Issue:
How do I upgrade to WithSecure Email and Server Security 15.10?
Resolution:
This upgrade is a little different from the other versions, as in the latest cumulative updates for Exchange - Microsoft has dropped a possibility to access Exchange Web Services under the SYSTEM account.
In order to support this change, we introduced a new service - "F-Secure ODS Manager for Microsoft Exchange".
Before starting the upgrade, please make sure that you have a dedicated user for mailbox scanning. It is recommended to create a dedicated domain user just for this purpose, for example domain\ods. User has to be the member of following active directory groups:
- Domain users
- Organization Management
- Public Folder Management
The user have to be a member of MS Exchange due to MS requirements for using backend API and have a mailbox which is used for public folders discovery.
On the server where exchange is installed the user have to have following permissions:
- Be a member of the local administrators group.
- Have the 'Logon as service' privilege.
- Has "Public Folder Management" administrator role.
In order to set 'Logon as service' privilege:
- On the exchange server execute the "secpol.msc"
- Go to Local policies->User Rights Assignments
- Select "Log on as service" and add the user into the list.
In order to check if user has "Public Folder Management" role:
- Go to Exchange Admin Center
- Permissions->Admin roles->Public Folder Management
- Check that the user is added here.
After you have done the steps above, you can start the upgrade:
- You can choose Policy based upgrade using the WithSecure Policy Manager Server Console, where you select "policy based upgrade" from Policy Manager console, i.e. you select the Exchange Server and perform the upgrade option, no push, otherwise all settings will be lost and the product will break.
- Then run the configuration tool F-Secure.Ess.Config.exe as administrator, locally from Exchange Server and set the product up. Note: The user you set at the beginning, will be added to step 8/8.
Important: Even if you deploy MSI and run it locally on Exchange Server, for this upgrade you still need to run the F-Secure.Ess.Config.exe additionally which is located in C:\Program Files (x86)\F-Secure\Email and Server Security\ui. Unless you perform a clean-install.
Article no: 000034478