works with the Microsoft Exchange Replication service to manage mailbox databases, which continues to use Extensible Storage Engine (ESE) as the database engine. The Microsoft Exchange Replication service is responsible for all service availability related to Mailbox servers. This change enables faster database failover and better physical disk failure handling. 

Certificate Management: Security is a major concern in Exchange organization, to make secure communion we use digital certificates which improve the security in Exchange organization. The major enhancement in certificate management is, it was difficult to see when a digital certificate was nearing expiration. In Exchange 2016, the Notifications center will display warnings when a certificate stored on any Exchange 2016 server is about to expire. Administrators can also choose to receive these notifications via email.

New look of Installation Setup: Exchange 2016 Setup has been completely rewritten so that during the installation of Exchange 2016, make sure you've got the latest product rollups and security fixes is easier than ever. Improved readiness check that your organization is ready to accept the new Exchange 2016 in your organization or not. 

Hybrid Configuration of Office 365: The hybrid configuration wizard, which was included in Exchange server 2013 itself have more enhancements, like: when you start hybrid configuration wizard it ask you to download and install as a small app. It provide you below new functionality:

·         The wizard can be updated quickly to support changes in the Office 365 service.
·         The wizard can be updated to account for issues detected when customers try to configure a hybrid deployment.
·         Improved troubleshooting and diagnostics to help you resolve issues that you run into when running the wizard.
·         The same wizard will be used by everyone configuring a hybrid deployment who's running Exchange 2013 or Exchange 2016.
·         In addition to Hybrid Configuration Wizard improvements, multi-forest hybrid deployments are being simplified with Azure Active Directory Connect (AADConnect). AADConnect introduces management agents that will make it significantly easier to synchronize multiple on-premises Active Directory forests with a single Office 365 tenant.

Enhancement in DLP Policy: Exchange 2016 provides a built-in DLP policies based on regulatory standards such as personally identifiable information (PII) and payment card industry data security standards (PCI), and is extensible to support other policies important to your business. With a DLP policy in Exchange 2016, you can now identify, monitor, and protect 80 different types of sensitive information

Enhancement in Transport Rules: Exchange 2016 have some exciting enhancements in transport rules, which help IT Administrators to protect transport role. For Example:

Condition: With the new condition Any attachment has these properties, including any of these words
Action: With the new action Notify the recipient with a message       or
The action Generate incident report and send it to

So like this we can use new transport rules.

Microsoft RM (Right Management) Connector: The Microsoft Rights Management connector (RMS connector) is an optional application that helps you enhance data protection for your Exchange 2016 server by connecting to cloud-based Microsoft Rights Management services. Once you install the RMS connector, it provides continuous data protection throughout the life span of the information and because these services are customizable, you can define the level of protection you need.
For example, you can limit email message access to specific users or set view-only rights for certain messages.

Enhancement in Auditing:  Auditing is a feature which used by organizations to monitor the users or have some compliance policy for auditing. The EAC in Exchange Server 2016 includes a new auditing functionality so that you can run reports or export entries from the mailbox audit log and the administrator audit log. This can help you troubleshoot configuration issues or identify the cause of problems related to security or compliance.

New Mail flow Architecture: Exchange 2016 have different architecture of mail flow compare then previous versions. These are the new components of mail flow in Exchange Server 2016

  • Transport pipeline: The transport pipeline in Exchange 2016 is now made up of several different services: the Front End Transport service, the Transport service, and the Mailbox Transport service.
  • Routing: Mail routing in Exchange 2016 recognizes DAG boundaries as well as Active Directory site boundaries. Also, mail routing has been improved to queue messages more directly for internal recipients.
  •  Connectors: The default maximum message size for a Send connector or a Receive connector, as specified by theMaxMessageSize parameter, has been increased from 10MB to 25MB. You can set a Send connector in the Transport service of a Mailbox server to route outbound mail through a Front End transport server in the local Active Directory site.
  • Edge Transport: You can optionally install an Edge Transport server in your perimeter network to reduce your attack surface and provide message protection and security.

Enhancement in Recipients: Exchange Server 2016 have below new enhancement in recipient section:
·         In Exchange Server 2016 now IT Administrators can use the EAC to create a group naming policy, which helps you manage the names of distribution groups created by users in your organization.
·         You can also use the EAC to track delivery information for email messages sent to or received by any user in your organization. You just select a mailbox, and then search for messages sent to or received by a different user.

