Exchange 2010 - Multi Site DAG with DAC - Node evicted

I have a 2 site DAG with 4 members, 2 at each site with DAC set. 
Primary Site:
EXMB01
EXMB02
FSW
Failover Site:
EXMB03 - PAM
EXMB04
AFSW
After updating and rebooting one of the members in the primary active site (exmb02), it looks like the server was removed from the cluster as it was booting back up:
Event ID: 4621
Source: FailoverClustering
This node was successfully removed from the cluster.
Directly preceding that, in the Failover Cluster Manager events, I can see the following progression:
Event ID: 4620
Task Category: Cluster Evict/Destroy Cleanup
Unloading the cluster service registry hive during cluster node cleanup failed. The error code was '3221225569'. You may be unable to create or join a cluster with this machine until cleanup has been successfully completed. For manual cleanup, execute the
'Clear-ClusterNode' PowerShell cmdlet on this machine.
and then: Cluster node cleanup encounted at least one error. You may be unable to create or join a cluster with this machine until cleanup has been successfully completed. Please review and resolve preceding cluster node cleanup events. For manual cleanup,
execute the 'Clear-ClusterNode' PowerShell cmdlet on this machine.
And then from all three other nodes:
Node MGR: Cluster node USTRYCO01EXMB02 has been evicted from the failover cluster.
I intend to move the PAM role back to the primary sight, I had not noticed it was there.
Curiously, if I run Cluster.exe node, I can see that all 4 nodes are listed as UP. 
What do I need to do to recover EXMB02?  I've read that sometimes just a reboot will clean up the cluster configuration,  but how would I add the node back into the cluster?  Why is it still listed as a node if it was evected?  Also,
what is the significance of having the PAM role in the primary data center as opposed to the failover data center?

Hi,
From the error message, you need to run the following cmdlet to force the cleanup on server EXMB02.
CLUSTER NODE /FORCECLEANUP
For more details about error 4620 and 4622, you can refer to these two articles: Event ID 4620 — Node Cleanup Success
and
Event ID 4622 — Node Cleanup Success.
About PAM, the PAM role is automatically held by the DAG member that owns the cluster’s core resource group. It doesn't matter what site the PAM is in, if the server that owns the cluster quorum resource fails, the PAM role automatically moves to a surviving
server that takes ownership of the cluster quorum resource.
Best regards,
Belinda
Belinda Ma
TechNet Community Support

Similar Messages

  • SQL Server 2012 Multi-Site clustering with 2 nodes for HA and DR

    Usually we setup 2 Node Prod cluster for Local HA and 1 or 2 Nodes in other data centre for DR
    Given that we have an option to setup multi-site / multi-subnet clustering from SQL 2008 R2/2012. I am planning to use just 2 nodes, 1 in prod data centre and 1 in DR data centre with 2 or 3 instances. This will act as both HA and DR solution.
    I would like to know if this solution is good, and any disadvantages, any best practices, etc.? By implementing this I can save some cost on physical servers.
    Following will be configured:
    * Will be using different subnets, quorum on different server with "Node and File Share Majority"
    * All virtual IPs will be registered for virtual name, and Subnetdelay, Subnet threshold will be modified accordingly
    * All nodes on same domain
    * Use SAN Disk with replication to DR site

