{"id":1903,"date":"2018-11-27T01:00:00","date_gmt":"2018-11-27T01:00:00","guid":{"rendered":"http:\/\/inswwdev.azurewebsites.net\/au\/insights\/uncategorized\/application-impersonation-o365-and-email-archive-migrations\/"},"modified":"2024-09-11T07:53:24","modified_gmt":"2024-09-11T07:53:24","slug":"application-impersonation-o365-and-email-archive-migrations","status":"publish","type":"post","link":"https:\/\/www.insentragroup.com\/nz\/insights\/geek-speak\/migrations\/application-impersonation-o365-and-email-archive-migrations\/","title":{"rendered":"Application Impersonation \u2013 O365 and Email Archive Migrations"},"content":{"rendered":"<p style=\"text-align: justify;\">For email archive migrations one of the pre-requisites are accounts with the application impersonation role.&nbsp; Application Impersonation is a management role within Office365 (O365) enabling applications to impersonate users so actions can be performed on their behalf using EWS.<\/p>\n<p style=\"text-align: justify;\">Within O365 there are two ways to set this up: via the O365 GUI or via PowerShell.<\/p>\n<p style=\"text-align: justify;\"><strong>Migration account(s)<\/strong><\/p>\n<p style=\"text-align: justify;\">Create the migration account(s) via your normal process and set the password not to expire. Although this is not actually required to assign the role, setting the password to expire it will mean that once the account details are added into the migration tool you will not be needing to update them every 30,60,90 days depending on your policy. Having to update the credentials repeatedly could cause delays in the migration project.<\/p>\n<p style=\"text-align: justify;\"><strong>Assigning role via the GUI<\/strong><\/p>\n<p style=\"text-align: justify;\">In the Exchange admin center, under permissions, admin roles.<\/p>\n<p style=\"text-align: justify;\"><img decoding=\"async\" style=\"width: 660px; height: 380px;\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/18\/2021\/02\/nov27_1.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/7effae17261942a18a8a903ca156bf59\"><\/p>\n<p style=\"text-align: justify;\">Click the + to add a new role group, give it a name and description then add the ApplicationImpersonation role to it. Finally add the members which will be the accounts (that you created earlier) you want to assign this role to and click save.<\/p>\n<p style=\"text-align: justify;\"><img decoding=\"async\" style=\"width: 547px; height: 1068px;\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/18\/2021\/02\/nov2718blog_2.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/b0101e8bae1449299f588e5323cca1df\"><\/p>\n<p style=\"text-align: justify;\">When you now look under the admin roles you will see the new admin role and on the right-hand side, you can see the role assigned.<\/p>\n<p style=\"text-align: justify;\"><img decoding=\"async\" style=\"width: 669px; height: 269px;\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/18\/2021\/02\/nov2718blog_3.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/69576830f4264c5f9d74ae0182ab7617\"><\/p>\n<p style=\"text-align: justify;\"><strong>Assigning role via PowerShell<\/strong><\/p>\n<p style=\"text-align: justify;\">Connect to your O365 PowerShell (<a href=\"https:\/\/docs.microsoft.com\/en-us\/powershell\/exchange\/exchange-online\/connect-to-exchange-online-powershell\/connect-to-exchange-online-powershell?view=exchange-ps#connect-to-exchange-online-powershell-1\" rel=\"nofollow noopener\" target=\"_blank\">https:\/\/docs.microsoft.com\/en-us\/powershell\/exchange\/exchange-online\/connect-to-exchange-online-powershell\/connect-to-exchange-online-powershell?view=exchange-ps#connect-to-exchange-online-powershell-1<\/a>)<\/p>\n<p style=\"text-align: justify;\">Creating the role group and assigning the role is done with a single script, replacing the &lt;..&gt; values as shown:<\/p>\n<p style=\"text-align: justify;\"><strong>Syntax<\/strong><\/p>\n<p style=\"text-align: justify;\">New-RoleGroup -Name &lt;admin role name&gt; -Roles ApplicationImpersonation -Members &lt;UPN for migration accounts&gt;<\/p>\n<p style=\"text-align: justify;\"><strong>Example<\/strong><\/p>\n<p style=\"text-align: justify;\">New-RoleGroup -Name \u201cApplication Impersonation PS Group\u201d -Roles ApplicationImpersonation -Members Migration.Account.PS@nickslab.onmicrosoft.com<\/p>\n<p style=\"text-align: justify;\"><strong>Output<\/strong><\/p>\n<p style=\"text-align: justify;\"><strong><img decoding=\"async\" style=\"width: 669px; height: 119px;\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/18\/2021\/02\/nov2718blog_4.