Lync 2013 Hybrid deployment with resource forest scenario on-premise

Hi there,
Im starting to deploy this scenario of Lync on-premise in resource forest with Lync Online:
I´am not finding any documentation about this specific scenario. I wish to know how the flow between forests will be to have users in lync online and users on premise.
Thank you very much in advance for your help.
Joaquin Gonzalez

Hi Joaquin,
You need to deploy Microsoft Forefront Identity Manager (FIM) 2010 to manage the life cycle of user accounts.
In a resource forest topology, one forest is dedicated to running server applications, such as Microsoft Exchange Server and Lync Server. The resource forest hosts the server applications and a synchronized representation of the active user object, but it
does not contain logon-enabled user accounts. The resource forest acts as a shared services environment for the other forests where user objects reside. The user forests have a forest-level trust relationship with the resource forest. When you deploy Lync
Server in this type of topology, you create one disabled user object in the resource forest for every user account in the user forests. If Microsoft Exchange is already deployed in the resource forest, the disabled user accounts might already exist. A directory
synchronization product, such as MIIS, Microsoft Forefront Identity Manager (FIM) 2010, or Microsoft Identity Lifecycle Manager (ILM) 2007 Feature Pack 1 (FP1), manages the life cycle of user accounts. When a new user account is created in one of the user
forests or a user account is deleted from a forest, the directory synchronization product synchronizes the corresponding user representation in the resource forest.
Click the links below for more information.
Supported Active Directory topologies in Lync Server 2013
http://technet.microsoft.com/en-us/library/gg398173.aspx
Windows Azure Active Directory Connector for FIM 2010 R2 Quick Start Guide
http://technet.microsoft.com/en-us/library/dn511002(v=ws.10).aspx
Hope it can be helpful.
Best regards,
Eric

Similar Messages

  • Is ADFS mandatory for Lync 2013 Hybrid Deployment?

    We alreadys have Lync 2013 Onpremise.
    We now wish to do a Lync Hybrid setup with O365 Lync Online but wish to know the following.
    While doing a Lync Hybrid setup, is deploying ADFS mandatory? We ask this because the new DirSync tool has the ability to Sync users password and thus we can avoid deploying ADFS/ADFs proxy/ADFS farm etc, thus reducing Onpremise
    complextities. We dont care about SSO as far as users can Logon Onpremise or Online using their same AD password.
    If we can do a Lync2013 hybrid setup without ADFS, then can we later have our Lync 2013 Hybrid setup to federate with our partners domain?

    yes, read it too quick. it happens.
    check these two resources:
    http://immencloud.wordpress.com/2013/06/03/office-365-dirsync-with-password-sync/
    http://blogs.technet.com/b/educloud/archive/2013/06/03/new-azure-active-directory-sync-tool-with-password-sync-is-now-available.aspx
    in short, if you are happy without a true SSO experience and other limitations described in the blogs, then you should need no AD federation.

  • Migration From Exchange 2010 Hybrid to Exchange 2013 Hybrid Deployment

    hi,
    I have existing Exchange Server 2010 Hybrid Deployment. Planning to migrate to Exchange 2013. However, while schema update, i am facing some errors/warnings as can be seen in attached screenshot. 
    I have already checked and current functional level in DC is Windows Server 2003. What could be the best steps to troubleshoot the problems and proceed further with Exchange 2013 installation?
    Thanks

    Hi Muhammad
    Can you please give few more information about your environment  so that people around here can help you out
    I have existing Exchange Server 2010 Hybrid Deployment - Do you have Exchange 2010 and Office 365 in a
    hybrid setup now ?
    Are you trying to upgrade your on premise Exchange 2010 servers to Exchange 2013 ?
    Or Are you trying to migrate your on premise Exchange 2010 to a different forest to Exchange 2013 ?
    You can try the below suggestions-
    I would better suggest you to follow Microsoft Exchange Server Deployment Assistant - http://technet.microsoft.com/en-us/office/dn756393.aspx
    Also i would recommend you to check the prerequisites for hybrid deployment with office 365 
    http://technet.microsoft.com/en-us/library/hh534377(v=exchg.150).aspx
    Cheers !!!
    Remember to mark as helpful if you find my contribution useful or as an answer if it does answer your question.That will encourage me - and others - to take time out to help you Check out my latest blog posts on http://exchangequery.com Thanks Sathish
    (MVP)

