Thursday, 9 May 2019

Azure AD - Roll over Kerberos keys

After enabling seamless SSO, you need to roll over Kerberos decryption key every month or so.
Process is desribed on this site:

However, you can need to adjust your installation on the server to run AzureAD 2.0.
Here is the short tutorial:

And here the effect:

Wednesday, 13 February 2019

Password sync does not work ADConnect and Office365

You just configured your ADConnect and password sync doesn't work?
Or maybe it just stopped after some configuration changes?

If you are getting errors with ID 611, then you need to check AD permissions for sync account, or if you are not sure, run embedded cmdlet in ADSyncConfig module (it's included in AD Connect from 1.1.880.0 released in August 2018 according to Microsoft)

Import-Module "C:\Program Files\Microsoft Azure Active Directory Connect\AdSyncConfig\AdSyncConfig.psm1"
Set-ADSyncPasswordHashSyncPermissions -ADConnectorAccountName YOUR_ADSYNC_ACCOUNTHERE -ADConnectorAccountDomain YOUR_LOCALDOMAIN_HERE

Wednesday, 3 October 2018

msExchHiddernFromAddressList is not synced to Office365

You need to hide Exchange Online mailbox from address list and have AD synchronization in place, but no local Exchange.
You then extend Active Directory schema by using local Exchange installation with setup.exe /prepareschema switch.
Next, you are fire up refresh directory schema in AD Connect, and do full AD sync, and...
No, msExchHiddenFromAddressList attribute is not syncing, even if it is set in AD account attributes and seen on AD Connect connector.

If you have made all the previous steps, then probably your AD account has mailnickname attribute not set

After fill it with proper data (alias), and do another AD Connect AD sync , you can  see your msExchHiddenFromAddressList synced at last.

Tuesday, 19 June 2018

Cannot install Skype For Business Online Powershell

If you trying to install "SkypeOnlinePowerShell.Exe", following guide on Microsoft site:,
and you are getting error about VC ++ minimum version 11.0.5727, you need to install EXACTLY this version, apart from your versions already installed on your system.
So, go to the below link and install it first:
Then you should be able to install SkypeOnlinePowershell

Wednesday, 23 November 2016

Azure: Azcopy error : Failed to validate destination

When you try to upload files into Azure using AzCopy command line you ca encounter this error:
Failed to validate destination: One or more errors occurred. The remote server returned an error: (404) Not Found.

Before you start pulling hair from your head just uninstall new version of AzCopy and install an old one.
For me, the latest working version is 5.0

Monday, 17 October 2016

Migration between two Office 365 tenants

In the era of cloud solutions, soon or later we will face the challenge of connecting two of them together. Merges and acquisitions of companies which possess separate cloud IT infrastructure needs to be joined, unified and also simplified if possible.
Using experience after few successful migrations, I will try to explain here the most important things to consider in similar projects, when Office356 is involved.
This is not step by step instruction – only lessons learned from the migration field.
At the beginning - things which appears every time you plan a change in the organization.

Determine customer expectations and goals

The most important thing, which – when chasing for time and money some people forget - the success of the project depends on the fulfilment of customer expectations. Dot.

More you can read at the Gooroo site: