Hybrid Exchange Server setup and Windows Extended Protection?

EnterpriseArchitect 4,761 Reputation points
2022-10-05T03:18:43.287+00:00

I'm currently running Exchange 2016 on-premise with Hybrid Setup to Exchange Online (AD DS --> Azure AD).

Based on https://microsoft.github.io/CSS-Exchange/Security/Extended-Protection/

How can I safely enable and secure the OnPremise Hybrid Exchange Server when the below script shows the warning:
247597-image.png

Thank you,

Microsoft Exchange Online Management
Microsoft Exchange Online Management
Microsoft Exchange Online: A Microsoft email and calendaring hosted service.Management: The act or process of organizing, handling, directing or controlling something.
4,190 questions
Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,356 questions
Microsoft Exchange Hybrid Management
Microsoft Exchange Hybrid Management
Microsoft Exchange: Microsoft messaging and collaboration software.Hybrid Management: Organizing, handling, directing or controlling hybrid deployments.
1,895 questions
0 comments No comments
{count} votes

Accepted answer
  1. Andy David - MVP 142.2K Reputation points MVP
    2022-10-05T23:22:03.597+00:00
    1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. Andy David - MVP 142.2K Reputation points MVP
    2022-10-05T12:02:45.253+00:00

    Did you enable Modern Hybrid? If not and you are using classic Hybrid, then you are ok:
    Extended Protection does not work with hybrid servers using Modern Hybrid configuration
    Extended Protection cannot be enabled on Hybrid Servers which uses Modern Hybrid configuration. In Modern Hybrid configuration, Hybrid Server are published to Exchange Online via Hybrid Agent which proxies the Exchange Online call to Exchange Server.

    Enabling Extended Protection on Hybrid servers using Modern Hybrid configuration will lead to disruption of hybrid features like mailbox migrations and Free/Busy. Hence, it is important to identify all the Hybrid Servers in the organization published via Hybrid Agent and not enable Extended Protection specifically on these servers.

    https://learn.microsoft.com/en-us/exchange/hybrid-configuration-wizard-options

    1 person found this answer helpful.