Problem removing a Exchange Federation Trust

Hi, 
I'm having a problem removing a Federation Trust.  I have removed the Organisation Relationship successfully. However when I go to remove the trust by Powershell  I get the following error
[PS] C:\Windows\system32>remove-federationtrust "Microsoft Federation Gateway"
Can't remove federation trust "Microsoft Federation Gateway". It's in use by the following organization(s): CN=Federation,CN=XXXXXX,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=XXXXX,DC=local
    + CategoryInfo          : InvalidOperation: (Microsoft Federation Gateway:ADObjectId) [Remove-FederationTrust], Or
   gsStillUsingThisTrustException
    + FullyQualifiedErrorId : A17E4A11,Microsoft.Exchange.Management.SystemConfigurationTasks.RemoveFederationTrusts
I cant seem to make other changes to it either, I cant add a domain, remove domain.  I have seen references to delete the object in the Schema but dont really want to do that unless I know it wont cause other problems as I need to recreate this.
Ian

There are few things you need to make sure before you remove the federation, like permissions, TXT records etc.
http://technet.microsoft.com/en-us/library/jj657500(v=exchg.150).aspx
http://technet.microsoft.com/en-us/library/dd297972(v=exchg.141).aspx
http://www.c7solutions.com/2012/03/fix-federation-trust-issues-after-html
Cheers,
Gulab Prasad
Technology Consultant
Blog:
http://www.exchangeranger.com    Twitter:
  LinkedIn:
   Check out CodeTwo’s tools for Exchange admins
Note: Posts are provided “AS IS” without warranty of any kind, either expressed or implied, including but not limited to the implied warranties of merchantability and/or fitness for a particular purpose.

Similar Messages

  • Unable to remove orpahned Exchange 2010 mailbox databse server permantely offline

    Greetings,
    I am having great problems removing and Exchange 2010 mailbox Database, the server that the database resided upon is permanently offline and gone,
    Under Organization Configuration / mailbox
    The orphaned database is listed there however I cannot delete it under Database Copies a copy of the orphaned database is listed as offline.
    How can I remove this database if the server is offline?

    run ADSIEDIT.msc
    Select Configuration well-known naming configuration -> CN=Configuration -> CN=Services -> CN=Microsoft Exchange -> CN=<YourExchOrgName> -> CN=Administrative Group -> CN=Exchange Administrative
    Group (FYDIBOHF23SPDLT) -> CN=Servers > CN=Databases -> Select Exchange 2010  database name and delete
    MCP, MCSE 2000 , MCSA 2000 ,MCSA 2003 , MCITP , MCTS , MCT

  • Calendar Sharing between 2 organisation Exchange 2010 SP3 and Exchange online with Federation Trust.

    Hi...
     Our company is running Exchange Server 2010 SP3 Standart would like to have Shared calendar with organisation running with Exchange online.
     We made a Federation trust between organisations and I checked that one certificate was installed and the rule for their domain was created. but when I try to share my calendar I always receive.
    "Calendar sharing is not available with the following contacts because of permission settings on your network."
    Name I took from GAL or input manually and always same. Forgot to mention that we migrated from Exchange 2003 to 2010 SP3 and all old exchange servers I removed. I tried everything that I know and read and nothing helped.
    Hope for your support.
    Thank you.

    1)I deleted everything and made step by step as indicated in your articles.
    2) recreated organisation relationship:
    RunspaceId            : xxxxxxxxxx
    DomainNames           : {xxxxxxx.microsoftonline.com, xxxxxxxxx.onmicrosoft.com, xxxxxxx.com}
    FreeBusyAccessEnabled : True
    FreeBusyAccessLevel   : LimitedDetails
    FreeBusyAccessScope   :
    MailboxMoveEnabled    : False
    DeliveryReportEnabled : False
    MailTipsAccessEnabled : False
    MailTipsAccessLevel   : None
    MailTipsAccessScope   :
    TargetApplicationUri  : outlook.com
    TargetSharingEpr      :
    TargetOwaURL          :
    TargetAutodiscoverEpr : https://pod12312.outlook.com/autodiscover/autodiscover.svc/WSSecurity
    OrganizationContact   :
    Enabled               : True
    ArchiveAccessEnabled  : False
    AdminDisplayName      :
    ExchangeVersion       : 0.10 (14.0.100.0)
    Name                  : xxx
    DistinguishedName     : CN=xxx,CN=Federation,CN=uxx,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=uxxx,DC=com
    Identity              : Lxx
    Guid                  : a8xxx
    ObjectCategory        : upxxs.com/Configuration/Schema/ms-Exch-Fed-Sharing-Relationship
    ObjectClass           : {top, msExchFedSharingRelationship}
    WhenChanged           : 27/01/2015 3:23:47 PM
    WhenCreated           : 26/01/2015 9:41:39 AM
    WhenChangedUTC        : 27/01/2015 8:23:47 PM
    WhenCreatedUTC        : 26/01/2015 2:41:39 PM
    OrganizationId        :
    OriginatingServer     : xxx.upxxxns.com
    IsValid               : True
    3. Configured Sharing Policies:
    [PS] C:\Windows\system32>Get-SharingPolicy
    Name                      Domains                                  Enabled    Default
    Default Sharing Policy    {*:CalendarSharingFreeBusySimple}        True       False
    Lxxx                              {lxxx.com:CalendarSharingFreeBusy...     True       True
    added my mail box to sharing policy but in the end receive same error 
    Calendar sharing is not available with the following contacts because of permission settings on your network.
    In EventViewer everything seems to be fine....
    No errors on policy creation... How can be checked this permission
    settings on your network they are on exchange on in DC ? 

  • Exchange2010 migration to Exchange 2013 federation trust failed (Outlook Provider Failure)

    We are in a migration Exchange 2010 to Exchange 2013.
    On the 'old' Exchange 2010 we are using a Federation Trust to 2 order company's. The federation trust for mailbox's on the exchange 2013 wont work.
    We removed the federation trust on the old exchange 2010 server and create a new federation trust on the new Exchange 2013 server. We also changes the DNS TXT records. Creating the new federation trust without errors. But when the 2 order company's trying
    to connect (add our company name for trust) they get a error.
    A have trying to run a couple tests on the new Exchange 2013 server and found this error:
    [PS] C:\Windows\system32>Test-OutlookWebServices -debug -Identity [email protected] -MailboxCredential(Get-Credential
    cmdlet Get-Credential at command pipeline position 1
    Supply values for the following parameters:
    Credential
    Source                              ServiceEndpoint                    
    Scenario                       Result  Latency
    (MS)
    AM111.AM.LAN                        autodiscover.company.nl            Autodiscover: Outlook
    Provider Failure     144
    AM111.AM.LAN                        webmail.company.nl                
    Exchange Web Services          Success     134
    AM111.AM.LAN                        webmail.company.nl                
    Availability Service           Success     207
    AM111.AM.LAN                                                           
    Offline Address Book           Skipped       0

    Hi,
    Are you add primary SMTP domain as a federated domain? If not, please run below command to achieve this function:
    Add-FederatedDomain -DomainName contoso.com
    Configure federated sharing for the Exchange 2013 organization. Complete the steps in
    Configure federated sharing.
    Configure federated delegation (previous name for federated sharing) for the Exchange 2010 SP2 organization. Complete the steps in
    Configure federated delegation.
    Besides, I find an similar thread about Autodiscover service failed within federated trust, for your convenience:
    https://social.technet.microsoft.com/Forums/ie/en-US/ea192e0a-1363-4cb6-9fc4-2973f64afc23/the-response-from-the-autodiscover-service-at?forum=exchange2010
    Best Regards,
    Allen Wang

  • Exchange 2010 to Office 365 federation trust

    I'm trying to setup a federated trust between two companies on different domains (Exchange 2010 SP2 on premise/Office 365).  We are trying to share calendar information and contacts.  I've gone through the steps to setup a federated trust and created
    the TXT file for the (Exchange 2010) on premise domain.  When I try creating the trust from the Exchange 2010 on premise domain to Office 365 I receive an error.
    COMMAND: 
    Set-FederatedOrganizationIdentifier –AccountNamespace <some_domain> –DelegationFederationTrust “Microsoft Federation Gateway”
    ERROR:
    Proof of domain ownership has failed. Make sure that the TXT record for the specified domain is available in DNS. The format of the TXT record should be "example.com IN TXT hash-value" where "example.com" is the domain you want to configure
    for Federation and "hash-value" is the proof value generated with "Get-FederatedDomainProof -DomainName example.com".
    Do I need to create a TXT file for the Office 365 side?
    Thanks
    Stephen

    You need to add this TXT record for your domain and publish it EXTERNALLY, so that the MFG can verify it. For example, check the TXT records for Microsoft.com:
    PS C:\> Resolve-DnsName -Type TXT microsoft.com
    Name Type TTL Section Strings
    microsoft.com TXT 2346 Answer {FbUF6DbkE+Aw1/wi9xgDi8KVrIIZus5v8L6tbIQZ
    kGrQ/rVQKJi8CjQbBtWtE64ey4NJJwj5J65PIggVY
    NabdQ==}

  • Issue when Creating a Federation Trust with MFG (Microsoft Federation Gateway)

    I am trying to create a Federation Trust with MFG (Microsoft Federation Gateway).  However, I am running into a problem.  I see in the following that link (http://technet.microsoft.com/en-us/library/ff607475(v=exchg.141).aspx)
    that I have to run this command:
    Set-ExchangeServer -Identity "MAIL01" -InternetWebProxy "<Webproxy URL>"
    Please note that I have the following in our Exchange 2010 SP3 environment:
    Two CAS/HT Servers (CAS Array between the two)
    Two mailbox servers (DAG between the two)
    One mailbox server (for stand-alone mailbox/archive databases)
    We use windows load balancing and the internal/external VIP name is "mail.domain.com"
    1. What do I put for the "Web Proxy URL"?
    2. Do I have to run the Set-ExchangeServer -Identity "MAIL01" -InternetWebProxy "<Webproxy URL>" command on every server?

    The link you posted is different than free-busy sharing through the Microsoft Federation Gateway.  All you need to establish Organization Relationships through the Microsoft Federation Gateway is properly published Autodiscover and Exchange Web Services. 
    You can use the Exchange Remote Connectivity Analyzer (http://exrca.com) to validate that.
    Ed Crowley MVP "There are seldom good technological solutions to behavioral problems."

  • Problem removing a window partition

    today i installed window xp via boot camp, the installation seems fine all the way up until the step 'to install boot camp drivers'. after i inserted the Max OS X disc, it went thru the normal installation...etc. then towards the end i got the 'Found New Hardware Wizard' window and a second saying boot camp is finished. however, at this point the mouse is dead and i am unable to move it. i rebooted it a couple of times, still the mouse is disable.
    so, i boot back to Mac OS, open up Boot camp and decided to remove the window partition. i chose 'If your computer has a single internal disk, click Restore'...
    then i am at the 'restore disk to a single volume' with the status: partitioning disk spinning...
    when i created the window partition i used 15G and i have the unibody macbook with 250G. however, this window's been spinning for the past two hours. i really don't think this should take this long. is this normal?
    i do not want to re-install 10.5.5 and do a restore. what is the best way to delete the window partition? i suspect something is wrong with boot camp. what should i do?

    There are few things you need to make sure before you remove the federation, like permissions, TXT records etc.
    http://technet.microsoft.com/en-us/library/jj657500(v=exchg.150).aspx
    http://technet.microsoft.com/en-us/library/dd297972(v=exchg.141).aspx
    http://www.c7solutions.com/2012/03/fix-federation-trust-issues-after-html
    Cheers,
    Gulab Prasad
    Technology Consultant
    Blog:
    http://www.exchangeranger.com    Twitter:
      LinkedIn:
       Check out CodeTwo’s tools for Exchange admins
    Note: Posts are provided “AS IS” without warranty of any kind, either expressed or implied, including but not limited to the implied warranties of merchantability and/or fitness for a particular purpose.

  • Problem removing a Topic or Queue

    Using the console to remove a JMS Destination from a server causes WLS
    6.0b2 to get into an unusable state. Even the management console no
    longer works. WLS needs to be restarted.
    Ben

    There are few things you need to make sure before you remove the federation, like permissions, TXT records etc.
    http://technet.microsoft.com/en-us/library/jj657500(v=exchg.150).aspx
    http://technet.microsoft.com/en-us/library/dd297972(v=exchg.141).aspx
    http://www.c7solutions.com/2012/03/fix-federation-trust-issues-after-html
    Cheers,
    Gulab Prasad
    Technology Consultant
    Blog:
    http://www.exchangeranger.com    Twitter:
      LinkedIn:
       Check out CodeTwo’s tools for Exchange admins
    Note: Posts are provided “AS IS” without warranty of any kind, either expressed or implied, including but not limited to the implied warranties of merchantability and/or fitness for a particular purpose.

