Preview build — Pull Request #115

Using Folder Permissions Manager in Hybrid Environments

Understand Folder Permissions Manager limitations for hybrid Exchange permissions and Entra ID-only users.

You wish to use Folder Permissions Manager in a Hybrid Exchange on-premises / Exchange online environment but would like to understand the limitations and requirements of this configuration.

As a first step in diagnosis, please ensure you are using the latest version of Folder Permissions Manager. Troubleshooting is not available for older versions.

Scenario: Applying permissions across on-premises and cloud mailboxes

You wish to use Folder Permissions Manager to apply permissions from a cloud user/distribution list/security group to an on-prem mailbox, or vice versa. You cannot apply permissions other than Full Access or Send on Behalf to the mailbox.

Cause: Cross-domain permissions are not supported

As detailed in the following Microsoft article, it is not possible to assign cross-domain (cloud to on-prem or on-prem to cloud) permissions using Outlook or the EWS console. This applies even if the accounts in question are synced across domains.

This information is covered in more detail in the following Microsoft article concerning cross-domain permissions.

Permissions in Exchange hybrid environments

Attempting to use cross-domain permissions can result in the following errors in File Permissions Manager:

User or Group is not found when searching for user

Email Address is not populated for a group

This permission could not be applied because the user identifier is invalid

You are attempting to use Folder Permissions Manager to apply permissions to a user located in Entra ID, however, the account is not displayed when using the search function

Cause: Users must exist in the on-premises AD domain

Users must be present within the on-premises AD domain to be visible within Folder Permissions Manager. Users that only exist within Entra ID cannot be listed by the search function, because it is unable to connect to Entra ID.