Cloud Mailbox full Access permission for terminated On-Premises employee not sync with Azure AD

In Hybrid Environment.

I have one user which has been moved to cloud and he had full  access permission on terminated mailbox (Disable account in AD). But after moving mailbox to cloud lost the access for terminated On-Premise mailbox which is not synced with Azure AD

1) How can we give full permission to cloud mailbox for the terminated mailbox which is not synchronized in Azure AD.

2.) I was trying to give full permission on terminated mailbox through Exchange On-Premise ECP but cloud mailbox not showing in search delegation ?

3)  Is there anyway we can give cloud user full access for terminated mailbox which is not synced with Azure AD ?
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

you cannot mix permissions between onpremise and cloud
cloud id can grant permissions on cloud mailbox, on premise user can grant permissions on onpremise mailbox

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Ali-Raza111Author Commented:
We cannot give disable mailbox full access permission to mailbox in the cloud?

I didn't see anywhere document, please share if you come across with any reference?

Appreciate your input..
When you said terminated mailbox, what it means?
Once you moved mailbox to cloud, how come your onprem user control it?
The onprem and cloud have different directories
If u could explain technically what you are trying to do, ur problem would get resolved
Creating Active Directory Users from a Text File

If your organization has a need to mass-create AD user accounts, watch this video to see how its done without the need for scripting or other unnecessary complexities.

Ali-Raza111Author Commented:
Terminated mailbox -- employee get terminated and he has mainbox on premises not sync with Azure AD.

Manager (Mailbox) had full mailbox access when he was on-premises to the terminated mailbox which is on premises.

We moved the manager (mailbox) to cloud after that he lost the access of terminated employee on-premise mailbox.

In hybrid full mailbox access permission supported in cross premises

But in my scenario-- Manager mailbox move to cloud and his terminated employee (mailbox) is on-premises and interesting note here is terminated employee (who left the company) not sync with Azure AD.

So the question is -- how can we give again full mailbox access to cloud mailbox for the terminated employee.
timgreen7077Exchange EngineerCommented:
Cross forest permissions between O365 and on-prem exchange hybrid are now supported. so you should be able to give full manage permissions to an on-prem user to a mailbox located in O365 and vice versa. if this isn't working for you, I would suggest making sure that you have the latest AD Connect software installed. Also be sure that you have the latest Hybrid software running. Run the hybrid wizard from O365 Exchange Online to be sure you are getting the latest version. If both are up to date, try to run a full AD sync again by running the following cmdlets

Start-ADSyncSyncCycle -PolicyType Initial

Actually I would try the full sync first and if that don't fix it, I would try the updates.

If this doesn't work you can contact O365 support and get assistance as to why it's not working, or just move the termed user mailbox to O365 also and then the manage mailbox will be able to access it.
Your manager lost access to terminated mailbox as soon as he got moved to Exchange online, this is expected behavior
Because these permissions are set on terminated mailbox by another onpremise user *mailbox* and in your case manager don't have mailbox onpremise, you have moved it to cloud and since OnPrem and cloud both directories are different, you cannot assign cloud mailbox full access permissions on onpremise mailbox.
In short, in order to grant someone full access on other mailbox, he also must have mailbox, then only scenario will work

even if you use group to grant full control access permissions, group members should have mailbox
Ali-Raza111Author Commented:
Thanks for the input,

Everything is according to MS best practice.

If terminated mailbox is not Sync with Azure AD,

Can we give full mailbox access to cloud mailbox for mailbox on-premise not sync with Azure AD.

So manager mailbox in the cloud can respond to terminated employee (mailbox) on-premise?
timgreen7077Exchange EngineerCommented:
well there still needs to be a sync of the user objects in place. sync the termed user object so that Azure AD will know about the object and it's email attributes.
Thanks for information.
However the feature OP looking for is still being rolled out and will be completely rolled out until April 2018
timgreen7077Exchange EngineerCommented:
ah @Mahesh got it. Thanks for that update. Good catch. I wasn't aware of that date. i thought it was already fully active.
timgreen7077Exchange EngineerCommented:
Answer has been provided. Closing ticket.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today

From novice to tech pro — start learning today.