SearchCtrl + K

Practical Exchange Administration with PowerShell

A practical guide to recipient administration, mail flow, security, compliance, hybrid operations, migration, public folders, monitoring, and troubleshooting with Exchange PowerShell.

Technology

Key Takeaways

  • Choose the correct management plane across Exchange Online, Exchange Server, Purview, and hybrid environments.
  • Manage recipients, mailboxes, permissions, mail flow, security, compliance, migration, and public folders safely.
  • Build operational reports and troubleshooting workflows around evidence rather than guesswork.
  • Preserve before-state, verification, and rollback evidence for production changes.

Practical Exchange Administration with PowerShell

Exchange administration usually starts with a simple request: give someone access to a mailbox, investigate a delivery problem, change a transport rule, prepare a migration, or find out why a setting is not behaving as expected.

The difficult part is rarely the first command.

The difficult part is knowing where the object is managed, what its current state is, how wide the change should be, and how you will prove that the result is correct.

This article brings those decisions together into one practical operating model. You will move from everyday recipient and mailbox administration into mail flow, security, compliance, hybrid operations, migration, public folders, monitoring, and troubleshooting.

Image detail
100%
Exchange administration operating model showing the progression from selecting the correct management plane through current-state discovery, baseline capture, target scoping, preview or pilot, controlled change, service verification, evidence preservation, and rollback.

1. Start with the management plane

Exchange administration becomes complicated when a property is visible in one place but authoritative somewhere else.

Exchange Online, Exchange Server, Microsoft Purview, and hybrid Exchange expose different command families and different boundaries. A syntactically correct command can still be the wrong operational choice if it is run against the wrong system.

Exchange PowerShell management planes
Management planeConnectionPrimary purposeOperational rule
Exchange Online`ExchangeOnlineManagement` / `Connect-ExchangeOnline`Cloud recipients, mailboxes, mail flow, Exchange Online configuration, and many EOP tasksUse modern authentication and current EXO behavior; prefer EXO-prefixed retrieval cmdlets for scale-sensitive reporting.
Exchange ServerExchange Management Shell / supported remote PowerShellServers, databases, DAGs, transport, virtual directories, certificates, and on-premises recipientsWrite current on-premises examples Subscription Edition-first.
Microsoft Purview / Security & Compliance`Connect-IPPSSession`Compliance search, eDiscovery, retention, audit, DLP, labels, and related compliance operationsDo not assume every compliance cmdlet exists in an Exchange Online session.
Hybrid ExchangeEXO PowerShell + Exchange Server EMS / management toolsRemote mailbox lifecycle, synchronized attributes, mail flow, OAuth, federation, migrations, and source-of-authority decisionsDetermine where the relevant identity or Exchange attribute is authoritative before changing it.
Image detail
100%
Exchange management planes and boundaries showing Exchange Online, Exchange Server, the hybrid boundary, and Microsoft Purview, with source-of-authority guidance for deciding where administrative changes belong.

Before we start changing recipients and mailboxes, keep one idea in mind: good Exchange administration is a sequence of decisions, not a race to the first working cmdlet.

Exchange administration field guide

The operating model

Use the same evidence-driven sequence for a single recipient change or a larger production operation: know where to act, establish the current state, control the change, and prove the result.

Step 01

Management Plane

Choose the correct management plane before touching the object or configuration.

What to do

  • Identify whether the task belongs to Exchange Online, Exchange Server, Microsoft Purview, or a hybrid boundary.
  • Determine the source of authority for the object or property.
  • Confirm the session, tenant, forest, and applicable permissions.
1 of 9
Core principle:successful command execution is not the same as successful administration. Verify the resulting service behavior and preserve the evidence that proves it.

2. Recipient administration: identify before you modify

Most Exchange requests begin with a recipient, mailbox, group, contact, or resource. Identify the actual recipient class before changing it.

$Identity = 'alex@contoso.com'

Get-EXORecipient -Identity $Identity |
    Select-Object DisplayName,
                  PrimarySmtpAddress,
                  RecipientType,
                  RecipientTypeDetails,
                  ExternalDirectoryObjectId,
                  Guid

Get-EXOMailbox -Identity $Identity `
    -Properties ArchiveStatus,RetentionPolicy,CustomAttribute1 |
    Select-Object DisplayName,
                  PrimarySmtpAddress,
                  RecipientTypeDetails,
                  ArchiveStatus,
                  RetentionPolicy,
                  CustomAttribute1

On Exchange Server:

