Search This Blog

Showing posts with label O365. Show all posts
Showing posts with label O365. Show all posts

Friday, February 18, 2022

Teams LBR outbound calls are failing

 Few points regarding Location based routing debug in Teams. A user can not call out and Teams shows error message:

"Get Outbound Direct routing - no trunk config found by LBR selection criteria."

in Usage reports, as well as in client logs (Ctrl-Shift-Alt-1 to generate logs in Teams client):


    "terminatedReason": 72,

    "ccCode": 403,

    "ccSubcode": 510546,

    "phrase": "Get Outbound Direct routing - no trunk config found by LBR selection criteria."


One of the possible reasons is that user has no Calling policy "AllowCallsPreventTollBypass"


The prerequisites for LBR:

Voice policy has PSTN usage pointing to routes to SBC with LBR enabled.

User connects from LAN segment that is known and attached to a network location

External public IP is in trusted list (if protected by Zscaler or something like that all Zscaler ranges must be in the trusted IP list, if no prox, then outgoing firewall IP must be included)

SBC is attached to the LBR location.

User has calling policy to prevent toll




Thursday, January 16, 2020

Windows Hello on HP Probook 470 G0

If you are looking for fingerprint sensor drivers for Windows Hello, try to get it from here:



I have WH bio-metric sensor successfully running on this platform.


D.

Thursday, May 16, 2019

Office 365 Exchange Online Protection and DMARC

If you want to protect your domain with DMARC or use DMARC to filter spam and you use Office 365, note that Microsoft decided to alter normal DMARC policy. Imagine the domain protects itself and a message was identified as DMARC=fail and policy is set to reject with 100%. DMARC policy example: v=DMARC1;p=reject;pct=100
Office 365 will ignore reject and will deliver email marked as spam. A header will contain

"dmarc=fail action=oreject" (oreject being overwritten reject.)

Here is how Microsoft justifies this design decision:

"If the DMARC policy of the sending server is p=reject, EOP marks the message as spam instead of rejecting it. In other words, for inbound email, Office 365 treats p=reject and p=quarantine the same way.
Office 365 is configured like this because some legitimate email may fail DMARC. For example, a message might fail DMARC if it is sent to a mailing list that then relays the message to all list participants. If Office 365 rejected these messages, people could lose legitimate email and have no way to retrieve it. Instead, these messages will still fail DMARC but they will be marked as spam and not rejected. If desired, users can still get these messages in their inbox through these methods:
  • Users add safe senders individually by using their email client
  • Administrators create an Exchange mail flow rule (also known as a transport rule) for all users that allows messages for those particular senders."


https://docs.microsoft.com/en-us/office365/securitycompliance/use-dmarc-to-validate-email#inbounddmarcfail

Tuesday, May 29, 2018

Skype for Business Hybrid one way


We have a problem of one way presence in hybrid deployment. From one Prems, we can not see online users in the same domain. Here is subscribe ok we get on onprem side:


TL_INFO(TF_PROTOCOL) [EDGE01\EDGE01]0E00.1480::05/25/2018-19:37:29.817.0000BB79 (SIPStack,SIPAdminLog::ProtocolRecord::Flush:ProtocolRecord.cpp(261)) [2044151173] Trace-Correlation-Id: 2044151173
Instance-Id: F3
Direction: incoming;source="external edge";destination="internal edge"
Peer: sipfed.online.lync.com:5061
Message-Type: response
Start-Line: SIP/2.0 200 OK
From: "Test Skype1";tag=b8040a09ec;epid=ff13667dd7
To: ;tag=5C4D0080
Call-ID: f7f33e99902d45488e4b2c76924d00a5
CSeq: 1 SUBSCRIBE
Contact:
Via: SIP/2.0/TLS 10.100.1.41:49186;branch=z9hG4bK9FE0F169.F3E35464A2AA98C9;branched=FALSE;ms-internal-info="aaDSMbd_7l0a4U9R6npyIrDBxYlV2GUNocfizAJ2ScR15kVOPzyc4VHQAA";received=52.112.132.124;ms-received-port=49186;ms-received-cid=B6C95E00
Via: SIP/2.0/TLS 10.20.1.36:61901;branch=z9hG4bKB46E0708.870D177F11B578C8;branched=FALSE;ms-received-port=61901;ms-received-cid=300
Via: SIP/2.0/TLS 10.20.1.9:49176;branch=z9hG4bK7D7D836D.E605002CA2AA98C9;branched=FALSE;ms-received-port=49176;ms-received-cid=4DBD00
Via: SIP/2.0/TLS 192.168.168.244:55348;received=84.75.200.148;ms-received-port=55348;ms-received-cid=1400
Record-Route:
Record-Route: ;tag=6B374769C547A54AF3927B7A63EC325B
Content-Length: 470
Content-Type: multipart/related; type="application/rlmi+xml";start=resourceList; boundary=1550b37c575843dbb98e18be4e840f3d
ms-split-domain-info: ms-traffic-type=SplitIntra
ms-telemetry-id: D31CB29B-EEE7-56FB-A1C5-7F04353D74C3
Expires: 0
Require: eventlist
Event: presence
subscription-state: terminated;expires=0
ms-piggyback-cseq: 1
Supported: ms-piggyback-first-notify
Message-Body:
--1550b37c575843dbb98e18be4e840f3dContent-Transfer-Encoding: binaryContent-ID: resourceListContent-Type: application/rlmi+xml--1550b37c575843dbb98e18be4e840f3d--


Solution, refresh directory schema in AADconnect.

