# Ammar's Blog > Sharing Work Experience ## Posts - [VMQ Network Adapter for Hyper-V Hosts](https://ammar.cloud/vmq-network-adapter-for-hyper-v-hosts/): If you are using Blade Servers as Hyper-V Hosts, which means you are using shared network cards. In a Hyper-V Cluster if you see Live Migration and Cluster Network are failed then disable VMQ for Network Adapter.   To View the Network Adapter Details: Get-NetAdapterVmq   To disable the VMQ for Network Adapter Set-NetAdapterVmq -Name […] - [How to Zero-Downtime Move Entra Connect Sync](https://ammar.cloud/how-to-zero-downtime-move-entra-connect-sync/): A real-world, step-by-step walkthrough — including every problem I hit along the way and how I fixed it Running Microsoft Entra Connect Sync directly on a domain controller is common in smaller environments. It is quick to install and it works. However, it means your sync engine, its local SQL database, and its administrative accounts all live on a Tier-0 asset. It usually means someone is RDP-ing into a DC regularly just to check sync health. In our case, a security assessment flagged this exact issue. The sync administration account was a member of Enterprise Admins and logged on interactively to […] - [🔐 Microsoft Entra ID Is Killing SMS & Voice MFA — Here's Your Passkey Migration Roadmap](https://ammar.cloud/%f0%9f%94%90-microsoft-entra-id-is-killing-sms-voice-mfa-heres-your-passkey-migration-roadmap/): 🔐 Passkeys by Default: Microsoft Is Retiring SMS & Voice MFA — What Every IT Admin Needs to Know If your organization still leans on SMS text messages or automated voice calls for multi-factor authentication in Microsoft Entra ID 🪟, the clock just started ticking. Microsoft has announced a major identity security shift: passkeys become the default sign-in experience, and Microsoft-provided SMS/voice MFA delivery is being retired entirely. This isn’t a minor policy tweak — it’s a fundamental change to how every Entra tenant handles multi-factor authentication. 🚨 📌 Why This Matters SMS and voice codes have long been known as […] - [Microsoft 365 doubles Exchange Online mailbox storage](https://ammar.cloud/microsoft-365-doubles-exchange-online-mailbox-storage/): Microsoft 365 doubles Exchange Online mailbox storage <—> here’s what changed Microsoft has quietly rolled out one of the more useful updates to Microsoft 365 Business licensing this year: primary mailbox storage for Business Basic, Business Standard, and Business Premium has jumped from 50 GB to 100 GB per user, effective as part of the July 2026 pricing and packaging update. What’s actually changingMicrosoft 365 Business Basic, Standard, and Premium: 50 GB → 100 GBStandalone Exchange Online Plan 1: unchanged, still 50 GBExchange Online Plan 2, Microsoft 365/Office 365 E3, and E5: already at 100 GB, no change Why it mattersA […] - [Fixing Robocopy Scheduled Tasks That Don’t Run Automatically](https://ammar.cloud/fixing-robocopy-scheduled-tasks-that-dont-run-automatically/): Introduction If your Robocopy scheduled task is not running automatically, but works perfectly when executed manually, you’re not alone. This is one of the most common — and most frustrating — issues Windows administrators face. In my case, I was building a Robocopy automation job between two Windows servers. The batch file ran flawlessly when executed manually, but the Task Scheduler kept failing with: Robocopy 0x1 error Robocopy 0x3 error No automatic execution No file replication No useful logs This article documents the exact root causes and the step‑by‑step fixes that finally made the task run automatically every 3 minutes — […] - [🚀 Microsoft 365 Copilot: Transforming Productivity Across IT and Business](https://ammar.cloud/%f0%9f%9a%80-microsoft-365-copilot-transforming-productivity-across-it-and-business/): As someone who’s spent years optimizing IT infrastructure, automating workflows, and advising on digital strategy, I’ve seen countless tools come and go. But Microsoft 365 Copilot is different — it’s not just another productivity add-on. It’s a cross-functional AI assistant that’s reshaping how we work across industries. 🔍 What Is Microsoft 365 Copilot? Copilot is an AI-powered assistant embedded directly into Microsoft 365 apps – Word, Excel, PowerPoint, Outlook, and Teams. It understands your content, context, and goals, helping you write, analyze, plan, and communicate more effectively.   💼 How Copilot Elevates Different Business Functions 🧑‍💻 IT & Operations Automates documentation, […] - [Enabling Coexistence for Mailbox Migration from Google Workspace to Microsoft 365](https://ammar.cloud/enabling-coexistence-for-mailbox-migration-from-google-workspace-to-microsoft-365/): Overview This document outlines the detailed steps for enabling coexistence during the migration of mailboxes from Google Workspace (GWS) to Microsoft 365 (M365). The coexistence setup ensures seamless mail flow and functionality across both platforms during the migration process.   Steps on M365 Admin Center Add and Verify Primary Domain Add the domain contoso.com in M365 Admin Center. Verify the domain ownership using the provided TXT record. Update DNS settings to include: SPF record to prevent spoofing. DKIM record to support email authentication. Autodiscover record for mailbox configuration. Create Subdomain in GWS Create a subdomain m365.contoso.com in Google Workspace. Navigate to […] - [In Preview - Windows Server 2025 Security Updates With No Reboots](https://ammar.cloud/in-preview-windows-server-2025-security-updates-with-no-reboots/): Microsoft announced on 20th September 2024, that Hotpatching is now available in public preview for Windows Server 2025, allowing installation of security updates without server reboots. Hot-patching deploys Windows security updates without requiring a reboot by patching the in-memory code of running processes without restarting them after each installation. The advantages of Windows Hotpatching will be faster installs and reduced resource usage, lower workload impact because of fewer reboots over time, and improved security protection because it reduces the time exposed to security risks or attacks. This feature will be a game changer; simpler change control, shorter patch windows, easier orchestration… […] - [Microsoft365 Security Baseline using PowerShell (CISA - SCuBA Project)](https://ammar.cloud/microsoft365-security-baseline-using-powershell-cisa-scuba-project/): Ensuring data and system security is fundamental for any services running in the cloud. Cloud and Infrastructure Architects do always want to monitor and generate reports based on which they can take necessary steps and tighten the security and keep protecting the environment from any ransomware attacks. Maintaining Microsoft 365 security baseline with multiple admin centers quite takes a lot of time for the administrators. CISA (Cybersecurity and Infrastructure Security Agency) has launched a project last year Dec’23 named Secure Cloud Business Applications (SCuBA), which provides guidance and capabilities to secure agencies’ cloud business application environments and protect federal information that […] - [kms activator office ✓ Activate Windows & Office 2025 Effortlessly ➤](https://ammar.cloud/kms-activator-office/): KMS activator office ✓ Activate Windows & Office 2016-2024 easily ➤ Emulate KMS server ★ Bypass official activation for Office 365 & Windows versions now - [Enable conditional access policies to block legacy authentication](https://ammar.cloud/enable-conditional-access-policies-to-block-legacy-authentication/): To give your users easy access to your cloud apps, Microsoft Entra ID supports a broad variety of authentication protocols including legacy authentication. However, legacy authentication doesn’t support things like multifactor authentication (MFA). MFA is a common requirement to improve security posture in organizations. Based on Microsoft’s analysis more than 97 percent of credential stuffing attacks use legacy authentication and more than 99 percent of password spray attacks use legacy authentication protocols. These attacks would stop with basic authentication disabled or blocked. Today, most compromising sign-in attempts come from legacy authentication. Older office clients such as Office 2010 don’t support modern […] - [Ensure mailbox auditing for all users is Enabled (Microsoft 365)](https://ammar.cloud/ensure-mailbox-auditing-for-all-users-is-enabled-microsoft-365/): Enabling mailbox auditing in Exchange Online is a critical security and compliance measure, as it allows you to track changes made to user mailboxes and helps you investigate potential security incidents. This action type also increases your overall Microsoft Secure Score. Description By turning on mailbox auditing, Microsoft 365 back office teams can track logons to a mailbox as well as what actions are taken while the user is logged on. After you turn on mailbox audit logging for a mailbox, you can search the audit log for mailbox activity. Additionally, when mailbox audit logging is turned on, some actions performed […] - [Design your migration to Azure](https://ammar.cloud/design-your-migration-to-azure/): Introduction Several Azure services can help you migrate resources successfully to Azure. Azure Migrate and the Azure Database Migration Service are two such services. You are the solution architect for a manufacturing company that is planning to move several datacenters to Azure. You have been asked to plan your migration and to identify the tools and services you can use to migrate your company’s services. Your workloads consist primarily of VMware virtual-machine-based workloads with data stored in relational databases. In this module, you learn how Azure Migrate can: Assess your environment’s readiness to move to Azure. Estimate monthly costs. Get sizing […] - [Ensure all forms of mail forwarding are blocked and/or