Get-Recipient -Identity 'alex@contoso.com' |
    Format-List Name,
                PrimarySmtpAddress,
                RecipientType,
                RecipientTypeDetails,
                Guid
Common Exchange recipient classes
Recipient typeTypical management planeRepresentative cmdletsOperational consideration
User mailboxEXO or Exchange Server, depending on mailbox location`Get-EXOMailbox`, `Get-Mailbox`, `Set-Mailbox`Confirm mailbox location, provisioning state, and synchronization status.
Shared mailboxEXO or Exchange Server`New-Mailbox -Shared`, `Set-Mailbox -Type Shared`, `Add-MailboxPermission`Review permissions, storage, archive, and licensing requirements before changes.
Room / equipment mailboxEXO or Exchange Server`New-Mailbox -Room`, `New-Mailbox -Equipment`, `Set-CalendarProcessing`Booking behavior is primarily calendar-processing configuration.
Mail user / contactEXO or Exchange Server`New-MailUser`, `New-MailContact`, `Set-MailUser`, `Set-MailContact`These represent external mail targets; do not casually change recipient semantics.
Remote mailboxHybrid / on-premises management plane`New-RemoteMailbox`, `Enable-RemoteMailbox`, `Set-RemoteMailbox`The on-premises object represents a cloud mailbox in classic hybrid management.
Distribution groupEXO or Exchange Server`New-DistributionGroup`, `Add-DistributionGroupMember`Membership is explicitly managed rather than calculated.
Dynamic distribution groupEXO or Exchange Server`New-DynamicDistributionGroup`, `Set-DynamicDistributionGroup`Membership is calculated from a recipient filter; validate the filter before relying on it for delivery.

Establish a baseline

For recurring administration, make discovery produce evidence rather than disappearing into the terminal.

$RunId = Get-Date -Format 'yyyyMMdd-HHmmss'
$Out   = ".\RecipientBaseline-$RunId.csv"

Get-EXORecipient -ResultSize Unlimited |
    Select-Object DisplayName,
                  PrimarySmtpAddress,
                  RecipientTypeDetails,
                  Guid,
                  ExternalDirectoryObjectId |
    Sort-Object RecipientTypeDetails,DisplayName |
    Export-Csv $Out -NoTypeInformation

Write-Host "Baseline exported to $Out"

3. Mailbox administration is service administration

Common mailbox changes include archives, forwarding, quotas, mailbox features, automatic replies, client access, regional settings, and resource booking.

Mailbox administration areas
AreaCmdletsWhat to inspectOperational caution
Inventory`Get-EXOMailbox`, `Get-Mailbox`, `Get-EXOMailboxStatistics`, `Get-MailboxStatistics``Identity`, `ResultSize`, properties, property setsUse optimized EXO retrieval for scale-sensitive reporting.
Mailbox features`Set-Mailbox`, `Set-CASMailbox`, `Set-MailboxRegionalConfiguration`Mailbox type, address visibility, retention, addresses, regional settingsBe deliberate with multivalued properties.
Archive`Enable-Mailbox -Archive`, `Disable-Mailbox -Archive`, `Set-Mailbox`Archive state and quota propertiesCheck licensing, mailbox plan, and tenant policy.
Automatic replies`Get-MailboxAutoReplyConfiguration`, `Set-MailboxAutoReplyConfiguration`State, messages, start/end timesCapture existing configuration before administrator-driven changes.
Resources`Get-CalendarProcessing`, `Set-CalendarProcessing`Booking policy, window, in-policy behavior, delegatesCalendar behavior is not explained by mailbox properties alone.
Client access`Get-CASMailbox`, `Set-CASMailbox`, `Get-EXOCASMailbox`OWA, MAPI, ActiveSync, POP, IMAP stateValidate the affected client population before broad protocol changes.

Controlled forwarding

Forwarding deserves additional scrutiny because it can be both a legitimate business requirement and a security signal.

$Identity = 'alex@contoso.com'
$RunId    = Get-Date -Format 'yyyyMMdd-HHmmss'

$Before = Get-EXOMailbox -Identity $Identity `
    -Properties ForwardingAddress,
                ForwardingSmtpAddress,
                DeliverToMailboxAndForward

$Before |
    Select-Object DisplayName,
                  PrimarySmtpAddress,
                  ForwardingAddress,
                  ForwardingSmtpAddress,
                  DeliverToMailboxAndForward |
    Export-Csv ".\Forwarding-Before-$RunId.csv" -NoTypeInformation

Set-Mailbox -Identity $Identity `
    -ForwardingSmtpAddress 'smtp:destination@contoso.com' `
    -DeliverToMailboxAndForward $true

Get-EXOMailbox -Identity $Identity `
    -Properties ForwardingAddress,
                ForwardingSmtpAddress,
                DeliverToMailboxAndForward |
    Select-Object DisplayName,
                  PrimarySmtpAddress,
                  ForwardingAddress,
                  ForwardingSmtpAddress,
                  DeliverToMailboxAndForward

Bulk changes

CSV-driven work should separate input validation, target resolution, execution, and result reporting.

