How do I upgrade to F-Secure Email and Server Security 15.10
This upgrade is a little different from the other versions, as in the latest cumulative updates for Exchange - Microsoft has dropped a possibility to access Exchange Web Services under the SYSTEM account.
In order to support this change, we introduced a new service - "F-Secure ODS Manager for Microsoft Exchange".
Before starting the upgrade, please make sure that you have an existing service user that is commonly used in your organization, for example domain\administrator. We do not recommend to use a general domain user, for example Domain\JohnDoe, since that user can leave the company and in that case the account usually will be disabled.
You can create a new service user, if its easier for you, for example: (domain\ods) with the password that is known to admins.
User should meet these conditions:
- If you create new user, make sure the user is member of: Domain users, Organization Management, Public Folder Management and own email address.
- If you use an existing user than make sure that permissions are set as instructed.
How to set 'Logon as service' privilege?
- Member of MS Exchange due to MS requirements for using backend API
- Have a mailbox which is used for public folders discovery
- Have 'Logon as service' privilege due to our ODS component design
- Have administrative privileges due to access to quarantine API, cosmos API, alerts API (our internal product related)
- User should be member of local administrators group
Check that this user has been added to the public folders.
- From Exchange Server go to secpol.msc, Local policies, User Rights Assignments, and select from there set "Log on as service" and make sure the user is added/enabled there.
Note: The user is added to organization management and public folder management directly from AD and the rule should be applied automatically but still check).
- Go to Exchange Admin Center, Permissions, Admin roles, Public Folder Management.
After you have done the steps above, you can start the upgrade:
Important: Even if you deploy MSI and run it locally on Exchange Server, for this upgrade you still need to run the F-Secure.Ess.Config.exe additionally which is located in C:\Program Files (x86)\F-Secure\Email and Server Security\ui. Unless you perform clean-install.
- You can chose Policy based upgrade using the F-Secure Policy Manager Server Console, where you select "policy based upgrade" from Policy Manager console, i.e. you select the Exchange Server and perform the upgrade option, no push, otherwise all settings will be lost and the product will brake.
- Then run the configuration tool F-Secure.Ess.Config.exe as administrator, locally from Exchange Server and set the product up. Note: The user you set at the beginning, will be added to step 8/8
Article no: 000034478