AD Connect with an existing O365 Tenant

%3CLINGO-SUB%20id%3D%22lingo-sub-3092684%22%20slang%3D%22en-US%22%3EAD%20Connect%20with%20an%20existing%20O365%20Tenant%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3092684%22%20slang%3D%22en-US%22%3E%3CP%3Ewe're%20about%20to%20enable%20AD%20Connect%20for%20an%20active%20Office%20365%20tenant%20and%20need%20some%20clarifications.%3C%2FP%3E%3CP%3EThe%20Tenant%20is%20hosting%20O365%20users%20with%20exchange%20online%20for%20the%20organization%20mail%20domain%20company.org%20but%20at%20the%20moment%20is%20disconnected%20from%20the%20On-Prem%20AD.%3C%2FP%3E%3CP%3ESo%20all%20the%20users%20have%20been%20defined%20on%20the%20tenant%20with%20smtp%20email%20address%20as%20%3CA%20href%3D%22mailto%3AEmail%20address%20removed%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EEmail%20address%20removed%3C%2FA%3E.%3C%2FP%3E%3CP%3ENo%20Exchange%20Server%20is%20present%20onprem.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20question%20is%20about%20Soft%20Merge%20and%20exchange%20management%20after%20the%20AD%20Connect%20is%20installed.%3C%2FP%3E%3CP%3E-%20Am%20I%20correct%20that%20simply%20having%20the%20logon%20account%20UPN%20been%20equal%20to%20the%20Tenant's%20username%20will%20be%20enough%20to%20%22match%22%20the%20users%20and%20have%20them%20synchronized%20by%20AD%20as%20master%20%3F%3C%2FP%3E%3CP%3E-%20What%20happens%20to%20exchange%20online%20mailboxes%20%3F%20Will%20there%20be%20any%20impact%20%3F%3CBR%20%2F%3EAs%20far%20as%20I%20know%20when%20the%20users%20are%20%22managed%22%20by%20AD%20an%20on-prem%20exchange%20server%20should%20be%20present%20to%20manage%20the%20%22email%22%20properties.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ethanks%3C%2FP%3E%3CP%3ESC%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-3092684%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAD%20sync%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Eadd-in%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EExchange%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%20Single%20Sign%20on%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3093302%22%20slang%3D%22en-US%22%3ERe%3A%20AD%20Connect%20with%20an%20existing%20O365%20Tenant%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3093302%22%20slang%3D%22en-US%22%3EYes%2C%20UPN%2C%20Primary%20SMTP%20Address%20or%20%22mail%22%20are%20the%20fields%20used%20for%20%22soft%20match%22%2C%20any%20should%20work.%20And%20yes%20on%20the%20management%20front%2C%20every%20scenario%20that%20involves%20directory%20synchronization%20requires%20you%20to%20have%20at%20least%20one%20Exchange%20box%20on%20premises%2C%20for%20management%20purposes.%20This%20is%20the%20only%20*supported*%20by%20Microsoft%20solution%2C%20although%20other%20configurations%20will%20still%20work.%20At%20the%20very%20least%20though%2C%20make%20sure%20you%20have%20the%20on%20premises%20AD%20schema%20extended%20with%20the%20Exchange%20attributes.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3097354%22%20slang%3D%22en-US%22%3ERe%3A%20AD%20Connect%20with%20an%20existing%20O365%20Tenant%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3097354%22%20slang%3D%22en-US%22%3EHello%3CBR%20%2F%3Ewhat%20about%20possible%20impacts%20on%20exchange%20mailboxes%20when%20activating%20the%20sync%20%3F%3CBR%20%2F%3EDO%20we%20have%20to%20manually%20modify%20the%20%22exchange%22%20properties%20of%20each%20AD%20users%20to%20reflect%20the%20Exchange%20Online%20users.%20before%20activating%20the%20sync%20%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3099695%22%20slang%3D%22en-US%22%3ERe%3A%20AD%20Connect%20with%20an%20existing%20O365%20Tenant%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3099695%22%20slang%3D%22en-US%22%3ENo%2C%20you%20don't.%20And%20you%20cannot%2C%20as%20you%20don't%20have%20the%20Exchange%20AD%20schema%20extensions%20available.%20The%20more%20important%20caveat%20here%20is%20that%20you%20will%20need%20to%20manage%20everything%20from%20on-premises%20once%20you%20%22match%22%20the%20objects%2C%20which%20includes%20the%20Exchange%20properties.