<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Active Directory on Kürşat Bal</title><link>http://kursatbal.com/tags/active-directory/</link><description>Recent content in Active Directory on Kürşat Bal</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Mon, 10 Nov 2025 00:00:00 +0000</lastBuildDate><atom:link href="http://kursatbal.com/tags/active-directory/index.xml" rel="self" type="application/rss+xml"/><item><title>Exchange Server'da Kerberos Kimlik Doğrulamasına Geçiş</title><link>http://kursatbal.com/p/exchange-serverda-kerberos-kimlik-do%C4%9Frulamas%C4%B1na-ge%C3%A7i%C5%9F/</link><pubDate>Mon, 10 Nov 2025 00:00:00 +0000</pubDate><guid>http://kursatbal.com/p/exchange-serverda-kerberos-kimlik-do%C4%9Frulamas%C4%B1na-ge%C3%A7i%C5%9F/</guid><description>&lt;p&gt;Bu kılavuz, Microsoft Exchange Server ortamınızda Kerberos kimlik doğrulamasına geçiş için gerekli adımları detaylandırmaktadır.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="ön-şartlar-ve-active-directory-yapılandırması"&gt;Ön Şartlar ve Active Directory Yapılandırması
&lt;/h2&gt;&lt;h3 id="dns-kayıtlarının-oluşturulması"&gt;DNS Kayıtlarının Oluşturulması
&lt;/h3&gt;&lt;p&gt;DNS &lt;strong&gt;Forward Lookup Zone&lt;/strong&gt; üzerinde ilgili Autodiscover ve mail adları için &lt;strong&gt;A kaydı&lt;/strong&gt; oluşturulmalıdır.&lt;/p&gt;
&lt;h3 id="alternatif-hizmet-hesabı-asa-computer-nesnesi-oluşturma"&gt;Alternatif Hizmet Hesabı (ASA) Computer Nesnesi Oluşturma
&lt;/h3&gt;&lt;p&gt;Kerberos&amp;rsquo;un düzgün çalışabilmesi için bir &lt;strong&gt;Alternatif Hizmet Hesabı (ASA)&lt;/strong&gt; bilgisayar nesnesi oluşturulmalıdır. Bu nesne &lt;strong&gt;devre dışı bırakılmamalıdır&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;OU Path Tespiti:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Exchange Server&amp;rsquo;ın bulunduğu OU üzerine gelin → Properties → Attribute Editor → &lt;code&gt;distinguishedName&lt;/code&gt; değerini not alın.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;ASA Computer Nesnesi Oluşturma:&lt;/strong&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;span class="lnt"&gt;3
&lt;/span&gt;&lt;span class="lnt"&gt;4
&lt;/span&gt;&lt;span class="lnt"&gt;5
&lt;/span&gt;&lt;span class="lnt"&gt;6
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;New-ADComputer&lt;/span&gt; &lt;span class="n"&gt;-Name&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;EXCH2019ASA&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;`&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;-AccountPassword&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;Read-Host&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;Enter new password&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-AsSecureString&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;`&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;-Description&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;Alternate Service Account credentials for Exchange&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;`&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;-Enabled:&lt;/span&gt;&lt;span class="vm"&gt;$True&lt;/span&gt; &lt;span class="p"&gt;`&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;-SamAccountName&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;EXCH2019ASA&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;`&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;-Path&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;OU=Exchange Servers,OU=Servers,OU=Company,DC=kuso,DC=local&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;blockquote&gt;
&lt;p&gt;&lt;code&gt;-Path&lt;/code&gt; parametresini kendi OU yapınıza göre güncelleyin.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;strong&gt;AES 256 Şifrelemesini Etkinleştirme:&lt;/strong&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Set-ADComputer&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;EXCH2019ASA&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-add&lt;/span&gt; &lt;span class="vm"&gt;@&lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;msDS-SupportedEncryptionTypes&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;28&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;&lt;strong&gt;Doğrulama:&lt;/strong&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Get-ADComputer&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;EXCH2019ASA&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;Format-List&lt;/span&gt; &lt;span class="nb"&gt;msDS-SupportedEncryptionTypes&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;&lt;strong&gt;AD Senkronizasyonunu Tetikleme:&lt;/strong&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Repadmin /syncall /ADPe
