O365/On-Prem Hybrid initial setup issues / errors - need help ASAP

%3CLINGO-SUB%20id%3D%22lingo-sub-206559%22%20slang%3D%22en-US%22%3EO365%2FOn-Prem%20Hybrid%20initial%20setup%20issues%20%2F%20errors%20-%20need%20help%20ASAP%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-206559%22%20slang%3D%22en-US%22%3E%3CP%3EI've%20gone%20through%20most%20of%20the%20preparatory%20steps%20in%20setting%20up%20a%20hybrid%20environment%2C%20but%20I'm%20having%20some%20strange%20issues%20that%20I%20need%20help%20with.%20I%20REALLY%20appreciate%20any%20guidance!%3C%2FP%3E%3CP%3ECurrent%20Environment%3A%3C%2FP%3E%3CP%3E-%20AD%20was%20original%20setup%20as%20OURNET%20(OURNET%5Cusername)%3C%2FP%3E%3CP%3E-%20on-Prem%20Exchange%202010%20Sp3%20(ourdomain.com)%3C%2FP%3E%3CP%3E-%20Exchange%20server%20(named%20EXCH%20-%20shows%20up%20as%20EXCH.OURNET.OURDOMAIN.com%20in%20EMC%20on%20ONPremise%20name%3C%2FP%3E%3CP%3E-%20Barracuda%20email%20services%20for%20antispam%20(inbound%20and%20outbound%20mail%20route%20through%20hosted%20Barracuda%20services.%20MX%20record%20for%20OURDOMAIN.com%20points%20to%20our%20Barracuda%20service%20then%20delivers%20to%20Exchange%20OnPrem)%3C%2FP%3E%3CP%3E-%20users%20were%20logging%20in%20as%26nbsp%3BOURNET%5Cusername%20forever%2C%20but%20as%20part%20of%20the%20prep%20for%20O365%2C%20I%20changed%20their%20UPNs%20to%20username%40OURDOMAIN.COM%20(which%20seems%20to%20work%20fine)%3C%2FP%3E%3CP%3E-%20Azure%20AD%20Sync%20setup%20a%20while%20ago%20successfully%26nbsp%3B(syncing%20fine)%20before%20we%20started%20the%20move%20to%20Hybrid.%20Users%20all%20licensed%3C%2FP%3E%3CP%3E-%20recently%20reissued%20an%20SSL%20for%20my%20Exchange%20server%20so%20that%20it's%20keyed%20to%20OURDOMAIN.com%20(and%20wildcards%20EMAIL.OURDOMAIN.COM%20etc).%20Previously%2C%20we%20had%20a%20cert.%20where%20OURDOMAIN.COM%20was%20listed%20as%20a%20alternate%20name.%20Email%20flowed%20but%20we%20had%20Autodiscover%20issues.%20That%20seems%20to%20be%20resolved%20now%20as%20Autodiscover%20works.%20I%20have%20SMTP%2C%20IIS%2C%20POP%2C%20and%20IMAP%20services%20assigned%20to%20this%20cert.%20(had%20to%20use%20powershell%20to%20assign%20POP%20and%20IMAP)%3C%2FP%3E%3CP%3EI%20went%20through%20all%20of%20the%20steps%20seemingly%20successfully%26nbsp%3Bto%20setup%20a%20minimal%20hybrid%20deployment%20(O365%20Admin%2FSetup%2FData%20Migration%20wizards).%20I%20see%20the%20hybrid%20connectors%20in%20my%20OP%20Exchange%20server.%20However%2C%20in%20my%20OP%20EMC%2FOrg.%20Config%20I%20see%20Hybrid%20Configuration%20listed%20but%20when%20I%20try%20to%20view%2Fedit%20it%2C%20it%20says%20%22You%20must%20add%20your%20online%20tenant%26nbsp%3Bas%20an%20additional%20forest%22%3C%2FP%3E%3CP%3EI%20HAVE%20NOT%20YET%20CHANGED%20THE%20MX%20RECORDS%20TO%20POINT%20TO%20OFFICE365%20(ourdomain-com.mail.protection.outlook.com)%20AS%20I'M%20NOT%20READY%20TO%20MIGRATE%20EVERYONE%20OVER.%20I%20figured%20that%20until%20I%20change%20this%2C%20mail%20would%20just%20continue%20to%20flow%20to%20my%20OP%20Exchange%20server%20as%20normal.%3C%2FP%3E%3CP%3EIssues%20(note%20most%20of%20these%20issues%20are%20sporadic%20and%20not%20for%20every%20user)%3A%3C%2FP%3E%3CP%3E-%20my%20biggest%20issue%3A%20I%20have%203%20users%20(identified%20so%20far)%20whose%20INTERNAL%20EMAIL%20are%20getting%20routed%20to%20my%20users'%20O365%20mailbox%20but%20NOT%20to%20their%20regular%20OnPrem%20mailbox.%20Unfortunately%2C%20one%20of%20these%203%20users%20is%20the%20owner%20of%20the%20company!%20I'm%20also%20one%20of%20them.%20Any%20email%20we%20send%20internally%20never%20shows%20up%20in%20users'%20Outlook%20but%20do%20show%20up%20in%20their%20O365%20mailbox.