# 07b. Synctool Exchange sources

## Introduction

Exchange sources are commonly used to create Zivver user accounts based on Exchange user mailboxes and functional accounts based on Exchange shared mailboxes.

The synchronization is executed in one way: from Exchange to Zivver, not the other way around. You can determine which (shared) mailboxes are synchronized from Exchange to Zivver with filters.

## Source details

1. Enter a **Source name**.
   
   _For example “Microsoft Exchange Online” or “Microsoft Exchange on-premise 2019”._
2. Enter a **Source description**.
   
   _For example the name of administrator who configured this Exchange source._
3. Select a **Default phone number region**.
   
   _This allows the Synctool to easily recognize mobile phone numbers with a country code prefix._

## Connection

These settings allow the Synctool to connect to your Exchange server.

Info

Check the [Synctool prerequisites](https://docs.zivver.com/en/admin/synctool-v2/prerequisites-synctool.html) to find out what is needed, to connect to your Exchange server.

**Exchange type**

Choose the Exchange type you want to use as a source to synchronize functional accounts to Zivver.

- [Exchange on premise](https://docs.zivver.com/en/admin/synctool-v2/sources-exchange.html#set-up-a-connection-to-exchange-on-premise)
- [Exchange Online with MFA login](https://docs.zivver.com/en/admin/synctool-v2/sources-exchange.html#set-up-a-connection-to-exchange-online-manually)

Note

**Only use Exchange Online with MFA for manual synchronizations**

It is not possible to use Exchange Online with MFA for automatic synchronizations, because entering a Multi-Factor Authentication requires a manual action from the administrator.

- [Exchange Online with Certificate login](https://docs.zivver.com/en/admin/synctool-v2/sources-exchange.html#set-up-a-connection-to-exchange-online-automatically-with-certificate)

### Set up a connection to Exchange on-premise

Select **Exchange on premise**.

- **Exchange address**

Fill in the Exchange address. The Synctool will use this address to set up a remote connection.

Tip

**What should the Exchange address look like?**

The address should look like `http://ServerFQDN/PowerShell/`. Replace `ServerFQDN` with the fully qualified domain name of your Exchange server.

_For example exchange01.example.com._
- **User name**

Fill in the username for the account that can be used to log in to Exchange. The account must meet the criteria in the [Synctool prerequisites](https://docs.zivver.com/en/admin/synctool-v2/prerequisites-synctool.html). The username often is preceded by the domain.

_For example `company\name_exchange_account`._
- **Password**

Enter the password for the Exchange on-premise account.
- **Use Kerberos**

Select this option. Using Kerberos is the default way to authenticate for Exchange on-premise.

### Set up a connection to Exchange Online manually

Select **Exchange Online with MFA login**.

**User name**

Fill in the username for the account that can be used to log in to Exchange Online. The account must meet the criteria in the [Synctool prerequisites](https://docs.zivver.com/en/admin/synctool-v2/prerequisites-synctool.html). The username for Exchange Online is always an email address.

**Use MFA Window Handle Workaround**

Select this option if the server has the ExchangeOnlineManagement PowerShell module version 3.7.0 or higher installed.

Info

**MFA not working with ExchangeOnlineManagement version 3.7.0 or higher**

Due to limitations in the ExchangeOnlineManagement PowerShell module version 3.7.0 and higher, MFA login does not work by default when this module is installed. Enabling this workaround resolves the issue.

### Set up a connection to Exchange Online automatically with certificate

Note

**Set up Certificate Based Authentication for unattended applications**

Make sure [app-only authentication for unattended scripts](https://docs.microsoft.com/en-us/powershell/exchange/app-only-auth-powershell-v2?view=exchange-ps) is already configured before attempting to connect the Zivver Synctool to Exchange Online.

Select **Exchange Online with Certificate login**.

- **Certificate location**

Fill in the location of the `.pfx` file created at [step 3: Generate a self-signed certificate](https://docs.microsoft.com/en-us/powershell/exchange/app-only-auth-powershell-v2?view=exchange-ps#step-3-generate-a-self-signed-certificate) including the name. For example `C:\mycert.pfx`.

Tip

**Pay attention to the run path in PowerShell**

The directory from which you run the PowerShell cmdlet needed to create a certificate is also where the `.pfx` file will be stored. For example if you run the cmdlet from `C:\Windows\System32`, then the file location will be `C:\Windows\System32\mycert.pfx`
- **Certificate password**

Fill in the password that you used to secure the `.pfx` file at [step 3: Generate a self-signed certificate](https://docs.microsoft.com/en-us/powershell/exchange/app-only-auth-powershell-v2?view=exchange-ps#step-3-generate-a-self-signed-certificate). Make sure the password is at least 12 characters long and store the password somewhere safe.
- **Application ID**

Fill in the application ID of the App registration created at [step 1: Application registration in Entra ID](https://learn.microsoft.com/en-us/powershell/exchange/app-only-auth-powershell-v2?view=exchange-ps#step-1-register-the-application-in-microsoft-entra-id).

1. Go to [portal.azure.com](https://portal.azure.com/).
2. Select **Microsoft Entra ID**.
3. Select the tab **App registrations**.
4. Select the App registration created for the Synctool from the list.
5. Copy the **Application (client) ID**.
- **Exchange Organization name**

Fill in the Microsoft domain of your Entra ID tenant. It usually looks like `yourcompany.onmicrosoft.com`.

