Managing Shared mailbox and resource permissions in Exchange Online with local AD

%3CLINGO-SUB%20id%3D%22lingo-sub-724721%22%20slang%3D%22en-US%22%3EManaging%20Shared%20mailbox%20and%20resource%20permissions%20in%20Exchange%20Online%20with%20local%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-724721%22%20slang%3D%22en-US%22%3E%3CP%3EI%20have%20been%20struggelig%20for%20some%20time%20managing%20permissions%20to%20shared%20mailboxes%20and%20calendars%20with%20my%20users.%3C%2FP%3E%3CP%3EFor%20most%20of%20the%20users%20it%20seems%20to%20work%20as%20expeced%2C%20but%20i%20have%20the%20odd%20user%20that%20is%20not%20getting%20the%20correct%20permissions%20to%20shared%20resources%20and%20i%20can't%20figure%20out%20why.%3C%2FP%3E%3CP%3EWe%20are%20running%20a%20local%20AD%20where%20user%20management%20is%20controlled%20by%20an%20IAM%20solution.%20All%20users%20are%20synced%20to%20Azure%20with%20AzureAD%20Connect%20and%20licensed%20for%20mailboxes.%3C%2FP%3E%3CP%3EWe%20still%20have%20one%20Exchange%20server%20locally%2C%20that%20was%20originally%20created%20to%20handle%20the%20migration%20to%20O365%20and%20then%20planned%20to%20be%20decomissoned.%20Due%20to%20the%20need%20for%20an%20SMTP%20relay%20it%20was%20kept%20in%20play%2C%20and%20as%20i%20have%20accumulated%20more%20knowledge%20about%20Exchange%20we%20realise%20that%20to%20be%20in%20an%20supported%20setup%20it%20has%20to%20stay.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EFor%20all%20our%20resources%2C%20all%20new%20shared%20mailboxes%20and%20calendar%20are%20created%20in%20EXO%20(while%20some%20migrated%20once%20still%20come%20from%20the%20local%20AD).%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20keep%20running%20into%20problems%20where%20i%20assing%20permissions%20to%20the%20resources%2C%20be%20that%20author%20rights%20to%20a%20calendar%20or%20FullAccess%20to%20a%20shared%20mailbox%2C%20where%20the%20user%20is%20not%20getting%20access%20through%20Outlook.%3CBR%20%2F%3EWhen%20we%20test%20in%20OWA%20everything%20works%20as%20expected.%3CBR%20%2F%3EFor%20testing%20purposes%20i%20have%20tried%20recreating%20the%20Outlook%20profile%20or%20deleting%20and%20re-adding%20calendars%20while%20not%20on%20the%20corporate%20network%20and%20that%20usually%20results%20in%20everyting%20working.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ELatest%20issue%2C%20and%20user%20that%20has%20had%20access%20to%20several%20shared%20calendar%20for%20months%20suddenly%20lost%20her%20access%20when%20upgrading%20to%20a%20new%20computer.%20Once%20she%20connected%20to%20an%20external%20network%20and%20removed%20and%20re-added%20the%20calendars%20all%20was%20working%20as%20expected%20again.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20can't%20figure%20out%20what%20is%20wrong%20to%20make%20this%20problem%20keep%20happening%20on%20our%20corporate%20network%2C%20and%20hope%20someone%20has%20a%20good%20idea%20or%20suggestion%20to%20where%20i%20can%20start%20to%20poke%20in%20order%20to%20make%20this%20work%20better%20for%20my%20users.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-724721%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EExchange%20Online%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EExchange%20Server%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOutlook%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Highlighted
Occasional Visitor

I have been struggelig for some time managing permissions to shared mailboxes and calendars with my users.

For most of the users it seems to work as expeced, but i have the odd user that is not getting the correct permissions to shared resources and i can't figure out why.

We are running a local AD where user management is controlled by an IAM solution. All users are synced to Azure with AzureAD Connect and licensed for mailboxes.

We still have one Exchange server locally, that was originally created to handle the migration to O365 and then planned to be decomissoned. Due to the need for an SMTP relay it was kept in play, and as i have accumulated more knowledge about Exchange we realise that to be in an supported setup it has to stay.

 

For all our resources, all new shared mailboxes and calendar are created in EXO (while some migrated once still come from the local AD).

 

I keep running into problems where i assing permissions to the resources, be that author rights to a calendar or FullAccess to a shared mailbox, where the user is not getting access through Outlook.
When we test in OWA everything works as expected.
For testing purposes i have tried recreating the Outlook profile or deleting and re-adding calendars while not on the corporate network and that usually results in everyting working.

 

Latest issue, and user that has had access to several shared calendar for months suddenly lost her access when upgrading to a new computer. Once she connected to an external network and removed and re-added the calendars all was working as expected again.

 

I can't figure out what is wrong to make this problem keep happening on our corporate network, and hope someone has a good idea or suggestion to where i can start to poke in order to make this work better for my users.

0 Replies