# CSV columns: Identity, Office, CustomAttribute1
$InputPath = '.\MailboxUpdates.csv'
$RunId     = Get-Date -Format 'yyyyMMdd-HHmmss'
$LogPath   = ".\MailboxUpdateLog-$RunId.csv"
$Rows      = Import-Csv $InputPath

$Results = foreach ($Row in $Rows) {
    $Result = [ordered]@{
        Identity         = $Row.Identity
        Office           = $Row.Office
        CustomAttribute1 = $Row.CustomAttribute1
        Status           = 'NotStarted'
        Error            = $null
    }

    try {
        if ([string]::IsNullOrWhiteSpace($Row.Identity)) {
            throw 'Identity is blank.'
        }

        $Mailbox = Get-EXOMailbox -Identity $Row.Identity -ErrorAction Stop

        $Params = @{
            Identity         = $Mailbox.PrimarySmtpAddress
            Office           = $Row.Office
            CustomAttribute1 = $Row.CustomAttribute1
            ErrorAction      = 'Stop'
        }

        Set-Mailbox @Params
        $Result.Status = 'Updated'
    }
    catch {
        $Result.Status = 'Failed'
        $Result.Error  = $_.Exception.Message
    }

    [pscustomobject]$Result
}

$Results | Export-Csv $LogPath -NoTypeInformation
$Results | Group-Object Status | Select-Object Name,Count

Common failures include using display names as identities, confusing configuration with mailbox statistics, replacing an entire multivalued address collection when only one value should change, assuming shared mailboxes never require licensing, and changing client-access protocols without understanding the affected population.

4. Delegation: configure the exact right

Treat each delegation permission as a separate capability.

Exchange mailbox delegation
PermissionPurposeRepresentative cmdletsImportant distinction
Full AccessOpen mailbox contents`Add-MailboxPermission`, `Get-EXOMailboxPermission`Does not grant Send As; automapping should be intentional.
Send AsSend as the mailbox or recipient`Add-RecipientPermission`, `Get-EXORecipientPermission`The mailbox appears as the sender; treat as a high-impact permission.
Send on BehalfSend on behalf of the mailbox`Set-Mailbox -GrantSendOnBehalfTo`Use multivalue add/remove syntax to avoid overwriting existing delegates.
Folder permissionAccess to a specific mailbox folder`Add-MailboxFolderPermission`, `Set-MailboxFolderPermission`Calendar and folder identities include the folder path.
$Mailbox  = 'shared-helpdesk@contoso.com'
$Delegate = 'alex@contoso.com'

Add-MailboxPermission -Identity $Mailbox -User $Delegate `
    -AccessRights FullAccess `
    -InheritanceType All `
    -AutoMapping $false

Add-RecipientPermission -Identity $Mailbox -Trustee $Delegate `
    -AccessRights SendAs `
    -Confirm:$false

Set-Mailbox -Identity $Mailbox `
    -GrantSendOnBehalfTo @{Add=$Delegate}

Add-MailboxFolderPermission -Identity "$Mailbox`:\Calendar" `
    -User $Delegate `
    -AccessRights Reviewer

Verify each right with the matching retrieval command:

Get-EXOMailboxPermission -Identity $Mailbox |
    Where-Object {
        $_.User -like '*alex*' -and
        $_.AccessRights -contains 'FullAccess'
    }

Get-EXORecipientPermission -Identity $Mailbox -Trustee $Delegate

Get-Mailbox -Identity $Mailbox |
    Format-List GrantSendOnBehalfTo

Get-MailboxFolderPermission -Identity "$Mailbox`:\Calendar"

5. Mail flow rules: broad power requires narrow changes

Transport rules operate at organization scale. Evaluate five interacting dimensions:

conditions → exceptions → actions → priority → mode

StopRuleProcessing adds another important control because it determines whether lower-priority rules continue to evaluate the message.

Baseline the existing configuration first.

$RunId = Get-Date -Format 'yyyyMMdd-HHmmss'

Get-TransportRule |
    Select-Object Name,
                  State,
                  Mode,
                  Priority,
                  Comments,
                  Description |
    Export-Csv ".\TransportRules-Before-$RunId.csv" -NoTypeInformation

For a new change, prefer a narrow test or audit mode where the workload supports it.

