Cross Domain Migrations - Able to access own mailbox but no other resource

Hi,
I wondered in anyone could offer any guidance on a problem we are seeing with a
cross forest Exchange 2010 (domain A) to Exchange 2013 (domain b)migration.
Our problem is based around the fact that the users are still logging into 'windows clients' in the source domain (domain A). We have configured mail enabled users in the source to enable auto discover to work correctly and the user can successfully
connect to their own mailbox once it is provisioned in Exchange 2013 (domain B). Our main Outlook client being 2010 SP2.
The user is not prompted to login at this stage, which is preferred.
However the problem is that they cannot connect to any other resource in the Exchange 2013 (domain B) environment. (We have no interest in them accessing resources in the Exchange 2010 environment as this is a major switchover). When attempting to connect
to public folders (2013) they receive only those permissions provided by the 'Default' user permission. When trying to expand a mailbox where full access has been granted they receive the 'Unable to expand. An attempt to logon to Microsoft Exchange
has failed' error.
If we change Outlook to 'Always prompt for logon credentials' and then login with credentials from the target domain (domain B, all resources can be accessed successfully.
As part of our migration we have used ADMT, a two way trust is in place, SID history has been migrated and SID filtering is turned off in both directions. Passwords in both domains are matching by virtue of an Identity management solution. Outlook anywhere
on exchange 2013 is set to negotiate (internal and external) with IIS configured with 'Basic, NTLM and Negotiate' as authentication types.
Whilst the obvious answer is simply to get the users to login to the target domain (domain B), it is unfortunately a requirement that users continue to login to the source domain (domain a) for a while after the Exchange migration has completed.
Would anyone be able to advise if this is just something we have to live with and find a way to force users to login every time they open outlook, or is there perhaps a way to configure this to work so that users are not prompted to login but can access
all their resources.
Many thanks for any assistance or opinions.
Kind Regards,
Mark Needham

Hi Mark,
Please try to clean up the cached credential in your computer. Then fill in with new domain information (domainB\user) when it prompted for credentials next time and check the Remember my credential to save it. About how to remove cached credentials, please
follow these steps:
1. Launch the Credential Manager from Control Panel > All Control Panel Items > Credential Manager.
2. In the Generic Credentials section you’ll see a setting for [MS Outlook] which will include your SSO details. Click the downward-pointing arrow to the right of that value.
3. In the expand details, click Remove from vault. Then Outlook will no longer have a stored copy of your old login information (domainA\user).
If it doesn’t work, please change the windows account with domainB\user information to have a try.
Regards,
Winnie Liang
TechNet Community Support

Similar Messages

  • Is that possible to do the cross domain migration for AD RMS Services?

    Hi guys, recently i am doing a cross domain migration, when i listing out the server, i found the server have AD RMS services which is still active.
    but after my migration is complete, it is planned to do the decommission on all the old server
    After my checking, i believe the AD RMS have trust establish with a cross site domain already. What i am planning to do is try to do a migration on it.
    i have do some research on it an i found "Cross forest Migration of AD RMS document"
    what i found in the document, it have mention about
    In the event when one cluster running AD RMS is to be discontinued, users may still want to access
    previously protected content that was issued a publishing license by that computer. Servers in other clusters can then add the to-be-discontinued server as a trusted publishing domain.
    So i was wondering if there is an option for Ad RMS services to select a server or host to discontinued?
    The scenario in my head now,
    1.Build trust between in my new domain AD RMS with the existing AD RMS.  update the certificate between the trusted domain as i mention above with my new domain AD RMS.
    but i was wondering if i power down or decommission the server what will happen?
    2. the worst case scenario will be decommission the old AD RMS service, and publish the new AD RMS services in new domain, simply build trust with the cross site domain.
    any suggestion on this? which case is more workable?
    Thanks
    Dave

    Hi,
    I think you may ask in AD RMS forums:
    http://social.technet.microsoft.com/Forums/en-US/home?category=rms&filter=alltypes&sort=lastpostdesc
    Regards.
    Vivian Wang

  • I'm able to access the internet but have no sound on videos?

    I'm able to access the internet but unable to ge sound from videos utilizing Safari?

    Contact the develpers of that app, which is not an Apple product for support.  You can find the developer contact info in the description of that app in the App Store or Google it.

  • Not able to access Central admin or any other site

    My machine name has been changed from abc-xyz to DT-012
    After changing my machine name am not able to access Central admin or any other site in sharepoint. which says '
    Server Error in '/' Application.'
    Please tell me after changing machine name what else i have to change so i can access my SharePoint back.

