Forum Discussion

PatrickWagemakers's avatar
PatrickWagemakers
Copper Contributor
Apr 07, 2025

"Exchange Delegation Federation certificate is expired", is it needed?

On our Exchange OnPrem-server (2019) we have a Self Signed Exchange Delegation Federation with certificate but it expired recently.

We run Exchange OnPrem in Hybrid with Exchange Online, there are currently no more mailboxes present on our OnPrem ExchangeServer.

I have found an instruction on how to renew it. But it also states that if it is already expired, the current federation must be removed and a new one must be created. However, those instructions apply to Exchange 2013 and the commands are not available in 2019

https://learn.microsoft.com/en-us/exchange/renew-the-federation-certificate-exchange-2013-help

Another forum-post somewhere states that for Exchange 2019 you need to run the Hybrid Configuration Wizard. We have run that multiple times already.

For example, after upgrading our previouse Exchange 2016 to Exchange 2019 and after migrating the Exchange 2019 to a new server.

If we look at the Exchange Delegation Federation via powershell, we only see our older domains present in that federation. Via the Hybrid Configuration Wizard, our current domains are present.

This raises a question to us, do we need the Exchange Delegation Federation? Can we safely remove this from our exchange server ( Remove-FederatedDomain, (multiple) & Remove-FederationTrust) via the commands , run the Hybrid Configuration Wizard once more. Will this be sufficient?

1 Reply

  • BooAGhost's avatar
    BooAGhost
    Iron Contributor

    It can be ignored in the internal environment, but for hybrid deployments, the federated certificate needs to be updated immediately.