You cannot move mailboxes between local One Identity Manager and Microsoft Exchange with Exchange Online. Microsoft offers migration scenarios for moving mailboxes. For detailed information, see your Microsoft documentation.
Synchronizing Microsoft Exchange after moving a mailbox from local Exchange Online to Microsoft Exchange in One Identity Manager results in:
- A remote mailbox being created
- The local mailbox being marked as outstanding.
After successful migration, delete outstanding mailboxes in One Identity Manager.
-
Check whether the mailbox was migrated and whether the Active Directory user account is connected with the local mailbox and a remote mailbox.
Migrated mailboxes are displayed in the Manager in the Active Directory | Troubleshooting | Mailboxes migrated to Exchange Online category.
-
Select the mailbox and switch to the Active Directory user account overview. Here you can see whether the user account is connected with a local mailbox and a remote mailbox.
-
-
Delete the outstanding mailbox.
-
In the Manager, in the Active DirectoryTarget system synchronization: Exchange category, select the mailbox in the EX0Mailbox table and execute the Delete method for the mailbox.
For more information, see Post-processing outstanding objects.
-
If you apply an account definition to local mailboxes, create a new account definition for remote mailboxes.
-
If the mailbox account definition currently in use, expects an account definition for Active Directory user accounts, enter this account definition as prerequisite for the remote mailbox account definition.
IMPORTANT: The remote mailbox account definition may not be distributed automatically to everybody. Otherwise One Identity Manager creates new remote mailboxes.
Example of exchanging account definitions for migrated mailboxes
The following is an example explaining how you can replace account definitions with migrated mailboxes
NOTE: The workflows described here are only for orientation. Always take your customized workflows into account while replacing.
You always required a custom migration scenario if the account definitions are requested through the IT Shop.
Example 1
Local mailboxes are managed through an account definition. This account definition requires an account definition for Active Directory user accounts.
The account definition is directly assigned to employees.
After migration, remote mailboxes are also managed through account definitions.
-
Create an account definition for remote mailboxes. Enter the Active Directory user account's account definition as prerequisite.
- After migrating a local mailbox.
- Ensure that the remote mailbox exists in One Identity Manager and is connected to the Active Directory user account.
-
Delete the outstanding local mailbox in One Identity Manager.
-
Assign the account definition for remote mailboxes to the employee.
-
Delete the account definition for local mailboxes belonging to the employee.
Example 2
Local mailboxes are managed through an account definition. This account definition requires an account definition for Active Directory user accounts.
The account definition is inherited by the employees through it's department relation.
After migration, remote mailboxes are also managed through account definitions.
-
Create a parallel structure to the department and assign the account definition for local mailboxes to this parallel structure.
The purpose of this parallel structure is to retain the local mailboxes' account definition assignment to an employee until the mailbox has been successfully migrated.
-
Configure a dynamic role for this parallel structure, to include all employees who:
-
Belong to the department and do not have a remote mailbox.
or
-
Belong to the department and own a remote mailbox and an outstanding local mailbox.
-
-
-
After completing DBQueue Processor processing, you can remove the account definition for local mailboxes from the department.
-
Create an account definition for remote mailboxes. Enter the Active Directory user account's account definition as prerequisite.
-
Create another parallel structure and assign the account definition for remote mailboxes to it..
The purpose of this parallel structure is to assign the remote mailboxes' account definition to employees after mailbox migration and to retain the assignment of the required account definition for Active Directory.
-
Configure a dynamic role for this parallel structure, to include all employees who:
-
Belong to the department and own a remote mailbox.
-
-
-
Delete the outstanding mailbox after migrating the local mailbox successfully.
-
After migrating all the department's local mailboxes, you can:
-
Assign a department to the remote mailboxes' account definition.
-
Remove the parallel structure.
-