Exchange server 2003 org decomission before DirSync with office365

Hi,
I am looking to do DirSync of passwords between local and office365 domain.  I have migrated all exchange services to office365 a couple of years ago, but still have old exchange 2003 server. 
I plan to completely decommission and remove the exchange organization.
Question is once that is done, is there any concern about using DirSync?  I thought that all attributes will sync during this process, so not sure if I could possibly be removing attributes that are needed as the exchange 2003 organization is removed,
which in turn can maybe cause sync issues with my current office365 production environment.
I do not run any type of hybrid setup, and not looking to do Single-Sign-On, I am only attempting to sync passwords with specific accounts.
Can I safely uninstall and remove my exchange 2003 organization (a single 2003 exchange server)?
Thank you

Hi,
This sounds like an ok method, (my one helpdesk technician does not manage my AD apart from password reset), since I am the only tech really to handle the AD - create users etc..
1. You mention setting exchange attributes, could you elaborate on what exchange attributes?  Since I am removing my exchange organization locally (single exchange 2003 server) I assume there will no longer be any exchange specific attributes.  By
removing the exchange 2003 server org, will I be missing any attributes in order to use AAD Sync?
2. Also, do you know how difficult or easy it is to remove AAD Sync, if I choose to simply keeping cloud authoritative?  Any concerns or potential issues you can think of?
Thank you
Robert
You extended your AD schema when Exchange was introduced.  Even if Exchange goes away, those attributes are forever defined in your forest, and will need to be populated
somehow for use with *Sync & Exchange Online. If you don't keep an Exchange Hybrid server, as mentioned above, and also don't want to use ADSIEdit, you may consider a tool such as:
Z-Hire Active Directory, Exchange, Lync, Office 365 User Creation Tool
EXCHANGETASKS 2013
As for the difficulty in removing AADSync - its really easy.  You'd just throw the server away and disable sync in your Azure AD tenant (one button).  Sounds like the main downside in your case would be:
no more password sync
you have to create users twice.  once on-prem for on-prem stuff, and again in Azure AD (o365).
Mike Crowley | MVP
My Blog --
Baseline Technologies

Similar Messages

  • When sending e-mail messages to a mail-enabled public folder that have been replicated from old Exchange Server 2000/2003/2007, Exchange Server 2010 environment mails are rejected with NDR.