%20This%20is%20the%20reason%20why%20Microsoft%20only%20%22supports%22%20configurations%20in%20which%20there%20is%20at%20least%20one%20Exchange%20server%20on%20premises%2C%20as%20the%20Exchange%20management%20tools%20are%20the%20only%20one%20supported%20for%20the%20task%20of%20managing%20Exchange%20objects%20and%20attributes.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3351771%22%20slang%3D%22en-US%22%3ERe%3A%20AD%20Connect%20with%20an%20existing%20O365%20Tenant%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3351771%22%20slang%3D%22en-US%22%3EHello%20Vasil%2C%3CBR%20%2F%3EI%20have%20installed%20an%20exchange%202016%20server%20on-prem%20to%20be%20used%20as%20management%20for%20mailboxes.%3CBR%20%2F%3EI've%20also%20activated%20the%20ADConnect%20between%20the%20Domain%20and%20the%20tenant.%3CBR%20%2F%3EAt%20the%20moment%20I've%20only%20enabled%20synchronization%20for%20a%20TEST%20OU%20where%20I%20moved%20an%20user.%3CBR%20%2F%3EThe%20user%20has%20been%20replicated%20and%20now%20I%20see%20it%20int%20the%20tenant%20as%20%22directory%20synced%22.%3CBR%20%2F%3EI%20expected%20to%20start%20seeing%20it%20also%20on%20the%20on-prem%20exchange%20server%20among%20the%20recipients%20but%20I%20don't.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3352010%22%20slang%3D%22en-US%22%3ERe%3A%20AD%20Connect%20with%20an%20existing%20O365%20Tenant%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3352010%22%20slang%3D%22en-US%22%3EIf%20you%20want%20the%20recipients%20to%20correctly%20appear%20in%20on-premises%20Exchange%2C%20you%20need%20to%20perform%20additional%20tasks.%20Generally%20speaking%2C%20this%20is%20not%20needed%2C%20and%20since%20this%20thread%20was%20opened%20Microsoft%20introduced%20a%20%22lightweight%22%20solution%20that%20allows%20you%20to%20manage%20objects%20with%20the%20last%20Exchange%20server%20removed%3A%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fexchange%2Fmanage-hybrid-exchange-recipients-with-management-tools%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fexchange%2Fmanage-hybrid-exchange-recipients-with-management-tools%3C%2FA%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3352115%22%20slang%3D%22en-US%22%3ERe%3A%20AD%20Connect%20with%20an%20existing%20O365%20Tenant%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3352115%22%20slang%3D%22en-US%22%3EThanks%20for%20the%20link%20provided.%3CBR%20%2F%3EI%20quickly%20read%20it%20and%20found%20that%3A%3CBR%20%2F%3EYou%20still%20need%20an%20installed%20exchange%20server%20installed%2C%20tough%20you%20can%20keep%20it%20powered%20off.%3CBR%20%2F%3EYou%20need%20to%20administer%20the%20user's%20properties%20via%20powershell%2C%20which%20the%20customer%20is%20not%20going%20to%20like.%3CBR%20%2F%3E%3CBR%20%2F%3ESo%20in%20this%20case%20it%20would%20be%20better%20if%20we%20can%20configure%20it%20in%20a%20way%20we%20can%20see%20the%20%22reecipients%22%20on%20the%20on-prem%20server%20too.%3CBR%20%2F%3ECan%20you%20define%20which%20additional%20steps%20are%20needed%20%3F%3CBR%20%2F%3Ethanks%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3352731%22%20slang%3D%22en-US%22%3ERe%3A%20AD%20Connect%20with%20an%20existing%20O365%20Tenant%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3352731%22%20slang%3D%22en-US%22%3EYou'll%20have%20to%20populate%20all%20the%20relevant%20attributes%20for%20that%2C%20and%20that%20part%20is%20not%20considered%20a%20supported%20scenario.%20Parts%201%20and%202%20of%20these%20series%20talk%20you%20over%20the%20experience%3A%20%3CA%20href%3D%22https%3A%2F%2Ftechgenix.com%2Foff-boarding-email-office-365-exchange-2013-part2%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Ftechgenix.com%2Foff-boarding-email-office-365-exchange-2013-part2%2F%3C%2FA%3E%3CBR%20%2F%3EIn%20your%20case%2C%20as%20the%20users%20already%20exist%2C%20you'll%20have%20to%20use%20Enable-RemoteMailbox%20instead%20of%20New-RemoteMailbox%2C%20or%20change%20the%20recipienttypedetails%20and%20related%20parameters%20manually.%3C%2FLINGO-BODY%3E
Contributor

