Академический Документы
Профессиональный Документы
Культура Документы
Office Communications
Server 2007 (Public
Beta) in a Multiple-
Forest
Environment
Published March 2007
This document supports a preliminary release of a software product that may be changed substantially prior to final commercial release.
This document is provided for informational purposes only and Microsoft makes no warranties, either express or implied, in this document.
Information in this document, including URL and other Internet Web site references, is subject to change without notice. The entire risk of
the use or the results from the use of this document remains with the user. Unless otherwise noted, the companies, organizations, products,
domain names, e-mail addresses, logos, people, places, and events depicted in examples herein are fictitious. No association with any real
company, organization, product, domain name, e-mail address, logo, person, place, or event is intended or should be inferred. Complying
with all applicable copyright laws is the responsibility of the user. Without limiting the rights under copyright, no part of this document
may be reproduced, stored in or introduced into a retrieval system, or transmitted in any form or by any means (electronic, mechanical,
photocopying, recording, or otherwise), or for any purpose, without the express written permission of Microsoft Corporation.
Microsoft may have patents, patent applications, trademarks, copyrights, or other intellectual property rights covering subject matter in this
document. Except as expressly provided in any written license agreement from Microsoft, the furnishing of this document does not give
you any license to these patents, trademarks, copyrights, or other intellectual property.
Microsoft, MS-DOS, Windows, Windows NT, Windows Server, Windows Vista, Active Directory, and SQL Server are either registered
trademarks or trademarks of Microsoft Corporation in the United States and/or other countries.
Prerequisites
To support a central forest topology, the following prerequisites are required.
• Microsoft Identity Integration Server In order to synchronize data across your forests,
you must deploy Microsoft Identity Integration Server. The following QFE is required for
proper cross-forest synchronization:
http://www.microsoft.com/downloads/details.aspx?familyid=FA9DBB67-4654-4C94-B073-
AA59676130AF&displaylang=en. For information on how to deploy MIIS, see the
Microsoft Identity Integration Server documentation.
• Office Communications Server deployed in your central forest. If you have not deployed
Communications Server, see the Microsoft Office Communications Server Planning Guide
and the Microsoft Office Communications Server Deployment Series.
The central forest can be an existing forest that hosts existing Communications Servers, users,
groups, and contacts, or you can create an entirely new forest.
The central forest should normally be the one that hosts the largest number of users. Connectivity
between the central forest and other forests should also be highly available. Figure 1 shows how
an example organization, Contoso, configured an Enterprise pool in its central forest.
Deploying Communications Server 2007 in a Multiple Forest Environment 3
Figure 1 Example of a Multiple Forest topology
(1)
SQL
MIIS Server
(2) (2)
(3) (3)
Active Directory
Active Directory Active Directory
Users &
Users &
groups
groups Contacts
User Forest User Forest
Pool
Central Forest
...
Labels SQL
Active
SQL
MIIS Server
Directory Communications Server 2007
Pool
User and (1 ) – MIIS synchronizes Communications Server users as contacts
Contact object
group objects
(2 ) – Minimum trust requirements are a 1-way trust between domains hosting Communications Server in one
forest and user- and groups in the other forest
Enterprise
SQL
SQL server (3 ) – Schema does not need to be extended
Edition server
After you have deployed Communications Server in the central forest, you do the following:
1. Configure the Microsoft Identity Integration Server.
2. Enable contacts for Communications Server.
4 Deploying Communications Server 2007 in a Multiple Forest Environment
For example:
<target-ou>OU=contactsDC=contosoDC=com</target OU>
6. If necessary, you can modify Logging.xml to change the file name and logging level. The
example below shows the default values in the xml:
<logging>
<use-single-log>false</use-single-log>
<file-name>lcssync.log</file-name>
<logging-level>1</logging-level>
</logging>
Deploying Communications Server 2007 in a Multiple Forest Environment 7
6. Select the Enable Provisioning Rules Extension check box, and then click OK.
8 Deploying Communications Server 2007 in a Multiple Forest Environment
Configuring the Object Deletion Rule in MIIS
After you have configured extensions for the Communications Server Sync tool, configure the
rule that determines what MIIS will do when a User object is deleted in a forest and how it will
synchronize the deletion with the central forest. If a User object is deleted in a user forest, the
corresponding Contact object that is used by Communications Server in the central forest must
also be deleted. Configuring the object deletion rule ensures that MIIS and the Communications
Server handle this situation correctly.