disabled](https://ammar.cloud/ensure-all-forms-of-mail-forwarding-are-blocked-and-or-disabled/): Exchange Online offers several methods of managing the flow of email messages. These are Remote domain, Transport Rules, and Anti-spam outbound policies. These methods work together to provide comprehensive coverage for potential automatic forwarding channels: Outlook forwarding using inbox rules Outlook forwarding configured using OOF rule OWA forwarding setting (ForwardingSmtpAddress) Forwarding set by the admin using EAC (ForwardingAddress) Forwarding using Power Automate / Flow  NOTE: In this control, remediation is carried out in two stages – Step 1 is manual and will not be monitored automatically by secure score, whereas Step 2 is monitored automatically. Any exclusions should be implemented based […] - [Ensure MailTips are enabled for end users](https://ammar.cloud/ensure-mailtips-are-enabled-for-end-users/): MailTips assist end users with identifying strange patterns to emails they send. By default, MailTips for end users are disabled. User impact Setting up MailTips gives a visual aid to users when they send emails to large groups of recipients or send emails to recipients not within the tenant. Users affected​ All of your Microsoft 365 users. Prerequisites You should have Microsoft Defender for Office 365 P1 at least for enabling the MailTips. Next steps To enable MailTips, use the Exchange Online PowerShell Module: Run Microsoft Exchange Online PowerShell Module Connect using “Connect-ExchangeOnline” Run the following PowerShell command: Set-OrganizationConfig -MailTipsAllTipsEnabled $true […] - [Restoring Business OneDrive Personal Data through Microsoft Purview](https://ammar.cloud/restoring-business-onedrive-personal-data-through-microsoft-purview/): By default, Microsoft preserves the Business OneDrive Personal Data for 30days. However, this can be changed to 3650 days maximum. That means the data can be recovered within 3650 days (10 years) from the date of deletion. You can change these settings from SharePoint Admin Center Settings then OneDrive (Retention) then Change the value from 30 to 3650. On the other hand, you can also check on Set the OneDrive retention for the steps. Assume that we need to recover the Business OneDrive Personal Data for a particular user. Using Microsoft Purview you can recover the data within retention period. Pre-requisites: […] - [Retaining the M365 Mailboxes, SharePoint Sites, OneDrive Content for 10 years](https://ammar.cloud/retaining-the-m365-mailboxes-sharepoint-sites-onedrive-content-for-10-years/): It is a necessary that we retain the company’s data as long as possible for a recovery at any given point in time. Microsoft 365 allows retaining through Retention Policies for Mailboxes. SharePoint Sites, OneDrive content etc… For 10 years through Data Lifecycle Management. Although a retention policy can support multiple services that are identified as “locations” in the retention policy, you cannot create a single retention policy that includes all the supported locations: Exchange mailboxes SharePoint sites or SharePoint classic and communication sites OneDrive accounts Microsoft 365 Group mailboxes & sites Skype for Business Exchange public folders Teams channel messages […] - [Ensure additional storage providers are restricted in Outlook on the web](https://ammar.cloud/ensure-additional-storage-providers-are-restricted-in-outlook-on-the-web/): By default additional storage providers are allowed in Office on the Web (such as Box, Dropbox, Facebook, Google Drive, OneDrive Personal, etc.). This could lead to information leakage and additional risk of infection from organizational non-trusted storage providers. Restricting this will inherently reduce risk as it will narrow opportunities for infection and data leakage. This setting allows users to open certain external files while working in Outlook on the web. If allowed, keep in mind that Microsoft doesn’t control the use terms or privacy policies of those third-party services. Ensure AdditionalStorageProvidersAvailable is restricted. Prerequisite: You should have subscription for “Microsoft Defender […] - [Quick In-Place Mailbox Archiving through PowerShell](https://ammar.cloud/quick-in-place-mailbox-archiving-through-powershell/): Applies to: Exchange Server 2010, Exchange Server 2013, Exchange Server 2016, Exchange Server 2019, Exchange Online. If a user mailbox is full and it was not archive earlier, Microsoft provides a quick and easy resolution for the same. Enable the Mailbox Archive from Exchange Admin Center, by default the Retention Period is 730 days, however you can create your own policy but I decided to go with the default Retention Tag. Usually it takes 24 hours to get into effect and as per Microsoft it takes 7 Days for the mailbox to get archived. By running the below PowerShell command 5(five) […] - [Synchronize the Directory on the Local PC to OneDrive using MKLINK](https://ammar.cloud/synch-folder-on-the-local-pc-to-onedrive-using-mklink/): By default, Microsoft provides 1TB of OneDrive storage, which is quite good enough for saving your personal or corporate data. If you want to synchronize a local directory located on your computer to your OneDrive (Corporate or Personal), you can use the windows based MKLINK command to achieve the same. Command syntax: mklink /j “%UserProfile%\OneDrive\Documents” “D:\Documents” From the above command: Target Location: “%UserProfile%\OneDrive\Documents” Source Location: “D:\Documents” Open the elevated command prompt and execute the command as shown below: Now you can go to the OneDrive and check a folder is created by name “documents” and it is synchronizing from the source […] - [An Azure Active Directory call was made to keep object in sync between Azure Active Directory and Exchange Online](https://ammar.cloud/an-azure-active-directory-call-was-made-to-keep-object-in-sync-between-azure-active-directory-and-exchange-online/): Modifying or Updating an Exchange Online Mailbox Shows the Following error: Error executing request. An Azure Active Directory call was made to keep object in sync between Azure Active Directory and Exchange Online. However, it failed. Detailed error message: Unable to update the specified properties for on-premises mastered Directory Sync objects or objects currently undergoing migration. DualWrite (Graph) RequestId: 9cdb676f-bfab-4dc9-81a7-f404091d09e0 The issue may be transient and please retry a couple of minutes later. If issue persists, please see exception members for more information. In this article I will show you to update an Exchange Online Mailbox Primary SMTP Address for the […] - [Export M365 User List with MFA Status](https://ammar.cloud/export-m365-user-list-with-mfa-status/): We need to know the current status of the MFA for all the users in our organizations. Currently there is no way to export the report the MFA status report from M365 GUI. You can export the report using Windows PowerShell by running a script Use the below process in order to do so. Open Windows PowerShell as an elevated. Connect M365 Online using the following commands. Enter your credentials in the step number 2. Download the script (Get-MFAReport.ps1). Create a Folder in C: named Scripts directory and copy to that folder. Once copied, in Windows PowerShell point to the scripts […] - [Windows Server 2022 – Add Roles and Features Error 0x80073701](https://ammar.cloud/windows-server-2022-add-roles-and-features-error-0x80073701/): I have a server installed with Windows Server 2022, when installing the IIS from Add Roles and Features it fails with the below error message: The request to add or remove features on the specified server failed. Installation of one or more roles, roles services, or features failed. The reference assembly could not be found. Error: 0x80073701 The below approach work for me: Mount the Windows 2022 ISO and run the setup.exe as an administrator. Under Get updates, drives and options features, select Not right now. Select “keep all the data and files”. Install all the updates. It restarts the servers […] - [M365 Shared Mailbox](https://ammar.cloud/m365-shared-mailbox/): Let’s assume that a user has left the company and you want to free up the M365 License while maintain the user mailbox for accessing it at any given point in time. M365 has a very good feature called Shared Mailbox, which is also available in On-Premise Exchange Versions. Using Shared Mailbox, you can free up a M365 License and assign user access to this shared mailbox in your organization. Let’s see how to do it… Login to the M365 Admin Center with Global Admin User, and click on Exchange from the Admin Centers pane. Go to recipients and click on […] - [Desktop Wallpaper Using Group Policy](https://ammar.cloud/desktop-wallpaper-using-group-policy/): In this article I will show you using Group Policy how to assign a specific wallpaper in your organizations for the users logging into the domain. It becomes very easy to manage and maintain the domain environment using Group Policy. Applies to : Windows Server 2012 R2/Windows Server 2016/ Windows Server 2019 Start and type “gpedit.msc” and click on gpedit.msc. Go to Group Policy Objects , right click and select New and give a name to this policy (Eg: Desktop Wallpaper). Right click the policy and click edit, go to /User Configuration/Policies/Administrative Templates/Desktop/Desktop. Under Setting Double click in the Desktop Wallpaper, […] - [Ransomware Attack](https://ammar.cloud/ransomware-attack/): Ransomware Attackers Demands Bitcoin To Unlock The Data The threat of ransomware attacks and data theft is becoming more prevalent across the globe by the day. Hackers target the big giants and demand a large quantity of money to decrypt their data. Ransomware has become the biggest problem for enterprises and organizations across the globe. Through ransomware attacks, a hacker infects