SOLVED

Reconnecting Exchange Online Mailbox

%3CLINGO-SUB%20id%3D%22lingo-sub-1492644%22%20slang%3D%22en-US%22%3EReconnecting%20Exchange%20Online%20Mailbox%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1492644%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%20I%20currently%20have%20a%20hybrid%20Exchange%20setup.%20As%20a%20test%20I%20deleted%20an%20on-prem%20user%20which%20in%20turn%20deleted%20the%20mailbox%20in%20exchange%20online.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20then%20created%20a%20new%20account%20in%20Azure%2FO365%20and%20tried%20to%20reconnect%20the%20old%20mailbox%20to%20this%20new%20account%20with%20the%20following%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EPS%20C%3A%5CUsers%5Cmark%26gt%3B%20New-MailboxRestoreRequest%20-SourceMailbox%20b432c9c9-c162-4788-8d01-492aa5a35bbc%20-TargetMailbox%209dcd79ba-%3C%2FP%3E%3CP%3Eb5eb-4a56-8b01-9c5c8fb55dd1%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHowever%20I%20received%20the%20following%20message%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESource%20mailbox's%20legacyExchangeDN%20'%2Fo%3DExchangeLabs%2Fou%3DExchange%20Administrative%20Goup%3C%2FP%3E%3CP%3E(FYDIBOHF23SPDLT)%2Fcn%3DRecipients%2Fcn%3De833cbc5ffed497397c623443b8425ef-Johnny%20Five'%20doesn't%20match%20the%20legacyExchangeDN%20or%3C%2FP%3E%3CP%3EX500%20proxy%20for%20target%20mailbox%20'Johnny%20Five'.%20Use%20the%20'AllowLegacyDNMismatch'%20switch%20if%20you%20want%20to%20allow%20this%3C%2FP%3E%3CP%3Eoperation.%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22Apple-converted-space%22%3E%26nbsp%3B%20%26nbsp%3B%20%3C%2FSPAN%3E%2B%20CategoryInfo%3CSPAN%20class%3D%22Apple-converted-space%22%3E%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%3C%2FSPAN%3E%3A%20InvalidArgument%3A%20(9dcd79ba-b5eb-4a56-8b01-9c5c8fb55dd1%3AMailboxLocationIdParameter)%20%5BNew-%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22Apple-converted-space%22%3E%26nbsp%3B%26nbsp%3B%20%3C%2FSPAN%3EMailboxRestoreRequest%5D%2C%20NonMatchingLega...SwitchException%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22Apple-converted-space%22%3E%26nbsp%3B%20%26nbsp%3B%20%3C%2FSPAN%3E%2B%20FullyQualifiedErrorId%20%3A%20%5BServer%3DLO3P123MB3034%2CRequestId%3D4f8b4fbf-8d4f-4ef5-a994-53d691807686%2CTimeStamp%3D23%2F06%2F202%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22Apple-converted-space%22%3E%26nbsp%3B%26nbsp%3B%20%3C%2FSPAN%3E0%2012%3A32%3A15%5D%20%5BFailureCategory%3DCmdlet-NonMatchingLegacyDNPermanentUseSwitchException%5D%20A90C5DD1%2CMicrosoft.Exchange.Ma%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22Apple-converted-space%22%3E%26nbsp%3B%20%3C%2FSPAN%3Enagement.Migration.MailboxReplication.MailboxRestoreRequest.NewMailboxRestoreRequest%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22Apple-converted-space%22%3E%26nbsp%3B%20%26nbsp%3B%20%3C%2FSPAN%3E%2B%20PSComputerName%3CSPAN%20class%3D%22Apple-converted-space%22%3E%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%3C%2FSPAN%3E%3A%20outlook.office365.com%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20it%20safe%20to%20use%20the%26nbsp%3BAllowLegacyDNMismatch%20switch%20or%20will%20this%20cause%20me%20issues.%20I%20want%20to%20do%20this%20process%20so%20I%20can%20move%20to%20be%20completely%20cloud%20based%20and%20not%20require%20my%20on-prem%20accounts%20if%20that%20make%20sense.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20help%20is%20appreciated%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMark.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1492644%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EExchange%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EHybrid%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1492787%22%20slang%3D%22en-US%22%3ERe%3A%20Reconnecting%20Exchange%20Online%20Mailbox%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1492787%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F400226%22%20target%3D%22_blank%22%3E%40oldhamuk%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EEasiest%20way%20to%20go%20completely%20cloud%20only%20is%20to%20disable%20directory%20sync%20tenant%20wide%20using%20PowerShell%20as%20per%20the%20following%20link%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Foffice365%2Fenterprise%2Fturn-off-directory-synchronization%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Foffice365%2Fenterprise%2Fturn-off-directory-synchronization%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20is%20only%20suitable%20if%20you%20are%20completely%20prepared%20for%20cloud%20only%20identity%20for%20all%20of%20your%20O365%20objects%20however.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20you%20needed%20to%20do%20this%20on%20a%20per%20user%20basis%2C%20then%20the%20simplest%20way%20is%20to%20do%20what%20you%20did%20and%20delete%20the%20on-prem%20account%2C%20then%20wait%20for%20the%20sync.