Solved

Office 365 Post Migration Questions

Posted on 2014-10-03
5
252 Views
Last Modified: 2014-12-02
We have just completed our cutover migration to Office 365 with DirSync and I like a few things clarified that I cannot seem to find direct answers to online.
1- We have an on-premise exchange server that is linked to Office 365. I would expect to be able to add/modify email addresses here, but can only do so using ADSI or the Attribute editor in AD. IS this correct? Can I not manage email addresses using Exchange?
2- Secondary addresses added using ADSI with a precurser of smtp: function but do not appear in Office 365's email address list. Is this correct?
3- Single Sign on works, in that the users AD domain password also works for Office 365. Is there some way to extend this functionality? Example: Setting up a new mail profile for a user, autodiscover finds the account, but I still must enter their password to complete the sync. Can single sign on extend to profile setup? When a user changes their password, they must re-enter it in Outlook to re-connect. Can SSO handle this so that their password is detected from the domain?

Thanks for all the help! I am a champion Googler, but their appear to be no straight answers to any of the above!
0
Comment
Question by:JP_TechGroup
  • 3
  • 2
5 Comments
 
LVL 38

Expert Comment

by:Vasil Michev (MVP)
ID: 40360168
For cutover migration you cannot have disrync enabled. Do you mean staged migration? Or do you mean that you enabled dirsync after the cutover migration?

Both 1) and 2) can be explained if the on-prem object is not matched with the cloud one after you have run the dirsync (if you have run it). You might have to resort to 'soft-matching': http://support.microsoft.com/kb/2641663
Otherwise the answer is that you should indeed be able to manage them on-prem

3) There is no real single sign on experience with Outlook, it uses the basic authentication method. You can select the "Remember password" option, which will store it in the Credentials manager. Once the password is changed, you have to type/save it again.
0
 

Author Comment

by:JP_TechGroup
ID: 40367112
We enabled DIrSync after the migration was completed. On premise Exchange is able to modify a few attributes, but not Emails or Distribution lists. When we try to add an email address locally, we get an error that states:

--------------------------------------------------------
Microsoft Exchange Error
--------------------------------------------------------
The following error(s) occurred while saving changes:

Set-Mailbox
Failed
Error:
The operation on mailbox "******" failed because it's out of the current user's write scope. The action 'Set-Mailbox', 'EmailAddresses', can't be performed on the object '******' because the object is being synchronized from your on-premises organization. This action should be performed on the object in your on-premises organization.

The action 'Set-Mailbox', 'EmailAddresses', can't be performed on the object 'Amparo Carrera' because the object is being synchronized from your on-premises organization. This action should be performed on the object in your on-premises organization.

Dirsync is working and passwords sync up happily. New users added in AD locally sync and their mailbox is created as expected.

We have a similar issue adding users to groups. Worse, we cannot add or modify from the Office 365 console. We are told since we are syncing it must be done locally... hence, we are stuck.
0
 
LVL 38

Expert Comment

by:Vasil Michev (MVP)
ID: 40367180
DG ownership can be managed from dsa/ADSIEdit or directly from Outlook, check here: http://support.microsoft.com/kb/2417592

Your EMC console seems to be connected to Exchange Online, this is why it's giving you the error. Just edit the proxyaddresses attribute with dsa.exe. If you only want to change the primarysmtpaddress, you can use the following cmdlet (works for synced users as well):

Set-mailbox user@domain.com -WindowsEmailAddress new@domain.com
0
 

Author Comment

by:JP_TechGroup
ID: 40401790
So, I'm correct in thinking that I cannot use the EMC console to do anything but look?
0
 
LVL 38

Accepted Solution

by:
Vasil Michev (MVP) earned 500 total points
ID: 40401812
Depends on where the object is located, and where exactly in the EMC you are looking at (the on-prem node or the O365 one). The O365 node is basically an interface for remote PowerShell for EO, so if an object is synced from on-prem you will not be able to make changes. You will have to use the On-prem node and recipient config, etc.
0

Featured Post

Maximize Your Threat Intelligence Reporting

Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

Join & Write a Comment

Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
Find out what Office 365 Transport Rules are, how they work and their limitations managing Office 365 signatures.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This Experts Exchange video Micro Tutorial shows how to tell Microsoft Office that a word is NOT spelled correctly. Microsoft Office has a built-in, main dictionary that is shared by Office apps, including Excel, Outlook, PowerPoint, and Word. When …

706 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now