To configure the Object Deletion Rule
1. On the MIIS computer, start Identity Manager: Click Start, point to All Programs, point to
Microsoft Identity Integration Server, and then click Identity Manager.
2. Click Metaverse Designer. The Identity Manager window should appear as shown in
Figure 4.
Figure 4 Configure Object Deletion Rule in Metaverse Designer
5. In the Configure Object Deletion Rule dialog box, which is shown in Figure 5, click Rules
Extension, and then click OK.
Figure 5 Configure Object Deletion Rule
5. In Name, type a name for the management agent. This name must be identical to the name
that is specified in the <lcsma name => tag in Lcscfg.xml.
6. Click Next.
7. Enter the user name and password of a member of the DomainAdmins group on the
Communications Server in the central forest.
8. Click Next.
Deploying Communications Server 2007 in a Multiple Forest Environment 11
Figure 7 Partitions Matching
9. In Partitions Matching, under Update Partitions, select the partition that needs to be
updated, and in Existing Partitions, select the partition that contains the distinguished name
of your central forest.
10. Click Match.
11. In Existing Partitions, select each unmatched partition and click Deselect.
12. Click OK.
13. In Select directory partitions, clear the check boxes for all domains except for the domain
that has the target organizational unit that you specified in Lcscfg.xml when you deployed
the Communications Server Sync tool.
14. Click Containers.
15. In Select Containers, select the OU container where contacts will be stored, and then click
OK.
16. Click Next.
17. On the Select Objects page, accept the default values, and then click Next.
18. On the Select Attributes page, accept the default values, and then click Next.
12 Deploying Communications Server 2007 in a Multiple Forest Environment
19. On the Configure Connector Filter page, accept the default values, and then click Next.
20. On the Configure Join and Projection Rules page, accept the default values, and then click
Next.
21. On the Configure Attribute Flow page, accept the default values, and then click Next.
22. On the Configure Deprovisioning page, accept the default values, and then click Next.
23. On the Configure Extensions page, verify that Lcssync.dll is selected, and then click
Finish.
Note
You must synchronize the metaverse with data from the
central forest before you synchronize with the user forests.
Note
You must synchronize information from the central forest
before synchronizing information from user forests.
ms-RTC-SIP- sidA
OriginatorSID
ms-RTC-SIP-
TargetHomeServer
telephoneNumber 555-1234 555-1234
displayName User A User A
givenName Dylan Dylan
surname Miller Miller
physicalDeliveryOfficeN 4500 4500
ame
l (city) Redmond Redmond
st (state) WA WA
Country U.S.A U.S.A
Title Director Director
Mail userA@contoso.com userA@contoso.com
Company Contoso Contoso
Group Attributes
Communications Server Sync and updated GAL sync synchronize all of the following attributes:
• objectSid
• mail
• displayName
• groupType
MIIS Errors
The following table lists some common MIIS errors and describes the possible causes and
resolution.
Prerequisites
To support a resource forest topology, you must have deployed Office Communications Server
deployed in your resource forest and configured at least a one-way trust between the resource
forest and all user forests (such that the resource forest trusts all user forests).
If you have not deployed Communications Server, see the Microsoft Office Communications
Server Planning Guide and the Microsoft Office Communications Server Deployment Series.
Figure 8 shows how an example organization, Contoso, configured an Enterprise pool in its
resource forest.
Figure 8 Example of a Resource Forest Topology
After you have deployed Communications Server in the resource forest, you do the following:
• Create disabled accounts with the corresponding attributes for each user account in the user
forests. This process will vary depending on whether or not you have Microsoft Exchange
Server deployed in the resource forest, as explained in the following section.
• Enable these disabled accounts for Office Communications Server.
Note
In resource forest deployments with Exchange Server, all of
the attributes are already populated except for the ones
beginning with the ms-RTC-SIP prefix. Populate these
attributes using the SID mapping tool.
In resource forest deployments without Exchange Server, you
must manually populate the required attributes on each
disabled user account in your resource forest. This method
can introduce problems that are difficult to fix. In these
deployments, use the Central Forest topology instead. For
more information, see Part 1: Deploying Office
Communications Server in a Central Forest Topology.