%26nbsp%3B%20The%20O365%20account%20will%20move%20from%20Active%20Users%20to%20Deleted%20Users.%26nbsp%3B%20You%20may%20then%20choose%20the%20option%20to%20restore%20the%20user%20which%20will%20recreate%20it%20as%20a%20cloud%20only%20object.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20you%20have%20Exchange%20Hybrid%2C%20be%20careful%20of%20your%20mail%20flow%20though.%26nbsp%3B%20Make%20sure%20you%20take%20this%20into%20consideration%20too.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1492960%22%20slang%3D%22en-US%22%3ERe%3A%20Reconnecting%20Exchange%20Online%20Mailbox%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1492960%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F616707%22%20target%3D%22_blank%22%3E%40PeterRising%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20for%20your%20reply.%20%26nbsp%3BIf%20I%20do%20that%20won't%20that%20mean%20the%20accounts%20will%20still%20show%20as%20Windows%20Server%20Accounts%20in%20Azure%20and%20then%20also%20mean%20I'm%20restricted%20on%20what%20I%20can%20edit%20for%20those%20users%20and%20mailboxes%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20may%20be%20using%20the%20incorrect%20term%20with%20Hybrid%20as%20all%20my%20mail%20routing%20is%20already%20directly%20to%20O365%20the%20only%20thing%20I%20have%20left%20is%20an%20SBS%20box%20with%20the%20users%20that%20are%20sync'd%20%26nbsp%3Bwith%20AD%20Connect%20and%20the%20Exchange%20which%20is%20only%20use%20to%20administer%20the%20Exchange%20properties%20of%20those%20users.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20that%20error%20I%20received%20something%20I%20need%20to%20be%20concerned%20with%20or%20can%20I%20go%20though%20the%20process%20and%20use%26nbsp%3B%3C%2FP%3E%3CP%3EAllowLegacyDNMismatch%20switch%20to%20proceed%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAs%20far%20as%20I'm%20aware%20I%20believe%20I%20have%20everything%20in%20place%20to%20be%20fully%20cloud%2C%20like%20I%20said%20the%20on-prem%20SBS%20box%20isn't%20really%20doing%20anything%20now%20and%20I'm%20keen%20to%20remove%20it%20from%20my%20setup%20gracefully%20than%20have%20to%20try%20and%20unpick%20something%20if%20it%20fails%20on%20me%20at%20some%20point.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20for%20your%20time%20and%20reply.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMark%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1493154%22%20slang%3D%22en-US%22%3ERe%3A%20Reconnecting%20Exchange%20Online%20Mailbox%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1493154%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F400226%22%20target%3D%22_blank%22%3E%40oldhamuk%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ENo%2C%20the%20opposite%20would%20be%20true.%26nbsp%3B%20The%20accounts%20would%20be%20cloud%20only%20and%20completely%20manageable%20from%20the%20O365%20portal%20%2F%20Azure%20AD%20with%20no%20reliance%20to%20on-premises.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI've%20never%20done%20what%20you%20are%20trying%20to%20achieve%20using%20your%20method%20so%20I%20can't%20comment%20to%20that.%26nbsp%3B%20However%2C%20you%20could%20test%20the%20experience%20with%20a%20test%20account%20to%20check%20what%20the%20impact%20would%20be.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1493248%22%20slang%3D%22en-US%22%3ERe%3A%20Reconnecting%20Exchange%20Online%20Mailbox%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1493248%22%20slang%3D%22en-US%22%3E%3CP%3EOh%20right%20ok%2C%20so%20if%20I%20understand%20correctly%20if%20I%20follow%20that%20article%20you%20have%20referenced%20the%20account%20that%20have%20sync'd%20into%20Azure%20from%20my%20On-Prem%20will%20automatically%20change%20and%20the%20source%20in%20Azure%20Active%20Directory%20will%20change%20from%20Windows%20Server%20AD%20to%20Azure%20Active%20Directory%20and%20then%20I%20can%20decommission%20the%20on-prem%20server%20simple%20as%20that%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI'd%20rather%20do%20this%20the%20correct%20way%20rather%20than%20the%20way%20I%20discovered.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMark%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1493636%22%20slang%3D%22en-US%22%3ERe%3A%20Reconnecting%20Exchange%20Online%20Mailbox%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1493636%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F400226%22%20target%3D%22_blank%22%3E%40oldhamuk%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAbsolutely%20correct%20yes.%26nbsp%3B%20Done%20it%20many%20times%20this%20way%20and%20it%20works%20great!%26nbsp%3B%20If%20your%20mailflow%20is%20already%20pointed%20to%20Exchange%20Online%20too%20then%20you%20are%20good%20to%20go%20with%20this.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
New Contributor

Hi,

 

So I currently have a hybrid Exchange setup. As a test I deleted an on-prem user which in turn deleted the mailbox in exchange online.

