Hi The_Exchange_Team Nino_Bilic . Thanks for all this information.
We have Exchange 2016 CU23 + Modern Hybrid in the company, no issues with the Healtchcheck script, except Extended Protection is disabled.
We can't enable EP for servers because of 2 issues:
1. Modern Hybrid
2. Zoom client uses EWS for calendar integration. When EP is enabled for EWS FrontEnd - integration breaks.
I opened a case in Zoom support about issue #2.
But what can we do with issue #1?
I tried to move from Modern Hybrid to Classic Hybrid. But there is no documentation about this type of migration, only from Classic to Modern.
After the removal of all agents and switching to Classic Hybrid in HCW we have broken free\busy from cloud to on-premise.
In get-organizationRelationship | select TargetsharingEpr it is filled with https://GUID.resource.mailboxmigration.his.msappproxy.net/EWS/Exchange.asmx like in Modern Hybrid.
I checked all parameters from https://techcommunity.microsoft.com/t5/exchange-team-blog/demystifying-hybrid-free-busy-what-are-the-moving-parts/ba-p/607704 , but still, no luck.
Questions:
1. Is it supported to switch from Modern to Classic Hybrid? Any documentation about it?
2. Will it be fixed by Microsoft, work with Modern Hybrid and EP, or it is impossible by design and Modern Hybrid is equal to a security breach with CVSS 9.8 from now?