在 Microsoft Intune Azure 中設定 Intune 內部部署 Exchange ConnectorSet up the Intune on-premises Exchange Connector in Microsoft Intune Azure

內部部署 Exchange Server 環境可以使用 Intune 內部部署 Exchange Connector,來管理裝置對內部部署 Exchange 信箱的存取 (依據裝置是否已經在 Intune 中註冊,以及是否符合 Intune 裝置合規性原則)。On-premises Exchange Server environments can use the Intune on-premises Exchange connector to manage devices access to on-premises Exchange mailboxes based on whether or not the devices are enrolled into Intune and compliant with Intune device compliance policies. 內部部署 Exchange Connector 也會負責找出連線至內部部署 Exchange Server 的行動裝置,方法是透過與 Intune 同步處理現有的 Exchange Active Sync (EAS) 記錄。The on-premises Exchange connector is also responsible for discovering mobile devices that connect to on-premises Exchange Servers by synchronizing the existing Exchange Active Sync (EAS) record with Intune.

重要

Intune 僅支援每個訂用帳戶一個任一類型的內部部署 Exchange Connector 連線。Intune only supports one on-premises Exchange Connector connection of any type per subscription.

若要設定可讓 Microsoft Intune 與內部部署 Exchange Server 通訊的連線,您必須依照下面的步驟執行作業:To set up a connection that enables Microsoft Intune to communicate with the on-premises Exchange Server, you need to follow the steps below:

  1. 從 Azure 入口網站下載 Intune 內部部署 Exchange Connector。Download the Intune on-premises Exchange Connector from the Azure portal.
  2. 安裝和設定 Intune 內部部署 Exchange Connector。Install and configure the Intune on-premises Exchange connector.
  3. 驗證 Exchange 連線。Validate the Exchange connection.

On-Premises Exchange Connector 需求On-premises Exchange Connector requirements

下表列出安裝 On-Premises Exchange Connector 之電腦的需求。The following table lists the requirements for the computer on which you install the On-premises Exchange Connector.

需求Requirement 詳細資訊More information
作業系統Operating systems 在執行任何版本的 Windows Server 2008 SP2 64 位元、Windows Server 2008 R2、Windows Server 2012 或 Windows Server 2012 R2 的電腦上,Intune 支援 On-Premises Exchange Connector。Intune supports the On-premises Exchange Connector on a computer that runs any edition of Windows Server 2008 SP2 64-bit, Windows Server 2008 R2, Windows Server 2012, or Windows Server 2012 R2.

任何 Server Core 安裝都不支援此 Connector。The Connector is not supported on any Server Core installation.
Microsoft ExchangeMicrosoft Exchange On-Premises Connector 需要 Microsoft Exchange 2010 SP1 或更新版本,或是舊版 Exchange Online Dedicated。On-premises Connectors require Microsoft Exchange 2010 SP1 or later or legacy Exchange Online Dedicated. 若要判斷您的 Exchange Online Dedicated 環境為舊版設定,請連絡您的帳戶管理員。To determine if your Exchange Online Dedicated environment is in the new or legacy configuration, contact your account manager.
行動裝置管理授權單位Mobile device management authority 將行動裝置管理授權單位設定為 IntuneSet the mobile device management authority to Intune.
硬體Hardware 安裝連接器的電腦需要 1.6 GHz CPU、2 GB RAM 和 10 GB 可用磁碟空間。The computer on which you install the connector requires a 1.6 GHz CPU with 2 GB of RAM and 10 GB of free disk space.
Active Directory 同步處理Active Directory synchronization 您必須設定 Active Directory 同步處理,以便將本機使用者和安全性群組與您的 Azure Active Directory 執行個體同步處理,才能使用 Connector 將 Intune 連線到您的 Exchange Server。Before you can use Connector to connect Intune to your Exchange Server, you must set up Active Directory synchronization so that your local users and security groups are synchronized with your instance of Azure Active Directory.
其他軟體Additional software 託管連接器的電腦必須安裝 Microsoft .NET Framework 4.5 和 Windows PowerShell 2.0 的完整安裝。A full installation of Microsoft .NET Framework 4.5 and Windows PowerShell 2.0 must be installed on the computer that hosts the connector.
Network (網路)Network 安裝連接器的電腦所在的網域,必須與託管 Exchange Server 的網域有信任關係。The computer on which you install the connector must be in a domain that has a trust relationship to the domain that hosts your Exchange Server.

