Chat now with support
Chat with Support

Identity Manager 9.2 - Administration Guide for Connecting to Exchange Online

About this guide Managing Exchange Online environments Synchronizing an Exchange Online environment
Setting up Exchange Online synchronization Customizing the synchronization configuration Running synchronization Tasks following synchronization Troubleshooting Ignoring data error in synchronization Pausing handling of target system specific processes (Offline mode)
Basic data for managing an Exchange Online environment Exchange Online organization configuration Exchange Online mailboxes Exchange Online mail users Exchange Online mail contacts Exchange Online mail-enabled distribution groups
Creating Exchange Online mail-enabled distribution groups Editing main data for Exchange Online mail-enabled distribution groups Main data for Exchange Online mail-enabled distribution groups Receive restrictions for Exchange Online mail-enabled distribution groups Customizing send permissions for Exchange Online mail-enabled distribution groups Specifying moderators for Exchange Online mail-enabled distribution groups Specifying Exchange Online mail-enabled distribution groups Assigning Exchange Online mail-enabled distribution groups to Exchange Online recipients Exchange Online mail-enabled distribution group inheritance based on categories Adding Exchange Online dynamic distribution groups to Exchange Online mail-enabled distribution groups Adding an Exchange Online dynamic distribution group to Exchange Online mail-enabled distribution groups Adding Exchange Online mail-enabled public folder to Exchange Online mail-enabled distribution groups Assigning extended properties to Exchange Online mail-enabled distribution groups Deleting Exchange Online mail-enabled distribution groups
Exchange Online Office 365 groups Exchange Online dynamic distribution groups Exchange Online mail-enabled public folders Reports about Exchange Online objects Configuration parameters for managing an Exchange Online environment Default project template for Exchange Online Editing Exchange Online system objects Exchange Online connector settings

Preparing the administrative workstation for access to Exchange Online

To configure synchronization with Exchange Online in the Synchronization Editor, One Identity Manager must load the data directly from Exchange Online. If the Exchange Online is accessed directly from the work station on which the Synchronization Editor is installed, the following software must also be installed on this workstation:

  • Windows PowerShell Version 5.1 or later

  • Exchange Online PowerShell module version 3.2.0 or later

If direct access from the workstation to Exchange Online is not possible, you can set up a remote connection.

Related topics

Preparing a remote connection server for access to Exchange Online

To configure synchronization with a target system, One Identity Manager must load the data from the target system. One Identity Manager communicates directly with the target system to do this. Sometimes direct access from the workstation, on which the Synchronization Editor is installed, is not possible. For example, because of the firewall configuration or the workstation does not fulfill the necessary hardware and software requirements. If direct access is not possible from the workstation, you can set up a remote connection.

The remote connection server and the workstation must be in the same Active Directory domain.

Remote connection server configuration:

  • One Identity Manager Service is started

  • RemoteConnectPlugin is installed

  • Windows PowerShell version 5.1 or above is installed

  • Exchange Online PowerShell V2 module is installed.

  • Exchange Online connector is installed

The remote connection server must be declared as a Job server in One Identity Manager. The Job server name is required.

TIP: The remote connection server requires the same configuration as the synchronization server (with regard to the installed software and entitlements). Use the synchronization as remote connection server at the same time by installing the RemoteConnectPlugin as well.

For more detailed information about setting up a remote connection, see the One Identity Manager Target System Synchronization Reference Guide.

Related topics

Creating a synchronization project for initial synchronization of an Exchange Online environment

Use the Synchronization Editor to configure synchronization between the One Identity Manager database and Exchange Online environment. The following describes the steps for initial configuration of a synchronization project. For more information about setting up synchronization, see the One Identity Manager Target System Synchronization Reference Guide.

After the initial configuration, you can customize and configure workflows within the synchronization project. Use the workflow wizard in the Synchronization Editor for this. The Synchronization Editor also provides different configuration options for a synchronization project.

IMPORTANT: Each Exchange Online environment should have its own synchronization project.

IMPORTANT: It must be possible to reach Exchange Online servers by DNS query for successful authentication. If the DNS cannot be resolved, the target system connection is refused.

NOTE: When setting up the synchronization, note the recommendations described under Exchange Online synchronization features.

Prerequisites for setting up a synchronization project
  • The Azure Active Directory tenant is declared in One Identity Manager.

  • Synchronization of the Azure Active Directory system is carried out regularly.

Related topics

Information required for Exchange Online synchronization projects

Have the following information available for setting up a synchronization project.

Table 4: Information required to set up a synchronization project
Data Explanation

Authentication information

Synchronization with Exchange Online supports authentication through a user account with sufficient permissions or through app-only authentication using a self-signed certificate.

For more information, see Users and permissions for synchronizing with Exchange Online.

Information required to authenticate through a user account:

  • User account and password for logging in to Exchange Online.

    Example:

    <user>@<domain.com>

    sync.user@<yourorganization>.onmicrosoft.com

Information required to authenticate using a self-signed certificate (app-only authentication):

  • Application ID created when the application is registered for Exchange Online PowerShell in the Azure Active Directory tenant.

  • Self-signed certificate thumbprint

For more information on how to set up app-only authentication, see Set up app-only authentication.

Organization domains

Azure Active Directory name of the domain for logging in to Azure Active Directory.

Example:

<yourorganization>.onmicrosoft.com

Synchronization server for Exchange Online

All One Identity Manager Service actions are run against the target system environment on the synchronization server. Data entries required for synchronization and administration with the One Identity Manager database are processed by the synchronization server.

The One Identity Manager Service with the Exchange Online connector must be installed on the synchronization server.

The synchronization server must be declared as a Job server in One Identity Manager. Use the following properties when you set up the Job server.

  • Server function: Exchange Online connector

  • Machine role: Server | Job Server | Exchange Online

For more information, see Setting up the Exchange Online synchronization server.

One Identity Manager database connection data
  • Database server

  • Database name

  • SQL Server login and password

  • Specifies whether integrated Windows authentication is used

    Use of the integrated Windows authentication is not recommended. If you decide to use it anyway, ensure that your environment supports Windows authentication.

Remote connection server

For more information, see Preparing a remote connection server for access to Exchange Online.

Related Documents

The document was helpful.

Select Rating

I easily found the information I needed.

Select Rating