Force OWA Light Users to Premium OWA After Exchange Server May 2026 CVE Mitigation

Force OWA Light Users to Premium OWA After Exchange Server May 2026 CVE Mitigation

Exchange, Exchange Server SE / 2019 / 2016, Migration & Upgrade, Security & Hardening
Applies to: Exchange Server SE / 2019 Microsoft recently published guidance for Exchange Server addressing the May 2026 vulnerability. One important note in the article is related to OWA Light. Microsoft states that OWA Light — accessed by using an OWA URL ending with /?layout=light — does not work properly after the mitigation is applied. Microsoft also notes that this feature was deprecated several years ago and is not intended for regular production use. For a deeper look at the OWA request path and frontend/backend authentication design, see Exchange OWA Authentication Deep Dive – Part 1. This can become a practical issue if some users previously selected the following option in Outlook on the web: "Use the light version of Outlook" When this option is selected, the user may continue…
Read More
What Happens to Shared Calendars After Exchange Hybrid Migration?

What Happens to Shared Calendars After Exchange Hybrid Migration?

Exchange, Exchange Online, Hybrid, Migration & Upgrade
Applies to: Exchange Server SE / 2019 / 2016 | Exchange Online | Hybrid In Exchange Hybrid environments, shared calendar behavior after mailbox migration is often misunderstood. Calendar access does not automatically fail when a mailbox moves to Exchange Online, but the result depends on the permission type, how it was assigned, and the hybrid configuration. This article walks through a controlled test and shows the behavior observed before and after the move. In This Article 1. Scenario 2. Step 1 – Test Default Behavior (On-Prem → On-Prem) 3. Step 2 – Check Existing Permissions 4. Step 3 – Assign Explicit Permission 5. Step 4 – Verify Access 6. Step 5 – Migrate Mailbox to Exchange Online 7. Step 6 – Test After Migration (Both Directions) 7.1 Test 1 –…
Read More
Reclaiming Space from Inflated Thin VMDK Disks After VM Export in ESXi

Reclaiming Space from Inflated Thin VMDK Disks After VM Export in ESXi

VMware, vSphere
Applies to: VMware ESXi 9.x / 8.x / 7.x / 6.7 / 6.5 / 6.0 / 5.5 / 5.1 / 5.0 / 4.1 After exporting several virtual machines from my ESXi environment, I noticed that datastore usage had increased significantly. Although the guest operating systems were using only a small portion of their virtual disks, the VMDK files appeared to occupy space close to their full provisioned size. For example, a virtual machine with a 100 GB thin-provisioned disk that was actually using only around 17 GB inside the guest OS appeared to consume almost the entire provisioned disk size on the datastore. This situation can quickly become problematic in environments where multiple virtual machines are exported or stored for later use. Datastores may appear nearly full even though the…
Read More
Wake on LAN Stops Working After a Windows 10 Upgrade

Wake on LAN Stops Working After a Windows 10 Upgrade

Archive / Legacy Topics, Windows 10, Windows Client
Applies to: Windows 10 Wake on LAN (WOL) stopped working on one of my systems after upgrading from Windows 8.1 to Windows 10. The system used an onboard Realtek PCIe GBE Family Controller. In this case, the problem was the network adapter driver installed after the Windows upgrade. Replacing it with the Realtek vendor driver restored WOL. This was the finding in this specific system, not a general rule for every Windows 10 WOL problem. In This Article 1. Original Environment 2. Check the WOL Power State 3. Verify Network Adapter Settings 4. Check the Network Adapter Driver 5. What Fixed It in This System 6. Key Takeaways 1. Original Environment Previous OS: Windows 8.1 Pro x64 Current OS: Windows 10 Pro x64 Mainboard: ASUS H87-Plus NIC: Onboard Realtek PCIe…
Read More
How to Join VMware ESXi to an Active Directory Domain

