Disabling AD Account and have Exchange Mailbox disabled, is this possible????

%3CLINGO-SUB%20id%3D%22lingo-sub-2107680%22%20slang%3D%22en-US%22%3EDisabling%20AD%20Account%20and%20have%20Exchange%20Mailbox%20disabled%2C%20is%20this%20possible%3F%3F%3F%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2107680%22%20slang%3D%22en-US%22%3E%3CP%3EHey%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20are%20currently%20a%20hybrid%20environment%2C%20On-Prem%20Exchange%202016%20with%20Office%20365%20for%20App%20usage.%20We%20are%20planning%20on%20going%20full%20365%20in%20the%20future%2C%20but%20this%20is%20our%20current%20run.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20there%20a%20way%20that%20when%20you%20disable%20a%20user%20account%20in%20Active%20Directory%20for%20it%20to%20disable%20the%20mailbox%20on%20exchange%2C%20or%20delete%20it%3F%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20know%20that%20you%20can%20delete%20the%20mailbox%20and%20it%20deletes%20the%20user%20in%20AD%2C%20but%20for%20some%20reason%20it%20won't%20work%20the%20other%20way.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOur%20practice%20is%20not%20to%20delete%20an%20account%20for%20a%20period%20of%20time%2C%20only%20disable%20it.%20Currently%20we%20have%20to%20go%20into%20EAC%2C%20disable%20all%20the%20access%20and%20options%2C%20and%20the%20mailbox%20sticks%20around.%20This%20works%2C%20but%20it%20would%20be%20great%20to%20be%20able%20to%20disable%20an%20AD%20account%20and%20have%20all%20groups%2Fdistributions%20they%20are%20associated%20with%20be%20disabled%20until%20we%20decide%20to%20delete%20it.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20spoke%20with%20MSFT%20and%20they%20talked%20about%20a%20GPO%20on%20the%20Exchange%20server%2C%20but%20even%20that%20doesn't%20seem%20to%20get%20triggered%20by%20the%20AD%20account%20being%20disabled.%20They%20said%20there%20may%20be%20a%20script%20that%20can%20run%2C%20but%20I'm%20not%20having%20a%20lot%20of%20luck%20there.%20Hoping%20someone%20else%20has%20come%20across%20this%20issue%20or%20though%20process%20before%20and%20found%20a%20solution.%3C%2FP%3E%3CP%3E%3CBR%20%2F%3EThank%20you!%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2107680%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3E2016%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EExchange%20Server%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
New Contributor

Hey,

 

We are currently a hybrid environment, On-Prem Exchange 2016 with Office 365 for App usage. We are planning on going full 365 in the future, but this is our current run. 

 

Is there a way that when you disable a user account in Active Directory for it to disable the mailbox on exchange, or delete it? 

 

I know that you can delete the mailbox and it deletes the user in AD, but for some reason it won't work the other way. 

 

Our practice is not to delete an account for a period of time, only disable it. Currently we have to go into EAC, disable all the access and options, and the mailbox sticks around. This works, but it would be great to be able to disable an AD account and have all groups/distributions they are associated with be disabled until we decide to delete it. 

 

I spoke with MSFT and they talked about a GPO on the Exchange server, but even that doesn't seem to get triggered by the AD account being disabled. They said there may be a script that can run, but I'm not having a lot of luck there. Hoping someone else has come across this issue or though process before and found a solution.


Thank you! 

1 Reply

@Richochet_Rabbit 

Hi,

When you disable a mailbox, all Exchange attributes are removed from the associated user account in Active Directory.
The disconnected mailbox is hidden and marked for removal.
The disconnected mailbox is permanently deleted (purged) based on the MailboxRetention property value for the mailbox database (the default value is 30 days)

 

Disable-Mailbox "AliasName"

 

Please see below link, If you want to run the script against all Disabled users (Active Directory)..

 

Do not run this script in your production environment directly, first test in your LAB.
https://www.thatlazyadmin.com/bulk-disable-exchange-mailboxes/ 

 

Regards,
MD