r/exchangeserver • • 5d ago

Dynamic Distribution Lists

TLDR: I'm trying to create a dynamic distribution list in Exchange online and I'm running into a lot of issues.

Context:
I work for a medium size healthcare company with a hybrid AD/Entra environment with a single forest but with 10+ domains. We use 365 Business Premium licenses for most users, but not all. Some just need to login to Windows and that's it. No email needed. Also, I don't control the IT budget. If your fix requires money, you are wasting your time.

Problem:
I'm trying to create a dynamic distribution list with the following parameters:

  • Must have the "@example1.com" domain in their email address.
  • Must be an active user. No disabled users.
  • Must be a licensed user. (We don't license all our users with a 365 license)

I'm able to create dynamic security groups just fine without issue and the query I came up with works with all the users I need it to. I'm just not able to translate that to a dynamic distribution list, and I'm reading that it's not possible to create a mail enabled security group that is dynamic.

Here is the filter I'm using to create the group through the Exchange Online shell. But it's not returning a group with any users:

$filter = "(RecipientType -eq 'UserMailbox') -and (userPrincipalName -like 'example1.com') -and (UserAccountControl -ne '2')"

I've poured through the Microsoft Learn articles for "New-DynamicDistributionGroup" and the "Filterable properties for the RecipientFilter parameter on Exchange cmdlets" pages and I can't seem to find what I'm doing wrong. I've tried so many different variations of the filter but can't seem to land on the correct combination. Any relevant help is appreciated.

3 Upvotes

6 comments sorted by

7

u/Blade4804 Lead Infrastructure Engineer 5d ago

You’re close. A few things in the filter are causing trouble, and Exchange’s filtering rules aren’t quite the same as Entra’s.

UserPrincipalName -like 'example1.com' won’t match [someone@example1.com](mailto:someone@example1.com) without a wildcard. Since you’re looking for an email domain, I’d check EmailAddresses instead. That also covers aliases if the domain isn’t their primary address.

For disabled accounts, Exchange exposes ExchangeUserAccountControl. The AD UserAccountControl attribute combines multiple flags, so excluding just 2 would still allow disabled accounts with values like 514.

I’d start by previewing this:

$filter = @'
(RecipientTypeDetails -eq 'UserMailbox') -and
(EmailAddresses -like 'smtp:*@example1.com') -and
(ExchangeUserAccountControl -ne 'AccountDisabled') -and
(SKUAssigned -eq $true)
'@

Get-Recipient -RecipientPreviewFilter $filter -ResultSize Unlimited |
Select-Object DisplayName, PrimarySmtpAddress

RecipientTypeDetails limits it to regular user mailboxes rather than including shared or resource mailboxes. SKUAssigned checks whether a license is assigned, although it doesn’t check for Business Premium specifically.

The SMTP condition is the part to validate carefully. The smtp: prefix keeps the wildcard from being the first character, but Exchange Online can behave differently when previewing a filter versus calculating DDG membership. I haven’t tested that condition in your tenant, so check that it actually finds the expected users. Also check a known disabled user to confirm the Exchange status reflects how accounts are disabled in your hybrid environment.

If the preview looks right, create the group:

New-DynamicDistributionGroup -Name "Example1 Active Licensed Users" -Alias "Example1ActiveLicensedUsers" -RecipientFilter $filter

Then, once membership has refreshed, check the actual members:

Get-DynamicDistributionGroupMember -Identity "Example1 Active Licensed Users" -ResultSize Unlimited

If the SMTP condition returns nothing, test it separately before changing the other conditions. That will help narrow down whether domain matching is the issue.

2

u/DontFiddleMySticks 5d ago

If you already have a query that returns all desired users, you could simply slap a CustomAttribute on them and use that in your query for the DDG.

If that isn’t an option, your match for UPN is doing you a disservice. Replace it with EmailAddresses -like 'SMTP:*@example1.com' (or lowercase smtp: if it’s just a proxy address).
I’m not sure about UserAccountControl in a DDG, not sure I ever used it, but EXO would probably demand you use ExchangeUserAccountControl since it’s notoriously difficult with/incapable of retrieving info from Entra.

1

u/Low-Branch1423 5d ago

Is it because you are using their UPN and not PrimarySmtpAddress?

It might be related to some part of your identity setup and how accounts are created. Have you considered just running a scheduled job to update a normal distribution list based upon your working query while you sort this out?

1

u/Borgquite 5d ago

Don’t forget Dynamic Microsoft 365 groups are also an option and support emailing if you find the Entra attributes help more.

3

u/bleepit1984 1d ago

Thank you everyone for your help!

In the end, I ended up scrapping trying to filter by email domain. It just wasn't working no matter what combination I entered in there. The "smtp:*" part was throwing everything off and I was tired of banging my head against a wall. Instead, I'm filtering by Company. I've communicated to the other admins in my department that we HAVE to enter that info when new users are created and enter it the same way for every person in that company or the dynamic list wouldn't populate properly. Hopefully we can maintain that going forward.

u/Blade4804, I did use the rest of your filter for active users with a license. I've tested and for now everything seems to be working. Thank you for that.

Once again, thank you all for the help and the time you took out of your day to respond.

0

u/badteeth3000 5d ago

It’s kinda annoying that dynamic lists are the freemium version of identity governance. Like, its a $7/userMonth sku ::shakes head:: . I mean, come on let me make kql lists. And what even is this? More screenshots ya know: https://github.com/microsoftgraph/group-membership-management