Cloud Mailbox full Access permission for terminated On-Premises employee not sync with Azure AD

In Hybrid Environment.

I have one user which has been moved to cloud and he had full  access permission on terminated mailbox (Disable account in AD). But after moving mailbox to cloud lost the access for terminated On-Premise mailbox which is not synced with Azure AD

1) How can we give full permission to cloud mailbox for the terminated mailbox which is not synchronized in Azure AD.

2.) I was trying to give full permission on terminated mailbox through Exchange On-Premise ECP but cloud mailbox not showing in search delegation ?

3)  Is there anyway we can give cloud user full access for terminated mailbox which is not synced with Azure AD ?
Ali-Raza111Asked:
Who is Participating?
 
MaheshArchitectCommented:
you cannot mix permissions between onpremise and cloud
cloud id can grant permissions on cloud mailbox, on premise user can grant permissions on onpremise mailbox
0
 
Ali-Raza111Author Commented:
We cannot give disable mailbox full access permission to mailbox in the cloud?

I didn't see anywhere document, please share if you come across with any reference?

Appreciate your input..
0
 
MaheshArchitectCommented:
When you said terminated mailbox, what it means?
Once you moved mailbox to cloud, how come your onprem user control it?
The onprem and cloud have different directories
If u could explain technically what you are trying to do, ur problem would get resolved
0
Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

 
Ali-Raza111Author Commented:
Okay,
Terminated mailbox -- employee get terminated and he has mainbox on premises not sync with Azure AD.

Manager (Mailbox) had full mailbox access when he was on-premises to the terminated mailbox which is on premises.

We moved the manager (mailbox) to cloud after that he lost the access of terminated employee on-premise mailbox.

In hybrid full mailbox access permission supported in cross premises

But in my scenario-- Manager mailbox move to cloud and his terminated employee (mailbox) is on-premises and interesting note here is terminated employee (who left the company) not sync with Azure AD.

So the question is -- how can we give again full mailbox access to cloud mailbox for the terminated employee.
0
 
timgreen7077Exchange EngineerCommented:
Cross forest permissions between O365 and on-prem exchange hybrid are now supported. so you should be able to give full manage permissions to an on-prem user to a mailbox located in O365 and vice versa. if this isn't working for you, I would suggest making sure that you have the latest AD Connect software installed. Also be sure that you have the latest Hybrid software running. Run the hybrid wizard from O365 Exchange Online to be sure you are getting the latest version. If both are up to date, try to run a full AD sync again by running the following cmdlets

Start-ADSyncSyncCycle -PolicyType Initial

Actually I would try the full sync first and if that don't fix it, I would try the updates.

If this doesn't work you can contact O365 support and get assistance as to why it's not working, or just move the termed user mailbox to O365 also and then the manage mailbox will be able to access it.
0
 
MaheshArchitectCommented:
OK
Your manager lost access to terminated mailbox as soon as he got moved to Exchange online, this is expected behavior
Because these permissions are set on terminated mailbox by another onpremise user *mailbox* and in your case manager don't have mailbox onpremise, you have moved it to cloud and since OnPrem and cloud both directories are different, you cannot assign cloud mailbox full access permissions on onpremise mailbox.
In short, in order to grant someone full access on other mailbox, he also must have mailbox, then only scenario will work
https://technet.microsoft.com/en-us/library/jj919240(v=exchg.160).aspx

even if you use group to grant full control access permissions, group members should have mailbox
0
 
Ali-Raza111Author Commented:
Thanks for the input,

Everything is according to MS best practice.

If terminated mailbox is not Sync with Azure AD,

Can we give full mailbox access to cloud mailbox for mailbox on-premise not sync with Azure AD.

So manager mailbox in the cloud can respond to terminated employee (mailbox) on-premise?
0
 
timgreen7077Exchange EngineerCommented:
well there still needs to be a sync of the user objects in place. sync the termed user object so that Azure AD will know about the object and it's email attributes.
0
 
MaheshArchitectCommented:
OK
@Timgreen:
Thanks for information.
However the feature OP looking for is still being rolled out and will be completely rolled out until April 2018
https://technet.microsoft.com/en-us/library/jj200581(v=exchg.150).aspx
1
 
timgreen7077Exchange EngineerCommented:
ah @Mahesh got it. Thanks for that update. Good catch. I wasn't aware of that date. i thought it was already fully active.
0
 
timgreen7077Exchange EngineerCommented:
Answer has been provided. Closing ticket.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.