SOLVED
Home

Tips to use Azure AD Connect with online Exchange management

%3CLINGO-SUB%20id%3D%22lingo-sub-122146%22%20slang%3D%22en-US%22%3ETips%20to%20use%20Azure%20AD%20Connect%20with%20online%20Exchange%20management%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-122146%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20all%2C%26nbsp%3BI've%20a%20question%20about%20setting%20up%20Azure%20AD%20Connect%20and%20maintenance%20of%20Exchange%20Online.%3C%2FP%3E%3CP%3EWe're%20a%20MSP%20with%20allot%20of%20customers%20running%20an%20on-prem%20AD%20and%20using%20Exchange%20Online%20(Office365%20bundles)%20for%20their%20e-mail.%3C%2FP%3E%3CP%3EFor%20the%20convenience%20of%20the%20end-users%20we%20would%20like%20to%20enable%20password%20sync%20through%20Azure%20AD%20Connect.%20But%20when%20we%20set%20this%20up%20we%20have%20to%20do%20the%20Exchange%20management%20on-prem.%20And%20that's%20something%20we%20want%20to%20move%20away%20from%20(even%20with%20the%20free%20Exchange%20license%20key....).%26nbsp%3B%3C%2FP%3E%3CP%3EHow%20are%20you%20guys%2Fgirls%20dealing%20with%20this%20issue%3F%20Or%20do%20I%20miss%20something%20and%20can%20I%20just%20sync%20the%20passwords%20and%20still%20do%20the%20management%20of%20Exchange%20Online%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-122146%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-133216%22%20slang%3D%22en-US%22%3ERe%3A%20Tips%20to%20use%20Azure%20AD%20Connect%20with%20online%20Exchange%20management%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-133216%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Joris%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAdsiedit%20is%20not%20supported%20by%20Microsoft.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EYou%20can%20view%20here%20the%20article%20that%20describe%20a%20decommission%20of%20Exchange%20Server.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechnet.microsoft.com%2Fen-us%2Flibrary%2Fdn931280(v%3Dexchg.150).aspx%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Ftechnet.microsoft.com%2Fen-us%2Flibrary%2Fdn931280(v%3Dexchg.150).aspx%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-133161%22%20slang%3D%22en-US%22%3ERe%3A%20Tips%20to%20use%20Azure%20AD%20Connect%20with%20online%20Exchange%20management%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-133161%22%20slang%3D%22en-US%22%3EHi%20John%2C%20in%20my%20understanding%20youre%20Cloud%20users%20are%20locked%20for%20serveral%20e-mail%20changes.%20They've%20to%20be%20made%20from%20the%20onprem%20environment.%20So%20changes%20to%20the%20emailadres%20for%20example%20have%20to%20be%20made%20from%20onprem%20Exchange%20or%20using%20Adsiedit.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-129149%22%20slang%3D%22en-US%22%3ERe%3A%20Tips%20to%20use%20Azure%20AD%20Connect%20with%20online%20Exchange%20management%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-129149%22%20slang%3D%22en-US%22%3E%3CP%3EI%20am%20curious%20about%20what%20the%20issue%20is.%20We%20use%20Azure%20AD%20Connect.%20We%20turned%20off%20our%20on-premise%20Exchange%20server%20a%20year%20ago%20and%20haven't%20had%20any%20issues.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBefore%20we%20did%20it%20I%20was%20a%20bit%20concerned%20because%20I%20read%20that%20you%20should%20keep%20an%20on-premise%20Exchange%20server%20but%20our%20IT%20people%20said%20it%20would%20be%20fine%20and%20it%20has%20been.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhat%20specifically%20is%20supposed%20to%20break%20if%20you%20don't%20have%20an%20on-premise%20exchange%20server%3F%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-122699%22%20slang%3D%22en-US%22%3ERe%3A%20Tips%20to%20use%20Azure%20AD%20Connect%20with%20online%20Exchange%20management%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-122699%22%20slang%3D%22en-US%22%3EThanks%20all.%20This%20is%20also%20a%20problem%20for%20us%20as%20MSP%20because%20we%20now%20have%20to%20maintain%20an%20extra%20server%20with%20its%20complexity.%20But%20we%20will%20be%20pati%C3%ABnt!%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-122449%22%20slang%3D%22en-US%22%3ERe%3A%20Tips%20to%20use%20Azure%20AD%20Connect%20with%20online%20Exchange%20management%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-122449%22%20slang%3D%22en-US%22%3E%3CP%3EIf%20all%20you%20want%20is%20password%20synchronization%20you%20can%20look%20at%20deploying%20the%20Windows%20Server%20Essentials%20role%20(not%20the%20server%20edition%2C%20just%20the%20server%20role)%20and%20connect%20on-prem%20AD%20accounts%20with%20Office%20365%20accounts.%20This%20will%20sync%20password%20changes%20to%20the%20cloud%2C%20but%20isn't%20the%20full%20directory%20sync%20that%20you%20get%20with%20Azure%20AD%20Connect.%20This%20works%20for%20small%20customers%2C%20which%20I%20imagine%20are%20the%20ones%20most%20feeling%20the%20pain%20of%20having%20to%20keep%20an%20on-prem%20Exchange%20server.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20you%20want%20the%20full%20directory%20sync%20experience%2C%20for%20now%20you%20need%20an%20on-prem%20Exchange%20server.%20Microsoft%20made%20announcements%20at%20Ignite%202016%20and%20again%20at%20Ignite%202017%20with%20their%20plans%20to%20create%20a%20%22hybrid%20connector%22%20that%20will%20do%20away%20with%20the%20on-prem%20Exchange%20server%20requirement%2C%20but%20that%20is%20still%20probably%20at%20least%20a%20year%20away%20(perhaps%20we'll%20get%20the%20good%20news%20at%20Ignite%202018).%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-122293%22%20slang%3D%22en-US%22%3ERe%3A%20Tips%20to%20use%20Azure%20AD%20Connect%20with%20online%20Exchange%20management%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-122293%22%20slang%3D%22en-US%22%3E%3CP%3EIt's%20a%20very%20common%20ask%2C%20but%20unfortunately%20there's%20no%20other%20way.%20At%20least%20for%20the%20time%20being%2C%20if%20you%20want%20to%20manage%2Fsync%20password%20from%20your%20AD%2C%20you%20have%20to%20do%20the%20management%20of%20Exchange%20attributes%20there%20as%20well.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Joris van der Sligte
Occasional Contributor

