MCT Summit Middle East 2021 - Exchange Hybrid - What, Why, and How

Thomas Stensitzki
Thomas StensitzkiCloud Native (MVP, MCSM, MCM, MCT, Blogger)
WHAT IS
EXCHANGE
HYBRID?
Thomas Stensitzki
Enterprise Consultant | Owner
Granikos GmbH & Co. KG
MVP | Office Apps & Services
MCT Regional Lead
Email thomas.stensitzki@granikos.eu
Twitter @Stensitzki
LinkedIn https://linkedin.com/in/thomasstensitzki
Blog http://JustCantGetEnough.Granikos.eu
Web https://www.stensitzki.de
What is Exchange Hybrid?
On-Premises Exchange Organization
Microsoft 365
Exchange Online
Hybrid Configuration
 Trusted relationship between an on-premises
Exchange Organization and Exchange Online
 Hybrid connections for mail flow (SMTP), and service
access (HTTPS) for Exchange hybrid functionality
 Hybrid Configuration Wizard (HCW) activates and
configures the hybrid mode of operation
What is Exchange Hybrid?
Hybrid Mode
Classic
Express Minimal Full
Modern
Minimal Full
Exchange Hybrid
Two Modes – Three Variants
On-Premises Exchange Organization
Hybrid
Configuration
Perimeter Network
Microsoft 365
Exchange Online Azure AD
Company Network
SMTP
HTTPS
 Active Directory Hybrid with Azure AD Connect
 Exchange Hybrid option enabled
 SMTP Connection between On-Premises and Exchange
Online
 Separate hostname (e.g., smtp365.company.com)
 Additional public IP address
 TLS certificate for hostname
 Edge Transport Role in perimeter network (1)
 Alternatively, direct inbound connection (2)
 Inbound HTTPS connection to Client Access Service
 Internal Exchange Servers published by a Reverse Proxy
 Requires additional public IP address
 Outbound HTTPS connections to Exchange Online
 Exchange Server communication to Exchange Online
Classic Full Hybrid
 Active Directory Hybrid with Azure AD Connect
 Exchange Hybrid option enabled
 SMTP Connection between On-Premises and Exchange
Online
 Separate hostname (e.g., smtp365.company.com)
 Additional public IP address
 TLS certificate for hostname
 Edge Transport Role in perimeter network (1)
 Alternatively, direct inbound connection (2)
 Outbound HTTPS connections to Exchange Online
 Exchange Hybrid-Agent
Exchange Online to Exchange on-premises communication
 Exchange Server communication to Exchange Online
 Install additional Hybrid-Agents for redundancy
Hybrid
Configuration
Perimeter Network
Microsoft 365
Exchange Online Azure AD
Company Network
On-Premises Exchange Organization
HTTPS
SMTP
Modern Full Hybrid
Full Full classic hybrid configuration, Exchange server published to the
internet (SMTP/HTTPS)
 permanent hybrid operation and Teams access to on-premises
Minimal Hybrid configuration, without rich coexistence to migrate
all on-premises mailboxes to Exchange Online
 temporary hybrid operation for a few weeks / months
Express Hybrid configuration, with Azure AD Connect Express settings, to
migrate all on-premises mailboxes to Exchange Online
 temporary hybrid operation for a few days / weeks
Full Full Modern Hybrid configuration, for new hybrid setups based on
Hybrid Agent deployment, with reduced hybrid functionality
 permanent hybrid operation
Minimal Modern Hybrid configuration, to migrate all on-premises mailboxes
to Exchange Online
 temporary hybrid operation for a few weeks / months
Exchange Hybrid
The Differences
Why do you need Exchange
Hybrid?
 Coexistence between your on-premises Exchange Organization and Exchange Online
 Mailbox migration to and from Exchange Online
 Seamless public folder migration to Exchange Online
 Microsoft Teams with on-premises mailboxes (calendar access)
 Transition from an on-premises Exchange Organization to Exchange Online
 Optimal migration experience for end users
 Centralized mail flow for use of on-premises email solutions with user mailboxes in Exchange Online
 Gateway-based S/MIME decryption/encryption, email disclaimer, archiving, journaling, …
 Hybrid mail flow providing email relay functionality for on-premises legacy applications and devices with
 No access to the internet
 No support for TLS protocols 1.0 or 1.1
 No support for SMTPAUTH user authentication
 No support for SMTP modern authentication
Why do you need Exchange Hybrid?
