• Native App Permission Policy to App Centric Management in MS Teams

    “Microsoft says, lets Keep it simple

    I know Copilot and several other AI features are making life simple for those in need, but I felt this article should be more of the good old days with genuine walkthrough of how a feature is being explored and implemented. No offence to AI features, just trying not to forget my tech blogging skills.

    Things to consider before we migrate the native app permission policy management to App Centric Management in MS Teams,

    1. Any org which doesn’t have a custom policy can just jump the gun and get back to your work as Microsoft got your back, they are automatically migrated to App Centric Management.
    2. Any org which has one or two custom policies, need a little bit of attention in fine tuning your custom policies and migrate to App centric management using the wizard as mentioned in the TechNet article
    3. Any org with 2 or more custom policies, let’s chat! It sounds like you have a thrilling game of “Policy Jenga” going on!

    How to get started?

    App permission policies so far was, you determined access to apps using the following three settings:

    • Permission policy: It applies at a user-level and controls if a specific user is allowed to use an app or not.
    • Org-wide app setting for third party apps: It applies at an org-level and controls if all third party apps are available for every user or not.
    • App status: It applies at an app-level as allow or block and controls if it’s available to any user or not.

    Every time when a new app is introduced in the organization and only limited users are bound to have access to it we end up creating a custom policy to meet the business need. From the administrator’s end this was adding up a lot of efforts and there was a question on the app policy hygiene.

    Now, with App centric policy in place we can either let everyone access it, block for all or allow only for specific set of users. this granular access control on apps will ensure smooth management of Teams Apps in future.

    “It is better to look ahead and prepare than to look back and regret”

    Why did i mention this quote? This migration is just a click away but this can cost you more if you aren’t prepared for this,

    Lets dig deeper into the logic behind, how these policies are transformed into app centric management.

    Lets assume, you have three custom policies in the org,

    1 Global (org-wide default) and 3 custom policies

    Just an example, below is the list of allowed and blocked apps in the respective policies,

    In the process of migration, it considers the apps which was allowed in all the app permission policies as “Allowed to Everyone“, Apps that are blocked in all the app permission policies are considered to be “Available to No One“, all other apps which has conflicts of allowed in one app and blocked in another will fall under “Available to specific users and groups” which required the admin to manually add the users or groups to the allow list (number of entries to a access list cant exceed 99 (users & groups together)

    Your entire migration happens at this step where you sit with your team and work on a policy hygiene mission to clean up this multiple conflicting policies to reduce manual interventions of adding the users and group on this 2k+ apps in the organization.

    Here is how it looks after the policy hygiene mission,

    Again this depends on how your business wants you to make the app availability for its users, it varies from business to business. Also remember, the best way to manage the app centric management is to have a dedicated group for each app which are listed under these “Available to specific users and group”.

    During the migration, at the next phase you get to see an option to verify which app is available for which user,

    Moving to the next phase, always remember You can only migrate one time. Review app availability and make any changes before completing the migration process

    Now you can verify the changes and “Start Migration”

    Or you can still take a step back to either finish it later or reset all changes to do this sometime later.

    With alignment to this change, there is an important change which MS has made which is “Integrated Apps” which will be covered in the upcoming post.

    Thank you for your patience is scrolling this far! Happy learning 🙂

    Storm the comment section for any questions.

  • On July 19, 2024, a faulty update to security software produced by CrowdStrike, an American cybersecurity company, caused a large number of computers and virtual machines running Microsoft Windows to crash. This incident led to widespread outages affecting various industries worldwide, including airlines, airports, banks, hotels, hospitals, manufacturing, stock markets, and broadcasting. Even governmental services such as emergency numbers and websites were impacted

    Was there any compensation for affected users?

    As of now, there hasn’t been any official announcement regarding compensation for the affected users due to the July 19, 2024 Microsoft outage caused by a faulty security software update. However, it’s possible that Microsoft may address this issue in the future.

    What is the Global business impact?

