How to decommission on-premises exchange servers and move completely to O365

%3CLINGO-SUB%20id%3D%22lingo-sub-1399441%22%20slang%3D%22en-US%22%3EHow%20to%20decommission%20on-premises%20exchange%20servers%20and%20move%20completely%20to%20O365%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1399441%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20are%20currently%20using%20Exchange%20server%202013%20in%20a%20hybrid%20setup%20with%20centralised%20mailflow%20through%20our%20on-premises%20servers.%3CBR%20%2F%3EAll%20our%20mailboxes%20are%20in%20O365.%3CBR%20%2F%3EFollowing%20outbound%20connectors%20exist%20in%20O365%3A-%3CBR%20%2F%3EOffice365%20to%20Mimecast%20Journaling%3CBR%20%2F%3EName%20RecipientDomains%20SmartHosts%3CBR%20%2F%3E----%20----------------%20----------%3CBR%20%2F%3EOffice365%20to%20Mimecast%20Journaling%20%7Bjournal.ourdomain.com.au%7D%20Mimecast%20Journaling%20Servers%3CBR%20%2F%3EOutbound%20to%20OnPremisesServerGUID%20%7B*%7D%20%7BOnPremisesServer.ourdomain.com.au%7D%3C%2FP%3E%3CP%3EFollowing%20send%20connectors%20exist%20on%20the%20on-premises%20exchange%20server%20with%20transport%20role%3A-%3CBR%20%2F%3EIdentity%20AddressSpaces%20Enabled%3CBR%20%2F%3E--------%20-------------%20-------%3CBR%20%2F%3EExchange%20On-Premise%20to%20Mimecast%20%7BSMTP%3A*%3B50%7D%20True%3CBR%20%2F%3EOutbound%20to%20Office%20365%20%7Bsmtp%3AOurO365TenantName.mail.onmicrosoft.com%3B1%7D%20True%3C%2FP%3E%3CP%3EWe%20want%20to%20decommission%20the%20on-premises%20servers%20or%20may%20just%20retain%201%20server%20for%20allowing%20relay%20from%20on-premises%20applications.%3CBR%20%2F%3EWhat%20will%20be%20the%20next%20step%20to%20decommission%20the%20on-premises%20servers%3F%3C%2FP%3E%3CP%3EI%20am%20thinking%20of%20following%20steps%3A-%3CBR%20%2F%3E1.%20Set%20up%20a%20connector%20in%20O365%20to%20Mimemcast%20with%20%22*%22%20as%20the%20recipient%20domains%20and%20disabling%20the%20%22Outbound%20to%20OnPremisesServerGUID%22%20connector.%3CBR%20%2F%3EAnd%20then%20running%20the%20Hybrid%20configuration%20wizard%20to%20remove%20the%20centralised%20mail%20flow%20setting.%3CBR%20%2F%3EThis%20should%20make%20the%20email%20flow%20from%20O365%20directly%20to%20mimecast%20instead%20of%20going%20through%20on%20premises%20server.%3CBR%20%2F%3EI%20need%20to%20ensure%20that%20O365%20spf%20is%20included%20in%20our%20spf.%3C%2FP%3E%3CP%3E2.%20Find%20out%20which%20applications%20are%20relaying%20through%20our%20on-premises%20exchange%20server%20and%20then%20make%20then%20relay%20through%20O365%20using%20option%201%20or%203%20described%20in%20following%20article%3A-%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fexchange%2Fmail-flow-best-practices%2Fhow-to-set-up-a-multifunction-device-or-application-to-send-email-using-office-3%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fexchange%2Fmail-flow-best-practices%2Fhow-to-set-up-a-multifunction-device-or-application-to-send-email-using-office-3%3C%2FA%3E%3C%2FP%3E%3CP%3E3.%20Change%20Mimecast%20to%20route%20mail%20to%20OurO365TenantName.mail.onmicrosoft.com%20rather%20then%20our%20on-premises%20servers.%3C%2FP%3E%3CP%3EIs%20that%20plan%20correct%20and%20what%20testing%20should%20be%20done%20at%20each%20stage%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1399441%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1399554%22%20slang%3D%22en-US%22%3ERe%3A%20How%20to%20decommission%20on-premises%20exchange%20servers%20and%20move%20completely%20to%20O365%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1399554%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F356941%22%20target%3D%22_blank%22%3E%40m_c_7%3C%2FA%3E%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIf%20you%20remove%20your%20exchange%20server%20you%20are%20in%20an%20unsupported%20configuration%2C%20please%20read%20more%20here%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fexchange%2Fdecommission-on-premises-exchange%3Fredirectedfrom%3DMSDN%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fexchange%2Fdecommission-on-premises-exchange%3Fredirectedfrom%3DMSDN%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EBest%20Regards%2C%3CBR%20%2F%3ENuno%20%C3%81rias%20Silva%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1400102%22%20slang%3D%22en-US%22%3ERe%3A%20How%20to%20decommission%20on-premises%20exchange%20servers%20and%20move%20completely%20to%20O365%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1400102%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F356941%22%20target%3D%22_blank%22%3E%40m_c_7%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20only%20way%20that%20you%20will%20remain%20supported%20when%20removing%20your%20final%20on-premises%20Exchange%20Server%20is%20by%20breaking%20the%20synchronisation%20between%20AD%20and%20Azure%20AD%2C%20and%20adopting%20a%20cloud%20only%20identity.