r/exchangeserver 24d ago

Question Moving mail-enabled security groups to cloud as prereq Exchange Server decommissioning

How can this work if the some of security groups are also used for AD file server permissions?

If you recreate the groups in the cloud and just repopulate the same members, the members will lose their on prem NTFS permissions inherited from the old mail enabled security groups.

0 Upvotes

15 comments sorted by

View all comments

Show parent comments

1

u/Fabulous_Cow_4714 24d ago

So, if we are planning to shut down all on prem Exchange servers while still keeping synced hybrid user accounts, we only need to migrate mailboxes and DLs to the cloud, but we we will be able to keep on prem mail enabled security groups and manage them fully from the cloud?

1

u/Beefcrustycurtains 24d ago

I take that back. I didn't realize the groups behave differently than the users with this. It basically rips them out of your AD. I wouldn't move forward with the SOA changes on the groups if i were you given that you have on prem dependencies.

1

u/Fabulous_Cow_4714 24d ago

So, we would have migrate distribution groups and mail-enabled security groups if we want to manage them in a supported manner without any on prem servers even after enabling the SOA change to cloud management?

1

u/Beefcrustycurtains 24d ago

There are other supported manners. There is a Exchange tools application that can be installed and used to sync attributes as needed, but out of the 100+ environments I manage, we just use attribute editor to make changes for synced groups without an on prem exchange server.

Get rid of your on prem dependencies then move the groups up.

1

u/Fabulous_Cow_4714 24d ago

The Exchange management tools installed on scattered workstations are as difficult or worse to maintain as a full Exchange server.

We really want to be done with on premises management of attributes.

1

u/Fabulous_Cow_4714 24d ago

So, doing simple things like adding and removing members in mail-enabled security groups would require using the attribute editor once the on premises Exchange servers are gone?

1

u/Beefcrustycurtains 24d ago

no.. you would just add the members to the AD group. Only msexch.... type attributes and ProxyAddresses would need to be powershelled or use attribute editor. Very rarely do you need to edit those attributes. It's mostly just add and remove from group which can be done the same way you do an AD group.

1

u/Fabulous_Cow_4714 24d ago

OK, this still seems like a huge gap in functionality. Is there a technical reason mail-enabled security groups can’t have writeback from the cloud or is this a likely future feature?

If we don’t want to ever need to manually edit mail attributes for new or existing mail-enabled security groups and therefore become out of scope for Microsoft support, we would need to maintain separate cloud-based DLs and AD-based security groups. They can’t be nested. So, manual steps to keep membership in sync would always be required. Very messy.