Manage Cloud Created Mailboxes/User On-Prem

%3CLINGO-SUB%20id%3D%22lingo-sub-1538055%22%20slang%3D%22en-US%22%3EManage%20Cloud%20Created%20Mailboxes%2FUser%20On-Prem%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1538055%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20all.%20We%20have%20an%20unusual%20situation.%20Im%20working%20with%20an%20organisation%20who%20started%20out%20M365%20fully%20cloud%20based%20-%20so%20Azure%20AD%20for%20the%20M365%20accounts%2C%20mailboxes%20etc.%20Over%20time%20they%20realised%20they%20needed%20on-prem%20fabric%20too.%20We%20deployed%20a%20local%20domain%20and%20created%20the%20cloud%20user%20identities%20within%20ADDS%2C%20and%20the%20AD%20Connect%20Sync%20has%20done%20its%20thing%20and%20the%20original%20Azure%20AD%20users%20and%20noted%20as%20being%20Windows%20Server%20AD%20managed.%20So%2C%20all%20good%20so%20far.%20So%2C%20Exchange%202019%20has%20now%20been%20deployed%20on-prem%20too%2C%20and%20configured%20in%20Full%20Hybrid%20-%20again%2C%20through%20PoC%20testing%20we%20found%20this%20to%20be%20fine%20and%20not%20overwrite%20any%20M365%20Exchange%20attributes%20for%20the%20existing%20users.%20Again%2C%20so%20far%20so%20good.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBut%20we%20face%20an%20issue%20where%20the%20M365%20mailboxes%20are%20not%20showing%20as%20'O365'%20Mailboxes%20within%20the%20on-prem%20ECP.%20If%20we%20try%20to%20move%20a%20mailbox%20from%20Cloud%20to%20On-prem%20we%20get%20an%20error%20that%20the%20Exchange%20Mailbox%20GUID%20doesnt%20exist.%20What%20we%20need%20to%20do%20it%20to%20(somehow)%20get%20the%20AADDS%20Exchange%20attributes%2C%20or%20at%20least%20a%20subset%20of%20them%2C%20applied%20to%20the%20user%20object%20in%20ADDS%20so%20Exchange%20knows%20the%20user%20has%20an%20M365%20mailbox%20and%20Exchange%20Online%20and%20On-prem%20can%20function%20properly%20-%20as%20if%20we%20went%20from%20on-prem%20to%20Cloud%2C%20rather%20than%20the%20other%20way%20around.%3C%2FP%3E%3CP%3E%3CBR%20%2F%3EWe%20have%20tried%20the%20'set-remotemailbox'%20command%20and%20passed%20just%20the%20Alias%20and%20email%20address%2C%20in%20the%20hope%20this%20would%20provide%20enough%20'local'%20info.%20It%20does%20help%20slightly%20in%20that%20the%20mailboxes%20for%20M365%20users%20are%20then%20shown%20in%20the%20local%20ECP%2C%20and%20also%20shows%20them%20as%20O365%20mailboxes%2C%20but%20you%20still%20cant%20move%20them%20about%20between%20Cloud-Prem-Cloud%20etc.%20We%20are%20also%20concerned%20if%20there%20would%20be%20other%20missing%20attributes%20which%20may%20lurk%20about%20and%20then%20cause%20issues%20further%20down%20the%20road.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20anyone%20has%20any%20experience%20with%20the%20same%20scenario%20we%20have%2C%20or%20can%20think%20of%20a%20solution%20to%20the%20problem%2C%20that%20would%20be%20appreciated.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERegards%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EPhil%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1538055%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EExchange%20Online%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EExchange%20Server%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EHybrid%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1538565%22%20slang%3D%22en-US%22%3ERe%3A%20Manage%20Cloud%20Created%20Mailboxes%2FUser%20On-Prem%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1538565%22%20slang%3D%22en-US%22%3E%3CP%3EThat's%20the%20expected%20behavior%2C%20follow%20the%20instructions%20in%20this%20article%3A%26nbsp%3B%3CA%20href%3D%22http%3A%2F%2Ftechgenix.com%2Fmigrating-standalone-office-365-tenant-exchange-2010-part1%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttp%3A%2F%2Ftechgenix.com%2Fmigrating-standalone-office-365-tenant-exchange-2010-part1%2F%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1538572%22%20slang%3D%22en-US%22%3ERe%3A%20Manage%20Cloud%20Created%20Mailboxes%2FUser%20On-Prem%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1538572%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F58%22%20target%3D%22_blank%22%3E%40Vasil%20Michev%3C%2FA%3E%26nbsp%3B-%20thank%20you.