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;hr&gt;
&lt;h2 id="exchange-server-üzerinde-asa-dağıtımı"&gt;Exchange Server Üzerinde ASA Dağıtımı
&lt;/h2&gt;&lt;h3 id="asa-kimlik-bilgilerinin-dağıtılması"&gt;ASA Kimlik Bilgilerinin Dağıtılması
&lt;/h3&gt;&lt;p&gt;Bu adımlar &lt;strong&gt;Exchange Management Shell (EMS)&lt;/strong&gt; üzerinden gerçekleştirilir.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Scripts klasörüne geçin:&lt;/strong&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;cd &lt;/span&gt;&lt;span class="nv"&gt;$exscripts&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;&lt;strong&gt;İlk Exchange Sunucusuna Dağıtma:&lt;/strong&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;span class="lnt"&gt;3
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;.\&lt;/span&gt;&lt;span class="n"&gt;RollAlternateServiceAccountPassword&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;ps1&lt;/span&gt; &lt;span class="p"&gt;`&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;-ToSpecificServer&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;kbexchsrv.kuso.local&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;`&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;-GenerateNewPasswordFor&lt;/span&gt; &lt;span class="n"&gt;kuso&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;EXCH2019ASA&lt;/span&gt;&lt;span class="p"&gt;$&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Önemli:&lt;/strong&gt; &lt;code&gt;kuso\EXCH2019ASA$&lt;/code&gt; kısmında netBIOS adını kullanın. İstendiğinde &lt;code&gt;Y&lt;/code&gt; yazıp Enter&amp;rsquo;a basın. İşlem tamamlandığında &lt;strong&gt;&amp;ldquo;Succeeded&amp;rdquo;&lt;/strong&gt; çıktısı görülmelidir.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;strong&gt;Birden Fazla Exchange Sunucusuna Dağıtma:&lt;/strong&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;span class="lnt"&gt;3
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;.\&lt;/span&gt;&lt;span class="n"&gt;RollAlternateServiceAccountPassword&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;ps1&lt;/span&gt; &lt;span class="p"&gt;`&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;-ToSpecificServer&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;exchsrv2.kuso.local&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;`&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;-CopyFrom&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;kbexchsrv.kuso.local&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;&lt;strong&gt;ASA Kimlik Bilgisi Ayarlarını Kontrol Etme:&lt;/strong&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Get-ClientAccessServer&lt;/span&gt; &lt;span class="n"&gt;-IncludeAlternateServiceAccountCredentialStatus&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nb"&gt;Format-List&lt;/span&gt; &lt;span class="n"&gt;Name&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;AlternateServiceAccountConfiguration&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;Çıktıda tüm sunucular için &lt;code&gt;kuso\EXCH2019ASA$&lt;/code&gt; görülmelidir.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="hizmet-asıl-adlarını-spn-ayarlama"&gt;Hizmet Asıl Adlarını (SPN) Ayarlama
&lt;/h2&gt;&lt;h3 id="mevcut-spn-ilişkilerini-kontrol-etme"&gt;Mevcut SPN İlişkilerini Kontrol Etme
&lt;/h3&gt;&lt;p&gt;CMD üzerinden çalıştırın. Çıktı &lt;strong&gt;&amp;ldquo;No such SPN found&amp;rdquo;&lt;/strong&gt; olmalıdır:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;setspn -F -Q http/mail.kuso.local
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;setspn -F -Q http/autodiscover.kuso.local
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;h3 id="spnleri-asa-kimlik-bilgilerine-bağlama"&gt;SPN&amp;rsquo;leri ASA Kimlik Bilgilerine Bağlama