  • Free/busy sharing using Exchange federation

    We run Exchange 2010 and one of our business partners is running in Office 365. We would like to share free busy across our two organizations. Is it setup feasible,
    1. We setup a federation trust with the MFG.
    2. We setup an org relationship with them, they setup a org relationship with us with appropriate free busy parameters.
    Most of the documentation I see is about a hybrid setup for the SAME organization. Here we are two completely separate organizations. Any documentation/links to real-world implementation would be much appreciated.

    Here are some references that may be helpful to you:
    Configure Federated Delegation in the Cloud
    http://help.outlook.com/en-us/140/ff383252.aspx
    Understanding Federated Delegation
    http://technet.microsoft.com/en-us/library/dd638083(v=exchg.141).aspx
    Cross Org Availability using Federation Trust and Organization Relationship
    http://blogs.technet.com/b/exchange/archive/2011/06/28/cross-org-availability-using-federation-trust-and-organization-relationship.aspx
    Federation in Office 365 and Exchange
    http://community.office365.com/en-us/w/exchange/785.federation-in-office-365-and-exchange.aspx

  • Can't create Federation Trust with Microsoft Federation Gateway

    Hi all,
    I'm trying to create Federation Trust with another Exchange 2010 RU9 Server and on the step "Set-FederatedOrganizationIdentifier" in the Manage Federation Wizard trows the Error:
    Unable to reserve domain "FYDIBMHF36SPPKT.subdomain.mydomain.com" for Application Identifier "000000005G82H793". Detailed information: "An unexpected result was received from Windows Live. Detailed information: "2028 DomainNotReservedinIDS:
    The input namespace was not found".".
    An unexpected result was received from Windows Live. Detailed information: "2028 DomainNotReservedinIDS: The input namespace was not found".
    DomainNotReservedinIDS: The input namespace was not found
    Click here for help... http://technet.microsoft.com/en-US/library/ms.exch.err.default(EXCHG.140).aspx?v=14.3.123.3&t=exchgf1&e=ms.exch.err.Ex703205
    Exchange Management Shell command attempted:
    Set-FederatedOrganizationIdentifier -DelegationFederationTrust 'Microsoft Federation Gateway' -AccountNamespace 'subdomain.mydomain.com' -OrganizationContact '[email protected]' -Enabled $true
    I don't have more then 32 characters in the domain name. 
    Thanks in advance.
    BR

    Hi,
    In addition, please try to create a recipient policy to add that subdomain email addresses to all my users, then create a new trust for that subdomain as the subject of the cert, add that subdomain as the primary domain, and then add the main domain as an
    additional one to the federation trust.
    Thanks
    Please remember to mark the replies as answers if they help, and unmark the answers if they provide no help. If you have feedback for TechNet Support, contact [email protected]
    Allen Wang
    TechNet Community Support

  • Hi I am having problems removing mail from trash folder. Can anyone help please

    Hi I am having problems removing mail from trash folder. I can send mails to the folder but cannot delete them permanently from the trash folder. I am using Iphone 3G and anm up to date with OS. Can anyone help please

    Check that there isn't a different Trash folder to the one with the proper Trash symbol on it.
    If you see one in your list of folders rather than a separate one, highlight it, then click on Mailbox...Use this mailbox for...Trash

  • Cannot open your default e-mail folder. Microsoft Exchange is not available. Either there are network problems or the Exchange computer is down for maintenance

    Windows Server 2012 R1 with Exchange 2013 SP1
    Windows XP SP3 with Outlook 2010 (14.0.4760.1000) computer is on the same network, but not a part of the domain. 
    When I try to configure Outlook profile for the user, I manually enter exchange server name and user name. 
    Check User button underlines server name and user name and profile gets created successfully.
    Once I try to open outlook for the user I get
    Cannot open your default e-mail folder. Microsoft Exchange is not available. Either there are network problems or the Exchange computer is down for maintenance
    If I search the content of the log files under
    X:\Program Files\Microsoft\Exchange Server\V15\Logging\RPC Client Access
    I can’t find any records indicating a connection attempt from the client’s IP or references to the version of the outlook used, however I can see a 3 way handshake followed by a 4 RCP packets and then 4 nspi bind requests and responses when outlook opens
    up and then connection is torn down.

