Home

Enabling Cross-premises delegate access

%3CLINGO-SUB%20id%3D%22lingo-sub-189696%22%20slang%3D%22en-US%22%3EEnabling%20Cross-premises%20delegate%20access%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-189696%22%20slang%3D%22en-US%22%3E%3CP%3EI%20am%20trying%20to%20enable%20cross-premises%20delegate%20access%20in%20my%20organization%20(specifically%20folder%20level%20permission)%2C%20but%20my%20experience%20is%20not%20matching%20what%20I%20have%20seen%20documented%20and%20was%20hoping%20others%20might%20have%20ran%20into%20this%20already.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EFrom%20my%20understanding%2C%20in%20order%20to%20allow%20a%20cloud%20user%20to%20add%20an%20on-premises%20user%20as%20a%20delegate%2C%20you%20simply%20need%20to%20set%20the%20following%20on-prem%3A%3C%2FP%3E%3CP%3E%3CSTRONG%3ESet-OrganizationConfig%20-ACLableSyncedObjectEnabled%20%24true%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAnd%20to%20enable%20on-prem%20users%20to%20add%20a%20cloud%20user%20as%20a%20delegate%20you%20simply%20need%20to%20do%20this%20for%20every%20user%20that%20was%20migrated%20prior%20to%20setting%20'ACLableSyncedObjectEnabled'%20to%20%24true%3A%3C%2FP%3E%3CP%3E%3CSTRONG%3EGet-RemoteMailbox%20%7C%20ForEach%20%7B%20Get-AdUser%20-Identity%20%24_.Guid%20%7C%20Set-ADObject%20-Replace%20%40%7BmsExchRecipientDisplayType%3D-1073741818%7D%7D%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHowever%2C%20what%20I%20am%20finding%20is%20that%20while%20the%20second%20thing%20is%20working%20(on-prem%20users%20can%20add%20cloud%20users%20as%20delegates)%2C%20the%20first%20is%20not%20(cloud%20users%20still%20can't%20assign%20delegate%20permissions%20to%20an%20on-prem%20user).%26nbsp%3B%20If%20you%20try%20the%20users%20still%20appear%20in%20the%20GAL%20like%3A%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20199px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F33451iB36DDEA3D78E8345%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22GALsnip.JPG%22%20title%3D%22GALsnip.JPG%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3EAnd%20trying%20to%20add%20them%20as%20a%20delegate%20results%20in%3A%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20442px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F33453iDAD20FFB4DC01F31%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22nonlocalusererror.JPG%22%20title%3D%22nonlocalusererror.JPG%22%20%2F%3E%3CSPAN%20class%3D%22lia-inline-image-caption%22%20onclick%3D%22event.preventDefault()%3B%22%3Enon-local%20users%20cannot%20be%20given%20rights%20on%20this%20server.%3C%2FSPAN%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3EIs%20there%20an%20undocumented%20requirement%20somewhere%20that%20I%20am%20missing%3F%3C%2FP%3E%3CP%3EWe%20are%20currently%20running%20Exchange%202013%20CU19%20on-premises.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-189696%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3E2013%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EExchange%20Online%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EExchange%20Server%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EHybrid%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-196356%22%20slang%3D%22en-US%22%3ERe%3A%20Enabling%20Cross-premises%20delegate%20access%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-196356%22%20slang%3D%22en-US%22%3EI%20did%20finally%20get%20a%20response%20today%20that%20they%20encountered%20problems%20with%20the%20initial%20rollout%20of%20the%20feature%20(the%20one%20scheduled%20to%20be%20complete%20at%20the%20end%20of%20April).%20The%20best%20they%20could%20give%20me%20regarding%20an%20ETA%20was%20that%20they%20might%20be%20resuming%20rollout%20end%20of%20Q2%202018.