    Hi, I would like to share with you issue that I’ve solved regarding mail-enabled PF that migrated from Exchange 2000/2003/2007 to 2010, I’ve searched & contacted my MVP leader – there’s no official KB regarding this issue right
    now, so I’m posting here in order to share this among others.
    Note: There’s article(s) that talked about PF replication from Exch2000/2003/2007 to 2010 – this is the same issue as well.
    Symptoms
    E-mail messages that been sent to mail-enabled public folder in Exchange Server 2010 environment rejected with the following NDR:
    “#< #5.2.0 smtp;554 5.2.0 STOREDRV.Deliver.Exception:ObjectNotFoundException; Failed to process message due to a permanent exception with message The Active Directory user wasn’t found. ObjectNotFoundException: The Active Directory
    user wasn’t found.> #SMTP#”
    Sometimes Exchange Server 2010 is documented as well Event ID 1020 on the Event Viewer with this information:
    “Log Name: Application
    Source: MSExchange Store Driver
    Event ID: 1020
    Level: Error
    Description:
    The store driver couldn’t deliver the public folder replication message "Hierarchy ([email protected])" because the following error occurred: The Active Directory user wasn't found.”
    Cause
    In an environment where Microsoft Exchange Server 2000 or Microsoft Exchange Server 2003 previously existed, and all those servers have been removed, there is a chance that an Administrative Group (First Administrative Group or another custom Administrative
    Group) remains with a Servers container, but no servers inside it.
    During replication, when the Exchange 2010 Store Driver sees the empty Servers container in Active Directory, it's expecting a System Attendant object inside the container and when it is not found the error occurs.
    Resolution
    To work around the issue, delete the empty Servers container. This can't be done through Exchange System Manager. Use the ADSI Edit tool to remove it using the following steps:
    Warning If you use the ADSI Edit snap-in, the LDP utility, or any other LDAP version 3 client, and you incorrectly modify the attributes of Active Directory objects, you can cause serious problems. These problems may require you to reinstall Microsoft Windows
    2003 Server, Microsoft Windows Server 2008, Microsoft Exchange 2010 Server or both Windows and Exchange. Microsoft cannot guarantee that problems that occur if you incorrectly modify Active Directory object attributes can be solved. Modify these attributes
    at your own risk.
    1.      
    Start the ADSI Edit MMC Snap-in. Click Start, then
    Run, and type adsiedit.msc, and then click OK.
    2.      
    Connect & Expand the Configuration Container [YourServer.DNSDomainName.com], and then expand
    CN=Configuration,DC=DNSDomainName,DC=com.
    3.      
    Expand CN=Services, and then CN=Microsoft Exchange, and then expand
    CN=YourOrganizationName.
    4.      
    You will see an empty Administrative Group. Expand the
    CN=YourAdministrativeGroupName.
    5.      
    Expand CN=Servers.
    6.      
    Verify there are no server objects listed under the
    CN=Servers container.
    7.      
    Right click on the empty CN=Servers container and choose
    Delete.
    8.      
    Verify the modification, and try to send again the E-mail to the mail-enabled public folder.
    Applies to
    Exchange Server 2010, Standard Edition
    Exchange Server 2010, Enterprise Edition
    Netanel Ben-Shushan, MCSA/E, MCTS, MCITP, Windows Expert-IT Pro MVP. IT Consultant & Trainer | Website (Hebrew): http://www.ben-shushan.net | IT Services: http://www.ben-shushan.net/services | Weblog (Hebrew): http://blogs.microsoft.co.il/blogs/netanelb
    | E-mail: [email protected]

    Sounds like you are looking in the wrong Administrative Group container which is why you are seeing your Exchange 2010 servers in there.
    When you install Exchange 2003 only you will see a container named by default as "CN=First Administrative Group" container. But this could be named anything if you changed the Organization Name on the installation when you installed the first
    Exchange 2003 server into the domain/forest. 
    You will notice that when you install Exchange 2010 part of the AD setup is to create a new configuration container and is named by default "CN=First Administrative Group (FYDIBOHF23SPDLT)".
    So it sounds like you are not looking in the right location within ADSIEdit. 
    You may find the following article also helpful for this issue which is the same resolution:
    http://blogs.technet.com/b/sbs/archive/2012/05/17/empty-cn-servers-container-causing-issues-with-public-folders-on-small-business-server-2011.aspx
    I recommend though that you ensure your Exchange 2003 servers are fully uninstalled or no longer present in your environment before you go deleting the Servers container though.. The following Microsoft article will help with this:
    http://technet.microsoft.com/en-gb/library/gg576862(v=exchg.141).aspx

  • A problem with Win 7 Pro, Outlook Web Access based on Exchange Server 2003, and two different domains

    Dear Microsoft Support,
    As mentioned in the title,
    I have two domains. One is Domain A at HQ. The other one is Domain A at branch office. A laptop having Win 7 Pro OS is a client of Domain A. The Domain A has Exchange Server 2003. Users of Domain B get connected to Exchange Server for email services. In
    all clients of the Domain B, IP address of the email server added in C:\Windows\System 32\drivers\etc\host file.
    Whereas in the clients of Domain A it was not done, because all the servers including the email server belong to the Domain A.
    Now, a user with Domain A's client (it is a laptop) came to Branch office and wanted to access the Outlook (using Outlook Web Access). since there is no IP address added in the Host file of the laptop, connectivity to email is not possible. When I try to
    add the IP address, I was not able to do so due to Domain A's security reasons.
    So, let me know, is there a way out to add the IP address in the host file of the Domain A's client.
    Thanks in advance.
    Ravi Sekhar Modukuru

    I would suggest adding the mailserver address in Domain B's DNS. Would that be possible?
    I agree. The correct solution in this case (since it appears you already have a two-way Domain Trust in place) is to properly configure DNS in Domain 'B' to be a secondary of Domain 'A' and completely eliminate the need to maintain the HOSTS file.
    Lawrence Garvin, M.S., MCSA, MCITP:EA, MCDBA
    SolarWinds Head Geek
    Microsoft MVP - Software Packaging, Deployment & Servicing (2005-2014)
    My MVP Profile: http://mvp.microsoft.com/en-us/mvp/Lawrence%20R%20Garvin-32101
    http://www.solarwinds.com/gotmicrosoft
    The views expressed on this post are mine and do not necessarily reflect the views of SolarWinds.

