Showing posts with label Powershell. Show all posts
Showing posts with label Powershell. Show all posts

Tuesday, 16 August 2016

Pull Name, SMTP, OU and last logon time from Exchange 2013

This script enables you to pull together the Name, Primary SMTP Address, Organizational Unit and Last Logon Time information.  This information can be useful if you are trying to find out which mailboxes are being used or not.  This script has been tested on Exchange 2013 only.  


Get-Mailbox -ResultSize Unlimited | Select-Object DisplayName, PrimarySMTPAddress, OrganizationalUnit, @{label="LastLogonTime";expression={(Get-MailboxStatistics $_).LastLogonTime}}



Tuesday, 5 January 2016

Retention Policy Powershell Commands

I've recently been working on applying retention policies to mailboxes and we've been doing a granular roll-out to the users.  I've been using some Powershell commands to track who has the policy applied and who hasn't.

The following command will list all users who have a retention policy applied to their mailbox:
Get-Mailbox -filter 'RetentionPolicy -like "*"' | Select-Object Name, RetentionPolicy

You can export that to a CSV if need be by using:

 Get-Mailbox -filter 'RetentionPolicy -like "*"' | Select-Object Name, RetentionPolicy | Export-CSV C:\directory\file.csv


To identify which users don't have a retention policy applied to their mailbox the following command will assist:

Get-Mailbox -filter 'RetentionPolicy -eq $null' | Select-Object Name, RetentionPolicy

Again to export that to CSV you would use:

Get-Mailbox -filter 'RetentionPolicy -eq $null' | Select-Object Name, RetentionPolicy | Export-CSV C:\Directory\file.csv 

Wednesday, 23 December 2015

Clearing out move requests

When you perform a successful mailbox migration, either from another version of Exchange or from another mailbox database the move request is "left" behind as such and should be cleared out as part of good housekeeping.

My favourite command for doing this is:

Get-MoveRequest -MoveStatus Completed | Remove-MoveRequest

Wednesday, 28 October 2015

Unable to sync phone to Exchange

If you've been following my blog for the last few weeks you'll have heard me talk about the Exchange 2013 migration project I've been working on.  Well we hit another snag in the migration the other day around the users mobile phones not syncing to the new mailbox server after moving to Exchange 2013.

At first we thought it was just one or two users but it transpired that over 80 users were affected!! After investigating whether or not ActiveSync was working as expected (it was) we turned our attention to looking at an issue within the users accounts.

It turned out that the 80 users were all a member of a protected group within Active Directory and weren't getting the correct permissions to sync their phones as per Microsoft's best practices.

In order to get to that stage I used some PowerShell queries which I thought were quite interesting so I'm sharing.

I used the following command to query Active Directory for all users that had the "AdminCount" attribute set to something greater than 0.  If set to 1 it indicates the user is either a member of a protected group or has been:


Import-Module ac* 
Get-ADuser -filter {admincount -gt 0} -Properties admincount -ResultSetSize $null | export-csv c:\\onyx\document.csv

To find out which groups within the Active Directory environment I was working in were considered a Protected Group I ran the following query:

Import-Module ac*
Get-ADgroup -LDAPFilter "(admincount=1)" | select name 

From there I was able to check the groups individually to see which ones contained, if any, the users that were having issues with their phones.  All the affected users were a member of the "Print Operators" group. Mystery solved!



Friday, 23 October 2015

Get Mailbox Move Progress

I've recently been involved in an email migration from Exchange 2007 to Exchange 2013 and in order to monitor the progress of the mailbox moves I've been using Powershell commands, the two I've used are:

Get-MoveRequestStatistics -MoveRequestQueue "Mailbox Database 1"| Sort PercentComplete

This results in giving the Display Name, StatusDetail, TotalMailboxSize, TotalArchiveSize and PercentComplete of each mailbox move to that Exchange 2013 database.



The other one that I've found useful is:

Get-MoveRequestStatistics -MoveRequestQueue "Mailbox Database 1"| Where-Object {$_.StatusDetail -eq "Copying Messages"} | Sort PercentComplete

This is just a variation on the first query but it only shows the mailboxes that are currently copying messages to the Exchange 2013 environment.



Just remember a watched kettle never boils though! lol 

Wednesday, 21 October 2015

Powershell Query to Analyze your Mailbox Movement

I've recently been doing an Exchange 2007 to Exchange 2013 migration and wanted to find out the kind of speed the mailbox moves were taking.  I used the below Powershell script to pull out the MB transfer speed per minute:


Get-MoveRequest | Where { $_.Status -eq “Completed” } | Get-MoveRequestStatistics | Select DisplayName,TotalMailboxSize,TotalMailboxItemCount,@{n=”Speed MB/min”; e={ [int]($_.BytesTransferred.ToMB() / $_.TotalInProgressDuration.TotalMinutes) }}


Friday, 18 September 2015

How to resolve the error ‘550 5.7.1 Unable to Relay’?

I recently came across an issue at work where one of our servers wasn't able to send any email alerts out. On troubleshooting the issue we were receiving a '550 5.7.1 Unable to relay' error message.

Duly checked the receive connectors within the Exchange Management GUI and everything looked okay but still the server wasn't able to relay. On launching the Exchange Management Powershell console we ran the command:

Get-ReceiveConnector "Receive Connector" | Get-ADPermission -User "NT AUTHORITY\ANONYMOUS LOGON"

And noticed that instead of there being rights for "ms-Exch-SMTP-Accept-Any-Recipient", there were rights for "ms-Exch-SMTP-Accept-Any-Sender"

We issued the command:

Get-ReceiveConnector "Receive Connector" | Add-ADPermission -User "NT AUTHORITY\ANONYMOUS LOGON" -ExtendedRights "ms-Exch-SMTP-Accept-Any-Recipient"

And the server was able to relay messages once again. We haven't been able to determine, who or what changed the permissions on the connector but they'd been modified and the above command resolved our issue.