    The global IT outage on July 19, 2024 had far-reaching impacts across various sectors worldwide. Here are some notable effects:

    1. Airlines: Major U.S. airlines like United, American, and Delta grounded flights due to the outage, causing global delays and disruptions12Chaos ensued at airports, with departure screens going blank and passengers receiving handwritten boarding passes3.
    2. Banks: Financial institutions faced challenges as their systems were affected. Transactions, electronic payments, and banking services experienced interruptions.
    3. Emergency Services: In Alaska, 911 services were down across the state due to the outage1.
    4. Businesses: The outage impacted media broadcasters, supermarkets, and telecommunications companies. Cybersecurity firm CrowdStrike, responsible for the faulty update, saw its shares plunge14.
    5. Online Gambling: Even online sports gambling site BetMGM reported temporary issues due to the global IT outage1.
    6. U.S.-Mexico Border: U.S. Customs and Border Protection faced processing delays at the Mexico border due to the outage1.
    7. Microsoft Services: Critical applications like Outlook, Teams, and OneDrive were affected, causing challenges for businesses across various industries5.

    In summary, the outage disrupted daily life, highlighting the importance of robust IT systems and quality control in software updates

    Global IT outage caused by a faulty update from CrowdStrike, Technical Briefing

    1. Cause:
      • CrowdStrike produces security software, including the Falcon Sensor product. This sensor installs at the operating system level on individual computers to detect and prevent threats.
      • On July 19, 2024, at 04:09 UTC, CrowdStrike distributed a driver update for its Falcon software on Windows PCs and servers.
      • Unfortunately, an update to a configuration file conflicted with the Windows sensor client, leading to affected machines encountering the dreaded blue screen of death (BSOD) with the stop code PAGE_FAULT_IN_NONPAGED_AREA—indicating an error caused by a page fault12.
    2. Impact:
      • The faulty update affected various industries globally, including airlines, airports, banks, hotels, hospitals, manufacturing, stock markets, and broadcasting.
      • Even governmental services like emergency numbers and websites were disrupted1.
      • Windows virtual machines on Microsoft Azure and Google Compute Engine began rebooting and crashing1.
      • The problem primarily affected systems running Windows 10 and Windows 11, but systems running Windows 7 and above were also impacted1.
      • Computers running MacOS and Linux remained unaffected1.
    3. Resolution:
      • CrowdStrike reverted the content update at 05:27 UTC, which resolved the issue for devices booted after the revert1.
      • By 07:15 UTC, CrowdStrike confirmed that their faulty driver update was the root cause of the problem1.

    Legal implications

    There haven’t been any publicly reported lawsuits against CrowdStrike or Microsoft specifically related to the July 19, 2024 global IT outage caused by the faulty update. However, the incident has likely prompted discussions and assessments within affected organizations. If any legal actions do arise, they would likely focus on the impact, financial losses, and contractual obligations

    Also remember! Microsoft, a technology powerhouse, has left an indelible mark on the digital landscape. Their legacy of innovation spans decades, from the ubiquitous Windows operating system to the cloud computing prowess of Azure. Microsoft’s commitment to reliability shines through its enterprise solutions, trusted by businesses worldwide. Their engagement with developers, open-source communities, and educational institutions fosters collaboration. Notably, Microsoft prioritizes accessibility, designing products like Narrator and Immersive Reader for diverse user needs. While no company is flawless, Microsoft’s impact on technology and society remains profound

  • Microsoft and Apple always has this mutual way of complementing each other with their security updates to the software. This is one other similar update from Apple which has caused a little wrinkle on the Microsoft Teams/ Outlook for IOS devices. Every time a mobile user(in our case its the IOS user) tries to dial in to a meeting by clicking on the dial in number from the respective teams meeting redirects them to the dial pad and the user can dial the number to join the meeting.

    But here is where Apple has decided to put an end to such easy dialing option (considering few potential security threats). After upgrading the Apple devices to IOS 15.4 users will not be able to use this feature. Microsoft has already published an article on the same and Apple confirmed that this is by design.

    When will this be resolved? Apple might or might not fix them, we may have to wait for an official confirmation from Apple on the same with no ETA mentioned.

    Concluding this to be a behavior by design and there are no actual workarounds unless you are okay to long press the link, copy the number with the code and paste it to the dialpad and join the meeting.

    Android users can still enjoy the feature.

