Exchange Hybrid Issues

%3CLINGO-SUB%20id%3D%22lingo-sub-1842148%22%20slang%3D%22en-US%22%3EExchange%20Hybrid%20Issues%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1842148%22%20slang%3D%22en-US%22%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3EHello%2C%3C%2FP%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3E%26nbsp%3B%3C%2FP%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3EI'm%20hoping%20that%20you'd%20be%20able%20to%20help%20me%20on%20an%20issue%20that%20I've%20found%20myself%20working%20on.%26nbsp%3B%3C%2FP%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3E%26nbsp%3B%3C%2FP%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3EI'm%20working%20on%20an%20Exchange%20Hybrid%20(Exchange%202010%20with%20Microsoft%20365).%20The%20Hybrid%20has%20been%20running%20fine%20since%20setup.%20However%20over%20the%20past%20few%20days%20we've%20seen%20a%20few%20issues%20which%20are%20a%20little%20confusing.%26nbsp%3B%3C%2FP%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3E%26nbsp%3B%3C%2FP%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3EI%20hadn't%20setup%20the%20environment%20or%20sync%20so%20its%20hard%20trying%20to%20piece%20together%20how%20everything%20should%20be%20setup.%26nbsp%3B%3C%2FP%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3E%26nbsp%3B%3C%2FP%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3EReported%20issues%3A%3C%2FP%3E%3CUL%20class%3D%22_33MEMislY0GAlB78wL1_CR%22%3E%3CLI%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3EMacOS%20users%20are%20unable%20to%20sign%20into%20or%20configure%20mailbox%20on%20Outlook%20-%26nbsp%3B%20Does%20not%20work%20internally%20or%20externally.%20Windows%20is%20fine%3C%2FP%3E%3C%2FLI%3E%3CLI%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3EUsers%20are%20unable%20to%20set%20OOO%2FAutoReply%20status%20-%20Works%20via%20OWA%20or%20Admin%20centre%26nbsp%3B%3C%2FP%3E%3C%2FLI%3E%3CLI%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3EUsers%20are%20unable%20to%20view%20calendars%20of%20other%20employees%20-%20(Works%20via%20OWA%20and%20in%20Desktop%20app%2C%20if%20i%20raise%20permissions%26nbsp%3B%20from%20limited%20details%20to%20reviewer)%3C%2FP%3E%3C%2FLI%3E%3C%2FUL%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3EI%20believe%20that%20all%20issues%20are%20related%20to%20the%20same%20issue%2C%20which%20I%20feel%20is%20around%20the%20%22AutoDiscover%22.%26nbsp%3B%3C%2FP%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3EFrom%20the%20tests%20I've%20ran%2C%20the%20AutoDiscovery%20CNAME%20is%20missing%20for%20M365.%20but%20is%20being%20pointed%20to%20the%20WAN%20IP%20for%20the%20site.%26nbsp%3B%3C%2FP%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3E%26nbsp%3B%3C%2FP%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3EExchange%20on-prem%20shows%3A%26nbsp%3B%3C%2FP%3E%3CDIV%20class%3D%22_2-UiOdhyj4wHBv7Rc2FeDr%20%22%3E%3CDIV%20class%3D%22_3Oa0THmZ3f5iZXAQ0hBJ0k%20_2LjgQiHLCZ9LDbCQx5KaOi%22%3E%3CDIV%20class%3D%22mceNonEditable%20lia-copypaste-placeholder%22%3E%26nbsp%3B%3C%2FDIV%3E%3CDIV%20class%3D%22mceNonEditable%20lia-copypaste-placeholder%22%3E%26nbsp%3B%3C%2FDIV%3E%3CDIV%20class%3D%22mceNonEditable%20lia-copypaste-placeholder%22%3E%26nbsp%3B%3C%2FDIV%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%222020-11-01_12-05-23.png%22%20style%3D%22width%3A%20774px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F230730i4C281915B0B0340B%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%222020-11-01_12-05-23.png%22%20alt%3D%222020-11-01_12-05-23.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3E(mail.%3CDOMAIN%3E%2F)%3C%2FDOMAIN%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FDIV%3E%3C%2FDIV%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3EI've%20been%20trying%20to%20find%20some%20setup%20guides%20on%20the%20best%20practice%20of%20how%20hybrid%20Autodisvoer%20should%20be%20set.%26nbsp%3B%3C%2FP%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3E%26nbsp%3B%3C%2FP%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3EThe%20exchange%20server%20was%20not%20running%20TLS%201.2%2C%20I've%20now%20fixed%20this%20by%20running%20Nartac%20ISSCrypto%2C%20which%20has%20resolved%20that%20issue%2C%20but%20the%20main%20issues%20reported%20are%20still%20outstanding.%26nbsp%3B%3CBR%20%2F%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%222020-11-01_01-54-42.png%22%20style%3D%22width%3A%20646px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F230731i654412426AAAD535%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%222020-11-01_01-54-42.png%22%20alt%3D%222020-11-01_01-54-42.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3E%26nbsp%3B%3C%2FP%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3EAny%20ideas%3F%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1842148%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3E2010%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EExchange%20Server%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Ehybrid%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1842320%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20Hybrid%20Issues%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1842320%22%20slang%3D%22en-US%22%3EHi%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F128498%22%20target%3D%22_blank%22%3E%40Enzo%20Faranda%3C%2FA%3E%2C%3CBR%20%2F%3E%3CBR%20%2F%3ESounds%20like%20it%20could%20be%20a%20cert%20issue.%20You%20mentioned%20the%20TLS%201.2%20thing%2C%20maybe%20that%20fix%20was%20the%20catalyst%20for%20this%20new%20issue%3F%3CBR%20%2F%3E%3CBR%20%2F%3EI%20would%20browse%20to%20the%20autodiscover%20URL%20you%20found%20from%20Get-ClientAccessServer%20and%20login%20using%20valid%20user%2Fpassword.%20It%20should%20let%20you%20in%20and%20show%20you%20some%20XML.%20The%20browser%20should%20see%20the%20certificate%20as%20valid.%20If%20both%20of%20those%20checks%20pass%2C%20it%20is%20likely%20something%20else%20like%20DNS%20or%20maybe%20load%20balancer.%3CBR%20%2F%3E%3CBR%20%2F%3EIf%20you%20updated%2Freplaced%20the%20certificate%20that%20Exchange%20had%20been%20using%20(for%20your%20TLS1.2%20fix)%2C%20it%20might%20not%20have%20been%20gracefully%20enabled%20for%20the%20Exchange%20services%20(e.g.%20IIS).%3CBR%20%2F%3E%3CBR%20%2F%3ELet%20us%20know.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1842553%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20Hybrid%20Issues%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1842553%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F64125%22%20target%3D%22_blank%22%3E%40Jeremy%20Bradshaw%3C%2FA%3EThanks%20Jeremy%2C%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20had%20only%20looked%20into%20the%20TLS%201.2%20upgrade%20as%20a%20potential%20fix%2C%20the%20issues%20I%20had%20mentioned%20were%20present%20before%20the%20TLS%20upgrade.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20did%20also%20check%20the%20cert%20and%20this%20is%20still%20valid%2C%20nothing%20cert%20wise%20has%20changed%20since%20the%20issues%20had%20been%20reported.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