    SQL 2008 R2 doesn't support multi-subnet clustering. You would still need 3rd party component like VLAN and Disk Replication. SQL 2012 is the first version to support multi-subnet clustering without using VLAN. you would still need disk replication hardware/software.
    Taken from my book
    Since nodes are often located in two different data centers at geographically dispersed locations, there is no shared storage between the nodes in a multi-site cluster. Clustering across two different data centers provides a higher level of availability and
    protection at the storage level as we have more than a single copy of the data.
    For SAN replication technology implemented in such clusters, the main activity is to keep data replicated between the sites. Typically, if we have nodes on two different sites, we would have two different network infrastructures and the nodes would be in
    different subnets. In such cases, if we are on a SQL Server version before 2012, we need to use third party VLAN (Virtual LAN) technology so that one IP address travels between two sites. This is called wide-IP. Companies hesitate with this solution because
    of the need to buy a third party solution to deploy the VLAN. Using VLAN technology means the same IP address would failover to the remote site in case of a local site disaster. Network administration might consider this as an overhead to maintenance and an
    extra piece of the networking component that needs to be secure.
    With SQL Server 2012 we do not need to use stretch VLAN technology but SAN replication is still needed for multi-site clustering. The OS version for this can be from Windows Server 2008 R2 and above. In this deployment, we can have a SQL virtual network
    name having an “OR” dependency on two different IP addresses. One address would be representing each subnet. With the “OR” dependency, if IP1 or IP2 is online we just use the network name. This is one of the Enterprise Editions only features.
    Other option which you can think of, without using 3rd party solutions would be AlwaysOn Availability Group. I have written details about it in my book.
    Balmukund Lakhani | Please mark solved if I've answered your question, vote for it as helpful to help other users find a solution quicker
    This posting is provided "AS IS" with no warranties, and confers no rights.
    My Blog |
    Team Blog | @Twitter
    Author: SQL Server 2012 AlwaysOn -
    Paperback, Kindle

  • Exchange 2010 cross subnet Dag - Errors creating DB copies in DR site

    We are running exchange 2010 standard edition in our main site with 2 mailbox servers in a DAG. I've added 2 more mailbox servers in a DR site connecting over a 20Mb fiber connection. I've tried adding one of the DR mailbox servers over to the DAG as database
    server, also tried updating copies of the database after it fails to update it.  Been working with Microsoft support on this but they have been little slow getting back with me so wanted to see if I can find anyone that has had this issue before. We've
    changed TCP global settings, they've set the Cluster setting for samesubnet and crosssubnet threshholds settings to recommended, made sure my DAG replication networks were correct and that's about it so far.  Tried running the update database
    from GUI and shell but to no avail.  Seems like it is copying the logs and database but fails at the very end.  We thought it might be backup software running so we turned that off completely.  Here are the different error messages I get..
     A source-side operation failed while performing seed operation.  error occurred whil communicating with mbx-01 (source server..)  unable to read data from transport connection..  connected host failed to respond..
    A source side operation failed performing seed operation.  An I/O error occurred while attempting to access file ..CatalogData-...ci on source server could not be opened. sys cannot find file.
    Information Store (1988) Mailbox-MBX-01:  The internal database copy (for seeding or analysis purposes) has been stopped because it was halted by the client or because the connection with the client failed.
    Any help is appreciated..
    Michael Duhon

    Hello,
    I recommend you try to restart Microsoft Exchange Replication Service to check the result.
    If the issue persists, please try to rebuild the Index for your database to check the result.
    If you have any feedback on our support, please click
    here
    Cara Chen
    TechNet Community Support

  • Exchange 2010 Decommisioning a DAG member from a 3 node Dag

    Hi Guys,
    What the safest way to remove one server from a 3 Node Dag.
    Currently I am planning the following steps:-
    Remove Exchange server MAIL03 from DAG
    1.Start up Exchange Management Console
    2.Go to Organization Configuration > Mailbox > Database Management;
    3.if mail boxes are mounted on MAIL03, Select the database where ” Mounted on Server” reads the MAIL03;
    3.1.Select Move Active Mailbox Database;
    3.2.Select the Mailbox server i.e. MAIL01\MAIL02 to host the mailbox database copy and select Move;
    5.When the move has finished, select the database copy hosted on the MAIL03 in the lower pane. There, select Remove.
    6.Remove the MAIL03 server from the DAG. Select tab Database Availability Groups;
    7.Select the DAG the MAL03 server is a member of and select Manage Database Availability Group Membership;
    8.Select the server and click the red cross to remove it from the list. Click Manage to proceed with the actual removal;
    9.When finished the mailbox server is no longer member of the DAG.
    10.Rebalance Mailbox Databases in DAG.
    What do you guys recommend?
    Also after the removal of the DAG node, what the best way to reduce the Passive Database/Transaction logs? our current setup is as follows:-
    I want to remove the drives L,M,N,O
    Thanks
    Jitinder