    Cheers,

    Ganesh G

  • Automapping enables an outlook user to be able to get all those mailboxes automatically populated in their respective outlook clients based on the value set on the MSExchDelegateListLink,

    The mailbox that is permissioned: msExchDelegateListLink
    The user who is being granted permissions: msExchDelegateListBL

    Scenario 1:

    Joe Biden has a mailbox hosted online (O365) and he is part of the Technical team to respond to end user’s queries which is sent to a shared mailbox “Tech Support Team”. Hence Joe is given full mailbox access to the shared mailbox,

    Add-MailboxPermission -Identity “Tech Support Team” -User “Joe Biden” -AccessRights FullAccess -InheritanceType All

    Once the permissions are in place, Joe will be able to access the tech support mailbox on his local outlook (Tech support Team primary mailbox & archive mailbox(if available) will be auto mapped to Joe’s mailbox.

    Scenario 2:

    Joe Biden has a mailbox hosted online (O365) and he is part of the Technical team to respond to end user’s queries which is sent to a shared mailbox “Tech Support Team”. As the team size is huge and people keep getting added or removed, hence a security group “Sec Group_Tech support” is created and all those who are part of the tech support team are added as members. Now the security group is given full mailbox access to the shared mailbox,

    Add-MailboxPermission -Identity “Tech Support Team” -User “Sec Group_Tech support” -AccessRights FullAccess -InheritanceType All

    By default when you run add-mailboxpermissions command, it enabled automapping, which means -Automapping $true, if you wish to turn it off explicitly, you can do it by adding -Automapping $false

    https://docs.microsoft.com/en-us/outlook/troubleshoot/profiles-and-accounts/remove-automapping-for-shared-mailbox

    As these users are not explicitly provided with full mailbox access, there are some limitations in automapping, but still the users can create individual outlook profile for the tech support team mailbox and that has no limitations. This is due to msExchDelegateListBL

    If you are part of a security group and the security group is given full mailbox access to a shared mailbox, it is expected that you wont be able to access the archive mailbox of the shared mailbox from outlook as an additional mailbox (auto-mapping) .

    But if you are explicitly given full access to shared mailbox you should see the primary shared mailbox along with the shared mailbox’s archive as well.

    Please keep me posted for any questions/clarifications.

    https://docs.microsoft.com/en-us/powershell/module/exchange/add-mailboxpermission?view=exchange-ps

    Ganesh G

  • I am considering that those who are here reading this blog has good understanding about how public folder is structured and how it works in Exchange 2013, If you are pretty new to this I would suggest you to go through Public folders Exchange 2013 before reading further to ensure this is not above your head,

    Scale the organization and get the below info,

    • No. of public folders – Getpublicfolderstatistics.ps1 script
    • No. of public folder mailboxes
    • No. of root public folders
    • Get the content mailbox info for each public folder
    • Export the public folder permissions to a csv which can be used if in case we need to restore the public folders and reapply the permissions

    Here we are exporting the permissions specific to the root folders along with its sub folders,

    $PFroot = read-Host "Enter the Publicfolder-Root"
    Write-host "You Entered $PFroot"
    Get-PublicFolder "\$PFroot" -Recurse -ResultSize "unlimited" | Get-PublicFolderClientPermission | Select-Object Identity,@{Expression={$_.User};Label="User";},@{Expression={$_.AccessRights};Label="AccessRights";} | Export-Csv C:\Temp\Publicfolderclinetpermission_$PFroot.csv -NoTypeInformation

    Once the client permissions are exported, we can remove the permissions on the public folders using the below script,

    $removepfroot = read-host "Enter the Root Public folder where the permission has to be removed"
    $AllPublicFolders = Get-publicFolder \$removepfroot -recurse
    
    foreach($Pf in $AllPublicFolders )
    {
    Get-PublicFolderClientPermission $Pf | Foreach{ Remove-PublicFolderClientPermission $_.Identity -User $_.User -Confirm:$false }
    }

    Then we can remove the public folders via EAC or using EMS,

    TechNet has a simple command to remove

    What is the Back-out plan ?

    I will detail the restoring procedures in my next post, Just an heads up on what will be covered in the upcoming post,

    1. Export the content mailbox information for each public folders
    2. Ways to restore public folders along with the sub folders
    3. How do we restore permissions back into the restored folders

    To make it easy one much know about the Primary and Secondary Hierarchy,

    Primary Hierarchy – The public folder mailbox that hosts writable copy of the public folder hierarchy. The first public folder mailbox created in an Exchange Organization is the primary hierarchy mailbox

    Secondary Hierarchy – All other public folder mailboxes in an Exchange organization, except the primary hierarchy, which store read-only copy of the public folder hierarchy.

