Logo
How to Create Users and Shared Mailboxes in an Exchange Hybrid Environment: Step-by-Step Guide
Exchange; Office 365

How to Create Users and Shared Mailboxes in an Exchange Hybrid Environment: Step-by-Step Guide

14 May 2019 By Hal Sclater

How to create users and shared mailboxes in a Hybrid Exchange environment. If you are running a hybrid environment, with Active Directory and Exchange on-premises together with Office 365 and Exchange Online, you need to keep your Exchange Server(s) to correctly manage your mailboxes.

The Exchange Management Console, Exchange Administration Center (EAC), and Exchange Management Shell are the only supported tools to manage Exchange recipients and objects.

Before you start

  • Run everything from on-premises Exchange PowerShell (the Exchange Management Shell). In a hybrid setup the objects have to be created on-premises and sync up — creating them directly in Exchange Online is not supported.
  • Check the OU you are targeting is in scope for directory sync, and that AD Connect is replicating normally.
  • Decide how licences will be assigned before you create anything. Group-based licensing is the usual approach: add the new user to the licence group in the same script, or the mailbox will be unlicensed once sync completes.

Using PowerShell

Connect to your on-premises Exchange PowerShell first.

Creating Users

New-RemoteMailbox -Alias auser -Name "Alex User" -FirstName Alex -LastName User -OnPremisesOrganizationalUnit "OU=MyOrg,DC=domain,DC=com" -SamAccountName auser -UserPrincipalName alex.user@domain.com -ResetPasswordOnNextLogon:$false

I normally use a CSV file with Alias, DisplayName, FirstName, LastName, UPN columns:

Import-Csv .\new-users.csv | ForEach-Object {
    New-RemoteMailbox `
        -Alias $_.Alias `
        -Name $_.DisplayName `
        -FirstName $_.FirstName `
        -LastName $_.LastName `
        -SamAccountName $_.Alias `
        -UserPrincipalName $_.UPN `
        -OnPremisesOrganizationalUnit "OU=MyOrg,DC=domain,DC=com" `
        -ResetPasswordOnNextLogon:$false
}

Your script should also add users into the required groups for licensing, assuming you are using group-based licensing — otherwise the mailbox will be deleted in 30 days.

Creating Shared Mailboxes

New-Remotemailbox -Shared -Alias test_shared -Name "Test Shared" -FirstName Test -LastName Shared -OnPremisesOrganizationalUnit "OU=MyOrg,DC=domain,DC=com" -SamAccountName test_shared -UserPrincipalName test.shared@domain.com

When you create a shared mailbox like this, there is no password and the account will be disabled, as it should be. Shared mailboxes created correctly do not need any license since the account is disabled.

Do not create a shared mailbox by creating a normal user mailbox and converting it afterwards. That leaves Exchange on-premises believing the mailbox is still a user mailbox, and the AD attributes then have to be corrected by hand — see fixing shared mailboxes created as user mailboxes.

What happens after you create a mailbox

New-RemoteMailbox only creates the on-premises AD object and stamps it with the routing address for the cloud mailbox. Nothing appears in Exchange Online until directory sync has run and a licence has been applied:

  1. Wait for an AD Connect sync cycle, or force one on the AD Connect server with Start-ADSyncSyncCycle -PolicyType Delta.
  2. Assign a licence — via the group you added the user to, or directly in the Microsoft 365 admin centre. Until a licence is applied the cloud mailbox is soft-deleted after 30 days.
  3. Send a test message to the new address and confirm it arrives.

Check the object on-premises before assigning anything:

Get-RemoteMailbox -Identity auser | Format-List Name, PrimarySmtpAddress, RemoteRoutingAddress

If the mailbox never shows up, check sync scope and the RemoteRoutingAddress first — a missing or wrong routing address is the usual cause, and the object will otherwise look correct in Active Directory.