    Hi Niraj, 
    Thanks for posting your issue, Just wanted to know have you changed server name  using below mentioned command?
    stsadm -o renameserver -oldservername oldservername -newservername newservername
    I hope, you have not changed your SQL Server name/instance. If changed SQL too. Kindly re-run the configuration Wizard of SQL server to set up Alias.
    Also, Browse below mentioned URLs to know more about the fixes of this issue
    http://www.ericjochens.com/2013/03/change-sharepoint-server-hostname-and.html
    http://www.bluesphereinc.com/blog/renaming-a-sharepoint-20102013-server/
    I hope this is helpful to you, mark it as Helpful.
    If this works, Please mark it as Answered.
    Regards,
    Dharmendra Singh (MCPD-EA | MCTS)
    Blog : http://sharepoint-community.net/profile/DharmendraSingh

  • Cross Domain migration

    Hi,
    I would like to know best practice for Cross forest Migration from Exchange 2010 to Exchange 2013... Here is the scenario:-
    1. There are two forest abc.xyz.com & efg.xyz.com.
    2. abc domain having Exchange 2010 is running.
    3.Efg domain having user accounts and users login to laptop using this domain.
    4. I have to install Exchange 2013 in Efg domain and migrate mailboxes from Exchange 2010 servers. This includes public folder, GAL Sync & Free /busy.
    Please suggest me best practice to achieve goal ... Pls. send details on
    Thanks in Advance !!
    Amit kumar

    Hello,
    You current topology is “Resource/User forest“, right?
    The basic requirement is: the Exchange 2013 target forest must contain a valid mail-enabled user with a specified set of Active Directory attributes.
    http://technet.microsoft.com/en-us/library/ee633491(v=exchg.150).aspx
    Thanks,
    Simon Wu
    TechNet Community Support

  • SBS2011 - Cross domain Migration to Server 2012 R2 w/ Exchange 2013

    I am attempting to find the best way to do this, and any input/guidance would be greatly appreciated.
    Source Server: SBS 2011 Standard - Internal domain costco.local
    Target Server: Server 2012 R2, 2 virtuals, one for the domain controller, one for Exchange 2013 - Internal domain ad.costco.com
    I know that in order to establish a trust relation, I must add a secondary domain controller to the SBS2011 domain and transfer FSMO roles.  My question is, can I use a trial Server 2008 R2 as an interim DC, create the trust, use ADMT to migrate user
    accounts to the new domain and move mailboxes from the SBS server with the trust established on the Server 2008 DC?  Or do I have to install an interim exchange server and move the mailboxes and remove the SBS server from the domain?
    If that is the case, can I use a 180 Trial of Server 2008 R2 and Exchange 2010 on two separate virtuals on the old domain, move all user accounts and mailboxes to a standard domain temporarily.  Then from the standard domain move user accounts and mailboxes
    to the Server 2012 R2 DC and Exchange 2013 virtual?
    It would be great if I could just establish a trust with with a second DC with SBS and move user accounts and mailboxes to the new internal domain, but I'm not sure if that is possible.  Any insight would be greatly appreciated!

    SBS can't do trusts but the migration prep tool temporarily allows them I believe.  Have a look at this link dealing with migration to 2012 essentials from SBS, it doesn't deal with exchange though:
    https://technet.microsoft.com/en-us/library/jj721754.aspx
    There is also a recent thread "Migrating from SBS 2011 to Server 2012R2 Standard & Exchange 2013" that may have some info.
    -- Al

  • Anyone else able to access store OK but all links inoperative?

    I have not seen this one before. I am able to access the music store no problem, but all links are acting like I am not even clicking on them (even though I am). Even the blue up/down scroll bar on the far right column is inoperative and not moving at all. Anyone else having this problem or have heard what is wrong? I could not even use the support link on the home page to get here to write this, but was able to do so through exiting out of the store and then just re-entering under my internet connection and punching in the Apple website.

    I had this problem
    decided to upgrade Itunes to the latest 7.0.2
    4 hours
    6 system restores
    5 uninstalls
    3 quicktime uninstalls and downloads later IT IS FINALLY WORKING!!!
    I went back to 6.0 as well then uninstalled and reinstalled quicktime and it seems like the problem is fixed ( fingers crossed)
    from my experience maybe uninstall and get the latest quicktime - that may work?

  • HT4437 How do I get my Air Play to access my two WD Share Space and my booklive duo?. Able to access with PS3 but not Apple TV Ver 3.  Have all my movies and music on it and do not want to have a computer on for it.