%20%26nbsp%3BYou%20will%20be%20missing%20out%20on%20the%20benefits%20of%20Seamless%20Sign%20Sign%20on%20if%20you%20do%20that%20however.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAs%20already%20stated%2C%20leaving%20at%20least%20one%20Exchange%20Management%20server%20in%20place%20when%20your%20mailboxes%20are%20in%20Exchange%20Online%2C%20but%20the%20source%20of%20authority%20is%20on-premises%20AD%20is%20the%20supported%20position.%20%26nbsp%3BGives%20you%20greater%20control%20of%20those%20on-premises%20attributes%2C%20and%20also%20allows%20you%20to%20use%20that%20Exchange%20Server%20for%20SMTP%20relay%20for%20your%20multi-function%20devices%20and%20any%20software%20which%20needs%20to%20send%20emails.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1410357%22%20slang%3D%22en-US%22%3ERe%3A%20How%20to%20decommission%20on-premises%20exchange%20servers%20and%20move%20completely%20to%20O365%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1410357%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F616707%22%20target%3D%22_blank%22%3E%40PeterRising%3C%2FA%3E%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F50%22%20target%3D%22_blank%22%3E%40Nuno%20Silva%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20Peter%20and%20Nuno.%3C%2FP%3E%3CP%3EBased%20on%20this%20I%20am%20thinking%20of%20following%20revised%20plan%3A-%3C%2FP%3E%3CP%3E1.%20Set%20up%20a%20connector%20in%20O365%20to%20Mimemcast%20with%20%22*%22%20as%20the%20recipient%20domains%20and%20disabling%20the%20%22Outbound%20to%20OnPremisesServerGUID%22%20connector.%3CBR%20%2F%3EAnd%20then%20running%20the%20Hybrid%20configuration%20wizard%20to%20remove%20the%20centralised%20mail%20flow%20setting.%3CBR%20%2F%3EThis%20should%20make%20the%20email%20flow%20from%20O365%20directly%20to%20mimecast%20instead%20of%20going%20through%20on%20premises%20server.%3CBR%20%2F%3EI%20need%20to%20ensure%20that%20O365%20spf%20is%20included%20in%20our%20spf%20(for%20all%20our%20domains).%3C%2FP%3E%3CP%3E2.%20Leave%20current%20exchange%20server%20that%20relays%20mail%20on-premises.%20Does%20that%20only%20need%20the%20CAS%20role%20(exchange%202013)%3F%3C%2FP%3E%3CP%3E3.%20Change%20Mimecast%20to%20route%20mail%20to%20OurO365TenantName.mail.onmicrosoft.com%20rather%20then%20our%20on-premises%20servers.%3CBR%20%2F%3E4.%20Remove%20following%20connector%20from%20on-premises%20server%20to%20make%20it%20route%20mail%20through%20O365%3A%3CBR%20%2F%3EIdentity%20AddressSpaces%20Enabled%3CBR%20%2F%3E--------%20-------------%20-------%3CBR%20%2F%3EExchange%20On-Premise%20to%20Mimecast%20%7BSMTP%3A*%3B50%7D%20True%3C%2FP%3E%3CP%3EDo%20you%20see%20any%20problems%20with%20this%20plan.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1410886%22%20slang%3D%22en-US%22%3ERe%3A%20How%20to%20decommission%20on-premises%20exchange%20servers%20and%20move%20completely%20to%20O365%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1410886%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F356941%22%20target%3D%22_blank%22%3E%40m_c_7%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20plan%20sounds%20good%20yes.%20Only%20other%20suggestion%20I%20would%20have%20is%20to%20install%20a%20new%20Exchange%202016%20Server%20to%20be%20the%20hybrid%20management%20server.%20%26nbsp%3BIf%20you%20have%20O365%20Enterprise%20licences%20in%20your%20tenant%20you%20will%20be%20eligible%20for%20a%20free%20Exchange%202016%20hybrid%20licence%20key%20(on%20the%20condition%20that%20no%20mailboxes%20are%20hosted%20on%20that%20server).%20%26nbsp%3BRunning%20the%20HCW%20on%20the%20new%20Exchange%202016%20server%20will%20detect%20this%20eligibility%20when%20you%20sign%20in%20to%20O365%20and%20assign%20the%20licence.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ENot%20an%20essential%20step%2C%20but%20it%20gives%20you%20the%20current%20supported%20hybrid%20configuration.%20%26nbsp%3BOnce%20you%20have%20the%20Exchange%202016%20server%20installed%2C%20you%20can%20move%20the%20arbitration%20and%20discovery%20management%20mailboxes%20etc%20over%20to%20it%2C%20and%20create%20a%20connector%20for%20SMTP%20relay.