How to Join VMware ESXi to an Active Directory Domain

Active Directory, Identity, VMware, vSphere
Applies to: VMware ESXi 9.x / 8.x / 7.x / 6.7 / 6.5 / 6.0 / 5.5 / 5.1 VMware ESXi can use Microsoft Active Directory for direct host authentication. This lets administrators assign ESXi permissions to domain users and groups instead of maintaining separate local accounts on every host. Security note: Current VMware security guidance no longer recommends joining ESXi hosts directly to Active Directory as the default design. In centrally managed environments, prefer managing authentication and permissions through vCenter unless direct host-level AD authentication is specifically required. The original version of this article was written for ESXi 5.1. The capability still exists in current ESXi releases, but the interface and security defaults have changed. In This Article 1. Before You Join the Domain 2. Join ESXi to Active…
Read More
How to Enable TLS for VSFTPD on RHEL-Family Linux

How to Enable TLS for VSFTPD on RHEL-Family Linux

Linux
Applies to: RHEL-family Linux — RHEL 6–10 | Rocky Linux 8–10 | AlmaLinux 8–10 | CentOS 6–8 | CentOS Stream 8–10 Traditional FTP sends usernames, passwords, and file data without encryption. If you still need to run vsftpd, you can protect the connection with TLS and use FTPS instead of plain FTP. Current guidance: For new deployments, prefer SFTP over OpenSSH where possible. Red Hat has deprecated FTP client and server software, including vsftpd, in RHEL 10 and recommends moving new workflows to SFTP or WebDAV. FTPS and SFTP are different protocols. FTPS is FTP protected with TLS. SFTP is the SSH File Transfer Protocol and does not use vsftpd. In This Article 1. Install VSFTPD 2. Prepare the TLS Certificate 3. Configure VSFTPD for TLS 4. Restart VSFTPD 5.…
Read More
How to Configure a Secondary BIND DNS Server on RHEL-Family Linux

How to Configure a Secondary BIND DNS Server on RHEL-Family Linux

Linux
Applies to: RHEL-family Linux — RHEL 6–10 | Rocky Linux 8–10 | AlmaLinux 8–10 | CentOS 6–8 | CentOS Stream 8–10 A secondary BIND DNS server keeps an authoritative copy of a DNS zone by transferring it from the primary server. If the primary DNS server is unavailable, clients can still query the secondary server for the zone. The original version of this article used the older master/slave terminology. Current BIND documentation prefers primary/secondary, although the older configuration keywords are still supported and remain useful for compatibility with older RHEL releases. In This Article 1. Configure the Primary Server 2. Install BIND on the Secondary Server 3. Configure the Secondary Zone 4. Start BIND and Open the Firewall 5. Validate the Zone Transfer 6. Current BIND Terminology 7. Key Takeaways…
Read More
How to Manage Swap Partitions on RHEL, Rocky Linux, AlmaLinux, and CentOS

How to Manage Swap Partitions on RHEL, Rocky Linux, AlmaLinux, and CentOS

Linux
Applies to: RHEL-family Linux — RHEL 6–10 | Rocky Linux 8–10 | AlmaLinux 8–10 | CentOS 6–8 | CentOS Stream 8–10 Linux can use swap when physical memory is under pressure. Swap can be provided by a dedicated partition, an LVM logical volume, or a swap file. The original version of this article was written for RHEL 6 and CentOS 6. The same core swap-management commands are also used on current RHEL, Rocky Linux, AlmaLinux, and CentOS releases, so the procedure below has been updated while keeping the older versions in scope. In This Article 1. Check Current Swap Space 2. Create a Swap Partition 3. Initialize the Partition as Swap 4. Add the Swap Partition to /etc/fstab 5. Activate and Verify Swap 6. Key Takeaways 1. Check Current Swap…
Read More
Common Linux Network Troubleshooting Commands

Common Linux Network Troubleshooting Commands

Linux
Applies to: RHEL-family Linux — RHEL 6–10 | Rocky Linux 8–10 | AlmaLinux 8–10 | CentOS 6–8 | CentOS Stream 8–10 Linux includes a small set of command-line tools that can quickly answer the most common network troubleshooting questions: Is the interface up? Is there a route? Is the remote host reachable? Is the port listening? Is DNS resolving correctly? The original version of this article used tools such as netstat, arp, and telnet. Those commands are still useful in older environments, but current RHEL-family systems primarily use ip, ss, ip neigh, nmcli, and tools such as nc or curl. In This Article 1. IP Address and Interface Status 2. Routing 3. Reachability 4. Listening Ports and Connections 5. Test a Remote Port 6. DNS Lookups 7. Neighbor Cache 8.…
Read More