%3C%2FP%3E%3CP%3E-%20I'm%20getting%20some%20email%20bouncebacks%20(from%20some%20of%20my%20users)%20when%20sending%20to%20outside%20organizations.%20I%20have%20added%20the%20required%20SPF%20record%20as%20O365%20directed.%20Is%20that%20the%20cause%20of%20the%20problem%3F%20Is%20it%20related%20to%20the%20certificate%20name%20issue%3F%3C%2FP%3E%3CP%3E%3CSTRONG%3EDiagnostic%20information%20for%20administrators%3A%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3EGenerating%20server%3A%20EXCH.OURNET.OURDOMAIN.COM%3C%2FP%3E%3CP%3Euser%40somedomain.com%3CBR%20%2F%3Emx1402.ess.rzc.cudaops.com%20%23550%20permanent%20failure%20for%20one%20or%20more%20recipients%20(user%40somedomain.com%3A443%26nbsp%3B%26nbsp%3BSPF%20(Sender%20Policy%20Framework)%20domain%20authentication%20fail.%20Refer%20to%20the%20Troubleshooting%20...)%20%23%23%3C%2FP%3E%3CP%3E%26nbsp%3B-%20my%20users%20are%20getting%20prompted%20often%20for%20their%20passwords%20by%20Outlook%20(and%20usually%2C%20they%20fail).%20I've%20had%20everyone%20reset%20their%20passwords%20and%20they%20can%20successfully%20login%20to%20both%20OURDOMAIN%20(using%20username%40ourdomain.com)%20and%20office.com%20with%20username%40ourdomain.com%20and%20their%20new%20passwords.%20I've%20seen%20a%20lot%20online%20about%20this%20issue.%20I've%20stripped%20local%20credentials%20from%20the%20manager%20and%20tried%20some%20other%20things%20but%20nothing%20works.%3C%2FP%3E%3CP%3E-%20some%20users%20when%20they%20open%20Outlook%20are%20getting%20%22Your%20mailbox%20has%20been%20temporarily%20moved%20on%20Exchanger%20Server...user%20temporary%20mailbox%2FOld%20data%22.%20I've%20deleted%20their%20mail%20profile%20and%20recreated%20it%20(it%20connects%20to%20their%20account%20username%40ourdomain.com%20fine)%20and%20then%20their%20Outlook%20works.%20This%20keeps%20happening%20intermittently%20for%20users%20(some%20multiple%20times)%3C%2FP%3E%3CP%3E-%20When%20opening%20Outlook%2C%20we%20are%20still%20getting%20certificate%20errors.%20We%20get%20a%20security%20popup%20that%20says%20our%20cert%20isn't%20quite%20right%20because%20the%20name%20of%20our%20server%20(EXCH.OURNET.OURDOMAIN.com)%20is%20not%20on%20the%20certificate%20even%20though%20the%20cert%20is%20setup%20for%20wildcards%20for%20OURDOMAIN.COM.%20We%20can%20click%20OK%20and%20get%20in%2C%20but%20I%20fear%20this%20is%20also%20causing%20issues.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAgain%2C%20thanks%20for%20any%20help%20you%20can%20offer.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-206559%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EHybrid%20O365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-206754%22%20slang%3D%22en-US%22%3ERe%3A%20O365%2FOn-Prem%20Hybrid%20initial%20setup%20issues%20%2F%20errors%20-%20need%20help%20ASAP%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-206754%22%20slang%3D%22en-US%22%3E%3CP%3EUPDATE%3A%20I%20was%20able%20to%20re-key%20our%20UCC%20Wildcard%20SSL%20with%20my%20domain%20and%20SANs%20for%20the%20domain%20and%20I%20changed%20the%20location%20of%20the%20offline%20address%20book%20in%20exchange%20(it%20WAS%20pointing%20to%20EXCH.OURNET.OURDOMAIN.COM%20which%20seemed%20to%20be%20part%20of%20the%20problem).%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMy%20certificate%20warnings%20on%20client%20machines%20seems%20to%20have%20stopped.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Esmall%20victory%3C%2FP%3E%3C%2FLINGO-BODY%3E
Deleted
Not applicable

I've gone through most of the preparatory steps in setting up a hybrid environment, but I'm having some strange issues that I need help with. I REALLY appreciate any guidance!

