HCW8064 The HCW has completed, but was not able to perform the OAuth portion of your Hybrid

%3CLINGO-SUB%20id%3D%22lingo-sub-1580532%22%20slang%3D%22en-US%22%3EHCW8064%20The%20HCW%20has%20completed%2C%20but%20was%20not%20able%20to%20perform%20the%20OAuth%20portion%20of%20your%20Hybrid%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1580532%22%20slang%3D%22en-US%22%3E%3CP%3EHello%2C%3CBR%20%2F%3EI%20have%20question.%3CBR%20%2F%3EI%20have%20to%20do%20a%20full%20hybrid%20setup.%3CBR%20%2F%3EMy%20on%20premises%20infrastructure%20consists%20of%20two%20exchange%20servers%202016%20cu17%20in%20dag.%3CBR%20%2F%3EThe%20various%20exchange%20services%20(owa%2C%20ews%2C%20smtp%20etc)%20are%20balanced%20through%20a%20load%20balancer.%3CBR%20%2F%3EThe%20various%20exchange%20services%20are%20published%20on%20the%20LAN%20and%20on%20the%20internet%20pointing%20to%20the%20address%20of%20the%20load%20balancer%20and%20everything%20works%20correctly.%3CBR%20%2F%3EI%20created%20my%20domain%20on%20o365%20and%20synchronized%20users%20with%20AAD%20connect.%3CBR%20%2F%3ETo%20perform%20the%20full%20hybrid%20I%20used%20hcw%20version%2017.0.4544.0.%3CBR%20%2F%3EDuring%20the%20hcw%20configuration%20I%20put%20both%20servers%20exchange%20in%20the%20receive%20connector%20configuration%20and%20I%20configured%20both%20servers%20exchange%20also%20in%20the%20send%20connector%20configuration.%3CBR%20%2F%3EAs%20an%20organization%20FQDN%20I%20put%20the%20records%20mx%20pointing%20to%20the%20public%20address%20of%20the%20balancer.%3CBR%20%2F%3EHCW%20ends%20with%20the%20following%20message%20HCW8064%20The%20HCW%20has%20completed%2C%20but%20was%20not%20able%20to%20perform%20the%20OAuth%20portion%20of%20your%20Hybrid%20configuration.%20If%20you%20need%20features%20that%20rely%20on%20OAuth%2C%20you%20can%20try%20running%20the%20HCW%20again%20or%20manually%20configure%20OAuth%20using%20these%20manual%20steps.%3CBR%20%2F%3EI%20tried%20to%20relaunch%20hcw%20again%20as%20suggested%20by%20microsoft%20article%20%3CA%20href%3D%22https%3A%2F%2Fsupport.microsoft.com%2Fen-us%2Fhelp%2F3089172%2Fhcw-has-completed-but-was-not-able-to-perform%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fsupport.microsoft.com%2Fen-us%2Fhelp%2F3089172%2Fhcw-has-completed-but-was-not-able-to-perform%3C%2FA%3E%20-the-oauth-portion-of-you%20but%20the%20problem%20persists.%3CBR%20%2F%3EFrom%20what%20I%20understand%20OAuth%20is%20for%3A%3CBR%20%2F%3EMessage%20Records%20Management%20(MRM)%3CBR%20%2F%3EExchange%20In-place%20eDiscovery%3CBR%20%2F%3EExchange%20In-place%20Archiving%3CBR%20%2F%3EIntegration%20between%20various%20services%20such%20as%20Teams%3CBR%20%2F%3EIs%20what%20I%20say%20correct%3F%3CBR%20%2F%3EIs%20OAuth%20authentication%20required%20to%20migrate%20the%20various%20exchange%20components%20to%20online%20exchanges%20(mailboxes%2C%20mail%20flow%2C%20frre%20busy%20etc)%20or%20can%20I%20ignore%20the%20message%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERegards%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1580532%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EExchange%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Ehybrid%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOn-Premises%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1580551%22%20slang%3D%22en-US%22%3ERe%3A%20HCW8064%20The%20HCW%20has%20completed%2C%20but%20was%20not%20able%20to%20perform%20the%20OAuth%20portion%20of%20your%20Hybrid%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1580551%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F709854%22%20target%3D%22_blank%22%3E%40pazzoide76%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EYes%20you%20are%20correct%20in%20your%20assessment%20of%20what%20OAuth%20does%20in%20the%20context%20of%20Hybrid.%26nbsp%3B%20Whilst%20the%20lack%20of%20OAuth%20will%20not%20prevent%20you%20from%20migrating%20mailboxes%20to%20the%20cloud%2C%20I%20would%20urge%20you%20to%20try%20and%20get%20it%20working%20as%20per%20-%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fexchange%2Fconfigure-oauth-authentication-between-exchange-and-exchange-online-organizations-exchange-2013-help%3Fredirectedfrom%3DMSDN%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fexchange%2Fconfigure-oauth-authentication-between-exchange-and-exchange-online-organizations-exchange-2013-help%3Fredirectedfrom%3DMSDN%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EEspecially%20if%20you%20are%20using%20Teams%20and%20wish%20your%20users%20to%20have%20the%20full%20possible%20functionality%20whilst%20they%20still%20have%20an%20on-premises%20mailbox.