Search WWW Search

Monday, April 30, 2012

Exchange 2003 Migration to Exchange 2010 Coexistence OWA ActiveSync Real Life Tips

When migrating from Exchange 2003 to 2010, it may be imperative to set up coexistenance during the migration to ensure smooth transition during the period when you have both your Exchange 2003 and Exchange 2010 environments running. This is the idea situation if you have many users\servers and can't perform an day or weekend cutover of moving all your mailboxes to the Exchange 2010 server. To set up coexistenance here are some tips I've encountered:

1. If you are using as the DNS name for your Exchange 2003 Outlook Mapi, OWA, and Activesync then perform the following.

In external DNS update the DNS record to the IP of the Exchange 2010 server. Create another record and point that to the IP of the Exchange 2003. In internal DNS create with the IP of the Exchange 2003 server. Do not change the internal DNS, leave that as is because your Exchange 2003 Outlook users are still using, if you change the internal record, your Outlook 2003 users will not work since it will be pointing to the Exchange 2010 server and it can't proxy rpc back to 2003. Before making DNS changes, set the TTL to something like 5 minutes 24 hours before you create these record,  this ensures when you change the records, you're not waiting for an hour or more for the DNS cache to timeout and hamper your testing and\or toubleshooting.

2. Go to the Exchange 2010 EMC and add the externalURL

Set-OwaVirtualDirectory -Identity "exchange2010cas01\owa (Default Web Site)" -Exchange2003Url

3. Set the same for the activesync virtual directory

Set-ActiveSyncVirtualDirectory \Microsoft-Server-ActiveSync* -ExternalURL

Supposedly you don't necessarily need to set the legacy against the activesync virtual directory for 2003-2010 coexistenence because Exchange 2010 will directly proxy to the 2003 activesync. I have found this did not work and required you to set the activesyncvirtualdirectory and let it redirect. At this point you should be able to open a browser outside the network and be able to perform the following.

A. Go to from outside the network and access a mailbox for a 2010 user and a 2003 user

B. Go to  from outside the network and access a 2003 user

C. On your activesync phone you should be able to access your 2003 user without changing any settings on your phone and still set to (some troubleshooting steps below if you can't)

D. On your activesync phone you can also set the mail server to and access your 2003 server.

You also need to ensure the following are set. On your Exchange 2003 front end, make sure you enable integrated authentication for the activesync directory as well as Basic. Also DISABLE the require SSL on the activesync vdir as well. You also need to DISABLE require SSL on the exchange virtual directory on your 2003 FE. I set this directly from IIS and not ESM and didnt run into DS2MB re-writing.

In addition if you are doing http to https redirect on your Exchange 2003 OWA you need to turn this off whether you were performing this using the http custom error file or some other method.

If you experience activesync slowness its because you didnt disable the require SSL on the Exchange virdir on your 2003. I also didnt need to disable the RPC\HTTP nor disable forms based on the 2003 to have it work.

Another tip: You dont want to set up the HTTP to HTTPS redirect on your 2010 just yet. Because if you're using for everything, outlook, activesync, owa and you're in this split brain DNS setup then it can break services. This is because when a 2010 user logs into OWA using say just it goes to the 2010 CAS and CAS will do a redirect to to but your CAS will use the internal DNS and internally will go to your Exchange 2003 which your 2010 user doesnt reside. This will render a redirect loop in the browser.

This is just one of the limitations of coexistence if you use a single namespace for all your services. Another limitation is internal 2010 users after they are migrated will not be able to use OWA or activesync on the internal wifi because they will be pointed to which of course points to 2003 internally. Of course you can go with alternate solutions such as using a new namespace for your 2010 users but that would mean you would have to re-home their devices and outlook anywhere after they are migrated so not seamless.

Once complete you want to enable your Exchange 2010 cas Outlook Anywhere to allow for both NTLM and Basic authentication since it's possible you may have Outlook Anywhere clients that may be set to either NTML or Basic already. I ended up requiring to set all 3, just setting the -defaultauthentication method for ntlm and basic did not work.

Set-OutlookAnywhere -Name Server01 -DefaultAuthenticationMethod ntlm, basic

Set-OutlookAnywhere -Name Server01 -IISAuthenticationMethod ntlm, basic

 Set-OutlookAnywhere -Name Server01 -ClientAuthenticationMethod ntlm, basic

James Chong
Security+, Project+, ITIL


Blogger Kevin Knaul said...

Thanks for the article...good stuff.

We have an issue on OWA 2010 that is only affected a handful of users who have been migrated from 2003 (coexistence still in place). The user's receive a "Calendar has become corrupted" message when attempting to access their calendar in OWA. It is accessible in Outlook, but in OWA it never allows access to their calendar.

This issue is not affecting all users, but it is concerning as we are still migrating accounts. Would you have any ideas or recommendations in what to investigate on this issue? Any assistance would be appreciated.


1:50 PM  
Blogger banlin mithra said...

Good, informative post.Helpful tips.
Exchange Migration

3:14 AM  
Blogger Rachel Burr said...

All the contents you mentioned in post is too good and very useful. I will keep it in mind, thanks for sharing the information keep updating, looking forward for more posts. cheap wildcard ssl

4:52 AM  
Blogger mogali said...

Cheap Wildcard SSL - Cheap SSL certificates (including wildcard and multi-domain (SAN) SSL certificates) from Comodo, GeoTrust, Thawte and Symantec (VeriSign)

11:41 PM  
Blogger Tom said...