    Hello,
    Based on your description.
    If you want to remove drives only from that server and leave databases working on the rest of nodes:
    1. Remove database copy on that server.
    2. Remove drives.
    It is not required to move mailboxes from these databases. In this scenario you will not be able to re-add copy of these databases because all nodes need to have the same drive
    letters.
    If you want to remove L, M, N, O from all servers:
    1. Move mailboxes from these databases.
    2. Remove them (copies and empty dabatabes).
    3. Remove drives.
    There is no need to remove server from DAG if you just want to remove database copy from one node. 
    Hope it helps,
    Adam
    www.codetwo.com
    If this post helps resolve your issue, please click the "Mark as Answer" or "Helpful" button at the top of this message. By marking a post as Answered, or Helpful you help others
    find the answer faster.

  • Exchange 2013 Multi Site Not SR/HA

    This is the first time we have deployed a multi site Exchange organization.  Here is the scenario and I am wondering if it is the correct one or if I should have done it a different way.
    We have a VPN setup between our corporate location and a satellite campus.  The satellite campus has it's own namespace and is a tree in our forest.  We have Exchange 2013 SP1 setup at the corp location.  We installed two Exchange 2013 SP1 servers
    at the satellite location in that domain in the same Exchange organization.  I was able to create a few linked users mailboxes (newly acquired and in process of user migration into our forest) and mail delivers between the two without issue.  But
    lately every new user will not receive email and they will be in the queue.  Does not matter if the email is from a corp user or a local user on the same mailbox server.
    We decided to do this because we want them to have all of their Exchange resources, email, CAS services and UM local to them, but they are still part of our system.  I am having a hard time finding why this is happening.  I also noticed that the emails
    sent from one satellite user to another is actually going through the corp hub transport server and not their local.  Sites and Services is setup with the correct subnets for each site.  I have verified the send and receive connectors.
    Is this scenario the best way to configure our organization or should we simply have created a second organization of their own and tried to share calendars, etc between the two?  All of our other services are centrally located so it only made sense that
    this should also work but before going live I wanted to see if this was the optimal way.  This is not a high availability or site resiliency plan.  No DAGs are used.  We are just one company with two separate very remote disjoint locations and
    even though we have a small VPN for services we would like to keep as much as possible local to that site.
    I have not been able to find information on this scenario.  Everything seems to point to SR/HA scenarios.  Any advice would be greatly appreciated.

    You can't create a second organization when the domain is in the same forest, so you shouldn't have done that.
    You're saying that SMTP messages are stuck in the queue?  That can be caused by any number of problems, but my experience is that it is most likely one of the following.  Look at the SMTP queue and see if any error code is listed, and post that
    here.
    1. In the main site, the site to which the messages are being sent, someone has modified the Default receive connector(s) in a way that the Exchange server can't connect.  The most likely issues would be modifying the PermissionGroups or RemoteIPRanges
    properties.  Best practice is to not modify the Default receive connector (except maybe to add AnonymousUsers to the PermissionGroups to allow inbound mail), and instead create a new connector for the special purpose with the connection limitations supplied.
    2. You have a firewall or relay device between the servers that's "helping" your SMTP connections (Cisco PIX firewalls are notorious for this, disable "SMTP Fixup") or breaking authentication.  The servers must be able to connect on port 25 without
    any molestation of the transactions.
    Ed Crowley MVP "There are seldom good technological solutions to behavioral problems."

  • Exchange 2010 SP3 - Can DAG member be on OS 2012 R2 STD?

    Hi guys.
    We have Exchange 2010 SP3 on 2008 r2 enterprise.
    now we are thinking about having DAG. I know that recommendations is to have the same OS on 2nd Exchange server but still is it possible to make DAG between: Exchange 2010 SP3 on 2008 r2 enterprise and on other side Exchange 2010 SP3 on 2012 R2 STD?
    with best regards,
    bostjanc

