Home

Hybrid Exchange and shared mailboxes

%3CLINGO-SUB%20id%3D%22lingo-sub-727898%22%20slang%3D%22en-US%22%3EHybrid%20Exchange%20and%20shared%20mailboxes%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-727898%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20all%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ENeeded%20some%20advice%20please.%20I%20have%20an%20Exchange%202010%20hybrid%20setup.%20On%20my%20onprem%20environment%20I%20had%20mailboxes%20that%20were%20essentially%20shared%20with%20a%20number%20of%20staff.%20In%20order%20for%20me%20to%20migrate%20those%20mailboxes%20I%20had%20to%20assign%20an%20office%20365%20license%20to%20it.%20Now%20that%20they%20are%20in%20the%20cloud%20I%20would%20like%20to%20convert%20them%20to%20actual%20shared%20mailboxes%20in%20office%20365.%20So%20I%20converted%20them%20to%20a%20shared%20mailbox%20and%20removed%20the%20license.%20Problem%20is%20I%20now%20want%20to%20remove%20the%20onprem%20AD%20object%20but%20if%20I%20delete%20the%20AD%20account%20the%20shared%20mailbox%20in%20office%20365%20gets%20deleted.%20How%20can%20I%20work%20around%20this%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20appreciate%20any%20advice...%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-727898%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EExchange%20Online%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EExchange%20Server%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EHybrid%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-727987%22%20slang%3D%22en-US%22%3ERe%3A%20Hybrid%20Exchange%20and%20shared%20mailboxes%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-727987%22%20slang%3D%22en-US%22%3E%3CP%3EHi%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F119208%22%20target%3D%22_blank%22%3E%40Navishkar%20Sadheo%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CH2%20id%3D%22toc-hId-1789791133%22%20id%3D%22toc-hId-1789791133%22%20id%3D%22toc-hId-1789791133%22%20id%3D%22toc-hId-1789791133%22%20id%3D%22toc-hId-1789791133%22%20id%3D%22toc-hId-1789791133%22%3EConvert%20a%20user's%20mailbox%20in%20a%20hybrid%20environment%3C%2FH2%3E%3CP%20class%3D%22%22%3E%22If%20this%20shared%20mailbox%20is%20in%20a%20hybrid%20environment%2C%20we%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSTRONG%3Estrongly%20recommend%3C%2FSTRONG%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E(almost%20require!)%20that%20you%20move%20the%20user%20mailbox%20back%20to%20on-premises%2C%20convert%20the%20user%20mailbox%20to%20a%20shared%20mailbox%2C%20and%20then%20move%20the%20shared%20mailbox%20back%20to%20the%20cloud.%3C%2FP%3E%3CP%20class%3D%22%22%3EHere's%20why%3A%20if%20you%20convert%20the%20mailbox%20in%20the%20cloud%2C%20it%20can%20get%20converted%2C%20but%20on-premises%20still%20thinks%20the%20mailbox%20is%20the%20user%20mailbox%2C%20because%20the%20new%20reality%20does%20not%20sync%20back%20to%20on-premises.%3C%2FP%3E%3CP%3EUsually%20this%20is%20not%20a%20problem%2C%20but%20there%20are%20some%20scenarios%20where%20the%20on-premises%20attributes%20(which%20think%20that%20the%20mailbox%20is%20the%20user%20mailbox)%20can%20overwrite%20the%20new%20cloud%20versions%20of%20those%20attributes%2C%20and%20as%20a%20result%2C%20the%20mailbox%20might%20convert%20back.%20This%20is%20a%20problem%20because%20user%20mailboxes%20require%20licenses%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSTRONG%3Eor%20they%20are%20soft%20deleted%20after%2030%20days%3C%2FSTRONG%3E!%3C%2FP%3E%3CP%3EWe've%20addressed%20most%20of%20the%20reasons%20why%20this%20happens%20but%20it%20still%20CAN%20happen%2C%20although%20infrequently.%20It's%20best%20to%20be%20safe%20and%20move%20the%20mailbox%20back%20to%20on-premises.%22%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESource%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-gb%2Foffice365%2Fadmin%2Femail%2Fconvert-user-mailbox-to-shared-mailbox%3FredirectSourcePath%3D%25252fen-us%25252farticle%25252fConvert-a-user-mailbox-to-a-shared-mailbox-2e122487-e1f5-4f26-ba41-5689249d93ba%26amp%3Bview%3Do365-worldwide%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-gb%2Foffice365%2Fadmin%2Femail%2Fconvert-user-mailbox-to-shared-mailbox%3FredirectSourcePath%3D%25252fen-us%25252farticle%25252fConvert-a-user-mailbox-to-a-shared-mailbox-2e122487-e1f5-4f26-ba41-5689249d93ba%26amp%3Bview%3Do365-worldwide%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you%26nbsp%3B%3C%2FP%3E%3CP%3EDav%2C%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-728097%22%20slang%3D%22en-US%22%3ERe%3A%20Hybrid%20Exchange%20and%20shared%20mailboxes%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-728097%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F340070%22%20target%3D%22_blank%22%3E%40Dav1988%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20Dav.%20I%20really%20don't%20want%20to%20migrate%20these%20mailboxes%20back%20to%20onprem.%20Surely%20there%20must%20be%20a%20another%20way.%20If%20I%20move%20them%20back%20to%20onprem%2C%20convert%20them%20to%20shared%20and%20move%20them%20to%20Office%20365%20would%20I%20then%20be%20able%20to%20delete%20the%20onprem%20AD%20accounts%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-728122%22%20slang%3D%22en-US%22%3ERe%3A%20Hybrid%20Exchange%20and%20shared%20mailboxes%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-728122%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F340070%22%20target%3D%22_blank%22%3E%40Dav1988%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAlso%20what%20happens%20to%20all%20the%20permissions%20currently%20set%20on%20this%20mailbox%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-744342%22%20slang%3D%22en-US%22%3ERe%3A%20Hybrid%20Exchange%20and%20shared%20mailboxes%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-744342%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F119208%22%20target%3D%22_blank%22%3E%40Navishkar%20Sadheo%3C%2FA%3E%26nbsp%3BHi%2C%20that%20is%20the%20official%20way%20to%20tackle%20this%20issue.%20There%20are%20some%20unsupported%20ways%20to%20tackle%20this%20problem%2C%20which%20are%20of%20course%20not%20recommended.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIn%20response%20to%20if%20you%20could%20remove%20the%20AD-Account%20associated%20with%20that%20%22new%22%20shared%20mailbox%2C%20the%20answer%20is%20no.%20Not%20without%20removing%20the%20shared%20mailbox%20in%20itself.%20The%20account%20however%20will%20be%20disabled%20when%20converted%20to%20a%20shared%20mailbox%20instead.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAs%20for%20permissions%2C%20there%20should%20not%20be%20any%20problems%20regarding%20this%20after%20the%20conversion%20has%20taken%20place.%20I%C2%B4ve%20done%20it%20multiple%20times%20on-prem.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERegards%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EViktor%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-750700%22%20slang%3D%22en-US%22%3ERe%3A%20Hybrid%20Exchange%20and%20shared%20mailboxes%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-750700%22%20slang%3D%22en-US%22%3ERemove%20AD%20object%20from%20on%20prem%20AD.%3CBR%20%2F%3EObject%20will%20be%20deleted%20from%20O365%20as%20well.%3CBR%20%2F%3EGo%20to%20%22Deleted%20Users%22%20and%20recover%20the%20deleted%20user%20in%20O365%2C%20it%20will%20be%20a%20cloud%20only%20identity%20now.%3C%2FLINGO-BODY%3E
Frequent Contributor

