Issue with Office 365 Shared Mailbox / AD Sync Tool.

%3CLINGO-SUB%20id%3D%22lingo-sub-170910%22%20slang%3D%22en-US%22%3EIssue%20with%20Office%20365%20Shared%20Mailbox%20%2F%20AD%20Sync%20Tool.%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-170910%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSTRONG%3EGreetings!!!%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThis%20article%20I%20prepared%20to%20notify%20the%20issue%26nbsp%3Bfound%26nbsp%3Bin%20Microsoft%20Office%20365%20Mailbox%2F%20Exchange%20(Shared%20Mailbox)%20access.%20Might%20be%20most%20of%20the%20admins%20are%20already%20aware%20on%20this.%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3E%3CU%3EDescription%20of%20the%20Issue%3A-%3C%2FU%3E%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3ERecently%2C%20I%20have%20noticed%20a%26nbsp%3Bsmall%20bug%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3Ein%20Microsoft%20Office%20365%20mailbox%20(shared%20mailbox)%20or%20AD%20Sync%20tool%2C%20The%20same%20has%20been%20presented%20to%20the%20Microsoft%20Technical%20Support%20Engineer%20over%20the%20remote%20session.%20As%20per%26nbsp%3Bhis%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3Eadvice%20only%2C%20Here%20I%20am%26nbsp%3Bpublishing%20the%20same.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EHere%20is%20the%20description%20of%20the%20issue%20I%20found%2C%3C%2FP%3E%0A%3CP%3E----------------------------------------------------------------------------------------------------------------%3C%2FP%3E%0A%3CP%3EHow%20can%20we%20save%20Exchange%20Online%20license%20(P1)%20cost%20by%20converting%20into%20Shared%20Mailbox%3F%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIf%20your%20organization%20have%20On-premise%20AD%20federated%20with%20Microsoft%20Office%20365%20for%20single%20sign-on%2C%20then%20no%20need%20to%20spend%20amount%20on%20Office%20365%20Exchange%20online%20license(P1).%20You%20can%20create%20number%20mailboxes%20without%20any%20payment.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EHow%20to%20Avail%20the%20full%20features%20of%20Shared%20Mailbox%20like%20a%20user%20mailbox%3A%20-%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3E%26nbsp%3B%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3EIf%20your%20organization%20have%20a%20local%20AD%20federated%20with%20Microsoft%20Cloud%2C%20then%20you%20can%20follow%20the%20below%20steps%20to%20save%20the%20license%20cost%20and%20you%20can%20use%20shared%20mailbox%20like%20user%20mailbox.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3ERequirements%20for%20free%20license%3A%20-%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3COL%3E%0A%3CLI%3E%3CEM%3EOn%20Premise%20AD%2C%20federated%20with%20Cloud.%3C%2FEM%3E%3C%2FLI%3E%0A%3CLI%3E%3CEM%3EOne%20Exchange%20Online%20(P1)%20license.%3C%2FEM%3E%3C%2FLI%3E%0A%3C%2FOL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3ESteps%20to%20follow%3A%20-%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3E%26nbsp%3B%3C%2FSTRONG%3E%3C%2FP%3E%0A%3COL%3E%0A%3CLI%3ECreate%20a%20user%20account%20in%20your%20local%20AD%2C%20and%20wait%20to%20sync%20created%20account%20with%20Cloud.%3C%2FLI%3E%0A%3CLI%3EOnce%20it%20is%20synced%20with%20cloud%2C%20first%20you%20must%20assign%20the%20Exchange%20Online%20License%20(P1).%3C%2FLI%3E%0A%3C%2FOL%3E%0A%3CP%3E%26nbsp%3B%3CEM%3ENow%20it%20is%20user%20mailbox%2C%20you%20can%20login%20into%20OWA%2C%20you%20can%20configure%20the%20mailbox%20in%20Outlook%20Mobile%20App%20and%20Desktop%20Outlook%20App.%3C%2FEM%3E%3C%2FP%3E%0A%3CP%3E%3CEM%3E%26nbsp%3B%20%26nbsp%3B%203.%26nbsp%3B%3C%2FEM%3EOnce%20you%20configure%20this%20account%20in%20Outlook%2C%20Convert%20the%20mailbox%20into%20Shared%20mailbox%20and%20revoke%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3Bthe%20license.