On-prem Exchange needed for Azure AD Connected MS365 users with a mailbox?

%3CLINGO-SUB%20id%3D%22lingo-sub-1592602%22%20slang%3D%22en-US%22%3EOn-prem%20Exchange%20needed%20for%20Azure%20AD%20Connected%20MS365%20users%20with%20a%20mailbox%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1592602%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20have%20an%20on-prem%20active%20directory%20with%20users%20synced%20to%20MS365%20for%20their%20Office%20365%20logins.%20Works%20great.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20used%20to%20use%20Zimbra%20for%20email%2C%20so%20no%20Exchange%20server%20in%20sight.%20We%20now%20want%20to%20add%20mailboxes%20to%20the%20users%20MS365%20accounts%2C%20and%20want%20to%20confirm%20if%20we%20NEED%20a%20full-blown%20on-prem%20Exchange%202016%20server%20with%20a%20free%20hybrid%20config%20license%20just%20to%20manage%20things%20like%20email%20addresses%2C%20aliases%2C%20and%20other%20user%20attributes%20that%20are%20sourced%20from%20active%20directory%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20done%20this%20a%20few%20times%20for%20sites%20that%20already%20had%20Exchange%2C%20but%20what%20about%20MS365%20tenants%20that%20never%20had%20an%20Exchange%20server%3F%20I%20guess%20it's%20close%20to%20Scenario%202%20in%20this%20article%2C%20just%20want%20to%20confirm%20what%20is%20the%20absolute%20minimum%20we%20should%20be%20trying%20to%20get%20away%20with%20when%20adding%20this%20to%20a%20site%20with%20no%20history%20of%20Exchange%3F%20Windows%2010%20and%20Exchange%20Management%20Tools%20looked%20like%20a%20plan%2C%20but%20that%20doesn't%20include%20Exchange%20Admin%20Centre%2C%20only%20EMS%20and%20Exchange%20Toolbox.%20Is%20this%20article%20still%20the%20current%20situation%3A%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fexchange%2Fdecommission-on-premises-exchange%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fexchange%2Fdecommission-on-premises-exchange%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBest%2C%3C%2FP%3E%3CP%3EKevin%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1592602%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EExchange%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Ehybrid%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIdentity%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOn%20Premise%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1593731%22%20slang%3D%22en-US%22%3ERe%3A%20On-prem%20Exchange%20needed%20for%20Azure%20AD%20Connected%20MS365%20users%20with%20a%20mailbox%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1593731%22%20slang%3D%22en-US%22%3EYou%20technically%20don't%20need%20the%20on-prem%20Exchange.%3CBR%20%2F%3EYou%20could%20just%20expand%20the%20AD%20schema%20with%20all%20the%20necessary%20Exchange%20attributes.%3CBR%20%2F%3E%3CBR%20%2F%3EBut%20Microsoft%20requires%20Exchange%20on-prem%20for%20a%20'supported'%20scenario%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1593838%22%20slang%3D%22en-US%22%3ERe%3A%20On-prem%20Exchange%20needed%20for%20Azure%20AD%20Connected%20MS365%20users%20with%20a%20mailbox%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1593838%22%20slang%3D%22en-US%22%3EThanks%20Thijs.%20I%20appreciate%20the%20on-premise%20Exchange%20is%20not%20required%20for%20MS365%20mail%20flow%20and%20reader%20access%20(Outlook)%2C%20but%20IS%20still%20required%20for%20user%20management.%20I'm%20not%20a%20fan%20of%20half-baked%20solutions%2C%20or%20leaving%20some%20parts%20incomplete%2C%20so%20will%20confirm%20with%20our%20other%20clients%20who%20are%20on%203rd%20party%20email%20systems.%20The%20fact%20they%20will%20need%20a%20full%20blown%20Exchange%20server%20on-premise%20to%20support%20MS365%20'cloud'%20mailbox%20users%20will%20be%20a%20deal%20breaker%20for%20most%2C%20if%20not%20all%2C%20based%20solely%20on%20additional%20hardware%20and%20ongoing%20maintenance%20costs.%20Microsoft%20dropped%20the%20ball%20on%20this%20one.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1593854%22%20slang%3D%22en-US%22%3ERe%3A%20On-prem%20Exchange%20needed%20for%20Azure%20AD%20Connected%20MS365%20users%20with%20a%20mailbox%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1593854%22%20slang%3D%22en-US%22%3EYou%20can%20get%20away%20with%20just%20managing%20the%20attributes%20through%20AD%20to%20be%20honest.%3CBR%20%2F%3EI%20see%20a%20lot%20of%20customers%20doing%20it%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1593868%22%20slang%3D%22en-US%22%3ERE%3A%20On-prem%20Exchange%20needed%20for%20Azure%20AD%20Connected%20MS365%20users%20with%20a%20mailbox%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1593868%22%20slang%3D%22en-US%22%3EThat's%20maybe%20OK%20for%20individual%20users%20who%20just%20have%20one%20mailbox%20with%20one%20email%20address%2C%20but%20you%20very%20quickly%20find%20you%20can't%20do%20basic%20things%20like%20aliases%2C%20groups%2C%20etc.%20Not%20only%20because%20you'll%20need%20to%20be%20comfortable%20in%20ADSIEDIT.msc%2C%20but%20you%20won't%20have%20the%20active%20directory%20schema%20extensions%20-%20this%20is%20a%20site%20that%20never%20had%20Exchange.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1593870%22%20slang%3D%22en-US%22%3ERE%3A%20On-prem%20Exchange%20needed%20for%20Azure%20AD%20Connected%20MS365%20users%20with%20a%20mailbox%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1593870%22%20slang%3D%22en-US%22%3EYou%20don't%20need%20to%20use%20ADSI%20perse%2C%20you%20can%20change%20the%20attributes%20in%20users%20and%20computers.%3CBR%20%2F%3E%3CBR%20%2F%3EYou%20can%20just%20extend%20the%20schema%2C%20without%20installing%20Exchange.%3CBR%20%2F%3EBut%20I%20agree%2C%20that%20it's%20finicky%3C%2FLINGO-BODY%3E
Occasional Contributor

