SOLVED
Home

Exchange hybrid - Users with on-prem mailboxes are being considered 'unauthenticated'

%3CLINGO-SUB%20id%3D%22lingo-sub-195602%22%20slang%3D%22en-US%22%3EExchange%20hybrid%20-%20Users%20with%20on-prem%20mailboxes%20are%20being%20considered%20'unauthenticated'%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-195602%22%20slang%3D%22en-US%22%3E%3CP%3E%3CU%3E%3CSTRONG%3EOverview%20%2B%20Setup%20Information%3C%2FSTRONG%3E%3C%2FU%3E%3C%2FP%3E%3CP%3EThis%20issue%26nbsp%3Brelates%20to%20Exchange%2C%20SharePoint%20Online%20and%20Office%20365.%26nbsp%3B%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3CP%3EHere's%20a%20quick%20summary%20of%20our%20setup%3A%3C%2FP%3E%3CUL%3E%3CLI%3EWe've%20integrated%20our%20on-prem%20AD%20with%20Azure%20AD%20via%20Azure%20AD%20Connect.%3C%2FLI%3E%3CLI%3EWe%20have%20hybrid%20Exchange%20set%20up%2C%20with%20some%20mailboxes%20hosted%20on-prem%20(%3CSPAN%3EExchange%20Server%202010%20SP3)%3C%2FSPAN%3E%20and%20others%20hosted%20on%20Exchange%20Online.%3C%2FLI%3E%3CLI%3EInbound%20mail%20flow%20is%20directed%20to%20Exchange%20Online%20so%20that%20we%20can%20use%20EOP%20for%20anti-spam%20and%20anti-malware%20protection.%3C%2FLI%3E%3C%2FUL%3E%3CP%3E%3CU%3E%3CSTRONG%3EIssue%3C%2FSTRONG%3E%3C%2FU%3E%3C%2FP%3E%3CP%3EUsers%20with%20%3CSTRONG%3Eon-prem%20mailboxes%3C%2FSTRONG%3E%20are%20unable%20to%20send%20emails%20to%20%3CSTRONG%3Edistribution%20groups%3C%2FSTRONG%3E%20using%20the%20'%3CSTRONG%3ESend%20by%20Email%3C%2FSTRONG%3E'%20functionality%20in%20SharePoint%20Online%20sites.%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F34491iD81A7AA666E5C40E%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20alt%3D%22Send%20by%20Email%20Button.png%22%20title%3D%22Send%20by%20Email%20Button.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThese%20users%20are%20able%20to%20select%20the%20distribution%20group%20and%20send%20the%20email%2C%20however%2C%20the%20message%20is%20not%20received%20by%20any%20of%20the%20members%20of%20the%20distribution%20group.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CU%3E%3CSTRONG%3ESolution%3C%2FSTRONG%3E%3C%2FU%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDisabling%26nbsp%3Bthe%20'%3CSTRONG%3ERequire%20that%20all%20senders%20are%20authenticated%3C%2FSTRONG%3E'%20option%20in%20EMC%20%26gt%3B%20Distribution%20Groups%20%26gt%3B%20%5Bdesired%20group%5D%20%26gt%3B%20Mail%20Flow%20Settings%20%26gt%3B%20Message%20Delivery%20Restrictions%2C%20fixes%20this%20issue.%20As%20in%2C%20members%20of%20the%20group%20will%20then%20receive%20emails%20that%20users%20with%20on-prem%20mailboxes%20send%26nbsp%3Busing%20the%20'Send%20by%20Email'%20button%20on%20SharePoint%20Online.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F34492i94B154AA9ABF0413%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20alt%3D%22Distribution%20Group%20Properties.png%22%20title%3D%22Distribution%20Group%20Properties.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3EFYI%2C%20the%20equivalent%20setting%20on%20Exchange%20Online%20seems%20to%20be%20EAC%20%26gt%3B%20Recipients%20%26gt%3B%20Groups%20%26gt%3B%20%5Bdesired%20group%5D%20%26gt%3B%20Delivery%20Management%20%26gt%3B%26nbsp%3B%3CSTRONG%3ESenders%20inside%20and%20outside%20my%20organization%3C%2FSTRONG%3E.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CU%3E%3CSTRONG%3EIssue%20with%20Solution%3C%2FSTRONG%3E%3C%2FU%3E%3C%2FP%3E%3CP%3EThis%20is%20not%20an%20acceptable%20solution%20as%20it%20leaves%20the%20door%20open%20for%20external%20senders%20to%20send%20emails%20to%20all%20the%20members%20in%20our%20distribution%20groups.%20This%20is%20problematic%20for%20a%20number%20of%20reasons%2C%20particularly%20from%20a%20security%20perspective.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CU%3E%3CSTRONG%3EQuestion%3C%2FSTRONG%3E%3C%2FU%3E%3C%2FP%3E%3CP%3EIt%20seems%20like%20either%20Exchange%20Online%20or%20our%20on-prem%20Exchange%20server%20is%20deeming%20these%20users%20(who%20have%20on-prem%20mailboxes)%20to%20be%20%3CSTRONG%3Eunauthenticated%3C%2FSTRONG%3E%2F%3CSTRONG%3Eoutside%20the%20organization%3C%2FSTRONG%3E%20-%20as%20a%20reminder%2C%20our%20inbound%20mail%20flow%20goes%20through%20Exchange%20Online.