%20%26nbsp%3BThen%20you%20will%20be%20free%20to%20decommission%20the%20older%20Exchange%20Servers%20(assuming%20you%20have%20no%20remaining%20on-premises%20mailboxes%20of%20course).%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1414559%22%20slang%3D%22en-US%22%3ERe%3A%20How%20to%20decommission%20on-premises%20exchange%20servers%20and%20move%20completely%20to%20O365%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1414559%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F356941%22%20target%3D%22_blank%22%3E%40m_c_7%3C%2FA%3E%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThe%20process%20seems%20good%20for%20your%20scenario.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EBest%20Regards%2C%3CBR%20%2F%3ENuno%20%C3%81rias%20Silva%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1462459%22%20slang%3D%22en-US%22%3ERe%3A%20How%20to%20decommission%20on-premises%20exchange%20servers%20and%20move%20completely%20to%20O365%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1462459%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F616707%22%20target%3D%22_blank%22%3E%40PeterRising%3C%2FA%3E%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F50%22%20target%3D%22_blank%22%3E%40Nuno%20Silva%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20Peter%20and%20Nuno.%3C%2FP%3E%3CP%3E%3CSPAN%3Ethanks%20...we%20might%20move%20the%20internal%20apps%20to%20O365%20smtp%20relay%20to%20allow%20redundancy%20(as%20a%20single%20exchange%20server%20will%20not%20have%20redundancy)%3C%2FSPAN%3E%3C%2FP%3E%3CP%3EBut%20keep%201%20server%20for%20mailbox%20management%20purposes.%3CBR%20%2F%3E%3CSPAN%3EAlso%2C%20does%20this%20single%20exchange%20server%20(that%20we%20need%20to%20keep%20on-prem)%20need%20to%20have%20the%20CAS%20and%20mailbox%20server%20roles....or%20we%20can%20install%20the%20console%20only%20on%20this%20server%20for%20mailbox%20mgmt%20purposes%20only%3F%3C%2FSPAN%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CSPAN%3EI%20am%20trying%20to%20see%20if%20MTA%20can%20be%20removed%20from%20the%20one%20server%20that%20needs%20to%20be%20left%20there.%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1462643%22%20slang%3D%22en-US%22%3ERe%3A%20How%20to%20decommission%20on-premises%20exchange%20servers%20and%20move%20completely%20to%20O365%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1462643%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F356941%22%20target%3D%22_blank%22%3E%40m_c_7%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EYou%20will%20need%20to%20install%20the%20mailbox%20role.%26nbsp%3B%20You%20can't%20install%20Exchange%202016%20without%20it.%26nbsp%3B%20Exchange%202016%20consolidates%20roles%20from%20previous%20versions%20into%20only%20two%20roles%20which%20are%20Mailbox%20and%20Edge%20Transport.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1462820%22%20slang%3D%22en-US%22%3ERe%3A%20How%20to%20decommission%20on-premises%20exchange%20servers%20and%20move%20completely%20to%20O365%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1462820%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F356941%22%20target%3D%22_blank%22%3E%40m_c_7%3C%2FA%3E%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAs%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F616707%22%20target%3D%22_blank%22%3E%40PeterRising%3C%2FA%3E%26nbsp%3Bsaid%2C%20you%20will%20need%20to%20install%20the%20mailbox%20role%20to%20have%20a%20full%20exchange%20installed%20and%20supported.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EBest%20Regards%2C%3CBR%20%2F%3ENuno%20%C3%81rias%20Silva%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1467812%22%20slang%3D%22en-US%22%3ERe%3A%20How%20to%20decommission%20on-premises%20exchange%20servers%20and%20move%20completely%20to%20O365%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1467812%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F616707%22%20target%3D%22_blank%22%3E%40PeterRising%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAt%20the%20moment%20we%20will%20be%20keeping%201%20exchange%202013%20server%20(may%20upgrade%20later%20to%202016%20and%20license%20it%20using%20HCW%20as%20per%20your%20advise).%20So%20I%20guess%20I%20will%20need%20both%20CAS%20and%20mailbox%20roles%20on%20it%3F%3C%2FP%3E%3CP%3ESo%20is%20there%20no%20way%20to%20get%20rid%20of%20MTA%20on%20it%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