Hi all

 

Needed some advice please. I have an Exchange 2010 hybrid setup. On my onprem environment I had mailboxes that were essentially shared with a number of staff. In order for me to migrate those mailboxes I had to assign an office 365 license to it. Now that they are in the cloud I would like to convert them to actual shared mailboxes in office 365. So I converted them to a shared mailbox and removed the license. Problem is I now want to remove the onprem AD object but if I delete the AD account the shared mailbox in office 365 gets deleted. How can I work around this?

 

Any appreciate any advice...

5 Replies

Hi@Navishkar Sadheo 

 

Convert a user's mailbox in a hybrid environment

"If this shared mailbox is in a hybrid environment, we strongly recommend (almost require!) that you move the user mailbox back to on-premises, convert the user mailbox to a shared mailbox, and then move the shared mailbox back to the cloud.

Here's why: if you convert the mailbox in the cloud, it can get converted, but on-premises still thinks the mailbox is the user mailbox, because the new reality does not sync back to on-premises.

Usually this is not a problem, but there are some scenarios where the on-premises attributes (which think that the mailbox is the user mailbox) can overwrite the new cloud versions of those attributes, and as a result, the mailbox might convert back. This is a problem because user mailboxes require licenses or they are soft deleted after 30 days!

We've addressed most of the reasons why this happens but it still CAN happen, although infrequently. It's best to be safe and move the mailbox back to on-premises."

 

Source https://docs.microsoft.com/en-gb/office365/admin/email/convert-user-mailbox-to-shared-mailbox?redire...

 

Thank you 

Dav,

@Deleted 

 

Thanks Dav. I really don't want to migrate these mailboxes back to onprem. Surely there must be a another way. If I move them back to onprem, convert them to shared and move them to Office 365 would I then be able to delete the onprem AD accounts?

@Deleted 

 

Also what happens to all the permissions currently set on this mailbox?

@Navishkar Sadheo Hi, that is the official way to tackle this issue. There are some unsupported ways to tackle this problem, which are of course not recommended.

 

In response to if you could remove the AD-Account associated with that "new" shared mailbox, the answer is no. Not without removing the shared mailbox in itself. The account however will be disabled when converted to a shared mailbox instead.

 

As for permissions, there should not be any problems regarding this after the conversion has taken place. I´ve done it multiple times on-prem.

 

Regards,

 

Viktor

Remove AD object from on prem AD.
Object will be deleted from O365 as well.
Go to "Deleted Users" and recover the deleted user in O365, it will be a cloud only identity now.