    Happy Learning !

    Cheers,

    GaGa

     

  • Pre-Existing permissions which were granted before migrating the mailbox to office 365 works, But any new mailbox permissions given post the migration breaks in a hybrid scenario. For example, if we have three mailboxes Mbx1, Mbx2 & Mbx3. Consider Mbx1 has send as permission on Mbx2 and now Mbx2 is migrated to O365, in this case the permission works seamlessly. But if i try to add send as permission for Mbx3 on Mbx2 , it won’t work.

    Exchange hybrid configurations do support the use of the Send-As, Receive-As, or Send on behalf of mailbox permissions, these permissions are only available when both the mailbox granting the permissions, and the mailbox receiving the permissions, are in the same realm. Any mailboxes that receive these permissions from another mailbox need to be moved at the same time as that mailbox. If a mailbox receives permissions from multiple mailboxes, that mailbox, and all of the mailboxes granting permissions to it, need to be moved at the same time and exist in the same realm of either on premises or Office 365 Exchange organizations.

    https://blogs.technet.microsoft.com/mconeill/2016/03/20/shared-mailboxes-in-exchange-hybrid-now-work-cross-premises/

    Watch this video from 44:00 for more clarity.

    https://www.youtube.com/watch?v=pN6lsxKRrJQ

  • Upgrading Exchange 2013 CU18 had few challenges when you have too many 3rd party applications running on the exchange servers, In my previous blog you would have seen the show spoiler being identified as Mcafee host intrusion service. Likewise I would also want to bring this to your notice that you should be slightly cautious when installing
    Security Update For Exchange Server 2013 CU18 (KB4045655).

    Not sure how many went through this caution note on the technet blog where it stresses the importance of running this security update with elevated permissions (run as administrator). I personally experienced this as I ran it just with a double click on the file, post which we had some issues in connecting to our OWA & ECP. Upon investigation its observed that most of the resources weren’t present in the OWA directory.

    Here are the known issues reported when this Security patch is installed (ref: https://support.microsoft.com/en-ca/help/4045655/description-of-the-security-update-for-microsoft-exchange-december-12)

    1. We are aware of some reports that Exchange services may remain in a disabled state after you install this security update. If this occurs, the update is installed correctly. However, the service control scripts encounter a problem when they try to return Exchange services to its usual state. To resolve this issue, use Services Manager to restore the startup type to Automatic, and then start the affected Exchange services manually.
    2. When you try to manually install this security update in “normal mode” (not running the update as an administrator) and by double-clicking the update file (.msp), some files are not correctly updated. When this issue occurs, you do not receive an error message or any indication that the security update is not correctly installed. Also, Outlook Web Access (OWA) and the Exchange Control Panel (ECP) may stop working. This issue occurs on servers that are using UAC (user account control). The issue occurs because the security update does not correctly stop certain Exchange-related services. To avoid this issue, run the security update in elevated mode as an administrator. To do this, right click the update file, and then click Run as administrator.

    In case if you already installed this, remove the security update from the server completely and post a reboot install the security update again with the elevated permission.

    Cheers,
    Ganesh G

  • download

     

    Environment:

    Exchange 2013 CU13
    .NET Framework 4.7
    Windows 2012 R2
    Physical Servers
    4 Node DAG

    Schema Changes:

    Active Directory schema changes in Exchange 2013 cumulative updates CU8 and later

    No changes have been made to the Active Directory schema in Exchange 2013 from CU8 onwards. The last cumulative update to include schema changes is currently Exchange 2013 CU7.
    https://technet.microsoft.com/en-us/library/bb738144%28v=exchg.150%29.aspx#CU7

    Confirm the schema versions as listed below,

    Exchange

    So there are no Schema changes in CU18 as well

    Downloads:

    1. Download Exchange 2013 CU18 from the link below:
    https://www.microsoft.com/en-us/download/details.aspx?id=55955

    2. Get .NET Framework 4.6.2 installation packages (Offline Installer)
    Download .NET Framework 4.6.2 offline package from the link below:
    https://www.microsoft.com/en-us/download/details.aspx?id=53344

    3. Security Update For Exchange Server 2013 CU18 (KB4045655)

    https://www.microsoft.com/en-us/download/details.aspx?id=56329

    Plan:

