<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Cross-site moves: The importance of proper ADC Connection Agreements</title><link>http://blogs.technet.com/evand/archive/2005/05/24/405312.aspx</link><description>It’s now been about a year since Exchange 2003 SP1 released, and cross-site, mixed-mode mailbox moves were introduced. In that time, I think folks have really started to get the hang of how it works and what needs to be in place to ensure successful moves.</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: Cross-site moves: The importance of proper ADC Connection Agreements</title><link>http://blogs.technet.com/evand/archive/2005/05/24/405312.aspx#405327</link><pubDate>Wed, 25 May 2005 02:26:19 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:405327</guid><dc:creator>Tony Du</dc:creator><description>Evan,&lt;br&gt;&lt;br&gt;I have read your posts regarding cross site move by using E2K3 SP1.&lt;br&gt;&lt;br&gt;We are in mixed-mode Exchange 5.5 to Exchange 2003 migration which includes site consolidation (cross site mailbox move). We find an issue related to mailbox delegated permission. &lt;br&gt;&lt;br&gt;For example, MailboxA and MailboxB were both in same Exchange 5.5 site (source). And mailboxB has delegated access to mailbox folders of mailboxA. Then mailboxB was cross site moved to Exchange 2003 via ESM (E2K3 SP1).&lt;br&gt;&lt;br&gt;Logon mailboxA we could still see mailboxB on folder permission list which pointed to &amp;quot;Stub&amp;quot; hidden object of mailboxB left in source site. When this &amp;quot;Stub&amp;quot; object got deleted, name of mailboxB on permission entry list changed to its original DN name. We do wait (overnight) for more than 12hrs for ADC and DIRsync settled down.  &lt;br&gt;&lt;br&gt;Basically issue is that cross site moved mailbox lost its delegated access to some resources mailboxes still in source site. &lt;br&gt;&lt;br&gt;I have not tested the situation of mailboxA cross moved as well. &lt;br&gt;&lt;br&gt;As you indicated your post I can clearly see proxy address of X500:ADCDeleteWhenUnlinked dropped from &amp;quot;stub&amp;quot; hidden object and all DL membeship replicated and retain without problem for mailboxB. &lt;br&gt;&lt;br&gt;I wonder if the cross site move tool covers situation of retaining mailbox delegate permissions. In my understanding those ACLs on are IS on DS of Exch55. ADC may not be able to handle. If not, we may have RCA issue here.&lt;br&gt;&lt;br&gt;Hopefully you may cross similar situation and had good advices.&lt;br&gt;&lt;br&gt;Mnay thanks,&lt;br&gt;Tony Du&lt;br&gt;tony.du@gsjbw.com&lt;br&gt;&lt;br&gt;</description></item><item><title>re: Cross-site moves: The importance of proper ADC Connection Agreements</title><link>http://blogs.technet.com/evand/archive/2005/05/24/405312.aspx#405328</link><pubDate>Wed, 25 May 2005 03:33:49 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:405328</guid><dc:creator>evand</dc:creator><description>Tony -&lt;br&gt;&lt;br&gt;Cross-site mixed-mode mailbox moves definitely do take mailbox delegation into account. &lt;br&gt;&lt;br&gt;Exchange 2003 Sp1 servers are smart enough to take into account the idea that a mailbox might have been moved across 5.5 site boundaries, and that an X500 address on this moved mailbox might also be a suitable replacement as a directory-identifier for the &amp;quot;obj-dist-name&amp;quot; (ie - LegDN) attribute.&lt;br&gt;&lt;br&gt;So, the short answer to your question is: Always move the manager (ie - the person who has the permissions defined in their mailbox) either before or at the same time as the delegate (the person who has been grated permissions in the manager's mailbox). And once this move is complete, be sure that the mailbox stays on an E2k3 Sp1 server.&lt;br&gt;&lt;br&gt;This will ensure that the permissions are always evaluated by an E2k3 Sp1 server. Once the delegate has also been moved, the permissions will still properly resolve, and you'll never have a &amp;quot;broken&amp;quot; state. &lt;br&gt;&lt;br&gt;Even if you've already moved the delegate, all hope is not lost. Simply move the manager to an E2k3 SP1 server, and the delegate permissions should resolve themselves at that point.&lt;br&gt;&lt;br&gt;Hope it helps!&lt;br&gt;Evan</description></item><item><title>Weekend reading</title><link>http://blogs.technet.com/evand/archive/2005/05/24/405312.aspx#405435</link><pubDate>Fri, 27 May 2005 10:33:22 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:405435</guid><dc:creator>subject: exchange</dc:creator><description /></item><item><title>re: Cross-site moves: The importance of proper ADC Connection Agreements</title><link>http://blogs.technet.com/evand/archive/2005/05/24/405312.aspx#405440</link><pubDate>Fri, 27 May 2005 12:14:42 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:405440</guid><dc:creator>philmara</dc:creator><description>I used cross site moved twice and it works fine. &lt;br&gt;I think the wizards are the best practice, even if you need to check after (CA for example).&lt;br&gt;The major problem is replication or network link, so same troobleshoot as a normal move mailbox.&lt;br&gt;&lt;br&gt;Last point, THANKS EVAN, your blogs helps me a lot especially because I tried it when the service pack was launched on a 20,000 international mbx structure.&lt;br&gt;&lt;br&gt;Philippe  </description></item></channel></rss>