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-196324%22%20slang%3D%22en-US%22%3ERe%3A%20Enabling%20Cross-premises%20delegate%20access%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-196324%22%20slang%3D%22en-US%22%3E%3CP%3ENo%20satisfactory%20resolution%20for%20my%20support%20request.%26nbsp%3B%26nbsp%3BI%20have%20moved%20on%20to%20trying%20to%20work%20around%20this%20problem%20for%20migrating%20delegates%20and%20Managers.%26nbsp%3B%20We%20are%20going%20to%20have%20to%20try%20and%20move%20them%20all%20together%20in%20batches%20of%20interconnected%20accounts.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EUnfortunately%20this%20is%20all%20I%20received%20for%20an%20explanation%26nbsp%3Bwhen%20they%20archived%20my%20case%2C%20I%20haven't%20added%20anything%20on%20the%20feedback%20page%20yet%3A%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIssue%3A%3C%2FP%3E%3CP%3Eassign%20on-prem%20delegates%20from%20o365%20mailbox.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EResolution%3A%3C%2FP%3E%3CP%3EOutlook%20delegate%20permission%20wont%20work%20in%20cross-premises%20in%20Office%20365.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWould%20request%20you%20to%20update%20feedback%20or%20suggestions%20regarding%20the%20Product%20or%20the%20services%2C%20you%20can%20certainly%20provide%20your%20Feedback%20and%20Suggestions%20by%20clicking%20on%20the%20link%20below%20as%20many%20features%20of%20the%20current%20program%20were%20designed%20and%20upgraded%20based%20on%20customer%20feedback.%20We%20strive%20to%20capture%20any%20product%20issues%20or%20feedback%20so%20as%20to%20ensure%20that%20we%20are%20continuously%20developing%20Microsoft%20products%20to%20meet%20customer%20needs.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EFeedback%20Link%20%3A%20%3CA%20href%3D%22https%3A%2F%2Foffice365.uservoice.com%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Foffice365.uservoice.com%2F%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-196302%22%20slang%3D%22en-US%22%3ERe%3A%20Enabling%20Cross-premises%20delegate%20access%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-196302%22%20slang%3D%22en-US%22%3E%3CP%3EDid%20MS%20support%20provide%20any%20sort%20of%20resolution%20or%20explanation%20for%20the%20problem%3F%26nbsp%3B%20I've%20had%20a%20case%20open%20with%20them%20for%20a%20while%20and%20while%20the%20issue%20has%20been%20escalated%2C%20they%20still%20haven't%20been%26nbsp%3Bable%20to%20provide%20me%20with%20anything.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-191142%22%20slang%3D%22en-US%22%3ERe%3A%20Enabling%20Cross-premises%20delegate%20access%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-191142%22%20slang%3D%22en-US%22%3E%3CP%3EI%20took%20your%20advice%20and%20opened%20an%20O365%20service%20request.%26nbsp%3B%20I%20was%20informed%20by%20Microsoft%20support%20that%20there%20is%20not%20an%20update%20being%20rolled%20out%20that%20will%20fix%20this%20particular%20problem%20with%20assigning%20delegate%20permissions%20from%20Outlook.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-190774%22%20slang%3D%22en-US%22%3ERe%3A%20Enabling%20Cross-premises%20delegate%20access%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-190774%22%20slang%3D%22en-US%22%3E%3CP%3EIf%20the%20on-prem%20mailboxes%20no%20longer%20have%20that%20red%20slash%20over%20them%20when%20adding%20as%20delegates%2C%20then%20you%20know%20your%20tenant%20is%20enabled.%20%3A)%3C%2Fimg%3E%26nbsp%3B%20I%20know%20that%20sounds%20snide%2C%20but%20its%20not%20meant%20to%20be%2C%20its%20realty%20the%20only%20true%20indicator.