    I had bought two Network Drives so I could watch my own movies anywhere in my house and clear up the clutter of all the DVDs, Blurays and CDs, Works greate with the PS3,  Bought the Apple TV version 3 because it was smaller and resently bought the IPAD 3 and have the IPHONE 4S and other apple products.
    My wish is to access my Network drives with the Apple TV - I have herd of Jailbreaking it (Not Avalible from where I can tell for the Version3) - but why didn't Apple ever think of accessing a Network drive and is their a work around for this?   Should I just shutup  and wait till Jail Breaking is avalible for the Version 3?.
    Thank you for any help

    longbeachjoe wrote:
    ......but why didn't Apple ever think of accessing a Network drive and is their a work around for this?
    I'm sure they did think of it, but quickly discarded the idea because of the horrendous user experience this causes.

  • I keep getting error -50 on itunes when i try to login through my apple id. I am able to access itunes store but it does not allows me to sign into my id

    When i try to login with my apple id i keep on getting error saying "We could not complete your itunes store request. An unknown error occured(-50)." I get this error everytime i try logging into my account. But still i can access to the iTunes store. I had recently downloaded this iTunes software into my new windows 8.1 laptop so i think it is up to date. I have earlier used this apple ID into another iTunes conneted to my older PC(I haven't logged out from it yet.Could that be the problem?).

    Ok.
    Seems this is a well known problem.
    https://discussions.apple.com/thread/3574459?start=0&tstart=0
    Killing the APSDaemon.exe works for me!

  • Cross Domain solution: Could not get bytesloaded swf external from other domain

    hello: good evening
    I leave my problem here:
    I am make a measurer of internet speed that consists one
    preloader (swf1.swf in www.dominio1.com) who loads a swf (swf2.swf
    in www.dominio2.com)
    The file swf2.swf visualizes perfect in swf1.swf without
    problems although on swf1.swf it does not take the variables from
    swf2.swf to show the rate of transference, total remaining time, kb
    loaded and kb total.
    If I use crossdomain.xml on the mother directory of the site,
    or both sites, the problem it persists.
    I need that they indicate to me like making solve this
    disadvantage
    if somebody knows where I can obtain a gratuitous measurer of
    speed, please, to indicate it:-o
    Thanks you very much for all
    any questions???

    no body answer?

  • Cross Domain Call in SharePoint Hosted app.

    Hi, I am very new in SharePoint 2013 App dev and want to understand when actually Cross domain calls are required and how we can achieve it. 
    Getting host web site title from a sharepoint hosted app needs a cross domain call?
    My point of confusion is some places I have seen we have to load SPRequestExecutor for getting data from host web  but I am able to get it using changing the context to host web and then getting the title without using SPRequestExecutor:
     appContextSite = new SP.AppContextSite(ctx, spHostUrl);
       Nweb = appContextSite.get_web();
       //Nweb = ctx.get_web();
       ctx.load(Nweb); 
    What is the difference between the two( using SPRequestExecutor and not using) and what places we need to use it and where we can get data without it ?
    please help me to resolve this confusion.
    Thanks

    Hi vmishr11,
    When you use SP.RequestExecutor, it will execute asynchronously to get data from host web. It will use like below:
    var executor = new SP.RequestExecutor(appweburl);
    executor.executeAsync(
    url:
    appweburl +
    "/_api/web/lists/getbytitle('Announcements')/items",
    method: "GET",
    headers: { "Accept": "application/json; odata=verbose" },
    success: successHandler,
    error: errorHandler
    For SP.AppContextSite, it will execute in order to get data.
    Here is a detailed article for your reference:
    How to: Access SharePoint 2013 data from apps using the cross-domain library
    Best Regards
    Zhengyu Guo
    TechNet Community Support

  • Error 2170 in Cross Domain Policy deployed in Enterprise Portal

    Hi All,
    We are facing an Error # 2170 for the Cross Domain Policy in Enterprise Portal.
    We developed the dashboard using 2 web service connections (using ECC Remote Enabled Functon Module). The Web services were made Public so that they can be accessed from any network. We developed the dashboard using the public enabled webservices and exported to the SWF file which is working fine.
    But when we place the dashboard SWF file in the Enterprise portal it gives the error " Cross Domain Policy Error #2170" .
    We Placed the Cross domain Policy file in ECC Server in the root directory and placed the same in Enterprise portal C drive.
    But still it shows the same error when we preview the dashboard in Enterprise Portal.
    The Cross Domain Policy File that we are using is as follows:
    -<cross-domain-policy> <site-control permitted-cross-domain-policies="all"/>
                <allow-access-from secure="false" to-ports="" domain=""/>
               <allow-http-request-headers-from secure="false" domain="" headers=""/>
               <allow-https-request-headers-from secure="false" domain="" headers=""/>
    </cross-domain-policy>
    Please let us know if the cross doamin file is correctly coded and suggest us with suitable solutions for this problem. Also let us know if there is some alternative solution to this issue.
    Thanks,
    Malla Reddy D

