Showing posts with label distribution list. Show all posts
Showing posts with label distribution list. Show all posts

Wednesday, 17 October 2018

O365 - reverting hard matching migration using ImmutableID

 

This is a very obscure problem, so I’m recording this more for my own reference in future rather than expecting anyone else to have the same issue!

The issue occurs when a migration from a hybrid exchange domain to another domain which uses AD Sync has been completed in the following manner:

1.    filter/delete user in current domain

2.    AD Sync soft deletes mailbox

3.    Create user in new domain (in a filtered OU that won’t be synchronised)

4.    Obtain new account GUID and convert to immutableID string (base64)

5.    Undelete mailbox (mailbox becomes cloud mailbox)

6.    Assign ImmutableID to mailbox (from the target account)

7.    Move target account to a synchronised OU then allow AD sync to hard match the accounts

8.    For some reason, there is a need to reverse this migration.  So filter/delete user in new domain

9.    AD Sync soft deletes mailbox

10. Re-create or unfilter user in old hybrid domain

11. Obtain account GUID and convert to immutableID string (base64)

12. Undelete mailbox (mailbox becomes cloud mailbox)

13. Assign ImmutableID to mailbox (from the original account) using the command

  

Set-MsolUser -UserPrincipalName "<UPN>" -ImmutableId "<ImmutableID>"

 

 

At this point the following error is received:

 

Set-MsolUser : Uniqueness violation. Property: SourceAnchor.

At line:1 char:1

+ Set-MsolUser -UserPrincipalName user@domain.com  -Immutableid

 

 

The fix is to run…

 

 

Get-MsolUser -ReturnDeletedUsers | select-object UserPrincipalName,Immutableid,objected

 

 

Find the user with the ImmutableID matching the one you are trying to assign

 

 

Remove-MsolUser -objectID "<objectID>" -RemoveFromRecycleBin

 

 

Then you should be able to run

 

 

Set-MsolUser -UserPrincipalName "<UPN>" -ImmutableId "<ImmutableID>"

 

 

…if you still have a problem, find the user’s objectID with

 

 

Get-MsolUser -userprincipalname "<UPN>" | select-object UserPrincipalName,Objectid

 

 

And run…

 

 

Set-MsolUser -objectid "<objectID" -ImmutableId "<ImmutableID>"

 

 

 

 

Tuesday, 25 September 2018

Send daily HTML email with outstanding Hyper-V checkpoints with encrypted password information

 

 

Here’s a script I’ve written that can be added as a scheduled task on the SCVMM server to send a daily report to selected people containing all the currently outstanding checkpoints on the Hyper-V hosts.  This is done without having to store any plain text passwords (they are stored but in an encrypted format).  It formats the email as HTML so that it looks a bit prettier.  I could have made the HTML fancier but I wanted to keep the script simple.

 

 

$Header = @"

       <style>

       TABLE {font-family: "Lucida Sans Unicode", "Lucida Grande", sans-serif; border: 1px solid #FFFFFF; background-color: #FFFFFF; width: 750px; height: 100px; text-align: center; border-collapse: collapse;}

       TH {background: #FF0000; border-bottom: 5px solid #FFFFFF; }

       TD { border: 1px solid #FFFFFF;}

       tr:nth-child(odd) {background: #D0CFD1; padding: 3px 2px; }

       </style>

"@

 

$Transpath = "C:\temp\logs\snapshot_report.log"

$DateTime = (Get-Date).ToString('dd/MM/yy hh:mm:ss')

$password = cat C:\scripts\securestring.txt | ConvertTo-SecureString

$mycred = New-Object System.Management.Automation.PSCredential ("username",$password)

$Date = Get-Date -Format "dd-MM-yyyy"

$Subject = "Daily Snapshot Report from $env:computername for $Date"

$Greeting = "Good morning, please find below the daily snapshot report.  For any queries on this report please contact Tom K `(info`@cloudwyse.co.uk`)"

$ReportText = Get-SCVirtualMachine | Get-VMCheckpoint | Select VM,Name,Description,AddedTime | ConvertTo-HTML -Head $Header -Body "$Greeting $_ " | Out-String

$Recipients = 'email1@cloudwyse.co.uk','email2@cloudwyse.co.uk','email3@cloudwyse.co.uk'

 

Start-Transcript -Path "$transpath" -Append

Write-Host "Started running script on $env:computername at $DateTime"

 

Send-MailMessage `

       -SmtpServer smtpserver.contoso.com `

       -Credential $mycred `

       -From 'reports@cloudwyse.co.uk' `

       -To $Recipients `

       -Subject $Subject `

       -Body $ReportText -BodyAsHtml `

       -Port 587 -UseSsl

 

Write-Host "Finished running script on $env:computername at $DateTime"

Stop-Transcript

 

 

Follow the instructions here to create the securestring.txt

 

 

Thursday, 12 July 2018

Adding Users to O365 Distribution List

 

A script I recently used to add members to an office 365 distribution group using a remote exchange session in a hybrid setup (covered at the end). 

 

$SourceFile = "<path to file>"

Import-CSV $SourceFile | ForEach `

{Add-DistributionGroupMember -Identity "Group Name" -Member $_.UPN

Write-Host -ForegroundColor Green "Processed the record for $($_.UPN)"

}

 

 

CSV file contains UPNs of all users to be added.

 

I also found it useful to see who had permissions to send to this group using

 

 

(Get-DistributionGroup -Identity "Group Name").AcceptMessagesOnlyFrom | ForEach {Get-User -Identity $_}

 

 

To open remote exchange shell:

 

 

$UserCredential = Get-Credential

 

 

A prompt will appear for your login credentials then,

 

 

$Session = New-PSSession -ConfigurationName Microsoft.Exchange -ConnectionUri https://outlook.office365.com/powershell-liveid/ -Credential $UserCredential -Authentication Basic -AllowRedirection

Import-PSSession $Session