SOLVED

Azure AD Password Hash Sync & Shared Mailboxes

%3CLINGO-SUB%20id%3D%22lingo-sub-266173%22%20slang%3D%22en-US%22%3EAzure%20AD%20Password%20Hash%20Sync%20%26amp%3B%20Shared%20Mailboxes%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-266173%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20there%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20are%20considering%20switching%20to%20Exchange%20Online%20Azure%20AD%20Password%20Hash%20Sync%20with%20our%20on-premise%20AD.%3C%2FP%3E%3CP%3EWondering%20whether%20if%20a%20user%20left%20the%20company%20and%20we%20set%20to%20Exchange%20Online%20account%20to%20a%20shared%20mailbox%20but%20delete%20off%20the%20account%20in%20the%20on-premise%20AD%2C%20will%20the%20account%20in%20Azure%20AD%20be%20deleted%20off%20as%20well%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EFrom%20what%20I%20read%2C%20it%20seems%20that%20if%20we%20disable%20the%20account%20in%20the%20on-premise%20AD%2C%20the%20account%20in%20Azure%20AD%20will%20also%20be%20removed%20(30%20days).%20Is%20there%20anyway%20we%20can%20prevent%20that%20from%20happening%3F%20Like%20having%20to%20manually%20remove%20accounts%20in%20Azure%20AD%20instead%3F%20It%20is%20password%20hash%20sync%20only.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20for%20reading.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-266173%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EExchange%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOn-Premises%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-267433%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20Password%20Hash%20Sync%20%26amp%3B%20Shared%20Mailboxes%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-267433%22%20slang%3D%22en-US%22%3E%3CP%3EHello%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F221960%22%20target%3D%22_blank%22%3E%40Boon%20Leong%20Ong%3C%2FA%3E%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EJust%20restore%20the%20user%2C%20it%20should%20come%20back%20as%20cloud.%20Since%20they%20no%20longer%20are%20in%20AD.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Eadam%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-267209%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20Password%20Hash%20Sync%20%26amp%3B%20Shared%20Mailboxes%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-267209%22%20slang%3D%22en-US%22%3E%3CP%3EThank%20you.%3C%2FP%3E%3CP%3EBut%20looks%20like%20it%20requires%20Exchange%20Online%20Plan%202%20for%20it%20to%20work.%20We%20are%20on%20Plan%201.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-267208%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20Password%20Hash%20Sync%20%26amp%3B%20Shared%20Mailboxes%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-267208%22%20slang%3D%22en-US%22%3E%3CP%3EGuys%2C%20thank%20you%20for%20your%20help.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%20if%20I%20restore%20an%20deleted%20(disabled%20in%20on-premise%20AD)%26nbsp%3Baccount%20and%20set%20it%20to%20be%20a%26nbsp%3Bshared%20mailbox%2C%20the%20synchronization%20will%20then%20be%20removed%3F%20I%20don't%20see%20any%20option%20to%20restore%20the%20account%26nbsp%3Bas%20a%20%3CSTRONG%3Ecloud%20object%20%3C%2FSTRONG%3Ethough.%26nbsp%3BJust%20a%20restore%20option.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThat%20would%20be%20great%20for%20my%20case.%20I%20just%20have%20to%20remember%20to%20do%20the%20process.%20Or%20basically%20I%20could%20just%20switch%20the%20mailbox%20to%20a%20shared%20mailbox%20in%20Office365%20and%20then%20disable%2Fdelete%20the%20account%20in%20the%20on-premise%20AD.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-266456%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20Password%20Hash%20Sync%20%26amp%3B%20Shared%20Mailboxes%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-266456%22%20slang%3D%22en-US%22%3E%3CP%3EFor%20such%20scenarios%2C%20the%20recommended%20solution%20is%20to%20use%20Inactive%20mailboxes%3A%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Foffice365%2Fsecuritycompliance%2Fcreate-and-manage-inactive-mailboxes%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Foffice365%2Fsecuritycompliance%2Fcreate-and-manage-inactive-mailboxes%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThey%20are%20free%2C%20allow%20you%20to%20keep%20the%20data%20immutably%20and%20indefinitely%2C%20and%20don't%20rely%20on%20the%20AD%20user%20object.%20Now%2C%20if%20you%20need%20%22online%22%20access%20to%20the%20data%20of%20the%20departed%20user%2C%20they%20are%20not%20as%20convenient%20as%20Shared%20mailboxes%20to%20use.