Blog Post

Exchange Team Blog
3 MIN READ

Cloud-Managed Remote Mailboxes: Now Generally Available!

The_Exchange_Team's avatar
The_Exchange_Team
Platinum Contributor
Oct 15, 2025

On Aug 20, 2025, we announced the Public Preview of Cloud-Managed Remote Mailboxes, a key step toward retiring the ‘last Exchange Server’ in your organization. The response from the community has been incredible, and your feedback has helped us make further improvements.

Today, we’re excited to announce that Cloud-Managed Remote Mailboxes are now Generally Available (GA)!

Steps to enable this feature are available here: Cloud-based management of Exchange attributes for Remote Mailboxes in hybrid environments.

Refinements

During Public Preview, Hybrid Identity Admin or Global Admin privilege was required to change the isExchangeCloudManaged property of the mailbox. If Exchange Admin privilege was used to change the above property, SOA wasn’t changed silently without explicitly showing the error on the Exchange Online PowerShell. This issue has been fixed, and going forward Exchange Admin permission privilege will be enough to change the isExchangeCloudManaged property of the mailbox.

Upcoming features

We’re continuing to invest in features to help customers remove their dependency on Last Exchange Server.

  1. Tenant-Level LES Flag. Using this organization level setting, customers will be able to ensure that all new directory-synced mailboxes are synced as users in cloud (without Exchange attributes) and are cloud-managed by default. This will eliminate the need for per-mailbox configuration and will accelerate adoption. This feature will be available for Private Preview later this month, with planned GA next month.
  2. Writeback of Exchange Attributes. Customers will be able to opt-in for writeback of critical Exchange attributes (mentioned in the documentation) from the cloud back to on-premises Active Directory via Entra Cloud Sync. This feature is aimed to ensure smooth transition for organizations having LOB apps dependent on these critical attributes in on-premises AD to work seamlessly even after moving management to the cloud. This feature will be available for Private Preview in November with planned GA early next year.

In case you want to opt-in to Private Preview / early access for any of the above features, let us know your interest through: https://forms.office.com/r/6wJJexJAZm.

Exchange Attribute SOA transfer and Object-Level SOA transfer features

As mentioned earlier, the Exchange attribute cloud management feature (mentioned in this post) is meant for those who will keep AD around and help them retire the last on-prem Exchange server. For organizations looking to eliminate on-prem AD dependency entirely, Microsoft has Object-level Source of Authority (SOA) transfer – the ability to move the entire object (user, group, contact) to cloud management in Entra ID.

  • Group SOA (cloud-managed distribution groups) is already in public preview
  • (new) User SOA (cloud-managed user objects) is also in public preview.
  • (new) Contact SOA is available for Preview. (Use the above form to share your interest in Preview.) 

These would apply if you planned to eventually manage identities in cloud as well.  It’s an important piece in the puzzle of fully decommissioning on-prem Exchange in a hybrid setup without losing management capabilities.

Next steps

If you’ve been waiting for GA to start your transition, now is the perfect time.

We’re thrilled to see how this feature will help organizations get rid of their Last Exchange Server. As always, your feedback is invaluable – please share your experiences and suggestions in the comments below.

Exchange Online Management and Exchange Hybrid teams

Published Oct 15, 2025
Version 1.0

11 Comments

  • Is there still anything in play about the previously described Phase 1 and Phase 2?

    • kumarmukesh's avatar
      kumarmukesh
      Icon for Microsoft rankMicrosoft

      So Phase 1 is the part of the feature that became generally available through this announcement.

      And Phase 2 is mentioned as upcoming feature. We are about to start Private Preview of these features shortly.
      "Upcoming features

      We’re continuing to invest in features to help customers remove their dependency on Last Exchange Server.

      1. Tenant-Level LES Flag. Using this organization level setting, customers will be able to ensure that all new directory-synced mailboxes are synced as users in cloud (without Exchange attributes) and are cloud-managed by default. This will eliminate the need for per-mailbox configuration and will accelerate adoption. This feature will be available for Private Preview later this month, with planned GA next month.
      2. Writeback of Exchange Attributes. Customers will be able to opt-in for writeback of critical Exchange attributes (mentioned in the documentation) from the cloud back to on-premises Active Directory via Entra Cloud Sync. This feature is aimed to ensure smooth transition for organizations having LOB apps dependent on these critical attributes in on-premises AD to work seamlessly even after moving management to the cloud. This feature will be available for Private Preview in November with planned GA early next year.  

      "

  • PS_Exchange_Adm's avatar
    PS_Exchange_Adm
    Copper Contributor

    Great job and thank you for bringing this feature to existence!  But it seems that it is only available for mailboxes.  Is there no corresponding flag for distribution lists, mail contacts, and mail users?  Or do we need to utilize SOA for groups to manage distribution lists in the cloud?

    • kumarmukesh's avatar
      kumarmukesh
      Icon for Microsoft rankMicrosoft

      For groups and mail contacts, the recommendation is to use Group and Contact SOA features (available in Private Preview)
      For mail users, if these are not on-premises mailboxes (as those also show up as mail users in cloud), you can use User SOA (available in Public Preview).

    • AriasJose's avatar
      AriasJose
      Brass Contributor

      It’s true that the cloud-managed capability currently applies only to mailboxes using the isExchangeCloudManaged flag. There isn’t an equivalent flag for distribution lists, mail contacts, or mail users. However, Microsoft has introduced Group SOA (Source of Authority) to handle those scenarios.

      For example, if you’ve already migrated all user mailboxes to the cloud and no longer need to manage Distribution Lists (DLs) or Mail-Enabled Security Groups (MESGs) in Active Directory, you can use Group SOA to make those groups cloud-managed. This lets you remove them from AD DS and manage them directly in Exchange Online, either through the Exchange admin center or via Exchange PowerShell modules. It’s worth noting that these mail objects can’t be managed directly from Microsoft Entra ID or through Microsoft Graph APIs, so Group SOA is the intended solution for managing DLs and MESGs fully in the cloud.

      • PS_Exchange_Adm's avatar
        PS_Exchange_Adm
        Copper Contributor

        Thank you for the confirmation AriasJose​ but unfortunately my organization is not ready to move AD groups to being cloud-managed only.  We still have some LOB apps and file shares on premise that rely on these groups for access control purposes.  So it doesn't look like we can utilize this feature just yet.

    • AriasJose's avatar
      AriasJose
      Brass Contributor

      Embrace cloud-first posture: Convert Group Source of Authority to the cloud

      https://learn.microsoft.com/en-us/entra/identity/hybrid/concept-source-of-authority-overview

       

  • Larry Heier's avatar
    Larry Heier
    Copper Contributor

    Great new Microsoft Exchange but we need the Entra team to have 100% feature parity for Entra AD sync (device sync mostly) to take advantage of this.  Do we know when this will be added in so most of us can take advantage of this long needed sync feature?

  • Gly's avatar
    Gly
    Brass Contributor

    I tried setting one account to IsExchangeCloudManaged $true, and since then, I’ve been receiving a synchronization error from Entra Connect (version 2.5.79.0). The error is:

    ExchangeManagedAttributesUpdateNotAllowed

    No additional details are provided. 

    • kumarmukesh's avatar
      kumarmukesh
      Icon for Microsoft rankMicrosoft

      Gly​ I have dm'ed you to share more info over email to debug your problem. Please check your messages.

  • MartinWildi's avatar
    MartinWildi
    Copper Contributor

    Great news, thanks!

    And now we need a small, tiny MTA to replace Exchange Server as relay onPrem (and forwarding Mails to EXO). Then all would be fine ;)