1. Try to get hold of a system where exchange and active directory are installed.
2. Install AD Connector on the OIM Server and provision a user (For testing purpose)
3. Install Microsoft Exchange connector on the OIM Server. Please note that you need the Remote Manager only when you are using the exchange server 2007. Otherwise you do not need to any thing on the OIM Server.
4. Create a IT Resource for Exchange and leave all the attributes as blank.
5. Run the “Exchange Mail Store Lookup Reconciliation” task , before running this task scheduler change the “AD IT resource” attribute to the AD Connector that you created in the step no:2.
6. This schedule task populates the “Lookup.ExchangeReconciliation.MailStore” lookup values. For example in my case it populated my mail box name as “celvpint0309-ADInstance~CN=Mailbox Store (MSBOX),CN=First Storage Group,CN=InformationStore,CN=MSBOX,CN=Servers,CN=First Administrative Group,CN=Administrative Groups,CN=MSExchange2003Org,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=vm,DC=oracle,DC=com”
7. Now provision the AD User to the Exchange System. Only mandatory fields are Email Alias Name and the mail store name.
8. Now log in to the AD Server machine and check the AD User. For the exchange user you will see more attributes in the AD User TAB.
1 comment:
Ravi,
I have a question. Is there any scheduled task in exchange connector 9115 which will identify deleted (not disabled) mailbox in exchange server and updated user's OIM exchange resource object status to "Revoked".
1) Create user in OIM and provision to AD and Exchange.
2) Disable user's OIM account, which will disable user's AD and Exchange resource objects.
3) Exchange Admin will DELETE the disabled mail boxes after 'n' number of days.
How can we let OIM know that user mail box deleted and hence the exchange resource object status should be marked to "Revoked" from "Disabled". If it set to Revoked we could recreate/reprovision the mailbox when user gets enabled in OIM.
(In AD connector "AD User Target Delete Recon" does this job for deleted AD account! )
Thanks
Logu.k
Post a Comment