    1. Get the general rechecks done on the exchange servers
    2. Microsoft doesn’t recommend .NET Framework 4.7 for CU18 and the same is published in the TechNet blog below,
    https://blogs.technet.microsoft.com/exchange/2017/06/13/net-framework-4-7-and-exchange-server/
    Hence remove 4.7 from the server and install 4.6.2
    Note: In our case our .NET Framework failed back to 4.6.2 (Windows 2012 R2 comes with .NET 4.6.2

    3. Turn off all the 3rd party services which can interrupt the installation, Don’t have mercy on any of them.
    Be brutal in stopping anything and everything other than Microsoft services,

    I am stressing this because, it was a night mare when we had to delay our installation by 8 hours as Mcafee was disrupting the upgrade from nowhere.

    Our installation failed with the below error when configuring the transport services,

    Processing component ‘Transport Common Configuration’ (Configuring common Transport properties.).
    Executing:
    $dllFile = join-path $RoleInstallPath “bin\ExSMIME.dll”;
    $regsvr = join-path (join-path $env:SystemRoot system32) regsvr32.exe;
    start-SetupProcess -Name:”$regsvr” -Args:”/s `”$dllFile`”” -Timeout:120000;

    Active Directory session settings for ‘Start-SetupProcess’ are: View Entire Forest: ‘True’, Configuration Domain Controller: “DC”, Preferred Global Catalog: ‘DC’, Preferred Domain Controllers: ‘{ DC }’
    User specified parameters: -Name:’C:\windows\system32\regsvr32.exe’ -Args:’/s “E:\Program Files\Microsoft\Exchange Server\V15\bin\ExSMIME.dll”‘ -Timeout:’120000’
    Beginning processing start-SetupProcess
    Starting: C:\windows\system32\regsvr32.exe with arguments: /s “E:\Program Files\Microsoft\Exchange Server\V15\bin\ExSMIME.dll”
    Timed out waiting for process to complete
    Timed out waiting for process to complete
    Ending processing start-SetupProcess
    The following 1 error(s) occurred during task execution:

    How we fixed it ?
    After several investigation , we identified that the McAfee Host intrusion Prevention was the cause for this time out and the Microsoft Registry server was crashing every time when it reached this stage of upgrade (70%)

    PS: McAfee Host intrusion Prevention can be stopped via the Orchestrator or by a elevated permission which has to be provided to you by your respective server management team.

    We stopped the McAfee Host intrusion Prevention service and re initiated the upgrade following a reboot.
    Upgrade completed successfully & installed the security update for CU18 as well.

    Should you have any further questions, please feel free to drop in your questions.

    Regards,
    Ganesh G

  • In a large sized environment, its a tedious job to verify the config files for any specific values, It takes a lot of manual efforts and a utter waste of time.

    Just to make it simple, came up with this very basic script that can fasten this task (Still this can be enhanced 🙂 ),

    1. Create a file named Server.txt which should have the list of servers where you would want to check the config files
    2. If you wish you can even change the path as per your convenience.
    3. In this example, we tried looking for the maxRequestLength, MaxDocumentDataSize & MaxRequestLength in the web.config file.
    4. Based on your requirement, you can alter the path, file and values.

    Please leave your comments or questions below.

    Regards,

    Ganesh G

    #Script to Simple Script to get the config file values – Exchange 2013

    #=========================================================

    #Ganesh G

    $server = Get-content “C:\Troubleshooting\Server.txt”
    Foreach ($Server in $Server)
    {
    Write-host “$server”
    Write-host “From: Exchsrvr\ClientAccess\Sync\web.config”
    Select-String “\\$server\d$\Exchsrvr\ClientAccess\Sync\web.config” -pattern “maxRequestLength” | Format-List “Line”
    Select-String “\\$server\d$\Exchsrvr\ClientAccess\Sync\web.config” -pattern “MaxDocumentDataSize” | Format-List “Line”
    Write-host “From: Exchsrvr\FrontEnd\HttpProxy\sync\web.config”
    Select-String “\\$server\d$\Exchsrvr\FrontEnd\HttpProxy\sync\web.config” -pattern “maxRequestLength” | Format-List “Line”
    }

Design a site like this with WordPress.com
Get started