在 Microsoft Intune Azure 中設定 Intune 內部部署 Exchange 連接器Set up the Intune on-premises Exchange connector in Microsoft Intune Azure

在內部部署 Exchange Server 環境中,Intune 條件式存取可以用來允許或封鎖存取 Exchange 內部部署信箱。In an on-premises Exchange Server environment, Intune conditional access can be used to allow or block access to Exchange on-premises mailboxes. 請使用 Exchange Active Sync 內部部署連接器,將 Intune 連線到您的 Exchange 組織,並設定 Intune 條件式存取以及裝置合規性政策。Use Exchange Active Sync on-premises connectors to connect Intune to your Exchange organizations, and set up Intune conditional access along with device compliance policies. 然後,當裝置試圖連線到 Exchange 時,Intune 會判斷裝置是否已在 Intune 中註冊且符合規範。Then, when a device attempts to connect to Exchange, Intune determines if the device is enrolled in Intune and is compliant. 為了判斷哪些裝置已在 Intune 中註冊,內部部署 Exchange 連接器會將 Exchange Server 中的 Exchange Active Sync (EAS) 記錄對應到 Intune 記錄。To determine which devices are enrolled in Intune, the on-premises Exchange connector maps Exchange Active Sync (EAS) records in Exchange Server to Intune records. 如需其運作方式的詳細資訊,請參閱常見的 Intune 條件式存取使用方式為何?For more about how this works, see What are common ways to use conditional access with Intune?

重要

Intune 現在支援每個訂閱有多個內部部署 Exchange 連接器。Intune now supports multiple on-premises Exchange connectors per subscription. 如果您有多個內部部署 Exchange 組織,則可以為每個 Exchange 組織設定個別的連接器。If you have more than one on-premises Exchange organization, you can set up a separate connector for each Exchange organization.

若要設定可讓 Microsoft Intune 與內部部署 Exchange Server 通訊的連線,一般步驟如下:To set up a connection that enables Microsoft Intune to communicate with the on-premises Exchange Server, here are the general steps:

  1. 從 Azure 入口網站下載 Intune 內部部署 Exchange連接器。Download the Intune on-premises Exchange connector from the Azure portal.
  2. 在內部部署 Exchange 組織中的電腦上安裝和設定 Exchange 連接器。Install and configure the Exchange connector on a computer in the on-premises Exchange organization.
  3. 驗證 Exchange 連線。Validate the Exchange connection.
  4. 針對每個您想要連線至 Intune 的 Exchange 組織重複這些步驟。Repeat these steps for each Exchange organization you want to connect to Intune.

Intune 內部部署 Exchange 連接器需求Intune on-premises Exchange connector requirements

下表列出安裝內部部署 Exchange 連接器之電腦的需求。The following table lists the requirements for the computer on which you install the on-premises Exchange connector.

需求Requirement 詳細資訊More information
作業系統Operating systems 在執行任何版本的 Windows Server 2008 SP2 64 位元、Windows Server 2008 R2、Windows Server 2012、Windows Server 2012 R2 或 Windows Server 2016 的電腦上,Intune 皆支援內部部署 Exchange 連接器。Intune supports the on-premises Exchange connector on a computer that runs any edition of Windows Server 2008 SP2 64-bit, Windows Server 2008 R2, Windows Server 2012, Windows Server 2012 R2, or Windows Server 2016.

任何 Server Core 安裝都不支援此連接器。The connector is not supported on any Server Core installation.
Microsoft ExchangeMicrosoft Exchange 內部部署連接器需要 Microsoft Exchange 2010 SP1 或更新版本,或是舊版 Exchange Online Dedicated。On-premises connectors require Microsoft Exchange 2010 SP1 or later or legacy Exchange Online Dedicated. 若要判斷您的 Exchange Online Dedicated 環境為舊版設定,請連絡您的帳戶管理員。To determine if your Exchange Online Dedicated environment is in the new or legacy configuration, contact your account manager.
行動裝置管理授權單位Mobile device management authority 將行動裝置管理授權單位設定為 IntuneSet the mobile device management authority to Intune.
硬體Hardware 安裝連接器的電腦需要 1.6 GHz CPU、2 GB RAM 和 10 GB 可用磁碟空間。The computer on which you install the connector requires a 1.6 GHz CPU with 2 GB of RAM and 10 GB of free disk space.
Active Directory 同步處理Active Directory synchronization 您必須設定 Active Directory 同步處理,以便將本機使用者和安全性群組與您的 Azure Active Directory 執行個體同步處理,才能使用連接器將 Intune 連線到您的 Exchange Server。Before you can use the connector to connect Intune to your Exchange Server, you must set up Active Directory synchronization so that your local users and security groups are synchronized with your instance of Azure Active Directory.
其他軟體Additional software 託管連接器的電腦必須安裝 Microsoft .NET Framework 4.5 和 Windows PowerShell 2.0 的完整安裝。A full installation of Microsoft .NET Framework 4.5 and Windows PowerShell 2.0 must be installed on the computer that hosts the connector.
Network (網路)Network 安裝連接器的電腦所在的網域,必須與託管 Exchange Server 的網域有信任關係。The computer on which you install the connector must be in a domain that has a trust relationship to the domain that hosts your Exchange Server.

