Sync users which works as linkedmailbox

%3CLINGO-SUB%20id%3D%22lingo-sub-1549848%22%20slang%3D%22en-US%22%3ESync%20users%20which%20works%20as%20linkedmailbox%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1549848%22%20slang%3D%22en-US%22%3E%3CP%3EHello%2C%3C%2FP%3E%3CP%3EI%20want%20to%20sync%20some%20users%20to%20office%20365%20using%20ADconnect%20while%20the%20users%20have%20the%20value%20msExchRecipientTypeDetails%20equal%202%20which%20means%20that%20it's%20a%20linked%20mailbox%20%2Ccurrently%20the%20ADconnect%20filter%20them%20and%20is%20not%20syncing%20them%20(these%20accounts%20are%20enabled)%20and%20also%20I%20won't%20be%20able%20to%20change%20the%20attribute%20msExchRecipientTypeDetails%20as%20recommended%20in%20this%20article%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-ca%2Ftroubleshoot%2Fazure%2Factive-directory%2Fuser-object-missing-filtered%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-ca%2Ftroubleshoot%2Fazure%2Factive-directory%2Fuser-object-missing-filtered%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1549848%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAD%20Connect%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1551912%22%20slang%3D%22en-US%22%3ERe%3A%20Sync%20users%20which%20works%20as%20linkedmailbox%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1551912%22%20slang%3D%22en-US%22%3E%3CP%3EHey%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F741162%22%20target%3D%22_blank%22%3E%40Moataz_shaaban900%3C%2FA%3E%26nbsp%3B%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EFrom%20the%20same%20article%20you%20shared%2C%20When%20you%20have%26nbsp%3B%3CSPAN%3EmsExchRecipientTypeDetails%20equal%202%2C%20AADC%3C%2FSPAN%3E%3CSPAN%3Eonnect%20is%20waiting%20for%20the%20master%20account%20(from%20account%20forest)%20to%20be%20synchronized%20first.%20Do%20you%20still%20have%20a%20requirement%20for%20using%20linked%20mailboxes%20%3F%20If%20yes%2C%20then%20you%20would%20have%20to%20sync%20the%20master%20account%20first%2C%20rest%20aadconnect%20will%20process%20and%20associate%20them.%20If%20you%20are%20no%20longer%20using%20the%20linked%20mailboxes%20and%20probably%20have%20already%20got%20rid%20of%20account%20forest%2C%20you%20can%20very%20well%20convert%20the%20linked%20mailbox%20into%20a%20regular%20mailbox%20and%20then%20synchronize%20the%20object%2C%20linked%20to%20resource%20mailbox%20coversion%3A%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3ESet-User%20-Identity%20abc%40domainname.com%20-LinkedMasterAccount%20%24null%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EThanks%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1551951%22%20slang%3D%22en-US%22%3ERe%3A%20Sync%20users%20which%20works%20as%20linkedmailbox%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1551951%22%20slang%3D%22en-US%22%3EActually%20syncing%20from%20account%20forest%20is%20technically%20is%20impossible%20due%20to%20a%20long%20story%20(even%20that%20confirmed%20by%20Microsoft%20support)%2Cso%20the%20workaround%20was%20to%20use%20the%20resource%20forest%20but%20users%20still%20access%20this%20mailboxes%20from%20users%20forest%20so%20I%20can't%20convert%20them%3CBR%20%2F%3E%3CBR%20%2F%3EI%20was%20looking%20for%20modifying%20the%20sync%20rules%20to%20allow%20sync%20the%20linkedmailbox%20accounts%20after%20enable%20them%20but%20I%20am%20not%20sure%20if%20that%20applicable%20or%20not%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1551991%22%20slang%3D%22en-US%22%3ERe%3A%20Sync%20users%20which%20works%20as%20linkedmailbox%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1551991%22%20slang%3D%22en-US%22%3EWell%2C%20in%20that%20case%20you%20can%20technically%20exclude%20the%20attribute%20from%20Aadconnect%20and%20you%20will%20be%20able%20to%20sync%20the%20user%2C%20but%20first%20you%20need%20to%20decide%20on%20further%20steps%2C%20if%20your%20plan%20is%20to%20setup%20hybrid%20later%20to%20migrate%20the%20mailboxes%2C%20not%20synchronizing%20recipienttypedetails%20would%20cause%20issues%2C%20if%20you%20are%20just%20looking%20to%20use%20other%20services%20in%20office%20365%20and%20not%20exchange%20you%20can%20simply%20exclude%20all%20exchange%20related%20attributes%20from%20synchronization%20and%20sync%20the%20user%2C%20beware%20that%20when%20you%20don't%20synchronize%20exchange%20attributes%20and%20you%20assign%20an%20exchange%20license%20to%20the%20user%2C%20o365%20will%20provision%20a%20new%20mailbox%20for%20the%20user.%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1552686%22%20slang%3D%22en-US%22%3ERe%3A%20Sync%20users%20which%20works%20as%20linkedmailbox%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1552686%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F67895%22%20target%3D%22_blank%22%3E%40harveer%20singh%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EYes%20this%20my%20point%20I%20will%20use%20other%20services%20than%20Exchange%20online%2C%20so%20please%20advice%20How%20should%20I%20exclude%20the%20Exchange%20attributes%20%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1552750%22%20slang%3D%22en-US%22%3ERe%3A%20Sync%20users%20which%20works%20as%20linkedmailbox%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1552750%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20%2C%3C%2FP%3E%3CP%3EI%20managed%20to%20sync%20the%20linked%20mailboxes%20after%20changing%204%20rules%20in%20AD%20connect%20%3A%3C%2FP%3E%3CP%3EIn%20from%20AD%20-%20user%20join%3C%2FP%3E%3CP%3EIn%20from%20AD%20-%20user%20accountEnaled%3C%2FP%3E%3CP%3EIn%20from%20AD-%20user%20common%20from%20Exchange%3C%2FP%3E%3CP%3EIn%20From%20AD%20-%20user%20common%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Eby%20changing%20any%20rule%20related%20to%20msexchrecipienttype%20eq%202%20%2C%20to%20be%20for%20example%20related%20to%20msexchrecipienttype%20eq%2044%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1553149%22%20slang%3D%22en-US%22%3ERe%3A%20Sync%20users%20which%20works%20as%20linkedmailbox%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1553149%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F742186%22%20target%3D%22_blank%22%3E%40Moataz_shaaban1245%3C%2FA%3E%26nbsp%3B%3A%20Great%20!%20synchronization%20rule%20editor%20has%20always%20been%20the%20classic%20way%20to%20do%20things%2C%20with%20new%20Aadconnect%20version%20you%20do%20get%20another%20option%20as%20well%20using%20%3CSTRONG%3Eoptional%20features%3C%2FSTRONG%3E%2C%20%3CSTRONG%3EAzure%20AD%20app%20and%20filtering%3C%2FSTRONG%3E%20and%20then%20deselecting%20%3CSTRONG%3EAzureAD%20attributes%3C%2FSTRONG%3E%20that%20you%20want%20to%20export.%20Ref%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Fhow-to-connect-install-custom%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Fhow-to-connect-install-custom%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Visitor