We are currently using Exchange server 2013 in a hybrid setup with centralised mailflow through our on-premises servers.
All our mailboxes are in O365.
Following outbound connectors exist in O365:-
Office365 to Mimecast Journaling
Name RecipientDomains SmartHosts
---- ---------------- ----------
Office365 to Mimecast Journaling {journal.ourdomain.com.au} Mimecast Journaling Servers
Outbound to OnPremisesServerGUID {*} {OnPremisesServer.ourdomain.com.au}

Following send connectors exist on the on-premises exchange server with transport role:-
Identity AddressSpaces Enabled
-------- ------------- -------
Exchange On-Premise to Mimecast {SMTP:*;50} True
Outbound to Office 365 {smtp:OurO365TenantName.mail.onmicrosoft.com;1} True

We want to decommission the on-premises servers or may just retain 1 server for allowing relay from on-premises applications.
What will be the next step to decommission the on-premises servers?

I am thinking of following steps:-
1. Set up a connector in O365 to Mimemcast with "*" as the recipient domains and disabling the "Outbound to OnPremisesServerGUID" connector.
And then running the Hybrid configuration wizard to remove the centralised mail flow setting.
This should make the email flow from O365 directly to mimecast instead of going through on premises server.
I need to ensure that O365 spf is included in our spf.

2. Find out which applications are relaying through our on-premises exchange server and then make then relay through O365 using option 1 or 3 described in following article:-
https://docs.microsoft.com/en-us/exchange/mail-flow-best-practices/how-to-set-up-a-multifunction-dev...