電腦需要設定,使其能夠在連接埠 80 和 443 上,透過防火牆和 Proxy 伺服器來存取 Intune 服務。The computer requires configurations to enable it to access the Intune service through firewalls and proxy servers over Ports 80 and 443. Intune 使用的網域包括 manage.microsoft.com、*manage.microsoft.com 和 *.manage.microsoft.com。Domains that are used by Intune include manage.microsoft.com, *manage.microsoft.com, and *.manage.microsoft.com.

Exchange Cmdlet 需求Exchange cmdlet requirements

您必須建立內部部署 Exchange 連接器所使用的 Active Directory 使用者帳戶。You must create an Active Directory user account that is used by the on-premises Exchange connector. 帳戶必須具有執行下列必要 Windows PowerShell Exchange Cmdlet 的權限:The account must have permission to run the following required Windows PowerShell Exchange cmdlets:

  • Get-ActiveSyncOrganizationSettings、Set-ActiveSyncOrganizationSettingsGet-ActiveSyncOrganizationSettings, Set-ActiveSyncOrganizationSettings
  • Get-CasMailbox、Set-CasMailboxGet-CasMailbox, Set-CasMailbox
  • Get-ActiveSyncMailboxPolicy、Set-ActiveSyncMailboxPolicy、New-ActiveSyncMailboxPolicy、Remove-ActiveSyncMailboxPolicyGet-ActiveSyncMailboxPolicy, Set-ActiveSyncMailboxPolicy, New-ActiveSyncMailboxPolicy, Remove-ActiveSyncMailboxPolicy
  • Get-ActiveSyncDeviceAccessRule、Set-ActiveSyncDeviceAccessRule、New-ActiveSyncDeviceAccessRule、Remove-ActiveSyncDeviceAccessRuleGet-ActiveSyncDeviceAccessRule, Set-ActiveSyncDeviceAccessRule, New-ActiveSyncDeviceAccessRule, Remove-ActiveSyncDeviceAccessRule
  • Get-ActiveSyncDeviceStatisticsGet-ActiveSyncDeviceStatistics
  • Get-ActiveSyncDeviceGet-ActiveSyncDevice
  • Get-ExchangeServerGet-ExchangeServer
  • Get-ActiveSyncDeviceClassGet-ActiveSyncDeviceClass
  • Get-RecipientGet-Recipient
  • Clear-ActiveSyncDevice、Remove-ActiveSyncDeviceClear-ActiveSyncDevice, Remove-ActiveSyncDevice
  • Set-ADServerSettingsSet-ADServerSettings
  • Get-CommandGet-Command

下載內部部署 Exchange 連接器軟體安裝套件Download the on-premises Exchange connector software installation package

  1. 在內部部署 Exchange 連接器支援的 Windows Server 作業系統上,開啟 Azure 入口網站,並使用在內部部署 Exchange Server 中為系統管理員且有權使用 Exchange Server 的使用者帳戶登入。On a supported Windows Server operating system for the on-premises Exchange connector, open the Azure portal and sign in with a user account that is an administrator in the on-premises Exchange server, and that has a license to use Exchange Server.

  2. 選擇左功能表中的 [All services] (所有服務),然後在文字方塊篩選中鍵入 IntuneChoose All services from the left menu, then type Intune in the text box filter.

  3. 選擇 [Intune],在在開啟 Intune 儀表板後,選擇 [內部部署存取]。Choose Intune, and when the Intune Dashboard opens, choose On-premises access.

