Hello The_Exchange_Team
Based on the action plan (26) in the pdf https://techcommunity.microsoft.com/t5/exchange-team-blog/demystifying-hybrid-free-busy-finding-errors-and-troubleshooting/ba-p/607727/page/2?attachment-id=63146
The exchange on-premises certificate for authorization should be uploaded to the Azure AD service principal credential as documented in the article, using steps 3&4:
https://learn.microsoft.com/en-us/exchange/configure-oauth-authentication-between-exchange-and-exchange-online-organizations-exchange-2013-help#step-3-export-the-on-premises-authorization-certificate
Although, there was no specification of whether only Exchange server 2013 is supported for the steps as indicated in the article but when the step 4 was followed after exporting with step 3, no certificate was uploaded for the Azure AD service principal, rather the existing service principal certificates were deleted. Even after uploading again, no certificate was uploaded for the Azure AD service principal using that method.
Please review steps 3&4 again for more recent versions of Exchange server 2016/2019.
Thank you.