Hello,

I want to sync some users to office 365 using ADconnect while the users have the value msExchRecipientTypeDetails equal 2 which means that it's a linked mailbox ,currently the ADconnect filter them and is not syncing them (these accounts are enabled) and also I won't be able to change the attribute msExchRecipientTypeDetails as recommended in this article https://docs.microsoft.com/en-ca/troubleshoot/azure/active-directory/user-object-missing-filtered

6 Replies

Hey @Moataz_shaaban900 ,

 

From the same article you shared, When you have msExchRecipientTypeDetails equal 2, AADConnect is waiting for the master account (from account forest) to be synchronized first. Do you still have a requirement for using linked mailboxes ? If yes, then you would have to sync the master account first, rest aadconnect will process and associate them. If you are no longer using the linked mailboxes and probably have already got rid of account forest, you can very well convert the linked mailbox into a regular mailbox and then synchronize the object, linked to resource mailbox coversion:

 

Set-User -Identity abc@domainname.com -LinkedMasterAccount $null

 

Thanks

 

Actually syncing from account forest is technically is impossible due to a long story (even that confirmed by Microsoft support),so the workaround was to use the resource forest but users still access this mailboxes from users forest so I can't convert them

I was looking for modifying the sync rules to allow sync the linkedmailbox accounts after enable them but I am not sure if that applicable or not
Well, in that case you can technically exclude the attribute from Aadconnect and you will be able to sync the user, but first you need to decide on further steps, if your plan is to setup hybrid later to migrate the mailboxes, not synchronizing recipienttypedetails would cause issues, if you are just looking to use other services in office 365 and not exchange you can simply exclude all exchange related attributes from synchronization and sync the user, beware that when you don't synchronize exchange attributes and you assign an exchange license to the user, o365 will provision a new mailbox for the user.

@harveer singh 

 

Yes this my point I will use other services than Exchange online, so please advice How should I exclude the Exchange attributes ?

Hi ,

I managed to sync the linked mailboxes after changing 4 rules in AD connect :

In from AD - user join

In from AD - user accountEnaled

In from AD- user common from Exchange

In From AD - user common

 

by changing any rule related to msexchrecipienttype eq 2 , to be for example related to msexchrecipienttype eq 44

 

 

 

 

@Moataz_shaaban1245 : Great ! synchronization rule editor has always been the classic way to do things, with new Aadconnect version you do get another option as well using optional features, Azure AD app and filtering and then deselecting AzureAD attributes that you want to export. Ref: https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-install-custom

 

Thanks.