If you are trying to send notifications via your Exchange with an Anonymous connector ensure the following has extended rights:

NT AUTHORITY\Anonymous Logon {ms-Exch-SMTP-Submit}
NT AUTHORITY\Anonymous Logon {ms-Exch-Accept-Headers-Routing}
NT AUTHORITY\Anonymous Logon {ms-Exch-Bypass-Anti-Spam}
NT AUTHORITY\Anonymous Logon {ms-Exch-SMTP-Accept-Any-Recipient}

Thursday, 25 June 2015

Powershell Tip: Search for users with an Active Sync device

The script below will search through a mailbox database and list the users that have Active Sync devices attached and list the type of device.

ForEach ($mb in (Get-Mailbox -database DATABASENAME)) { Get-ActiveSyncDeviceStatistics -Mailbox $mb | Select @{Label="Name";Expression={$mb.Name}},DeviceType,DeviceOS,LastSuccessSync}

Replace DATABASENAME with the name of the database you wish to query

This script has been test on Exchange 2010 SP1 and Exchange 2010 SP3.

Monday, 22 June 2015

Powershell Tip: How many DIMMs are in a machine and utilised

The following Powershell command will tell you the total amount of DIMM slots within a machine and what is currently installed within those slots, if anything.

Just save it as a .PS1 file and when you run it you will be asked for the name of the machine you wish to query. If you wish to query your own PC just enter "localhost" as the name.


$strComputer = Read-Host "Enter Computer Name"
$colSlots = Get-WmiObject -Class "win32_PhysicalMemoryArray" -namespace "root\CIMV2" `
-computerName $strComputer
$colRAM = Get-WmiObject -Class "win32_PhysicalMemory" -namespace "root\CIMV2" `
-computerName $strComputer

Foreach ($objSlot In $colSlots){
"Total Number of DIMM Slots: " + $objSlot.MemoryDevices
}
Foreach ($objRAM In $colRAM) {
"Memory Installed: " + $objRAM.DeviceLocator
"Memory Size: " + ($objRAM.Capacity / 1GB) + " GB"
}

Tuesday, 7 April 2015

Deploying Windows Update (.msu) with SCCM

I was recently packaging up an application for SCCM and one of the pre-requisites of this application was that a Windows Update (.msu) had to be installed.

In order to package up this Windows Update and deploy it as an application I did the following:


  • To silently install the update I ran the following command within the application deployment -wusa.exe KBxxxxxx.msu /quiet /norestart
  • In the detection method tab, set the option to "Use a custom script to detect the presence of this deployment type" and select Edit
  • Change the script so that it is set to Powershell and enter in the following command -
    get-hotfix | Where-Object {$_.HotFixID -match "KBxxxxxx"}
The deployment ran fine after that.  If you have any execution errors from the script you can change the PowerShell Execution Policy to bypass on the SCCM agent client settings. 

Check out my blog post on setting the PowerShell Execution Policy for all SCCM agents - http://www.techielass.com/2015/03/powershell-execution-settings-sccm-agent.html


Thursday, 2 April 2015

PowerShell Execution Settings SCCM Agent

If you are using any kind of PowerShell commands within your SCCM application deployments you and are having issues getting the commands to run because of the the PowerShell Execution Policy level then a way around it is to do the following:


  • Within the SCCM console go to Administration > Client Settings > Open Default Client Settings
  • Click on Computer Agent
  • Set the PowerShell Execution Policy to Bypass
  • Click OK
This setting will take a while to roll out to all your clients but should fix any errors you've been having with PowerShell running. 

Monday, 23 March 2015

Enabling Powershell support in your boot image - SCCM 2012 R2

I am currently running SCCM 2012 R1 CU3 (version 5.0.7958.1401) and was looking to add Powershell support to my Boot Images but was constantly coming up against an error message.

Let me walk you through the process, the error message and solution.

To add Powershell support to your Boot Image, launch your SCCM Console and browse to Software Library > Operating Systems > Boot Images



Right click on the Boot Image you wish to modify and click Properties. Then click on Optional Components.

Click on the Yellow star to add a component



If you type Powershell into the filter it will display three options, select "Windows Powershell (WinPE-Powershell)".  A prompt will come up telling you that you need to enable "Microsoft .NET (WinPE-NetFx)"



If you click OK three times you will be prompted that you have made a change and you need up update the distribution points.  Click YES and the update Distribution Points Wizard will display, let the wizard run.

The Wizard will fail and offer the following error message:



The problem is that when you filter the optional components it hasn't automatically enabled the "Microsoft .NET (WinPE-NetFx)" component that is needed alongside Powershell.  You need to manually add this in also.

So click on Close on the failed distribution wizard.

Right click on the boot image that you wish to modify, select Properties and Optional Components.  Powershell should still be listed, so click on the yellow star and search for "NetFx" and select this and Click OK three times.  Again you will be prompted to update the distribution points.



Allow this to complete and you will be provided with a window saying your boot image has been successfully updated.

The lesson learned here is if you are filtering the optional components, ensure you read any warnings that are shown and manually check the other required components.

Wednesday, 5 November 2014

How many users are stored in an Exchange Database?

In order to find out how many users are stored within an Exchange 2010 Database there is a very useful and simple Powershell Command you can run:

Get-Mailbox | Group-Object -Property:Database | Select-Object name,count