New-TransportRule -Name 'Mark External Project Aurora Mail' `
    -FromScope NotInOrganization `
    -SubjectOrBodyContainsWords 'Project Aurora' `
    -PrependSubject '[EXTERNAL-PROJECT] ' `
    -Mode Audit `
    -Comments 'Change CHG000000; owner Messaging Operations'

Get-TransportRule -Identity 'Mark External Project Aurora Mail' |
    Format-List Name,
                State,
                Mode,
                Priority,
                Comments,
                Description

Use message-trace evidence to prove Exchange Online behavior rather than relying only on the rule object’s configuration.

6. Connectors, domains, and routing

Start connector administration with the routing question: What path should the message take, and why? Exchange Online uses inbound/outbound connectors; Exchange Server uses Send/Receive connectors.

Exchange connector and domain administration
ObjectRepresentative cmdletsKey propertiesOperational concern
EXO inbound connector`Get/New/Set/Remove-InboundConnector``SenderDomains`, `SenderIPAddresses`, `RequireTls`Defines trusted or partner mail entering Exchange Online.
EXO outbound connector`Get/New/Set/Remove-OutboundConnector`, `Validate-OutboundConnector``RecipientDomains`, `SmartHosts`, `TLSSettings`Defines routes from Exchange Online to partners, smart hosts, or on-premises systems.
Exchange Server Send connector`Get/New/Set/Remove-SendConnector``AddressSpaces`, `SmartHosts`, `DNSRoutingEnabled`Defines outbound routing from on-premises transport.
Exchange Server Receive connector`Get/New/Set/Remove-ReceiveConnector``Bindings`, `RemoteIPRanges`, `PermissionGroups`, `AuthMechanism`Controls SMTP submission; open-relay exposure must be explicitly avoided.
Accepted / remote domains`Get/Set-AcceptedDomain`, `Get/Set-RemoteDomain``DomainName`, `DomainType`, `TargetDeliveryDomain`Domain classification and remote behavior often explain routing symptoms.
# Exchange Online
Get-InboundConnector |
    Select-Object Name,Enabled,ConnectorType,SenderDomains,
                  SenderIPAddresses,RequireTls

Get-OutboundConnector |
    Select-Object Name,Enabled,ConnectorType,RecipientDomains,
                  SmartHosts,TLSSettings

Get-AcceptedDomain |
    Select-Object Name,DomainName,DomainType,Default

Get-RemoteDomain |
    Select-Object DomainName,AutoReplyEnabled,
                  AllowedOOFType,AutoForwardEnabled

# Exchange Server
Get-SendConnector |
    Select-Object Name,Enabled,AddressSpaces,
                  SmartHosts,DNSRoutingEnabled,SourceTransportServers

Get-ReceiveConnector |
    Select-Object Identity,Enabled,Bindings,
                  RemoteIPRanges,PermissionGroups,AuthMechanism

7. Message trace: diagnose the path, not just the symptom

Use the evidence source appropriate to the transport boundary: Exchange Online message trace; Exchange Server message tracking and queues.

Message-delivery diagnostic paths
ScenarioPrimary evidenceUseful inputsWhat it tells you
Missing or delayed cloud message`Get-MessageTraceV2`Sender, recipient, time range, Message-ID when availableWhat Exchange Online observed: received, delivered, deferred, failed, quarantined, or expanded.
Detailed cloud event history`Get-MessageTraceDetailV2`MessageTraceId, recipient, MessageIdPipeline events such as RECEIVE, SEND, DELIVER, DEFER, FAIL, EXPAND, and TRANSFER.
Deep cloud transport evidence`Start-HistoricalSearch`Report title, time range, MessageId, notification addressExtended Message Trace output for deeper analysis.
On-premises queue growth`Get-Queue`, `Get-Message`, `Get-QueueDigest`Server, queue identity, filtersQueue state, next hop, retry state, and affected messages.
On-premises delivery path`Get-MessageTrackingLog`Sender, recipients, MessageId, start/end, EventIdEvents recorded by Exchange Server transport.
$Start = (Get-Date).AddHours(-4)
$End   = Get-Date

$Trace = Get-MessageTraceV2 `
    -SenderAddress sender@contoso.com `
    -RecipientAddress recipient@fabrikam.com `
    -StartDate $Start `
    -EndDate $End `
    -ResultSize 5000

$Trace |
    Select-Object Received,
                  SenderAddress,
                  RecipientAddress,
                  Subject,
                  Status,
                  MessageTraceId |
    Export-Csv '.\MessageTraceV2.csv' -NoTypeInformation