Integration with SharePoint and Skype for business: In Exchange 2016, you can also integrate the SharePoint and Skype for business to enhance the Exchange functionality.

Outlook on Web: Outlook Web Access is replaced now with Outlook on Web, mean now you can access your emails from any of the supported web browser, like: Microsoft Edge, IE, Chrome, Mozilla and Safari.

Offline Outlook on Web: Internet Explorer 11 and Windows Store apps using JavaScript support the Application Cache API (or AppCache), as defined in the HTML5 specification, which allows you to create offline web applications. AppCache enables webpages to cache (or save) resources locally, including images, script libraries, style sheets, and so on. In addition, AppCache allows URLs to be served from cached content using standard Uniform Resource Identifier (URI) notation. The following is a list of the browsers that support AppCache:
·         Microsoft Edge
·         Internet Explorer 11 or later versions
·         Google Chrome 44 or later versions
·         Firefox 39 or later versions
·         Safari 8 or later (only on OS X/iOS) versions

MAPI over HTTP: In Exchange 2016 MAPI over HTTP is now the default protocol which used by Outlook to communicate with Exchange Server. MAPI over HTTP improves the reliability and stability of the Outlook and Exchange connections by moving the transport layer to the industry-standard HTTP model. This allows a higher level of visibility of transport errors and enhanced recoverability.

Document collaboration: Exchange 2016 will enable Outlook on the web users to link to and share documents stored in OneDrive for Business in an on-premises SharePoint server instead of attaching a file to the message. 

Batch mailboxes move: Exchange 2016 support batch mailbox move feature, which mean now you can move multiple mailboxes in large batch files.

Enhancement in High Availability and Site resiliency: Exchange 2016 uses DAGs and mailbox database copies, along with other features such as single item recovery, retention policies, and lagged database copies, to provide high availability, site resilience, and Exchange native data protection.

 New Functionality/ features from Exchange 2013:

Exchange Server 2016 is little bit similar to Exchange 2013 but again there is lots of new features, which introduced in Exchange 2016.

Here is the list of Exchange Server 2016.

Ø  Enhanced Exchange Server 2016 architecture
Ø  Outlook on Web
Ø  MAPI over HTTP
Ø  Document collaboration
Ø  Office 365 Hybrid enhancements
Ø  Enhancement in messaging policy and compliance




Kindly provide your valuable comments and feedback on my articles to motivate me, so I will continue with more new articles of this series.
In next article I will explain you about “How to install Exchange Server 2016”………. So wait me J

Author,
Arun Chaudhary
MCP, MCTS, MCITP, MCTS, ITIL, VCA-Cloud, VCP, MCSE
AD/ Exchange SME, Founder/ Owner of
Q-Lative Solutions

About me: Hello dear readers, I am working as an AD & Exchange SME and handling complex setup of 60K users with hundreds of Email Servers. I am the founder and owner of “Q-Lative Solutions”. Under this IT Training and Consultancy we offer only customized course for my clients who are from across the world. I have already trained more than 500+ students in customized training. We offer a complete package for training on real world scenario and setup by SME’s. We offer a full package of products, Eg:

Messaging Expert: This package include Exchange 2010, 2013, 2016, Office 365, Proof point Gateway, Blackberry, EOP and Google-App, Migration and Office 365 Migration with Hybrid configuration wizard and all the installation, configuration and functionality on a very cheaper price in all the world.

Wintel Admin: This package include Windows Server 2008, R2, 2012, Basic of Active Directory, Hyper-V, SCVMM, VMware (VCP), and Server Patching, monitoring and Backup / Restoring on real world scenario.

AD Admin/ Expert: Windows Server 2008, R2, 2012 including in-depth knowledge of Active directory and Windows Server Roles, AD-DS, AD-CS, AD-FS, IIS, WDS, RRAS and VPN Server installation, configuration and managing.

Note: We offer SCOM, ITIL, SNOW, Remedy training fully free and mandatory with all the courses. We also offer live servers troubleshooting and how to create Incidents/ Problem Tickets, Change Request with complete ITIL Process, which used by all MNC.