Exchange 2019 Delegation Federation certificate expired hybrid

Jan De Smet 66 Reputation points
2022-05-16T11:02:57.85+00:00

Hello we have an exchange 2019 onprem, hybrid configuration. We use the exchange onprem for user mgmt and internal relaying only. No mailboxes onprem anymore.
We noticed our Exchange Delegation Federation certificate expired a while ago. I was wondering, do we need to renew this certificate in our deployment? or can we remove this certificate? I did notice there was a federation set up.
Or can we renew this certificate by rerunning the HCW?
thanks

Exchange | Exchange Server | Management
Exchange | Hybrid management
{count} vote

Accepted answer
  1. Andy David - MVP 157.8K Reputation points MVP Volunteer Moderator
    2022-05-16T11:06:24.24+00:00

    I would keep it current. Even if not being used.

    You can use these steps :
    https://learn.microsoft.com/en-us/exchange/renew-the-federation-certificate-exchange-2013-help

    or run the Hybrid Wizard.

    1 person found this answer helpful.
    0 comments No comments

3 additional answers

Sort by: Most helpful
  1. KyleXu-MSFT 26,396 Reputation points
    2022-05-17T07:23:13.457+00:00

    @Jan De Smet

    I agree with AndyDavid‘s suggestion.

    Follow the "Replace an expired federation certificate" part in the article that AndyDavid provided. An expired or missing certificate will cause a lot of errors in Event Viewer.

    Due to there still exist hybrid in your organization, it is suggested to renew this certificate.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


    0 comments No comments

  2. Jan De Smet 66 Reputation points
    2022-05-17T12:55:59.737+00:00

    Hi,

    The instructions on this page only suggest to remove the federated domains and the trust.
    When they are removed, I just recreate it via the ECP?
    https://learn.microsoft.com/en-us/exchange/configure-a-federation-trust-exchange-2013-help

    Rerunning the HCW did not renew the certificate. Maybe it renews the trust, but it did not renew the certificate.

    Thanks


  3. Jan De Smet 66 Reputation points
    2022-06-14T10:38:48.35+00:00

    Hello, I removed the Federation.
    I followed the instructions here: https://learn.microsoft.com/en-us/exchange/renew-the-federation-certificate-exchange-2013-help

    I also renewed the Federation via EAC: https://learn.microsoft.com/en-us/exchange/configure-a-federation-trust-exchange-2013-help

    All is looking good now;
    Many thanks

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.