SOLVED
Home

Hybrid Decommission questions

%3CLINGO-SUB%20id%3D%22lingo-sub-563357%22%20slang%3D%22en-US%22%3EHybrid%20Decommission%20questions%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-563357%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Community%2C%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOne%20of%20our%20customer%20raised%20the%20below%20query%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EEnvironment%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOn%20prem%20AD%20installed%2C%26nbsp%3B%3C%2FP%3E%3CP%3EHybrid%20is%20deployed.%3C%2FP%3E%3CP%3EExchange%202010%20is%20still%20running%2C%20but%20all%20the%20mailboxes%20are%20migrated%20to%20Office%20365.%3C%2FP%3E%3CP%3EAAD%20sync%20is%20running%20%2B%20Password%20sync%20is%20enabled.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EPlan%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHybrid%20is%20going%20to%20be%20decommissioned.%3C%2FP%3E%3CP%3EGoing%20to%20keep%20one%20on-prem%20(Exchn%202010)%20according%20to%20MS%20recommendation%20after%20Hybrid%20decommission.%3C%2FP%3E%3CP%3EWould%20like%20to%20use%20the%20password%20sync%20option%20even%20after%20Hybrid%20decommission.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EQuestions%3A%3C%2FP%3E%3CP%3E1.%20What%20is%20the%20best%20practice%20to%20create%20new%20users%20who%20must%20use%20password%20sync%20option%3F%3C%2FP%3E%3CP%3EIs%20it%20okay%20to%20create%20it%20on%20on-prem%20AD%20and%20sync%20it%2C%20then%20enable%20mailbox%20on%20office%20365%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B(or)%3C%2FP%3E%3CP%3EIs%20it%20good%20to%20create%20remote%20mailbox%20so%20that%20on-prem%20credentials%20can%20still%20be%20used%20through%20password%20sync%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E2.%20Do%20I%20need%20to%20upgrade%20the%20existing%20exchange%202010%20to%20the%20latest%3F%20If%20so%2C%20can%20I%20upgrade%20the%20existing%20exchange%202010%20to%20the%20latest%20through%20Hybrid%20(using%20Free%20key%20option)%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20pointers%20would%20be%20of%20great%20help!!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMany%20thanks%20in%20advance.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-563357%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EHybrid%20Decommission%20questions%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-563400%22%20slang%3D%22en-US%22%3ERe%3A%20Hybrid%20Decommission%20questions%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-563400%22%20slang%3D%22en-US%22%3EHi%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F301435%22%20target%3D%22_blank%22%3E%40Newlife%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3E1.)%20See%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FExchange%2FThe-question-nobody-dares-to-ask-How-do-you-create-a-new-user-in%2Ftd-p%2F54596%22%20target%3D%22_blank%22%3Ehttps%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FExchange%2FThe-question-nobody-dares-to-ask-How-do-you-create-a-new-user-in%2Ftd-p%2F54596%3C%2FA%3E.%20There%20is%20a%20discussion%20on%20this%20topic%20here%20but%20the%20general%20consensus%20is%20to%20use%20the%20method%20which%20works%20for%20your%20management%20workflows.%3CBR%20%2F%3E%3CBR%20%2F%3E2.)%20Exchange%202010%20is%20supported%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fexchange%2Fhybrid-deployment-prerequisites%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fexchange%2Fhybrid-deployment-prerequisites%3C%2FA%3E.%20As%20stated%20in%20the%20article%3A%20Hybrid%20deployments%20require%20the%20latest%20cumulative%20update%20or%20update%20rollup%20available%20for%20the%20version%20of%20Exchange%20you%20have%20installed%20in%20your%20on-premises%20organization.%20If%20you%20can't%20install%20the%20latest%20cumulative%20update%20or%20update%20rollup%2C%20the%20immediately%20previous%20release%20is%20also%20supported.%20Older%20cumulative%20updates%20or%20update%20rollups%20aren't%20supported.%3CBR%20%2F%3E%3CBR%20%2F%3EHope%20that%20answers%20your%20questions!%3CBR%20%2F%3E%3CBR%20%2F%3EBest%2C%20Chris%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-565697%22%20slang%3D%22en-US%22%3ERe%3A%20Hybrid%20Decommission%20questions%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-565697%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAdding%20little%20more%20clarity%20here%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3EQuestion%201.%3C%2FSTRONG%3E%20Using%20Remote-Mailbox%2C%20can%20this%20be%20done%20after%20Exchange%20Hybrid%20has%20been%20decommissioned%3F%20What%20server%20roles%20must%20be%20left%20on%20an%20Exchange%20management%20server%20in%20order%20to%20do%20this%20as%20remote-mailbox%20is%20only%20available%20via%20Exchange%202010%20PowerShell%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3EQuestion%202.%3C%2FSTRONG%3E%20Do%20I%20simply%20install%20Exchange%202016%20on%20the%20hybrid%20server%20to%20get%20access%20to%20the%20key%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECan%20you%20help%20in%20this%20case%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks!!%3C%2FP%3E%3C%2FLINGO-BODY%3E
Newlife
Contributor

Hi Community, 

 

One of our customer raised the below query:

 

Environment:

 

On prem AD installed, 

Hybrid is deployed.

Exchange 2010 is still running, but all the mailboxes are migrated to Office 365.

AAD sync is running + Password sync is enabled.

 

Plan:

 

Hybrid is going to be decommissioned.

Going to keep one on-prem (Exchn 2010) according to MS recommendation after Hybrid decommission.

Would like to use the password sync option even after Hybrid decommission.

 

Questions:

1. What is the best practice to create new users who must use password sync option?

Is it okay to create it on on-prem AD and sync it, then enable mailbox on office 365                   

                                                 (or)

Is it good to create remote mailbox so that on-prem credentials can still be used through password sync?

 

2. Do I need to upgrade the existing exchange 2010 to the latest? If so, can I upgrade the existing exchange 2010 to the latest through Hybrid (using Free key option)?

 

Any pointers would be of great help!!

 

Many thanks in advance.

2 Replies
Solution
Hi @Newlife

1.) See https://techcommunity.microsoft.com/t5/Exchange/The-question-nobody-dares-to-ask-How-do-you-create-a.... There is a discussion on this topic here but the general consensus is to use the method which works for your management workflows.

2.) Exchange 2010 is supported https://docs.microsoft.com/en-us/exchange/hybrid-deployment-prerequisites. As stated in the article: Hybrid deployments require the latest cumulative update or update rollup available for the version of Exchange you have installed in your on-premises organization. If you can't install the latest cumulative update or update rollup, the immediately previous release is also supported. Older cumulative updates or update rollups aren't supported.

Hope that answers your questions!

Best, Chris

Hi 

 

Adding little more clarity here:

 

Question 1. Using Remote-Mailbox, can this be done after Exchange Hybrid has been decommissioned? What server roles must be left on an Exchange management server in order to do this as remote-mailbox is only available via Exchange 2010 PowerShell

 

Question 2. Do I simply install Exchange 2016 on the hybrid server to get access to the key?

 

Can you help in this case?

 

Thanks!!