Office 365 Group External Email (Hybrid)

%3CLINGO-SUB%20id%3D%22lingo-sub-508288%22%20slang%3D%22en-US%22%3EOffice%20365%20Group%20External%20Email%20(Hybrid)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-508288%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20are%20experiencing%20problems%20with%20our%20Office%20365%20Groups%20not%20being%20able%20to%20receive%20external%20emails%20in%20a%20Hybrid%20Environment.%20We%20have%20read%20countless%20topics%20about%20it%20as%20it%20seems%20like%20a%20common%20issue%2C%20but%20nothing%20seems%20to%20work%20for%20us.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CUL%3E%3CLI%3EI%20have%20attached%20the%20error%20that%20I%20get%20when%20emailing%20from%20Gmail.%3C%2FLI%3E%3CLI%3EWe%20can%20email%20the%20group%20internally%20just%20fine%3C%2FLI%3E%3CLI%3EThe%20Groups%20have%20been%20created%20with%20the%20%22allow%20external%20senders%22%20option%20turned%20on%3C%2FLI%3E%3CLI%3EWe%20have%20Azure%20Group%20write-back%20enabled%20and%20the%20groups%20appear%20in%20our%20Active%20Directory%3C%2FLI%3E%3CLI%3EWe%20cannot%20create%20a%20mailbox%20for%20the%20groups%20in%20our%20Exchange%202012%20server%20because%20they%20already%20exist%20due%20to%20the%20AD%20write-back%20(this%20seems%20like%20the%20big%20issue%20to%20me)%3C%2FLI%3E%3CLI%3EWe%20can%20email%20the%20group%20externally%20if%20we%20use%20the%20%7Bgroup%7D%40%7Bcompany%7D.onmicrosoft.com%20email%20but%20not%20using%20%7Bgroup%7D%40%7Bcompany%7D.org%3C%2FLI%3E%3CLI%3EThe%20email%20is%20trying%20to%20route%20through%20our%20exchange%20server%20first%2C%20where%20it%20cannot%20find%20the%20email%2C%20and%20then%20it%20almost%20gives%20up%20because%20it%20thinks%20that%20it%20doesn't%20exist.%3C%2FLI%3E%3C%2FUL%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20would%20be%20more%20than%20happy%20to%20supply%20any%20information%20that%20could%20get%20this%20problem%20fixed.%3C%2FP%3E%3CP%3EWe%20are%20very%20frustrated%20and%20just%20need%20some%20help!!!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-508288%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EExchange%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EHybrid%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%20Groups%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-508857%22%20slang%3D%22en-US%22%3ERe%3A%20Office%20365%20Group%20External%20Email%20(Hybrid)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-508857%22%20slang%3D%22en-US%22%3EYou%20have%20redacted%20too%20much%20info%20in%20that%20screenshot%20so%20it%20is%20unfortunately%20unhelpful.%20If%20you%20need%20to%20sanatize%20it%2C%20post%20a%20screenshot%20where%20you%20have%20edited%20it%20rather%20than%20redacted%2C%20so%20that%20things%20like%20the%20same%20server%20name%20is%20used%20repeatedly%20and%20is%20not%20just%20a%20red%20box%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-779538%22%20slang%3D%22en-US%22%3ERe%3A%20Office%20365%20Group%20External%20Email%20(Hybrid)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-779538%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F314268%22%20target%3D%22_blank%22%3E%40zrigby%3C%2FA%3E%26nbsp%3BDid%20you%20ever%20get%20this%20resolved%3F%20We%20have%20exactly%20the%20same%20problem%20you%20described.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-781672%22%20slang%3D%22en-US%22%3ERe%3A%20Office%20365%20Group%20External%20Email%20(Hybrid)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-781672%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F384450%22%20target%3D%22_blank%22%3E%40JamesH50%3C%2FA%3E%26nbsp%3BYes%20we%20did%20get%20this%20resolved%2C%20but%20we%20did%20not%20do%20it%20ourselves%20as%20we%20had%20to%20use%20a%20vendor.%20I%20will%20reach%20out%20to%20them%20for%20a%20detailed%20explanation%2C%20but%20here%20is%20the%20idea%20of%20what%20they%20did%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThey%20used%20a%20write-back%20feature%20in%20Azure%20to%20recreate%20the%20Office%20365%20groups%20created%20on%20the%20web%20in%20our%20on-site%20Active%20Directory.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20made%20it%20so%20that%20when%20an%20external%20email%20went%20through%20our%20Exchange%20Server%20which%20serves%20as%20a%20relay%2C%20the%20email%20address%20existed%20and%20allowed%20it%20to%20then%20go%20to%20Office%20365%20where%20the%20actual%20group%20existed%20and%20distributed%20the%20email.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20reason%20I%20am%20not%20entirely%20sure%20how%20it%20works%20is%20because%20in%20AD%20the%20groups%20are%20called%20something%20like%3A%20Name%3A%20Group_70b9cd7-6f22-...%20Type%3A%20Distribution%20Group%20-%20Universal%20Description%3A%20%7BGroup%20Name%7D%20Email%20Address%3A%20%7BEmail%20Address%7D.%26nbsp%3BThere%20is%20an%20attribute%20labeled%3A%20msExchRequireAuthToSendTo%20that%20needed%20to%20be%20set%20to%20FALSE%20for%20some%20of%20the%20groups%20that%20still%20had%20problems.%20The%20groups%20are%20also%20placed%20in%20an%20Admin%20OU%20since%20they%20wont%20be%20used%20for%20anything%20except%20for%20a%20relay.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20you%20use%20some%20sort%20of%20support%2C%20maybe%20this%20will%20help%20then%20understand%20what%20needs%20to%20be%20done.%20If%20I%20can%20get%20a%20better%20explanation%20from%20someone%20who%20knows%20more%20than%20me%2C%20I%20will%20update%20here!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-781714%22%20slang%3D%22en-US%22%3ERe%3A%20Office%20365%20Group%20External%20Email%20(Hybrid)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-781714%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F314268%22%20target%3D%22_blank%22%3E%40zrigby%3C%2FA%3E%26nbsp%3BThanks%20for%20the%20reply%2C%20we%20worked%20it%20out%20earlier%20today%20and%20came%20up%20with%20a%20similar%20answer%20-%20we%20needed%20some%20Azure%20AD%20P1%20licences%20to%20enable%20writeback%20feature.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20then%20had%20to%20follow%20instructions%20here%20to%20enable%20the%20O365%20group%20to%20receive%20external%20email%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fanswers.microsoft.com%2Fen-us%2Fmsoffice%2Fforum%2Fall%2F550-57133%2Fbe2b2e38-c528-4752-bd0b-cfaca424090e%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fanswers.microsoft.com%2Fen-us%2Fmsoffice%2Fforum%2Fall%2F550-57133%2Fbe2b2e38-c528-4752-bd0b-cfaca424090e%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
New Contributor

We are experiencing problems with our Office 365 Groups not being able to receive external emails in a Hybrid Environment. We have read countless topics about it as it seems like a common issue, but nothing seems to work for us.

 

  • I have attached the error that I get when emailing from Gmail.
  • We can email the group internally just fine
  • The Groups have been created with the "allow external senders" option turned on
  • We have Azure Group write-back enabled and the groups appear in our Active Directory
  • We cannot create a mailbox for the groups in our Exchange 2012 server because they already exist due to the AD write-back (this seems like the big issue to me)
  • We can email the group externally if we use the {group}@{company}.onmicrosoft.com email but not using {group}@{company}.org
  • The email is trying to route through our exchange server first, where it cannot find the email, and then it almost gives up because it thinks that it doesn't exist.

 

I would be more than happy to supply any information that could get this problem fixed.

We are very frustrated and just need some help!!!

4 Replies
Highlighted
You have redacted too much info in that screenshot so it is unfortunately unhelpful. If you need to sanatize it, post a screenshot where you have edited it rather than redacted, so that things like the same server name is used repeatedly and is not just a red box
Highlighted

@zrigby Did you ever get this resolved? We have exactly the same problem you described.

Highlighted

@JamesH50 Yes we did get this resolved, but we did not do it ourselves as we had to use a vendor. I will reach out to them for a detailed explanation, but here is the idea of what they did:

 

They used a write-back feature in Azure to recreate the Office 365 groups created on the web in our on-site Active Directory. 

 

This made it so that when an external email went through our Exchange Server which serves as a relay, the email address existed and allowed it to then go to Office 365 where the actual group existed and distributed the email.

 

The reason I am not entirely sure how it works is because in AD the groups are called something like: Name: Group_70b9cd7-6f22-... Type: Distribution Group - Universal Description: {Group Name} Email Address: {Email Address}. There is an attribute labeled: msExchRequireAuthToSendTo that needed to be set to FALSE for some of the groups that still had problems. The groups are also placed in an Admin OU since they wont be used for anything except for a relay.

 

If you use some sort of support, maybe this will help then understand what needs to be done. If I can get a better explanation from someone who knows more than me, I will update here!

 

 

Highlighted

@zrigby Thanks for the reply, we worked it out earlier today and came up with a similar answer - we needed some Azure AD P1 licences to enable writeback feature.

 

We then had to follow instructions here to enable the O365 group to receive external email: https://answers.microsoft.com/en-us/msoffice/forum/all/550-57133/be2b2e38-c528-4752-bd0b-cfaca424090...