We have an on-prem active directory with users synced to MS365 for their Office 365 logins. Works great.

 

We used to use Zimbra for email, so no Exchange server in sight. We now want to add mailboxes to the users MS365 accounts, and want to confirm if we NEED a full-blown on-prem Exchange 2016 server with a free hybrid config license just to manage things like email addresses, aliases, and other user attributes that are sourced from active directory?

 

I have done this a few times for sites that already had Exchange, but what about MS365 tenants that never had an Exchange server? I guess it's close to Scenario 2 in this article, just want to confirm what is the absolute minimum we should be trying to get away with when adding this to a site with no history of Exchange? Windows 10 and Exchange Management Tools looked like a plan, but that doesn't include Exchange Admin Centre, only EMS and Exchange Toolbox. Is this article still the current situation:

https://docs.microsoft.com/en-us/exchange/decommission-on-premises-exchange 

 

Best,

Kevin 

5 Replies
You technically don't need the on-prem Exchange.
You could just expand the AD schema with all the necessary Exchange attributes.

But Microsoft requires Exchange on-prem for a 'supported' scenario
Thanks Thijs. I appreciate the on-premise Exchange is not required for MS365 mail flow and reader access (Outlook), but IS still required for user management. I'm not a fan of half-baked solutions, or leaving some parts incomplete, so will confirm with our other clients who are on 3rd party email systems. The fact they will need a full blown Exchange server on-premise to support MS365 'cloud' mailbox users will be a deal breaker for most, if not all, based solely on additional hardware and ongoing maintenance costs. Microsoft dropped the ball on this one.
You can get away with just managing the attributes through AD to be honest.
I see a lot of customers doing it
That's maybe OK for individual users who just have one mailbox with one email address, but you very quickly find you can't do basic things like aliases, groups, etc. Not only because you'll need to be comfortable in ADSIEDIT.msc, but you won't have the active directory schema extensions - this is a site that never had Exchange.
You don't need to use ADSI perse, you can change the attributes in users and computers.

You can just extend the schema, without installing Exchange.
But I agree, that it's finicky