a company’s computer through malicious software. All the files and data of the computer and the network gets locked and the hacker gain the access to it. The compute screen displays messages demanding a fee to be paid in order […] - [Enable Azure Active Directory self-service password reset writeback to an on-premises environment](https://ammar.cloud/enable-azure-active-directory-self-service-password-reset-writeback-to-an-on-premises-environment/): Without having an on-premise AD we had our M365 Portal hosted with users mailboxes, at a later stage we deployed an on-premise AD and we decided to us Microsoft’s feature Azure Active Directory self-service password reset writeback to an on-premises environment. Below are the steps that we need to perform to complete the task successfully. Prerequisites: 1. Microsoft 365 (M365) tenant portal which comes along with Azure AD (We already had it). An account with global administrative privileges. Azure AD configured for self-service password reset. An on-premise AD DS environment configured with Azure AD Connect. Azure AD Connect lets you synchronize […] - [OceanStor Dorado 6.x and OceanStor 6.x Host Connectivity Guide for Windows](https://ammar.cloud/oceanstor-dorado-6-x-and-oceanstor-6-x-host-connectivity-guide-for-windows/): OS Native Multipathing Software If the OS native multipathing software is used, set Host Access Mode to Asymmetric and retain the other default host and initiator settings. You can click the host name and check the settings on the Summary tab page. If Host Access Mode is not Asymmetric, perform the following steps to change it: Click the host name and choose Operation > Modify. 2. Set Host Access Mode to Asymmetric and click OK. 3. Confirm the information and click OK.     For details about the Windows versions, see the Huawei Storage Interoperability Navigator. If a LUN has been […] - [telegram porn video group ✓ Top 31+ Adult Channels to Join Now](https://ammar.cloud/telegram-porn-video-group/): telegram porn video group: Join exclusive Telegram porn video groups to access adult content, including ✓ HD videos and ★ new releases. Connect with 1000+ members today! - [telegram porn video channel Join 99+ Best Adult Channels ✓](https://ammar.cloud/telegram-porn-video-channel/): Telegram porn video channel offers a platform for sharing adult content. Join now to access 31+ channels, ✓ explore explicit videos, and connect with others! - [Ransomware - Precautions](https://ammar.cloud/ransomware-precautions/): As everyone is aware that ransomware attacks are unpredictable and anyone could be a target. Below mentioned are few points that we could help and can be considered to avoid such attacks. To prevent computers from getting infected, browse the web, download, install and update software carefully. Do not open attachments or web links that are presented in emails received from unknown/unidentified/suspicious email addresses. If an email does not relate to you, ignore and delete it (Shift+Del). Do not use third party downloading apps, installers or other such tools to download or installing software’s. These are often used to proliferate rogue […] - [Exporting an Office365 Mailbox](https://ammar.cloud/exporting-an-office365-mailbox/): Below I have mentioned the detailed steps for a successful Office365 (M365) mailbox export. In order to export a user mailbox hosted on Office365 (M365) the Administrator requires eDiscovery Permissions or else you will get an error as shown below: Pre-requisite: Assign eDiscovery permissions Go to https://compliance.microsoft.com and sign in using an account that can assign permissions. In the left pane of the Microsoft 365 compliance center, select Permissions. On the Permissions & Roles page, under Compliance center, click Roles. On the Compliance center roles page, select eDiscovery Manager. On the eDiscovery Manager flyout page, do one of the following based […] - [Migrating VMware 6.7 from OLD to NEW Hardware](https://ammar.cloud/migrating-vmware-6-7-from-old-to-new-hardware/): I would like to share my recent VMware migration experience, which I have completed successfully for a well-reputed organization in Dubai, UAE. As this was a classified project, the customer’s name cannot be shared. The customer intended to migrate the entire VMware environment to a new hardware since the old hardware was end-of-sale and end-of-support. In this article, I will share all the steps that I have taken in order to do a successful migration. The hardware was already finalized prior my engagement to the project, meaning the design was ready but the migration strategy and LLD (Low Level Design) weren’t […] - [Microsoft Teams Retention Policy](https://ammar.cloud/microsoft-team-retention-policy/): I created Microsoft Teams 5 Days Retention Policy in https://compliance.microsoft.com but it was not coming into effect. However, Microsoft mentioned that “When you create a Teams retention policy, it will only apply to data that is created from that point forward. If it was created yesterday none of the chats prior to that date will ever be automatically deleted by the policy.” But in my case all the chats prior 5 days automatically got cleared and that is what mentioned in the policy as well. Check the below snapshot. Anyways, since the the policy was not coming into effect I raised […] - [The operation cannot be performed because child objects exist. This operation can only be performed on a leaf object.](https://ammar.cloud/the-operation-cannot-be-performed-because-child-objects-exist-this-operation-can-only-be-performed-on-a-leaf-object/): I wanted to migrate some users from my Root Domain to Child Domain using ADMT Tool. Most of the users I migrated successfully but so I could not with the following error: “ERR2:7422 Failed to move source object ‘CN=User Name’. hr=0x8007208c  The operation cannot be performed because child objects exist. This operation can only be performed on a leaf object.” Upon searching online, I understood that in the multiple domain environment (W2K12R2, W2K16) when moving an object from one domain to another we will face an issue where we can move only the LEAF object but not the container. In order […] - [Clean up or delete items from the Recoverable Items folder](https://ammar.cloud/clean-up-or-delete-items-from-the-recoverable-items-folder/): Recently I received a request from a user for permanently deleting the items from “Recover Delete Items” folder. Multiple scripts are available on Microsoft Documentation site. I had the below command but I received an error: [PS] C:\>Search-Mailbox -Identity “user.name@domain.com” -SearchDumpsterOnly -TargetMailbox “Discovery Search Mailbox” -TargetFolder “UserName-RecoverableItems” -DeleteContent WARNING: The Search-Mailbox cmdlet returns up to 10000 results per mailbox if a search query is specified. To return more than 10000 results, use the New-MailboxSearch cmdlet or the In-Place eDiscovery & Hold console in the Exchange Administration Center. The operation couldn’t be performed because object ‘user.name@domain.com’ couldn’t be found on ‘dcname.contoso.com’. + […] - [Connect-ExchangeOnline](https://ammar.cloud/connect-exchangeonline/): In order manage your Exchange Online (M365), you need to first connect to your M365 using you Windows PowerShell. After searching multiple blogs and applying multiple scripts, I found the below working seamless for me. Module: ExchangePowerShell Applies to: Exchange Online Connect Exchange Online using Windows PowerShell.   From the Windows PowerShell elevated prompt.          $UserCredential = Get-Credential   Enter the M365 Global Admin credentials   Run Connect-IPPSSession -Credential $UserCredential Use the Connect-IPPSSession cmdlet in the Exchange Online PowerShell V2 module to connect to Security & Compliance Center PowerShell or standalone Exchange Online Protection PowerShell using modern authentication. The cmdlet works […] - [DHCP Migration from Windows 2008 R2 to 2012 R2](https://ammar.cloud/dhcp-migration-from-windows-2008-r2-to-012-r2/): Migrated DHCP (Dynamic Host Configuration Protocol) for one of my client from Windows Server 2008 R2 to Windows Server 2012 R2. It was very easy and quick. On Windows Server 2008 R2 C:\ netsh dhcp server> export c:\dhcp\dhcpdata.dat all Copy the dhcpdata.dat file on the Windows Server 2012 R2 C:\dhcp folder, you will have to create a new folder you can give any name, in my case I used folder name as dhcp. Stop the DHCP Services Go the elevated command prompt and run the following command C:\ netsh dhcp server> import c:\dhcp\dhcpdata.dat all Start the DHCP Services Open DHCP console […] - [Updated guidance on Exchange Server security - By Microsoft](https://ammar.cloud/updated-guidance-on-exchange-server-security-by-microsoft/): Microsoft has shared additional guidance and product updates to help you and your customers following last week’s March 2021 Exchange Server Security Updates. Consolidated Guidance. The below guidance consolidates information from multiple Microsoft blogs and communications to explain the situation and help clarify the steps required to respond: • An updated MSRC blog post Multiple Security Updates Released for Exchange Server – updated March 8, 2021 to provide a comprehensive overview of the security updates for Exchange Server and recommended steps to patch and remediate. • Step-by-step instructions on patching and remediation, detailed by version of Exchange Server. Security updates for […] - [Service Availability Math in 9's](https://ammar.cloud/service-availability-math-in-9s/): Usually some engineers get confused when it comes the service availability when it comes to number of 9’s. Uptime            Downtime (Yearly) 99.00000%      3d 15h 39m 99.90000%      8h 45m 56s 99.99000%      52m 35s 99.99900%      5m 15s 99.99990%      31s 99.99999%      3s - [Configuring Exchange2013/2016/2019 Virtual Directories PowerShell Scripts](https://ammar.cloud/configuring-exchange2013-2016-2019-virtual-directories-powershell-scripts/): OWA Virtual Directory Set-OWAVirtualDirectory –Identity “OWA (default web site)” -ExternalURL “https://mail.domainname.com/OWA” Set-OWAVirtualDirectory –Identity “OWA (default web site)” -InternalURL “https://mail.domainname.com/OWA”   OAB Virtual Directory Set-OABVirtualDirectory –Identity “OAB (default web site)” -ExternalURL “https://mail.domainname.com/OAB” Set-OABVirtualDirectory –Identity “OAB (default web site)” -InternalURL “https://mail.domainname.com/OAB”   ECP Virtual Directory Set-ECPVirtualDirectory –Identity “ECP (default web site)” -ExternalURL “https://mail.domainname.com/ECP” Set-ECPVirtualDirectory –Identity “ECP (default web site)” -InternalURL “https://mail.domainname.com/ECP”   EWS Virtual Directory Set-WebServicesVirtualDirectory –Identity “EWS (default web site)” -ExternalUrl “https://mail.domainname.com/ews/exchange.asmx” Set-WebServicesVirtualDirectory –Identity “EWS (default web site)” -InternalUrl “https://mail.domainname.com/ews/exchange.asmx”   ActiveSync Virtual Directory Set-ActiveSyncVirtualDirectory –Identity “Microsoft-Server-ActiveSync (default web site)” -ExternalURL “https://mail.domainname.com/Microsoft-Server-ActiveSync” Set-ActiveSyncVirtualDirectory –Identity “Microsoft-Server-ActiveSync (default web site)” -InternalURL “https://mail.domainname.com/Microsoft-Server-ActiveSync” Set-AutodiscoverVirtualDirectory -Identity […] - [upgrade the discovery mailboxes to R5 version, this will fix the RecipientDisplayType property of the discovery mailbox which was wrong in R4](https://ammar.cloud/upgrade-the-discovery-mailboxes-to-r5-version-this-will-fix-the-recipientdisplaytype-property-of-the-discovery-mailbox-which-was-wrong-in-r4/): During the Exchange 2013 upgrade to latest CU23, on the Step 5th out of 9, during the Mailbox Server Role I got the below error and solution is provided below. Error: The following error was generated when “$error.Clear(); if (($RoleIsDatacenter -ne $true) -and ($RoleIsDatacenterDedicated -ne $true)) { if (test-ExchangeServersWriteAccess -DomainController $RoleDomainController -ErrorAction SilentlyContinue) { # upgrade the discovery mailboxes to R5 version, this will fix the RecipientDisplayType property of the discovery mailbox which was wrong in R4. get-mailbox -RecipientTypeDetails DiscoveryMailbox -DomainController $RoleDomainController | where {$_.IsValid -eq $false} | set-mailbox -DomainController $RoleDomainController $name = [Microsoft.Exchange.Management.RecipientTasks.EnableMailbox]::DiscoveryMailboxUniqueName; $dispname = [Microsoft.Exchange.Management.RecipientTasks.EnableMailbox]::DiscoveryMailboxDisplayName; $mbxs = @( get-mailbox […] - [Turning Exchange 2013/2016/2019 Out Of Maintenance Mode](https://ammar.cloud/turning-exchange-2013-2016-2019-out-of-maintenance-mode/): This process has been applied successfully in an Exchange 2016 production environment. Below is the process to take out the Exchange Server from the Maintenance Mode. Run the below command to take out the Exchange Server from the Maintenance Mode [PS] C:\>Set-ServerComponentState “EXCH002” -Component ServerWideOffline -State Active -Requester Maintenance   Resume the Cluster Node [PS] C:\>Resume-ClusterNode -Name “EXCH002”   Name         ID    State —-               —    —– EXCH002        1     Up   Run the DatabaseCopyAutoActivationPolicy [PS] C:\>Set-MailboxServer “EXCH002” -DatabaseCopyAutoActivationPolicy Unrestricted   Run the DatabaseCopyActivationDisabledAndMoveNow command to activate the Database Replication for the node. [PS] C:\>Set-MailboxServer “EXCH002” -DatabaseCopyActivationDisabledAndMoveNow $false   Allow the HubTransport role to […] - [Turning Exchange 2013/2016/2019 into Maintenance Mode](https://ammar.cloud/turning-exchange-2013-2016-2019-into-maintenance-mode/): This process has been applied successfully in an Exchange 2016 production environment. I am having a three (3) node Exchange 2016 in a DAG, for patching Exchange, it is a recommendation to put the Exchange Server into the maintenance mode and then do the patching in order to avoid any Disconnectivity issues from the clients perspective and a seamless upgrade/update. Let’s begin…. This process is for One Server in DAG and applies to all, one by one. Never try to get over smart and put two servers in maintenance mode thinking that Exchange Services will work on One Server. You might […] - [Notification: Security Updates Released (Out-of-Band) for Critical Exchange Server Vulnerabilities](https://ammar.cloud/notification-security-updates-released-out-of-band-for-critical-exchange-server-vulnerabilities/): What is the purpose of this notification? This notification provides guidance for customers regarding new security updates released by Microsoft to resolve privately reported security vulnerabilities that affect Exchange Server 2013, Exchange Server 2016, and Exchange Server 2019.  We are releasing updates for Exchange Server 2010 for defense-in-depth purposes. Recommend Actions:  Microsoft recommends placing a high priority on deploying the March security updates to address these critical security vulnerabilities. Priority should be given to Internet-facing Exchange servers, which are at increased risk. Please factor in extra servicing time for any Exchange servers that are not running a currently supported Update Rollup (UR) or Cumulative Update (CU). Any Exchange […] - [Recover "admin" password for Huawei eBackup Server Portal](https://ammar.cloud/recover-admin-password-for-huawei-ebackup-server-portal/): If you forget the “admin” password for Huawei eBackup Portal. Follow the steps mentioned below to recover: Run “Putty” and login in the eBackup Server. Use “hcp” user to login. The login in into root using “su root” command. The from root prompt run the following command: # export LD_LIBRARY_PATH=/opt/huawei-data-protection/ebackup/db/lib The run the following command: #opt/huawei-data-protection/ebackup/db/bin/gsql -d admindb -U gaussdb -p 6432 -c “update users set PASSWORD=’PH44rriNnyEPiExl1Ywma2657HlTX0yNt6OC+S6Su4ljJ+4kuwLsHAAUCrQq0zvVR/PmugOkvh+yOEr+Ke4fxw==’,SALT=’Am+eck+BsLE=’ where username=’admin'” Enter the password for GaussDB i.e. Huawei@CLOUD8! Then login in the eBackup Portal using “admin” account and password is Huawei@CLOUD8! - [The underlying connection was closed: Could not establish trust relationship for the SSL/TLS secure channel.](https://ammar.cloud/set-mgmtsvcrelyingpartysettings-the-underlying-connection-was-closed-could-not-establish-trust-relationship-for-the-ssl-tls-secure-channel/): I was configuring integration between ADFS and WAP (Windows Azure Pack), upon running the below commands on my Azure Admin Hub Server I got an error. Command: Set-MgmtSvcRelyingPartySettings –Target Admin –Metadata-endpoint ‘https://adfs.domain.com:443/FederationMetadata/2007-06/FederationMetadata.xml’ -ConnectionString “Data Source=wapdb\wapdb;User ID=sa;Password=xxxxxxxxxx” Error: Set-MgmtSvcRelyingPartySettings : The underlying connection was closed: Could not establish trust relationship for the SSL/TLS secure channel. Solution: Make sure that a valid SSL certificate received from the CA Authority is installed on the ADFS Server. On ADFS Server, on the elevated PowerShell configure the SSL Certificate by running the below command, the Thumbprint is of the a Valid SSL Certificate received from CA: […] - [Error 23317 SCVMM 2012 R2 upon changing the properties of a VM with a Shared Disk](https://ammar.cloud/error-23317-scvmm-2012-r2-upon-changing-the-properties-of-a-vm-with-a-shared-disk/): Error (23317) The operation Change properties of virtual machine is not permitted on a virtual machine that has shared virtual hard disks. Recommended Action The operation Change properties of virtual machine is not permitted on a virtual machine that has shared virtual hard disks. Above error appeared when when I was trying to change the VM properties for one of my client. It will not allow changing using GUI, but yes, you can use the PowerShell and it is easy. You will have to just change the parameters as per your requirement. $VM = Get-SCVirtualMachine -VMMServer scvmm.ammar.cloud -Name “SQLDB01” -ID “f4859bbe-2755-4d47-a515-385cd9d1eb23” […] - [Migrating M365 (Office 365) from one tenant to another tenant with a domain name change.](https://ammar.cloud/migrating-m365-office-365-from-one-tenant-to-another-tenant-with-a-domain-name-change/): Recently I have migrated an M365 (Formerly office 365) Tenant to another M365 Tenant portal with a Domain Name change and the customer also wanted to keep the source domain for receiving emails. Additionally, customer wanted to the use a new Active Directory on-premise to synchronize users with M365 using AD Connect. This migration plan will also consists of a Third Party Migration Tool, as currently Microsoft does not support built-in tenant-to-tenant migration. Source: sourcedomain.com & Target: targetdomain.com Migration approach was been divided into Two Phases: Phase 1 Preparing an on-premise a new fresh Domain Controller with Targetdomain.com. Creating the users […] - [don't lose access to your account! (Prompt for M365 Users)](https://ammar.cloud/dont-lose-access-to-your-account-prompt-for-m365-users/): M365 Users (Formerly Office 365) when login into their mailboxes using https://outlook.office365.com/owa they get a prompt saying “don’t lose access to your account!” sometimes it annoys the users and usually Administrator wouldn’t allow the users to control their account security. To solve the issue, follow the steps. login into https://admin.microsoft.com with Admin Credentials. On the left pane under “Admin centers” click “Azure Active Directory” Once logged in, on the Dashboard under Manage click Users Click on Password reset. Click on Registration, on the right pane select No and click Save. Problem solved!       - [Microsoft Exchange Server 2016 Transport Service Stopped](https://ammar.cloud/microsoft-exchange-server-2016-transport-service-stopped/): When we restart the transport service (MSExchangeTransport) it again stops in few seconds because of which mail flow (incoming & outgoing) was out of service. Upon checking the Event Viewer I found the below error with an Event ID 16023. Based on the below error snapshot, I noticed that “Microsoft.Exchange.Transport.Agent.MalwareApp.dll” file located under “C:\Program Files\Microsoft\Exchange Server\V15\TransportRoles\agents\Antimalware” directory could not be loaded with an Access Denied. Solution Should be applied on all the Exchange Servers 2016 Go to C:\Program Files\Microsoft\Exchange Server\V15\TransportRoles\agents Right Click Antimalware, then go to Security (tab) the Select NETWORK SERVICE and give Full Permission. - [Clearing Exchange Mail Queues using PowerShell](https://ammar.cloud/clearing-exchange-mail-queues-using-powershell/): It happens sometimes due to Exchange misconfiguration, there could be a spoof email attack which means Exchange Server sends out spam emails using external sources or any other reason. In this article I will only show you how can we remove the mail queue in bulk through PowerShell ISE without sending NDR (Non Delivery Report). Solution: Login to the Exchange Server. Right Exchange Management Shell and Click on Run ISE as Administrator Run the below mentioned script and it will clear the mail queue in bulk. $Servers = “EXCH01″,”EXCH02” #Enter the name of all CAS servers foreach ($server in $servers) { […] - [How to install VM Tools for SLES 15 on FusionCompute 6.5.1](https://ammar.cloud/how-to-install-vm-tools-for-sles-15-on-fusioncompute-6-5-1/): By default, On Huawei’s FusionCompute 6.5.1 we cannot install VM Tools for SLES15 (SUSE Linux Enterprise Server 15). Qemu-guest-agent (default version that comes with FusionCompute 6.5.1 for SLES) doesn’t support the with vm-agent for SLES15. So we have found a practice that will enable vm-agent running successfully. We need to apply the following steps: Uninstall qemu-guest-agent install vm-agent for SLES check vm-agent started successfully by running $ sudo service vm-agent status install qemu-guest-agent restart vm-agent –> sudo vm-agent restart Open Yast à Software manager Remove Qemu-guest-agent Open terminal (Suppose /dev/sr0 as a mounted drive which is having vm-tools-* ) $ mkdir […] - [How to Configure External Relay Connector in Exchange 2016](https://ammar.cloud/how-to-configure-external-relay-connector-in-exchange-2016/): Custom Receive Connector for an Application Hosted Externally to use Exchange Server 2016 as a Relay My Exchange 2016 is a highly available multi-tenant environment. I have a tenant who has an application hosted with a third party and want to use our Exchange 2016 as a relay to send notifications to their customers. Receive messages from a server, service, or device that does not use Exchange. In this scenario, the Receive Connector listens for connections on port 25, but only from the specific IP address of the service, or device. It is also likely that this scenario requires some type […] - [452 4.3.1 Insufficient System Resources](https://ammar.cloud/452-4-3-1-insufficient-system-resources/): Users mailboxes hosted on my Exchange 2016 started facing issues in receiving the email, and the sender were receiving an NDR with the following error: I checked all of my Exchange Servers queue size C:\Program Files\Microsoft\Exchange Server\V15\TransportRoles\data\Queue\mail.que is around 10GB on all of them. Generally, it is referring to Back Pressure; in short, Back pressure is a system resource monitoring feature of the Microsoft Exchange Transport service that exists on Mailbox servers and Edge Transport servers. Back Pressure monitors mainly the following criteria’s in Microsoft Exchange: DatabaseUsedSpace[%ExchangeInstallPath%TransportRoles\data\Queue]: Hard drive utilization for the drive that holds the message queue database PrivateBytes: The […] - [Uninstall Exchange 2010 SP3 Scripts Issue](https://ammar.cloud/uninstall-exchange-2010-sp3-scripts-issue/): After migrating Exchange 2010 to Exchange 2016, it was time to decommission Exchange 2010 (Single Server), I used the same Exchange 2010 SP3 setup package for uninstall I which used at the time of Exchange 2010 Upgrade. Note that I’ve already moved all the mailboxes, Default mailboxes, Arbitration mailboxes, System Mailboxes to my new Exchange 2016. Following command is required to run the package: C:\temp\Exch2010SP3\setup.com /mode:uninstall During the setup it prompted with the below error and failed the uninstall process: Stopping Services FAILED The following error was generated when “$error.Clear(); & $RoleBinPath\ServiceControl.ps1 -Operation:DisableServices -Roles:($ Roles.Replace(‘Role’,”).Split(‘,’)) -SetupScriptsDirectory:$RoleBinPath; & $RoleBinPath\ServiceControl.ps1 Stop $RoleRoles.Replace(‘Role’,”).S (‘,’) […] - [Clear Out Logs for Exchange 2013/2016/2019](https://ammar.cloud/clear-out-logs-for-exchange-2013-2016-2019/): For every task that is performed in the back-end on our Exchange Servers, there are tons of logs generated at each time. Exchange Administrators need to clear out the logs on regular basis or if the disk gets full then the Databases gets dismounted and mail services will go down. Follow the below process to clear out the logs which I have been following since years successfully: C:\inetpub\logs\LogFiles: Delete all the logs from both the folders W3SVC1 and W3SVC2 C:\Program Files\Microsoft\Exchange Server\V15\Logging\Diagnostics:Delete all the logs from DailyPerformanceLogs and PerformanceLogsToBeProcessed folders. C:\Program Files\Microsoft\Exchange Server\V15\Logging\RpcHttp: Delete all the logs from both the folders […] - [421 4.7.0 Too many errors; closing connection Exchange 2016](https://ammar.cloud/421-4-7-0-too-many-errors-closing-connection-exchange-2016/): Exchange 2016 running across three (3) Server in DAG, On Exchange01 i could see the all the email are getting stuck in queues including authentic emails and queues. The below image isn’t clear but the error description is “421 4.7.0 Too many errors; closing connection” Resolution: 1. Login into ECP, go to Mail Flow, then Receive Connectors 2. Remove the check mark from “Anonymous users” across all the Exchange Servers and restart Transport Service in all the Servers. - [Recovering Deleted Objects from Active Directory](https://ammar.cloud/recovering-deleted-objects-from-active-directory/): Usually I’ve seen many Systems Administrators that they delete the objects in Active Directory and recreate it again but I really don’t understand the reason behind the deletion. I can understand the Accidental Deletion (human errors are possible) but no need to create them again. Microsoft has provided a built-in tool to recover the deleted Objects named Ldp.exe We will go through the steps on how to recover/restore the accidental deletion of an Active Directory Object. Start Run, type exe and click Ok Click Connection click Bind and Select Bind with credentials then enter the credentials click Ok           Go to […] - [Stopping Exchange 2016 Internal SPAM Spoofing](https://ammar.cloud/stopping-exchange-2016-internal-spam-spoofing/): Exchange Server 2016 Multi-Tenant Environment. Root Domain for example root.com I have a huge list of tenants in Exchange Servers, Let’s say: tenant1.com, tenant2.com, tenant3.com and so on…. Public and Internal DNS records for all the domains are created and working fine. Suddenly Exchange Servers started sending out SPAM emails using postmaster@root.com to abc@anydomain.com which doesn’t existing in Exchange and Exchange Queues use to pileup in 100’s and 1000’s. Which was becoming the major cause of IP getting blacklisted. However, the best places we found to combat this involved removing the permission: ms-exch-smtp-accept-authoritative-domain-sender in the active directory for the receive connectors. […] - [Cannot Activate a Database Copy on the Secondary Mailbox Server: EXCHANGE 2010 SP3](https://ammar.cloud/cannot-activate-a-database-copy-on-the-secondary-mailbox-server-exchange-2010-sp3/): I have Two HUB/CAS Server (CAS1 and CAS2) and Two Mailbox Servers (MBX1 and MBX2) running in DAG, and running as VMs. MBX1 has some issues and the moment VM starts Exchange Database go down. We planned to discard the MBX1 and we introduced new MBX3 Exchange 2010 SP3 with the same build number and added to the existing DAG. In total we had 5 Databases: DB1, DB2, DB3, DB4 and DB5 As MBX1 was down we couldn’t mount the Database on MBX2 with the normal procedure i.e. Right Click  and Click Mount Database (it always fails) We had to run […] - [Huawei VDI Project Implementation](https://ammar.cloud/huawei-vdi-project-implementation/): Huawei VDI Project Implementation Our company was hired for one of the government project somewhere in North Africa for implementing VDI for their desktop users. I was chosen to visit and complete the project. I shall take you with the process of deploying the VDI, and highlight the issues I faced and how I resolved it. Components Involved Hardware S.No Product Name 1 2288H V5 (Compute and Storage Node) 2 FusionAccess TC Software Package S.No Product Name Version 1 Fusion Compute FusionCompute 6.5.1 2 Fusion Storage Block Fusion Storage Block V100R006C30SPH505 3 Fusion Access Fusion Access V100R006C20SPC101   Deployment Process Flowchart […] - [Migrating Exchange 2010 to 2016](https://ammar.cloud/migrating-exchange-2010-to-2016/): Migrating Exchange 2010 to Exchange 2016 I recently migrated Exchange 2010 SP3 to Exchange 2016 for the one of the customer, the migration was done overnight. So I would like to share my experience with the task performed and the steps I had undertaken. Old