Setting up Exchange 365 RBAC for Shared Mailboxes to add and remove users

Victor Ramsey 1 Reputation point
2022-01-06T21:06:25.597+00:00

Hello,
I have the following question.

Currently the org I work for has an Exchange Hybrid Environment.

The on-premises servers are Exchange 2016.

All shared mailboxes have been migrarted to Exchange 365.

What I am looking to set up, I would like to allow a specific set of users to have access to add and remove Shared Mailbox members.

What is currently set up,
I have created and admin role in Exchange 365 that has a custom Mail Recipient Creation and Mail Recipients Assigned roles.
I have an Exchange 365 user that is a member of the Admin Role.
The admin role is scoped to a specific OU in om-premsies AD that houses the test shared mailbox for this.

The issue, when I log into the Exchange 365 console with the set up account, I do not have the tabs in mailbox delgation for the scoped shared mailbox to add or remove users for full and send as access.

I did add the Exchange Admin role via the azure console to the test Admin account. however it overides the custom admin role with the custom assigned roles in the Exchange 365 control panel.

Thank you, any help at this time is most appreciated.

Microsoft Exchange Hybrid Management
Microsoft Exchange Hybrid Management
Microsoft Exchange: Microsoft messaging and collaboration software.Hybrid Management: Organizing, handling, directing or controlling hybrid deployments.
1,964 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. KyleXu-MSFT 26,231 Reputation points
    2022-01-07T06:43:09.393+00:00

    @Victor Ramsey

    I would like to allow a specific set of users to have access to add and remove Shared Mailbox members.

    Do you mean manage the Full Access and Send As permission for shared mailbox?

    Both are controlled by "Add-MailboxPermission" command, from the information below, we can know this command contained in the "Mail Recipients" admin role:
    162988-qa-kyle-14-28-40.png

    Here is my testing, you could have a compare with yours:

    I created a new admin group which contained this admin role, then added an Exchange online mailbox into it:
    162965-qa-kyle-14-34-18.png

    This mailbox could manage the delegation permission for this migrated shared mailbox successfully:
    162989-qa-kyle-14-41-34.png


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.



  2. Victor Ramsey 21 Reputation points
    2022-03-17T18:20:26.157+00:00

    I was unable to get this to work as expected. That said, we have moved on from this.

    0 comments No comments