DaveQuance
asked on
Exchange Online (Office 365): Mail-enable AD Sync'd Security group - without on-premise?
I have a local domain that has never had Microsoft Exchange setup. I'm migrating from one cloud-based email solution to Exchange Online (Office 365). There is *not* an on-premise Exchange server and will not be, as I know this is possible if there were. Without an on-premise Exchange, is it possible to mail-enable my security groups sync'd up?
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
Thank you for the info. I'm going to look at which attributes are required to trigger what I'm looking for in Exchange Online. My only concern is that since this has never had Exchange, the schema doesn't include the vast majority of the attributes used by Exchange.
I'll have a chance to look deeper a little later today and will post.
I'll have a chance to look deeper a little later today and will post.
How big is your org?
You can use scripting to populate ad attributes. Here is a good place to start.
https://blogs.technet.microsoft.com/heyscriptingguy/2013/03/21/use-the-powershell-ad-provider-to-modify-user-attributes/
You can use scripting to populate ad attributes. Here is a good place to start.
https://blogs.technet.microsoft.com/heyscriptingguy/2013/03/21/use-the-powershell-ad-provider-to-modify-user-attributes/
ASKER
I've no concerns on the scripting part, roughly 500 users. It's just more of the if the attributes I need aren't in the AD Schema, since Exchange has never extended it, then there wouldn't be a way to set them unless I ran a schema extension to create the attribute options.
Ah I understand. 👍
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
A change in plans made it a non-issue. Madison provided good information though.
Azure ad connect will create mailboxes and associate user accounts. It will sync password changes made in your domain. You can edit the extended user properties in ad users and computers to populate the necessary fields. You can do the same with groups.
https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directory-aadconnect
https://blogs.technet.microsoft.com/rmilne/2017/04/28/how-to-install-ad-fs-2016-for-office-365/