Azure AD Connect single on-prem AD and Exchange to multiple tenants --- how to decommission 2010 servers(and mailboxes, distros, contacts) without deleting the objects in 365

iconoclast88 61 Reputation points
2020-08-06T16:55:33.353+00:00

Azure AD Connect single on-prem AD and Exchange to multiple tenants --- how to decommission 2010 servers(and mailboxes, distros, contacts) without deleting the objects in 365

The goal is to remove on-premise exchange objects from on-prem exchange so that the AD users is only left on-premise, and the exchange 365 objectsd (distros, contacts, mailboxes) aren't affected.

Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,347 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,458 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Nuno Alexandre 31 Reputation points
    2020-08-06T21:45:01.913+00:00

    From my understanding, you have today all the objects synchronized from on-premises AD to Azure AD/Exchange Online (EXO) and you want to start managing distros, contacts, mailboxes from EXO only (i.e. use cloud-mastered objects).
    If the mailboxes are still in on-premises Exchange, then first you need to move all the mailboxes to EXO.
    After having all the mailboxes in EXO, you'll have to transfer the source of authority of all the objects in Azure AD by stopping AAD Connect synchronization and disabling DirSync on the tenant. This is a process that can take many days depending on the size of the tenant as it will convert every single DirSyncEnabled object to a cloud-only object mastered in the cloud.
    If you want to keep managing users from on-prem, you can reconfigure AADConnect with a sync scope (e.g. OU filtering) to only synchronize these users (and not the other object like distros and contacts) and re-enable synchronization on the tenant. After this, AAD Connect will "re-match" the existing users in Azure AD with the users from local AD and convert these objects back again to DirSyncEnabled objects in Azure AD. For these "hybrid exchange" objects though, you might still need to manage Exchange properties from on-premises so I would recommend keeping one last on-prem Exchange Server for management purposes only.

    For more information, please read: https://learn.microsoft.com/en-us/exchange/decommission-on-premises-exchange

    2 people found this answer helpful.
    0 comments No comments

  2. KyleXu-MSFT 26,206 Reputation points
    2020-08-07T08:00:21.17+00:00

    Do you want to remove all local configuration without effect Exchange mailbox attributes?

    If so, just follow the Scenario one to disconnect local AD from Azure AD, after that you will could uninstall Exchange on-premises and manage AD account from Azure AD directly without effect existing mailbox attributes.