&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;MAPI/HTTP ve Outlook Anywhere SPN&amp;rsquo;si:&lt;/strong&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;setspn -S http/mail.kuso.local kuso\EXCH2019ASA$
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;&lt;strong&gt;Autodiscover SPN&amp;rsquo;si:&lt;/strong&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;setspn -S http/autodiscover.kuso.local kuso\EXCH2019ASA$
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;h3 id="spn-ilişkilerini-doğrulama"&gt;SPN İlişkilerini Doğrulama
&lt;/h3&gt;&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;setspn -L kuso\EXCH2019ASA$
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;hr&gt;
&lt;h2 id="exchange-sanal-dizinlerini-yapılandırma"&gt;Exchange Sanal Dizinlerini Yapılandırma
&lt;/h2&gt;&lt;h3 id="outlook-anywhere-için-kerberos"&gt;Outlook Anywhere İçin Kerberos
&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;Etkinleştirme:&lt;/strong&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Get-OutlookAnywhere&lt;/span&gt; &lt;span class="n"&gt;-Server&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;kbexchsrv&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nb"&gt;Set-OutlookAnywhere&lt;/span&gt; &lt;span class="n"&gt;-InternalClientAuthenticationMethod&lt;/span&gt; &lt;span class="n"&gt;Negotiate&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;&lt;strong&gt;Doğrulama:&lt;/strong&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;span class="lnt"&gt;3
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Get-OutlookAnywhere&lt;/span&gt; &lt;span class="n"&gt;-Server&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;kbexchsrv&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nb"&gt;Format-Table&lt;/span&gt; &lt;span class="n"&gt;InternalClientAuthenticationMethod&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Beklenen: Negotiate&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;h3 id="mapi-over-http-için-kerberos"&gt;MAPI over HTTP İçin Kerberos
&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;Etkinleştirme (NTLM + Negotiate):&lt;/strong&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Get-MapiVirtualDirectory&lt;/span&gt; &lt;span class="n"&gt;-Server&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;kbexchsrv&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nb"&gt;Set-MapiVirtualDirectory&lt;/span&gt; &lt;span class="n"&gt;-IISAuthenticationMethods&lt;/span&gt; &lt;span class="n"&gt;Ntlm&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;Negotiate&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;&lt;strong&gt;Doğrulama:&lt;/strong&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;span class="lnt"&gt;3
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Get-MapiVirtualDirectory&lt;/span&gt; &lt;span class="n"&gt;-Server&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;kbexchsrv&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nb"&gt;Format-List&lt;/span&gt; &lt;span class="n"&gt;IISAuthenticationMethods&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Beklenen: {Ntlm, Negotiate}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;&lt;strong&gt;Hibrit/OAuth Ortamları İçin (Opsiyonel):&lt;/strong&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;span class="lnt"&gt;3
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nv"&gt;$mapidir&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;Get-MapiVirtualDirectory&lt;/span&gt; &lt;span class="n"&gt;-Server&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;kbexchsrv&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nv"&gt;$mapidir&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;Set-MapiVirtualDirectory&lt;/span&gt; &lt;span class="p"&gt;`&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;-IISAuthenticationMethods&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$mapidir&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;IISAuthenticationMethods&lt;/span&gt; &lt;span class="p"&gt;+=&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;Negotiate&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;hr&gt;
&lt;h2 id="son-işlemler-ve-test"&gt;Son İşlemler ve Test
&lt;/h2&gt;&lt;h3 id="grup-ilkesi-gpo-uygulama"&gt;Grup İlkesi (GPO) Uygulama
&lt;/h3&gt;&lt;p&gt;Kerberos kullanacak tüm kullanıcılara bir GPO uygulanmalıdır. &lt;strong&gt;Authenticated Users&lt;/strong&gt; grubuna uygulanabilir.&lt;/p&gt;