Hello,

 

I'm hoping that you'd be able to help me on an issue that I've found myself working on. 

 

I'm working on an Exchange Hybrid (Exchange 2010 with Microsoft 365). The Hybrid has been running fine since setup. However over the past few days we've seen a few issues which are a little confusing. 

 

I hadn't setup the environment or sync so its hard trying to piece together how everything should be setup. 

 

Reported issues:

  • MacOS users are unable to sign into or configure mailbox on Outlook -  Does not work internally or externally. Windows is fine

  • Users are unable to set OOO/AutoReply status - Works via OWA or Admin centre 

  • Users are unable to view calendars of other employees - (Works via OWA and in Desktop app, if i raise permissions  from limited details to reviewer)

I believe that all issues are related to the same issue, which I feel is around the "AutoDiscover". 

From the tests I've ran, the AutoDiscovery CNAME is missing for M365. but is being pointed to the WAN IP for the site. 

 

Exchange on-prem shows: 

 
 
 

2020-11-01_12-05-23.png

(mail.<Domain>/)

 

I've been trying to find some setup guides on the best practice of how hybrid Autodisvoer should be set. 

 

The exchange server was not running TLS 1.2, I've now fixed this by running Nartac ISSCrypto, which has resolved that issue, but the main issues reported are still outstanding. 


2020-11-01_01-54-42.png

 

Any ideas? 

3 Replies
Hi @Enzo Faranda,

Sounds like it could be a cert issue. You mentioned the TLS 1.2 thing, maybe that fix was the catalyst for this new issue?

I would browse to the autodiscover URL you found from Get-ClientAccessServer and login using valid user/password. It should let you in and show you some XML. The browser should see the certificate as valid. If both of those checks pass, it is likely something else like DNS or maybe load balancer.

If you updated/replaced the certificate that Exchange had been using (for your TLS1.2 fix), it might not have been gracefully enabled for the Exchange services (e.g. IIS).

Let us know.

@Jeremy BradshawThanks Jeremy, 

 

I had only looked into the TLS 1.2 upgrade as a potential fix, the issues I had mentioned were present before the TLS upgrade. 

 

I did also check the cert and this is still valid, nothing cert wise has changed since the issues had been reported. 

 

 

@Enzo Farandaonly a guess -  check the targetsharingepr in Exchange Online.  We had to set that to the hybrid namespace every time we ran the hybrid wizard as it would sometimes clear it, else free busy would not work.