How to disconnect a mailbox & re-assign it to new user in a Hybrid Scenario
Scenario objectives: We have an Exchange Hybrid setup between on-premises and Exchange Online (Office 365). All users are synced and the mailbox is located at Exchange Online.
We need to separate an existing mailbox from its user account and re-connect this mailbox to a new user account. If the mailbox in this scenario was located at the on-premises Exchange it would be an easy process just using the Exchange Management Console. But in a Hybrid scenario, the process includes many steps since the mailbox is not directory conencted to the Active Directory user account but it is conected to the Azure AD Synced User Account.
For the ease of the guide we will name the Existing User Account: OLDUSER and the New User Account: NEWUSER.
We will disconnect the Exchange Online Mailbox from the OLDUSER and connect it to the NEWUSER.
At the on-premises Active Directory, at an OU that is not synced with Azure AD, create the new user account. The “NEWUSER”. Ensure that you do not enter nothing at the email field. Just a user account with no email attributes.
Move the “OLDUSER” to an OU that is not synced with Azure AD
Run a Delta Sync. Go to the server that the AD Connect is installed, open the PowerShell and run “Start-ADSyncSyncCycle”
We need to get the GUID of the NEWUSER. To do so login to a Domain Controller, open PowerShell and run:
Copy the GUID to a Notepad
Open the Office 365 Admin Center and Restore the deleted user “OLDUSER”
Go to Users –> Deleted Users –> Select the user “OLDUSER” –>Click Restore
Connect to Azure AD and set the GUID of the “NEWUSER” to the Office 365 “OLD USER”. Details for connecting to Azure AD “https://technet.microsoft.com/en-us/library/dn975125.aspx“
Connect-MsolService Set-MsolUser -UserPrincipalName [email protected] -ImmutableId vMZGJpW6CUGY09bduJ5dlw==
Open the Office 365 Admin Center and Delete the old user “OLDUSER”
Go to Users –> Active users –> Select the “OLDUSER” –> click Delete user
Clean the on-premises Active Directory account of the old user “OLDUSER” from all attributes that will be added to the new user, like Proxy addresses, Target, address, Alias name, nickname etc.
Make the “NEWUSER” user account a Remote Mailbox object
At the on-premises Exchange, open the Exchange Management Shell and run:
Enable-RemoteMailbox -Identity NEWUSER -DisplayName "NEW USER" -RemoteRoutingAddress [email protected] -Alias newuser -PrimarySmtpAddress [email protected]
Move the “NEWUSER” to an OU that is Synced with Azure AD and run a Delta Sync like Step 3.
After that the “NEWUSER” active directory account will be connected with the “OLDUSER” Exchange Online mailbox and all attributes of the Exchange Online mailbox will be replaced with the “NEWUSER’s” values.
I suppose there are other ways, maybe easier, to accomplish this task, but following this process you will have the desired result without problems.
Pantelis Apostolidis is a Cloud Solutions Architect at Microsoft and an ex Microsoft Azure MVP. For the last 15 years, Pantelis has been involved to major cloud projects in Greece and abroad, helping companies to adopt and deploy cloud technologies, driving business value. He is entitled to a lot of Microsoft Expert Certifications, demonstrating his proven experience in delivering high quality solutions. He is an author, blogger and he is acting as a spokesperson for conferences, workshops and webinars. He is also an active member of several communities as a moderator in azureheads.gr and autoexec.gr. Follow him on Twitter @papostolidis.