&lt;p&gt;Yol: &lt;code&gt;Computer Configuration → Policies → Windows Settings → Security Settings → Local Policies → Security Options&lt;/code&gt;&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Policy&lt;/th&gt;
&lt;th&gt;Setting&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Restrict NTLM: Incoming NTLM traffic&lt;/td&gt;
&lt;td&gt;Deny all accounts&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Restrict NTLM: NTLM authentication in this domain&lt;/td&gt;
&lt;td&gt;Disable&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Restrict NTLM: Outgoing NTLM traffic to remote servers&lt;/td&gt;
&lt;td&gt;Deny all&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id="hizmetleri-yeniden-başlatma"&gt;Hizmetleri Yeniden Başlatma
&lt;/h3&gt;&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Restart-Service&lt;/span&gt; &lt;span class="n"&gt;MSExchangeServiceHost&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Restart-WebAppPool&lt;/span&gt; &lt;span class="n"&gt;-Name&lt;/span&gt; &lt;span class="n"&gt;MSExchangeAutodiscoverAppPool&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;h3 id="test-ve-doğrulama"&gt;Test ve Doğrulama
&lt;/h3&gt;&lt;ol&gt;
&lt;li&gt;İstemci makinesinde &lt;strong&gt;Outlook&amp;rsquo;u&lt;/strong&gt; başlatın&lt;/li&gt;
&lt;li&gt;CMD&amp;rsquo;yi başlatın ve Kerberos biletlerini kontrol edin:&lt;/li&gt;
&lt;/ol&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;klist
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;Çıktıda aşağıdaki biletlerin görülmesi Kerberos&amp;rsquo;un başarıyla çalıştığını gösterir:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;span class="lnt"&gt;3
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Server: HTTP/mail.kuso.local @ kuso.local
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Server: HTTP/autodiscover.kuso.local @ kuso.local
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;KerbTicket Encryption Type: AES-256-CTS-HMAC-SHA1-96
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;</description></item><item><title>Exchange On-Premises'ten Microsoft 365'e Hibrit Geçiş Rehberi</title><link>http://kursatbal.com/p/exchange-on-premisesten-microsoft-365e-hibrit-ge%C3%A7i%C5%9F-rehberi/</link><pubDate>Mon, 30 Jun 2025 00:00:00 +0000</pubDate><guid>http://kursatbal.com/p/exchange-on-premisesten-microsoft-365e-hibrit-ge%C3%A7i%C5%9F-rehberi/</guid><description>&lt;p&gt;Kurumsal altyapınızı buluta taşımak, günümüz iş dünyasının vazgeçilmez bir parçası haline geldi. Bu makale, şirket içi Exchange yapınızı Exchange Online (Microsoft 365) ile nasıl harmanlayacağınızı adım adım anlatmaktadır.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Not:&lt;/strong&gt; Bu rehber genel bir yol haritası sunar. Buradaki dökümanı sadece geçiş öncesi bilgilendirme gibi düşünebilirsiniz.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;hr&gt;
&lt;h2 id="geçiş-öncesi-hazırlıklar"&gt;Geçiş Öncesi Hazırlıklar
&lt;/h2&gt;&lt;h3 id="ou-yapısı-analizi-ve-düzenlemesi"&gt;OU Yapısı Analizi ve Düzenlemesi
&lt;/h3&gt;&lt;p&gt;Hibrit yapıya adım atarken Organizasyonel Birim (OU) yapılarınızı gözden geçirmek zorunludur. Şirket OU&amp;rsquo;su altında aşağıdaki 4 OU oluşturulması önerilir:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;SirketMailboxUsers&lt;/strong&gt; — E-posta kutusu olan kullanıcılar&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;SirketUsers&lt;/strong&gt; — E-postası olmayan AD kullanıcıları&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;SirketDistGroups&lt;/strong&gt; — Dağıtım grupları&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;SirketGroups&lt;/strong&gt; — E-posta grubu olmayan genel gruplar&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="senkronize-edilecek-birimlerin-kontrolü"&gt;Senkronize Edilecek Birimlerin Kontrolü
&lt;/h3&gt;&lt;p&gt;Bu işlemin arkasındaki kahraman &lt;strong&gt;Microsoft Entra Connect Cloud Sync&lt;/strong&gt; aracıdır. Kilit nokta, AD kullanıcılarının &lt;strong&gt;&amp;ldquo;E-mail&amp;rdquo; (mail-attribute)&lt;/strong&gt; değeridir.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Püf Noktası:&lt;/strong&gt; E-posta kutusu olan tüm kullanıcıların ve dağıtım gruplarının istisnasız Office 365&amp;rsquo;e senkronize edilmesi gerekir. Senkronize olmayan birimlerin Azure kimliği oluşmaz.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3 id="e-posta-değerlerinin-kontrolü"&gt;E-posta Değerlerinin Kontrolü
