This post explains how to configure Office Communications Server in a resource forest topology, in a resource topology, a single resource forest contains all Office Communications Server servers and disables user accounts for each logon enabled account in a user forest.
A resource forest topology is an Active Directory® Domain Services topology used to deploy Office Communications Server and Microsoft Exchange Server in one Active Directory forest while all logon enabled user accounts are located in a separate Active Directory forest. The resource forest hosts only servers and does not contain any primary user accounts. The primary user accounts from other forests are represented as disabled user accounts. The SID (security identifier) of a disabled user account in the resource forest is mapped to the corresponding primary user account in the other forest to allow for single sign in. These disabled user accounts are enabled for Office Communications Server and mail-enabled for Exchange Server if it is deployed.
To support a resource forest topology, Office Communications Server must be deployed in your resource forest and configured at least with one-way trust between the resource forest and all user forests (such that the resource forest trusts all user forests).
Also DNS Forwarding between users forests DNS Servers and new resources forest DNS Servers is required to allow name resolution across forests.
If you have not deployed Office Communications Server, see the Microsoft Office Communications Server Planning Guide and the Microsoft Office Communications Server Deployment Series.
Figure below shows how an example organization, configured as an Enterprise pool in its resource forest.
After you have deployed Office Communications Server in the resource forest, complete the following steps:
Extend the new Resource Forest Schema for Exchange 2007
In all cases if the old Forest host Exchange 2003 or Exchange 2007, it is better to extend the new Resource Forest with Exchange 2007 schema, in this case the disabled user accounts will already exist and many of the necessary attributes on the disabled user accounts will be populated.
Use ADMT for Users Migration
Creating Disabled users manually in Resource Forest will require allot of attributes synchronization and can lead for some issues, the best way that was tested is using ADMT to migrate the users from old Users Forest to the new Resource Forest.
For more information about using ADMT refer to ADMT Guide http://technet.microsoft.com/en-us/library/cc974332(WS.10).aspx.
Use ILM for attributes synchronization
o Telephone Number
o Mobile Number
o IP Phone Number
o Telephone Number
o Mobile Number
o IP Phone Number
Table below shows the attributes that must be mapped from a user object in the user forest to a corresponding disabled user object in the resource forest using the example user, User A.
User A in User Forest
Disabled user account for User A in a Resource Forest
Note In a deployment that includes Microsoft Exchange Server, set the ObjectSID attribute to the value from the msExchMasterAccountSID attribute.
Table below shows how attributes are mapped from a user object to a contact object using the example group, Group A.
Contact for Group A
Distribution Group - Universal
Distinguished name (DN)
<distinguished name of group A>
<Distinguished name of group A>
Enable Disabled Users for Office Communication Server
Enable disabled users for OCS in the Resource Forest should be done periodically depend on changes happened in the Users Forest, so if new user created in the User Forest and ILM synchronize this user to the Resource Forest then enable user for OCS and configure this user for OCS services is required, also in some change cases like change in email address for user in Users Forest and this user enabled for OCS in Resource Forest with SIP Address same like email address, then re-enable this user for OCS should be done to keep using his new email address as his SIP Address,
Below are the required steps to enable the disabled users for OCS:
1. In the resource forest, log on to a computer running the Office Communications Server 2007 service as a member of the RTCUniversalUserAdmins group.
2. Start Active Directory Users and Computers: Click Start, point to Administrative Tools, and then click Active Directory Users and Computers.
3. Go to the organizational unit where you created your disabled user accounts.
4. Right-click the contact that you want to enable, click Properties, and then click the Communications tab.
5. Select the Enable users for Office Communications Server check box.
6. In the Sign-in name box, type the sign-in name (also known as the SIP URI) for this user account and then select the SIP domain that is used by your Office Communications Server servers. For example, firstname.lastname@example.org.
7. In Server or pool, select the Office Communications Server server where you want to host the user account.
8. Click Configure.
9. In the User Options dialog box, select the appropriate settings required for your deployment and then click OK. Click OK again to apply the changes and close the user properties.
Enable Anonymous access on Address Book Web Service Virtual Directory on OCS Front End Server (Optional)
Enable Anonymous access on Address Book Web Service Virtual Directory on OCS Front End Server is optional step, however it is required step in case if there is VLAN restrictions between users VLANs and the new Resource Forest VLAN, which is normal scenario in most cases,
All you should change from IIS under default web site in all OCS Front End Servers is to allow Anonymous access on Address Book Virtual Directory and all sub Virtual Directories under it.
Enable Anonymous access on Group Expansion Web Service Virtual Directory OCS Front End Server (Optional)
Enable Anonymous access on Group Expansion Web Service Virtual Directory on OCS Front End Server is optional step, however it is required step in case if there is VLAN restrictions between users VLANs and the new Resource Forest VLAN, which is normal scenario in most cases,
All you should change from IIS under default web site in all OCS Front End Servers is to allow Anonymous access Group Expansion Virtual Directory and all sub Virtual Directories under it.