Current Environment:

- AD was original setup as OURNET (OURNET\username)

- on-Prem Exchange 2010 Sp3 (ourdomain.com)

- Exchange server (named EXCH - shows up as EXCH.OURNET.OURDOMAIN.com in EMC on ONPremise name

- Barracuda email services for antispam (inbound and outbound mail route through hosted Barracuda services. MX record for OURDOMAIN.com points to our Barracuda service then delivers to Exchange OnPrem)

- users were logging in as OURNET\username forever, but as part of the prep for O365, I changed their UPNs to username@OURDOMAIN.COM (which seems to work fine)

- Azure AD Sync setup a while ago successfully (syncing fine) before we started the move to Hybrid. Users all licensed

- recently reissued an SSL for my Exchange server so that it's keyed to OURDOMAIN.com (and wildcards EMAIL.OURDOMAIN.COM etc). Previously, we had a cert. where OURDOMAIN.COM was listed as a alternate name. Email flowed but we had Autodiscover issues. That seems to be resolved now as Autodiscover works. I have SMTP, IIS, POP, and IMAP services assigned to this cert. (had to use powershell to assign POP and IMAP)

I went through all of the steps seemingly successfully to setup a minimal hybrid deployment (O365 Admin/Setup/Data Migration wizards). I see the hybrid connectors in my OP Exchange server. However, in my OP EMC/Org. Config I see Hybrid Configuration listed but when I try to view/edit it, it says "You must add your online tenant as an additional forest"

I HAVE NOT YET CHANGED THE MX RECORDS TO POINT TO OFFICE365 (ourdomain-com.mail.protection.outlook.com) AS I'M NOT READY TO MIGRATE EVERYONE OVER. I figured that until I change this, mail would just continue to flow to my OP Exchange server as normal.

Issues (note most of these issues are sporadic and not for every user):

- my biggest issue: I have 3 users (identified so far) whose INTERNAL EMAIL are getting routed to my users' O365 mailbox but NOT to their regular OnPrem mailbox. Unfortunately, one of these 3 users is the owner of the company! I'm also one of them. Any email we send internally never shows up in users' Outlook but do show up in their O365 mailbox.

- I'm getting some email bouncebacks (from some of my users) when sending to outside organizations. I have added the required SPF record as O365 directed. Is that the cause of the problem? Is it related to the certificate name issue?

Diagnostic information for administrators:

Generating server: EXCH.OURNET.OURDOMAIN.COM

user@somedomain.com
mx1402.ess.rzc.cudaops.com #550 permanent failure for one or more recipients (user@somedomain.com:443  SPF (Sender Policy Framework) domain authentication fail. Refer to the Troubleshooting ...) ##

 - my users are getting prompted often for their passwords by Outlook (and usually, they fail). I've had everyone reset their passwords and they can successfully login to both OURDOMAIN (using username@ourdomain.com) and office.com with username@ourdomain.com and their new passwords. I've seen a lot online about this issue. I've stripped local credentials from the manager and tried some other things but nothing works.

- some users when they open Outlook are getting "Your mailbox has been temporarily moved on Exchanger Server...user temporary mailbox/Old data". I've deleted their mail profile and recreated it (it connects to their account username@ourdomain.com fine) and then their Outlook works. This keeps happening intermittently for users (some multiple times)

- When opening Outlook, we are still getting certificate errors. We get a security popup that says our cert isn't quite right because the name of our server (EXCH.OURNET.OURDOMAIN.com) is not on the certificate even though the cert is setup for wildcards for OURDOMAIN.COM. We can click OK and get in, but I fear this is also causing issues.

 

Again, thanks for any help you can offer.

 

1 Reply

UPDATE: I was able to re-key our UCC Wildcard SSL with my domain and SANs for the domain and I changed the location of the offline address book in exchange (it WAS pointing to EXCH.OURNET.OURDOMAIN.COM which seemed to be part of the problem).

 

My certificate warnings on client machines seems to have stopped.

 

small victory