  • Portal integration with Exchange server 2003 issues.

    Hello,
    We are using NW04s EP 7.0 SP16 and Exchange server 2003. We are trying to perform OWA and Groupware integration. Both the servers are in the same domain.
    I have followed all the steps in the notes and documents available there in SDN. There are few issues:
    1) The latest KerbMap filter has been configured in Exchange backend server. SAP note 785343 says that the exchange frontend server needs to be configured for anonymous authentication to enable pass-through authentication. But doing this breaks the form based authentication in exchange server, and it also poses security risk when the backend exchange server is behind the firewall. How do we enable pass-through authentication so that the exchange frontend passes the mysapsso2 cookie to the exchange backend server?
    2) When I try to create an appointment or try to view the appointments, it gives an error message saying " No logon data found for system Exchange". The Exchange system has been configured for SAP Logon Ticket, and the user mapping fields were left empty. Why should it prompt for user mapping when the logon method is "SAP Logon Ticket"?
    There are many documents out there, but none is the latest with clear steps. Can anyone point me in the right direction please?
    Thanks,
    ~Yasin

    As far as I remember, when Exchange 2003 is installed on a Domain Controller, it uses the local DC as a GC. You need to set back the 2003 DC as GC and restart it.
    I believe, you are aware that demoting/promoting a DC with Exchange server on it is not supported by MS. The best approach is to:
    Introduce an Exchange 2010 member server
    Move all resources from Exchange 2003 to Exchange 2010
    Decommission Exchange 2003
    Demote the 2003 DC
    Step by Step Screencasts and Video Tutorials

  • Anybody using MBA OSX able to use "Notes" to Sync with the notes located on a exchange server 2003 pls?

    My company is using an Exchange Server 2003 and Im using both an Iphone 5s and a MBA OSX.
    All Exchange features are seamless on Iphone (mail, contacts, alendar AND NOTES)
    On my laptop MBA:
    - I used to use Outlook for mAc in which the notes were working but I had to go away from this (issue rebuilding too often and incompatibility with Wrikes etc.)
    - so I now use Mail, Ical, Contacts and ... I wish Notes! - but I cant get Notes to pick up the exchange server notes ... no error message just nothing happens (yes the account exchange is set up for all features and Notes is checked) ... Im puzzled - Am I alone experiencing this please?
    Thanks community!
    Seb

    correction: It's SBS 2011 running a strip down version of exchange 2010 ... and my MacBook Air Notes Application wont sync the notes with exchange ... ;-(((

  • Can't sync IMAP inbox with Exchange Server 2003

    Since Lion doesn't work with Exchange Server 2003, I set up an IMAP account in Outlook 2011 via Davmail for myself and a colleague on our laptops. This has worked for my e-mail account (syncs on multiple computers, including one running Exchange directly, and with my iPad's mail client), but not for my colleague.
    For some reason, my colleague's inbox receives pushes from the server, but won't send back changes made in Outlook. Messages that have been read remain unread; deleted e-mails go into what is purportedly the server's trash in Outlook 2011, but remain in the inbox on the server. Changes made on the IMAP on the laptop also don't sync to my colleague's iPhone.
    Our configuration is the same.
    Any ideas? Could it be on the server side?
    Thanks!