 

I then created a new account in Azure/O365 and tried to reconnect the old mailbox to this new account with the following:

 

PS C:\Users\mark> New-MailboxRestoreRequest -SourceMailbox b432c9c9-c162-4788-8d01-492aa5a35bbc -TargetMailbox 9dcd79ba-

b5eb-4a56-8b01-9c5c8fb55dd1

 

However I received the following message:

 

Source mailbox's legacyExchangeDN '/o=ExchangeLabs/ou=Exchange Administrative Goup

(FYDIBOHF23SPDLT)/cn=Recipients/cn=e833cbc5ffed497397c623443b8425ef-Johnny Five' doesn't match the legacyExchangeDN or

X500 proxy for target mailbox 'Johnny Five'. Use the 'AllowLegacyDNMismatch' switch if you want to allow this

operation.

    + CategoryInfo          : InvalidArgument: (9dcd79ba-b5eb-4a56-8b01-9c5c8fb55dd1:MailboxLocationIdParameter) [New-

   MailboxRestoreRequest], NonMatchingLega...SwitchException

    + FullyQualifiedErrorId : [Server=LO3P123MB3034,RequestId=4f8b4fbf-8d4f-4ef5-a994-53d691807686,TimeStamp=23/06/202

   0 12:32:15] [FailureCategory=Cmdlet-NonMatchingLegacyDNPermanentUseSwitchException] A90C5DD1,Microsoft.Exchange.Ma

  nagement.Migration.MailboxReplication.MailboxRestoreRequest.NewMailboxRestoreRequest

    + PSComputerName        : outlook.office365.com

 

 

Is it safe to use the AllowLegacyDNMismatch switch or will this cause me issues. I want to do this process so I can move to be completely cloud based and not require my on-prem accounts if that make sense.

 

Any help is appreciated

 

Thanks

 

Mark.

 

5 Replies
Highlighted
Solution

@oldhamuk 

 

Easiest way to go completely cloud only is to disable directory sync tenant wide using PowerShell as per the following link;

 

https://docs.microsoft.com/en-us/office365/enterprise/turn-off-directory-synchronization

 

This is only suitable if you are completely prepared for cloud only identity for all of your O365 objects however.

 

If you needed to do this on a per user basis, then the simplest way is to do what you did and delete the on-prem account, then wait for the sync.  The O365 account will move from Active Users to Deleted Users.  You may then choose the option to restore the user which will recreate it as a cloud only object.

 

If you have Exchange Hybrid, be careful of your mail flow though.  Make sure you take this into consideration too.

Highlighted

@PeterRising 

Thanks for your reply.  If I do that won't that mean the accounts will still show as Windows Server Accounts in Azure and then also mean I'm restricted on what I can edit for those users and mailboxes?

 

I may be using the incorrect term with Hybrid as all my mail routing is already directly to O365 the only thing I have left is an SBS box with the users that are sync'd  with AD Connect and the Exchange which is only use to administer the Exchange properties of those users.

 

Is that error I received something I need to be concerned with or can I go though the process and use 

AllowLegacyDNMismatch switch to proceed?

 

As far as I'm aware I believe I have everything in place to be fully cloud, like I said the on-prem SBS box isn't really doing anything now and I'm keen to remove it from my setup gracefully than have to try and unpick something if it fails on me at some point.

 

Thanks for your time and reply.

 

Mark 

Highlighted

@oldhamuk 

 

No, the opposite would be true.  The accounts would be cloud only and completely manageable from the O365 portal / Azure AD with no reliance to on-premises.

 

I've never done what you are trying to achieve using your method so I can't comment to that.  However, you could test the experience with a test account to check what the impact would be.

Highlighted

Oh right ok, so if I understand correctly if I follow that article you have referenced the account that have sync'd into Azure from my On-Prem will automatically change and the source in Azure Active Directory will change from Windows Server AD to Azure Active Directory and then I can decommission the on-prem server simple as that?

 

I'd rather do this the correct way rather than the way I discovered.

 

Thanks

 

Mark

Highlighted

@oldhamuk 

 

Absolutely correct yes.  Done it many times this way and it works great!  If your mailflow is already pointed to Exchange Online too then you are good to go with this.