Replace an expired federation certificate

MS-QuestBox 20 Reputation points
2023-09-26T15:49:25.34+00:00

We have to recreate the Federated Trust since the self-issue cert expired. Runing Exhange 2016 Hybrid DAG with no mailboxes on prem..

When we remove the federated trust will that affect access, users ability to log in to O365 online mailboxes until its recreated?

Will doing the following:

  • Remove Federated Domain
  • Remove Federation Trust
  • Create a new federation certificate
  • Configure the new certificate as the federation certificate
  • Update the federation proof of domain ownership TXT record in external DNS
  • Verify the distribution of the new federation certificate to all Exchange servers
  • FederationTrust UpdateMetadata
  • Add Federated Domains
Exchange | Exchange Server | Management
{count} votes

Accepted answer
  1. Andy David - MVP 157.8K Reputation points MVP Volunteer Moderator
    2023-09-26T16:53:24.7066667+00:00

3 additional answers

Sort by: Most helpful
  1. Jarvis Sun-MSFT 10,231 Reputation points Microsoft External Staff
    2023-09-27T05:29:45.2666667+00:00

    @MS-QuestBox

    When you remove the federated trust, it will not affect users’ ability to log in to their mailboxes. However, it is important to note that the federated trust is a critical component of the hybrid configuration. Removing it will disable certain features such as free/busy calendar sharing and mailbox moves between on-premises and Exchange Online. Once you recreate the federated trust, these features will be restored.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment". 

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    1 person found this answer helpful.

  2. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  3. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.