<Tenant>.onmicrosoft.com added to on-premises Accepted Domains

%3CLINGO-SUB%20id%3D%22lingo-sub-1596628%22%20slang%3D%22en-US%22%3E%3CTENANT%3E.onmicrosoft.com%20added%20to%20on-premises%20Accepted%20Domains%3C%2FTENANT%3E%3CLINGO-BODY%20id%3D%22lingo-body-1596628%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20all%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI'm%20working%20with%20a%20customer%20who%20has%20had%20their%20Hybrid%20Configuration%20in%20place%20for%20years%20and%20they%20do%20not%20remember%20is%20this%20happened%20automatically%20via%20the%20HCW%2C%20or%20if%20they%20manually%20added%20it.%26nbsp%3B%20Anyway%2C%20they%20have%20both%20of%20the%20'onmicrosoft'%20domains%20added%20as%20Accepted%20Domains%2C%20and%20to%20the%20Email%20Address%20Policies.%26nbsp%3B%20I%20mean%20these%20ones%3A%3C%2FP%3E%3CUL%3E%3CLI%3E%3CSTRONG%3E%3CTENANT%3E.%3CEM%3Email%3C%2FEM%3E.onmicrosoft.com%3C%2FTENANT%3E%3C%2FSTRONG%3E%20(the%20usual%20one%2C%20and%20what%20I%20see%20in%20every%20other%20environment%20I%20can%20remember).%3C%2FLI%3E%3CLI%3E%3CSTRONG%3E%3CTENANT%3E.onmicrosoft.com%3C%2FTENANT%3E%3C%2FSTRONG%3E%20(the%20one%20I%20thought%20was%20intended%20for%20dedicated%20use%20in%20EXO%20only).%3C%2FLI%3E%3C%2FUL%3E%3CP%3EI%20am%20not%20sure%20if%20the%20HCW%20used%20to%20add%20both%20domains%20to%20the%20on-premises%20env.%20but%20I%20do%20know%20that%20the%20HCW%20doesn't%20do%20that%20today%2C%20and%20hasn't%20since%20I%20can%20remember%2C%20but%20I%20may%20have%20missed%20it%20in%20the%20past.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20noted%20it%20is%20also%20set%20to%20Authoritative%2C%20so%20I%20see%20it%20as%20a%20potential%20mail%20flow%20issue%20down%20the%20road%2C%20where%20the%20same%20address%20will%20exist%20in%20both%20locations%2C%20but%20if%20a%20message%20to%20said%20address%20is%20received%20on-premises%2C%20that%20message%20will%20never%20properly%20be%20sent%20up%20to%20EXO.%26nbsp%3B%20This%20is%20why%20my%20gust%20says%20to%20remove%20this%20domain%20from%20their%20env.%2C%20but%20then%20I%20wonder%20-%20why%20is%20it%20there%2C%20and%20so%20here%20I%20am.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHas%20anyone%20seen%20this%20before%3F%26nbsp%3B%20Is%20anyone%20more%20sure%20than%20I%20that%20it%20must%20have%20been%20added%20manually%2C%20and%20do%20you%20think%20it%20would%20be%20best%20for%20me%20to%20get%20rid%20of%20it%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20main%20risk%20in%20removing%20it%20that%20I%20have%20thought%20of%20is%20that%20somebody%20could%20have%20setup%20depending%20other%20stuff%20that%20uses%20one%20of%20the%26nbsp%3B%40%3CTENANT%3E.onmicrosoft.com%20email%20addresses%2C%20and%20the%20depending%20other%20stuff%20will%20have%20an%20issue%20if%20these%20email%20addresses%20go%20away.%26nbsp%3B%20I%20can%20do%20Message%20Tracking%20logs%20to%20determine%20that%20(hopefully%3A)%20that%20is).%3C%2FTENANT%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20in%20advance.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1596628%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EExchange%20Online%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EExchange%20Server%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Ehybrid%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3C%2FLINGO-SUB%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1597140%22%20slang%3D%22en-US%22%3ERe%3A%20%3CTENANT%3E.onmicrosoft.com%20added%20to%20on-premises%20Accepted%20Domains%3C%2FTENANT%3E%3CLINGO-BODY%20id%3D%22lingo-body-1597140%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F64125%22%20target%3D%22_blank%22%3E%40Jeremy%20Bradshaw%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ENot%20many%20of%20my%20clients%20are%20using%20Exchange%20Hybrid%2C%20but%20there%20is%20one%20at%20the%20moment.%20We're%20looking%20to%20move%20them%20into%20365%20completely%2C%20but%20covid%20put%20a%20spanner%20in%20the%20works%20so%20that's%20been%20delayed.