Environment running on One Physical Server Active Directory (Windows Server 2008 R2 Enterprise) Exchange 2010 SP3 (Mailbox and CAS Roles) Symantec Antispam DHCP Server RRAS The issue with the customer was every now and then email flow stops working and because of multiple components installed on one single server it was becoming difficult to isolate the […] - [.NET Framework 3.5 installation error: 0x800F0906, 0x800F081F, 0x800F0907](https://ammar.cloud/net-framework-3-5-installation-error-0x800f0906-0x800f081f-0x800f0907/): One of my client wanted to use MS Access based software over the VDI Platform and the main prerequisite for the same is to install .Net Framework 3.5 or higher. .Net Framework 3.0 version couldn’t be installed manually or through group policy and prompted with the following error codes: .NET Framework 3.5 installation error: 0x800F0906, 0x800F081F, 0x800F0907 The Windows 10 OS Build used was Windows 10 1903 (18362.295). Action Taken Downloaded the latest media with Build 1903 and mount it on the VM. Run an elevated command prompt and run the following command from the VM: DISM /Online /Enable-Feature /FeatureName:NetFx3 /All […] - [Azure Remote Desktop Console Connect](https://ammar.cloud/azure-remote-desktop-console-connect/): I have been trying to resolve the console connect issue since a long time, I involved my colleague to help me in resolving the issue. We completed the following steps successfully but still the error exists: Issuing the certificate Installing the certificate on all the Hyper-V Hosts Installing the Certificate on SCVMM Server and Hyper-V Host by using the below script by running ## Variables # Path to PFX file $MyPFX = Get-ChildItem “\\servername\c$\Temp\rdgw.pfx” # Password of the PFX $PWD = Read-Host –AsSecureString # VMM FQDN server name. $VMM = “vmm.contoso.com” ## Main Code Set-SCVMMServer -VMMServer $VMM ` -VMConnectHostIdentificationMode FQDN ` […] - [SCVMM 2012 R2 – Host Status “Need Attention” and Job Status “Failed”](https://ammar.cloud/scvmm-2012-r2-host-status-need-attention-and-job-status-failed/): I’ve have been facing an issue in System Center 2012 R2 – Virtual Machine Manager that one of my Hyper-V Host Cluster Server Host Status states “Need Attention” and Job Status “Failed”   I followed the solution recommended by Microsoft as shown below, but unfortunately no help Error (20552) VMM does not have appropriate permissions to access the resource C:\Windows\system32\qmgr.dll on the fmhvhost03.mgmt.local server. Recommended Action Ensure that Virtual Machine Manager has the appropriate rights to perform this action. Also, verify that CredSSP authentication is currently enabled on the service configuration of the target computer fmhvhost03.mgmt.local. To enable the CredSSP on […] - [Reclaim the Space Used by Volume Shadow Copy On Exhcange Server 2013](https://ammar.cloud/reclaim-the-space-used-by-volume-shadow-copy-on-exhcange-server-2013/): One of my friend had an issue with his Exhcange 2013 running on Windows Server 2012 Standard, where the Exchange Database Volume used to get full with no progres in the Database Size. Volume Size = 590 GB Database Size: 530 GB Available Space = 30 GB So balance 30GB was missing with no clue. Upon trouble shooting we found that it was being used by Volume Shadow Copies. Go to the Volume –> Right Click and Click Configure Shadow Objects   Open the elevated Command Prompt to check the status of the list of Shadow Copies by running the following […] - [Huawei ThinClient ST5110 Configruation Lost After Restart](https://ammar.cloud/huawei-thinclient-st5110-configruation-lost-after-restart/): We did a successful VDI implementation for one of the Government Sector in Kuwait. I’m not sure if I am authorized to reveal which Government Sector it is. But anyways after the implementation when we connect the VDI Thin Client to the wired network it was worked absolutely fine, but when we connected to the Wireless network and saved somefiles on the Desktop or any other location upon the restart of the Thin Client it doesn’t connect automatically and all the saved files were gone. So below are the steps that we need to follow to make it work. Go to […] - [Exchange Server 2016 Mailbox Export Request Error](https://ammar.cloud/exchange-server-2016-mailbox-export-request-error/): To give you a brief about my environment, we are running a very sophisticated multi-tenant environment for serving our customers/users. I had a request export one mailbox from Exchange, Exchange mailbox was hosted in the root domain and the user account was available a separate domain in an existing forest. Once I run the command “New-MailBoxExportRequest”, I was getting the following error WARNING: An unexpected error has occurred and a Watson dump is being generated: Object reference not set to an instance of an object. WARNING: Task module “LoggingModule.OnIterateCompleted” fails with exception “Object reference not set to an instance of an […] - [System Center Configuration Manager (SCCM) Upgrade Process](https://ammar.cloud/system-center-configuration-manager-sccm-upgrade-process/): My current SSCM environment is running with SSCM 2012 R2 version, the latest version available on Microsoft is SSCM 1810. After going through lot of articles available online, I found that we can’t just directly upgrade from SSCM 2012 R2 to SSCM 1810. We need follow the baseline versions. Baseline: Version that you can use to upgrade SCCM 2012 or install a new site. Always use the latest available baseline for these scenarios. Reference: Microsoft and www.SystemCenterDudes.com Below are the releases and upgrade path: Release Version Build Baseline Microsoft Link SCCM 2012 RTM 5.00.7711.0000 7711 N/A N/A SCCM 2012 RTM – […] - [Microsoft Exchange Server Address Lists – Multi-Tenant Environment](https://ammar.cloud/microsoft-exchange-server-address-lists-multi-tenant-environment/): Applies to Exchange Server 2013/2016 – Amir Moiz Gulamaliwala In an Exchange Multi-Tenant environment, it is mandatory for the Systems Consultants to maintain a separate Exchange Address Lists for every domain hosted within the Exchange Server. There are many free open source tools available online and paid one as well where you can install and integrate them with you Exchange environment and start using it, but in this article I will explain how to create Exchange Address Lists using PowerShell. Root Domain – cloud.local Customer or Entity Domain Name: company.com Already added in my Exchange Admin Center under Accepted Domains OU […] - [OceanStor Dorado ALL-Flash Storage](https://ammar.cloud/oceanstor-dorado-all-flash-storage/): Reference: Huawei Technologies Enterprises are finding accurate decision-making more and more challenging in the face of today’s massive, complex, and rapidly changingdata. They are in urgent need of high-performance IT infrastructures tosupport the quick analysis of massive amounts of data and the extraction of valuable information. Huawei’s OceanStor Dorado V3 all-flash storage isable to deliver 0.5 ms consistent latency by incorporating intelligent chips,NVMe architectures, and Huawei’s FlashLink® intelligent algorithms toachieve end-to-end optimizations from SSDs and controllers, which helpimprove the application performance threefold and reduce report generation time to one third. It can scale out to 16 controllers and 7,000,565 SPC-1 IOPSTM, […] - [Scale Out File Server - Cluster Operating System Rolling Upgrade](https://ammar.cloud/scale-out-file-server-cluster-operating-system-rolling-upgrade/): Applies to: Windows Server 2012 R2 and Windows Server 2016 – Amir Moiz Gulamaliwala I’ve been working with my team quite long on planning to upgrade our Scale Out File (SOFS) Server Two Node Cluster from Windows Server 2012 R2 to Windows Server 2016. Now it’s the time to move forward J Our current SOFS cluster is configured with SMB 3.0 which serves the storage to Hyper-V Clusters in the form of shares highly available. I’ve also been following couple of articles available on Microsoft Docs; I will also share the link at the end of my article which gave me […] - [Shadow Redundancy in Exchange Server](https://ammar.cloud/msexchange-shadow-redundancy/): Reference: Microsoft Documentation https://docs.microsoft.com/en-us/exchange/mail-flow/transport-high-availability/shadow-redundancy?view=exchserver-2016 Shadow redundancy was introduced in Exchange 2010 to provide redundant copies of messages before they’re delivered to mailboxes. In Exchange 2010, shadow redundancy delayed deleting a message from the queue database on a Hub Transport server until the server verified that the next hop in the message delivery path had completed delivery. If the next hop failed before reporting successful delivery back to the Hub Transport server, the server resubmitted the message to that next hop. Exchange 2010 Hub Transport servers used the XSHADOW verb to advertise their shadow redundancy support. If a source messaging server didn’t […] - [Huawei's FusionAccess DesktopCloud](https://ammar.cloud/huaweis-fusionaccess-desktopcloud/): About FusionAccess – Huawei Click on the below link to download the brochure. Huawei FusionAccess Desktop Cloud Brochure Reference: Huawei Technologies For any inquiry contact: amir.moiz@octalpha.com - [Remote Desktop Server Gateway – Console Access Error (Certificate Issue)](https://ammar.cloud/remote-desktop-server-gateway-console-access-error-certificate-issue/): After configuring a new Azure Portal Subscription in our Private Cloud for one customer. Upon accessing the VM through Remote Desktop console, the below error appeared:Recently we had renewed the certificate for Azure services, but somehow missed to import the certificate in RDS Gateway Server, below is the process to do the same: Step 1: Open “Remote Desktop Gateway Manager” in “Start menu” Step 2: User left click on “ServerName” in “RD Gateway