Skip to content

Writeback to AD

Michael Mardahl edited this page Aug 19, 2026 · 1 revision

Writing mailbox changes back to AD

By default, changes you make in Exchange Online after a mailbox SOA conversion stay in the cloud. AD does not receive them. If you need the on-premises copies updated, install Microsoft Entra Cloud Sync and configure Exchange attribute writeback.

How Cloud Sync fits

Cloud Sync runs alongside Connect Sync. Do not uninstall Connect Sync. Connect Sync keeps handling user and group synchronization; Cloud Sync only writes the supported Exchange attributes back to AD.

Setup

  1. Install the Cloud Sync provisioning agent on a server that can reach your domain controllers. Version must be 1.1.1107.0 or higher.
  2. In the Entra admin center, go to Identity, Hybrid management, Microsoft Entra Connect, Cloud Sync.
  3. Create a new configuration and choose EXO to AD attribute sync.
  4. Verify the agent matches your domain and create the job.
  5. Start provisioning.

What writes back

  • mail
  • proxyAddresses
  • extensionAttribute1 through 15
  • msExchExtensionCustomAttribute1 through 5
  • msExchRecipientDisplayType
  • msExchRecipientTypeDetails

Other Exchange attributes you change in the cloud, such as forwarding rules or moderation settings, stay in the cloud only.

Verify

Change a supported attribute in Exchange Online, wait about 20 minutes for the sync cycle, and check the same value on the on-premises remote mailbox:

Get-RemoteMailbox -Identity <user> | Format-List CustomAttribute1

Or use Provision on demand in the Cloud Sync configuration for an immediate sync.

Clone this wiki locally