Convert AD connect synced user to shared mailbox

microsoft-office-365

What I want to do is the following:
A user from Company X is no longer working there. So, the account can be deleted, but the e-mail should stay accessible for colleagues for a while. I want to convert the mailbox to a shared mailbox.

But, local AD is synced to Azure AD with AD connect. How to convert this users mailbox to a shared (non-synced) one? We do not have Exchange on-premises.

I guess I should do this, but I am not sure:

  • Use Exchange admin panel to convert user to a shared mailbox.
  • Assign permissions to access the shared mailbox.
  • Remove Office365 license.
  • Delete user from local AD
  • Wait for AD connect to do a sync

Please confirm this would work. I do not want to risk that the shared mailbox get's deleted because I removed the user from local AD

EDIT: Just tried the following:

  • Deleted user from local AD
  • Forced sync with AD connect
  • Go to Office admin panel > deleted users
  • Recover the user. I now see it as "cloud" account.
  • When user is recovered, use "convert to shared mailbox".
  • Remove licenses from user.
  • It now is a shared mailbox, not using licensed, and not synced from local AD. Just what we wanted.
  • HOWEVER: As soon as AD connect runs it sync again, the restored user (which is a shared mailbox now) is deleted again.

How to prevent this?

Best Answer

Your plan was valid, apart the step where you delete user account in local AD. You should keep it disabled as long as you are using shared mailbox.

Where are several methods to restore user in local AD. Check https://technet.microsoft.com/en-us/library/dd379509(v=ws.10).aspx

So your plan now is:

  • Undelete user in local AD
  • Run AD Connect sync
  • Make sure mailbox at Office 365 is configured as shared