04-10-2023 01:55 PM - edited 04-10-2023 01:58 PM
OK, se we want to move out company from using the RAT table to querying and LDAP directory.
Right now, my co-worker's email is in this AD dir and mine is not. I made a test policy that any email from my gmail to anyone in the LDAP group would hit this policy. We do not have anything set on the listener.
Now, if I email from my gmail to alex@myco.com it hits the rule as expected, but if I email from my gmail to dustin@myco.com it hits the default policy as expected.
TAC said the RAT table supersedes LDAP, but if that was true my email should have hit that rule also. They also said it would not check LDAP without it set on the listener, but that is not true it would seem.
So,
1) I guess in what order does stuff get checked, does policy supersede RAT which supersedes LDAP?
2) How do I set the group check on the listener? I can select a query, but unlike a policy it doesn't have a spot to add the group.
2b) TAC said we have to call the group on the listener and also call the group in the mail policies, but policies are not listener specific.
2c) If it's just set on the listener, do I have to modify the query to the correct group? IE change
(&(memberOf={g})(proxyAddresses=smtp:{a}))
to
(&(memberOf={CN=fg_External_Email_Access,OU=Domain,OU=Functional Groups,DC=MYCO,DC=COM})(proxyAddresses=smtp:{a}))
3)Where/what does the RAT table play in it, do we blank it out once we set LDAP?
My biggest issue is there really is no easy way to test global email settings without causing issues. We get over 150k/day incoming emails on 3 ESAs. So, if we mess it up we can mess up 1/3 of our emails.
Solved! Go to Solution.
04-10-2023 02:45 PM
04-10-2023 02:16 PM
04-10-2023 02:30 PM
Yeah, this is the issue, we do limit who can be emailed as some email addresses are internal use only along with distribution lists.
And yeah, they used the RAT as the filter, there are over 6800 entries in the RAT currently for any email that can be accepted.
So, because of some internal only emails etc, they wan to have a FG or externally available email addresses and for the ESAs to check that instead of a manual RAT entries.
So, with that, do we leave the policies to any recipient, set the LDAP group query on the listener, and blank out the RAT table?
04-10-2023 02:45 PM
04-11-2023 06:09 AM
Thanks,
And yeah, I figured they should be able to do it in Exchange, but our admin didn't seem to know how so it looks to be falling to us to do their job.
04-13-2023 09:07 AM
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: