Share via

Error Message: Admin Center

Yazmin Reyes 0 Reputation points
2026-04-08T17:28:45.88+00:00

Hello,

I need to figure out why I am having issues with adding an alias to existing Microsoft accounts.

My co-worker, [Moderator note: personal info removed] and I cannot do this on our end, and it is imperative that we can create these.

This is the error message that I am receiving:

"An exception of type Microsoft.Online.BOX.Util.Exceptions.InternalException (EXOBadRequest) was thrown."

We both have global admin access rights. Please help.

Microsoft 365 and Office | Subscription, account, billing | For business | Other
0 comments No comments

2 answers

Sort by: Most helpful
  1. Alexis-NG 14,895 Reputation points Microsoft External Staff Moderator
    2026-04-08T18:09:31.11+00:00

    Hi @Yazmin Reyes,

    Good day, and thank you for detailing your issue.

    When Exchange-related actions (such as adding aliases, creating recipients, or modifying mail attributes) fail even for Global Administrators it is often caused by Exchange RBAC (Role-Based Access Control) roles being modified or restricted.

    It's important to note that Global Administrator doesn't have Full Exchange permissions if Exchange management roles were edited or stripped.

    You have to confirm if whether core Exchange permissions (such as Organization Management) were reduced to view-only access.

    Please go to Exchange Admin Center

    1. Go to https://admin.exchange.microsoft.com
    2. Select Roles > Admin roles
    3. Select Organization Management
    4. Open the Assigned -panel and Permissions panel

    User's image

    User's image

    A healthy Organization Management role should include many Exchange roles, not “View-only” or minimal permissions.

    If you see only read‑level permissions (similar to View‑Only Organization Management), then the role has been manually stripped of its functional capabilities.

    For managing aliases and mail-enabled objects, confirm these Exchange RBAC roles are present:

    • Mail Recipient Creation
    • Mail Recipients
    • Recipient Policies
    • E‑Mail Address Policies
    • Organization Configuration
    • Organization Transport Settings

    These roles are required for:

    • Adding or modifying email aliases
    • Updating SMTP addresses
    • Managing mail-enabled users, groups, and shared mailboxes

    If Mail Recipient Creation or Mail Recipients is missing, alias operations will fail with backend errors such as EXOBadRequest.

    Missing recipient creation roles can block admin portal actions even when Global Admin is assigned.

    I hope this provides enough clarity and helps you stay inform with your current situation.

    In the meantime, if you see my replies bring helpful information, please kindly accept it as an answer and vote it up by your original account, which raised this question. Once marked, it will automatically pin to top. As other users will also search information in this community, your valuable vote up will definitely also help other users who have similar queries easily to find the correct channel and useful information more quickly.   

     

    Thank you for your patience and your understanding. If you have any questions or need further assistance, please feel free to share them in the comments on this post so I can continue to support you.   


    Note: Follow the steps in this documentation to enable email notifications if you want to receive email notifications related to this topic.

    0 comments No comments

  2. Q&A Assist
    2026-04-08T17:28:57.9833333+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    Use the Microsoft 365 admin center alias flow and then check for the known blocking conditions.

    1. Verify you are using the correct place to add aliases
      • Go to Users > Active users.
      • Select the user.
      • Under Aliases, select Manage username and email.
      • Add the alias in Username, choose the correct domain from the drop-down, then select Add, and finally Save changes.
      • It can take up to 24 hours for aliases to fully update.
    2. Check if the tenant/domain setup is still in progress
      • If the tenant or a custom domain was added recently, setup can take up to 4 hours.
      • During this time, alias operations can fail. Wait a few hours and try again.
    3. Check for directory synchronization (hybrid) constraints
      • If the user is synchronized from on-premises Active Directory, aliases must be added on-premises, not in the cloud.
      • In that case:
        • Open Active Directory Users and Computers (ADUC).
        • Enable View > Advanced Features.
        • Open the user’s Properties > Attribute Editor > proxyAddresses.
        • Add the alias in the form smtp:******@yourdomain.com (lowercase smtp: prefix).
        • Wait for synchronization to Microsoft Entra ID, then test again in Microsoft 365.
    4. Check for alias uniqueness conflicts
      • If the alias is already used as another user’s alias, you must remove it from that user first:
        • In the admin center, locate the user that currently owns the alias.
        • Select Manage email aliases.
        • Remove the conflicting alias and Save changes.
      • After removal, add the alias to the intended user again.
    5. If the error persists for multiple admins and users
      • Because this is an internal EXO (Exchange Online) error and both global admins are affected, it likely requires backend investigation.
      • Open a support ticket from the Microsoft 365 admin center so Support can run a full sync and check for service-side issues.

    References:

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.