3. Change Mimecast to route mail to OurO365TenantName.mail.onmicrosoft.com rather then our on-premises servers.

Is that plan correct and what testing should be done at each stage?

9 Replies
Highlighted

Hi @m_c_7,

 

If you remove your exchange server you are in an unsupported configuration, please read more here https://docs.microsoft.com/en-us/exchange/decommission-on-premises-exchange?redirectedfrom=MSDN

 

Best Regards,
Nuno Árias Silva 

Highlighted

@m_c_7 

 

The only way that you will remain supported when removing your final on-premises Exchange Server is by breaking the synchronisation between AD and Azure AD, and adopting a cloud only identity.  You will be missing out on the benefits of Seamless Sign Sign on if you do that however.

 

As already stated, leaving at least one Exchange Management server in place when your mailboxes are in Exchange Online, but the source of authority is on-premises AD is the supported position.  Gives you greater control of those on-premises attributes, and also allows you to use that Exchange Server for SMTP relay for your multi-function devices and any software which needs to send emails.

Highlighted

@PeterRising @Nuno Silva 

Thanks Peter and Nuno.

Based on this I am thinking of following revised plan:-

1. Set up a connector in O365 to Mimemcast with "*" as the recipient domains and disabling the "Outbound to OnPremisesServerGUID" connector.
And then running the Hybrid configuration wizard to remove the centralised mail flow setting.
This should make the email flow from O365 directly to mimecast instead of going through on premises server.
I need to ensure that O365 spf is included in our spf (for all our domains).

2. Leave current exchange server that relays mail on-premises. Does that only need the CAS role (exchange 2013)?

3. Change Mimecast to route mail to OurO365TenantName.mail.onmicrosoft.com rather then our on-premises servers.
4. Remove following connector from on-premises server to make it route mail through O365:
Identity AddressSpaces Enabled
-------- ------------- -------
Exchange On-Premise to Mimecast {SMTP:*;50} True

Do you see any problems with this plan.

Highlighted

@m_c_7 

 

The plan sounds good yes. Only other suggestion I would have is to install a new Exchange 2016 Server to be the hybrid management server.  If you have O365 Enterprise licences in your tenant you will be eligible for a free Exchange 2016 hybrid licence key (on the condition that no mailboxes are hosted on that server).  Running the HCW on the new Exchange 2016 server will detect this eligibility when you sign in to O365 and assign the licence.

 

Not an essential step, but it gives you the current supported hybrid configuration.  Once you have the Exchange 2016 server installed, you can move the arbitration and discovery management mailboxes etc over to it, and create a connector for SMTP relay.  Then you will be free to decommission the older Exchange Servers (assuming you have no remaining on-premises mailboxes of course).

Highlighted

Hi @m_c_7,

 

The process seems good for your scenario.

 

Best Regards,
Nuno Árias Silva 

Highlighted

@PeterRising @Nuno Silva 

Thanks Peter and Nuno.

thanks ...we might move the internal apps to O365 smtp relay to allow redundancy (as a single exchange server will not have redundancy)

But keep 1 server for mailbox management purposes.
Also, does this single exchange server (that we need to keep on-prem) need to have the CAS and mailbox server roles....or we can install the console only on this server for mailbox mgmt purposes only?

I am trying to see if MTA can be removed from the one server that needs to be left there.

Highlighted

@m_c_7 

 

You will need to install the mailbox role.  You can't install Exchange 2016 without it.  Exchange 2016 consolidates roles from previous versions into only two roles which are Mailbox and Edge Transport.

Highlighted

Hi @m_c_7,

 

As @PeterRising said, you will need to install the mailbox role to have a full exchange installed and supported.

 

Best Regards,
Nuno Árias Silva 

Highlighted

@PeterRising 

At the moment we will be keeping 1 exchange 2013 server (may upgrade later to 2016 and license it using HCW as per your advise). So I guess I will need both CAS and mailbox roles on it?

So is there no way to get rid of MTA on it?