    I feel your pain. I also am a lone Mac user in an entire building full of PC robots, and the IT people haven't got a clue.
    I've been trying to get Mac mail working with the Exchange server here, but it's just not happening. I've managed to get Entourage working though, which is far from ideal but significantly better than the web-based version of Outlook that I'd been having to use up till now.
    For entourage, then yes - the incoming and outgoing servers are the same. You may need to ask your recalcitrant IT people which port numbers to use, but give it a whirl anyway.
    Best of luck,
    Boris
    UK

  • Exchange Server 2003 SP2 - Forest and Domain Functional Level Limitations

    Hi All
    Bit of a legacy question and theres not much clarity out there..
    I need to confirm the highest DFL and FFL Supported by Microsoft for Exchange 2003 SP2?
    We currently have a mix of 2003 R2 and 2008 R2 domain controllers with the FFL and DFL currently set at 2003 R2.
    The plan is to move to Exchange 2010 in the very near future, so the question is do we need to wait until we upgrade to Exchange 2010 Before upgrading the DFL and FFL to 2008 R2?
    From what Ive read we will need to complete the Exchange upgrade first before moving forward with the functional level upgrades..
    Thanks in advance
    Bull

    Hi Bull,
    As Ed mentioned, Exchange server 2003 and Exchange 2010 support Windows Server 2003 domain functional level and Windows Server 2003 forest functional level, also supported in higher environment.
    More details about it, please refer to “Supported Active Directory environment” section:
    http://technet.microsoft.com/en-us/library/ff728623(v=exchg.150).aspx
    Note that we cannot add new DCs which are the less version of Windows Server
    cannot be added to the domain or forest. More details about
    the Impact of Upgrading the Domain or Forest Functional Level, for your reference:
    http://blogs.technet.com/b/askds/archive/2011/06/14/what-is-the-impact-of-upgrading-the-domain-or-forest-functional-level.aspx
    Best Regards,
    Allen Wang

  • Snow Leopard-Exchange Server 2003-Entourage 2008 (12.2.1)

    +I have one final question before I upgrade to Snow Leopard.+
    I currently run a 2.8 GHz Mac Pro, Leopard 10.5.8, Entourage 2008 (12.2.1) using Exchange server 2003. Everything is happy and works well.
    I understand that I won't be able to use the new Snow Leopard built-in Exchange Server support.
    *But, if I upgrade to Snow Leopard...will everything stay happy with what I've been running?*

    There are connectivity issues between Exchange Server 2003 and Exchange accounts in Entourage 2008 running on Snow Leopard. These connectivity issues are also evident via web-based email (Safari & FireFox) on Snow Leopard and Exchange Serve 2003.
    You will eventually loose connection to Exchange Server 2003. Restarting your computer will solve the problem temporarily.
    POP accounts appear to work fine in this environment.

  • ICal and Exchange Server 2003

    Hello from Barcelona,
    I am a new mac user trying to sync iCal with Exchange Server 2003. I have followed all instructions regarding domain, user name, password and URL address but it does not work. The last answer received was "account info not found" & "“HTTP/1.1 440 Login Timeout”. Incredible but when using the program AddressX (downloaded from internet) with the above mentioned configuration...it works and can get my company's global book address.
    Just to make sure I am following all "mac" rules. What I am using is:
    Domain/UserName
    Password
    https://company.com/exchange/User.Name
    Am I missing any important thing? Please help!!
    Thanks in advanced!!

    There are several discussions regarding this same topic on the Apple forums and elsewhere. None of them have solved the problem. This seems to be an issue that has been around for a long time but never addressed by Apple or Microsoft. From some simple tests that I have done, it appears the the Microsoft Exchange Server is not interpreting the iCal event (.ics extension) properly. I have seen discussions saying that Apple is not formatting the event properly or is using a newer standard that MS Exchange does not support. I believe it is the later as I can make the event work properly without any software changes but I have to do some steps manually. Here is how I can make it work and why I believe something is wrong in MS Exchange:
    - create event in iCal and add an Outlook user
    - send the event/email (ignore this email on the PC as it does not work)
    - open the just sent email and save the attached iCal event
    - find the saved iCal event and add a letter to the extension such as ".icss"
    - (Note: I don't know if there is a way to rename an attachment already in a message)
    - attach this renamed event to a new message and send it to the Outlook user
    - the Outlook user must open the message, save the attachment and rename it back to ".ics"
    - double clicking / opening this renamed file now works perfectly in Outlook
    Now, if I could only automate some of these steps on the Mac before I send the message would be very helpful. This is not a great solution but I use it for events that I want to sync between my home Mac and my office PC.
    Because the renamed attachment (.icss) works through Exchange (by ignoring it), I am lead to believe that MS Exchange will interpret an ".ics" extension and mess up the handling of it for some reason. Microsoft is never one to follow standards very carefully or adopt them very quickly. Our company is using Exchange 2003 so maybe that is part of the problem as it is an older version.