$Trace |
    Get-MessageTraceDetailV2 |
    Export-Csv '.\MessageTraceDetailV2.csv' -NoTypeInformation

On Exchange Server:

Get-MessageTrackingLog `
    -Sender sender@contoso.com `
    -Recipients recipient@fabrikam.com `
    -Start (Get-Date).AddHours(-4) `
    -End (Get-Date) |
    Select-Object Timestamp,
                  EventId,
                  Source,
                  Sender,
                  Recipients,
                  MessageSubject,
                  RecipientStatus

Get-Queue |
    Format-Table Identity,Status,MessageCount,NextHopDomain

Get-QueueDigest

8. Security and protection policies

Protection administration follows a policy-and-rule model: the policy defines behavior; the rule controls scope, priority, and state.

Protection policy administration
AreaRepresentative cmdletsCheckOperational guidance
Anti-spam / hosted content filter`Get/Set/New-HostedContentFilterPolicy`, `Get/Set/New-HostedContentFilterRule`Policy settings plus rule scope and priorityBaseline policy/rule pairs before introducing custom behavior.
Anti-malware`Get/Set/New-MalwareFilterPolicy`, `Get/Set/New-MalwareFilterRule`Settings, recipients, exceptionsPolicy and rule are separate objects.
Anti-phishing / Safe Links / Safe AttachmentsCorresponding policy and rule familiesRecipient scope, action settings, priorityPrefer standard or strict preset security policies before unnecessary custom sprawl.
Quarantine`Get-QuarantineMessage`, `Release-QuarantineMessage`, `Delete-QuarantineMessage`Message identity, recipient, received timePreserve evidence before release or delete actions.
DKIM`Get-DkimSigningConfig`, `New-DkimSigningConfig`, `Set-DkimSigningConfig`Domain, enabled state, selectorsCoordinate DNS and service verification.
Message encryptionIRM and OME cmdlet familiesConfiguration, transport rules, message identityCombine configuration, trace, headers, and client evidence during troubleshooting.
Get-HostedContentFilterPolicy |
    Select-Object Name,IsDefault,
                  SpamAction,HighConfidenceSpamAction

Get-HostedContentFilterRule |
    Select-Object Name,State,Priority,
                  HostedContentFilterPolicy,RecipientDomainIs

Get-MalwareFilterPolicy |
    Select-Object Name,IsDefault,Action,EnableFileFilter

Get-MalwareFilterRule |
    Select-Object Name,State,Priority,
                  MalwareFilterPolicy,SentTo

Get-DkimSigningConfig |
    Select-Object Domain,Enabled,Status,
                  Selector1CNAME,Selector2CNAME

9. Retention, compliance, eDiscovery, and audit

Compliance work requires precise terminology. Exchange MRM and Microsoft Purview retention are related but not interchangeable: MRM remains relevant to mailbox/archive lifecycle, while Purview provides the broader Microsoft 365 governance model.

Exchange and Purview compliance workloads
AreaCmdlet familyUse caseOperational boundary
Exchange MRMRetention policy/tag cmdlets, `Set-Mailbox`, `Start-ManagedFolderAssistant`Mailbox retention tags, archive movement, deleted-item behaviorExchange mailbox/archive lifecycle; do not present it as the only Microsoft 365 retention model.
Purview retention`RetentionCompliancePolicy` / `RetentionComplianceRule` familiesMulti-workload retention and deletion governanceRequires appropriate Purview permissions and licensing.
Compliance Search`New-ComplianceSearch`, `Start-ComplianceSearch`, `Get-ComplianceSearch`, `New-ComplianceSearchAction`Search locations and contentUse Security & Compliance PowerShell and verify current session requirements.
Unified audit`Search-UnifiedAuditLog`Microsoft 365 audit investigationsExport and preserve investigation evidence.
Exchange admin audit`Get-AdminAuditLogConfig`, `Search-AdminAuditLog`Administrative operation reviewUseful for Exchange cmdlet and parameter activity.

For compliance-search scenarios that require it, establish the Purview session explicitly.

Connect-IPPSSession -EnableSearchOnlySession

New-ComplianceSearch -Name 'Incident-Project-Aurora' `
    -ExchangeLocation alex@contoso.com `
    -ContentMatchQuery 'subject:"Project Aurora"'

Start-ComplianceSearch -Identity 'Incident-Project-Aurora'

Get-ComplianceSearch -Identity 'Incident-Project-Aurora'

For an audit investigation:

$Start = (Get-Date).AddDays(-7)
$End   = Get-Date

Search-UnifiedAuditLog `
    -StartDate $Start `
    -EndDate $End `
    -Operations SoftDelete,HardDelete,MoveToDeletedItems `
    -UserIds alex@contoso.com `
    -ResultSize 5000 |
    Export-Csv '.\Audit-MailDeletion.csv' -NoTypeInformation

10. Hybrid administration: determine the source of authority

Hybrid Exchange is where administrative syntax meets architecture. A recipient can exist across directory, cloud, and on-premises systems without those systems sharing authority over every property.

