New Post has been published on o365info.com
New Post has been published on http://o365info.com/migrating-exchange-on-premises-mailboxes-separately-exchange-hybrid-based-environment-what-are-the-migrated-permissions-part-5-of-5/
Migrating Exchange on-Premises Mailboxes Separately | Exchange Hybrid based environment | What are the migrated permissions? | Part 5#5Â
In the current article, we will review the mail migration scenario in which we âbreakâ existing Exchange permissionâs relationship.I use the term âbreakâ because in this scenario we are migrating only one partner from the existing âcoupleâ to the cloud.
When we migrate Exchange on-Premises mailboxes in the cloud not as a âgroupâ we are actually creating a âcross site permissionsâ scenario in which the object from Exchange on-Premises environment needs to have permissions on âcloud mailboxesâ and vice versa.
Article series Table of content | Click to expend
Cross site permission and migrated permissions in Exchange Hybrid based environment | Part 1#5
Testing cross site permissions in Exchange Hybrid based environment| Part 2#5
Migrated permissions of migrated mailboxes in Exchange Hybrid based environment â Introduction | Part 3#5
Migrating Exchange on-Premises mailboxes as a group | Exchange Hybrid based environment | What are the migrated permissions? | Part 4#5
Migrating Exchange on-Premises Mailboxes Separately | Exchange Hybrid based environment | What are the migrated permissions? | Part 5#5
Generally speaking, this scenario is not recommended by Microsoft. The thing is that, in reality, this type of scenario is implemented because many reasons such as specific limitations or, a lack of knowledge about the preferred scenario (migrating Exchange on-Premises mailboxes as a group).
For this reason, itâs important that we will know what are the Disadvantages of the mail migration method, meaning â what are the mailbox migration that will not be migrated to the cloud when we âbreakâ existing Exchange permissionâs relationship that exists between Exchange on-Premises mailboxes.
The formal Microsoft information about such type of scenario.
The interesting thing that in the current time, there is no formal information published by Microsoft about such type of scenario.
The only option that we have is to try to draw conclusions from the existing information about the projected results.
The general idea is that in case that the Exchange on-Premises mailboxes have a âpermissions relationshipâ, the recommendation is to migrate this mailbox together as a group and avoid from âbreakingâ the permissionâs relationship, because, in this case, some of the permissions will not be migrated.
For example, the article says that in an Exchange Hybrid environment only Full Access permission can be assigned to Exchange on-Premises mailbox in cloud mailbox and other permissions such as Send As permission are not supported.
The conclusion is that if we implemented mailbox migration scenario that âbreakâ the permissionâs relationship between two Exchange on-Premises mailboxes that have Send As permission, these permissions will not function anymore.
For example, an Office 365 mailbox can be granted the Full Access permission to an on-premises shared mailbox.
We donât, however, support the use of the Send-As, Receive-As, or Send on behalf of mailbox permissions in hybrid deployments between on-premises Exchange and Office 365 organizations.
[Source of information â Exchange Server Hybrid Deployments]
If a mailbox receives permissions from multiple mailboxes, that mailbox, and all of the mailboxes granting permissions to it, need to be moved at the same time.
[Source of information â Exchange Server Hybrid Deployments]
Mailbox permissions migration On-premises mailbox permissions such as Send As, Receive As, and Full Access that are explicitly applied on the mailbox are migrating to Exchange Online.
Inherited (non-explicit) mailbox permissions and any permissions on non-mailbox objectsâsuch as distribution lists or a mail-enabled userâare not migrated.
[Source of information â Exchange Server Hybrid Deployments]
Scenario 2 â migrate only part of the Exchange on-Premises mailboxes to the cloud
In this scenario, we would like to verify, what are the Exchange permissions that will be migrated to the cloud, along with the migrated mailbox given that we âbreakâ existing permissionâs relationship that exists between Exchange on-Premises mailboxes.
Description of the different scenario that we are going to check
In the following table, we can see the list of the different Exchange permissionâs scenario that we are going to test:
The expected results are as follows:
Full Access permission are going to be migrated to the cloud.
Send AS permission are not going to be migrated to the cloud.
Folder permission (calendar sharing) â there is no formal information regarding the expected results.
Delegated permission â there is no formal information regarding the expected results.
Phase 1#2 â preparing the Exchange on-Premises infrastructure for the test scenario
In the following scenario, we will deliberately âbreakâ the permission relationships that existed between Exchange on-Premises mailboxes, by migrating only a specific Exchange on-Premises mailboxes to the cloud.
In our scenario, a recipient named Amanda, have permissions on a couple of Exchange on-Premises mailboxes.
Amanda mailbox will stay on the Exchange on-Premises server and all the recipient mailboxes that Amana has permissions to will be migrated to the cloud.
Step 1 â define the Exchange permissionâs relationship between the Exchange on-Premises mailboxes.
The structure of the Exchange permissionâs relationship that exists between the Exchange on-Premises mailboxes are as follows:
1. Â Emma has Full Access permission + Send As permission on Anthony Mailbox.
In the following screenshot, we can see that Amanda has Full Access permission on Robertâs mailbox.
In the following screenshot, we can see that Amanda has Send As permission on Robertâs mailbox.
2. Â Emma has Publishing author permission to Jacksonâs calendar.
In the following screenshot, we can see that Jackson, share his calendar with Amanda by giving her Publishing author permission.
3. Â Amanda configured as a delegate of Henry.
In the following screenshot, we can see Oliverâs mailbox. Oliver defines Emma as his delegate.
Phase 2#2 â Verifying the Exchange permissions that were migrated to the cloud
Migrating the Exchange on-Premises mailboxes to the cloud
In the following screenshot, we can see that the Exchange administrator, migrated only part of the Exchange on-Premises mailboxes that had âExchange permissionâs relationshipâ to the cloud (Exchange Online).
