Ping Symantec Enterprise Vault Employee - RE Hidden Mailbox Archiving
Ok, so we have fully implemented Enterprise Vault for Exchange company wide, we have gone through the painstaking operational meetings to define policies and create both an archival, and a retention policy for every walk of life. The system has been up and running for almost a year and is working beautifully....
UNTIL...
We start writing some reports that tell us when it is ok to:
1. delete a termed employee's mailbox once all the email has been archived.
2. delete a termed employee's archive and account once all the email has been retentioned out
Therein lies the problem. We made sure during the planning stages that we set the registry keys to Archive Disabled and Hidden mailboxes, since we knew that disabling and hiding was part of our termination process. What do we find? Enterprise Vault is not archiving a single message from the time we check Hide Mailbox. Not one.
So I do what we always do, track down anything I may have done incorrectly, scour the Internet for more information. After a couple of days of searching I find this article:
http://www.symantec.com/connect/forums/archiving-h...
In this article it mentions that the Provisioning process changed the MbxExchangeState field in the ExchangeMailboxEntry table to 2 every time it runs, and that this is the reason that mailboxes are not being archived. The answer to my question lies in running a sql script to reset the MbxExchangeState back to 0 after every run of Provisioning.
So my question is, WHY? Why would you have a registry setup key that says process hidden mailboxes only to not process them? Why is the sql script not mentioned in the documentation? Why does the documentation state that after changing the registry you will have to rerun the Provisioning task, which will insure the hidden mailboxes will not be processed?
This makes our termination process somewhat manual, we have to run the script, then execute an archive job just to ensure all the terminated, (disabled & hidden) users get archived.
Does Symantec consider this as big of a bug as I do?
Please advise....
Comments
Hi,
EV certainly should be archiving from those hidden mailboxes. Please contact support, let me know the case number here and I'll keep an eye out for it.
Mike
Mike Bilsborough
Director,Enterprise Vault Engineering Support
I will do so first thing Monday morning. Thank you for your time and your support.
Faster, faster, faster, until the thrill of speed overcomes the fear of death. ~Hunter S Thompson
Symantec Case Number 412487933.
Thanks!
Faster, faster, faster, until the thrill of speed overcomes the fear of death. ~Hunter S Thompson
I have heard nothing so far, how are things on your end?
Faster, faster, faster, until the thrill of speed overcomes the fear of death. ~Hunter S Thompson
The case was closed. Symantec stated that there is no way to archive hidden mailboxes unless the sql script was run, their suggestion was that we schedule the script to run after the provisioning task. They also suggested that I complete an enhancement request.
Note to all out there in EV land, if you think your hidden mailboxes are getting archived you best check again!
Faster, faster, faster, until the thrill of speed overcomes the fear of death. ~Hunter S Thompson
Hi,
I've just done a quick test using just the hidden mailbox reg key and that seems to work in isolation without the AD account being disabled. I'll just try it with both settings to see if that works or not as it may be the combination of keys that is the problem
It seems to work for me without setting the disabled AD accounts reg key. Just setting ProcessHiddenMailboxes to 1 under the Agents key still allowed hidden mailboxes with disabled AD accounts to be archived... Not sure why it's not working for you though, but it sounds like it might be worth re-engaging with Support for further investigation
Ok so it works only for hidden mailboxes, if the account is not disabled.
It's still broke though.
Currently normal users get disabled upon terminated. We hide them from the address list so people don't complain they are still listed in our directories. The combo of both is what I need.
But for your example, we also disable system accounts (that just use mailboxes) for example our Conference Room accounts, used for resource scheduling in outlook, so that those accounts can not log in, but have email for calendar purposes. If we only did hidden only, those mailboxes would not be archived. I would be trading one issue for another.
I can get on or the other working, just not both.
Faster, faster, faster, until the thrill of speed overcomes the fear of death. ~Hunter S Thompson
Which reg keys do you have set? I have a disabled AD account with a hidden mailbox which appeared to archive just fine with just the ProcessHiddenMailboxes key set
Nick,
I have them both set for the reasons mentioned above. ProcessHiddenMailboxes = 1 and ExcludeDisabledADAccounts = 0
Terminated Users are Both Hidden and Disabled (I understand, you say if registry key ExcludeDisabledADAccounts is not present it works)
Outlook Resource Scheduling Accounts and others like it are disabled not hidden (without ExcludeDisabledADAccounts these boxes will not be archived)
Faster, faster, faster, until the thrill of speed overcomes the fear of death. ~Hunter S Thompson
Sorry, I completely missed the point about the ORSA accounts...! I've got someone looking into this as it looks like it's a problem with the ExcludeDisabledADAccounts reg key, so I may need you to reopen the case for escalation if it proves to be a code issue. Hopefully I'll have an update tomorrow, though probably not tonight
JimRich, what version of EV are you using?
Andy Becker | Authorized Symantec Consultant | Trace3 | Symantec National Partner | www.trace3.com
8 SP 4 and thank you thank you thank you!
Faster, faster, faster, until the thrill of speed overcomes the fear of death. ~Hunter S Thompson
Hi,
In typical fashion, I can repro this but the dev can't, though he was only trying it very quickly. Can you reopen the case for further investigation please? Feel free to point the Support person in my direction if needed!