Monday, May 28, 2018

How to check user attributes in Azure AD

Open https://graphexplorer.azurewebsites.net/#

login with a user who has access to Azure AD

then type url:

https://graph.windows.net/myorganization/users/tskype1@domain.com



Friday, January 26, 2018

Integration with Exchange Online breaks Skype for Business federation

Hello,

if you follow this article to setup your  integration with Exchange online (for voicemail)
https://blogs.technet.microsoft.com/nexthop/2016/03/29/integrate-on-premise-lync-or-skype-for-business-with-office-365-unified-messaging-um/comment-page-3/#comments


you may kill your sfb federation. If this is a case, please note a following specificity of SFB:

when you set up Edge, you will be confronted with a choice, where to set your DNS. You can set it to external DNS, such as 8.8.8.8  or your internal DNS.

If you select external, you might need to define some hosts file entry like for FrontEnd pool, etc. Not ideal, right?

then you select internal DNS. However once you run

New-CsHostingProvider -Identity UMonline-Enabled $True -EnabledSharedAddressSpace $True -HostsOCSUsers $False -ProxyFQDN "exap.um.outlook.com" -IsLocal $False -VerificationLevel UseSourceVerification


you cut all federation. This is due to the fact that after this powershell , the edge will try to look for it's own SRV _sipfederationtls._tcp   and because it is usually not defined internally, it will fail.

Solution is to check what is defined externally and in internal split DNS zone create exactly the same (SRV pointing to A record of to external public IP of edge access (SIP) interface. 

Tuesday, October 3, 2017

Polycom VVX debug

I had a case when VVX did not work for hybrid Exchange with Lync onPremises, I spent a lot of time to understand why it is not working until I enabled logging for CURL as DEBIG :)

As always the problem was in SSL Certificates.

Saturday, September 23, 2017

Polycom VVX for hybrid Exchange

Polycom FW version 5.5.3 and Exchange hybrid.

From the logs we see that Polycom tries to perform autodiscover, but finally fails and leave EWS not deployed for online users.  I will continue debuging that, but I found a workaround:

login with sip and UPN  as username@domain.com but leaving domain field empty.
Then in settings-applications-exchange server URL you can hardcode:

https://outlook.office365.com/EWS/Exchange.asmx/WSSecurity

and leave autodiscover disabled.

Update: with CURL DEBUG we can see that problem was in SSL certificates of Digicert not being trusted due to limits we left from other tests in Network - TLS - Application profile 6 (select certificates from platform or imported, but we had only one certificte selected). I also imported Digicert root, as for unknown reasons outlook is based on that while rest of MS is Baltimore.


Friday, September 15, 2017

ADFS trics for MFA

ADFS access control rules to disable MFA for Office 365 application if usrs are connecting from intranet, Lync clients and enforce MFA for member of AD group:

$rp = Get-AdfsRelyingPartyTrust –Name "Microsoft Office 365 Identity Platform"
$groupMfaClaimTriggerRule = 'NOT EXISTS([Type == "http://schemas.microsoft.com/2012/01/requestcontext/claims/x-ms-client-user-agent", Value =~ "(?i)skype"]) && NOT EXISTS([Type=="http://schemas.microsoft.com/2012/01/requestcontext/claims/x-ms-client-user-agent", Value =~ "(?i)ACOMO"]) && NOT EXISTS([Type=="http://schemas.microsoft.com/2012/01/requestcontext/claims/x-ms-client-user-agent", Value =~ "(?i)lync"]) => add(type = "http://schemas.company.com/not_lync", value = "true" );
c1:[Type == "http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid", Value == "S-1-5-21-796845957-688789844-854245398-6148"]  && c2:[Type =="http://schemas.company.com/not_lync", Value== "true"] && c3:[Type =="http://schemas.microsoft.com/ws/2012/01/insidecorporatenetwork", Value== "false"]=> issue(Type = "http://schemas.microsoft.com/ws/2008/06/identity/claims/authenticationmethod", Value = "http://schemas.microsoft.com/claims/multipleauthn");'

Set-AdfsRelyingPartyTrust –TargetRelyingParty $rp –AdditionalAuthenticationRules $groupMfaClaimTriggerRule


We use this rule to let Lync on Premises users to use Exchange online