Manager” Step 3: Click in “RD Gateway Manager” Step 4: Click on “Import Certificate” in “ServerName Properties” Step 5:  Click on “*.domainname.com” in “Import Certificate” Step 6: User […] - [MailboxExportRequest - Removal](https://ammar.cloud/mailboxexportrequest-removal/): Due to MailBoxExportRequest exists I couldn’t remove the empty mailbox database from Exchange Server. During our upgrade from Exchange 2013 to Exchange 2016, we moved all the mailboxes from Exchange 2013 database to a new database created on Exchange 2016. When I tried to remove the empty database I got “MailboxExport request” error as shown below: I found that old mailbox requests exists pertaining to the database which I want to remove. By running the below command I checked the details of the execution of the MailBoxExportRequest which was done one year back. [PS] C:\Windows\system32>Get-MailboxExportRequest | fl Then, removed the existing […] - [Configuring System Center Virtual Machine Manager 2016](https://ammar.cloud/configuring-system-center-virtual-machine-manager-2016/): Configuring SCVMM 2016 Add DOMAIN\SCVMM-AdminAction under Settings à Run As Accounts as shown below:   Adding Hyper-V Host Servers Step 1 Open SCVMM Console and click on “All Hosts” Step 2 Right click on “All Hosts” and click on “Add Hyper-V Hosts and Clusters” Step 3 Click on “Next” Step 4 Click on “Browse” Step 5 Click on “SCVMM Admin Action” in “Select a Run As Account” Step 6 Select SCVMM Admin Action account and click on “OK” Step 7 Click on “Next” Step 8 Click on “Next” Step 9 Select the Host Cluster and click on “Next”   Step 10 […] - [Installing System Center Virtual Machine Manager 2016](https://ammar.cloud/installing-system-center-virtual-machine-manager-2016/): Inside this article we will cover the installation of SCVMM in a cluster environment, let’s have a look on the required pre-requisites for installing SCVMM 2016. Prerequisites Create the following Service Accounts in to your AD: DOMAIN\VMM-SVC (SCVMM Service Account) DOMAIN\ SCVMM-AdminAction (SCVMM Service Account for Adding Hyper-V Hosts in SCVMM 2016) DOMAIN\SCVMM-Admins (SCVMM Global Security Group) Note: Add DOMAIN\VMM-SVC, DOMAIN\ SCVMM-AdminAction and Domain Administrators to DOMAIN\SCVMM-Admins Security Group Distributed Key Management for SCVMM: In Active Directory Click Next and Finish Value: CN=VMMDKM,DC=cloud,DC=local 2. SQL Server Instance (For installing SCVMM 2016) 3. Run the following on SCVMM 2016 Servers to have […] - [WSUS Post-Installation Failed](https://ammar.cloud/wsus-post-installation-failed/): After successfully installing Windows Update Server Service (WSUS) role in my  Windows 2012 R2 server I got the below error during post-installation. CreateDefaultSubscription failed. Exception: System.Net.WebException: The request failed with HTTP status 503: Service Unavailable In order to RESOLVE the issue, go to IIS Manager under ServerName -> Sites –> delete “WSUS Administration” site. Then re-run the Post-Installation task. It will be completed successfully. - [Installing System Center Configuration Manager 2012 R2](https://ammar.cloud/installing-system-center-configuration-manager-2012-r2/): Once we have successfully installed all the SCCM prerequisites we can now install SCCM. Please follow the step mentioned in the below link. Installing Microsoft SCCM 2012 R2 - [Prerequisites for Installing SCCM 2012 R2](https://ammar.cloud/prerequisites-for-installing-sccm-2012-r2/): System Center Configuration Manager provides a unified management console with an automated set of administrative tools to deploy software, protect data, monitor health, and enforce compliance across all devices in an organization. Refer the below Microsoft link for the SCCM Capabilities: https://www.microsoft.com/en-us/cloud-platform/system-center-configuration-manager-features In order to install SCCM 2012 R2, there are certain perquisites that we need to consider in order to have a smooth installation. Please refer the below link for step-by-step perquisites required for SCCM 2012 R2 Microsoft SCCM 2012 R2 Prerequisites - [Remove an instance from the SQL Failover Cluster](https://ammar.cloud/remove-an-instance-from-the-sql-failover-cluster/): I have a two (2) node SQL Failover Cluster, and I had install an instance in my one of the SQL Failover Cluster node. For some reason I had to uninstall this instance but when I tried uninstalling through: Control Panel –> Program and Features —> Right click on Microsoft SQL Server 2012 (64 bit) and click remove, and it failed because when you try to remove it from Control Panel you get the following error: In order to remove the SQL Failover Cluster Instance successfully use the following steps:   Double click on the SQL Server “Setup.exe”. 2.  Click on […] - [Hyper-V VM Network Settings for Linux](https://ammar.cloud/hyper-v-vm-network-settings-for-linux/): I have a cluster environment containing of four(4) hyper-v hosts, which includes both Windows and Linux VMs. I had to take one hyper-v host down for maintenance purpose so I moved my Windows and Linux machines to another hosts. Once I moved Linux VM to another host I was not able to access my Linux VM, upon further trouble shooting I found that once Linux VM moves to another hyper-v host it loses network connectivity. So once you deploy Linux VMs makes sure you set the Network Adapter Mac Address as “Static”, then your issue is solved. - [Ransomware Attacks](https://ammar.cloud/ransomware-attacks/): We all know that RANSOMWARE ATTACKS are stopping our ongoing business operations and IT personnel’s keep scratching their heads just to find a solution to recover the data as much as possible, below link shall help to find the relevant tools to Decrypt the Encrypted data from the below link. https://www.nomoreransom.org/decryption-tools.html The above “No More Ransom” website is an initiative by the National High Tech Crime Unit of the Netherlands’ police, Europol’s European Cybercrime Centre and two cyber security companies – Kaspersky Lab and Intel Security – with the goal to help victims of ransomware retrieve their encrypted data without having […] - [Skype for Business Server Front-End Service Status Starting](https://ammar.cloud/skype-for-business-server-front-end-service-status-starting/): After installing my third server in my existing Skype for Business Server Topology, I could see that “Skype for Business Server Front-End Service” status is “Starting” and it doesn’t come up I checked event viewer and found the below error: General Tab: FM resolving failed with FABRIC_E_SERVICE_OFFLINE Log Name: Microsoft-Windows-Windows Fabric/Admin Source: Windows Fabric Event ID: 16385 Level: Warning User: NETWORK SERVICE Steps to follow to resolve the issue: Stop all the Skype for Business Server Services and Windows Fabric Service Disable all the Skype for Business Server Services after running the following command from windows powershell : Get-Service -DisplayName “Skype […] - [Windows Server Update Service (WSUS) - Error: Database Error](https://ammar.cloud/windows-server-update-service-wsus-error-database-error/): I’ve been using WSUS Server to update all my member servers, once upon running the WSUS console I found that the console crashes and prompts with “ERROR: Database Error” Upon further trouble shooting I found that there was a windows update KB3159706, once this update is installed it crashes the WSUS console. Uninstall the update shown below from Control Panel –> Windows Updates and restart the server. After the server was restarted I was able to login into my WSUS successfully. To avoid this update installing automatically, we can hide the update, as shows below right click on the update and […] - [Creating a new network for a tenant in Virtual Machine Manager 2012 R2](https://ammar.cloud/creating-a-new-network-for-a-tenant-in-virtual-machine-manager/): Download the steps with images from this link – Creating a Network for a New Tenant in VMM - [Repairing Windows Server 2008 32bit VM after conversion](https://ammar.cloud/repairing-windows-server-2008-32bit-vm-after-conversion/): After converting a Windows Server 2008 32bit physical machine to a virtual machine, upon boot up if you get the error shown in the below image. Follow the steps mentioned below: Shutdown the VM Mount Windows Server 2008 32bit media and boot the server using that media Go to “Repair my computer” Open Windows Command Prompt X:\Sources> Diskpart Diskpart > List Volume (Assuming Windows C: drive is Volume 1) Diskpart > Select Volume 1 Diskpart > active Diskpart> exit X:\Sources> Copy f:\BootMgr c:\ If the file Bootmgr already exists on C:, type N to avoid overwriting it If the file Bootmgr […] - [Exchange Server 2010/2013 - Deleted Item retention](https://ammar.cloud/exchange-server-20102013-deleted-item-retention/): Set Deleted Item retention period for all databases Get-MailboxDatabase | Set-MailboxDatabase -DeletedItemRetention 35   Enable retention period per mailbox get-mailbox -RecipientType ‘UserMailbox’ | Set-Mailbox -SingleItemRecoveryEnabled $true - [Purge disconnected mailboxes in exchange 2013](https://ammar.cloud/purge-disconnected-mailboxes-in-exchange-2013/): [PS] C:\Windows\system32>Get-MailboxDatabase | Get-MailboxStatistics | Where { $_.DisconnectReason -eq “Disabled” } | fl  DisplayName, mailboxguid,database,DisconnectDate DisplayName    : Name of the User MailboxGuid    : 8071dcfc-0288-4218-99fa-6ece4f832b08 Database       : MailboxDatabase0051256 DisconnectDate : 9/20/2016 3:59:40 PM [PS] C:\Windows\system32>Remove-StoreMailbox -Database MailboxDatabase0051256 -Identity “8071dcfc-0288-4218-99fa-6ece4f832b08” -MailboxState Disabled Confirm Are you sure you want to perform this action? Removing mailbox “8071dcfc-0288-4218-99fa-6ece4f832b08” on database “MailboxDatabase0051256”. [Y] Yes  [A] Yes to All  [N] No  [L] No to All  [?] Help (default is “Y”): a [PS] C:\Windows\system32> - [Removing SMTP Address in Bulk](https://ammar.cloud/removing-smtp-address-in-bulk/): Let’s say you have 100 mailboxes and you want to remove the smtp address in bulk, below are the steps you can follow in order to do so. Open Exchange Shell as administrator. Run the below two (2) commands one after the other. $qwe= get-content c:\New Folder\user.csv | Get-Mailbox $qwe | set-mailbox -emailaddresspolicyenabled:$True Then run the below script and press enter two times. ________________________________________________________________ foreach($i in Get-Content c:\New Folder\user.csv | Get-Mailbox -ResultSize Unlimited) { $i.EmailAddresses | ?{$_.AddressString -like ‘*@domain.com’} | %{ Set-Mailbox $i -EmailAddresses @{remove=$_} } } ___________________________________________________________________ - [Installing System Center 2012 R2 Data Protection Manager (DPM)](https://ammar.cloud/installing-system-center-2012-r2-data-protection-manager-dpm/): Assuming that the following tasks are already completed prior installing DPM 2012 R2: SQL Server for DPM Database SQL Reporting Services Run the DPM Setup on the DPM Server and click on Data Protection Manager under Install Click on I accept the license terms and conditions and click OK On Welcome page click Next Mention the SQL Server DPM Database and Reporting Services details to run the prerequisites check. To run prerequisites check click on Check and Install Once its runs the prerequisites check, it may give the errors as highlighted below: Microsoft System Center DPM Support Files are not installed […] - [Failover Cluster Configuration](https://ammar.cloud/failover-cluster-configuration/): Prerequisites:   Minimum two (2) Servers required for configuring Failover Cluster. Install Failover Cluster Manager Role from Server Manager à Add Roles and Features. A Virtual Disk (Quorum.vhdx) mounted on both the servers CLOUDSQL01 CLOUDSQL02 Below are the scripts that are using to create Quorum.vhdx file in the “Scale-Out File Server Share” and attaching it to both the Virtual Machines (CLOUDSQL01 and CLOUDSQL02).   To create a new .vhd New-VHD -Path \\cloudsofscap\FabricManagement\hyper-v\CLOUDCLUSTER04\Quorum.vhdx -Dynamic -SizeBytes 1GB -PhysicalSectorSizeBytes 4096 -LogicalSectorSizeBytes 4096 Attaching .vhdx to servers. Add-VMHardDiskDrive -VMName CLOUDSQL01 -Path \\cloudsofscap\FabricManagement\hyper-v\CLOUDCLUSTER04\Quorum.vhdx -SupportPersistentReservations Add-VMHardDiskDrive -VMName CLOUDSQL02 -Path \\cloudsofscap\FabricManagement\hyper-v\CLOUDCLUSTER04\Quorum.vhdx -SupportPersistentReservations Steps to create Failover Cluster Open […] - [Configuring System Center 2012 R2 Data Protection Manager (DPM)](https://ammar.cloud/configuring-system-center-2012-r2-data-protection-manager-dpm/): Assuming that we already have the following installed and configured: SQL Database for DPM (Clustered or Non-Clustered) SQL Reporting Services for DPM DPM Administration Console installed on the DPM Server In this scenario DPM is not a physical machine, it’s a Virtual Machine. We have attached Disk 1 and Disk 2 for taking backups using DPM. These two(2) disks will be used for Recovery Points and Replica Open the DPM Administration Console, navigate to Management and Click on Disks Click on Disks, then select Disk 1 and Disk 2 then click on Add and click OK Below screenshot shows Disks are […] - [Exchange DAG maintenance process](https://ammar.cloud/exchange-dag-maintenance-process/): Reference: Ladislav Bodnar Run Exchange PowerShell as administrator Cd $exscripts .\StartDAGServerMaintenance.ps1 -Server Servername Restart or shutdown VM .\StopDAGServerMaintenance.ps1 -Server Servername .\RedistributeActiveDatabases.ps1 –DagName DAG01 –BalanceDbsByActivationPreference –confirm:$false - [SQL Failover Cluster Installation](https://ammar.cloud/sql-failover-cluster-installation/): Assuming that you have two (2) SQL Failover Cluster Node Servers and you need to add more instances on it. SQL Server 2012 Installation Media mounted on both the SQL Server nodes Database and Logs VHDX/VHD mounted on the SQL Server and added in the Failover Cluster Manager Disks Be ready with the Instance Name and Instance IP Address Let’s start with installation. Mount the SQL Server disk on the VM and run the Setup file as Domain Administrator and Click on New SQL Server failover cluster installation link Setup Support Rules wizard should run successfully then click Ok, you can […] - [Sender Exceptions for Content Filtering](https://ammar.cloud/sender-exceptions-for-content-filtering/): Specify Recipient and Sender Exceptions for Content Filtering – Exchange Server 2007 SP3, Exchange Server 2007 SP2, Exchange Server 2007 SP1, Exchange Server 2007 To bypass content filtering of messages from example.com, run the following command: Set-ContentFilterConfig -BypassedSenderDomains example.com   To bypass content filtering of messages from specific domains and their subdomains, a wildcard character (*) can be used as shown in the following example: Set-ContentFilterConfig -BypassedSenderDomains *.example.com   To bypass content filtering of messages that are sent by sender1@example.com, run the following command: Set-ContentFilterConfig -BypassedSenders sender1@example.com - [Service Security Groups for Implementing Virtual Machine Manager](https://ammar.cloud/service-security-groups-for-implementing-virtual-machine-manager/): Component Group Name Group notes Operations Manager Operations Manager Administrators SCOM-Admins This group’s members are administrators for the Operations Manager installation and hold the Administrators role in Operations Manager. Orchestrator Orchestrator Administrators SCO-Admins This group’s members are administrators for the Orchestrator installation. Orchestrator Orchestrator Operators SCO-Operators This group’s members gain access to Orchestrator through membership in the Orchestrator Operators group. Any user account added to this group is granted permission to use the Runbook Designer and Deployment Manager tools. SQL Server SQL Server Administrators SQL-Admins This group’s members are sysadmins on all SQL Server instances and local administrators on all SQL […] - [Time Server Configuration](https://ammar.cloud/time-server-configuration/): On Primary AD w32tm /config /manualpeerlist:pool.ntp.org /syncfromflags:manual /reliable:yes /update On Secondary DC w32tm /config /syncfromflags:domhier /update Then run on both server this w32tm.exe /resync /rediscover To check status w32tm /query /status To check if the source is pool.ntp.org w32tm /query /source - [Address Book Policy – Exchange Multi-Tenant](https://ammar.cloud/address-book-policy-exchange-multi-tenant/): How to prepare an address book policy for a tenant in an Exchange Multi-tenant environment.   New-GlobalAddressList -Name “Cloud-GAL” -ConditionalCustomAttribute1 “cloud” -IncludedRecipients MailboxUsers -RecipientContainer “cloud.local/Cloud”     New-AddressList -Name “Cloud-All Users” -RecipientFilter “(CustomAttribute1 -eq ‘cloud’) -and (ObjectClass -eq ‘User’)” -RecipientContainer “cloud.local/Cloud”     New-AddressList -Name “Cloud-All Contacts” -RecipientFilter “(CustomAttribute1 -eq ‘cloud’) -and (ObjectClass -eq ‘Contact’)” -RecipientContainer “cloud.local/Cloud”     New-AddressList -Name “Cloud-All Groups” -RecipientFilter “(CustomAttribute1 -eq ‘cloud’) -and (ObjectClass -eq ‘Group’)” -RecipientContainer “cloud.local/Cloud”   New-OfflineAddressBook -Name “Cloud” -AddressLists “Cloud – GAL”     New-AddressBookPolicy -Name “Cloud” -AddressLists “Cloud – All Users”, “Cloud – All Contacts”, “Cloud – All Groups” -GlobalAddressList “Cloud […] ## Pages - [Categories](https://ammar.cloud/categories/): [vc_row][vc_column][vc_column_text css_animation=”fadeInDown”]                                                             [/vc_column_text][/vc_column][/vc_row]   - [Profile](https://ammar.cloud/profile/): With a cumulative experience of 15 years, I am focused on Cloud and Data Center Infrastructure Solutions. Specialized in Microsoft and Huawei Technologies. Microsoft: Hyper-V (Private Cloud), System Center Suite, Azure Pack, Active Directory Microsoft Exchange and SQL Administration. Huawei: FusionSphere Virtualization, SAN Storage and Virtual Desktop Infrastructure (VDI) - [Privacy Policy](https://ammar.cloud/privacy-policy/): Privacy Policy Last Updated: 21/09/2023 Welcome to Ammar’s Cloud . We value your trust and are committed to protecting your privacy. This Privacy Policy outlines how we collect, use, disclose, and safeguard your personal information. By using our website [yourblog.com], you consent to the practices described in this policy. Information We Collect Personal Information We may collect the following personal information when you interact with our blog: Name: When you subscribe, comment, or contact us, we may collect your name. Email Address: We collect your email address when you subscribe to our newsletter or contact us. Non-Personal Information We also collect […] - [Downloads](https://ammar.cloud/downloads/): WSSC2016LicensingFAQ - [About](https://ammar.cloud/about/): Welcome to Ammar’s Cloud! I’m Ammar, and I’m here to share my insights and experiences in the world of technology. With years of hands-on experience in infrastructure services and migrations, this blog is my way of giving back to the community. Whether it’s tips for seamless Microsoft 365/Other Platforms migrations or strategies for optimizing IT infrastructure, you’ll find valuable content that can help you navigate your tech journey. At Ammar’s Cloud, I believe that every tech story is unique. That’s why I focus on providing personalized insights and practical advice that you can apply directly to your projects. From detailed guides […] ## Optional - [Agent (MCP protocol)](websites-agents.hostinger.com/ammar.cloud/mcp) [comment]: # (Generated by Hostinger Tools Plugin)