we're about to enable AD Connect for an active Office 365 tenant and need some clarifications.

The Tenant is hosting O365 users with exchange online for the organization mail domain company.org but at the moment is disconnected from the On-Prem AD.

So all the users have been defined on the tenant with smtp email address as Email address removed.

No Exchange Server is present onprem.

 

The question is about Soft Merge and exchange management after the AD Connect is installed.

- Am I correct that simply having the logon account UPN been equal to the Tenant's username will be enough to "match" the users and have them synchronized by AD as master ?

- What happens to exchange online mailboxes ? Will there be any impact ?
As far as I know when the users are "managed" by AD an on-prem exchange server should be present to manage the "email" properties.

 

thanks

SC

 

7 Replies
Yes, UPN, Primary SMTP Address or "mail" are the fields used for "soft match", any should work. And yes on the management front, every scenario that involves directory synchronization requires you to have at least one Exchange box on premises, for management purposes. This is the only *supported* by Microsoft solution, although other configurations will still work. At the very least though, make sure you have the on premises AD schema extended with the Exchange attributes.
Hello
what about possible impacts on exchange mailboxes when activating the sync ?
DO we have to manually modify the "exchange" properties of each AD users to reflect the Exchange Online users. before activating the sync ?
No, you don't. And you cannot, as you don't have the Exchange AD schema extensions available. The more important caveat here is that you will need to manage everything from on-premises once you "match" the objects, which includes the Exchange properties. This is the reason why Microsoft only "supports" configurations in which there is at least one Exchange server on premises, as the Exchange management tools are the only one supported for the task of managing Exchange objects and attributes.
Hello Vasil,
I have installed an exchange 2016 server on-prem to be used as management for mailboxes.
I've also activated the ADConnect between the Domain and the tenant.
At the moment I've only enabled synchronization for a TEST OU where I moved an user.
The user has been replicated and now I see it int the tenant as "directory synced".
I expected to start seeing it also on the on-prem exchange server among the recipients but I don't.
If you want the recipients to correctly appear in on-premises Exchange, you need to perform additional tasks. Generally speaking, this is not needed, and since this thread was opened Microsoft introduced a "lightweight" solution that allows you to manage objects with the last Exchange server removed: https://docs.microsoft.com/en-us/exchange/manage-hybrid-exchange-recipients-with-management-tools
Thanks for the link provided.
I quickly read it and found that:
You still need an installed exchange server installed, tough you can keep it powered off.
You need to administer the user's properties via powershell, which the customer is not going to like.

So in this case it would be better if we can configure it in a way we can see the "reecipients" on the on-prem server too.
Can you define which additional steps are needed ?
thanks
You'll have to populate all the relevant attributes for that, and that part is not considered a supported scenario. Parts 1 and 2 of these series talk you over the experience: https://techgenix.com/off-boarding-email-office-365-exchange-2013-part2/
In your case, as the users already exist, you'll have to use Enable-RemoteMailbox instead of New-RemoteMailbox, or change the recipienttypedetails and related parameters manually.