Oregon State University - Network Engineering
Common Administrative Tasks
In order to administer e-mail attributes in Active Directory, you must first install Exchange
System Manager. To obtain the necessary tools, please see:
Installing Exchange 2000
Administration Tools
Choose a link for detailed instructions:
Create a Mailbox-Enabled User
Create a Mail-Enabled User
Create a Contact
Create a Distribution List
Create an @oregonstate.edu alias for a non-Exchange User
Delete an object in Active Directory
Restore a deleted mailbox
Create a Mailbox-Enabled User
Regular Exchange users are mailbox-enabled users. To create a mailbox-enabled user, follow
these steps:
Open AD Users and Computers.
Connect to the Global Catalog server (GC) for your domain (In FS_Mail, the GC is
MtMazama). To connect to the GC, right-click on the name of the domain and select
"Connect to Domain Controller". If there is no GC in your domain, any domain controller will do.
Right-click on the OU you want to create the new user in and choose New-User.
On the first screen, enter the user's name and username. For the first logon name
(the UPN) you should use @oregonstate.edu as the suffix. The logon names might look something
like this:
UPN: bob.jones@oregonstate.edu
pre-Windows 2000: FS_MAIL\jonesb
Enter a password on the next screen. If this account is for a resource mailbox, you
can disable the account if you like.
Leave the "Create an Exchange mailbox" checkbox checked and choose your server and
store. (If you're not sure which store to use, send email to
IT Consult.)
Click Finish on the last page to save changes.
Wait 30 minutes for replication and to allow the Recipient Update Service to
create the X400, @exchangemail.orst.edu, @oregonstate.edu and X500 addresses. Open
properties on the new user and choose the E-mail Addresses tab. If the e-mail addresses
field is empty, close the properties sheet and wait a few minutes, then try again. You can
refresh the interface by choosing Action, Refresh. (If after 30 minutes the e-mail
addresses have not appeared, send email to
IT Consult.)
The default address for the new user will be First.Last@oregonstate.edu, but you can change this if
needed.
NOTE: The smtp addresses will begin working within about 1 hour, when the virtualusers
script runs.
[top]
Create a Mail-Enabled User
You may want to create an Active Directory account for someone who already has an
e-mail account somewhere else. This is called a mail-enabled user.
Open AD Users and Computers.
Connect to the Global Catalog server (GC) for your domain (In FS_Mail, the GC is
MtMazama). To connect to the GC, right-click on the name of the domain and select
"Connect to Domain Controller". If there is no GC in your domain, any domain controller will do.
Right-click on the OU you want to create the new user in and choose New-User.
On the first screen, enter the user's name and username. For the first logon name
(the UPN) you should use @oregonstate.edu as the suffix. You can set the pre-Windows
2000 name according to any standard you like, but we recommend that you set the UPN to
match the person's @oregonstate.edu e-mail address, like this:
UPN: bob.jones@oregonstate.edu
pre-Windows 2000: FS_MAIL\jonesb
Enter a password on the next screen.
We don't want to create a mailbox for this user, so uncheck the "Create an Exchange mailbox"
checkbox.
Click Finish on the last page to save changes.
Right-click on the new user and choose Exchange Tasks.
Choose Establish E-mail Address and hit Next.
Choose Modify.
Choose SMTP Address and hit OK.
Type in the external e-mail address and hit OK. This could be something like: bobjones@yahoo.com
Set the Associated Administrative Group to:
Oregon State University/Central E-mail Services
Choose Next and Finish.
Wait 30 minutes for replication and to allow the Recipient Update Service to create
the X400 address.
Open properties on the new user and choose the E-mail Addresses tab. You should see at least an
X400 address and the address you typed in. If the e-mail addresses field is empty, close the
properties sheet and wait a few minutes, then try again. You can refresh the interface by choosing
Action, Refresh.
[top]
Create a Contact
Contacts are similar to custom recipients in Exchange 5.5.
It is important to note ONID accounts are in both Active Directory and UNIX.
You shouldn't need to create a contact for an
ONID account. Simply reference the AD object at onid.oregonstate.edu.
They are commonly used for the following:
To list a person's external address in the Global Address Book.
To add people outside of Exchange to Distribution Lists.
To set up a forward from a mailbox to an external address.
To give someone outside of Exchange an @oregonstate.edu alias.
To create a contact, follow these steps:
Open AD Users and Computers.
Connect to the Global Catalog server (GC) for your domain (In FS_Mail, the GC is
MtMazama). To connect to the GC, right-click on the name of the domain and select
"Connect to Domain Controller". If there is no GC in your domain, any domain controller will do.
Right-click on the OU you want to create the new contact in and choose New - Contact.
Enter a name and display name and click Next.
Choose Modify.
Choose SMTP Address and hit OK.
Type in the external e-mail address and hit OK. This could be something like: bobjones@yahoo.com
Set the Associated Administrative Group to:
Oregon State University/Central E-mail Services
Choose Next and Finish.
Wait 30 minutes for replication and to allow the Recipient Update Service to create
the X400 address.