%3C%2FP%3E%0A%3CP%3E%26nbsp%3BSet-mailbox%20-identity%20%E2%80%9C%3CEM%3EEmailID%E2%80%9D%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FEM%3E-type%20Shared%3C%2FP%3E%0A%3CP%3ESet-MsolUserLicense%20-UserPrincipalName%20%E2%80%9C%3CEM%3EEmailID%E2%80%9D%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FEM%3E-RemoveLicense%20%E2%80%9C%3CEM%3ELicense%3C%2FEM%3E%E2%80%9D%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B4.%20Keep%20user%20account%20is%20enabled%20in%20AD.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3CSTRONG%3ECurrent%20state%20is%3A%20-%20Account%20is%20Enabled%20in%20AD%20and%20mailbox%20is%20shared%20mailbox%2C%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3BIn%20this%20state%2C%20all%20features%20available%20for%20Exchange%20Online%20is%20accessible%20for%20shared%20mailbox%20also.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3COL%3E%0A%3CLI%3EPossible%20to%20access%20this%20mailbox%20from%20anywhere%20via%20OWA%20using%20shared%20mailbox%20credentials.%3C%2FLI%3E%0A%3CLI%3EPossible%20to%20configure%20this%20Shared%20Mailbox%20in%20Desktop%20Outlook%20App%20and%20Mobile%20Outlook%20App.%3C%2FLI%3E%0A%3CLI%3EIf%20any%20user%20shared%20the%20One%20Drive%20file%20with%20shared%20mailbox%2C%20possible%20to%20access%20and%20edit%20the%20shared%20file%20using%20online%20edit%20through%20portal%20using%20shared%20mailbox%20credentials.%3C%2FLI%3E%0A%3CLI%3EOnce%20you%20enable%20the%20Archive%2C%20Archiving%20(50%20Gb)%20is%20also%20available%20for%20the%20shared%20mailbox.%3C%2FLI%3E%0A%3CLI%3EPossible%20to%20access%20the%20Yammer%20Service.%3C%2FLI%3E%0A%3C%2FOL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3E%3CEM%3ETo%20enable%20the%20full%20features%20of%20Shared%20mailbox%20like%20user%20mailbox%2C%20Keep%20the%20account%20is%20enabled.%3C%2FEM%3E%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThe%20only%20drawback%20is%2C%20we%20can%20add%20shared%20mailbox%20into%20Office%20365%20groups%2C%20but%2C%20if%20any%20user%20shared%20any%20file%20in%20Office%20365%20group%20is%20not%20accessible%20for%20shared%20mailbox.%20Rest%20of%20all%20service%20is%20accessible%20like%20P1%20user.%3C%2FP%3E%0A%3CP%3EIf%20you%20want%20to%20disable%20all%20the%20services%2C%20then%20must%20disable%20this%20account%20in%20AD.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ENB%3A%20-%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CEM%3EIf%20your%20organization%20fully%20hosted%20in%20Cloud%20and%20user%E2%80%99s%20credentials%20are%20storing%20in%20Azure%20AD%2C%20then%20this%20process%20will%20not%20work.%20If%20you%20are%20in%20cloud%2C%20you%20need%20a%20separate%20user%20mailbox%20to%20access%20this%20shared%20mailbox%20with%20access%20right.%3C%2FEM%3E%3C%2FP%3E%0A%3CP%3E%3CEM%3E---------------------------------------------------------------------------------------------------------------%3C%2FEM%3E%3C%2FP%3E%0A%3CP%3E%3CEM%3ERegards%2C%3C%2FEM%3E%3C%2FP%3E%0A%3CP%3E%3CEM%3EYahkoob%20Ayappally%3C%2FEM%3E%3C%2FP%3E%0A%3CP%3E%3CEM%3Eyahkoob.ayappally%40outlook.com%3C%2FEM%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-170910%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-536292%22%20slang%3D%22en-US%22%3ERe%3A%20Issue%20with%20Office%20365%20Shared%20Mailbox%20%2F%20AD%20Sync%20Tool.%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-536292%22%20slang%3D%22en-US%22%3E%3CP%3EIf%20you%20do%20this%2C%20the%20mailbox%20will%20auto-delete%20in%2030%20days.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOnce%20it%20has%20a%20password%2C%20the%20-needslicensereconsiliation%20attribute%20is%20flagged%20to%20%24true.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIt's%20now%20a%20user.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EA%20user%20needs%20a%20license%20or%20is%20deleted%20in%2030%20days.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