電腦需要設定,使其能夠在連接埠 80 和 443 上,透過防火牆和 Proxy 伺服器來存取 Intune 服務。The computer requires configurations to enable it to access the Intune service through firewalls and proxy servers over Ports 80 and 443. Intune 使用的網域包括 manage.microsoft.com、*manage.microsoft.com 和 *.manage.microsoft.com。Domains that are used by Intune include manage.microsoft.com, *manage.microsoft.com, and *.manage.microsoft.com.

Exchange Cmdlet 需求Exchange cmdlet requirements

您必須建立 Intune Exchange Connector 所使用的 Active Directory 使用者帳戶。You must create an Active Directory user account that is used by the Intune Exchange Connector. 帳戶必須具有執行下列必要 Windows PowerShell Exchange Cmdlet 的權限:The account must have permission to run the following required Windows PowerShell Exchange cmdlets:

  • Get-ActiveSyncOrganizationSettings、Set-ActiveSyncOrganizationSettingsGet-ActiveSyncOrganizationSettings, Set-ActiveSyncOrganizationSettings
  • Get-CasMailbox、Set-CasMailboxGet-CasMailbox, Set-CasMailbox
  • Get-ActiveSyncMailboxPolicy、Set-ActiveSyncMailboxPolicy、New-ActiveSyncMailboxPolicy、Remove-ActiveSyncMailboxPolicyGet-ActiveSyncMailboxPolicy, Set-ActiveSyncMailboxPolicy, New-ActiveSyncMailboxPolicy, Remove-ActiveSyncMailboxPolicy
  • Get-ActiveSyncDeviceAccessRule、Set-ActiveSyncDeviceAccessRule、New-ActiveSyncDeviceAccessRule、Remove-ActiveSyncDeviceAccessRuleGet-ActiveSyncDeviceAccessRule, Set-ActiveSyncDeviceAccessRule, New-ActiveSyncDeviceAccessRule, Remove-ActiveSyncDeviceAccessRule
  • Get-ActiveSyncDeviceStatisticsGet-ActiveSyncDeviceStatistics
  • Get-ActiveSyncDeviceGet-ActiveSyncDevice
  • Get-ExchangeServerGet-ExchangeServer
  • Get-ActiveSyncDeviceClassGet-ActiveSyncDeviceClass
  • Get-RecipientGet-Recipient
  • Clear-ActiveSyncDevice、Remove-ActiveSyncDeviceClear-ActiveSyncDevice, Remove-ActiveSyncDevice
  • Set-ADServerSettingsSet-ADServerSettings
  • Get-CommandGet-Command

下載 On-Premises Exchange Connector 軟體安裝套件Download the On-premises Exchange Connector software installation package

  1. 在內部部署 Exchange Connector 之受支援的 Windows Server 作業系統上,開啟 Azure 入口網站,並使用在內部部署 Exchange Server 中為系統管理員,且有權使用 Exchange Server 的使用者帳戶登入。On a supported Windows Server operating system for the On-premises Exchange Connector, open the Azure portal and sign in with a user account that is an administrator in the on-premises Exchange server, and that has a license to use Exchange Server.

  2. 選擇左功能表中的 [更多服務],然後在文字方塊篩選中輸入 IntuneChoose More services from the left menu, then type Intune in the text box filter.

  3. 選擇 [Intune],隨即開啟 Intune 儀表板,然後選擇 [內部部署存取]。Choose Intune, the Intune Dashboard opens, choose On-premises access.

  4. 在 [內部部署存取 - Exchange ActiveSync 連接器] 刀鋒視窗中,從 [安裝] 區段選擇 [下載內部部署連接器]。On the On-premises access - Exchange ActiveSync connector blade, from the Setup section, choose Download the on-premises connector.

