Access to Shared Mailbox for non trusted domain users?

%3CLINGO-SUB%20id%3D%22lingo-sub-236596%22%20slang%3D%22en-US%22%3EAccess%20to%20Shared%20Mailbox%20for%20non%20trusted%20domain%20users%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-236596%22%20slang%3D%22en-US%22%3E%3CP%3EScenario%3A%20Office365%20Tenant%3A%20abc.com%20Users%20able%20to%20access%20shared%20mailbox%20residing%20on%20trusted%20client%20domain%3A%20xyz%20(using%20Exchange%202016)%20Recently%2C%20XYZ%20has%20moved%20all%20mailboxes%20(user%20mailbox%20and%20shared%20mailbox)%20to%20its%20Office365%20Tenant%3A%20xyz.com%20Since%20then%2C%20users%20from%20abc.com%20can%20no%20longer%20access%20the%20shared%20mailboxes.%20Any%20suggestion%20on%20what%20can%20be%20done%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-236596%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EExchange%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-239469%22%20slang%3D%22en-US%22%3ERe%3A%20Access%20to%20Shared%20Mailbox%20for%20non%20trusted%20domain%20users%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-239469%22%20slang%3D%22en-US%22%3E%3CP%3EHey%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F180469%22%20target%3D%22_blank%22%3E%40Admin%20O365%3C%2FA%3E%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIn%20short%20yes.%3CBR%20%2F%3E%3CBR%20%2F%3EIf%20you%20have%20the%20organizational%20relationship%20setup%2C%20with%20all%20the%20needed%20connectors%20etc%2C%20then%20you%20can%20do%20the%20permissions%20as%20you%20are%20talking%20(to%20the%20one%20exchange%20system%20you%20own%20that%20your%20AD%20is%20linked%20too%2C%20etc).%3C%2FP%3E%3CP%3E%3CBR%20%2F%3EBut%20just%20an%20external%20domain%2C%20that%20is%20not%20in%20a%20hybrid%20setup%20with%20your%20O365%20tenant%2C%20cannot%20do%20the%20permissions.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAdam%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-239288%22%20slang%3D%22en-US%22%3ERe%3A%20Access%20to%20Shared%20Mailbox%20for%20non%20trusted%20domain%20users%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-239288%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Adam%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20for%20the%20clarity.%3C%2FP%3E%3CP%3ESo%20Office365%20Tenants%20cannot%20be%20federated%20to%20the%20external%20domain%2C%20even%20though%20they%20are%20federated%20with%20the%20on-premise%26nbsp%3BActive%20Directory%20and%20they%20are%20using%20Azure%20AD%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-236793%22%20slang%3D%22en-US%22%3ERe%3A%20Access%20to%20Shared%20Mailbox%20for%20non%20trusted%20domain%20users%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-236793%22%20slang%3D%22en-US%22%3E%3CP%3EHello%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EUnfortunately%20you%20cannot%20assign%20permissions%20to%20a%20shared%20mailbox%20for%20a%20user%20that%20rests%20outside%20of%20the%20tenant.%3CBR%20%2F%3E%3CBR%20%2F%3EIn%20the%20previous%20setup%20you%20had%2C%20I%20would%20think%20you%20had%20an%20organizational%20relationship%20setup%20with%20your%20exchange%202016%20server%20that%20allowed%20you%20to%20do%20this.%20That%20is%20not%20possible%20between%20O365%20tenants.%3CBR%20%2F%3E%3CBR%20%2F%3EI%20would%20approach%20this%20in%20a%20few%20different%20ways%2C%20based%20on%20what%20you%20find%20works%20best%3A%3CBR%20%2F%3E1.%20To%20me%20the%20easiest%20would%20be%20to%20setup%20a%20forward%20on%20that%20mailbox%20to%20send%20to%20a%20mailbox%20on%20your%20tenant.%20So%20any%20mail%20that%20comes%20into%20shared%40xyz.com%20forwards%20to%20shared%40abc.com.%20You%20could%20use%20%22%3CSPAN%3ESet-Mailbox%20shared%40xyz%20-ForwardingSmtpAddress%20shared%40abc.com%20-DeliverToMailboxAndForward%20%24True%22%20and%20it%20should%20work%2C%20just%20make%20sure%20you%2C%20you%20have%20the%20last%20flag%20to%20keep%20a%20copy.%3CBR%20%2F%3E%3CBR%20%2F%3E2.%20If%20that%20solution%20doesnt%20work%20because%20the%20XYZ%20company%20doesn't%26nbsp%3Bwant%20to%20forward%20mail%20externally%2C%20I%20would%20maybe%20look%20at%20cheap%20alternatives%20like%20an%20extra%20account%20on%20the%20xyz.com%20tenant%20that%20can%20be%20used%20by%20your%20users%20abc%40xyz.com%2C%20that%20has%20access%2C%20and%20then%20your%20users%20would%20just%20need%20to%20setup%20abc%40xyz.com%20in%20their%20outlook%20profile%20as%20well.%3CBR%20%2F%3E%3CBR%20%2F%3EHope%20this%20helps%20give%20you%20some%20ideas%2C%20but%20ultimately%20you%20will%20need%20to%20do%20something%20like%20the%20above%20as%20what%20you%20are%20looking%20to%20do%20just%20does%20not%20work%20across%20tenants.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EAdam%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Frequent Contributor

Scenario: Office365 Tenant: abc.com Users able to access shared mailbox residing on trusted client domain: xyz (using Exchange 2016) Recently, XYZ has moved all mailboxes (user mailbox and shared mailbox) to its Office365 Tenant: xyz.com Since then, users from abc.com can no longer access the shared mailboxes. Any suggestion on what can be done?

3 Replies
Highlighted

Hello,

 

Unfortunately you cannot assign permissions to a shared mailbox for a user that rests outside of the tenant.

In the previous setup you had, I would think you had an organizational relationship setup with your exchange 2016 server that allowed you to do this. That is not possible between O365 tenants.

I would approach this in a few different ways, based on what you find works best:
1. To me the easiest would be to setup a forward on that mailbox to send to a mailbox on your tenant. So any mail that comes into shared@xyz.com forwards to shared@abc.com. You could use "Set-Mailbox shared@xyz -ForwardingSmtpAddress shared@abc.com -DeliverToMailboxAndForward $True" and it should work, just make sure you, you have the last flag to keep a copy.

2. If that solution doesnt work because the XYZ company doesn't want to forward mail externally, I would maybe look at cheap alternatives like an extra account on the xyz.com tenant that can be used by your users abc@xyz.com, that has access, and then your users would just need to setup abc@xyz.com in their outlook profile as well.

Hope this helps give you some ideas, but ultimately you will need to do something like the above as what you are looking to do just does not work across tenants.

 

Adam

Highlighted

Hi Adam,

 

Thanks for the clarity.

So Office365 Tenants cannot be federated to the external domain, even though they are federated with the on-premise Active Directory and they are using Azure AD?

 

Highlighted

Hey @Admin O365,

 

In short yes.

If you have the organizational relationship setup, with all the needed connectors etc, then you can do the permissions as you are talking (to the one exchange system you own that your AD is linked too, etc).


But just an external domain, that is not in a hybrid setup with your O365 tenant, cannot do the permissions.

 

Adam