%20Good%20to%20know%20its%20the%20expected%20behaviour%20and%20we%20havent%20done%20something%20wrong.%20Thank%20you%20for%20the%20link%20-%20I%20will%20read%20through%20this%20ASAP.%20Phil%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1541306%22%20slang%3D%22en-US%22%3ERe%3A%20Manage%20Cloud%20Created%20Mailboxes%2FUser%20On-Prem%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1541306%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F58%22%20target%3D%22_blank%22%3E%40Vasil%20Michev%3C%2FA%3E%26nbsp%3BThanks%2C%20it%20wasnt%20quite%20the%20same%20scenario%20but%20I%20have%20been%20able%20to%20utilise%20this%20and%20implement%20using%20slightly%20different%20commands%20for%20the%20remote%20mailboxes.%20Thank%20you%20for%20your%20initial%20response.%20Phil%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1541382%22%20slang%3D%22en-US%22%3ERe%3A%20Manage%20Cloud%20Created%20Mailboxes%2FUser%20On-Prem%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1541382%22%20slang%3D%22en-US%22%3E%3CP%3ESo%2C%20ive%20figured%20it%20out%2C%20and%20the%20following%20will%20provide%20the%20answer%20to%20anyone%20else%20with%20the%20same%20scenario%3A-%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22ember-view%22%3E%3CSPAN%3EOkay%2C%20so%2C%20the%20process%20isn't%20too%20difficult%20(once%20you%20figure%20it%20out).%20Here%20are%20the%20details%3A-%20%3C%2FSPAN%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22ember-view%22%3E%3CSPAN%3EUse%20powershell%20to%20set%20up%20a%20remote%20pssession%20to%20M365%3A%20%3C%2FSPAN%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22ember-view%22%3E%3CSPAN%3E%24UserCredential%20%3D%20Get-Credential%20%3C%2FSPAN%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22ember-view%22%3E%3CSPAN%3E%24Session%20%3D%20New-PSSession%20-ConfigurationName%20Microsoft.Exchange%20-ConnectionUri%20%3C%2FSPAN%3E%3C%2FSPAN%3E%3CA%20href%3D%22https%3A%2F%2Foutlook.office365.com%2Fpowershell-liveid%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Foutlook.office365.com%2Fpowershell-liveid%3C%2FA%3E%3CSPAN%20class%3D%22ember-view%22%3E%3CSPAN%3E%2F%20-Credential%20%24UserCredential%20-Authentication%20Basic%20-AllowRedirection%3C%2FSPAN%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22ember-view%22%3E%3CSPAN%3EImport-PSSession%20%24Session%20-DisableNameChecking%20%3C%2FSPAN%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22ember-view%22%3E%3CSPAN%3EThen%20get%20the%20mailbox%20details%20of%20the%20user(s)%20using%20something%20like%20this%3A-%20%3C%2FSPAN%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22ember-view%22%3E%3CSPAN%3Eget-mailbox%26nbsp%3B%7C%20select%20name%2Cprimarysmtpaddress%2Cexchangeguid%2Cisdirsynced%20%3C%2FSPAN%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22ember-view%22%3E%3CSPAN%3EYou%20can%20play%20with%20the%20get-mailbox%20selection%20criteria%20%E2%80%93%20the%20%E2%80%98isdirsynced%E2%80%99%20is%20useful%20as%20it%20allows%20to%20filter%20based%20on%20whether%20the%20user%20is%20from%20on-prem%20or%20not..%20%3C%2FSPAN%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22ember-view%22%3E%3CSPAN%3EOnce%20we%20have%20this%20list%20%E2%80%93%20suggest%20you%20export%20to%20a%20csv.%20You%20can%20then%20run%20the%20following%20using%20the%20on-prem%20exchange%20powershell%20%E2%80%93%20reading%20in%20the%20csv%20and%20using%20the%20fields%20as%20variables%20maybe.%20The%20basic%20commands%20are%3A-%20%3C%2FSPAN%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22ember-view%22%3EEnable-RemoteMailbox%20username%20-RemoteRoutingAddress%20%3CA%20href%3D%22mailto%3Aemailaddress%40XXXXXXX%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Eemailaddress%40XXXXXXX%3C%2FA%3E%20%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22ember-view%22%3ESet-RemoteMailbox%20username%20-ExchangeGuid%20%3CEXCHANGEGUID%3E%20%3C%2FEXCHANGEGUID%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22ember-view%22%3EOnce%20these%20commands%20have%20been%20run%20the%20O365%20mailbox%20will%20show%20up%20on%20your%20on-prem%20ECP%20and%20function%20in%20the%20expected%20manner.%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