%26nbsp%3B%20If%20that%20isn't%20true%20for%20you%2C%20you%20could%20always%20open%20a%20case%20with%20365%20and%20ask%20them%20to%20check%20on%20it%20%2F%20enable%20it.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-190677%22%20slang%3D%22en-US%22%3ERe%3A%20Enabling%20Cross-premises%20delegate%20access%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-190677%22%20slang%3D%22en-US%22%3E%3CP%3EIs%20the%20way%20to%20check%20if%20your%20tenant%20has%20been%20enabled%20to%20run%20G%3CSPAN%3Eet-OrganizationConfig%3C%2FSPAN%3E%20from%20Exchange%20Online%20PowerShell%20and%20look%20for%20the%20value%20of%26nbsp%3B%3CSPAN%3EACLableSyncedObjectEnabled%3F%26nbsp%3B%20It%20was%20set%20to%20false%20for%20my%20organization%20when%20I%20last%20checked.%3CBR%20%2F%3E%3CBR%20%2F%3EMy%20organization%20has%20the%20same%20problem%20as%20Marc's%20(on-prem%20users%20can%20add%20cloud%20users%20as%20delegates%3B%20cloud%20users%20still%20can't%20assign%20delegate%20permissions%20to%20an%20on-prem%20user).%3CBR%20%2F%3E%3CBR%20%2F%3EIs%20there%20an%20updated%20timeline%20for%20the%20roll%20out%2C%20I%20believe%20that%20I%20read%20that%20it%20should%20have%20been%20completed%20by%20April%3F%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-190517%22%20slang%3D%22en-US%22%3ERe%3A%20Enabling%20Cross-premises%20delegate%20access%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-190517%22%20slang%3D%22en-US%22%3E%3CP%3EIt%20may%20not%20be%20enabled%20in%20your%20tenant%20yet.%20You%20cant%20enable%20it%20yourself%20in%20365.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CEM%3ESet-OrganizationConfig%20-ACLableSyncedObjectEnabled%20%24true%3C%2FEM%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3Eapplies%20to%20on-prem%20only%2C%20not%20Office%20365%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-190104%22%20slang%3D%22en-US%22%3ERe%3A%20Enabling%20Cross-premises%20delegate%20access%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-190104%22%20slang%3D%22en-US%22%3E%3CP%3E%26nbsp%3BYeah%20I%20have%20seen%20that%20already%20and%20have%26nbsp%3Bset%26nbsp%3B%3CSTRONG%3EmsExchRecipientDisplayType%3C%2FSTRONG%3E%20on%26nbsp%3Ball%20migrated%20mailboxes%2C%20and%20that%20works%20for%20allowing%20o%3CSPAN%3En-premises%20users%26nbsp%3Bto%20add%20a%20cloud%20mailbox%20user%20as%20a%20delegate.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3EHowever%2C%20my%20problem%20is%20the%20reverse.%26nbsp%3B%20A%20cloud%20mailbox%20user%20is%20not%20able%20to%20add%20an%20on-premises%20user%20as%20a%20delegate.%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-190003%22%20slang%3D%22en-US%22%3ERe%3A%20Enabling%20Cross-premises%20delegate%20access%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-190003%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fsupport.microsoft.com%2Fen-gb%2Fhelp%2F4051497%2Fa-remote-mailbox-created-in-on-premises-active-directory-is-not%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fsupport.microsoft.com%2Fen-gb%2Fhelp%2F4051497%2Fa-remote-mailbox-created-in-on-premises-active-directory-is-not%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-893684%22%20slang%3D%22en-US%22%3ERe%3A%20Enabling%20Cross-premises%20delegate%20access%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-893684%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F24266%22%20target%3D%22_blank%22%3E%40Marc%20Pituley%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20Marc%2C%20this%20does%20work%20on%20Exchange%202010%20Hybrid.%3C%2FP%3E%3CP%3EYou%20will%20need%20to%20generate%20a%20new%20offline%20address%20book%20and%20delete%20the%20OAB%20from%20the%20outlook%20profile%20before%20the%20fix%20will%20take%20effect%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Marc Pituley
New Contributor

