A portable, dependency-free PowerShell terminal UI for managing Source of Authority (SOA) in Exchange Online / Microsoft Entra hybrid environments.
Switch Exchange attribute management between on-premises and cloud for mailboxes, convert the object-level SOA of mail-enabled groups and contacts, and control the tenant-wide default for new dir-synced mailboxes. Built for the road toward decommissioning the Last Exchange Server.
Exchange SOA Manager v1.0.0 ● EXO admin@contoso.com ● Graph admin@contoso.com
1 Mailboxes 2 Groups 3 Contacts 4 Organization 5 Log
340 of 340 mailboxes 3 selected filter:All sort:Name↑
sel Name Email Type SOA
[■] Anna Andersen anna.andersen@contoso.com UserMailbox ● Cloud
[ ] Anna Clausen anna.clausen@contoso.com UserMailbox ● On-prem
[■] Astrid Dahl astrid.dahl@contoso.com UserMailbox ● Cloud
...
Spc select A all N none / find F filter S sort C to cloud O to on-prem E export
Try it in 10 seconds, no tenant required:
.\SOA-Manager.ps1 -Demo
Full usage guide, keyboard shortcuts, prerequisites, and troubleshooting live in the GitHub Wiki.
| Page | What it covers |
|---|---|
| Usage | Running the tool, status badges, files it writes |
| Keyboard shortcuts | Every key and confirmation prompt |
| Prerequisites | Modules, roles, Graph scopes, sync client versions |
| Mailbox SOA | Per-mailbox conversion and rollback |
| Group and Contact SOA | Mail-enabled groups and contacts, forward audit |
| Tenant-wide default | The organization switch and its warning |
| Writeback to AD | Cloud Sync setup for writing changes back on-premises |
| Troubleshooting | Common errors and fixes |
Download the zip from Releases, extract, then double-click Launch-SOA-Manager.bat. Or run it yourself:
# Explore the UI with fake data (no tenant access, nothing installed)
.\SOA-Manager.ps1 -Demo
# The real thing
.\SOA-Manager.ps1| Parameter | Effect |
|---|---|
-Demo |
Generated sample data, no connections, no changes |
-Ascii |
Plain ASCII glyphs for legacy consoles |
-NoDisconnect |
Keep the EXO and Graph sessions alive on exit |
PowerShell 5.1 or 7+. The tool installs ExchangeOnlineManagement and Microsoft.Graph.Authentication to the current user on first use. Roles, Graph scopes, and minimum sync client versions are listed in Prerequisites.
Bug reports and PRs are welcome. See CONTRIBUTING.md for the ground rules and a scripted tmux recipe for testing the TUI. Release notes live in CHANGELOG.md.
No telemetry, no credential handling (auth is delegated to MSAL via the official modules). Logs, backups, and exports contain directory data; treat them accordingly. See SECURITY.md for the full policy.
Inspired by codeandersen's Exchange-SOA-Conversion-tool (WinForms, user mailboxes only). This project is an independent rewrite that adds groups, contacts, the tenant-wide default switch, safety checks, and a portable terminal UI.
MIT. See LICENSE.
Provided as-is, without warranty. Test in a non-production tenant first.