
Important Notice About Certificate Expiration for Exchange 2013 Hybrid Customers
Microsoft is making a change on April 15th that will possibly break mail flow from your on-premises environment to the Office 365 platform.
This will have no impact on you if you are not running Exchange in hybrid mode. Please see the full details below on who will be affected.
Our team is standing by to assist you with this change if needed to ensure mail flow is not interrupted.
If you’re running Exchange 2013 and you’ve configured a hybrid deployment with Office 365, this post contains important information that might impact you. Please evaluate this information and take any necessary action before April 15, 2016.
On April 15, 2016, the Office 365 TLS certificate will be renewed. This certificate is used by Office 365 to provide TLS encryption between Office 365 and external SMTP servers. The new certificate, which will help improve the security of mail sent to and from Office 365, will be issued by a new Certificate Authority and it will have a new Issuer and Subject.
This change has the potential to stop hybrid mailflow between Office 365 and your on-premises Exchange servers if one of the following conditions applies to you:
- Your on-premises Exchange servers are running Exchange 2013 Cumulative Update 8 (CU8) or lower.
- You’ve upgraded the Exchange 2013 servers that handle hybrid mailflow to Exchange 2013 CU9 or higher. However, since upgrading to CU9, you HAVE NOT re-run the Hybrid Configuration wizard (either from the Exchange Admin Center or via the direct download link).
If one of the previous conditions applies to your organization, hybrid mailflow between Office 365 and your organization will stop working after April 15, 2016 unless you complete the steps below.
Note: This only affects hybrid mailflow. Regular mailflow and TLS encryption is NOT affected.
How to keep hybrid mail flowing (MUST be completed before 4/15/2016)
Let the new Hybrid Configuration wizard do it for you
You can use the latest Hybrid Configuration wizard (HCW) to configure your Exchange 2013 servers to work with the new TLS certificate. Just follow these steps:
- If the Exchange 2013 servers handling hybrid mailflow are running Exchange 2013 CU8 or lower, follow the instructions in Updates for Exchange 2013 to install the latest cumulative update on at least one server.
- After you install the latest cumulative update, download the new HCW application and run the wizard following the instructions here.
Note: For information on which releases of Exchange are supported with Office 365, see Hybrid deployment prerequisites.
Manual update
If you can’t upgrade Exchange 2013 to latest cumulative update right now (although we would like to remind you of our support policy), you can manually configure your servers to work with the new TLS certificate. On each Exchange 2013 server that’s used for hybrid mailflow, open the Exchange Management Shell, and run the following commands:
$rc=Get-ReceiveConnector |where {$_.TlsDomainCapabilities -like "**"}
Set-ReceiveConnector -Identity $rc.Identity -TlsDomainCapabilities "mail.protection.outlook.com:AcceptCloudServicesMail
About the author
Matt Scherocman brings more than 15 years of experience in the information technology industry to Interlink. His experience includes both the system integrator and manufacturer sides of the business. During his time at the Microsoft Corporation he was responsible for all the Large Account Reseller (LAR) relationships in the four-state Heartland Area of Michigan, Ohio, Kentucky, and Tennessee. Prior to Microsoft, Scherocman led a Cincinnati -based IT consulting company to grow 5000% and become a Microsoft Worldwide Partner of the Year. He is actively involved in the strategic vision and operation decisions of the company including finance, selling strategy and marketing. Matt holds a Bachelor of Science in Business degree from Miami University and is a Certified Expert in Microsoft licensing including speaking engagements at both Microsoft's Worldwide Partner Conference and Channel Partner Summit. He is a frequent contributor to leading industry publications.
Related Posts
Welcome to the Interlink Cloud Blog
By subscribing to the blog, you will be notified whenever a new blog post is created on the site.
All content provided on this blog is for informational purposes only. The owner of this blog makes no representations or warranties regarding the information from our partners or other external sources.
Blog Categories
Blog Archive
- April 2023 (2)
- March 2023 (7)
- February 2023 (2)
- January 2023 (4)
- December 2022 (2)
- November 2022 (3)
- October 2022 (1)
- September 2022 (3)
- August 2022 (5)
- July 2022 (2)
- June 2022 (8)
- May 2022 (2)
- April 2022 (2)
- January 2022 (4)
- November 2021 (2)
- October 2021 (5)
- September 2021 (1)
- August 2021 (4)
- July 2021 (5)
- June 2021 (2)