  • Microsoft Exchange Server 2003 and Windows 8 Compatibility

    Is there a fix or workaround for accessing email via Outlook 2013 (Windows 8) when your company uses Microsoft exchange server 2003 and has not plans on upgrading it any time soon. I am a remote employee so I am the only one that has this problem in the
    company. I can access email through an owa account but it's a pain. I tried to set up a rule to have all incoming mail forwarded to my gmail account in Outlook 2013, but that did not work. Any other ideas?

    If server has enabled ActiveSync you can use Windows 8 Mail Client - works almost like Outlook.
    AFAIR Outlook 2013 can't work with Exchange 2003.
    Regards, Konrad Sagala, MCT, MCSE+M, MCITP: Exchange 2007/2010, Lync 2010, Office365, Windows 2008, Virtualization

  • Iphone 3G, Exchange Server 2003 and NOT sending "Read Mail" receipts

    I have a 3G Iphone that syncs with Exchange Server 2003. I do NOT want people to see when I read or delete their emails so I have my Outlook account set up that way. It works from my desktop, however, my Iphone still triggers notifications saying whether I read a message or deleted without reading. I haven't found a way to change this on the phone - has anyone else?
    Sorry to repost this question, but the first back in March never got any replies, so support suggested I try again. Thanks!

    http://davmail.sourceforge.net/osximapmailsetup.html
    http://davmail.sourceforge.net/faq.html
    http://davmail.sourceforge.net/macosxsetup.html

  • Microsoft Exchange Server 2003 Small Business Server

    Has anyone been successful syncing email with a MS Exchange Server 2003 Small Business Server?
    My IT guy has tunred on IMAP, but still no luck. Just get a warning message that the iPhone cannot connect to the server.
    Thanks.

    Turning IMAP on is the 1st step. IT will also need to open that port (143) on the firewall.

  • Incoming email - Routing rules on exchange server 2003

    I am configuring SAP system to receive emails as per note 455140. We currently have only one client and have updated necessary profile parameters including setting SMTP port to 25 for incoming mails. We have specified our enterprise exchange server 2003 as the mail server in SCOT transaction and are able to send out emails from SAP without issues, but cannot receive emails in SAP.
    Following note 607108, I am able to receive emails in the SAP system using telnet test (by passing mail server), thereby I believe all relevant configuration settings in SAP system have been correctly maintained. Now, if I try to send an email to SAP user from another SAP system or Microsoft Outlook or Internet, these emails are not being received in SAP. No inbound traces are generated in SAP since the mail has not been received by SAP.
    As part of the config, our server admins have set up a rule on mail server to forward specific emails to SAP system. Does anyone have any insight into what might be the issue here? Also, if someone can provide links/directions on how to setup routing rules on exchange server 2003 to forward specific requests to SAP system (I believe this is where our issue is).
    Thanks!
    Fahad

    Hello Markus,
    By specific, I meant emails addressed to specific users need to be forwarded to SAP. Instead of specifying *ATcompany.com --> WebASHost:25000, we put in a rule userATcompany.com --> WebASHost:25000
    Based on your response, I asked SAP support whether there is such restriction when SU01 email address and exchange email address are same, exchange will not forward to SAP. Below is there response
    "SAPconnect like most mail platforms route mails via the email address.
    SAP recommends the following:-
    UserATClient.SID.company.com
    I know that a DNS entry will have to be written for this to be routed
    to your Exchange server for relay into SAP.
    The only other recommendation is to use the local part of the mail
    address to route the mails. This will not require an external DNS
    entry but every new user will have to be updated in Exchange.
    User.client.sidATcompany.com
    There are no other way of correctly routing mails other than these
    methods. Thank you."
    Now SAP says when email addresses are same and if we put in a rule based on local part of the mail, it should still forward.
    Since the issue is through exchange, SAP will not provide further support to resolve this and we cannot go with sub-domains currently due to business requirements.
    Any suggestions.
    Thanks,
    Fahad

