How to update Exchange Delegation Federation Certificate in Exchange SE

Jason Earhart 0 Reputation points
2026-01-07T18:41:37.8166667+00:00

Currently running Exchange SE and I need to update our Exchange Delegation Federation Certificate. I am seeing links and documentation that points to Exchange 2013 steps. Are these steps still valid for Exchange SE?

Exchange | Exchange Server | Management
Exchange | Exchange Server | Management

The administration and maintenance of Microsoft Exchange Server to ensure secure, reliable, and efficient email and collaboration services across an organization.

0 comments No comments

2 answers

Sort by: Most helpful
  1. Emmanuel Eze 0 Reputation points
    2026-07-18T15:47:40.8933333+00:00

    @Hani-Ng I am running SE, did the HCW run, but no Federation Certificate was created. Does running this when the current Federation Certificate has expired have any impact?

    Was this answer helpful?

    1 person found this answer helpful.

  2. Hani-Ng 13,460 Reputation points Microsoft External Staff Moderator
    2026-01-08T00:00:05.4166667+00:00

    Hi Jason Earhart

    Thank you for reaching out to Microsoft Q&A forum.

    Based on your description, I would like to share this official Microsoft Learn article, as the procedure is applicable to both Exchange 2019 and Exchange SE. You can follow the article below; the PowerShell commands listed there are fully compatible with Exchange SE. (Exchange 2013 has reached End of Support, as have Exchange 2016 and 2019. However, the architecture for the Federation Trust (and the Microsoft Federation Gateway) has remained consistent since those versions. Consequently, the steps utilized in previous versions are still the valid and supported method for Exchange SE).

    Renew the federation certificate: Exchange 2013 Help | Microsoft Learn

    If you are running Exchange SE in a Hybrid environment, the most reliable method to update this certificate is to download and run the latest Hybrid Configuration Wizard (HCW). The wizard is updated regularly to support Exchange SE and will automatically rotate the certificate for you, ensuring the trust with Entra ID (Azure AD) is maintained correctly.

    If you must perform this manually (for on-premises only scenarios), please use the PowerShell steps in the link above, as the Exchange Admin Center (EAC) in Exchange SE does not support this workflow.

    I hope this information is helpful, and if you need any additional details, please feel free to ask. I’m here to help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    Was this answer helpful?

    1 person found this answer helpful.

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.