Nick,
I have done so I am awaiting a call back.
Faster, faster, faster, until the thrill of speed overcomes the fear of death. ~Hunter S Thompson
JimRich,
we have the same problem as you describe. unfortunately we stumbled apon it when asked to retrieve archived mail from an employee who left the company then was rehired months later. our process was to move the AD account to a 'Terminated Employees' OU then hide from teh GAL. our new strategy is to enable them after 2 months, and put them in a security group that archives everything older than 0 days. once the mail is completely archived we disable again. As you stated, this is a manual process and is very annoying to do. we actually scripted it out recently so it isnt too bad, but we did lose a bunch of mail that we thought was being archived until we realized this was happening.
Again, disabled accounts do not get archived. Please post if Symantec resolves this. we are on 8.0 sp2.
Nick,
No call back today either, I will place another call to Symantec tomorrow morning. I have been juggling other issues today :(
Faster, faster, faster, until the thrill of speed overcomes the fear of death. ~Hunter S Thompson
Nick,
I got that call back today. I told him to look you up. His original solution was to schedule the sql script from above, please see what you can do.
in the least get the documentation changed to state reality :)
Thanks!
Faster, faster, faster, until the thrill of speed overcomes the fear of death. ~Hunter S Thompson
Hi Jim,
I had a message from the Support rep late on Friday, so I'll ask him to escalate the case
Thanks Nick.
Faster, faster, faster, until the thrill of speed overcomes the fear of death. ~Hunter S Thompson
Any movement on getting this fixed?
Faster, faster, faster, until the thrill of speed overcomes the fear of death. ~Hunter S Thompson
Hi Jim,
apologies for the lack of updates. I have chased the support representative again
Nick
Hi
Please can you validate your Exchange server version for us as I don't see it mentioned here. Exchange 2003 requires an update to be able to log in to mailboxes of disabled accounts.
See the following article:
http://blogs.technet.com/b/benw/archive/2007/07/09/exchange-2003-and-disabled-user-accounts.aspx
For Exchange 2003 SP2 your store.exe version must be equal to or later than 6.5.7651.14. Unfortunately in EV there is a silent error if we encounter this issue that can only be picked up via Dtrace.
The ExchangeMbxState of 2 records the fact the mailbox is hidden, however this field is deprecated in the archiving task and it now uses the ADMbxFlags field (if your mailbox is hidden and disabled you can expect this value to be 3). The VAC doesn't list hidden/disabled mailboxes for enabling - so I'm guessing this might be why you are setting ExchangeMbxState back to 0.
Alternatives for enabling are EVPM or automatically via the provisioning group.
Regards
Karl
My store version is 6.5.7652.24
My Exchange server version is 6.5 (Build 7638.2: Service Pack 2)
Faster, faster, faster, until the thrill of speed overcomes the fear of death. ~Hunter S Thompson
Hi Jim
I was reading the support case and it doesn't say mailboxes aren't being processed only that you have to apply the SQL fix to each terminated user in order to enable them. Do they archive correctly after this?
One method for processing terminated users is to move them to another OU in AD or generate a group/distribution list of terminated users. You then create a new provisioning group in EV and target this OU or group. Set the appropriate policy and set mailboxes to be enabled automatically. Because you've set the target specifically you don't need to worry that other mailboxes will be automatically enabled.
When the archiving task runs as part of its schedule (making sure the ProcessHiddenMailboxes and ExcludeDisabledADAccount registry values are configured correctly) the task should enable and process these mailboxes regardless of SQL scripts to update ExchangeMbxState.
The provisioning will run daily and continue to set ExchangeMbxState to 2 and ADMbxFlags to 3 - this should be fine and not stop mailboxes from being archived. Unfortunately as you have found what you cannot do with EV is enable these mailboxes through the VAC.
Sorry if I missed something from the case - if this issue is that mailboxes are not being archived once enabled then to determine the cause we may need to capture a trace of the archive task.
Regards
Karl
I could be wrong on this but here is my two cents. I have been working with EV since 2005. If you hide a mailbox you can not make a MAPI connection to the mailbox, so you can use OWA but you can use the full Outlook client. So since EV is making a MAPI connection it cannot connect to the mailbox to Archive the item. This is the reason we can not hide the Journal Mailbox.
At least it works that way in Exchange 2003. Comments would be appricated.
Thanks
Max
When a mailbox is hidden from the GAL EV cannot configure a MAPI profile against that mailbox (as this results in a lookup - try doing the same from Outlook).
For this reason the system mailboxes for the tasks cannot be hidden. However other mailboxes can be hidden (including the journal mailbox) as profiles are not created against these.
If you search these forums you'll find other topics talking about hiding the journal mailbox. Microsoft suggest the journal mailbox is hidden (http://technet.microsoft.com/en-us/library/bb738122(EXCHG.80).aspx)
Regards
Karl
Symantec's solution to this
Symantec's solution to this problem is what they told me initially. They created this document and closed my case. They did however say they would correct the documentation to reflect the correct functionality.
http://seer.entsupport.symantec.com/docs/282737.htm
Faster, faster, faster, until the thrill of speed overcomes the fear of death. ~Hunter S Thompson
Would you like to reply?
Login or Register to post your comment.