( Courteous of http://www.edutech.me.uk/bes-express/installing-bes-express-on-sbs2008-server/ ) for future reference
First of all we need to install the Microsoft Exchange Server MAPI Client and Collaboration Data Objects 1.2.1 if these have not already been done. You can download these from:
Your Server must also have Microsoft Exchange Server 2007 Service Pack 2 and all Patches Installed.
Once you have installed the above, you then need to Raise Windows Server 2008 Active Directory Domain and Forest Function Levels.
- To do this launch “Active Directory Users and Computers” from the Administrative Tools
- Right click your domain and choose ‘Raise Domain Function Level’
- Choose Windows Server 2008 and click Raise, Accept and Ok and then Ok upon Success
- Close MMC and then launch “Active Directory Domains and Trusts” from the Administrative Tools.
- Right Click ‘Active Directory Domains and Trusts’ and select Raise Forest Function Level.
- Choose Windows Server 2008 and click Raise, Accept and Okay and then Ok upon Success.
Next, we need to create a Windows account and mailbox to act as the Blackberry Enterprise Server Express Account
- Open the Exchange Management Console
- Select the Recipient Configuration Node, and then the Mailbox Note. Click on “New Mailbox” on the right
- Select “User Mailbox” as the type and then click next, Create a Mailbox for “New User” and click next
- Fill in the usual fields First Name, Name, User Logon Name and give a strong password to the account (BESAdmin – Recommended Username) and then click next.
- Select the Mailbox Database you wish to add the account too, click on next and then new
Once that process has been completed successfully, you then need to configure some settings within Exchange Server 2007 using the Exchange Management Shell
- Launch the Exchange Management Shell
- Type in the following PowerShell command to set ViewOnlyAdmin role for BESAdmin
add-exchangeadministrator “BESAdmin” -role ViewOnlyAdmin
- Type in the following PowerShell command to assign the ms-Exch-Store-Admin, Receive As, and Send-As Permissions for BESAdmin
get-mailboxserver “ContosoServer” | add-adpermission -user “BESAdmin” -accessrights ExtendedRight -extendedrights Receive-As, ms-Exch-Store-Admin, Send-As
Next we need to configure the server that will host the Blackberry Enterprise Server Express Software
- Launch “Active Directory users and Computers”
- Select the hive Builtin and double click ‘Administrators’
- Choose the tab ‘Members’ and click on Add, Type ‘BESAdmin’ and click ‘Check Names’, Click Ok, Apply and then Ok
- Launch Group Policy Management
- Right click ‘Default Domain Controllers Policy’ and then choose ‘Edit’
- Choose Computer Configuration –> Windows Settings –> Security Settings –> Local Policies –> User Rights Assignment and double right click in the right pane ‘Allow log on locally’
- Click ‘Add User or Group’ , Browse, Type ‘BESAdmin’ and click ‘Check Names’ click on Ok, Apply and then Ok.
- Scroll down and double click ‘Log on as a Service’
- Check ‘Define these policy settings’ and click ‘Add User or Group’
- Click Browse, type ‘BESAdmin’ and click ‘Check Names’ and then Click on Ok, Ok, Apply and then Ok
Once you have completed these steps, we will then need to configure the Database Server and Run the BES Setup but before we can do that we need to get you on to the RIM website to Register and Download the Software and get all of the Licence/CAL keys you will be required to enter later.
NOTE: You need to now Logoff from the Server and logon with the BESAdmin account you created earlier, if you DO NOT do this then the whole thing will just fail and give you a headache!
Run the download, unzip the contents into a folder C:\BESExpress and the setup will start automatically.
Make sure that on the prompt it states you are logged in with the BESAdmin account and the domain shown is correct.
Fill in the details asked for, Username/Organisation/Country and accept the Licence Agreement.
On the next screen choose ‘Create a Blackberry Configuration Database’ and click on next, choose the defaults and then click on next, go through the checklist and make sure you do not see any warnings. If you do then please correct the warnings by installing any components you may be missing. (If your server is up to date then this should be fine).
On SBS2008 there is already a SQL 2005 Instance, you can choose to install the database into the SBSMonitoring Instance but I would recommend that you create a dedicated instance, the BES Express software will look after all of that for you.
So, on the next screen choose “Install Microsoft SQL Server 2005 Express Edition SP3 on this Computer”, and then click on next.
Fill in the Password and the name of your server and then click on next, make sure you type in this information correctly otherwise again you will have problems further down the line, review your settings and click Install.
Go and grab yourself a drink, and some lunch if it’s that time already and when you return it should be prompting you to restart the server. After the server has restarted make sure you logon again with the BESAdmin account otherwise it won’t continue the setup.
*NOTE it won’t fail if you logon with Administrator by accident, just logoff and login as the right user.
Once you have logged back on to the server, the installation should pop back up for you on screen, leave the settings as they are on screen and select next.
Wait a couple of seconds and then you will be asked to create the BESMgmt Database, Choose Yes and then the database will be created, Click on Ok once you the Success Info Prompts.
On the next screen you will be asked to fill in the CAL Key, SRP Identifier and Authentication Key, Click on Verify on both SRP Host and SRP Authentication Information, upon success click next
On the next screen, fill in the name of your server and the mailbox field is the user you created earlier BESAdmin, Select ‘Check Name’ and then Apply and Ok
Next, type in a password for the SSL Certificate and click on next
On the next screen type in the account credentials to allow the Blackberry Administration Service to Authenticate users in Microsoft Active Directory, NOTE: DO NOT use the BESAdmin account here, Use the account you created upon Installation of the Server Operating System i.e. Administrator and then click Next.
On the next screen I chose to use a Non Active Directory Account to manage the Blackberry Accounts, So Select “Use Blackberry Administration Services Authentication” and type in a Secure Password, and then click next.
Nearly Finished, Click on “Start Services” on the next page and sit back and wait in suspense, click on next and then you should see the results come back as Successful.
Then make a Note/Save the URL’s and then click on Finish
Finally, configure the firewall on the Small Business Server to allow access to the Blackberry Administration Service and Web Desktop Manager. I personally chose to do this via Command Prompt but it can be doing using the GUI via Control Panel.
- Launch Command Prompt (Start > Run > CMD > Enter)
- Type netsh firewall add portopening TCP 3443 “BESExpress Management Port” and press Enter.