  4. 在 [安裝] 下選擇 [Exchange ActiveSync 連接器],然後選擇 [下載內部部署連接器]。Under Setup, choose Exchange ActiveSync connectors, and then choose Download the on-premises connector.

  5. 內部部署 Exchange 連接器包含在可以開啟或儲存的壓縮 (.zip) 資料夾中。The on-premises Exchange connector is contained in a compressed (.zip) folder that can be opened or saved. 在 [檔案下載] 對話方塊中,選擇 [儲存],將壓縮資料夾儲存到安全的位置。In the File Download dialog box, choose Save to store the compressed folder to a secure location.

    重要

    請不要重新命名或移動內部部署 Exchange 連接器資料夾內的檔案。Do not rename or move the files that are in the on-premises Exchange connector folder. 移動或重新命名資料夾的內容會造成 Exchange 連接器安裝失敗。Moving or renaming the folder's contents will cause the Exchange connector installation to fail.

安裝和設定 Intune 內部部署 Exchange 連接器Install and configure the Intune on-premises Exchange connector

請執行下列步驟來安裝 Intune 內部部署 Exchange 連接器。Perform the following steps to install the Intune on-premises Exchange connector. 如果您有多個 Exchange 組織,請針對每個您想要設定的其他 Exchange 連接器重複這些步驟。If you have multiple Exchange organizations, repeat these steps for each additional Exchange connector you want to set up.

  1. 在內部部署 Exchange 連接器支援的作業系統上,將 Exchange_Connector_Setup.zip 中的檔案解壓縮到安全位置。On a supported operating system for the on-premises Exchange connector, extract the files in Exchange_Connector_Setup.zip to a secure location.

  2. 在檔案解壓縮之後,請開啟解壓縮的資料夾,然後按兩下 Exchange_Connector_Setup.exe 安裝內部部署 Exchange 連接器。After the files are extracted, open the extracted folder and double-click Exchange_Connector_Setup.exe to install the on-premises Exchange connector.

    重要

    如果目的地資料夾不是安全的位置,您應該在完成安裝內部部署連接器後刪除 MicrosoftIntune.accountcert 憑證檔案。If the destination folder is not a secure location, you should delete the certificate file MicrosoftIntune.accountcert when you are finished installing your on-premises connectors.

  3. 在 [Microsoft Intune Exchange Connector] 對話方塊中,選取 [內部部署 Microsoft Exchange Server] 或 [託管 Microsoft Exchange Server]。In the Microsoft Intune Exchange Connector dialog box, select either On-premises Microsoft Exchange Server or Hosted Microsoft Exchange Server.

    顯示可從何處選擇 Exchange 伺服器類型的影像

    如果是內部部署 Exchange Server,請提供主控 Client Access Server 角色之 Exchange Server 的伺服器名稱或完整網域名稱。For an on-premises Exchange server, provide either the server name or the fully-qualified domain name of the Exchange server that hosts the Client Access Server role.

    如果是託管 Exchange 伺服器,請提供 Exchange 伺服器位址。For a hosted Exchange server, provide the Exchange server address. 若要尋找託管 Exchange 伺服器 URL:To find the hosted Exchange server URL:

    1. 開啟 Office 365 的 Outlook 網頁版。Open Outlook on the web for Office 365.

    2. 選擇左上方的 Choose the ? 圖示,然後選取 [關於]。icon at the upper left, and then select About.

    3. 找到 [POP 外部伺服器] 值。Locate the POP External Server value.

    4. 選擇 [Proxy 伺服器],以便指定託管 Exchange 伺服器的 Proxy 伺服器設定。Choose Proxy Server to specify proxy server settings for your hosted Exchange server.

      1. 選取 [同步處理行動裝置資訊時使用 Proxy 伺服器] 。Select Use a proxy server when synchronizing mobile device information.

      2. 輸入用來存取伺服器的 [Proxy 伺服器名稱] 和 [連接埠號碼] 。Enter the proxy server name and the port number to be used to access the server.

      3. 如果需要提供使用者認證才能存取 Proxy 伺服器,請選取 [使用認證來連線至 Proxy 伺服器]。If it's necessary to provide user credentials to access the proxy server, select Use credentials to connect to the proxy server. 然後輸入 [網域\使用者] 和 [密碼]。Then enter the domain\user and the password.

