SOLVED

On-prem Exchange needed for Azure AD Connected MS365 user with a mailbox?

%3CLINGO-SUB%20id%3D%22lingo-sub-1592758%22%20slang%3D%22en-US%22%3EOn-prem%20Exchange%20needed%20for%20Azure%20AD%20Connected%20MS365%20user%20with%20a%20mailbox%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1592758%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20have%20an%20on-prem%20active%20directory%20with%20users%20synced%20to%20MS365%20for%20their%20Office%20365%20logins.%20Works%20great.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20used%20to%20use%20Zimbra%20for%20email%2C%20so%20no%20Exchange%20server%20in%20sight.%20We%20now%20want%20to%20add%20mailboxes%20to%20the%20users%20MS365%20accounts%2C%20and%20want%20to%20confirm%20if%20we%20NEED%20a%20full-blown%20on-prem%20Exchange%202016%20server%20with%20a%20free%20hybrid%20config%20license%20just%20to%20manage%20things%20like%20email%20addresses%2C%20aliases%2C%20and%20other%20user%20attributes%20that%20are%20sourced%20from%20active%20directory%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20done%20this%20a%20few%20times%20for%20sites%20that%20already%20had%20Exchange%2C%20but%20what%20about%20MS365%20tenants%20that%20never%20had%20an%20Exchange%20server%3F%20I%20guess%20it's%20close%20to%20Scenario%202%20in%20this%20article%2C%20just%20want%20to%20confirm%20what%20is%20the%20absolute%20minimum%20we%20should%20be%20trying%20to%20get%20away%20with%20when%20adding%20this%20to%20a%20site%20with%20no%20history%20of%20Exchange%3F%20Windows%2010%20and%20Exchange%20Management%20Tools%20looked%20like%20a%20plan%2C%20but%20that%20doesn't%20include%20Exchange%20Admin%20Centre%2C%20only%20EMS%20and%20Exchange%20Toolbox.%20Is%20this%20article%20still%20the%20current%20situation%3A%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fexchange%2Fdecommission-on-premises-exchange%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fexchange%2Fdecommission-on-premises-exchange%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBest%2C%3C%2FP%3E%3CP%3EKevin%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1592758%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EExchange%20Online%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EExchange%20Server%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Ehybrid%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1593015%22%20slang%3D%22en-US%22%3ERe%3A%20On-prem%20Exchange%20needed%20for%20Azure%20AD%20Connected%20MS365%20user%20with%20a%20mailbox%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1593015%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F761689%22%20target%3D%22_blank%22%3E%40Kevin_Davis%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20is%20a%20common%20question%2C%20and%20to%20answer%20it%20quickly%20-%20yes%20you%20need%20to%20install%20an%20Exchange%202016%20server%20(not%202019%20since%20you%20can't%20get%20a%20free%20hybrid%20key%20for%20this)%2C%20if%20you%20plan%20to%20retain%20your%20on-prem%20AD%20and%20sync%20users%20with%20Office%20365.%3C%2FP%3E%3CP%3EThe%20reason%20is%20that%20since%20you%20accounts%20originate%20in%20AD%2C%20you%20have%20to%20add%20the%20email%20attributes%20to%20those%20accounts%20in%20your%20on-prem%20AD%20(not%20in%20Azure%20AD%20or%20Exchange)%2C%20and%20the%20only%20supported%20way%20of%20doing%20that%20is%20to%20use%20the%20EAC.%20The%20are%20other%20options%20that%20are%20not%20really%20viable%3A%3C%2FP%3E%3CP%3E-%20Just%20license%20the%20users%20for%20Exchange%20online%2C%20they%20will%20get%20a%20mailbox%20and%20email%20will%20work.%20But%20you%20will%20find%20that%20you%20cannot%20do%20some%20things%20e.g.%20add%20email%20aliases%20(proxy%20addresses)%2C%20since%20they%20have%20to%20be%20added%20in%20AD%20as%20properties%20of%20the%20user%20account.%3C%2FP%3E%3CP%3E-%20Use%20other%20tools%20e.g.%20ADUC%2C%20ADSI%20edit%2C%203rd%20party%20to%20manage%20email%20the%20email%20attributes%2C%20no%20supported%20and%20you%20could%20cause%20issues.%20Exchange%20uses%20many%20different%20attributes%20so%20hard%20to%20manage%20manually%20(and%20you%20wouldn't%20even%20have%20the%20schema%20extensions).%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%20basically%3A%3C%2FP%3E%3CP%3E-%20Install%20Exchange%20on%20one%20server.%3C%2FP%3E%3CP%3E-%20Use%20the%20EAC%20to%20manage%20mailboxes%2C%20including%20mailbox%20creation%20(choose%20New%20-%20Office%20365%20mailbox%2C%20or%20new-remotemailbox%20in%20powershell%20for%20example).