    Hi guys.
    We have Exchange 2010 SP3 on 2008 r2 enterprise.
    now we are thinking about having DAG. I know that recommendations is to have the same OS on 2nd Exchange server but still is it possible to make DAG between: Exchange 2010 SP3 on 2008 r2 enterprise and on other side Exchange 2010 SP3 on 2012 R2 STD?
    with best regards,
    bostjanc
    No. It wont let you do that. 
    http://technet.microsoft.com/en-us/library/dd638104(v=exchg.141).aspx
    DAGs are available in both Exchange 2010 Standard Edition and Exchange 2010 Enterprise Edition. In addition, a DAG can contain a mix of servers running Exchange 2010 Standard Edition and Exchange 2010 Enterprise Edition.
    Each member of the DAG must also be running the same operating system. Exchange 2010 is supported on both the Windows Server 2008 and Windows Server 2008 R2 operating systems. All members of a DAG must run either Windows Server 2008 or Windows Server 2008
    R2. They can't contain a combination of both Windows Server 2008 and Windows Server 2008 R2.
    In addition to meeting the prerequisites for installing Exchange 2010, there are operating system requirements that must be met. DAGs use Windows Failover Clustering technology, and as a result, they require the Enterprise version of Windows.
    Twitter!: Please Note: My Posts are provided “AS IS” without warranty of any kind, either expressed or implied.

  • Outlook 2010 SP1 Profile Does Not Update After Moving Mailbox Between Exchange 2010 SP2 Sites

    I am working on a large mailbox migration from one AD site to another. 
    Exchange version at both sites:Exchange 2010 SP2
    Two Mailbox Servers: MBX01 in site A / MBX02 in site B
    (There is a DAG but keeping this simple)
    Two CAS Arrays: CASA.domain.com / CASB.domain.com
    The RPCClientAccessServer property is set accordingly.  Where MBX01 is set to CASA.domain.com and MBX02 is set to CASB.domain.com
    Clients:Outlook 2010 SP1
    Scenario: I successfully move a mailbox from Site A to Site B.  The Outlook client does not automatically update its server settings to point to the new cas array (CASB.domain.com) and continues to connect to the old CAS server (CASA.domain.com).
    I have seen a few articles regarding this pointing to workarounds such as:
    - repairing the outlook profile on the client
    - delete the existing outlook profile
    - run a script to update the prf file (re-cache's email at the client)
    I am interested in knowing if anyone else has experienced this, what their solution was for a large migration and if any roll-ups or service packs have possibly fixed this problem.
    I would also like to know if you have seen this affect ActiveSync devices.  I am getting mixed results in my tests and thought it may be contributed toward different device types, mobile os versions, etc...
    I have posted this to the Exchange 2010 forum as well, just wasn't sure where to start.
    Thanks.
    Mike

    Hi,
    Seems you got several replies in the thread below that you posted in Exchange forum:
    http://social.technet.microsoft.com/Forums/exchange/en-US/68ae67c1-59f5-44bb-aadc-0aea3f72ad2d/outlook-profile-not-updated-to-new-cas-array-after-mailbox-move-between-sites?forum=exchange2010#68ae67c1-59f5-44bb-aadc-0aea3f72ad2d
    Please come back to the thread above and check if the replies are helpful.
    Since this issue is more related to Exchange, we can provide rarely assistance on this problem. If you need any help on Outlook client side, please don't hesitate to let me know.
    I would appreciate it if you could post the solution here when you found it, so that other community members who have same question in this forum will benefit from it.
    Best Regards,
    Steve Fan
    TechNet Community Support

  • Rename existing Exchange 2010 database in DAG

    Hello,
    I want to rename one existing database on our exchange 2010 server. This database is in DAG and hosting around 1000 users. So not possible to create a new mailbox database and move.
    How can I rename the database?
    After renaming it, what will happen to the Copy database on another server as it is in DAG.
    Thanks,
    Mihir

    Appreciate your response, Andy.
    To clear my doubt,
    If I am ok to reseed the passive copy, then I can follow below steps, Correct?
    --> Remove Passive copy
    --> Remove Database files and Log files on this passive server manually
    And
    "1. Then will a New database with this new name be created?"
    --> On Move database, I will mention same location, but just
    rename .edb file. So a exact copy of new database with this new name will be created. Correct?
    --> And then I can delete the old named .edb, Correct?
    Thanks.