I am trying to enable cross-premises delegate access in my organization (specifically folder level permission), but my experience is not matching what I have seen documented and was hoping others might have ran into this already.

 

From my understanding, in order to allow a cloud user to add an on-premises user as a delegate, you simply need to set the following on-prem:

Set-OrganizationConfig -ACLableSyncedObjectEnabled $true

 

And to enable on-prem users to add a cloud user as a delegate you simply need to do this for every user that was migrated prior to setting 'ACLableSyncedObjectEnabled' to $true:

Get-RemoteMailbox | ForEach { Get-AdUser -Identity $_.Guid | Set-ADObject -Replace @{msExchRecipientDisplayType=-1073741818}}

 

However, what I am finding is that while the second thing is working (on-prem users can add cloud users as delegates), the first is not (cloud users still can't assign delegate permissions to an on-prem user).  If you try the users still appear in the GAL like:

GALsnip.JPG

And trying to add them as a delegate results in:

nonlocalusererror.JPGnon-local users cannot be given rights on this server.

Is there an undocumented requirement somewhere that I am missing?

We are currently running Exchange 2013 CU19 on-premises.

10 Replies

 Yeah I have seen that already and have set msExchRecipientDisplayType on all migrated mailboxes, and that works for allowing on-premises users to add a cloud mailbox user as a delegate.

However, my problem is the reverse.  A cloud mailbox user is not able to add an on-premises user as a delegate.

It may not be enabled in your tenant yet. You cant enable it yourself in 365.

 

Set-OrganizationConfig -ACLableSyncedObjectEnabled $true

 

applies to on-prem only, not Office 365

Is the way to check if your tenant has been enabled to run Get-OrganizationConfig from Exchange Online PowerShell and look for the value of ACLableSyncedObjectEnabled?  It was set to false for my organization when I last checked.

My organization has the same problem as Marc's (on-prem users can add cloud users as delegates; cloud users still can't assign delegate permissions to an on-prem user).

Is there an updated timeline for the roll out, I believe that I read that it should have been completed by April?

If the on-prem mailboxes no longer have that red slash over them when adding as delegates, then you know your tenant is enabled. :)  I know that sounds snide, but its not meant to be, its realty the only true indicator.  If that isn't true for you, you could always open a case with 365 and ask them to check on it / enable it.

I took your advice and opened an O365 service request.  I was informed by Microsoft support that there is not an update being rolled out that will fix this particular problem with assigning delegate permissions from Outlook.

Did MS support provide any sort of resolution or explanation for the problem?  I've had a case open with them for a while and while the issue has been escalated, they still haven't been able to provide me with anything.

No satisfactory resolution for my support request.  I have moved on to trying to work around this problem for migrating delegates and Managers.  We are going to have to try and move them all together in batches of interconnected accounts.

 

Unfortunately this is all I received for an explanation when they archived my case, I haven't added anything on the feedback page yet: 

 

Issue:

assign on-prem delegates from o365 mailbox.

 

Resolution:

Outlook delegate permission wont work in cross-premises in Office 365.

 

Would request you to update feedback or suggestions regarding the Product or the services, you can certainly provide your Feedback and Suggestions by clicking on the link below as many features of the current program were designed and upgraded based on customer feedback. We strive to capture any product issues or feedback so as to ensure that we are continuously developing Microsoft products to meet customer needs.

 

Feedback Link : https://office365.uservoice.com/ 

I did finally get a response today that they encountered problems with the initial rollout of the feature (the one scheduled to be complete at the end of April). The best they could give me regarding an ETA was that they might be resuming rollout end of Q2 2018.

@Marc Pituley 

 

Thanks Marc, this does work on Exchange 2010 Hybrid.

You will need to generate a new offline address book and delete the OAB from the outlook profile before the fix will take effect :)

Related Conversations