%3C%2FP%3E%3CP%3E-%20Wait%20for%20Microsoft%20remove%20the%20requirement%20to%20use%20Exchange%20and%20give%20us%20another%20way%20of%20doing%20it.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThere%20was%20a%20blog%20post%20about%20this%20recently%20-ERR%3AREF-NOT-FOUND-here%20where%20the%20Exchange%20team%20confirmed%20that%20for%20the%20time%20being%20you%20still%20need%20hybrid%2C%20but%20they%20are%20working%20on%20a%20solution%20(and%20have%20been%20for%20several%20years%20by%20all%20accounts)%20that%20would%20enable%20you%20to%20remove%20the%20on-prem%20Exchange%20server.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1593021%22%20slang%3D%22en-US%22%3ERe%3A%20On-prem%20Exchange%20needed%20for%20Azure%20AD%20Connected%20MS365%20user%20with%20a%20mailbox%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1593021%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F761689%22%20target%3D%22_blank%22%3E%40Kevin_Davis%3C%2FA%3E%26nbsp%3BIt%20really%20depends%20on%20which%20settings%20you%20need%20to%20configure.%20If%20the%20users%20just%20have%20one%20normal%20E-Mail%20Address%2C%20then%20you%20can%20configure%20it%20with%20the%20normal%20%22E-Mail%22%20attribute%20in%20Active%20Directory%20Users%20and%20Computers.%20If%20you%20want%20to%20add%20more%20E-Mail%20addresses%20to%20one%20user%2C%20or%20hide%20users%20in%20the%20Exchange%20address%20lists%2C%20then%20you%20need%20an%20Exchange%20Server%20to%20manage%20these%20attributes.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1593098%22%20slang%3D%22en-US%22%3ERe%3A%20On-prem%20Exchange%20needed%20for%20Azure%20AD%20Connected%20MS365%20user%20with%20a%20mailbox%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1593098%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F464343%22%20target%3D%22_blank%22%3E%40halbp%3C%2FA%3E%26nbsp%3BThanks%20for%20the%20reply.%20Much%20as%20I%20expected%2C%20given%20what%20I%20know%20about%20sites%20with%20historic%20Exchange%20servers.%3C%2FP%3E%3CP%3ESeems%20MS%20missed%20a%20trick%20here%3B%20%22So%20you're%20on%20a%203rd%20party%20email%20server%3F%20Come%20to%20MS365%20where%20everything%20is%20just%20better.%20But%20you'll%20have%20to%20provision%20a%20full%20blown%20Exchange%20server%20on-premise%20if%20you%20are%20using%20Azure%20AD%20Connect%20to%20sync%20passwords.%22%20I%20understand%20the%20reason%20behind%20it%2C%20just%20think%20there%20should%20be%20a%20MUCH%20neater%20solution%2C%20esp.%20for%20small%20companies%20that%20over%20the%20years%20landed%20up%20with%20ADDS%20on%20a%20small%20office%20file%20server%20and%20want%20to%20use%20their%20work%20login%20details%20for%20MS365%20with%20a%20mailbox.%26nbsp%3B%3C%2FP%3E%3CP%3EKevin%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1593120%22%20slang%3D%22en-US%22%3ERe%3A%20On-prem%20Exchange%20needed%20for%20Azure%20AD%20Connected%20MS365%20user%20with%20a%20mailbox%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1593120%22%20slang%3D%22en-US%22%3EThanks%20for%20the%20reply%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F353272%22%20target%3D%22_blank%22%3E%40diecknet%3C%2FA%3E%3CBR%20%2F%3EIt%20seems%20the%20limitations%20surrounding%20not%20going%20the%20full%20blown%20Exchange%202016%20server%20route%20just%20to%20manage%20a%20few%20attributes%20will%20be%20too%20limiting.%20Fortunately%20we%20have%20suitable%20hardware%20to%20add%20an%20Exchange%20server%20to%20the%20on-premises%20estate%2C%20but%20I%20can%20see%20such%20an%20expense%20coming%20as%20a%20deal-breaker%20to%20most%20small%20companies%20who%20want%20MS365%20mailboxes%20with%20logins%20synced%20from%20active%20directory.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1593236%22%20slang%3D%22en-US%22%3ERe%3A%20On-prem%20Exchange%20needed%20for%20Azure%20AD%20Connected%20MS365%20user%20with%20a%20mailbox%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1593236%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F761689%22%20target%3D%22_blank%22%3E%40Kevin_Davis%3C%2FA%3E%26nbsp%3Byes%20pretty%20much%20everyone%20has%20the%20same%20reaction%20when%20they%20find%20this%20out.%20Move%20to%20the%20cloud%2C%20but%20you%20still%20need%20to%20install%20Exchange%3F%20Crazy!%3C%2FP%3E%3CP%3EThey%20really%20need%20to%20get%20this%20fixed%2C%20but%20for%20the%20moment%20that's%20how%20you%20have%20to%20do%20it.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

