Azure AD Connect and removal of on-prem Exchange 2010 server

Thomas Bluhme Andersen 21 Reputation points
2020-02-18T12:47:21.247+00:00

Hi

We have been running Azure AD Connect for a while now syncing users to O365 mainly for password syncing reasons. The sync is scoped so that only members of a specific AD security group gets synced. We only sync one-way meaning on-prem to Office365.

We are now about to migrate all mailboxes on the old on-prem Exchange 2010 server to O365. We are not running a hybrid environment, so migration will be made using a 3rd party tool. This will be done later this week.

Now I am getting a little concerned regarding the decommission of the old Exchange 2010 server after all mailboxes have been migrated. Azure AD Connect is running just fine with pretty much default settings, so I believe that it is also syncing a lot of Exchange attributes from the On-Prem AD and I am concerned that when I decommission the Exchange 2010 server I also remove the Exchange attributes from the local AD and it's users. I suspect this as I get the error message when trying to hide a user from O365 address book.

The operation on mailbox "USERNAME REMOVED" failed because it's out of the current user's write scope. The operation on mailbox failed because it’s out of the current users’s write scope. The action ‘Set-Mailbox’, ‘HiddenFromAddressListsEnabled’, can’t be performed on the object because the object is being synchronized from your on-premises organization. This action should be performed on the object in your on-premises organization. I also get a similar error while trying to edit one of the users email addresses.

So I am concerned that when I decommission the old Exchange 2010 server, a lot of Exchange attributes are removed on-prem (which is fine), but I fear that these removals will be synced to Office 365 thereby removing them there too...for example email addresses and such.

Can anyone please tell me if I need to be careful here and take some kind of action before I decommission the on-prem Exchange server or if my concerns are without reason.

Best
Thomas

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,418 questions
0 comments No comments
{count} votes

Accepted answer
  1. Riegler, Wolfgang 81 Reputation points
    2020-02-18T13:28:26.907+00:00

    If you have synced identities, an Exchange Management Server should remain on premise. The clean way to do object changes is to do the changes on premise and let AAD connct sync the changes to Azure.

    https://techcommunity.microsoft.com/t5/exchange-team-blog/decommissioning-your-exchange-2010-servers-in-a-hybrid/ba-p/597185

    Full cloud management will come in future (hopefully)

    1 person found this answer helpful.

2 additional answers

Sort by: Most helpful
  1. Vasil Michev 95,081 Reputation points MVP
    2020-02-18T17:03:12.56+00:00

    If you want to decommission the Exchange server, you need to remove AAD Connect first. Since the link to the On-Prem AD will then be broken, the objects will be manageable directly in O365 and any changes made to attributes after removing the Exchange server wont impact them. If you still want to use AAD Connect, you must keep at least one Exchange server for management purposes.

    1 person found this answer helpful.

  2. Thomas Bluhme Andersen 21 Reputation points
    2020-04-28T06:00:29.217+00:00

    Hi, after a lot of "deep thinking" I ended up pulling the plug on the Exchange 2010 servers and crossing my fingers. Almost everything worked as it should (not messing much up), but I needed to manually add emailadress and smtpproxyaddresses for all users in AD afterwards, as they had been blanked when Exchange 2010 was removed. Not a big problem as it was only 60-70 users, so an hour of manual input and everything was good. Probably more settings was deleted when Exch2010 was removed but this being a pretty simple setup nothing that was being used :)

    And yes Exchange attributes such as "hide from addressbook" I have to manage locally in AD attribute editor so that they are synced from AD to 365.... or use a third party tool......found one that actually plugs into ADUC and adds an extra tab but I haven't decided yet if I need it as I'm used to the attribute editor.

    So many thanks for all the input, over and out :)