Entra iD SaaS Exchange Management

Hey Team,

I just activated the Exchange Feature for our Entra ID SaaS connector and am now a bit confused to how to set everything up correctly. The documentation I can find isn’t really sufficient for this case.

We need to manage distribution lists and shared mailboxes (provisioning/deprovisioning) specifically.

I am able to aggregate distriibution lists as type “Group” via the “Aggregate All Groups” checkbox, however it is not fetching shared mailboxes as entitlements. There is no documentation on how to set up new Entitlement Type:s for these type of objects, and the ones i have tried doesn’t work.

I am able to fetch the value of sharedMailbox on the account.

Preferrably I would like for distribution lists and shared mailboxes to have their own entitlement type’s, but having no success with this. Can someone shed some light?

For “their own entitlement type”, consider using metadata attributes.

As for the shared mailboxes’ entitlements, you don’t see any entitlement with names in the form of “<Shared Mailbox name>: <Permission name>”?

Hello Terry,

By metadata attributes, what do you mean specifically?

I am able to see Shared Mailboxes when the attribute “sharedMailbox” is not of type “Entitlement” on the account schema. When checking this box I seem to not get anything at all.

I would like to be able to aggregate shared mailboxes via “Entitlement Aggregation”, but then I must know how to set up the entitlement type, can’t find any documentation on this.

Metadata Attributes:

Hello Terry, yes this is how we have configured it now and it works. However, this only lets us aggregate Shared Mailboxes via Account Aggregation, we need to aggregate all shared mailboxes via Entitlemenet Aggregation if possible.

Don’t think you can change this aspect of the connector behaviour.

I have checked with SailPoint and this is not possible at this time. There are ideas up for this however.