%20There%20are%20few%20other%20factors%20to%20consider%20as%20well%2C%20as%20detailed%20here%3A%20%3CA%20href%3D%22https%3A%2F%2Fpractical365.com%2Fexchange-online%2Fshared-mailboxes-vs-inactive-mailboxes-departed-users%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fpractical365.com%2Fexchange-online%2Fshared-mailboxes-vs-inactive-mailboxes-departed-users%2F%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-266322%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20Password%20Hash%20Sync%20%26amp%3B%20Shared%20Mailboxes%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-266322%22%20slang%3D%22en-US%22%3E%3CP%3EHello%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F221960%22%20target%3D%22_blank%22%3E%40Boon%20Leong%20Ong%3C%2FA%3E%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThere%20are%20a%20few%20ways%20you%20can%20go%20about%20handling%20this.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E1.%20Using%20a%20Hybrid%20exchange%20server%2Fmanually%20changing%20the%20msExchangerecipienttypedetails%20value.%20This%20is%20one%20of%20the%20values%20that%20O365%20looks%20at%20to%20determine%20what%20type%20of%20object%20you%20have.%20If%20you%20change%20this%20value%2C%20and%20then%20re-sync%20the%20user%20object%2C%20it%20should%20convert%20over%20to%20a%20shared%20mailbox.%20At%20that%20point%20the%20password%20in%20O365%20does%20not%20matter%2C%20you%20can%20then%20change%20the%20password%20to%20your%20local%20ad%20(or%20lock%20it)%20and%20it%20should%20work.%20You%20cant%20disable%2Fdelete%20the%20AD%20account%2C%20but%20you%20can%20effectively%20block%20it%20out%20and%20keep%20the%20object%20in%20o365.%20You%20MAY%20need%20to%20do%20a%20full%20sync%20to%20get%20the%20type%20to%20change%2C%20as%20sometimes%20O365%20is%20notoriously%20stubborn%20at%20picking%20up%20a%20recipient%20type%20change.%20Once%20they%20have%20been%20converted%20to%20a%20shared%20mailbox%2C%20you%20can%20remove%20their%20license.%3C%2FP%3E%3CP%3E%3CA%20href%3D%22http%3A%2F%2Ftechgenix.com%2Fmsexchangerecipienttypedetails-active-directory-values%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttp%3A%2F%2Ftechgenix.com%2Fmsexchangerecipienttypedetails-active-directory-values%2F%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E2.%20Disable%2Fremove%20the%20account%20in%20local%20AD%2C%20restore%20it%20through%20the%20recycling%20bin%20-%20You%20are%20correct%20after%2030%20days%20the%20account%20is%20removed%20once%20a%20local%20AD%20is%20deleted.%20This%20is%20just%20a%20function%20of%20how%20AADC%20works.%20However%2C%20since%20you%20have%20that%2030%20day%20window%2C%20you%20can%20choose%20to%20go%20restore%20the%20user%2C%20and%20you%20can%20restore%20them%20as%20a%20cloud%20object.%20This%20will%20provision%20them%20out%20as%20a%20cloud%20object%20not%20linked%20to%20your%20AD%2C%20you%20will%20also%20want%20to%20make%20sure%20you%20re-license%20them%20so%20that%20the%20exchange%20mailbox%20comes%20back.%20Once%20that%20is%20back%20(and%20now%20a%20cloud%20user)%2C%20you%20can%20go%20through%20the%20exchange%20GUI%20and%20convert%20the%20user%20mailbox%20to%20a%20shared%20mailbox.%20Once%20that%20is%20done%20you%20can%20unlicense%20the%20user.%20Their%20exchange%20data%20will%20be%20saved%20as%20a%20shared%20mailbox.%3C%2FP%3E%3CP%3E*Note%20any%20data%20in%20Onedrive%20or%20other%20applications%20for%20this%20user%20will%20however%20be%20lost.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E3.%20Export%20and%20Import%20-%20This%20is%20the%20longest%20option%2C%20but%20probably%20the%20%22safest%22%20from%20a%20process%20stand%20point.%20(assuming%20you%20control%20the%20steps%20properly).%20When%20a%20user%20is%20going%20to%20leave%20that%20is%20currently%20licensed%2C%20you%20can%20use%20the%20security%20and%20compliance%20center%20to%20export%20their%20data%20for%20you.%20You%20just%20create%20a%20search%20for%20that%20user%20(mail%20to%20and%20from)%20and%20then%20export%20it%20to%20a%20PST.%20Go%20in%20and%20create%20a%20shared%20mailbox%2C%20this%20can%20be%20a%20cloud%20object%20or%20a%20fresh%20AD%20account.%20Then%20import%20that%20data%20in.%20Once%20you%20are%20comfortable%20with%20your%20work%2C%20delete%20the%20user%20account%2C%20purge%20the%20data%20from%20deleted%20items%20in%20O365%20(to%20free%20up%20the%20email%20address)%2C%20and%20add%20their%20email%20address%20to%20the%20shared%20mailbox%20you%20created.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EPersonally%20I%20did%20mostly%201%20or%202%20with%20my%20clients%20based%20on%20if%20they%20wanted%20their%20shared%20mailboxes%20to%20have%20objects%20in%20AD%20or%20not.%20If%20they%20did%2C%20I%20would%20do%201%2C%20if%20they%20did%20not%20and%20were%20fine%20with%20them%20being%20cloud%20objects%20(and%20thus%20having%20no%20reference%20in%20AD)%20I%20would%20do%202.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAdam%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
New Contributor