Before changing a hybrid recipient, answer five questions:

  1. Is the object directory-synchronized?
  2. Where is identity authoritative?
  3. Where are Exchange attributes authoritative?
  4. Is cloud-managed Exchange attribute management enabled for this object or tenant?
  5. Is the task recipient management, service configuration, mail flow, or migration?
Get-HybridConfiguration | Format-List *

Get-OnPremisesOrganization |
    Format-List Name,OrganizationGuid,HybridDomains,OutboundConnector

Get-IntraOrganizationConnector |
    Format-List Name,DiscoveryEndpoint,TargetAddressDomains,Enabled

Get-OrganizationRelationship |
    Format-List Name,DomainNames,
                FreeBusyAccessEnabled,
                TargetAutodiscoverEpr

Get-RemoteMailbox -Identity 'alex@contoso.com' |
    Format-List Name,
                PrimarySmtpAddress,
                RemoteRoutingAddress,
                RemoteRecipientType,
                ExchangeGuid,
                ArchiveGuid
Hybrid task and likely management plane
TaskLikely management planeRepresentative cmdletsRisk
Remote mailbox propertiesUsually Exchange Server EMS / management tools unless supported cloud-managed attributes are enabled`Get/Set-RemoteMailbox`Wrong-plane edits can be overwritten by synchronization.
Cloud mailbox service settingsExchange Online`Set-Mailbox`, `Set-CASMailbox`, `Get-EXOMailbox`Cloud-only service features belong in EXO.
Hybrid connectors / configurationHCW plus EXO and EMS validation`Get-HybridConfiguration`, connector cmdletsPrefer HCW-owned configuration unless a documented change requires manual edits.
Free/busy and OAuthBoth sides`Get-IntraOrganizationConnector`, `Test-OAuthConnectivity`, `Get-OrganizationRelationship`Certificates, endpoints, and version dependencies matter.
Cloud-managed Exchange attributesExchange Online for supported attributes after enablementSupported `Set-Mailbox` cloud-management controlsDo not treat cloud management as a blanket replacement for on-premises identity authority.

11. Migration: make every phase observable

Mailbox migration depends on endpoint readiness, authentication, directory and mailbox state, throttling, data consistency, cutover timing, and post-move validation.

Mailbox migration phases
StageRepresentative cmdletsOperational focus
Endpoint discovery`Get-MigrationEndpoint`, `Test-MigrationServerAvailability`Confirm endpoint type, authentication, remote server, MRSProxy readiness, and credentials.
Batch creation`New-MigrationBatch`Use CSV input, endpoint, target delivery domain, and start/completion behavior intentionally.
Batch control`Start-MigrationBatch`, `Stop-MigrationBatch`, `Complete-MigrationBatch`, `Remove-MigrationBatch`Separate synchronization from completion when cutover timing matters.
User status`Get-MigrationUser`, `Get-MigrationUserStatistics`Review status, skipped items, consistency, errors, and reports.
Move requests`New/Get/Suspend/Resume/Remove-MoveRequest`, `Get-MoveRequestStatistics`Use for lower-level mailbox moves and troubleshooting.
$Endpoint = Get-MigrationEndpoint |
    Where-Object { $_.Identity -like '*Hybrid*' } |
    Select-Object -First 1

$Batch = New-MigrationBatch -Name 'Wave-01' `
    -SourceEndpoint $Endpoint.Identity `
    -TargetDeliveryDomain 'contoso.mail.onmicrosoft.com' `
    -CSVData ([System.IO.File]::ReadAllBytes('.\Wave-01.csv'))

Start-MigrationBatch -Identity $Batch.Identity

Get-MigrationBatch -Identity 'Wave-01'

Get-MigrationUser -BatchId 'Wave-01' |
    Get-MigrationUserStatistics |
    Select-Object Identity,
                  Status,
                  PercentComplete,
                  DataConsistencyScore,
                  SkippedItemCount

12. Public folders: treat them as an architecture

Public-folder administration combines hierarchy, content, permissions, mail enablement, mailboxes, capacity, migration, and client behavior, so treat it as a structured project rather than isolated commands.