&lt;/h3&gt;&lt;p&gt;Türkçe karakterlere (ş, ç, ö vb.) dikkat edin! Bu karakterler senkronizasyon sonrası Office 365&amp;rsquo;te farklı işaretlere dönüşebilir.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="microsoft-365-tenant-oluşturulması"&gt;Microsoft 365 Tenant Oluşturulması
&lt;/h2&gt;&lt;h3 id="domain-ekleme"&gt;Domain Ekleme
&lt;/h3&gt;&lt;p&gt;Microsoft 365 Yönetici Merkezi&amp;rsquo;nden &lt;strong&gt;Ayarlar → Etki Alanları → Etki alanı ekle&lt;/strong&gt; adımlarını izleyerek domain adınızı girin.&lt;/p&gt;
&lt;h3 id="dns-kayıtları"&gt;DNS Kayıtları
&lt;/h3&gt;&lt;p&gt;Etki alanınızın size ait olduğunu kanıtlamak için DNS&amp;rsquo;e bir TXT kaydı eklemeniz gerekir:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;span class="lnt"&gt;3
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;TXT adı : @
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;TXT değeri: MS=ms12345678
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;TTL : 3600
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Hibrit Geçiş Ayarı:&lt;/strong&gt; Alan adınıza tıkladıktan sonra &lt;strong&gt;&amp;ldquo;Exchange ve Exchange Online Protection&amp;rdquo;&lt;/strong&gt; seçeneğini kapatın. SPF, Autodiscover ve MX kayıtlarını şimdilik manuel yöneteceksiniz.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3 id="accepted-domains--autodiscover-ayarı"&gt;Accepted Domains — Autodiscover Ayarı
&lt;/h3&gt;&lt;ul&gt;
&lt;li&gt;Hem şirket içi Exchange&amp;rsquo;de hem Exchange Online&amp;rsquo;da &amp;ldquo;accepted domain&amp;rdquo; ayarları birebir aynı olmalıdır.&lt;/li&gt;
&lt;li&gt;Posta kutusu taşıma sırasında &lt;code&gt;autodiscover.domain.com&lt;/code&gt; kaydı mutlaka şirket içi Exchange&amp;rsquo;e çözülmelidir.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="connector-ayarları"&gt;Connector Ayarları
&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;Hybrid Configuration Wizard (HCW)&lt;/strong&gt; bu ayarların çoğunu otomatik yapar:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Şirket içinden Office 365&amp;rsquo;e giden postalar için &lt;strong&gt;Send Connector&lt;/strong&gt; oluşturur&lt;/li&gt;
&lt;li&gt;Office 365&amp;rsquo;ten şirket içine gelen postalar için &lt;strong&gt;Inbound Connector&lt;/strong&gt; kurar&lt;/li&gt;
&lt;li&gt;Güvenli iletişim için &lt;strong&gt;TLS&lt;/strong&gt; ayarlarını yapar&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Standart hibrit kurulumda manuel Receive Connector oluşturmanıza gerek yoktur.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="hibrit-konfigürasyonu-için-gerekli-kurulumlar"&gt;Hibrit Konfigürasyonu İçin Gerekli Kurulumlar
&lt;/h2&gt;&lt;h3 id="windows-server-vm-kurulumu"&gt;Windows Server VM Kurulumu
&lt;/h3&gt;&lt;p&gt;1000 kişiden az kullanıcı için: &lt;strong&gt;2 CPU, 8 GB RAM, 70 GB disk&lt;/strong&gt; ile bir Windows Server VM yeterlidir.&lt;/p&gt;
&lt;p&gt;AD&amp;rsquo;de özel bir kullanıcı açın (örn. &lt;code&gt;azuresync&lt;/code&gt;). Zorunlu roller:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Domain Admin&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Organization Management&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="eac-ayarları"&gt;EAC Ayarları
&lt;/h3&gt;&lt;p&gt;&lt;code&gt;https://ipadress/ecp&lt;/code&gt; adresinden &lt;strong&gt;Sunucular → Sanal Dizinler → EWS&lt;/strong&gt; altında &lt;strong&gt;&amp;ldquo;Enable MRS Proxy endpoint&amp;rdquo;&lt;/strong&gt; seçeneğinin etkin olduğundan emin olun.&lt;/p&gt;
&lt;h3 id="hybrid-configuration-wizard-hcw"&gt;Hybrid Configuration Wizard (HCW)
&lt;/h3&gt;&lt;p&gt;&lt;a class="link" href="https://aka.ms/HybridWizard" target="_blank" rel="noopener"
&gt;https://aka.ms/HybridWizard&lt;/a&gt; adresinden indirin.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Hibrit Özellikler:&lt;/strong&gt;&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Seçenek&lt;/th&gt;