Hi there,

 

We are considering switching to Exchange Online Azure AD Password Hash Sync with our on-premise AD.

Wondering whether if a user left the company and we set to Exchange Online account to a shared mailbox but delete off the account in the on-premise AD, will the account in Azure AD be deleted off as well?

 

From what I read, it seems that if we disable the account in the on-premise AD, the account in Azure AD will also be removed (30 days). Is there anyway we can prevent that from happening? Like having to manually remove accounts in Azure AD instead? It is password hash sync only.

 

Thanks for reading.

5 Replies
Highlighted
Best Response confirmed by Boon Leong Ong (New Contributor)
Solution

Hello @Boon Leong Ong,

 

There are a few ways you can go about handling this.

 

1. Using a Hybrid exchange server/manually changing the msExchangerecipienttypedetails value. This is one of the values that O365 looks at to determine what type of object you have. If you change this value, and then re-sync the user object, it should convert over to a shared mailbox. At that point the password in O365 does not matter, you can then change the password to your local ad (or lock it) and it should work. You cant disable/delete the AD account, but you can effectively block it out and keep the object in o365. You MAY need to do a full sync to get the type to change, as sometimes O365 is notoriously stubborn at picking up a recipient type change. Once they have been converted to a shared mailbox, you can remove their license.

http://techgenix.com/msexchangerecipienttypedetails-active-directory-values/

 

2. Disable/remove the account in local AD, restore it through the recycling bin - You are correct after 30 days the account is removed once a local AD is deleted. This is just a function of how AADC works. However, since you have that 30 day window, you can choose to go restore the user, and you can restore them as a cloud object. This will provision them out as a cloud object not linked to your AD, you will also want to make sure you re-license them so that the exchange mailbox comes back. Once that is back (and now a cloud user), you can go through the exchange GUI and convert the user mailbox to a shared mailbox. Once that is done you can unlicense the user. Their exchange data will be saved as a shared mailbox.

*Note any data in Onedrive or other applications for this user will however be lost.

 

3. Export and Import - This is the longest option, but probably the "safest" from a process stand point. (assuming you control the steps properly). When a user is going to leave that is currently licensed, you can use the security and compliance center to export their data for you. You just create a search for that user (mail to and from) and then export it to a PST. Go in and create a shared mailbox, this can be a cloud object or a fresh AD account. Then import that data in. Once you are comfortable with your work, delete the user account, purge the data from deleted items in O365 (to free up the email address), and add their email address to the shared mailbox you created.

 

Personally I did mostly 1 or 2 with my clients based on if they wanted their shared mailboxes to have objects in AD or not. If they did, I would do 1, if they did not and were fine with them being cloud objects (and thus having no reference in AD) I would do 2.

 

Adam

Highlighted

For such scenarios, the recommended solution is to use Inactive mailboxes: https://docs.microsoft.com/en-us/office365/securitycompliance/create-and-manage-inactive-mailboxes

 

They are free, allow you to keep the data immutably and indefinitely, and don't rely on the AD user object. Now, if you need "online" access to the data of the departed user, they are not as convenient as Shared mailboxes to use. There are few other factors to consider as well, as detailed here: https://practical365.com/exchange-online/shared-mailboxes-vs-inactive-mailboxes-departed-users/

Highlighted

Guys, thank you for your help.

 

So if I restore an deleted (disabled in on-premise AD) account and set it to be a shared mailbox, the synchronization will then be removed? I don't see any option to restore the account as a cloud object though. Just a restore option.

 

That would be great for my case. I just have to remember to do the process. Or basically I could just switch the mailbox to a shared mailbox in Office365 and then disable/delete the account in the on-premise AD.

Highlighted

Thank you.

But looks like it requires Exchange Online Plan 2 for it to work. We are on Plan 1.

Highlighted

Hello @Boon Leong Ong,

 

Just restore the user, it should come back as cloud. Since they no longer are in AD.

 

adam