Get-PublicFolder -Recurse -ResultSize Unlimited |
    Select-Object Identity,
                  Name,
                  ParentPath,
                  MailEnabled |
    Export-Csv '.\PublicFolder-Hierarchy.csv' -NoTypeInformation

Get-PublicFolderStatistics -ResultSize Unlimited |
    Select-Object Name,
                  FolderPath,
                  ItemCount,
                  TotalItemSize,
                  LastModificationTime |
    Export-Csv '.\PublicFolder-Statistics.csv' -NoTypeInformation

Get-MailPublicFolder -ResultSize Unlimited |
    Select-Object Name,
                  PrimarySmtpAddress,
                  EmailAddresses |
    Export-Csv '.\MailEnabledPublicFolders.csv' -NoTypeInformation
Public-folder administration areas
AreaRepresentative cmdletsWhat to preserve
Hierarchy`Get/New/Set/Remove-PublicFolder`Path and parent-child relationships; export before restructuring.
Statistics`Get-PublicFolderStatistics`Item count, size, and modification data.
Permissions`Get/Add/Remove-PublicFolderClientPermission`Explicit and inherited access before changes.
Mail enablement`Get/Enable/Disable/Set-MailPublicFolder`SMTP addresses and mail-flow expectations.
Public-folder mailboxes`Get-Mailbox -PublicFolder`, `New-Mailbox -PublicFolder`Placement and capacity considerations.
MigrationMigration batch and public-folder migration familiesPre/post snapshots, validation, lock-down/finalization steps, and one controlled migration plan.

13. Monitoring and operational reporting

A useful operational report identifies the affected scope, fault domain, severity, and evidence. Exchange Server adds database, DAG, queue, and server-health data to the cloud-side configuration and trace data used in Exchange Online.

Exchange Server health snapshot

Get-ServerHealth -Identity EX01 |
    Where-Object AlertValue -ne 'Healthy' |
    Select-Object Server,
                  HealthSet,
                  Name,
                  AlertValue,
                  TargetResource

Get-MailboxDatabaseCopyStatus * |
    Select-Object Name,
                  Status,
                  CopyQueueLength,
                  ReplayQueueLength,
                  ContentIndexState

Test-ReplicationHealth -Identity EX01

Get-QueueDigest

Exchange Online operational reports

$RunId = Get-Date -Format 'yyyyMMdd-HHmmss'

Get-EXOMailbox -ResultSize Unlimited `
    -Properties ArchiveStatus,RetentionPolicy |
    Select-Object DisplayName,
                  PrimarySmtpAddress,
                  RecipientTypeDetails,
                  ArchiveStatus,
                  RetentionPolicy |
    Export-Csv ".\EXO-MailboxInventory-$RunId.csv" -NoTypeInformation

Get-EXOMailbox -ResultSize Unlimited `
    -Properties ForwardingSmtpAddress,
                ForwardingAddress,
                DeliverToMailboxAndForward |
    Where-Object {
        $_.ForwardingSmtpAddress -or
        $_.ForwardingAddress
    } |
    Select-Object DisplayName,
                  PrimarySmtpAddress,
                  ForwardingSmtpAddress,
                  ForwardingAddress,
                  DeliverToMailboxAndForward |
    Export-Csv ".\EXO-ForwardingInventory-$RunId.csv" -NoTypeInformation
Operational reporting by environment
Monitoring areaRepresentative cmdletsEnvironmentOperational use
Server health`Get-ServerHealth`, `Get-HealthReport`, monitoring probesExchange ServerLocate component-level health faults.
Database availability`Get-MailboxDatabaseCopyStatus`, `Test-ReplicationHealth`Exchange ServerAssess database-copy and replication health.
Queues and transport`Get-Queue`, `Get-QueueDigest`Exchange ServerInvestigate delivery backlogs and routing incidents.
Message trace`Get-MessageTraceV2`, `Get-MessageTraceDetailV2`, `Start-HistoricalSearch`Exchange OnlineEstablish cloud-side transport evidence.
Mailbox reporting`Get-EXOMailbox`, `Get-EXOMailboxStatistics`Exchange OnlineInventory mailbox configuration and service data.
Audit / compliance`Search-UnifiedAuditLog`, compliance cmdletsPurview / Security & CompliancePreserve investigation and governance evidence.

14. Troubleshooting: collect evidence before changing things

Troubleshooting should be hypothesis-driven: collect evidence, isolate the fault domain, remediate deliberately, and verify the outcome.