  • Steps to restore a failed exchange server 2003

    If I have a recently taken full backup of my failed server what are the steps to restore it.
    I mean, After installing OS, then may I have to create the domain or restoring full backup creates domain automatically?

    Hi,
    Firstly, I’d like to explain, if you want install the Exchange server on the server you have installed OS, I recommend you just add the server into domain and create the domain on another server. Because it’s not recommended to install Exchange sever on
    DC:
    http://technet.microsoft.com/en-us/library/ms.exch.setupreadiness.warninginstallexchangerolesondomaincontroller(v=exchg.150).aspx
    And here are some references about restoring Exchange server:
    http://support.microsoft.com/kb/258243
    http://www.msexchange.org/articles-tutorials/exchange-server-2003/high-availability-recovery/Exchange-2003-Backup-Restore-NTBACKUP.html
    Best regards,
    Angela Shi
    TechNet Community Support

  • Compatibility Exchange Server 2003 SP2 and Domain controllers Windows Server 2008 R2

    Hi all, I have this scenario:
    - Two Domain Controllers Windows Server 2003 R2 SP2
    - Two mail servers Exchange Server 2003 with the following version:
      6.5 (Build 7638.2 Service Pack 2)
    I want to upgrade my domain controllers to Windows Server 2008 R2.
    My question is whether exchange Server 2003 6.5 (Build 7638.2 Service Pack 2) is supported with Domain Controllers Windows Server 2008 R2.
    Can you tell me some official Microsoft website where this reflected?
    regards
    Microsoft Certified IT Professional Server Administrator

    Exchange Server 2003 SP2 supports DCs running Windows Server 2008 R2. These DCs should be RWDCs and not RODCs:
    Exchange 2003 SP2 will now be supported against writeable Windows Server 2008 R2 Active Directory Servers.  Additionally, with the General Availability of Exchange Server 2010, and those looking to standardize on Windows
    Server 2008 R2 we have enhanced the supportability of forest and domain functional levels up to Windows Server 2008 R2.  This change is effective immediately on Exchange 2003 SP2.
    Reference: http://blogs.technet.com/b/exchange/archive/2009/11/30/3408893.aspx
    This posting is provided AS IS with no warranties or guarantees , and confers no rights.
    Ahmed MALEK
    My Website Link
    My Linkedin Profile
    My MVP Profile

Maybe you are looking for

  • Cell border

    This may sound like a really silly question that has a simple answer, but is there anyway of adding a border to one cell instead of a whole table in Dreamweaver MX? Thanks Lucy

  • Display archive directory status in DB12

    Dear Experts,                When i click on Archive directory status   in DB12.It shows the "unknown" status.Please tell me   What can be done to see the free space.                       We are running SAP in HP-UX on oracle    9.2.0.2. Thanks in a

  • PHOTOSMART 370 WONT PRINT FROM MY LAPTOP

    i WAS ABLE TO PRINT PICTURES FROM MY MEMORY CARD ON MY CAMERA HOWEVER WHEN TRYING TO PRINT PICTURES SAVED ON MY COMPUTER NOTHING HAPPENS. i HAVE IT PLUGED INTO WALL FOR POWER AND INTO LAPTOP WITH A USB CABLE. WHEN i CLOCK ON A PICTURE AND HIT THE PRI

  • Validate from List property of dynamically attached LOV

    Dear Oracle Gurus, I have multi record block , the fields are Argument_name,Argument_Code ,argument_lov displaying two fields . data is populated at run time user has to input for the argument_value according to the argument_name displayed it may loo

  • How do i wipe all the files and information on my macbook air?

    how do i wipe all the files and information on my macbook air?