Hi all. We have an unusual situation. Im working with an organisation who started out M365 fully cloud based - so Azure AD for the M365 accounts, mailboxes etc. Over time they realised they needed on-prem fabric too. We deployed a local domain and created the cloud user identities within ADDS, and the AD Connect Sync has done its thing and the original Azure AD users and noted as being Windows Server AD managed. So, all good so far. So, Exchange 2019 has now been deployed on-prem too, and configured in Full Hybrid - again, through PoC testing we found this to be fine and not overwrite any M365 Exchange attributes for the existing users. Again, so far so good. 

 

But we face an issue where the M365 mailboxes are not showing as 'O365' Mailboxes within the on-prem ECP. If we try to move a mailbox from Cloud to On-prem we get an error that the Exchange Mailbox GUID doesnt exist. What we need to do it to (somehow) get the AADDS Exchange attributes, or at least a subset of them, applied to the user object in ADDS so Exchange knows the user has an M365 mailbox and Exchange Online and On-prem can function properly - as if we went from on-prem to Cloud, rather than the other way around.


We have tried the 'set-remotemailbox' command and passed just the Alias and email address, in the hope this would provide enough 'local' info. It does help slightly in that the mailboxes for M365 users are then shown in the local ECP, and also shows them as O365 mailboxes, but you still cant move them about between Cloud-Prem-Cloud etc. We are also concerned if there would be other missing attributes which may lurk about and then cause issues further down the road.

 

If anyone has any experience with the same scenario we have, or can think of a solution to the problem, that would be appreciated.

 

Regards

 

Phil

4 Replies
Highlighted

That's the expected behavior, follow the instructions in this article: http://techgenix.com/migrating-standalone-office-365-tenant-exchange-2010-part1/

Highlighted

@Vasil Michev - thank you. Good to know its the expected behaviour and we havent done something wrong. Thank you for the link - I will read through this ASAP. Phil

Highlighted

@Vasil Michev Thanks, it wasnt quite the same scenario but I have been able to utilise this and implement using slightly different commands for the remote mailboxes. Thank you for your initial response. Phil

Highlighted

So, ive figured it out, and the following will provide the answer to anyone else with the same scenario:-

 

Okay, so, the process isn't too difficult (once you figure it out). Here are the details:-

Use powershell to set up a remote pssession to M365:

 

$UserCredential = Get-Credential

$Session = New-PSSession -ConfigurationName Microsoft.Exchange -ConnectionUri https://outlook.office365.com/powershell-liveid/ -Credential $UserCredential -Authentication Basic -AllowRedirection

Import-PSSession $Session -DisableNameChecking

 

Then get the mailbox details of the user(s) using something like this:-

 

get-mailbox | select name,primarysmtpaddress,exchangeguid,isdirsynced

 

You can play with the get-mailbox selection criteria – the ‘isdirsynced’ is useful as it allows to filter based on whether the user is from on-prem or not..

 

Once we have this list – suggest you export to a csv. You can then run the following using the on-prem exchange powershell – reading in the csv and using the fields as variables maybe. The basic commands are:-

 

Enable-RemoteMailbox username -RemoteRoutingAddress emailaddress@XXXXXXX

 

Set-RemoteMailbox username -ExchangeGuid <ExchangeGuid>

 

Once these commands have been run the O365 mailbox will show up on your on-prem ECP and function in the expected manner.