We just moved from an on-prem Exchange 2013 server to a Office 365 with hosted Exchange. We have a handful of shared mailboxes that we use, such as info and orders.
With our on-prem Exchange server, I had a access based security groups set up for each of of the shared mailboxes, such as "shmb_info_fullaccess" and "shmb_orders_fullaccess". I also had role based security groups setup, such as "shared mailbox - info" and "shared mailbox - orders." Users would then be assigned to the role based security group. The role based security group would then be assigned to an access based security group. The access based security group would then be given permissions on the Exchange shared mailbox.
With Office 365 and hosted Exchange, it appears that the security group must be a Universal security group and also be mail-enabled in order to apply the security group to a shared mailbox. I have tested this and it seems to work as intended.
With that said, the following is my dilemma. In order to make the security group mail-enabled one must run the enable-distribution cmdlet from the Exchange Management Shell. Withut an on-prem Exchange server, one cannot run this command as the command is not supported with Office 365 hosted Exchange. Therefore, it does not seem that I can create a mail-enabled security group from within my on-prem AD. It seems that I must created the security group from within the hosted Exchange Admin Center.
When I create a security group within the hosted Exchange Admin Center, it shows the group within the Office 365 Admin Center that the group status is "In Cloud" and not "Synced with Active Directory." I am not sure if it is possible or not to get the security groups created in the Office 365 hosted Exchange to sync with my on-prem Active Directory or not. I like the idea of being able to manage all of my users, groups, etc. within my on-prem AD instead of bouncing between my on-prem AD and the Office 365 Admin Center.
I'd love to hear your feeback on my current situation. Maybe I am going about this all wrong.