  • Exchange 2010 AD Site Changes

    We have 2 Exchange 2010 servers.  Hub Transport/Mailbox server is at our local office.  CAS server is at a remote data center.  It is all one AD site and all domain controller/DNS servers are in the local office.
    We are now adding a domain controller with DNS to the remote data center with the CAS.  This new domain controller will also be the DC for the new AD site that will represent the data center location.
    What needs to be done to make sure adding a new AD site doesn't negatively affect Exchange?
    IP addresses are not changing.  Is there any problem with the CAS being in a different AD site than the mailbox/hub transport server?

    Hi ,
    Thank you for your question.
    What needs to be done to make sure adding a new AD site doesn't negatively affect Exchange?
    What is a new AD site?  A new sub-domain or a new BDC?
    If it is a sub-domain, by my understanding, it is important for us to make sure the DNS property of IP address point to local AD on Exchange CAS server. then Exchange CAS server will not communicate with new AD on remote site. If it is a BDC, we could add
    the IP into the property of “alternate DNS server” on Exchange CAS server. if i have misunderstanding, please be free to let me know.
    IP addresses are not changing.  Is there any problem with the CAS being in a different AD site than the mailbox/hub transport server?
    A: yes, we could do that, we just make sure all subnets could communicate without ant problem.
    If there are any questions regarding this issue, please be free to let me know. 
    Best Regard,
    Jim
    Please remember to mark the replies as answers if they help, and unmark the answers if they provide no help. If you have feedback for TechNet Support, contact [email protected]
    Jim Xu
    TechNet Community Support

  • Exchange 2010SP1 Multi-Tenant Issue with Multiple Domains

    I have an installation of Exchange 2010 SP1 with multi-tenant support enabled via the install time /hosting switch.
    Everything works well for my smaller clients. I now have a bigger client that has about 300 users and 3 domains. The users are divided roughly equally amongst the domains - ie, 3 domains each with 100 users. I've added the first domain as normal:
    $c = get-credential
    New-organization -name "Pretend Company" -DomainName domain1.com -ProgramId HostingSample -OfferId 2 -location en-US -AdministratorPassword $c.password
    After that I logged into the ECP control panel and created all the users. The migration went smoothly and has been working well for the last week. Now, it's time to add the next domain. Since the client wants all 300 users visible in the same GAL, I just
    added a domain to the organization:
    New-AcceptedDomain -Name domain2.com -DomainName domain2.com -Organization "Pretend Company"
    This is where I run into problems. When I try to create the users for domain2.com via ECP, I am able to create the user successfully, and select domain2.com from the drop down. Once the user is created however, I am able to see that although their UPN
    is [email protected], it created their email address as [email protected].
    I tried creating the users manually via EMS:
    $password = Read-Host "Enter password" -AsSecureString
    New-MailUser -UserPrincipalName [email protected] -Password $password -Name "Test User" -Organization "Pretent Company" -PrimarySmtpAddress [email protected]
    The user creates successfully and I can see the user created in the proper OU in AD. Unfortunately I can not see them in ECP nor can I see them if I do:
    get-mailbox -Organization "Pretend Company"
    This makes the management of the users very difficult to delegate, and I'm not sure that the users at domain2.com will even work.
    This brings me to my questions:
    (1) Is is possible create accounts that have different domain names in their default email addresses within the same Organization in /hosting mode?
    (2) Is this something I need to do with an EmailAddressPolicy? I read the documentation but it didn't seem /hosting friendly.

    Hi Earonk,
    Please post your issue on below forum, you will get more help from there:
    http://social.technet.microsoft.com/Forums/en-us/exchange2010hosters/threads
    Regards!
    Gavin