  • Auto-mapping of shared mailboxes in a resource forest scenario

    In a resource forest scenario you assign full access to a shared mailbox using:
    Add-MailboxPermission -Identity SharedMailbox -User AccountForestDomain\UserID -AccessRights FullAccess
    This provides the user in the account forest full access, but it will NOT auto-map the shared mailbox in Outlook.
    If you use the command:
    Add-MailboxPermission -Identity SharedMailbox -User UserID -AccessRights FullAccess
    and UserID is the disabled account of the linked mailbox in the resource forest then the user in the account forest does not have the necessary permission to
    open the mailbox, but the auto-mapping of the mailbox in Outlook works.
    You have to use both commands to have the auto-mapping feature and have access to the shared mailbox.
    This looks like another issue of the auto-mapping feature. The intention of the feature is good, but the way it was implemented can be improved.
    How do you configure full access to shared mailboxes in a resource forest scenario?

    Hi J-H,
    Because i don’t have such a lab environment, so I am unable to do a test.
    Now let’s separate the issue.
    1. The first issue is
    [email protected]
    unable to auto configure outlook profile.
    I suggest you
    changing the user’s attributes in the account forest, does it work?
     2. The second issue is
    [email protected] unable to open a shared mailbox in the resource
    forest.
    At first, I suggest you create a shared mailbox in resource forest with this command.
    New-Mailbox -name
    <name> -Database <Database name> -OrganizationalUnit Users –UserPrincipalName
    <UPN value, example: [email protected]> -<ResourceType: Room, Equipment or Shared>
    Managing
    Resource Mailboxes in Exchange Server 2007 (Part 1)
    Then test if you can log on the shared mailbox via outlook.
    If yes, then grant full access right for
    [email protected]
    to [email protected]
    Resource:
    Shared mailbox
    permission in resource forest with linked users
    Manage Full Access Permissions
    Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.

  • Lync 2013 FE pool with two server limitions

    Hi,
    I have some query about Lync 2013 FE pool with two FE servers.
    1. if I deploy two servers in the one FE pool so what happen if one fe server down ?
    2. will windows fabric work?
    Thanks.

    I don't completely agree with this. I have built a few environments with only 2 servers in the Front End pool (despite recommending that three be deployed) 
    1. Anyway in the event that one FE fails, users are temporarily disconnected and then the client will re-sign them in to the second server.
    2. Two servers is supported, but not recommended. See this link (it also contains how to handle two servers - scroll to bottom) http://technet.microsoft.com/en-ca/library/gg412996.aspx.
    The biggest issue with only having two servers is losing quorum. If both servers are shutdown at the same time, you can run into issues starting them back up. (it is recoverable by resetting the fabric/quorum, but it's a pain)
    If this helped you please click "Vote As Helpful" if it answered your question please click "Mark As Answer" | Blog
    www.lynced.com.au | Twitter
    @imlynced

  • Exchange 2013 Hybrid Deployment, on-premise to multiple Office 365 tenants

    Hello, we are in the early stages of planning an Exchange 2013 hybrid deployment for a federation of education organisations.
    We are planning to use a single on-premise Exchange organisation for staff mailboxes across all member organisations, each member already has it's own Office 365 tenancy for students, which we would like to maintain if possible.
    My question is, is it possible (and supported) for an Exchange hybrid deployment with a single on-premise organisation with multiple Office 365 tenants, my understanding is that only a 1:1 deployment is supported, can somebody confirm or clarify this ?
    Thanks

