我昨晚在将Exchange 2013 CU 8更新到CU 10时出错 – 在步骤14的18中设置失败邮箱angular色:邮箱服务 – 错误是“无法parsing用户或组”我们的域/ Microsoft Exchange安全组/发现pipe理“。我有以下完整的错误,我发现了两个可能的解决scheme,通过search和解决,并通过从AD删除DiscoverySearchMailbox用户帐户来解决和完成安装问题(其他可能的解决scheme是禁用发现search邮箱,但我不能这样做,因为安装已经中途完成安装完成后,我运行安装程序/ PrepareAD / IAcceptblablabla …和DiscoverySearchMailbox被重新创build,所有似乎都很好服务器,除了DiscoverySearchMailbox用户帐户现在实际上是被禁用的,我有一些关于这个的问题,希望有人能够阐明一些 –
提前感谢任何帮助 – 这里是收到的全部错误:
错误:“$ error.Clear(); $ name = [Microsoft.Exchange.Management.RecipientTasks.EnableMailbox] :: DiscoveryMailboxUniqueName; $ dispname = [Microsoft.Exchange.Management.RecipientTasks.EnableMailbox] ::如果($ dismbx -ne $ null){$ srvname = $ dismbx.ServerName; if($ dismbx.Database -ne $); $ dismbx = get-mailbox -Filter {name -eq $ name} -IgnoreDefaultScope -resultSize 1; null -and $ RoleFqdnOrName-like“$ srvname。*”){Write-ExchangeSetupLog -info“Setup DiscoverySearchMailbox Permission。”; $ mountedMdb = get-mailboxdatabase $ dismbx.Database -status |其中{$ _。Mounted -eq $ true };如果($ mountedMdb -eq $ null){写-ExchangeSetupLog -info“挂载数据库之前邮戳DiscoverySearchMailbox权限…”;挂载数据库$ dismbx.Database;}
$mountedMdb = get-mailboxdatabase $dismbx.Database -status | where { $_.Mounted -eq $true }; if( $mountedMdb -ne $null ) { $dmRoleGroupGuid = [Microsoft.Exchange.Data.Directory.Management.RoleGroup]::DiscoveryManagement_InitInfo.WellKnownGuid; $dmRoleGroup = Get-RoleGroup -Identity $dmRoleGroupGuid -DomainController $RoleDomainController -ErrorAction:SilentlyContinue; if( $dmRoleGroup -ne $null ) { trap [Exception] { Add-MailboxPermission $dismbx -User $dmRoleGroup.Name -AccessRights FullAccess -DomainController $RoleDomainController -ErrorAction SilentlyContinue; continue; } Add-MailboxPermission $dismbx -User $dmRoleGroup.Identity -AccessRights FullAccess -DomainController $RoleDomainController -WarningAction SilentlyContinue; } } } } " was run: "Microsoft.Exchange.Data.Common.LocalizedException: Couldn't resolve the user or group "ourdomain/Microsoft Exchange Security Groups/Discovery Management." If the user or group is a foreign forest principal, you must have either a two-way trust or an outgoing trust. ---> System.SystemException: The trust relationship between the primary domain and the trusted domain failed.
在System.Security.Principal.NTAccount.Translate上System.Security.Principal.NTAccount.Translate(IdentityReferenceCollection sourceAccounts,typestargetType,布尔forceSuccess)上System.Security.Principal.NTAccount.TranslateToSids(IdentityReferenceCollection sourceAccounts,布尔&someFailed) )在Microsoft.Exchange.Configuration.Tasks.SecurityPrincipalIdParameter.GetUserSidAsSAMAccount(SecurityPrincipalIdParameter用户,TaskErrorLoggingDelegate logError,TaskVerboseLoggingDelegate logVerbose)—结束内部exception堆栈跟踪—在Microsoft.Exchange.Configuration.Tasks.Task.ThrowError(exceptionexception,ErrorCategory errorCategory,Object target,String helpUrl)在Microsoft.Exchange.Configuration.Tasks.Task.WriteError(Exception exception,ErrorCategory category,Object target)at Microsoft.Exchange.Configuration.Tasks.SecurityPrincipalIdParameter.GetUserSidAsSAMAccount(SecurityPrincipalIdParameter user,TaskErrorLoggingDelegate logError ,TaskVerboseLogg Microsoft.Exchange.Configuration.Tasks.SecurityPrincipalIdParameter.GetSecurityPrincipal(IRecipientSession会话,SecurityPrincipalIdParameter用户,TaskErrorLoggingDelegate logError,TaskVerboseLoggingDelegate logVerbose)在Microsoft.Exchange.Management.RecipientTasks.SetMailboxPermissionTaskBase.InternalValidate()Microsoft.Exchange.Management.RecipientTasks Microsoft.Exchange.Configuration.Tasks.Task.b__b()在Microsoft.Exchange.Configuration.Tasks.Task.InvokeRetryableFunc(stringfuncName,操作func,布尔terminatePipelineIfFailed)“.AddMailboxPermission.InternalValidate()。
谢谢,
乔治
更新:现在我已经确定由于与安装CU期间不可用的另一个林的信任关系而发生此错误。 我已经重新创build了这个问题,并且每次不再使用的旧信任仍列在“域和信任”对话框中的信任下时,就会发生错误。 简单地删除不再需要,不再使用信任允许安装完成,无需删除(或做任何事情)发现search邮箱。 只是想更新,以便这可能会帮助其他人面临同样的问题。