Site icon WinCert

550 5.4.1 Recipient address rejected: Access denied – O365 Exchange

<p>As we started migrating users to O365 Exchange we have run into a problem for one user&period; When we tried to send this user an e-mail outside of O365 tenant we receive the following error message&colon;<&sol;p>&NewLine;<p><strong>550 5&period;4&period;1 Recipient address rejected&colon; Access denied &lbrack;VE1EUR02FT035&period;eop-EUR02&period;prod&period;protection&period;outlook&period;com&rsqb;<&sol;strong><&sol;p>&NewLine;<p><img class&equals;"alignnone size-full wp-image-3558" src&equals;"https&colon;&sol;&sol;www&period;wincert&period;net&sol;wp-content&sol;uploads&sol;2020&sol;02&sol;email-3249062&lowbar;640&period;png" alt&equals;"" width&equals;"640" height&equals;"358" &sol;><&sol;p>&NewLine;<p>From the error message&comma; we could see that the e-mail address rejected was actually the master UPN address with <strong>&ast;&period;onmicrosoft&period;com <&sol;strong>domain&period; Once I have checked this user&&num;8217&semi;s account I could see that he was missing the email alias <strong>&ast;&period;onmicrosoft&period;com<&sol;strong> where &ast; is replaced with our tenant name&period; And that was the reason why external e-mail messages were rejected&period; The external mail servers could not find this user with <strong>&ast;&period;onmicrosoft&period;com UPN<&sol;strong>&period;<&sol;p>&NewLine;<p>To fix this we had to add the <strong>&ast;&period;onmicrosoft&period;com<&sol;strong> alias for this user account&period;<&sol;p>&NewLine;<h4>How to add an alias to the O365 email account<&sol;h4>&NewLine;<p>Navigate to O365 admin portal at <a href&equals;"https&colon;&sol;&sol;admin&period;microsoft&period;com&sol;AdminPortal" target&equals;"&lowbar;blank" rel&equals;"noopener noreferrer">https&colon;&sol;&sol;admin&period;microsoft&period;com&sol;AdminPortal<&sol;a><br &sol;>&NewLine;Click on <strong>Users<&sol;strong> and then <strong>Active users<&sol;strong><br &sol;>&NewLine;Search for the user and click on his display name to open Properties<br &sol;>&NewLine;Under <strong>Account tab<&sol;strong> look for <strong>Aliases<&sol;strong> and click on <strong>Manage email aliases link&period;<br &sol;>&NewLine;<&sol;strong>Once an alias has been added your problem should be solved&period;<&sol;p>&NewLine;<p>On the other hand&comma; if you are using <strong>on-premises organization synchronization with O365 Azure services<&sol;strong> you might receive the following error message when trying to add email alias&period;<&sol;p>&NewLine;<p><strong>The operation on mailbox &lt&semi;username&gt&semi; failed because it&&num;8217&semi;s out of the current user&&num;8217&semi;s write scope&period; The action &&num;8220&semi;Set-Mailbox&&num;8217&semi;&comma; &quest;EmailAddresses&&num;8217&semi;&comma; can&&num;8217&semi;t be performed on the object &lt&semi;username&gt&semi; because the object is being synchronized from your on-premises organization&period; This action should be performed on the object in your on-premises organization&period;<&sol;strong><&sol;p>&NewLine;<p><img class&equals;"alignnone wp-image-3552 size-full" src&equals;"https&colon;&sol;&sol;www&period;wincert&period;net&sol;wp-content&sol;uploads&sol;2020&sol;02&sol;manage-aliases-o365&period;png" alt&equals;"550 5&period;4&period;1 Recipient address rejected" width&equals;"578" height&equals;"175" &sol;><&sol;p>&NewLine;<p>Considering that email alias cannot be added using on-premise Active Directory services we can add it by using <strong>Exchange Online Powershell module<&sol;strong>&period;<&sol;p>&NewLine;<p>To add email alias using <strong>Exchange Online Powershell module<&sol;strong> here&&num;8217&semi;s what you need to do&colon;<&sol;p>&NewLine;<p>Run <strong>Powershell in elevated mode<&sol;strong> &lpar;run as administrator&rpar;<br &sol;>&NewLine;Type <strong>Set-ExecutionPolicy RemoteSigned<&sol;strong> and hit enter<br &sol;>&NewLine;Type <strong>Install-Module -Name ExchangeOnlineManagement<&sol;strong> and hit enter to install Exchange Online Management module<br &sol;>&NewLine;Select <strong>&lbrack;A&rsqb; Yes to All to All<&sol;strong> to allow installation of this module from <strong>PSGallery<&sol;strong>&period;<br &sol;>&NewLine;Type <strong>&dollar;Session &equals; New-PSSession -ConfigurationName Microsoft&period;Exchange -ConnectionUri https&colon;&sol;&sol;outlook&period;office365&period;com&sol;powershell-liveid&sol; -Credential &dollar;UserCredential -Authentication Basic -AllowRedirection<&sol;strong> to connect to Exchange Online Management<br &sol;>&NewLine;Enter your <strong>O365 credentials<&sol;strong> in the following prompt<&sol;p>&NewLine;<p><img class&equals;"alignnone wp-image-3553 size-full" src&equals;"https&colon;&sol;&sol;www&period;wincert&period;net&sol;wp-content&sol;uploads&sol;2020&sol;02&sol;azure-credentials-prompt&period;jpg" alt&equals;"550 5&period;4&period;1 Recipient address rejected" width&equals;"322" height&equals;"261" &sol;><&sol;p>&NewLine;<p>Please note that if you are using <strong>2FA authentication<&sol;strong> you won&&num;8217&semi;t be able to authenticate and might receive the access denied error message&colon;<br &sol;>&NewLine;<strong>Connecting to remote server outlook&period;office365&period;com failed with the following error message &colon; Access is denied&period; For more information&comma; see<&sol;strong><br &sol;>&NewLine;<strong>the about&lowbar;Remote&lowbar;Troubleshooting Help topic&period;<&sol;strong><&sol;p>&NewLine;<p>To be able to login to the Exchange Online Management module when using <strong>2FA authentication<&sol;strong> we have to install the <strong>Exchange Online Management Powershell V2<&sol;strong> <strong>module<&sol;strong>&period;<&sol;p>&NewLine;<p>Type <strong>Install-Module PowerShellGet -Force<&sol;strong> and hit enter<br &sol;>&NewLine;Type <strong>Set-ExecutionPolicy Unrestricted<&sol;strong> and hit enter&period; Now <strong>restart<&sol;strong> Powershell to continue&period;<&sol;p>&NewLine;<p>To connect to Exchange Online Management services type&colon;<br &sol;>&NewLine;<strong>Connect-ExchangeOnline -UserPrincipalName &lt&semi;UPN&gt&semi;<&sol;strong><br &sol;>&NewLine;Replace <strong>&lt&semi;UPN&gt&semi;<&sol;strong> with your <strong>UPN<&sol;strong>&period;<&sol;p>&NewLine;<p>Now you will get a new type of credentials prompt where you&&num;8217&semi;ll be able to use 2FA&period;<&sol;p>&NewLine;<p><img class&equals;"alignnone size-full wp-image-3556" src&equals;"https&colon;&sol;&sol;www&period;wincert&period;net&sol;wp-content&sol;uploads&sol;2020&sol;02&sol;code&period;jpg" alt&equals;"" width&equals;"507" height&equals;"222" &sol;><&sol;p>&NewLine;<p>After you have logged in&comma; type the following commands to add an alias for the user&colon;<br &sol;>&NewLine;<strong>Set-Mailbox -Identity &lt&semi;UPN&gt&semi;  -WindowsEmailAddress <span style&equals;"color&colon; &num;ff0000&semi;">&lt&semi;UPN&gt&semi;<&sol;span><&sol;strong><br &sol;>&NewLine;<strong>Set-Mailbox -Identity &lt&semi;UPN&gt&semi;  -WindowsEmailAddress &lt&semi;UPN&gt&semi;<&sol;strong><&sol;p>&NewLine;<p><span style&equals;"color&colon; &num;ff0000&semi;">&lt&semi;UPN&gt&semi;<&sol;span> marked in <span style&equals;"color&colon; &num;ff0000&semi;">RED<&sol;span> has to be replaced <strong>with email alias address<&sol;strong>&period;<&sol;p>&NewLine;<p>After you have added a new alias&comma; please wait for <strong>Azure AD Connect<&sol;strong> sync to finish before testing the e-mail again&period;<&sol;p>&NewLine;<p>More info can be found here&colon;<br &sol;>&NewLine;<a href&equals;"https&colon;&sol;&sol;docs&period;microsoft&period;com&sol;en-us&sol;powershell&sol;exchange&sol;exchange-online&sol;exchange-online-powershell-v2&sol;exchange-online-powershell-v2&quest;view&equals;exchange-ps" target&equals;"&lowbar;blank" rel&equals;"noopener noreferrer">https&colon;&sol;&sol;docs&period;microsoft&period;com&sol;en-us&sol;powershell&sol;exchange&sol;exchange-online&sol;exchange-online-powershell-v2&sol;exchange-online-powershell-v2&quest;view&equals;exchange-ps<&sol;a><br &sol;>&NewLine;<a href&equals;"https&colon;&sol;&sol;www&period;powershellgallery&period;com&sol;packages&sol;ExchangeOnlineManagement&sol;0&period;3555&period;1" target&equals;"&lowbar;blank" rel&equals;"noopener noreferrer">https&colon;&sol;&sol;www&period;powershellgallery&period;com&sol;packages&sol;ExchangeOnlineManagement&sol;0&period;3555&period;1<&sol;a><&sol;p>&NewLine;<p>If you&&num;8217&semi;ll need help regarding this topic please post your comment below&period;<&sol;p>&NewLine;

Exit mobile version