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20server%20is%20Exchange%202010%20server%2C%20and%20I%20can%20see%20both%20the%26nbsp%3B%3CEM%3Etenant.onmicrosoft.com%26nbsp%3B%3C%2FEM%3Eand%26nbsp%3B%3CEM%3Etenant.mail.onmicrosoft.com%3C%2FEM%3E%20set%20up%20as%20both%20a%20accepted%20and%20a%20remote%20domain%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAccepted%20domains%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22hybrid1.png%22%20style%3D%22width%3A%20525px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F213159i7CCFF63FBD2D15F8%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20title%3D%22hybrid1.png%22%20alt%3D%22hybrid1.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAnd%20for%20remote%20domains...%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22HidMov_0-1597779784484.png%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F213162i4D2586955B0A3DA7%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20title%3D%22HidMov_0-1597779784484.png%22%20alt%3D%22HidMov_0-1597779784484.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EGoing%20to%20be%20honest%20with%20you%20-%20I%20can't%20recall%20if%20I%20added%20in%20the%26nbsp%3B%3CEM%3Etenant.onmicrosoft.com%3C%2FEM%3E%20one%20manually%20or%20not%20as%20it%20was%20last%20year.%20That%20said%2C%20I%20wouldn't%20have%20added%20it%20in%20unless%20I%20had%20a%20good%20reason%20to%20do%20so.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHope%20this%20helps%20in%20some%20way%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMark%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3C%2FLINGO-SUB%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1597713%22%20slang%3D%22en-US%22%3ERe%3A%20%3CTENANT%3E.onmicrosoft.com%20added%20to%20on-premises%20Accepted%20Domains%3C%2FTENANT%3E%3CLINGO-BODY%20id%3D%22lingo-body-1597713%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F383653%22%20target%3D%22_blank%22%3E%40HidMov%3C%2FA%3E%26nbsp%3B%20Thanks%20very%20much%20for%20the%20info.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3C%2FLINGO-SUB%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1598037%22%20slang%3D%22en-US%22%3ERe%3A%20%3CTENANT%3E.onmicrosoft.com%20added%20to%20on-premises%20Accepted%20Domains%3C%2FTENANT%3E%3CLINGO-BODY%20id%3D%22lingo-body-1598037%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F64125%22%20target%3D%22_blank%22%3E%40Jeremy%20Bradshaw%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHi%2C%20I%20can%20also%20confirm%20that%20in%20older%20hybrid%20deployments%20using%20Exchange%202010%20I%20have%20seen%20both%20the%20%3CSTRONG%3E.onmicrosoft.com%3C%2FSTRONG%3E%20and%20%3CSTRONG%3Email.onmicrosoft.com%3C%2FSTRONG%3E%20domains%20added%20as%20accepted%20domains%20on%20premises.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOn%20more%20recent%20hybrids%20using%20Exchange%202016%2C%20only%20the%26nbsp%3B%3CSTRONG%3Email.onmicrosoft.com%26nbsp%3B%3C%2FSTRONG%3Edomain%20is%20present.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3C%2FLINGO-SUB%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1598928%22%20slang%3D%22en-US%22%3ERe%3A%20%3CTENANT%3E.onmicrosoft.com%20added%20to%20on-premises%20Accepted%20Domains%3C%2FTENANT%3E%3CLINGO-BODY%20id%3D%22lingo-body-1598928%22%20slang%3D%22en-US%22%3EThanks%20for%20the%20info%20as%20well.%20Based%20on%20this%2C%20and%20the%20earlier%20response%2C%20as%20well%20as%20the%20environment%20I%20noticed%20it%20in%2C%20seems%20like%20it%20was%20the%20way%20previously%2C%20either%20with%20Exchange%202010%2C%20or%20just%20earlier%20HCW%20versions.%3CBR%20%2F%3E%3CBR%20%2F%3EIn%20retrospect%2C%20it%20seems%20I've%20been%20on%20quite%20a%20stretch%20of%20Exchange%202013%20and%20newer%20projects%2C%20which%20I%20guess%20is%20a%20good%20thing%2C%20but%20clearly%20I've%20lost%20touch%20with%202010%2C%20at%20least%20a%20little%20bit.%3C%2FLINGO-BODY%3E%3C%2FLINGO-SUB%3E
Highlighted
Contributor