We have an on-prem active directory with users synced to MS365 for their Office 365 logins. Works great.

 

We used to use Zimbra for email, so no Exchange server in sight. We now want to add mailboxes to the users MS365 accounts, and want to confirm if we NEED a full-blown on-prem Exchange 2016 server with a free hybrid config license just to manage things like email addresses, aliases, and other user attributes that are sourced from active directory?

 

I have done this a few times for sites that already had Exchange, but what about MS365 tenants that never had an Exchange server? I guess it's close to Scenario 2 in this article, just want to confirm what is the absolute minimum we should be trying to get away with when adding this to a site with no history of Exchange? Windows 10 and Exchange Management Tools looked like a plan, but that doesn't include Exchange Admin Centre, only EMS and Exchange Toolbox. Is this article still the current situation:

https://docs.microsoft.com/en-us/exchange/decommission-on-premises-exchange 

 

Best,

Kevin 

5 Replies
Best Response confirmed by Kevin_Davis (Occasional Contributor)
Solution

Hi @Kevin_Davis 

This is a common question, and to answer it quickly - yes you need to install an Exchange 2016 server (not 2019 since you can't get a free hybrid key for this), if you plan to retain your on-prem AD and sync users with Office 365.

The reason is that since you accounts originate in AD, you have to add the email attributes to those accounts in your on-prem AD (not in Azure AD or Exchange), and the only supported way of doing that is to use the EAC. The are other options that are not really viable:

- Just license the users for Exchange online, they will get a mailbox and email will work. But you will find that you cannot do some things e.g. add email aliases (proxy addresses), since they have to be added in AD as properties of the user account.

- Use other tools e.g. ADUC, ADSI edit, 3rd party to manage email the email attributes, no supported and you could cause issues. Exchange uses many different attributes so hard to manage manually (and you wouldn't even have the schema extensions).

 

So basically:

- Install Exchange on one server.

- Use the EAC to manage mailboxes, including mailbox creation (choose New - Office 365 mailbox, or new-remotemailbox in powershell for example).

- Wait for Microsoft remove the requirement to use Exchange and give us another way of doing it.

 

There was a blog post about this recently here where the Exchange team confirmed that for the time being you still need hybrid, but they are working on a solution (and have been for several years by all accounts) that would enable you to remove the on-prem Exchange server.

@Kevin_Davis It really depends on which settings you need to configure. If the users just have one normal E-Mail Address, then you can configure it with the normal "E-Mail" attribute in Active Directory Users and Computers. If you want to add more E-Mail addresses to one user, or hide users in the Exchange address lists, then you need an Exchange Server to manage these attributes.

@halbp Thanks for the reply. Much as I expected, given what I know about sites with historic Exchange servers.

Seems MS missed a trick here; "So you're on a 3rd party email server? Come to MS365 where everything is just better. But you'll have to provision a full blown Exchange server on-premise if you are using Azure AD Connect to sync passwords." I understand the reason behind it, just think there should be a MUCH neater solution, esp. for small companies that over the years landed up with ADDS on a small office file server and want to use their work login details for MS365 with a mailbox. 

Kevin

Thanks for the reply @diecknet
It seems the limitations surrounding not going the full blown Exchange 2016 server route just to manage a few attributes will be too limiting. Fortunately we have suitable hardware to add an Exchange server to the on-premises estate, but I can see such an expense coming as a deal-breaker to most small companies who want MS365 mailboxes with logins synced from active directory.

@Kevin_Davis yes pretty much everyone has the same reaction when they find this out. Move to the cloud, but you still need to install Exchange? Crazy!

They really need to get this fixed, but for the moment that's how you have to do it.