    I think if you have different AD sites then you can install the DirSync or ADFS for each of them and have one way replication. I 'd aks this question to Office365 Forum and support.
    Where Technology Meets Talent

  • Lync 2013 OCT deployment on machines with Office 2010. Installation Failure

    Hi,
    In our environment, we have Win7, Office 2010 x86. (no plans to upgrade all of Office to 2013 as yet)
    I'm trying to deploy Lync 2013 x86, and have packaged an MSP using "setup /admin" for later deployment via SCCM.
    Now I know there are no problems running Lync 2013 with Office 2010 as it works fine if you manually install.
    Strange thing is, when I try running the setup with MSP for silent install, it runs silent and all looks well although all the Office Tools shortcuts are created and there are files under the Program Files folders for Office\15.0 as expected
    but not Lync itself. ie: no lync.exe file or shortcuts.
    Reviewing the setup log doesn't show any obvious errors that I can tell.
    Also after this, if I go through the "Add/Remove Components" under Uninstall Programs\Lync 2013, and I can see in there that it DOES already show Lync as being installed, if I just click continue, it runs through the setup process and
    then Lync will be installed
    I've also tried this same process using the Full "Office Pro Plus 2013" and only select Lync to install and the same thing happens.
    Has anyone else come across this issue or could point me in the right direction.
    For the OCT (setup.exe /admin) the only settings I've changed from defaults are:
    - Filled in the Organisation name
    - Set KMS licensing, display level to none and suppress modal
    - some regkeys for some default settings for GalDownloadInitialDelay, ShownFirstRunOptin
    - Force on Lync (Run from My Computer)
    I'm running "setup.exe /adminfile Lync_x86.MSP" in my case to test this MSP.

    I had the same issue. As soon as I updated to the latest Admin admx/opal files, it worked great.
    Cheers,
    JeffCSP
    This issue was introduced when SP1 was released, and is detailed here:
    http://blogs.technet.com/b/odsupport/archive/2014/03/21/lync-2013-and-onedrive-for-business-are-not-installed-when-installing-office-2013-with-service-pack-1.aspx
    (it remains uncorrected by MSFT :(
    Don
    (Please take a moment to "Vote as Helpful" and/or "Mark as Answer", where applicable.
    This helps the community, keeps the forums tidy, and recognises useful contributions. Thanks!)

  • Lync 2013 client deployment via SCCM with silent uninstall of Communicator / Live Meeting / Plugin

    Hi
    We are rolling out Lync 2013 across our org to many remote sites and are wondering the best approach for this.
    We hope to leverage our SCCM, but so far we've only been installing Lync manually in our local test group.
    I noticed that when installing Lync, it doesn't remove Communicator, Live Meeting, or the Live Meeting plugin for Outlook though.
    Ideally, we would want to be able to push Lync 2013 client (standalone version, not Office 2013 Suite) via SCCM as well as uninstall Communicator 2007 R2, Live Meeting 2007 and Conferencing Add-in for Microsoft Office Outlook, all silently. Whether this
    can be done while the user is logged in and using Outlook/Communicator, I am unsure (probably not), so doing this overnight with users logged off but machines on would probably work best.
    Is there any documentation / guides from MS or other blog sites that have gone through this same process? From the searching I've done, it doesn't seem to be too common for a large deployment / jump from OCS 2007 to Lync 2013 on-premise.

    Hi,
    refer to this article it might help
    http://social.technet.microsoft.com/Forums/lync/en-US/cf9ca58c-b9e8-465c-afb4-ed3992092f81/lync-2013-client-silent-installation
    also did you try using Group Policy?
    http://blogs.technet.com/b/mir/archive/2011/06/04/how-to-automate-lync-client-2010-deployment-in-multi-architect-environment-using-active-directory-group-policy.aspx
    hope this help
    If you find this helpful
    please click "Vote as Helpful" if it answered your question please click "Mark as Answer"
    Mostafa Eltohamy
    Blog: http://Lyncdude.com  Twitter:
      LinkedIn:
      XING:

  • Is Lync 2013 perfectly compatible with Office 2010?