Hi all, I've a question about setting up Azure AD Connect and maintenance of Exchange Online.

We're a MSP with allot of customers running an on-prem AD and using Exchange Online (Office365 bundles) for their e-mail.

For the convenience of the end-users we would like to enable password sync through Azure AD Connect. But when we set this up we have to do the Exchange management on-prem. And that's something we want to move away from (even with the free Exchange license key....). 

How are you guys/girls dealing with this issue? Or do I miss something and can I just sync the passwords and still do the management of Exchange Online?

 

6 Replies

It's a very common ask, but unfortunately there's no other way. At least for the time being, if you want to manage/sync password from your AD, you have to do the management of Exchange attributes there as well.

Solution

If all you want is password synchronization you can look at deploying the Windows Server Essentials role (not the server edition, just the server role) and connect on-prem AD accounts with Office 365 accounts. This will sync password changes to the cloud, but isn't the full directory sync that you get with Azure AD Connect. This works for small customers, which I imagine are the ones most feeling the pain of having to keep an on-prem Exchange server.

 

If you want the full directory sync experience, for now you need an on-prem Exchange server. Microsoft made announcements at Ignite 2016 and again at Ignite 2017 with their plans to create a "hybrid connector" that will do away with the on-prem Exchange server requirement, but that is still probably at least a year away (perhaps we'll get the good news at Ignite 2018).

Thanks all. This is also a problem for us as MSP because we now have to maintain an extra server with its complexity. But we will be patiënt!

I am curious about what the issue is. We use Azure AD Connect. We turned off our on-premise Exchange server a year ago and haven't had any issues. 

 

Before we did it I was a bit concerned because I read that you should keep an on-premise Exchange server but our IT people said it would be fine and it has been.

 

What specifically is supposed to break if you don't have an on-premise exchange server? 

Hi John, in my understanding youre Cloud users are locked for serveral e-mail changes. They've to be made from the onprem environment. So changes to the emailadres for example have to be made from onprem Exchange or using Adsiedit.

Hi Joris,

 

Adsiedit is not supported by Microsoft. 

 

You can view here the article that describe a decommission of Exchange Server.

 

https://technet.microsoft.com/en-us/library/dn931280(v=exchg.150).aspx

Related Conversations
Calendar not available for older AD accounts
_jancis in Microsoft Teams on
0 Replies
RSAT missing DNS Server Tools?
Oliver Stähr in Windows Server Insiders on
51 Replies
Outlook (365) Need Password - Issue
Muhammad Ali Khan in Office 365 on
20 Replies
Accessing a shared mailbox from a mobile device
Hexsysadmins in Office 365 on
14 Replies
Reporting on Project Online (PWA) Timesheets
Andy Dennis in Project on
3 Replies
Adding License to Existing KMS Host
Mitch Sprague in Windows Server for IT Pro on
4 Replies