  • Exchange 2010 SP2: Different problems with E_ACCESSDENIED on exchange servers

    Hello All,
    I'm observing a strange problem in an AD 2008 R2 / Exchange 2010 SP2 environment:
    When creating a DAG and adding 1 or more servers to the DAG, the following error occurs:
    Summary: 2 item(s). 0 succeeded, 2 failed.
    Elapsed time: 00:00:05
    <MAILBOX SERVER 1> Failed
    Error:
    Access is denied. (Exception from HRESULT: 0x80070005 (E_ACCESSDENIED))
    Exchange Management Shell command attempted:
    Add-DatabaseAvailabilityGroupServer -MailboxServer '<MAILBOX SERVER 1>' -Identity '<NAME DAG>'
    Elapsed Time: 00:00:02
    <MAILBOX SERVER 2> Failed
    Error:
    Access is denied. (Exception from HRESULT: 0x80070005 (E_ACCESSDENIED))
    Exchange Management Shell command attempted:
    Add-DatabaseAvailabilityGroupServer -MailboxServer '<MAILBOX SERVER 2>' -Identity '<NAME DAG>'
    Elapsed Time: 00:00:02
    There are no logs created on the Mailservers, so I have no more detailed information. Where to start with troubleshooting this issue?
    Edit: BTW I already checked the local admin membership of the "Exchange Trusted Subsystem" domain group.
    Also commands like get-owavirtualdirectory give the Access Denied error (except on the CAS servers themselves).
    You know you're an engineer when you have no life and can prove it mathematically

    Hi Frank,
    The DAG is not yet populated. When inserting the first server(s) in the freshly created DAG, the error appeared.
    [PS] C:\Program Files\Microsoft\Exchange Server\V14\Scripts>Get-DatabaseAvailabilityGroup
    Name             Member Servers                                     
    Operational Servers
    IICT-DAG-002     {}
    [PS] C:\Program Files\Microsoft\Exchange Server\V14\Scripts>Get-DatabaseAvailabilityGroup IICT-DAG-002 -Status | fl
    RunspaceId                             : cc985264-fa89-48f8-8aba-c1b0c89eb097
    Name                                   : IICT-DAG-002
    Servers                                : {}
    WitnessServer                          : iict-srvp00-011.insourceict.local
    WitnessDirectory                       : C:\IICT-DAG-002
    AlternateWitnessServer                 :
    AlternateWitnessDirectory              :
    NetworkCompression                     : InterSubnetOnly
    NetworkEncryption                      : InterSubnetOnly
    DatacenterActivationMode               : Off
    StoppedMailboxServers                  : {}
    StartedMailboxServers                  : {}
    DatabaseAvailabilityGroupIpv4Addresses : {10.100.0.54}
    DatabaseAvailabilityGroupIpAddresses   : {10.100.0.54}
    AllowCrossSiteRpcClientAccess          : False
    OperationalServers                     :
    PrimaryActiveManager                   :
    ServersInMaintenance                   :
    ThirdPartyReplication                  : Disabled
    ReplicationPort                        : 0
    NetworkNames                           : {}
    WitnessShareInUse                      :
    AdminDisplayName                       :
    ExchangeVersion                        : 0.10 (14.0.100.0)
    DistinguishedName                      : CN=IICT-DAG-002,CN=Database Availability Groups,CN=Exchange Administrative Gro
                                             up (FYDIBOHF23SPDLT),CN=Administrative
    Groups,CN=InsourceICT,CN=Microsoft Exch
                                             ange,CN=Services,CN=Configuration,DC=insourceict,DC=local
    Identity                               : IICT-DAG-002
    Guid                                   : 71d5d869-03ac-4f8a-8de7-fc15bc6a0ae1
    ObjectCategory                         : insourceict.local/Configuration/Schema/ms-Exch-MDB-Availability-Group
    ObjectClass                            : {top, msExchMDBAvailabilityGroup}
    WhenChanged                            : 8-6-2012 14:35:59
    WhenCreated                            : 8-6-2012 13:35:21
    WhenChangedUTC                         : 8-6-2012 12:35:59
    WhenCreatedUTC                         : 8-6-2012 11:35:21
    OrganizationId                         :
    OriginatingServer                      : IICT-SRV003.insourceict.local
    IsValid                                : True
    You know you're an engineer when you have no life and can prove it mathematically

  • Exchange 2010 SP3 - Delayed emails with XLSM attachments...