    Microsoft Office 2010 and Lync 2013 are two diferrent instances, but they use some common elements.
    In our company we have over a hundred MS Office 2010 licences and we dont need/afford to change them all to 2013. Now we want to install Lync 2013 and I wonder if there could be compatibility issues or, if Lync 2013 can modifiy the common files they use,
    so that certain functions in Office 2010 will not be available or not work properly.
    Is there a risk of this happening or they can work together "in complete harmony"? This is very important to me and I cannot afford to make a mistake. I would appreciate any help. Thank you.

    Hi Cristi,
    Checkout these Lyncs on compatibility and interoperability:
    Lync 2013 Compatibility http://technet.microsoft.com/en-us/library/gg412817.aspx
    Client Interoperability http://technet.microsoft.com/en-us/library/jj204672.aspx
    As far as having Lync 2013 & Office 2010 on the same PC, largely it SHOULD be ok and I've not had many issues. The exception to this was on a recent Citrix deployment, where for some reason running Lync 2013 was causing the Office 2010 instance to rerun
    everytime it was started. All desktops were ok though.
    My suggestion is to make sure you thoroughly test with every scenario that you can think of before rolling out to the masses.
    If this helped you please click "Vote As Helpful" if it answered your question please click "Mark As Answer" | Blog
    www.lynced.com.au | Twitter
    @imlynced

  • Exchange 2013 Hybrid Deployment issues.

    Hello.
    i have an issue when configuring Exchange hybrid deployment in my environment.
    when i complete the Exchange hybrid wizard and OAuth is finished our exchange environment will not receive emails from the "internet" as in senders outside the company.
    mail will can be sent out and will flow between internal users.
    when i check the message trace on 365 the emails were failing with the following error.
    Users were also getting a bounce back saying 
    Diagnostic-Code: smtp;550 5.4.1 [[email protected]]: Recipient address rejected: Access denied
    i wondered if it had anything to do with the MX record on our public DNS, i changed this to the one recommended by O365 domain DNS assistant, but this made no odds,
    it looks like it could be a receive connector issue however i am new to exchange so i am still learning.
    the only way to fix the issue was to run Remove-Hybridconfiguration on the Exchange 2013 server, when this finished and few moments had passed mail began being received from the internal again.
    Any Suggestions on what could be caused 
    many thanks

    Hello.
    i have an issue when configuring Exchange hybrid deployment in my environment.
    when i complete the Exchange hybrid wizard and OAuth is finished our exchange environment will not receive emails from the "internet" as in senders outside the company.
    mail will can be sent out and will flow between internal users.
    when i check the message trace on 365 the emails were failing with the following error.
    Users were also getting a bounce back saying 
    Diagnostic-Code: smtp;550 5.4.1 [[email protected]]: Recipient address rejected: Access denied
    i wondered if it had anything to do with the MX record on our public DNS, i changed this to the one recommended by O365 domain DNS assistant, but this made no odds,
    it looks like it could be a receive connector issue however i am new to exchange so i am still learning.
    the only way to fix the issue was to run Remove-Hybridconfiguration on the Exchange 2013 server, when this finished and few moments had passed mail began being received from the internal again.
    Any Suggestions on what could be caused 
    many thanks
    Make sure the accepted SMTP domains in the Office 365 EAC are set to Internal Relay rather then Authoritative.
    Twitter!:
    Please Note: My Posts are provided “AS IS” without warranty of any kind, either expressed or implied.