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1580565%22%20slang%3D%22en-US%22%3ERe%3A%20HCW8064%20The%20HCW%20has%20completed%2C%20but%20was%20not%20able%20to%20perform%20the%20OAuth%20portion%20of%20your%20Hybrid%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1580565%22%20slang%3D%22en-US%22%3E%3CP%3EThanks%20for%20the%20reply.%3C%2FP%3E%3CP%3ESince%20I%20have%20a%20two-node%20dag%2C%20should%20the%20procedure%20described%20in%20the%20microsoft%20article%20to%20enable%20OAth%20be%20done%20on%20both%20servers%3F%3C%2FP%3E%3CP%3ENo%20mailboxes%20will%20remain%20on%20the%20servers%20on%20premises%2C%20it%20will%20be%20used%20only%20for%20management.%3C%2FP%3E%3CP%3EAlso%20the%20dag%20will%20be%20deleted%20and%20only%20one%20server%20will%20remain.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ethank%20you%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERegards%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1580616%22%20slang%3D%22en-US%22%3ERe%3A%20HCW8064%20The%20HCW%20has%20completed%2C%20but%20was%20not%20able%20to%20perform%20the%20OAuth%20portion%20of%20your%20Hybrid%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1580616%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F709854%22%20target%3D%22_blank%22%3E%40pazzoide76%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHow%20many%20mailboxes%20do%20you%20have%2C%20and%20how%20quickly%20do%20you%20anticipate%20being%20able%20to%20complete%20your%20mailbox%20moves%3F%26nbsp%3B%20If%20it's%20a%20short%20time%20period%2C%20you%20could%20possibly%20skip%20this%20step.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20you%20did%20that%2C%20I'd%20encourage%20you%20to%20thoroughly%20test%20cross%20premise%20mail%20flow%20and%20free%20busy%20using%20a%20test%20migrated%20mailbox%20to%20ensure%20that%20things%20are%20going%20to%20work%20for%20you%20as%20required%20whilst%20you%20are%20migrating%20and%20have%20mailboxes%20both%20on-premises%20and%20in%20the%20cloud.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1580629%22%20slang%3D%22en-US%22%3ERe%3A%20HCW8064%20The%20HCW%20has%20completed%2C%20but%20was%20not%20able%20to%20perform%20the%20OAuth%20portion%20of%20your%20Hybrid%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1580629%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F616707%22%20target%3D%22_blank%22%3E%40PeterRising%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20for%20the%20reply.%3CBR%20%2F%3EThere%20are%20about%20500%20mailboxes%20to%20migrate%20and%20I%20think%20it%20will%20take%20about%202%20weeks.%3CBR%20%2F%3EI%20wanted%20to%20understand%20if%20the%20procedure%20to%20enable%20OAth%20(article%20microsoft%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fexchange%2Fconfigure-oauth-authentication-between-exchange-and-exchange-online-organizations-exchange-2013-help%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fexchange%2Fconfigure-oauth-authentication-between-exchange-and-exchange-online-organizations-exchange-2013-help%3C%2FA%3E%20)%20must%20be%20performed%20on%20both%20nodes%20of%20the%20DAG.%3CBR%20%2F%3EAlso%20from%20what%20I%20understand%20OAth%20is%20only%20for%20mailboxes%20that%20are%20on%20premises%20and%20not%20for%20those%20on%20o365%2C%20correct%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERegards%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1580656%22%20slang%3D%22en-US%22%3ERe%3A%20HCW8064%20The%20HCW%20has%20completed%2C%20but%20was%20not%20able%20to%20perform%20the%20OAuth%20portion%20of%20your%20Hybrid%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1580656%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F709854%22%20target%3D%22_blank%22%3E%40pazzoide76%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20is%20an%20organization%20based%20configuration%20and%20so%20running%20the%20commands%20on%20the%20Exchange%20Management%20Shell%20from%20a%20single%20on-prem%20Exchange%20Server%20should%20do%20the%20trick%2C%26nbsp%3B%20and%20yes%20this%20process%20relates%20only%20to%20on-prem%20mailboxes.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1580670%22%20slang%3D%22en-US%22%3ERe%3A%20HCW8064%20The%20HCW%20has%20completed%2C%20but%20was%20not%20able%20to%20perform%20the%20OAuth%20portion%20of%20your%20Hybrid%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1580670%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F616707%22%20target%3D%22_blank%22%3E%40PeterRising%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20you%20are%20number%20one.%3CBR%20%2F%3ENow%20I%20try%20to%20enable%20OAuth.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20again%20for%20the%20support%3C%2FP%3E%3C%2FLINGO-BODY%3E
Contributor