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/2dc1dadd2ea943469d9220fa363756db\"><\/strong><\/p>\n<p style=\"text-align: justify;\">You can check the Role Group with this script:<\/p>\n<p style=\"text-align: justify;\"><strong>Syntax<\/strong><\/p>\n<p style=\"text-align: justify;\">Get-RoleGroup &lt;Role group name&gt;<\/p>\n<p style=\"text-align: justify;\"><strong>Example<\/strong><\/p>\n<p style=\"text-align: justify;\">Get-RoleGroup \u201cApplication Impersonation PS Group\u201d<\/p>\n<p style=\"text-align: justify;\"><strong>Output<\/strong><\/p>\n<p style=\"text-align: justify;\">In the output, you can see the role assigned the members of the role group<\/p>\n<p style=\"text-align: justify;\"><img decoding=\"async\" style=\"width: 761px; height: 166px;\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/18\/2021\/02\/nov2718blog_5.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/8b63494dcca14451a1b0a48fecc4075b\"><\/p>\n<p style=\"text-align: justify;\"><strong>Confirm that the application impersonation role is working<\/strong><\/p>\n<p style=\"text-align: justify;\">Browse to<span>&nbsp;<\/span><strong><a rel=\"noopener nofollow\" href=\"https:\/\/testconnectivity.microsoft.com\/\" target=\"_blank\">https:\/\/testconnectivity.microsoft.com\/<\/a><\/strong><\/p>\n<ul>\n<li>Click on \u200bthe Office 365 tab.<\/li>\n<li>Select Service Account Access and click on Next<\/li>\n<li>Specify the target mailbox email address<\/li>\n<li>Specify the migration account user name<\/li>\n<li>Specify the migration account password<\/li>\n<li>Checkmark Specify Exchange Web Services URL and specify the URL https:\/\/outlook.office365.com\/EWS\/Exchange.asmx<\/li>\n<li>Check the box Use Exchange Impersonation.<\/li>\n<li>Check Ignore Trust for SSL.\u200b<\/li>\n<li>Click on Perform Test.<\/li>\n<\/ul>\n<p style=\"text-align: justify;\">Once results are displayed, check the overall results; also click on Expand All.<\/p>\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/www.insentragroup.com\/nz\/email-archive-migration\/?utm_source=insentra&amp;utm_medium=email&amp;utm_campaign=email-migration-best-practice-guide&amp;utm_term=email-signature-nz\" target=\"_blank\" rel=\"noopener\"><img fetchpriority=\"high\" decoding=\"async\" width=\"600\" height=\"180\" src=\"https:\/\/www.insentragroup.com\/nz\/wp-content\/uploads\/sites\/18\/2022\/08\/email_archive_migration_banner_2022.png\" alt=\"\" class=\"wp-image-11021\" srcset=\"https:\/\/www.insentragroup.com\/nz\/wp-content\/uploads\/sites\/18\/2022\/08\/email_archive_migration_banner_2022.png 600w, https:\/\/www.insentragroup.com\/nz\/wp-content\/uploads\/sites\/18\/2022\/08\/email_archive_migration_banner_2022-300x90.png 300w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><\/a><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>For email archive migrations one of the pre-requisites are accounts with the application impersonation role.&nbsp; Application Impersonation is a management role within Office365 (O365) enabling applications to impersonate users so actions can be performed on their behalf using EWS. Within O365 there are two ways to set this up: via the O365 GUI or via&hellip; <a class=\"more-link\" href=\"https:\/\/www.insentragroup.com\/nz\/insights\/geek-speak\/migrations\/application-impersonation-o365-and-email-archive-migrations\/\">Continue reading <span class=\"screen-reader-text\">Application Impersonation \u2013 O365 and Email Archive Migrations<\/span><\/a><\/p>\n","protected":false},"author":98,"featured_media":1904,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"content-type":"","footnotes":""},"categories":[22],"tags":[],"class_list":["post-1903","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-migrations","entry"],"_links":{"self":[{"href":"https:\/\/www.insentragroup.com\/nz\/wp-json\/wp\/v2\/posts\/1903","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.insentragroup.com\/nz\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.insentragroup.com\/nz\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/nz\/wp-json\/wp\/v2\/users\/98"}],"replies":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/nz\/wp-json\/wp\/v2\/comments?post=1903"}],"version-history":[{"count":1,"href":"https:\/\/www.insentragroup.com\/nz\/wp-json\/wp\/v2\/posts\/1903\/revisions"}],"predecessor-version":[{"id":11022,"href":"https:\/\/www.insentragroup.com\/nz\/wp-json\/wp\/v2\/posts\/1903\/revisions\/11022"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/nz\/wp-json\/wp\/v2\/media\/1904"}],"wp:attachment":[{"href":"https:\/\/www.insentragroup.com\/nz\/wp-json\/wp\/v2\/media?parent=1903"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.insentragroup.com\/nz\/wp-json\/wp\/v2\/categories?post=1903"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.insentragroup.com\/nz\/wp-json\/wp\/v2\/tags?post=1903"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}