  5. On-Premises Exchange Connector 包含在可以開啟或儲存的壓縮 (.zip) 資料夾中。The On-premises Exchange Connector is contained in a compressed (.zip) folder that can be opened or saved. 在 [檔案下載] 對話方塊中,選擇 [儲存],將壓縮資料夾儲存到安全的位置。In the File Download dialog box, choose Save to store the compressed folder to a secure location.

    重要

    請不要重新命名或移動 On-Premises Exchange Connector 資料夾內的檔案。Do not rename or move the files that are in the on-premises Exchange Connector folder. 移動或重新命名資料夾的內容會造成 Exchange Connector 安裝失敗。Moving or renaming the folder's contents will cause the Exchange Connector installation to fail.

安裝和設定 Intune On-Premises Exchange ConnectorInstall and configure the Intune On-premises Exchange Connector

請執行下列步驟來安裝 Intune On-Premises Exchange Connector。Perform the following steps to install the Intune On-premises Exchange Connector. 每個 Intune 訂閱只可安裝 On-Premises Exchange Connector 一次,而且只可安裝在一部電腦上。The On-premises Exchange Connector can only be installed once per Intune subscription, and only on one computer. 如果您嘗試設定另一個 On-Premises Exchange Connector,則新連線會取代原始連線。If you try to configure an additional On-premises Exchange Connector, the new connection will replace the original one.

  1. 在 On-Premises Connector 支援的作業系統上,將 Exchange_Connector_Setup.zip 中的檔案解壓縮到安全位置。On a supported operating system for the On-premises Connector, extract the files in Exchange_Connector_Setup.zip to a secure location.

  2. 在檔案解壓縮之後,請開啟解壓縮的資料夾,然後按兩下 Exchange_Connector_Setup.exe 安裝 On-Premises Exchange Connector。After the files are extracted, open the extracted folder and double-click Exchange_Connector_Setup.exe to install the On-premises Exchange Connector.

    重要

    如果目的地資料夾不是安全的位置,您應該在安裝 On-Premises Connector 之後刪除 WindowsIntune.accountcert 憑證檔案。If the destination folder is not a secure location, you should delete the certificate file WindowsIntune.accountcert after you install the On-premises Connector.

  3. 在 [Microsoft Intune Exchange Connector] 對話方塊中,選取 [內部部署 Microsoft Exchange Server] 或 [託管 Microsoft Exchange Server]。In the Microsoft Intune Exchange Connector dialog box, select either On-premises Microsoft Exchange Server or Hosted Microsoft Exchange Server.

    選擇 Exchange Server 類型

    如果是內部部署 Exchange Server,請提供主控 Client Access Server 角色之 Exchange Server 的伺服器名稱或完整網域名稱。For an On-premises Exchange server, provide either the server name or the fully-qualified domain name of the Exchange server that hosts the Client Access Server role.

    如果是託管 Exchange 伺服器,請提供 Exchange 伺服器位址。For a hosted Exchange server, provide the Exchange server address. 若要尋找託管 Exchange 伺服器 URL:To find the hosted Exchange server URL:

    1. 開啟適用於 Office 365 的 Outlook Web App。Open the Outlook Web App for Office 365.

    2. 選擇左上方的 Choose the ? 圖示,然後選取 [關於]。icon at the upper left, and then select About.

    3. 找到 [POP 外部伺服器] 值。Locate the POP External Server value.

    4. 選擇 [Proxy 伺服器],以便指定託管 Exchange 伺服器的 Proxy 伺服器設定。Choose Proxy Server to specify proxy server settings for your hosted Exchange server.

      1. 選取 [同步處理行動裝置資訊時使用 Proxy 伺服器] 。Select Use a proxy server when synchronizing mobile device information.

      2. 輸入用來存取伺服器的 [Proxy 伺服器名稱] 和 [連接埠號碼] 。Enter the proxy server name and the port number to be used to access the server.