    Windows Server 2012 R1 with Exchange 2013 SP1
    Windows XP SP3 with Outlook 2010 (14.0.4760.1000) computer is on the same network, but not a part of the domain. 
    Hi,
    That version of Outlook 2010 (14.0.4760.1000) is not supported with Exchange 2013 and will not be able to connect. It need to be on at least SP1 +
    Outlook 2010 November 2012 update (14.0.6126.5000)
    See: Exchange 2013 System Requirements -
    Client Support
    Martina Miskovic

  • Is there any API to add and remove certs from acrobat trusted identities?

    Is there any API to add and remove certs from acrobat trusted identities? if this is not possible any work around for this. Please help me

    No, there is not – that would be a security concern.

  • Problem removing Zombie GS

    Hey all. Having a problem removing Zombie Gunship from my Game Center. Basically, I want to delete my current progress and start over, thanks to my nephew messing up my config.
    So, I've deleted Zombie GS and it prompts me to remove the data and that my progess will be removed from the leader boards. So I do all that, restart it, blah blah blah. After I've reinstalled the app, my old config/progress/money is still there.
    I've emailed the game company and of course no response. So what am I missing or doing wrong? Or is this a situation where I can never start over?
    Thanks in advance for the help.

    I've got the same problem. I am revisiting the game and I want to start again from scratch but it seems Game Center has other plans for me. Dammit Apple gestapo!

  • Problem removing files with CVS (JDeveloper 10.1.3 Preview)

    Hello,
    I've got a problem removing files from CVS :
    - I right-click on the file I want to remove -> Versioning -> Remove
    - The file is removed from local directory, and it appears in "Pending changes" view, on "Outgoing" tab. Its status is "scheduled for removal".
    - When I commit the file in the "Pending Changes" view, and click OK, then nothing happens. The file stay with "scheduled for removal" status, and it is not deleted on CVS server.
    I tried to commit the package or the project, but it's the same thing.
    Files additions and modifications work correctly.
    I'm using JDeveloper 10.1.3 Preview version.
    Is this a bug ? Or do I do something wrong ? Is there an other way to solve my problem ?
    Thanks.

    Here is the message displayed in the log window when I remove file (in Versioning menu) :
    C:\J2EE\Projets\budgetapptest\src\test\swm>
    $ <internal cvs client> remove -l Test_suppr_1.java
    cvs remove: scheduling `Test_suppr_1.java' for removal
    cvs remove: use 'cvs commit' to remove this file permanently
    Here is the message displayed in the log window when I COMMIT the "scheduled for removal" file :
    C:\J2EE\Projets\budgetapptest\src\test\swm>
    $ <internal cvs client> commit -F C:\DOCUME~1\19363~1.WIN\LOCALS~1\Temp\.jdevcvs_cmt22356.tmp Test_suppr_1.java
    cvs commit: Examining .
    Thanks.
    Message was edited by:
    user444728

Maybe you are looking for

  • How to get the CallbackHandler

    Hi experts, I'm trying to do JAAS Authentication programatically in a servlet (without configuration in Visual Admin). Code looks like this: CallbackHandler cbh = new <what should go here?>(request, response); LoginContext lc = new LoginContext(LOGIN

  • How do i chat with att employee

    how do i chat with att employee

  • ICloud - how to get it on older OS versions?

    Hi, I was helping someone tonight with a MacBook Pro, 2GHz Core 2 Duo, 2GB RAM, 160GB disk.  They are running OSX 10.5.8 aka Leopard. I had setup iCloud on her PC so the pictures taken from her iPhone and iPad all show on each other. She's wondering

  • "This computer cannot install this software"

    Ok, so heres the deal. I decided to wipe my hd and reinstall os x. No problem except that now I am told by the machine that I cannot install from my OEM disk at all.

  • Scale Object with Panel, but what about inside a Tab control?

    The Scale Object with Panel option works very well for simple UI objects.  I like to use it for VIs that display tables or multicolumn listboxes, etc.  I am finding a limitation when I use the Tab control.  If I have a table or listbox in each tab, I