    Hello Malla,
    Maybe SAP Note 1240810 helps... Anyway, I would say that if your issue is with the direct SAP NW BI connection, through BICS, the only file which is relevant is bicsremotecrossdomain.xml, which should be located on your server HTTP root.
    Another check you can perform is if you have both portal certificate entries as per SAP Note 1508663.
    Kind Regards,
    Marcio

  • Endeca cross domain problem

    We are currently using Endeca Commerce 3.1 on a distributed environment with MDEX installed on one server and Experience Manager on another but both on the same domain.
    When we use the RecordSpotlight cartridge in Experience Manager the record selection radio buttons are greyed out.
    We followed the instructions under “Setting up a cross-domain policy file” under Appendix C in the “Tools and Framework Installation Guide” and added the following crossdomain.xml file under <MDEX_install_dir>/6.4.0/conf/dtd/xform but still the problem persists. We have also set the value of permitted-cross-domain-policies in the crossdomain.xml file to “none”, “master-only” and “all”. None of them solved the problem.
    <?xml version="1.0"?>
    <!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
    <cross-domain-policy>
    <site-control permitted-cross-domain-policies="all"/>
    <allow-access-from domain="*.mydomain.com" />
    <allow-access-from domain="*.mydomain.ca" />
    <allow-http-request-headers-from domain="*" headers="SOAPAction"/>
    </cross-domain-policy>
    Could you please advise on how to enable those record selection radio buttons?
    Sincerely,
    Alex Luc

    It looks like I've solved it. The parent domain was
    sub-domain and I was leaving off the "
    http://" for the allowDomain argument. Once I
    added it, the swfs work.

  • Cross Domain Ajax in newScale

    We have lots of form field validations in our newScale instance, for which we rely upon external applications.
    I am using http://ajax.googleapis.com/ajax/libs/dojo/1.6.0/dojo/dojo.xd.js for making cross domain ajax.
    Now there are multiple issues that I am facing & need a better approach -
    1. This works great in IE 8 & 9 but pops up a security warning which is kind of annoying to the end user.
    2. Never works on Firefox.
    Has someone faced a similar issue or have a better solution w.r.t newScale environment, please share the details.
    Thanks,
    Abhishek

    Hi vmishr11,
    When you use SP.RequestExecutor, it will execute asynchronously to get data from host web. It will use like below:
    var executor = new SP.RequestExecutor(appweburl);
    executor.executeAsync(
    url:
    appweburl +
    "/_api/web/lists/getbytitle('Announcements')/items",
    method: "GET",
    headers: { "Accept": "application/json; odata=verbose" },
    success: successHandler,
    error: errorHandler
    For SP.AppContextSite, it will execute in order to get data.
    Here is a detailed article for your reference:
    How to: Access SharePoint 2013 data from apps using the cross-domain library
    Best Regards
    Zhengyu Guo
    TechNet Community Support

  • Am I able to access Numbers file from my iPad in iCloud?

    I work on numbers on my mac at work and was wondering if I'm able to access that file through iCloud on my iPad at home? I don't want to pay $10 for the Numbers app on my iPad if I can't access those files.
    Thanks

    You will be able to access them from the iPad

Maybe you are looking for

  • How do I install on a slave drive and not C drive

    How do I install on a slave drive and not C drive

  • Different Character sets (Codepages) in the same Login

    Hi, I need to enter different character sets (Russian and English) in the same login and save the different characters to SAP database tables. The codepage for Russian is different from English codepage. I have Russian codepage language settings on b

  • Error/Exception Messages in OA FramWork

    Hi, I am working on SSHR. The Business say, IF the Leave Encashment is >10 it should through an error. For this I am using dbms_standard.raise_application_error (num => -20999 ,msg => 'Cannot encash more than 10 Leaves'); Through PL/SQL User hook cod

  • Operating temperature

    Does anyone know what's a decent temperature for my HD bay on my 24" iMac? My HD recently crashed (6 month old iMac) and I'm looking at my HD bay temp at it hovers around 106F. I've upped my fan speed but does anyone know if this is in the range of o

  • Hardcode Distribution Channel For Opportunities

    Hello, I have a requirement where once a prospect is selected for an opportunity and the sales areas are selected, I need to hardcode the distribution channel to a specific value regardless of what the org determination procedure brings back.  Does a