1. Go to [portal.azure.com](https://portal.azure.com/).
2. Select **Microsoft Entra ID**.
3. Select the tab **Overview**.
4. Look for the primary `.onmicrosoft.com` domain on the tenant information tile.

### Use Get-EXOMailbox command

To improve the performance speed from the Synctool while fetching data from Exchange online, we recommend to select the option **Use Get-EXOMailbox command**. If you are using Exchange properties that are not in the minimum set retrieved by this command, you can specify additional _Properties_ or _Property Sets_. Read more about this [in the Microsoft documentation](https://learn.microsoft.com/en-us/powershell/exchange/cmdlet-property-sets?view=exchange-ps#get-exomailbox-property-sets).

### Select extra PowerShell commands to get more member/delegation data

You can select extra PowerShell commands to get more members or delegations for your mailboxes.

- Use **GetADGroupMember** if you delegate access to mailboxes in Exchange Server via Active Directory Security Groups.
- Use **GetADPermissionSendAs** to retrieve Active Directory access control lists (ACLs) in Exchange Server. This legacy feature is not recommended for use.
- Use **GetDistributionGroupMember (recommended)** if you delegate access to mailboxes in Exchange Server/Online via mail-enabled security groups or distribution groups
- Use **GetRecipient** if mail-enabled objects from Exchange Server/Online are missing in the synchronization that should be present based on filtering options. This legacy feature is not recommended for use.

## Users

**User Field Mapping (Exchange)** allows you to synchronize different types of Exchange mailboxes to Zivver as user accounts. By default only the **UserMailbox** type is enabled, as this usually reflects the users that need to login to Zivver to send or receive sensitive data.

If you are using **Microsoft ADFS** as Identity Provider, you need to select the option to Base64 encode the ZivverAccountKey value. ADFS will provide Zivver with the Base64 encoded version of this value when the user logs in with Single Sign-On.

The following fields are mapped to the values that are standard in Exchange sources:

- **IsActive**

Mapped to the property _AccountDisabled_.
- **Aliases**

Mapped to the property _EmailAddresses(smtp)_.
- **Delegates**

Mapped to the mailbox permissions (retrieved with the _Get-MailboxPermissions_ command).

## Groups

**Group Field Mapping (Exchange)** allows you to synchronize different types of Exchange mailboxes to Zivver as functional accounts.

By default only **SharedMailbox** type is enabled. Other mailbox types are often not used to send or receive sensitive data, and therefore a Zivver functional account is not required.

Tick the box **Replace nested shared mailboxes and nested security groups with their members** when your organization assigns mailbox permissions to nested security groups (groups in groups) or nested shared mailboxes.

## Organizational Units

**Organizational Units Mapping** maps accounts from your Exchange source to an organizational units (OU) in Zivver.

If your organization does not use organizational units in Zivver, leave the default **None or Excel** selected.

Info

**How do I find out if my organization uses organizational units in Zivver?**

If your organization uses organizational units in Zivver, you should have access to [the Organization Units tab in Zivver](https://app.zivver.com/organization/units). If you don’t have access, either your organization doesn’t use organizational units in Zivver, or you don’t have administrator rights.

If your organization uses organizational units in Zivver, then select an option based on your configuration of OUs in the Zivver admin panel.

Tip

**How do I find out if Domain or Custom OU Identifier should be used?**

You can check the Organizational Unit Identifier by browsing to [the Organization Units tab in Zivver](https://app.zivver.com/organization/units), clicking on one of the OUs present and edit _edit_ the Organizational Unit. You will see the identifier in a popup under **Automated account provisioning identifier**.

## Source Filter

**Organization Unit Identifier** allows you to filter on email addresses.

1. Check **Enable Exchange Source filtering**.
2. Select the **Filter variable** you want to filter on.
3. Enter the filter value(s) at **Filter text**.

_If you want to enter more than one filter value, add each value on a separate line._
4. Choose between a positive filter (include) or negative filter (exclude).

_You can’t include and exclude in the same filter._

_View the results at [Data Preview](https://docs.zivver.com/en/admin/synctool-v2/sources-exchange.html#data-preview)._

## Merge Settings

Use **Source Merge Settings** to choose what the Synctool should do if distinct sources (e.g. an Exchange source and Excel source) contain identical entries.

If this is the first source in the [Source Overview](https://docs.zivver.com/en/admin/synctool-v2/sources.html#overview) then no merge settings are available.

- **Overwrite**

Objects found in the currently selected source overwrite duplicate objects from previous sources.
- **Ignore**

Objects found in the currently selected source are overwritten by duplicate objects from previous sources.
- **Conflict**

Prompt the admin to resolve duplicates before synchronizing.

## Data Preview

**Source Data Preview (Exchange)** allows you to preview all accounts found in your Exchange source.

Click Load the data now to get a preview of all accounts found in your Exchange source.

## Next steps

If the data preview is returned as you would expect, you can either [configure another source](https://docs.zivver.com/en/admin/synctool-v2/sources.html#sources-to-add), or go to [Syncing](https://docs.zivver.com/en/admin/synctool-v2/syncing.html).

Updated on 2026-06-18
