Post Cleanup of Connectors, DNS & Cert with Hybrid Environment

%3CLINGO-SUB%20id%3D%22lingo-sub-460436%22%20slang%3D%22en-US%22%3EPost%20Cleanup%20of%20Connectors%2C%20DNS%20%26amp%3B%20Cert%20with%20Hybrid%20Environment%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-460436%22%20slang%3D%22en-US%22%3E%3CP%3EI'm%20attempting%20to%20cleanup%20some%20DNS%20Records%20and%20understand%20what%20SAN(s)%20we%20actually%20need%20(or%20don't)%20for%20our%20Hybrid%20Environment.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E1.%20No%20MB's%20On-Prem%20(it's%20been%20more%20than%20a%20year)%3C%2FP%3E%3CP%3E2.%20No%20Inbound%20mail%20(that%20I%20can%20think%20of)%3C%2FP%3E%3CP%3E3.%20autodiscover%20is%20pointing%20to%20O365%3C%2FP%3E%3CP%3E4.%20We%20still%20have%20our%20Hybrid's%20(2013)%3B%20but%20just%20for%20Mgmt%20%26amp%3B%20as%20a%20mail%20relay%20for%20internal%20Servers%2FServices%3C%2FP%3E%3CP%3E5.%20We%20have%202%20Hybrid's%20utilizing%20Windows%20Load%20Balance%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EO365%20Portal%20Connectors%3A%3C%2FP%3E%3CP%3E1.%20O365%20outbound%20to%20On-Prem%20is%2Fhas%20been%20disabled%20for%20some%20time%20(can%2Fshould%20I%20delete)%3C%2FP%3E%3CP%3E2.%20O365%20inbound%20from%20On-Prem%20-%20enabled%2C%20but%20I%20don't%20believe%20it's%20being%20used%20(references%20old%20cert)%3C%2FP%3E%3CP%3EAny%20thought%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHybrid%20Connectors%3A%3C%2FP%3E%3CP%3E1.%20Direct%3B%20Enabled%20-%20will%20not%20touch%3C%2FP%3E%3CP%3E2.%20Outbound%20to%20O365%3B%20Enabled%20-%20I%20don't%20believe%2C%20or%20not%20sure%20it's%20being%20used%20-%20is%20there%20a%20way%20to%20determine%3F%20Can%20it%20be%20disabled%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHybrid%20Cert%20SAN(s)%20Entries%3C%2FP%3E%3CP%3E1.%20autodiscover%20-%20upon%20renewal%20can%20this%20be%20remove%2Fnot%20renewed%3C%2FP%3E%3CP%3E2.%20Hybrid%20Load%20Balance%20VIP%20DNS%20Name%20-%20is%20this%20even%20necessary%3F%20We%20already%20have%20a%20separate%20DNS%20Name%20with%20same%20IP%20that%20we%20configure%20internal%20servers%2Fservices%2C%20so%20can%20I%20remove%20the%20SAN%20that%20refers%20to%20the%20WNLB%20%22name%22%3F%3C%2FP%3E%3CP%3E3.%20Is%20there%20even%20a%20need%20for%20this%20cert%20anymore%2C%20the%20only%20thing%20that%20I%20can%20this%20would%20be%20relevant%20is%20the%20Connector%20outbound%20to%20O365%20which%20I'm%20not%20even%20sure%20it's%20being%20used%20(as%20mentioned%20above).%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20feedback%20would%20be%20grateful....%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-460436%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EExchange%20Online%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EExchange%20Server%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EHybrid%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-462057%22%20slang%3D%22en-US%22%3ERe%3A%20Post%20Cleanup%20of%20Connectors%2C%20DNS%20%26amp%3B%20Cert%20with%20Hybrid%20Environment%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-462057%22%20slang%3D%22en-US%22%3E%3CP%3EHave%20you%20gone%20over%20the%20%22decommission%20hybrid%22%20article%3F%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fexchange%2Fdecommission-on-premises-exchange%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fexchange%2Fdecommission-on-premises-exchange%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIt%20details%20what%20to%20with%20connectors%2C%20among%20other%20things.%20It%20doesn't%20look%20like%20you%20need%20any%20Hybrid%20functionality%2C%20but%20you%20will%20have%20to%20keep%20one%20of%20the%20Exchange%20boxes%20for%20management%20purposes.%20So%20scenario%202.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
New Contributor

I'm attempting to cleanup some DNS Records and understand what SAN(s) we actually need (or don't) for our Hybrid Environment.

 

1. No MB's On-Prem (it's been more than a year)

2. No Inbound mail (that I can think of)

3. autodiscover is pointing to O365

4. We still have our Hybrid's (2013); but just for Mgmt & as a mail relay for internal Servers/Services

5. We have 2 Hybrid's utilizing Windows Load Balance

 

O365 Portal Connectors:

1. O365 outbound to On-Prem is/has been disabled for some time (can/should I delete)

2. O365 inbound from On-Prem - enabled, but I don't believe it's being used (references old cert)

Any thought?

 

Hybrid Connectors:

1. Direct; Enabled - will not touch

2. Outbound to O365; Enabled - I don't believe, or not sure it's being used - is there a way to determine? Can it be disabled

 

Hybrid Cert SAN(s) Entries

1. autodiscover - upon renewal can this be remove/not renewed

2. Hybrid Load Balance VIP DNS Name - is this even necessary? We already have a separate DNS Name with same IP that we configure internal servers/services, so can I remove the SAN that refers to the WNLB "name"?

3. Is there even a need for this cert anymore, the only thing that I can this would be relevant is the Connector outbound to O365 which I'm not even sure it's being used (as mentioned above).

 

Any feedback would be grateful....

 

 

 

 

 

 

 

 

 

 

 

 

1 Reply
Highlighted

Have you gone over the "decommission hybrid" article? https://docs.microsoft.com/en-us/exchange/decommission-on-premises-exchange

 

It details what to with connectors, among other things. It doesn't look like you need any Hybrid functionality, but you will have to keep one of the Exchange boxes for management purposes. So scenario 2.