    Running Exchange 2010 SP3 Rollup 5.  Clients running Windows 7 and Office 2010 Pro Plus SP2.  Have one specific user / client that when sending emails with an XLSM attachment around 5:30AM, the email is delayed getting to the Exchange server and
    is delayed up to 16 hours.  Unfortunately, this is a random occurrence, and not necessarily easy to duplicate.
    The Sent Items on the Outlook client reflect the correct sent time, but the Message Tracking Log on the Exchange server shows the server did not receive the email until approximately 12 to 16 hours later.
    The desktop is a shared system and this issue appears to be isolated to the user's profile, AD account, or Exchange.  I've literally blown away the users local profile and reconfigured it with no resolution.
    Any suggestions are greatly appreciated.
    Fuel

    Hi,
    Please verify whether there is any error/warning/information message left in App log. If yes, please paste the details without sensitive information.
    I suggest re-send a .xlsm attachment for testing to verify whether it delays.
    Thanks
    Mavis
    Mavis Huang
    TechNet Community Support

  • Disable SafeHTML in OWA on Exchange 2010? XML attachment with non-XML extension content gets stripped

    Is it possible to disable SafeHTML in Outlook Web App on Exchange 2010?
    We have users that receive messages with attachments that are generated by a 3rd party.
    They are XML files saved with a XLS extension.
    When opening via Outlook, Excel prompts that the content does not match the content type and asks the user if they want to open the file anyway, when opened the file does contain the data.
    When opening the file via OWA, the contents are stripped out and replaced with the text: This attachment was removed because it contains data that could pose a security risk.
    The problem is that some users exclusively use OWA and they need to be able to open these attachments.
    Thank You.

    Hi,
    You can disable the OWA SafeHTML filtering by changing changing the
    BypassOwaHTMLAttachmentFiltering option to true, for more details, please refer to the following article.
    All HTML content in attachment files of messages is run through an HTML filter when you open or save the attachment by using Outlook Web Access (OWA)
    http://support.microsoft.com/kb/958881
    Best regards,
    Belinda Ma
    TechNet Community Support

  • Exchange 2010 SP1 install fails with -1603 error

    I am getting a -1603 error when installing Exchange 2010 SP1.  Installation fails when copying files/removing old version with the following error:
    [10/01/2010 23:17:06.0823] [2] Beginning processing uninstall-MsiPackage -ProductCode:'6574fdc2-40fc-405a-9554-22d1ce15686b' -LogFile:'C:\ExchangeSetupLogs\InstallSearch.msilog'
    [10/01/2010 23:17:06.0847] [2] Removing MSI package with code '6574fdc2-40fc-405a-9554-22d1ce15686b'.
    [10/01/2010 23:17:09.0400] [2] [ERROR] Unexpected Error
    [10/01/2010 23:17:09.0401] [2] [ERROR] Couldn't remove product with code 6574fdc2-40fc-405a-9554-22d1ce15686b. Fatal error during installation. Error code is 1603.
    [10/01/2010 23:17:09.0401] [2] [ERROR] Fatal error during installation
    [10/01/2010 23:17:09.0409] [2] Ending processing uninstall-MsiPackage
    [10/01/2010 23:17:09.0411] [1] The following 1 error(s) occurred during task execution:
    [10/01/2010 23:17:09.0412] [1] 0.  ErrorRecord: Couldn't remove product with code 6574fdc2-40fc-405a-9554-22d1ce15686b. Fatal error during installation. Error code is 1603.
    Does anyone know how to resolve this?
    Thanks,
    greg

