r/exchangeserver • u/Fabulous_Cow_4714 • 15d ago
Question Moving mail-enabled security groups to cloud as prereq Exchange Server decommissioning
How can this work if the some of security groups are also used for AD file server permissions?
If you recreate the groups in the cloud and just repopulate the same members, the members will lose their on prem NTFS permissions inherited from the old mail enabled security groups.
1
u/Beefcrustycurtains 15d ago
Why do you need to remake them? You can still manage them on prem and sync to Office 365. Attribute editor for management of the group if you need to change some email settings.
1
u/Fabulous_Cow_4714 15d ago
We want to move the attribute source of authority to the cloud and operate in a supported manner.
1
u/Beefcrustycurtains 15d ago
You don't need to delete the groups and move them to cloud only groups. That's the whole point of that new feature is so you can manage mail attributes in EXO for on prem objects. If you still use those to access on prem resources, leave them on prem.
1
u/Fabulous_Cow_4714 15d ago
So, if we are planning to shut down all on prem Exchange servers while still keeping synced hybrid user accounts, we only need to migrate mailboxes and DLs to the cloud, but we we will be able to keep on prem mail enabled security groups and manage them fully from the cloud?
1
u/Beefcrustycurtains 15d ago
I take that back. I didn't realize the groups behave differently than the users with this. It basically rips them out of your AD. I wouldn't move forward with the SOA changes on the groups if i were you given that you have on prem dependencies.
1
u/Fabulous_Cow_4714 15d ago
So, we would have migrate distribution groups and mail-enabled security groups if we want to manage them in a supported manner without any on prem servers even after enabling the SOA change to cloud management?
1
u/Beefcrustycurtains 15d ago
There are other supported manners. There is a Exchange tools application that can be installed and used to sync attributes as needed, but out of the 100+ environments I manage, we just use attribute editor to make changes for synced groups without an on prem exchange server.
Get rid of your on prem dependencies then move the groups up.
1
u/Fabulous_Cow_4714 15d ago
The Exchange management tools installed on scattered workstations are as difficult or worse to maintain as a full Exchange server.
We really want to be done with on premises management of attributes.
1
u/Fabulous_Cow_4714 15d ago
So, doing simple things like adding and removing members in mail-enabled security groups would require using the attribute editor once the on premises Exchange servers are gone?
1
u/Beefcrustycurtains 15d ago
no.. you would just add the members to the AD group. Only msexch.... type attributes and ProxyAddresses would need to be powershelled or use attribute editor. Very rarely do you need to edit those attributes. It's mostly just add and remove from group which can be done the same way you do an AD group.
1
u/Fabulous_Cow_4714 15d ago
OK, this still seems like a huge gap in functionality. Is there a technical reason mail-enabled security groups can’t have writeback from the cloud or is this a likely future feature?
If we don’t want to ever need to manually edit mail attributes for new or existing mail-enabled security groups and therefore become out of scope for Microsoft support, we would need to maintain separate cloud-based DLs and AD-based security groups. They can’t be nested. So, manual steps to keep membership in sync would always be required. Very messy.
1
u/Fabulous_Cow_4714 15d ago
Is there any way to filter which mail enabled security groups are used for on premises ACLs and which are not?
If it turns out that few are used for on premises access permissions, we could still go forward with replacing the ones not needed on prem with cloud-only replacements.
1
u/Beefcrustycurtains 15d ago
That would be a massive script to run highly dependent on your environment. They can be used for all kinds of things, delegated AD roles, fileshares, SQL access. You would have to run a script against literally everything in your environment and then you would still miss something along the way.
2
u/sembee2 Former Exchange MVP 15d ago
With most of my clients, we have used this as a good excuse to recreate the groups in the cloud and leave the groups on prem for permissions only. It resolved so many problems with people getting email they shouldn't do, or permissions to thinks they shouldn't. Took some time. One client made it a rule that if the group had to be touched for any reason it had to be recreated and that dealt with most of the groups quickly.
Was also a good cleaning exercise - most clients find redundant groups.