      4. 選擇 [確定]。Choose OK.

    5. 在 [使用者 (網域\使用者)] 和 [密碼] 欄位中,輸入連線至 Exchange Server 所需的認證。In the User (Domain\user) and Password fields, enter the credentials that are necessary to connect to your Exchange server.

    6. 提供傳送通知給使用者 Exchange Server 信箱所需的認證。Provide the necessary credentials to send notifications to a user’s Exchange Server mailbox. 此使用者可專作收發通知之用。This user can be dedicated to just notifications. 通知使用者需要 Exchange 信箱,才能夠透過電子郵件傳送通知。The notifications user needs an Exchange mailbox to be able to send notifications by email. 您可以在 Intune 中使用條件式存取原則來設定這些通知。You can configure these notifications with conditional access policies in Intune.

      請確定自動探索服務和 Exchange Web 服務是在 Exchange Client Access Server 上設定。Ensure that the Autodiscover service and Exchange Web Services are configured on the Exchange Client Access Server. 如需詳細資訊,請參閱 Client Access ServerFor more information, see Client Access server.

    7. 在 [密碼] 欄位中提供此帳戶的密碼,以便 Intune 能夠存取 Exchange Server。In the Password field, provide the password for this account to enable Intune to access the Exchange Server.

    8. 選擇 [連線]。Choose Connect.

    注意

    設定連線可能需要幾分鐘的時間。It might take a few minutes for the connection to be configured.

在設定期間,Exchange 連接器會儲存 Proxy 設定,讓您可存取網際網路。During configuration, the Exchange connector stores your proxy settings to enable access to the Internet. 如果您的 Proxy 設定發生變更,您必須重新設定 Exchange 連接器,以便將更新的 Proxy 設定套用到 Exchange 連接器。If your proxy settings change, you will have to reconfigure the Exchange connector to apply the updated proxy settings to the Exchange connector.

在 Exchange 連接器設定連線之後,與 Exchange 中受控使用者建立關聯的行動裝置便會自動同步處理並新增到 Exchange 連接器。After the Exchange connector sets up the connection, mobile devices that are associated with users that are managed in Exchange are automatically synchronized and added to the Exchange connector. 這項同步處理可能需要一些時間才能完成。This synchronization might take some time to complete.

注意

如果您已安裝內部部署 Exchange 連接器,而且在某個階段刪除 Exchange 連線,您必須從已安裝內部部署 Exchange 連接器的電腦解除安裝該軟體。If you have installed the on-premises Exchange connector, and if at some point you delete the Exchange connection, you must uninstall the on-premises Exchange connector from the computer onto which it was installed.

為多個 Exchange 組織安裝連接器Install connectors for multiple Exchange organizations

Intune 支援每個訂閱有多個內部部署 Exchange 連接器。Intune supports multiple on-premises Exchange connectors per subscription. 對於具有多個 Exchange 組織的租用戶,您可以為每個 Exchange 組織設定一個連接器。For a tenant with multiple Exchange organizations, you can set up one connector for each Exchange organization. 下載 .zip 資料夾一次,然後針對每個 Exchange 組織遵循前一節中的步驟,擷取安裝程式並在組織中的伺服器上執行。Download the .zip folder once, and then for each Exchange organization, follow the steps in the previous section to extract and run the setup program on a server in the organization.

每個連線至 Intune 的 Exchange 組織都支援下列各節所述的高可用性、監視和手動同步處理。The high availability, monitoring, and manual sync features described in the following sections are supported for each Exchange organization connected to Intune.

內部部署 Exchange Connector 高可用性支援On-premises Exchange connector high availability support

在 Exchange Connector 使用指定的 CAS 建立與 Exchange 的連線之後,連接器便能夠探索其他 CAS。After the Exchange connector creates a connection to Exchange using the specified CAS, the connector has the ability to discovery other CASs. 如果無法使用主要的 CAS,連接器將容錯移轉至另一個 CAS (如果有的話),直到有可用的主要 CAS 為止。If the primary CAS becomes unavailable, the connector will failover to another CAS, if available, until the primary CAS becomes available. 這項功能預設為開啟。This feature is on by default. 您可以使用下列程序來關閉此功能:You can turn this feature off by using the following procedure:

