Skip to main content

UAG Pre-installation Checklist

Here's a quick pre-installation checklist I have developed for the UAG deployments. Of course, it may not cover all possible deployment scenarios. So, feel free to expand upon it as necessary.

  • Networking has been configured correctly
  • Static IPs assigned to all network interfaces
  • Static IPs to be assigned to each trunk (in load-balanced array this will be assigned to the VIP associated with the trunk) have been reserved
  • Connectivity to the Internet works
  • Connectivity to the internal network works
  • All internal networks (network ranges that UAG will be fronting/protecting) have been explicitly identified

  • All servers meet system requirements 
  • All available Windows updates have been installed
  • All servers are clean, with no additional (unnecessary) software installed
  • All servers have been properly named
  • If applicable (required for UAG array), all servers have been joined to the domain 
  • No previous versions of UAG, TMG, or SQL are installed on any of the servers
  • Windows firewall service is started, and set to start automatically on all servers

  • User account (domain account if UAG server is joint to the domain) and password to perform UAG installation have been identified (must have administrative permissions on the server)
  • User account and password that will be impersonated by UAG to retrieve data from Active Directory have been identified (must have permissions to traverse AD and read objects and their attributes). Similar provisions will apply to other authentication repositories. 
  • If SharePoint resources are to be published, user account and password to access SharePoint central admin (for AAM modification) has been identified.  

Media and Licenses:

  • UAG installation media (latest version with applicable service packs and updates) has been obtained and made available
  • UAG product key / license has been obtained and made available

  • All required URLs (for trunks and applications to be published) have been identified
  • Means of creating/editing DNS records (for the URLs mentioned above) have been established
  • Valid digital certificates for each trunk and each application that will require the use of HTTPS (SSL/TLS) have been obtained and made available

NOTE: The certificates should match the FQDN names used in access URL (for example: if is used to access UAG portal, then the certificate should be issued to To simplify operations the use of wildcard (* certificate is recommended.


Popular posts from this blog

Mail-enabled security groups in Office 365

Another update (11/19/2013):  further evolution of Office 365 services makes creation of distribution and security groups even easier, plus there's now an option of creating a dynamic distribution group (click here for more information):    Update (08/06/2012): a clear sign of Office 365 evolving along the same lines as other agile cloud services - small incremental features and minor new functionality are being delivered almost continuously and, unlike important major service updates,  without much fanfare. For example, there's no need to resort to using PowerShell to setup mail-enabled security groups anymore, it can now be done at creation using management portal:       Those managing Office 365 ( O365 ) tenant via the Microsoft Online Services Portal  ( MOS Portal ) interface would notice that there are two distinct group entities: Security Groups: can be created via MOS Portal (main portal page>Management>Security Groups) and used for assigning

Drumbeat - Sales and Technical Resources for Office 365

​ Drumbeat - provides information as well as technical and sales resources for Office 365. From partnering with Microsoft, to building up your sales and technical readiness, to adopting proven methodologies for successful deployment - you will find lots of good information and many helpful links there. Here's a quick sample of topics covered: The Customer Decision Framework is Microsoft's selling methodology designed to help partners sell Office 365 to their customers. Office 365 FastTrack is Microsoft's new, 3-step pilot and deployment methodology designed so customers experience service value early in the sales cycle with a smooth path to advance from a pilot to deployment.

Sample DS Command

PowerShell is all the hype these days, and rightfully so - you can do just about anything with it; but, call me old-fashioned I still like to use ds commands every now and then, it's quick and dirty. Here are a few samples that query AD and to get some basic counts and other information: # Get a count of enabled and disabled user accounts in the domain dsquery user -limit 0 domainroot | dsget user -dn -disabled | find /c /i " no" dsquery user -limit 0 domainroot | dsget user -dn -disabled | find /c /i " yes" # Get a count of enabled and disabled computer accounts in the domain dsquery computer -limit 0 domainroot | dsget computer -dn -disabled | find /c /i " no" dsquery computer -limit 0 domainroot | dsget computer -dn -disabled | find /c /i " yes" # Get a count of enabled, but inactive (at least 24 weeks) user and computer accounts in the domain dsquery user -inactive 24 -limit 0 domainroot | dsget user -dn -disabled | find /c /i