Hello all,

 

I'm working with a customer who has had their Hybrid Configuration in place for years and they do not remember is this happened automatically via the HCW, or if they manually added it.  Anyway, they have both of the 'onmicrosoft' domains added as Accepted Domains, and to the Email Address Policies.  I mean these ones:

  • <Tenant>.mail.onmicrosoft.com (the usual one, and what I see in every other environment I can remember).
  • <Tenant>.onmicrosoft.com (the one I thought was intended for dedicated use in EXO only).

I am not sure if the HCW used to add both domains to the on-premises env. but I do know that the HCW doesn't do that today, and hasn't since I can remember, but I may have missed it in the past.

 

I noted it is also set to Authoritative, so I see it as a potential mail flow issue down the road, where the same address will exist in both locations, but if a message to said address is received on-premises, that message will never properly be sent up to EXO.  This is why my gust says to remove this domain from their env., but then I wonder - why is it there, and so here I am.

 

Has anyone seen this before?  Is anyone more sure than I that it must have been added manually, and do you think it would be best for me to get rid of it?

 

The main risk in removing it that I have thought of is that somebody could have setup depending other stuff that uses one of the @<Tenant>.onmicrosoft.com email addresses, and the depending other stuff will have an issue if these email addresses go away.  I can do Message Tracking logs to determine that (hopefully:) that is).

 

Thanks in advance.

4 Replies
Highlighted

Hi @Jeremy Bradshaw 

 

Not many of my clients are using Exchange Hybrid, but there is one at the moment. We're looking to move them into 365 completely, but covid put a spanner in the works so that's been delayed.

 

The server is Exchange 2010 server, and I can see both the tenant.onmicrosoft.com and tenant.mail.onmicrosoft.com set up as both a accepted and a remote domain

 

Accepted domains

 

hybrid1.png

 

And for remote domains...

 

HidMov_0-1597779784484.png

 

Going to be honest with you - I can't recall if I added in the tenant.onmicrosoft.com one manually or not as it was last year. That said, I wouldn't have added it in unless I had a good reason to do so.

 

Hope this helps in some way,

 

Mark

 

Highlighted

@HidMov  Thanks very much for the info. 

Highlighted

@Jeremy Bradshaw 

 

Hi, I can also confirm that in older hybrid deployments using Exchange 2010 I have seen both the .onmicrosoft.com and mail.onmicrosoft.com domains added as accepted domains on premises.  

 

On more recent hybrids using Exchange 2016, only the mail.onmicrosoft.com domain is present.

Highlighted
Thanks for the info as well. Based on this, and the earlier response, as well as the environment I noticed it in, seems like it was the way previously, either with Exchange 2010, or just earlier HCW versions.

In retrospect, it seems I've been on quite a stretch of Exchange 2013 and newer projects, which I guess is a good thing, but clearly I've lost touch with 2010, at least a little bit.