Forum Discussion
"Exchange Delegation Federation certificate is expired", is it needed?
On our Exchange OnPrem-server (2019) we have a Self Signed Exchange Delegation Federation with certificate but it expired recently.
We run Exchange OnPrem in Hybrid with Exchange Online, there are currently no more mailboxes present on our OnPrem ExchangeServer.
I have found an instruction on how to renew it. But it also states that if it is already expired, the current federation must be removed and a new one must be created. However, those instructions apply to Exchange 2013 and the commands are not available in 2019
https://learn.microsoft.com/en-us/exchange/renew-the-federation-certificate-exchange-2013-help
Another forum-post somewhere states that for Exchange 2019 you need to run the Hybrid Configuration Wizard. We have run that multiple times already.
For example, after upgrading our previouse Exchange 2016 to Exchange 2019 and after migrating the Exchange 2019 to a new server.
If we look at the Exchange Delegation Federation via powershell, we only see our older domains present in that federation. Via the Hybrid Configuration Wizard, our current domains are present.
This raises a question to us, do we need the Exchange Delegation Federation? Can we safely remove this from our exchange server ( Remove-FederatedDomain, (multiple) & Remove-FederationTrust) via the commands , run the Hybrid Configuration Wizard once more. Will this be sufficient?
1 Reply
- BooAGhostIron Contributor
It can be ignored in the internal environment, but for hybrid deployments, the federated certificate needs to be updated immediately.