How to create users and shared mailboxes in a Hybrid Exchange environment. If you are running a hybrid environment, with Active Directory and Exchange on-premises together with Office 365 and Exchange Online, you need to keep your Exchange Server(s) to correctly manage your mailboxes.
The Exchange Management Console, Exchange Administration Center (EAC), and Exchange Management Shell are the only supported tools to manage Exchange recipients and objects.
Connect to your on-premises Exchange PowerShell first.
New-RemoteMailbox -Alias auser -Name "Alex User" -FirstName Alex -LastName User -OnPremisesOrganizationalUnit "OU=MyOrg,DC=domain,DC=com" -SamAccountName auser -UserPrincipalName alex.user@domain.com -ResetPasswordOnNextLogon:$false
I normally use a CSV file with Alias, DisplayName, FirstName, LastName, UPN columns:
Import-Csv .\new-users.csv | ForEach-Object {
New-RemoteMailbox `
-Alias $_.Alias `
-Name $_.DisplayName `
-FirstName $_.FirstName `
-LastName $_.LastName `
-SamAccountName $_.Alias `
-UserPrincipalName $_.UPN `
-OnPremisesOrganizationalUnit "OU=MyOrg,DC=domain,DC=com" `
-ResetPasswordOnNextLogon:$false
}
Your script should also add users into the required groups for licensing, assuming you are using group-based licensing — otherwise the mailbox will be deleted in 30 days.
New-Remotemailbox -Shared -Alias test_shared -Name "Test Shared" -FirstName Test -LastName Shared -OnPremisesOrganizationalUnit "OU=MyOrg,DC=domain,DC=com" -SamAccountName test_shared -UserPrincipalName test.shared@domain.com
When you create a shared mailbox like this, there is no password and the account will be disabled, as it should be. Shared mailboxes created correctly do not need any license since the account is disabled.
Do not create a shared mailbox by creating a normal user mailbox and converting it afterwards. That leaves Exchange on-premises believing the mailbox is still a user mailbox, and the AD attributes then have to be corrected by hand — see fixing shared mailboxes created as user mailboxes.
New-RemoteMailbox only creates the on-premises AD object and stamps it with the routing address for the cloud mailbox. Nothing appears in Exchange Online until directory sync has run and a licence has been applied:
Start-ADSyncSyncCycle -PolicyType Delta.Check the object on-premises before assigning anything:
Get-RemoteMailbox -Identity auser | Format-List Name, PrimarySmtpAddress, RemoteRoutingAddress
If the mailbox never shows up, check sync scope and the RemoteRoutingAddress first — a missing or wrong routing address is the usual cause, and the object will otherwise look correct in Active Directory.