  1. 在安裝 Exchange Connector 的伺服器上,移至 %ProgramData%\Microsoft\Windows Intune Exchange Connector。On the server where the Exchange Connector is installed, go to %ProgramData%\Microsoft\Windows Intune Exchange Connector.
  2. 使用文字編輯器,開啟 OnPremisesExchangeConnectorServiceConfiguration.xmlUsing a text editor, open OnPremisesExchangeConnectorServiceConfiguration.xml.
  3. 將 <IsCasFailoverEnabled>true</IsCasFailoverEnabled> 變更為 <IsCasFailoverEnabled>false</IsCasFailoverEnabled> 以停用該功能。Change <IsCasFailoverEnabled>true</IsCasFailoverEnabled> to <IsCasFailoverEnabled>false</IsCasFailoverEnabled> to disable the feature.

監視 Exchange Connector 活動Monitor the Exchange connector activity

成功設定 Exchange 連接器之後,即可檢視連線和上次成功同步處理嘗試的狀態。After you have successfully configured Exchange connectors, you can view the status of the connections and the last successful synchronization attempt. 驗證 Exchange 連接器連線:To validate the Exchange connector connections:

  1. 在 Intune 儀表板中,選擇 [內部部署存取]。On the Intune Dashboard, choose On-premises access.
  2. 在 [安裝] 下,選取 [Exchange ActiveSync 連接器] 來確認每個 Exchange 連接器的連線狀態。Under Setup, select Exchange ActiveSync connectors to verify the connection status for each Exchange connector.

您也可以查看上次嘗試同步作業成功的時間和日期。You can also check the time and date of the last successful synchronization attempt.

System Center Operations Manager (SCOM) 管理組件System Center Operations Manager (SCOM) management pack

從 Intune 1710 版開始,您可以使用適用於 Exchange connector 和 Intune 的 SCOM 管理組件Beginning with the Intune 1710 release, you can use the SCOM management pack for Exchange connector and Intune. 這可在您需要針對問題進行疑難排解時,為您提供不同方式來監視 Exchange Connector。This gives you different ways of monitoring the Exchange connector when you need to troubleshoot issues.

手動強制執行快速同步處理或完整同步處理Manually force a quick sync or full sync

內部部署 Exchange 連接器會定期自動同步處理 EAS 和 Intune 的裝置記錄。An on-premises Exchange connector automatically synchronizes EAS and Intune device records on a regular basis. 如果裝置的合規性狀態變更時,自動同步處理程序會定期更新記錄,讓裝置存取可以據以封鎖或允許。If the compliance status of a device changes, the automatic sync process regularly updates records so that device access can be blocked or allowed accordingly.

  • 快速同步處理會定期執行,一天進行數次。Quick sync occurs regularly, several times a day. 快速同步處理會針對上次同步處理後已變更之 Intune 授權的使用者和以內部部署 Exchange 條件式存取為目標的使用者,擷取裝置資訊。A quick sync retrieves device information for Intune-licensed and on-premises Exchange conditional access-targeted users that have changed since the last sync.

  • 完整同步處理預設每天將執行一次。Full sync occurs once per day by default. 完整同步處理會針對所有 Intune 授權的使用者和以內部部署 Exchange 條件式存取為目標的使用者,擷取裝置資訊。A full sync retrieves device information for all Intune-licensed and on-premises Exchange conditional access-targeted users. 完整同步處理還會擷取 Exchange Server 資訊,並確保 Intune 在 Azure 入口網站中指定的設定已在 Exchange Server 上更新。A full sync also retrieves Exchange server information and ensures that the configuration specified by Intune in the Azure portal is updated on the Exchange server.

您可以執行下列步驟,藉由在 Intune 儀表板中使用 [快速同步處理] 或 [完整同步處理] 選項,強制連接器執行同步處理:You can force a connector to run a sync by using the Quick Sync or Full Sync options on the Intune dashboard with the following steps:

  1. 在 Intune 儀表板中,選擇 [內部部署存取]。On the Intune dashboard, choose On-premises access.
  2. 在 [安裝] 下,選擇 [Exchange Active Sync 連接器]。Under Setup, choose Exchange Active Sync Connectors.
  3. 選取您想要同步處理的連接器,然後選擇 [快速同步處理] 或 [完整同步處理]。Select the connector you want to sync, and then choose Quick Sync or Full Sync.

接下來的步驟Next steps

建立 Exchange 內部部署的條件存取原則Create a conditional access policy for Exchange on-premises