&lt;th&gt;Açıklama&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Full Hybrid&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Kontrollü ve aşamalı geçiş için — önerilen&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Minimal Hybrid&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Hızlı, direkt geçiş senaryosu için&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;Hibrit Topoloji:&lt;/strong&gt;&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Seçenek&lt;/th&gt;
&lt;th&gt;Açıklama&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Classic Hybrid Topology&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Full Hybrid için genellikle tercih edilir&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Modern Hybrid Topology&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Daha hızlı, yerel sunucuya dışarıdan erişim gerektirmez&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;hr&gt;
&lt;h2 id="microsoft-entra-connect--cloud-sync"&gt;Microsoft Entra Connect — Cloud Sync
&lt;/h2&gt;&lt;h3 id="cloud-synce-giriş"&gt;Cloud Sync&amp;rsquo;e Giriş
&lt;/h3&gt;&lt;p&gt;Azure Portal&amp;rsquo;da arama kutusuna &lt;strong&gt;&amp;ldquo;Microsoft Entra Connect&amp;rdquo;&lt;/strong&gt; yazın → Cloud Sync.&lt;/p&gt;
&lt;h3 id="cloud-sync-kurulumu"&gt;Cloud Sync Kurulumu
&lt;/h3&gt;&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Yeni yapılandırma&lt;/strong&gt; → &amp;ldquo;AD&amp;rsquo;den Microsoft Entra Kimliği&amp;rdquo; seçin&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&amp;ldquo;Şirket içi aracıyı indir&amp;rdquo;&lt;/strong&gt; ile ajan yazılımını indirip kurun&lt;/li&gt;
&lt;li&gt;Sol menüden &lt;strong&gt;Aracılar&lt;/strong&gt; sekmesinde ajanın &lt;strong&gt;&amp;ldquo;Etkin&amp;rdquo;&lt;/strong&gt; göründüğünü doğrulayın&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="kapsam-belirleme-filtreleri"&gt;Kapsam Belirleme Filtreleri
&lt;/h3&gt;&lt;p&gt;&amp;ldquo;Seçili kuruluş birimleri&amp;rdquo; seçeneğiyle senkronize edilecek OU&amp;rsquo;ları belirleyin.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Örnek DN Bilgileri:&lt;/strong&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;OU=SirketMailboxUsers,OU=Sirketim,DC=sirketim,DC=com
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;OU=SirketDistGroups,OU=Sirketim,DC=sirketim,DC=com
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;blockquote&gt;
&lt;p&gt;DN bilgisini almak için: ilgili OU → sağ tık → Özellikler → Öznitelik Düzenleyici → &lt;strong&gt;distinguishedName&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3 id="öznitelik-eşleştirmesi-attribute-mapping"&gt;Öznitelik Eşleştirmesi (Attribute Mapping)
&lt;/h3&gt;&lt;p&gt;&lt;code&gt;UserPrincipalName&lt;/code&gt; karşısına şunu yazın:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Trim([mail])
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;h3 id="public-dns-kayıtları"&gt;Public DNS Kayıtları
&lt;/h3&gt;&lt;p&gt;SPF kaydınızı mutlaka güncelleyin:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;include:spf.protection.outlook.com -all
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;hr&gt;
&lt;h2 id="mailbox-geçişi-migration"&gt;Mailbox Geçişi (Migration)
&lt;/h2&gt;&lt;p&gt;&lt;strong&gt;Exchange Admin Center → Migration → Add migration batch:&lt;/strong&gt;&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Adım&lt;/th&gt;
&lt;th&gt;Seçim&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Migration path&lt;/td&gt;
&lt;td&gt;Migration to Exchange Online&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Migration type&lt;/td&gt;
&lt;td&gt;Remote move migration&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Kullanıcı ekleme&lt;/td&gt;
&lt;td&gt;Manually add users&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Schedule&lt;/td&gt;
&lt;td&gt;Automatically&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;blockquote&gt;
&lt;p&gt;Geçiş işlemlerinden önce bir pivot kullanıcı ve dağıtım grubu açarak tüm testlerinizi bu birimlerde gerçekleştirin.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Ana ekranda işlem &lt;code&gt;syncing → synced → complete&lt;/code&gt; olarak ilerleyecektir.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="sonuç"&gt;Sonuç
&lt;/h2&gt;&lt;p&gt;Exchange On-Premises&amp;rsquo;ten Microsoft 365&amp;rsquo;e hibrit geçiş süreci, adım adım ve dikkatli bir planlamayla sorunsuz şekilde tamamlanabilir. Her altyapı farklılık gösterebilir; bu adımları kendi ortamınıza uyarlarken dikkat edin.&lt;/p&gt;</description></item></channel></rss>