  • Lync 2013 Cumulative updates with coexistence 2010

    Hello 
    I am pretty new lync admin, i have successfully done a coexistence with 2010 and 2013
    I just need clarification on the steps for a 2013 standard edition cu updates. 
    From the site http://support.microsoft.com/kb/2809243  I am seeing that I need to 
    1) run LyncServerUpdateInstaller.exe
    2)run Install-CsDatabase -ConfiguredDatabases -SqlServerFqdn SE.FQDN -Verbose
    3) Do not run Install-CsDatabase -CentralManagementDatabase until after full 2013 migration 
    4) Enable the Mobility service, run the following cmdlet:
    Enable-CsTopology
    5) Run %ProgramFiles%\Microsoft Lync Server 2013\Deployment\Bootstrapper.exe
    Just need those steps confirmed and..
    1) Just to confirm that I dont need to worry about output of Get-CsPoolUpgradeReadinessState command
    2) We dont have Mobility service, do I still need to run Enable-CsTopolgy for Standard edition?
    Thanks !

    Thank Iain 
    Just to confirm it is lync 2013 CU updates I am trying to perform on standard pool 
    When i run the CsPoolUpgradeReadinessState 
    I get State:insufficientActiveFrontEnds and IsReadForUpgrade True
    According to the update notes, they only speak of running cspoolupgradereadiness on Enterprise edition pool. 
    So i just wanted to know if the output of cspoolupgradereadinessState can be ignored or concerned about for the updates. 

  • Lync 2013 Step 3 - Prepare Current Forest Error

    Hello All;
    We are trying to upgrade with a side by side migration but Both in Server 2012R2 and Server 2008R2 SP1 - I'm getting stuck at the same error.
    Our current environment;
    Domain.net
       company.domain.net
       farm.domain.net
    Lync 2010 installed & running with user interaction on farm.domain.net.  "Lync2010.farm.domain.net"
    Lync 2013 is trying to install on farm.domain.net as well "Lync2013.farm.domain.net"
    I get to Step 3 running the setup on "Lync2013.farm.domain.net" and get the error:
    Error: Computer is not a member of the root domain. For security reasons, this action must be run on a root domain computer.
    ▼ Details
    └ Type: DeploymentException
    └ ▼ Stack Trace
        └  
    at Microsoft.Rtc.Management.Deployment.LcForest.PrePrepCheck()
    at Microsoft.Rtc.Management.Deployment.LcForest.PrepareForest()
    Now I've tried the "Enable-CsAdForest -GroupDomain weblynx.net" in both admin powershell and admin lync powershell. 
    http://support.microsoft.com/kb/2549544/en-us 
    Googling is basically telling me the same thing but getting the same error. 
    Any Ideas? 

    Are you running this part of the deployment from the root domain (domain.net) or just farm?  You'll need to run this step separately in the root, even if you're not deploying Lync servers there. 
    Please remember, if you see a post that helped you please click "Vote As Helpful" and if it answered your question please click "Mark As Answer".
    SWC Unified Communications

  • Lync 2013 Edge deployment

    Hi Guys,
    I am deploying Lync 2013 with edge server but i am having some problem running the services i was able to import already the CMS from the FrontEnd Server you can see from the image bellow for more details:
    Your help would be a great help for me.
    Thanks.