Thanks for this posting. We ran in to the slowness problem with active sync. None of the articles i used mentioned you have to disable the ssl on the exchange dir as well as the active sync dir.

Again thank you!

4:25 AM  
Blogger Tom S. said...

I'm running into an issue where PUSH breaks for ActiveSync.. I have SSL disabled on the Exchange and ActiveSync vDirs..

Any ideas?


11:05 AM  
Blogger chenyingying9539 9539 said...

nike air max
jrodan retro
burberry outlet
chanel bags
true religion jeans
jordan 8s
oakley vault
dior handbags
gucci outlet
michael kors outlet
polo ralph lauren
toms outlet
louis vuitton outlet
cheap jordans
oakley sunglasses
hermes birkin bag
sac longchamp pas cher
michael kors outlet
mulberry handbags
chanel bags
louis vuitton outlet
coach outlet
coach factorty outlet
ray ban uk
hollister clothing store
hollister clothing store
louis vuitton handbags
ralph lauren outlet
michael kors

7:40 PM  
Blogger oakleyses said...

louis vuitton outlet, oakley sunglasses, michael kors handbags, cheap jordans, prada handbags, uggs outlet, michael kors outlet, oakley sunglasses, uggs on sale, ray ban sunglasses, burberry outlet, tiffany jewelry, uggs on sale, kate spade, gucci handbags, ray ban sunglasses, prada outlet, longchamp outlet, louboutin uk, burberry factory outlet, tory burch outlet, nike air max, tiffany jewelry, christian louboutin, louboutin shoes, oakley sunglasses, cheap oakley sunglasses, chanel handbags, michael kors outlet store, louis vuitton outlet, nike outlet, ralph lauren polo, louis vuitton, christian louboutin, michael kors outlet online, longchamp outlet, uggs outlet, michael kors outlet online, nike air max, longchamp bags, replica watches, ralph lauren outlet, oakley sunglasses, ray ban sunglasses, louis vuitton outlet online, nike free, michael kors

6:41 PM  
Blogger oakleyses said...

burberry pas cher, lunette oakley pas cher, coach outlet, kate spade outlet, true religion jeans, converse, coach outlet, longchamp soldes, north face uk, michael kors, louboutin pas cher, new balance, lululemon outlet, coach purses, nike air max, hermes pas cher, nike tn pas cher, vans pas cher, coach outlet store online, mulberry uk, lunette ray ban pas cher, nike air max uk, sac guess pas cher, nike air force, nike roshe run pas cher, longchamp pas cher, north face pas cher, nike air max pas cher, ray ban uk, true religion outlet, abercrombie and fitch, polo lacoste pas cher, true religion outlet, michael kors, jordan pas cher, nike free, polo ralph lauren uk, vanessa bruno pas cher, true religion outlet, hogan sito ufficiale, ralph lauren pas cher, michael kors outlet online, nike free pas cher, nike roshe uk, abercrombie and fitch UK, nike blazer pas cher, hollister uk

6:44 PM  
Blogger oakleyses said...

converse shoes outlet, salvatore ferragamo, timberland boots, softball bats, herve leger, ray ban, hollister, louboutin, gucci, nike roshe run, iphone cases, beats by dre, mcm handbags, oakley, p90x workout, insanity workout, wedding dresses, abercrombie and fitch, abercrombie, nike air max, mac cosmetics, babyliss pro, valentino shoes, bottega veneta, mont blanc, converse, jimmy choo outlet, hollister clothing, nike air max, north face outlet, new balance shoes, north face outlet, instyler ionic styler, soccer shoes, lululemon outlet, asics running shoes, ghd hair, giuseppe zanotti, soccer jerseys, nfl jerseys, longchamp uk, reebok outlet, nike air huarache, chi flat iron, hermes handbags, vans outlet, polo ralph lauren, celine handbags, nike trainers uk, vans scarpe

6:47 PM  
Blogger oakleyses said...

toms shoes, supra shoes, montre pas cher, ugg uk, juicy couture outlet, moncler, lancel, michael kors outlet online, ugg pas cher, michael kors handbags, barbour, doke & gabbana, michael kors outlet, coach outlet, louis vuitton uk, canada goose jackets, pandora charms, moncler, ugg,ugg australia,ugg italia, links of london uk, moncler jackets, hollister, juicy couture outlet, canada goose outlet, swarovski uk, pandora jewelry, canada goose pas cher, canada goose outlet, marc jacobs, moncler pas cher, thomas sabo uk, swarovski jewelry, karen millen uk, louis vuitton, moncler, moncler uk, sac louis vuitton, canada goose, moncler outlet, louis vuitton, canada goose, wedding dresses uk, ugg,uggs,uggs canada, canada goose uk, sac louis vuitton, moncler, replica watches, barbour jackets uk, bottes ugg pas cher, canada goose jackets

6:50 PM  
Blogger Minko Chen said...

adidas outlet
soccer jerseys wholesale
michael kors handbags
mulberry outlet store
prada outlet
cheap nba jerseys
ralph lauren uk
swarovski crystal
oakley sunglasses wholesale
chanel handbags outlet
ralph lauren outlet
cheap jordan shoes
canada goose coats
toms outlet store
puma outlet
north face outlet store
ugg boots
black friday deals
ugg outlet
toms outlet

6:46 PM  

Post a Comment

<< Home

xml:lang="en" lang="en"> MS Exchange Tips: Exchange 2003 Migration to Exchange 2010 Coexistence OWA ActiveSync Real Life Tips