Exchange 2016 Deployment on Virgin Windows Server 2016

Use: “SSS_X64FRE_EN-US_DV9-KB4493440-KB4103723.iso”

During install select Server w/GUI

Upon completion of install:

  1. Install virt-io or ESXi drivers
  2. Assign Static IP and Local DNS (127.0.0.1)
  3. Change Hostname
  4. Reboot
  5. Add Active Directory Domain Service [Role], IIS [Role] and Media Foundation [Feature]
  6. Allow automatic reboots (tick box)
  7. Create new forest.
  8. Reboot
  9. Add forward DC lookup (8.8.8.8 and 8.8.4.4 and 1.1.1.1)
  10. Internet Explorer Mode Off
  11. Enable RDP
  12. Install Chrome

Install Exchange 2016 Dependencies:

  1. Install dotNet Framework v4.8 (ndp48-x86-x64-allos-enu.exe)
  2. Install IIS rewrite (rewrite_amd64_en-US.msi)
  3. Install UMCA (UcmaRuntimeSetup.exe)
  4. Install 2013 C++ runtimes (vcredist_x64.exe)

(the above 4 items can be installed in any order)

Install Exchange CU23.ISO – do not check for updates.

  1. Select Mailbox role with automatically install dependencies ticked, depending on hardware it takes approx. 40 minutes.
  2. Reboot as suggested by the installer.

Deploy SSL (host.subdomain.domain.tld,autodiscover.domain.tld,exchange.domain.tld):

https://www.alitajran.com/install-free-lets-encrypt-certificate-in-exchange-server/

Extract win-acme to root of C: (as to ensure it’s not accidentally deleted) the program will create a scheduled task.

  1. Populate Exchange as required.
  2. Add Exchange Rules (eg: impersonation warnings.)
  3. Install Exchange2016-KB5030524-x64-en (this is the latest Exchange 2016 rollup at the time of writing) – it is not yet available through Windows Update and must be installed manually.
  4. Install other Windows Updates

Suggested Actions:

  1. Block ECP: Disable external access to ECP in Exchange Server https://www.alitajran.com/disable-external-access-to-ecp-exchange/
  2. Setup DKIM. https://powerdmarc.com/dkim-on-prem-exchange-server-setup/
Published
Categorised as Windows

Leave a comment

Your email address will not be published. Required fields are marked *