Greetings!!!

 

This article I prepared to notify the issue found in Microsoft Office 365 Mailbox/ Exchange (Shared Mailbox) access. Might be most of the admins are already aware on this.

Description of the Issue:-

Recently, I have noticed a small bug in Microsoft Office 365 mailbox (shared mailbox) or AD Sync tool, The same has been presented to the Microsoft Technical Support Engineer over the remote session. As per his advice only, Here I am publishing the same.

 

Here is the description of the issue I found,

----------------------------------------------------------------------------------------------------------------

How can we save Exchange Online license (P1) cost by converting into Shared Mailbox?

 

If your organization have On-premise AD federated with Microsoft Office 365 for single sign-on, then no need to spend amount on Office 365 Exchange online license(P1). You can create number mailboxes without any payment.

 

How to Avail the full features of Shared Mailbox like a user mailbox: -

 

If your organization have a local AD federated with Microsoft Cloud, then you can follow the below steps to save the license cost and you can use shared mailbox like user mailbox.

 

Requirements for free license: -

 

  1. On Premise AD, federated with Cloud.
  2. One Exchange Online (P1) license.

 

Steps to follow: -

 

  1. Create a user account in your local AD, and wait to sync created account with Cloud.
  2. Once it is synced with cloud, first you must assign the Exchange Online License (P1).

 Now it is user mailbox, you can login into OWA, you can configure the mailbox in Outlook Mobile App and Desktop Outlook App.

    3. Once you configure this account in Outlook, Convert the mailbox into Shared mailbox and revoke         the license.

 Set-mailbox -identity “EmailID” -type Shared

Set-MsolUserLicense -UserPrincipalName “EmailID” -RemoveLicense “License

     4. Keep user account is enabled in AD.

 Current state is: - Account is Enabled in AD and mailbox is shared mailbox,

 In this state, all features available for Exchange Online is accessible for shared mailbox also.

 

  1. Possible to access this mailbox from anywhere via OWA using shared mailbox credentials.
  2. Possible to configure this Shared Mailbox in Desktop Outlook App and Mobile Outlook App.
  3. If any user shared the One Drive file with shared mailbox, possible to access and edit the shared file using online edit through portal using shared mailbox credentials.
  4. Once you enable the Archive, Archiving (50 Gb) is also available for the shared mailbox.
  5. Possible to access the Yammer Service.

 

To enable the full features of Shared mailbox like user mailbox, Keep the account is enabled.

 

The only drawback is, we can add shared mailbox into Office 365 groups, but, if any user shared any file in Office 365 group is not accessible for shared mailbox. Rest of all service is accessible like P1 user.

If you want to disable all the services, then must disable this account in AD.

 

NB: - If your organization fully hosted in Cloud and user’s credentials are storing in Azure AD, then this process will not work. If you are in cloud, you need a separate user mailbox to access this shared mailbox with access right.

---------------------------------------------------------------------------------------------------------------

Regards,

Yahkoob Ayappally

yahkoob.ayappally@outlook.com

1 Reply
Highlighted

If you do this, the mailbox will auto-delete in 30 days.

 

Once it has a password, the -needslicensereconsiliation attribute is flagged to $true.

 

It's now a user.

 

A user needs a license or is deleted in 30 days.