Hello,
I have question.
I have to do a full hybrid setup.
My on premises infrastructure consists of two exchange servers 2016 cu17 in dag.
The various exchange services (owa, ews, smtp etc) are balanced through a load balancer.
The various exchange services are published on the LAN and on the internet pointing to the address of the load balancer and everything works correctly.
I created my domain on o365 and synchronized users with AAD connect.
To perform the full hybrid I used hcw version 17.0.4544.0.
During the hcw configuration I put both servers exchange in the receive connector configuration and I configured both servers exchange also in the send connector configuration.
As an organization FQDN I put the records mx pointing to the public address of the balancer.
HCW ends with the following message HCW8064 The HCW has completed, but was not able to perform the OAuth portion of your Hybrid configuration. If you need features that rely on OAuth, you can try running the HCW again or manually configure OAuth using these manual steps.
I tried to relaunch hcw again as suggested by microsoft article https://support.microsoft.com/en-us/help/3089172/hcw-has-completed-but-was-not-able-to-perform -the-oauth-portion-of-you but the problem persists.
From what I understand OAuth is for:
Message Records Management (MRM)
Exchange In-place eDiscovery
Exchange In-place Archiving
Integration between various services such as Teams
Is what I say correct?
Is OAuth authentication required to migrate the various exchange components to online exchanges (mailboxes, mail flow, frre busy etc) or can I ignore the message?

 

Thank you

 

Regards

6 Replies

@pazzoide76 

 

Yes you are correct in your assessment of what OAuth does in the context of Hybrid.  Whilst the lack of OAuth will not prevent you from migrating mailboxes to the cloud, I would urge you to try and get it working as per - https://docs.microsoft.com/en-us/exchange/configure-oauth-authentication-between-exchange-and-exchan...

 

Especially if you are using Teams and wish your users to have the full possible functionality whilst they still have an on-premises mailbox.

Thanks for the reply.

Since I have a two-node dag, should the procedure described in the microsoft article to enable OAth be done on both servers?

No mailboxes will remain on the servers on premises, it will be used only for management.

Also the dag will be deleted and only one server will remain.

 

thank you

 

Regards

@pazzoide76 

 

How many mailboxes do you have, and how quickly do you anticipate being able to complete your mailbox moves?  If it's a short time period, you could possibly skip this step.

 

If you did that, I'd encourage you to thoroughly test cross premise mail flow and free busy using a test migrated mailbox to ensure that things are going to work for you as required whilst you are migrating and have mailboxes both on-premises and in the cloud.

@PeterRising 

Thanks for the reply.
There are about 500 mailboxes to migrate and I think it will take about 2 weeks.
I wanted to understand if the procedure to enable OAth (article microsoft https://docs.microsoft.com/en-us/exchange/configure-oauth-authentication-between-exchange-and-exchan... ) must be performed on both nodes of the DAG.
Also from what I understand OAth is only for mailboxes that are on premises and not for those on o365, correct?

 

Thank you

 

Regards

@pazzoide76 

 

This is an organization based configuration and so running the commands on the Exchange Management Shell from a single on-prem Exchange Server should do the trick,  and yes this process relates only to on-prem mailboxes.

@PeterRising 

Thanks you are number one.
Now I try to enable OAuth.

 

Thanks again for the support