Exchange Online Protection transition from Forefront Online Protection for Exchange

Posted on 2014-01-29
Last Modified: 2014-11-12
Anyone here use Forefront Online Protection for Exchange (FOPE) and have your services transitioned over to Exchange Online Protection? The process is confusing, because Exchange Online Protection doesn't seem to show the distribution groups from the organization whereas FOPE used to show these. I've already installed the Azure Directory Sync Tool.

Under recipients in the Exchange Admin Center, all I see are "Users" and "Contacts". Nothing for distribution groups.

I called into their support but got a guy with a thick accent and probably overseas as there seemed to be a delay where he could hear me. I couldn't make much sense of what he was telling me and i don't think he understood what I was trying to relay to him. He seemed to relay that they are aware of the distribution groups on the back end but they won't show on EAC.

I don't want to switch over my MX records until I'm sure that EOP can handle emails to the distribution groups. help!
Question by:HornAlum
LVL 14

Expert Comment

by:Shabarinath Ramadasan
ID: 39820111
We have a similar infrastructure but using Hybrid setup. We have FOPE as part of the O365 Subscription however, yet to start the mail routing through FOPE.

Could you please let me know if you are doing a full sync or partial sync from On-Premise to cloud? I have done a partial sync based on a custom attribute and I could see the groups which I have set the value correctly to be synced.

Cheers !

Author Comment

ID: 39820798
we are doing a full sync i believe. Partial sync was not an option in the azure tool
LVL 20

Accepted Solution

Svet Paperov earned 400 total points
ID: 39821154
We also have been transferred to OEP from FOPE. And, I have to say it, I am a little bit disappointed. We had the same setup: Exchange on-premises with FOPE before and it was much easier to manage with more features available.

I tried Azure Sync Tool but I had to revert to In-Cloud management of the addresses because it messed up with my accounts and uploaded far more users (including AD accounts without e-mails addresses) than I actually had in FOPE.

About the distribution groups: I believe the Sync Tool uploads the static distribution groups only but not the dynamic once (at least in my case it was like that). You should be able to see the uploaded groups when you go to Users and Groups – Manage mail contacts.

However, even if the group is not listed, the emails sent to it will be treated and forwarded. EOP does not have Directory blocking yet, as it was in FOPE, so all messages, even for addresses that do not exist in EOP will be forwarded to your Exchange.

Shabarinath Thekkemeppully Ramadasan: how do you do partial Synch? I would like to have it but I didn’t find any configuration option in the current version of Azure Directory Synch Tool. Could you provide more information, please?
Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!


Assisted Solution

HornAlum earned 0 total points
ID: 39824455
I agree, FOPE seemed much friendlier and granular. I'm not liking EOP so far. I also see some contacts in the 365 console that don't even exist anymore in our current on-premise.

ok ... I just uncovered something really strange.

if you go to the Exchange Admin Console, then Recipients, you only see "Users" and "Contacts"

If you go back to the Office 365 console, then "Users and Groups" and "Manage Mail Contacts", you see "Groups" and "contacts", and wha-la, there are the groups.

what the crap? this is so disorganized
LVL 20

Expert Comment

by:Svet Paperov
ID: 39824495
I completely agree. And I found the same things.

That's way I decided not to use Dir Synch.

In FOPE, Dir Synch was very useful because of Directory blocking but since there is no Directory blocking in EOP yet, and the end-user cannot logon to his Quarantine.. again yet, I don't see way should I complicate my life with this synch.

It's "wait and see" for me.

Author Comment

ID: 39824501
I can't see not using DirSync right now though, because there's no way i want to manage accounts/groups in two separate places.
LVL 32

Expert Comment

by:Robberbaron (robr)
ID: 40103445
I too have been forced into the transition and DIrSync does not sync mail-enabled public folders at all.
1. My distrib groups got synced, including some that used to be internal-only !  So they do show up for me using DirSync.  Where are they in your AD tree ?  (mine were below our OrgUnit)

2. DirectoryEdge blocking is on for us (maybe cause MS did much of the migration automatically) and working.....  But this BLOCKED our main as this an email address is to a public folder named ReceptionMail.  And unless you look hard, I didnt realise that PF's were not synced like they were with the FOPE sync tool.

There is a script floating around that creates contacts for each mail-enabled public folder and these should sync but no luck for me.

3. @HornAlum.. I cant workout how you saw the groups ....

Author Closing Comment

ID: 40334199
i was able to find the location where the groups were stored

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Encryption for Business Encryption ( ensures the safety of our data when sending emails. In most cases, to read an encrypted email you must enter a secret key that will enable you to decrypt the email. T…
Azure Functions is a solution for easily running small pieces of code, or "functions," in the cloud. This article shows how to create one of these functions to write directly to Azure Table Storage.
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…
how to add IIS SMTP to handle application/Scanner relays into office 365.

679 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question