Open properties on the new contact and choose the E-mail Addresses tab. You should see at least an
X400 address and the address you typed in. If the e-mail addresses field is empty, close the
properties sheet and wait a few minutes, then try again. You can refresh the interface by choosing
Action, Refresh.
To grant an @oregonstate.edu alias to this contact, follow the steps below.
[top]
Create a Distribution List
The terminology for groups in Active Directory is a bit confusing. The following definitions should
help clarify things a bit:
Distribution Group - a group that cannot be assigned permissions
Security Group - a group that can be assigned permissions
Local Group - can contain members from any domain, can only be assigned permissions in the domain
Global Group - can only contain members from the domain, can be assigned permissions anywhere in the forest
Universal Group - can contain members from anywhere in the forest, can be assigned permissions anywhere in the forest
Distribution List - any mail-enabled group
When creating a distribution list for Exchange, you should set the scope of the group to Universal so that it
will be replicated to the global catalog server. Otherwise, people may not be able to send mail to the list.
It is up to you whether the list should be a security group or a distribution group. If you plan to use
the DL to grant access to a public folder (or any other resource), you must set it as a security group.
To create a distribution list:
Open AD Users and Computers.
Connect to the Global Catalog server (GC) for your domain (In FS_Mail, the GC is
MtMazama). To connect to the GC, right-click on the name of the domain and select
"Connect to Domain Controller". If there is no GC in your domain, any domain controller will do.
Right-click on the OU you want to create the new DL in and choose New - Group.
Enter a name.
Set the Group Scope to: Universal
Set the Group Type to either Security or Distribution, depending on how you plan to use it.
Choose Next.
Set the Associated Administrative Group for the e-mail address to:
Oregon State University/Central E-mail Services
Choose Next and Finish.
Wait 30 minutes for replication and to allow the Recipient Update Service to create
the X400, @exchangemail.orst.edu and @oregonstate.edu addresses.
Open properties on the new group and choose the E-mail Addresses tab. You should see at least an
X400 address and the @exchangemail.orst.edu address. If the e-mail addresses field is empty, close the
properties sheet and wait a few minutes, then try again. You can refresh the interface by choosing
Action, Refresh. (If after 30 minutes the @exchangemail.orst.edu address has not appeared, send email
to
IT Consult.)
The default address for the Distribution List will be
Name@oregonstate.edu, but you can change this if needed.
Add members to the list via the Members tab.
NOTE: The smtp addresses will begin working within about 1 hour, when the virtualusers
script runs.
[top]
Delete an object in Active Directory
Warning: restoring a deleted AD object is not really possible,
so think before you delete. Once a user account has been deleted, it's SID (unique identifier)
is gone for good, and any new account created for that user will have to have permissions
re-assigned to it.
To remove any object in Active Directory, simply right-click on the object, choose
Delete, and select Yes when prompted.
If you want to delete a mailbox without deleting the user account associated with it, follow
these steps:
Right-click on the account in AD Users & Computers.
Choose Exchange Tasks.
Select Delete Mailbox and click Next.
Click Next again and choose Finish.
[top]
Restore a deleted mailbox
When you delete an account in AD, the associated mailbox is always deleted - this is by design.
However, we retain deleted mailboxes on the system for 90 days before they are completely purged.
In that time, you can reconnect a deleted mailbox to another account. The account that you reconnect
to must not already have a mailbox associated with it.
NOTE: When a mailbox is deleted, the SMTP addresses are lost, and will need to be added back when you reconnect the mailbox.
To reconnect a mailbox, you need to use the Exchange System Manager tool. Here is the procedure:
- Open System Manager. Click on Start, Programs, Microsoft Exchange, System Manager.
- Browse to Administrative Groups, Central Email Services, Servers, Servername, Storage Group, Store.
- Click on Mailboxes.
- On the right, look for the deleted mailbox - it will have a red X next to it.
- Right-click the deleted mailbox and choose Reconnect.
- Find the account to associate the mailbox with and choose OK.
- You may see a warning pop up about replication - just click OK.
- Once the e-mail attributes have replicated to the new user object, add the SMTP addresses back.
[top]
Create an @oregonstate.edu alias for a non-Exchange/non-AD User
To grant an @oregonstate.edu alias to a user who is not in AD, you must first create a
contact for that user. Follow the steps above to create a contact.
Once you have created a contact for a non-Exchange user, you can give them an @oregonstate.edu alias
by following these steps:
In Active Directory Users & Computer, right-click on the Contact and choose Properties.
Choose the E-mail Addresses tab.
Click on New and choose SMTP Address.
Enter the new @oregonstate.edu address and click OK.
Click OK again to save changes.
The new alias will begin working when the virtualusers script runs on the next half hour.
To grant an @oregonstate.edu alias to a user who is in AD but doesn't have an exchange account.
- Right-click on the account object in AD Users and Computers
- Select Exchange Tasks
- Choose Establish E-mail Address
- Modify
- SMTP address
- Enter the address of the non-exchange email address
- Finish
Go back into the user object and select the E-mail addresses tab and select New,
SMTP address and enter the desired @oregonstate.edu address.
[top]