1. Verifying the migrated explicit Full Access permissions
In the Exchange on-Premises environment, Amanda had Full Access permission on Robertâs mailbox.
The expected results are:
Amanda explicit Full Access permission on Anthonyâs mailbox will be migrated to the cloud.
The actual results are:
When we look at the mailbox delegation information on Robertâs mailbox, we can see that Emma has Full Access permission on Robertâs mailbox.
In the next step, we will try to check if Amanda that had Full Access permission on Robertâs mailbox, can successfully access Robertâs mailbox. In addition, we would like to check if the Auto Mapping feature is still âworking.â The expected result is that the Auto Mapping feature will not be migrated to the cloud.
Verifying Amandaâs ability to access Robertâs mailbox
In the following screenshot, we can see the Amanda Outlook profile doesnât include Robertâs mailbox.
The expected result is that Amanda will âkeepâ her Full Access permission, but the AutoMap option was not supposed to be kept after the migration.
In other words, the expected scenario is that Amanda will need to add Robertâs mailbox to her Outlook mail profile manually.
In the following screenshot, we can see how to add Robertâs mailbox manually to Amanda Outlook mail profile.
Robertâs mailbox was successfully added to Amanda Outlook mail profile.
2. Verifying explicit Send As permissions
In the Exchange on-Premises environment, Amanda had Send As permission on Robertâs mailbox.
The expected results are:
Amanda explicit Send As permission on Anthonyâs mailbox will not be migrated to the cloud.
The actual results are:
When we look at the mailbox delegation information on Robertâs mailbox, we can see that Amanda has Send As permission on Robertâs mailbox.
In the next step, we will try to check if Amanda that has Send As permission on Robertâs mailbox, can successfully send an E-mail message using the identity of Robert (using Robert E-mail address). Verifying Amanda ability to send E-mail using Robertâs identity
To verify if Amanda Send As permission is functional, we will try to send E-mail from Amanda mailbox.
In the following screenshot, we can see that Amanda uses Robertâs identity, by providing Robert E-mail address in the From field.
In the following screenshot, we can see that the E-mail was successfully sent to the destination recipient.
The recipient (Jackson in our scenario) sees the E-mail as if it was sent by Robert.
The conclusion is that the Send As permission was successfully migrated, and can be used by the recipient (Amanda) that has these permissions.
3. Â Verifying Folder permissions (calendar sharing)
In this section, we would like to check what happened the Folder permission that Amanda had on Jacksonâs calendar (In the Exchange on-Premises environment; Amanda had Publishing author permission on Jacksonâs calendar).
In the scenario of Folder permission (calendar sharing), we donât have a âspecific expected resultsâ because the Microsoft articles, doesnât include a direct reference to the Folder permission in a mailboxâs migration scenario.
To be able to check this scenario, we will login to Amandaâs mailbox, and check if she can access Jacksonâs calendar.
In the following screenshot, we can see that Amanda manages to display Jacksonâs calendar.
The meaning is, that the Folder permission was successfully migrated from the Exchange on-Premises environment to the cloud.
4. Â Verifying Delegate permissions
In this section, we would like to check what happened the Delegate permission that Amanda had on Henryâs mailbox.
In the Exchange on-Premises environment, Amanda had Delegate permission on Henryâs mailbox.
In the scenario of Delegated permission, we donât have an âexpected resultsâ because, the Microsoft articles, doesnât include a direct reference to the Delegate permission in a mailboxâs migration scenario.
In the following screenshot, we can see that when we look at the delegated list that configured in on Henryâs mailbox, Amanda appears as delegated.
The meaning is that the Delegate permission was successfully migrated from the Exchange on-Premises environment to the cloud.
Verifying Amandaâs ability to send E-mail on behalf Henry
The Delegation permission should enable Amanda to send E-mail on behalf of Henry.
To verify if Amanda Send on behalf permission is functional, we will try to send E-mail from Amandaâs mailbox.
In the following screenshot, we can see that Amanda uses Henryâs identity, by providing Henry E-mail address in the From field.
In the following screenshot, we can see that the E-mail was successfully sent to the destination recipient.
The recipient (Robert in our scenario), sees the E-mail was sent by Amanda on behalf of Henry.
The conclusion is that the Send on behalf permission was successfully migrated.
Summary and recap
In the following comparison table, we can inform about the expected Exchange permissions that should be migrated versus the actual result of the Exchange permissions that was migrated.
Just a quick reminder, the scenario that we have reviewed in the current article was based on a concept in which we âseparateâ between Exchange on-Premises mailboxes that have an Exchange permissionâs relationship, and migrate only part of the mailboxes to the cloud.
Itâs important that we notice the difference between the âexpected resultsâ as they appear in the Microsoft formal articles, versus, the âactual resultsâ that we get when performing the mail migration.
When looking at the âactual resultsâ we can see that some of the migration that was not supposed to be migrated to the cloud, was migrated!
To what ârowâ should you reference
In case that your question is â should I relate to the formal information that appears in the Microsoft article (the expected result) or should I relate to the results that I experience when I migrate mailboxes to the cloud?
My answer is:
Itâs important that we will be familiar with the âformal informationâ as itâs published by Microsoft because this information defines what are the exact Exchange permissions that are supposed to be migrated.
In case that our experience problem in which a specific Exchange permission that was supposed to be migrated was not migrated, only then we can contact Microsoftâs support.
Bottom line
When you plan your mail migration project in an Exchange Hybrid environment, you will have to decide if you want to relate only to the documented formal information or, to the actual results that you get by testing the different mail migration scenarios.
Cross site permission and migrated permissions â Exchange Hybrid | Article series index
Now itâs Your Turn! It is important for us to know your opinion on this article