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHence%2C%20how%20can%20we%20make%26nbsp%3B%3CSPAN%3EExchange%20Online%2Fon-prem%20Exchange%20consider%20these%20users%20to%20be%20%3CSTRONG%3Eauthenticated%3C%2FSTRONG%3E%2F%3CSTRONG%3Einside%20the%20organization%3C%2FSTRONG%3E%3F%26nbsp%3BI%20am%20of%20course%20also%20open%20to%20trying%20other%20solutions%20that%20might%26nbsp%3Bfix%20the%20issue%20we're%20having.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EAny%20help%20would%20be%20much%20appreciated.%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-195602%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EExchange%20Online%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EExchange%20Server%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EHybrid%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESharePoint%20Online%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-196079%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20hybrid%20-%20Users%20with%20on-prem%20mailboxes%20are%20being%20considered%20'unauthenticated'%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-196079%22%20slang%3D%22en-US%22%3E%3CDIV%20class%3D%22post-body%22%3EAdding%26nbsp%3B%3CSTRONG%3E%3CA%20href%3D%22mailto%3Ano-reply%40sharepointonline.com%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Eno-reply%40sharepointonline.com%3C%2FA%3E%3C%2FSTRONG%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3Eas%20a%20mail-enabled%20contact%20in%20AD%20and%20Exchange%20on-prem%20resolved%20the%20issue.%26nbsp%3B%3C%2FDIV%3E%3CDIV%20class%3D%22post-body%22%3E%26nbsp%3B%3C%2FDIV%3E%3CDIV%20class%3D%22post-body%22%3EIt%20seems%20like%20emails%20from%20this%20address%20are%20now%20being%20considered%20'authenticated'%20given%20that%20they%20are%20going%20through%20to%20all%20distribution%20group%20members%20without%20my%20having%20to%20disable%26nbsp%3Bthe%20'Require%20that%20all%20senders%20are%20authenticated'%20option%20for%20the%20distribution%20group%20in%20EMC.%3C%2FDIV%3E%3CDIV%20class%3D%22post-body%22%3E%26nbsp%3B%3C%2FDIV%3E%3CDIV%20class%3D%22post-body%22%3EThanks%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F58%22%20target%3D%22_blank%22%3E%40Vasil%20Michev%3C%2FA%3E%26nbsp%3B-%20not%20sure%20if%20this%20is%20what%20you%20meant%2C%20but%20it%20gave%20me%20the%20idea%20anyway.%3C%2FDIV%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-196000%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20hybrid%20-%20Users%20with%20on-prem%20mailboxes%20are%20being%20considered%20'unauthenticated'%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-196000%22%20slang%3D%22en-US%22%3EThat%20is%20indeed%20unlikely%20to%20happen.%20Thanks%20for%20pointing%20that%20out%20anyway%2C%20hopefully%20there's%20another%20workaround.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-195998%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20hybrid%20-%20Users%20with%20on-prem%20mailboxes%20are%20being%20considered%20'unauthenticated'%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-195998%22%20slang%3D%22en-US%22%3ENo%2C%20how%20can%20I%20do%20this%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-195883%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20hybrid%20-%20Users%20with%20on-prem%20mailboxes%20are%20being%20considered%20'unauthenticated'%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-195883%22%20slang%3D%22en-US%22%3E%3CP%3EMoreover%20those%20messages%20are%20sent%20from%20the%20SPO%20backend%2C%20so%20Exchange%20is%20not%20even%20involved.%20Have%20you%20tried%20allowing%20just%20the%20no-reply%40sharepointonline.com%20address%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-195711%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20hybrid%20-%20Users%20with%20on-prem%20mailboxes%20are%20being%20considered%20'unauthenticated'%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-195711%22%20slang%3D%22en-US%22%3E%3CP%3EThe%20quick%20answer%20is...you%20can't.%20Exchange%20Online%20users%20are%20not%20authenticated%20on%20premise%2C%20the%20email%20originates%20from%20Exchange%20online%20which%20is%20essentially%20a%20federated%20organisation.%20Maybe%20MS%20could%20implement%20a%20separate%20tick%20box%20for%20%22federated%20partners%22%20but%20this%20is%20unlikely%20to%20happen.%3C%2FP%3E%3C%2FLINGO-BODY%3E
mohammad housaini
Occasional Contributor

