How to create users and shared mailboxes in a Hybrid Exchange environment.
If you are running a hybrid environment, with Active Directory and Exchange on-premises together with Office 365 and Exchange Online, you should already know that you need to keep your Exchange Server(s) in order to be able to correctly manage your mailboxes as per https://docs.microsoft.com/en-gb/exchange/decommission-on-premises-exchange:
‘The Exchange Management Console, the Exchange Administration Center (EAC), and the Exchange Management Shell are the only supported tools that are available to manage Exchange recipients and objects.’
So, whilst you could just sync users to Azure AD and license them for an Exchange Online license which will create a mailbox, it will be difficult to manage the accounts, they will not appear in your on-premises EAC, and you will have to resort to the AD attribute editor or another tool in order to configure additional SMTP addresses etc, which is not supported. Not only that, if you are still routing mail via your on-premises servers, since the accounts will have no target address they won’t be able to receive email, and any non-migrated user will be unable to email them.
So, with this in mind, what is the correct way of creating users and shared mailboxes?
Using the EAC
Whilst you could use the good old EAC, this has significant drawbacks:
- You cannot create a mailbox for a pre-existing user in AD
- You can’t create an online archive at the same time, you would have to enable this later
- You cannot create an online shared mailbox at all using EAC
You shouldn’t have to modify your whole joiners and leavers process to work around these limitations, so you should do this the right (and easy) way, using PowerShell. Then you can always view the properties and modify them later if you are die hard GUI fan.
I accommodate the following commands into PowerShell scripts, typically importing CSV files in order to create multiple accounts at the same time. But here are the commands to get you started. These will create a user account in the OU specified, along with all the correct attributes. The mailbox will be created once the account has synced up to Azure AD.
Connect to your on-premises Exchange PowerShell first (note that the -shared switch requires 2013 or later).
1 New-RemoteMailbox -Alias auser-Name "Alex User" -FirstName Alex -LastName User -OnPremisesOrganizationalUnit "OU=MyOrg,DC=domain,DC=com" -SamAccountName auser -UserPrincipalName firstname.lastname@example.org -ResetPasswordOnNextLogon:$false
1 $securePass = (ConvertTo-SecureString -String $newUser.Password -AsPlainText -Force)