      3. 如果需要提供使用者認證才能存取 Proxy 伺服器,請選取 [使用認證來連線至 Proxy 伺服器]。If it's necessary to provide user credentials to access the proxy server, select Use credentials to connect to the proxy server. 然後輸入 [網域\使用者] 和 [密碼]。Then enter the domain\user and the password.

      4. 選擇 [確定]。Choose OK.

    5. 在 [使用者 (網域\使用者)] 和 [密碼] 欄位中,輸入連線至 Exchange Server 所需的認證。In the User (Domain\user) and Password fields, enter the credentials that are necessary to connect to your Exchange server.

    6. 提供傳送通知給使用者 Exchange Server 信箱所需的系統管理認證。Provide the necessary administrative credentials to send notifications to a user’s Exchange Server mailbox. 您可以在 Intune 中使用條件式存取原則來設定這些通知。You can configure these notifications with Conditional Access policies in Intune.

      請確定自動探索服務和 Exchange Web 服務是在 Exchange Client Access Server 上設定。Ensure that the Autodiscover service and Exchange Web Services are configured on the Exchange Client Access Server. 如需詳細資訊,請參閱 Client Access ServerFor more information, see Client Access server.

    7. 在 [密碼] 欄位中提供此帳戶的密碼,以便 Intune 能夠存取 Exchange Server。In the Password field, provide the password for this account to enable Intune to access the Exchange Server.

    8. 選擇 [連線]。Choose Connect.

    注意

    設定連線可能需要幾分鐘的時間。It might take a few minutes for the connection to be configured.

在設定期間,Exchange Connector 會儲存 Proxy 設定,讓您可存取網際網路。During configuration, the Exchange Connector stores your proxy settings to enable access to the Internet. 如果您的 Proxy 設定發生變更,您必須重新設定 Exchange Connector,以便將更新的 Proxy 設定套用到 Exchange Connector。If your proxy settings change, you will have to reconfigure the Exchange Connector to apply the updated proxy settings to the Exchange Connector.

在 Exchange Connector 設定連線之後,與 Exchange Connector 中受管理使用者相關聯的行動裝置便會自動同步處理並新增到 Exchange Connector。After the Exchange Connector sets up the connection, mobile devices that are associated with users that are managed in Exchange Connector are automatically synchronized and added to the Exchange Connector. 這項同步處理可能需要一些時間才能完成。This synchronization might take some time to complete.

注意

如果您已安裝 On-Premises Exchange Connector,而且在某個階段刪除 Exchange 連線,您必須從已安裝 On-Premises Exchange Connector 的電腦解除安裝該軟體。If you have installed the On-premises Exchange Connector, and if at some point you delete the Exchange connection, you must uninstall the On-premises Exchange Connector from the computer onto which it was installed.

監視 Exchange Connector 活動Monitor the Exchange connector activity

順利設定 Exchange Connector 之後,即可檢視連線和上次成功同步處理嘗試的狀態。After you have successfully configured the Exchange Connector, you can view the status of the connection and the last successful synchronization attempt. 驗證 Exchange Connector 連線:To validate the Exchange Connector connection:

  1. 在 Intune 儀表板中,選擇 [內部部署存取]。On the Intune Dashboard, choose On-premises access.
  2. 在 [管理] 下,選取 [Exchange 內部部署存取] 來驗證連線狀態。Under Manage, select Exchange on-premises access to verify the connection status.

您也可以查看上次嘗試同步作業成功的時間和日期。You can also check the time and date of the last successful synchronization attempt.

System Center Operations Manager (SCOM) 管理組件System Center Operations Manager (SCOM) management pack

從 Intune 1710 版開始,您可以使用適用於 Exchange connector 和 Intune 的 SCOM 管理組件Beginning with the Intune 1710 release, you can use the SCOM management pack for Exchange connector and Intune. 這可在您需要針對問題進行疑難排解時,為您提供不同方式來監視 Exchange Connector。This gives you different ways of monitoring the Exchange connector when you need to troubleshoot issues.

後續步驟Next steps

建立 Exchange 內部部署的條件存取原則Create a conditional access policy for Exchange on-premises