Overview + Setup Information

This issue relates to Exchange, SharePoint Online and Office 365. 

Here's a quick summary of our setup:

  • We've integrated our on-prem AD with Azure AD via Azure AD Connect.
  • We have hybrid Exchange set up, with some mailboxes hosted on-prem (Exchange Server 2010 SP3) and others hosted on Exchange Online.
  • Inbound mail flow is directed to Exchange Online so that we can use EOP for anti-spam and anti-malware protection.

Issue

Users with on-prem mailboxes are unable to send emails to distribution groups using the 'Send by Email' functionality in SharePoint Online sites.

Send by Email Button.png

 

These users are able to select the distribution group and send the email, however, the message is not received by any of the members of the distribution group.

 

Solution

 

Disabling the 'Require that all senders are authenticated' option in EMC > Distribution Groups > [desired group] > Mail Flow Settings > Message Delivery Restrictions, fixes this issue. As in, members of the group will then receive emails that users with on-prem mailboxes send using the 'Send by Email' button on SharePoint Online.

 

Distribution Group Properties.png

FYI, the equivalent setting on Exchange Online seems to be EAC > Recipients > Groups > [desired group] > Delivery Management > Senders inside and outside my organization.

 

Issue with Solution

This is not an acceptable solution as it leaves the door open for external senders to send emails to all the members in our distribution groups. This is problematic for a number of reasons, particularly from a security perspective.

 

Question

It seems like either Exchange Online or our on-prem Exchange server is deeming these users (who have on-prem mailboxes) to be unauthenticated/outside the organization - as a reminder, our inbound mail flow goes through Exchange Online.

 

Hence, how can we make Exchange Online/on-prem Exchange consider these users to be authenticated/inside the organization? I am of course also open to trying other solutions that might fix the issue we're having.

 

Any help would be much appreciated.

5 Replies

The quick answer is...you can't. Exchange Online users are not authenticated on premise, the email originates from Exchange online which is essentially a federated organisation. Maybe MS could implement a separate tick box for "federated partners" but this is unlikely to happen.

Solution

Moreover those messages are sent from the SPO backend, so Exchange is not even involved. Have you tried allowing just the no-reply@sharepointonline.com address?

That is indeed unlikely to happen. Thanks for pointing that out anyway, hopefully there's another workaround.
Adding no-reply@sharepointonline.com as a mail-enabled contact in AD and Exchange on-prem resolved the issue. 
 
It seems like emails from this address are now being considered 'authenticated' given that they are going through to all distribution group members without my having to disable the 'Require that all senders are authenticated' option for the distribution group in EMC.
 
Thanks @Vasil Michev - not sure if this is what you meant, but it gave me the idea anyway.