    Hi All,
    I already manage to Import the Central Management Store to the Edge server.
    Please see more information bellow every time i run the "Setup or Remove Lync Server Components" 
    > Bootstrap-CsComputer
    Logging status to: C:\Users\lync.admin.VMEDGE\AppData\Local\Temp\BootstrapFull-[2014_03_08][07_49_45].html
    Checking prerequisites for bootstrapper...
    Checking prerequisite WMIEnabled...prerequisite satisfied.
    Checking prerequisite NoBootstrapperOnBranchOfficeAppliance...prerequisite satisfied.
    Checking prerequisite SupportedOS...prerequisite satisfied.
    Checking prerequisite NoOtherVersionInstalled...prerequisite satisfied.
    Host name: vmedge.ad.itechgaming.com
    WARNING! Host not found in topology. All roles will be uninstalled.
    Disabling unused roles...
    Executing PowerShell command: Disable-CSComputer -Confirm:$false -Verbose -Report "C:\Users\lync.admin.VMEDGE\AppData\Local\Temp\Disable-CSComputer-[2014_03_08][07_49_54].html"
    Checking prerequisites for roles...
    Checking prerequisite SupportedOS...prerequisite satisfied.
    Checking prerequisite SupportedOSNoDC...prerequisite satisfied.
    Checking prerequisite SupportedSqlRtcLocal...prerequisite satisfied.
    Checking prerequisite WMIEnabled...prerequisite satisfied.
    Checking prerequisite NoOtherVersionInstalled...prerequisite satisfied.
    Checking prerequisite PowerShell...prerequisite satisfied.
    Checking prerequisite WindowsIdentityFoundation...prerequisite satisfied.
    Checking prerequisite SqlInstanceRtcLocal...prerequisite satisfied.
    Checking prerequisite VCredist...prerequisite satisfied.
    Checking prerequisite SqlNativeClient...prerequisite satisfied.
    Checking prerequisite SqlClrTypes...prerequisite satisfied.
    Checking prerequisite SqlSharedManagementObjects...prerequisite satisfied.
    Checking prerequisite UcmaRedist...prerequisite satisfied.
    No databases discovered, skipping Install-CsDatabase...
    No roles discovered, skipping Enable-CsComputer...
    Thanks.

  • Decomission Exchange Server in Hybrid Deployment with Exchange online

    Referencing tech net article titled: Decommissioning your Exchange 2010 servers in a Hybrid Deployment ( I am not able to link to it due for some reason)
    I was also not able to comment directly on the article, would appreciate if the author or someone in the know could kindly review my comment/question below and provide feedback:
    So as I understand it if we used Hybrid mode as our method to migrate to O365 we must now keep an aging onPremise exchange server for time eternal?  This is not practical or sustainable as the whole point of going to O365 was to get rid of our old Exchange
    server.  Now we have to keep and maintain expensive hardware and keep windows patched and maintained etc, all the tasks we thought we were moving away from with this migration.  What happens when Exchange 2010 reaches EOL?  Do we then have to
    upgrade a server we are not really using? 
    Please tell me there is an update to this article or an update in the works with a more sustainable solution to cut ties with old on-prem Exchange servers after migrating to O365.  Is there an update or something in the works?  Is there anyway
    I can speak to someone on this in more detail to better understand the details to the downsides listed in this article?  We very much want to shutdown our on prem server ASAP as we are shutting down our datacenter since moving to O365 and this is the
    only kink hold us back.
    Thanks.

    If you have the infrastructure, you could move to a virtual server, and upgrade to Exchange 2013. There is a free license for Exchange 2013 when used hybrid server.
    https://support.microsoft.com/kb/2939261?wa=wsignin1.0
    I have to admit to being slightly confused about the conditions for obtaining the hybrid license as it says you can't already have a licensed Exchange server.  So what do you do if you had Exchange and then migrated to Office 365 rather than created
    the hybrid initially?
    CRM Advisor

  • LYNC 2010 hybrid deployment support

    Hi,
    We are currently using Microsoft LYNC 2010 on premise. Which is working fine.
    We are thinking of moving to office 365 for exchange etc. As we a partners we receive licenses also for LYNC online. I was wondering we have some users in the UK Maylasia etc, we would like them to use the LYNC online features as we here in Australia are
    on the LYNC on premise. We would eventually all be under the same domain.
    ie users [email protected] would be the username for office 365 login,
    If user A was in Au he would connect to the on premise link
    If user is in Uk or not setup to au LYNC server he can login to the online LYNC??
    spafco

    Hi,
    Lync server 2010 is not support hybrid deployment. Hybrid deployment will be supported by Lync server 2013.
    Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.

Maybe you are looking for