Exchange troubleshooting starting points
SymptomEvidence to collectRepresentative commands
Recipient cannot receive mailRecipient type, accepted domain, address, moderation, rules, connectors, trace/tracking, quarantine`Get-Recipient`, `Get-EXORecipient`, `Get-AcceptedDomain`, `Get-TransportRule`, Message Trace V2 or message tracking
Shared mailbox inaccessibleFull Access, automapping, mailbox type/state, licensing, Outlook/client state, hybrid ACL behavior`Get-EXOMailboxPermission`, `Get-MailboxPermission`, `Get-Recipient` and client checks
External mail delayedTrace status, connector, TLS, queue, remote response, DNS, smart hostMessage Trace V2, `Start-HistoricalSearch`, `Get-Queue`, Send/Outbound connector cmdlets
Transport rule behaves unexpectedlyPriority, mode, conditions, exceptions, `StopRuleProcessing`, trace events`Get-TransportRule`, `Get-MessageTraceDetailV2`, Extended Message Trace
Compliance search returns unexpected resultsSession, permissions, location, query, indexing, time zone, scope`Connect-IPPSSession`, `Get-ComplianceSearch`, audit cmdlets where relevant
Hybrid migration failsEndpoint, authentication, MRSProxy, mailbox/archive state, skipped items, version, certificate, network`Test-MigrationServerAvailability`, `Get-MigrationUserStatistics`, `Get-MoveRequestStatistics`

A useful troubleshooting sequence is:

Confirm scope → choose management plane → collect evidence → test the hypothesis → isolate the fault domain → remediate → verify → preserve evidence

Image detail
100%
Exchange troubleshooting evidence flow showing symptom identification, scope confirmation, evidence collection, hypothesis formation, fault isolation, remediation, resolution verification, and evidence preservation.

Reusable evidence folder

$CaseId = 'INC000000'
$RunId  = Get-Date -Format 'yyyyMMdd-HHmmss'
$Path   = ".\$CaseId-$RunId"

New-Item -ItemType Directory -Path $Path | Out-Null

Start-Transcript -Path "$Path\Transcript.txt"

Get-TransportRule |
    Export-Clixml "$Path\TransportRules.xml"

Get-AcceptedDomain |
    Export-Clixml "$Path\AcceptedDomains.xml"

Get-RemoteDomain |
    Export-Clixml "$Path\RemoteDomains.xml"

Stop-Transcript

15. A production runbook pattern

For repeatable administration, make the operational stages explicit.

param(
    [Parameter(Mandatory)]
    [string]$ChangeId,

    [Parameter(Mandatory)]
    [string]$InputCsv,

    [switch]$WhatIf
)

$RunId = Get-Date -Format 'yyyyMMdd-HHmmss'
$Root  = ".\$ChangeId-$RunId"

New-Item -ItemType Directory -Path $Root -Force | Out-Null

Start-Transcript -Path "$Root\Transcript.txt"

try {
    $Rows = Import-Csv $InputCsv
    $Rows | Export-Csv "$Root\InputSnapshot.csv" -NoTypeInformation

    # 1. Validate input
    # 2. Discover and export before-state
    # 3. Apply scoped change with ShouldProcess or -WhatIf
    # 4. Verify and export after-state
    # 5. Emit structured result objects
}
catch {
    $_ | Out-File "$Root\FatalError.txt"
    throw
}
finally {
    Stop-Transcript
}

16. The production checklist

Use the following as the final muscle memory for Exchange PowerShell changes.

Production Exchange PowerShell checklist
#CheckpointWhat good looks like
1Choose management planeEXO, Exchange Server, Purview, or a hybrid boundary is explicitly identified.
2Verify RBACThe operator has the cmdlets and parameters required.
3Discover current stateObject type, identity, source of authority, and current values are confirmed.
4Export baselineBefore-state is preserved with a run ID or change ID.
5Scope narrowlyTargets are filtered and counted before a write.
6Preview or pilotUse `-WhatIf` where supported or test against a low-risk pilot object.
7Execute defensivelyUse `ErrorAction Stop`, structured handling, logging, and batching where appropriate.
8Verify service behaviorUse matching Get/Test/trace/statistics commands rather than relying on command completion.
9Preserve evidenceTranscript, output, errors, and verification results are retained.
10Prepare rollbackOriginal values and an explicit rollback path are available.

Conclusion

Practical Exchange administration is less about memorizing commands and more about learning to ask the right questions before you run them.

Where is this object actually managed? What is its current state? Who will be affected? What evidence will show that the change worked? What will let you recover if it did not?

Once those questions become part of your normal workflow, PowerShell becomes much more than a collection of Exchange commands. It becomes a dependable way to investigate, change, verify, and support the service.

References