    Hi Frank,
    I've the same problem when I try to install the SP2.
    When I try to install RU 4v2, 5 or 6, then comes error 2771. So I waiting for SP2 in the hope, a full install of the SP will fix this.
    But the setup broke with the following entries:
    [12.07.2011 19:51:59.0379] [0] Setup will run the task 'uninstall-msipackage'
    [12.07.2011 19:51:59.0379] [1] Setup launched task 'uninstall-msipackage -logfile 'C:\ExchangeSetupLogs\ExchangeSetup.msilog' -ProductCode '4934d1ea-be46-48b1-8847-f1af20e892c1' -PropertyValues 'BYPASS_CONFIGURED_CHECK=1 DEFAULTLANGUAGENAME=DEU''
    [12.07.2011 19:51:59.0379] [1] Die Active Directory-Sitzungseinstellungen für 'Uninstall-MsiPackage' lauten: Vollständige Gesamtstruktur anzeigen: 'True', Konfigurationsdomänencontroller: 'LicPDC.kh-lichtenstein.local', Bevorzugter globaler Katalog:
    'LicPDC.kh-lichtenstein.local', Bevorzugte Domänencontroller: '{ LicPDC.kh-lichtenstein.local }'
    [12.07.2011 19:51:59.0379] [1] Beginning processing uninstall-msipackage -LogFile:'C:\ExchangeSetupLogs\ExchangeSetup.msilog' -ProductCode:'4934d1ea-be46-48b1-8847-f1af20e892c1' -PropertyValues:'BYPASS_CONFIGURED_CHECK=1 DEFAULTLANGUAGENAME=DEU'
    [12.07.2011 19:51:59.0410] [1] Removing MSI package with code '4934d1ea-be46-48b1-8847-f1af20e892c1'.
    [12.07.2011 19:52:04.0551] [1] [ERROR] Unexpected Error
    [12.07.2011 19:52:04.0551] [1] [ERROR] Couldn't remove product with code 4934d1ea-be46-48b1-8847-f1af20e892c1. Schwerwiegender Fehler bei der Installation. Error code is 1603.
    [12.07.2011 19:52:04.0551] [1] [ERROR] Schwerwiegender Fehler bei der Installation
    [12.07.2011 19:52:04.0613] [1] Ending processing uninstall-msipackage
    The MSI package with code '4934d1ea-be46-48b1-8847-f1af20e892c1' ist the SP1.
    Actual System: Server2008R2SP1 / Exchange2010SP1 RU3v3
    It is possible to solve this problem?
    Rene Hubert - Systemadministrator - DRK KH Lichtenstein gGmbH
    I too have this
    problem.

  • Securing publishing exchange 2010 OWA and ActiveSync with WAP 2012

    Hello,
    my client have the following environment:
    Exchange 2010 sp3
    AD 2003
    we want to secure activesync and owa by using reverse proxy. TMG/UAG life ends 2015, then we study WAP 2012 and ADFS 3.0. the difficulties is there is not enough experience feedback, specially for this environnement.
    Is there any incompatibility ?
    do you know good articles and blogs which address this issue ?
    Thanks in advance

    Are any other options available since posting in June 2014?  Specifically for securing ActiveSync connections from smartphones on the Internet.  We are running Exchange 2010 in AD 2008  
    TMG has already transitioned from mainstream to extended support.  Not only is there less support now, to my understanding there is still a licensing cost for this product.  Paying for a product at EOL seems inadvisable.
    Web Access Protocol (WAP) looked like the right choice, but to secure communications from domain users on unknown devices over the Internet requires Exchange 2013 which is "claims aware".  Exchange 2010 is not and what we are left with is
    configuring WAP in pass-thru mode, allowing unauthenticated Internet traffic into our internal network where the Exchange CAS server is. 
    Is there any Microsoft solution to authenticate the user before allowing the user's device to connect to our CAS server on our internal network.

Maybe you are looking for

  • Unable to establish AV call with Lync server 2013 from internal to external remote users

    Hi, Instant messaging is working fine When trying to video call from the internal Lan to an remote external user Video call connects for 10 seconds and then drops. This also happens between federated sites when we initiate the call Internal to intern

  • Month end closing question from a DBA

    Hi all, I am a DBA not a functional setup person/Business Analyst; so excuse me if my question is not put in business terms. We have an 11.5.10.2 that operates in US, Canada, Peru, China and Australia. Each of these have their own Set of Books. When

  • Error msg: Enter at least one condition item

    Hi SAP, I try to change (extend) rental end date but i received error msg "Enter at least one condition item": Enter at least one condition item Message no. 62226 Diagnosis No condition items with a positive amount exist. Each condition header, howev

  • Ejecting ipod from the pc

    here is what my pc states when i try to discconnect: the ipod cannot be ejected beacuse it contains files that are in use by another application. steps i took 1-safely remove hardware(results no good) 2-ejecting from i tunes(results no good) 3-going

  • Subcontracting / Job work

    Hi All, I have an issue with subcontracting / job work. We are raising a production order and from there we are receiving the purchase requisitions both for job work and subcontracting. We are issuing raw materials for production order. Now in betwee