 On-Premises Exchange Server 2019 hybrid endpoint
 Microsoft Teams backend services use AutoDiscover v2 to discover on-premises EWS and REST endpoints
 Client Access Endpoint accessible for Microsoft Teams backend services
 Always use latest Exchange Server cumulative update
 In-Place upgrade capability for Exchange Server vNEXT (H2 2021)
 Use Third-Party TLS-certificate with all required subject alternate names (SAN) for incoming HTTPS connections
 AutoDiscover
 Exchange namespace  Exchange Virtual Directory’s external URL-Settings
 Use a dedicated Third-Party TLS-certificate for SMTP when using centralized mail flow
 Enable and configure OAUTH authentication using Hybrid Configuration Wizard
 Exchange team provides detailed information on how to configure OAUTH manually
 AutoDiscover DNS resource records for SMTP domains used for primary email addresses
 Use Exchange Server 2016 if you need a coexistence server only
Exchange Hybrid Recommendations
How to implement
Exchange Hybrid?
 Know the differences of the Exchange hybrid variants and modes of operation available
 Know the mode of operation for your Exchange Organization and hybrid requirements
 Have your on-premises Exchange organization ready for hybrid configuration
 Install latest Exchange Server Cumulative Updates on all Exchange Servers, including Edge Transport
 Have required IP addresses & DNS hostnames for the Exchange namespace set up
 Verify inbound connectivity to your Exchange organization using Remote Connectivity Analyzer (RCA)
 When your firewall policy is restricted for inbound traffic, add the RCA IP addresses to that policy  RCA release notes
 Have Edge Transport TLS certificates installed on internal an Exchange Server for selection by HCW, when using Edge
 Do NOT enable this certificate for any Exchange service
 Enable Exchange Hybrid option in Azure AD Connect first
Exchange Hybrid Requirtements
 Click-2-Run Setup
 https://aka.ms/HybridWizard
 .application file type requires mapping to Internet
Explorer
 Note the HCW version information
 Current: v17
 Uninstall v16 first
 HCW is updated regularly
 HCW downloads a newer version automatically when
started
 HCW configuration steps vary depending on your
Exchange Organization configuration
Hybrid Configuration Wizard
 HCW detects the optimal Exchange Server for
configuration automatically
 Specify a CAS server manually, if needed
 Select the appropriate Office 365 target infrastructure
 Office 365 Worldwide is the default for commercial
customers
Hybrid Configuration Wizard
On-Premises Organization
 HCW connects to on-premises Exchange and Exchange
Online to gather the current organizational configuration
 Adjust credentials as needed
  Check, if WinRM allows Basic Authentication
Hybrid Configuration Wizard
Gathering Organization Configuration
 Select hybrid features to configure
 Minimal Hybrid
 Full Hybrid
 Enable Organization Configuration Transfer
 One-time transfer of selected configuration objects
 Available objects depend on the on-premises Exchange
Server version
Hybrid Organization Configuration Transfer Documentation
Hybrid Configuration Wizard
Hybrid Features
 Select Hybrid Topology
 Exchange Classic Hybrid
 Exchange Modern Hybrid
 Modern Hybrid uses the Modern Hybrid Agent
 Azure Application Proxy-style component using HTTPS
outbound connectivity only
 Automatic download and installation of
 Hybrid Updater
 Hybrid Agent
 HCW uninstalls and unregisters the Modern Hybrid
Agent when switching from Modern Hybrid
Hybrid Configuration Wizard
Hybrid Topology
 Configure hybrid mail flow
 Direct to/from internal Exchange Servers
 Via Edge Transport Servers in perimeter network,
already subscribed to Active Directory site
 Centralized mail flow
 Route all mail flow to/from Exchange Online mailboxes
via on-premises Exchange Organization
Hybrid Configuration Wizard
Hybrid Mail Flow
 Select the Exchange server used for receiving email
messages from Exchange Online
 Select the Exchange Server published to the Internet
 HCW configures the default frontend receive connector
 HCW might select the wrong receive connector
 You use additional receive connectors with a remote IP
address range 0.0.0.0 – 255.255.255.255
 The default frontend connector uses individual remote
IP address ranges configuration
 Compare TlsCertificateName and TlsDomainCapabilities
connector properties afterwards
Hybrid Configuration Wizard
Receive Connector
 Select Exchange server for sending email messages
from the on-premises Exchange Organization to
Exchange Online
 HCW configures Send Connector
 Exchange Server needs outbound connectivity to
Exchange Online
 EdgeSync transfers the Edge Servers’ Send Connector
configuration (when using Edge Transport)
Hybrid Configuration Wizard
Send Connector
 Select TLS certificate to secure the trusted mail flow
between on-premises Exchange and Exchange Online
 With Edge Transport
 Ensure that the dedicated TLS certificate is installed in
the certificate store of one of the internal Exchange
servers
 Import the TLS certificate prior to executing HCW into
the local Exchange Server certificate store
 Do NOT enable the TLS certificate for any Exchange
service
 Avoid using NAT between Edge Transport Servers and
internal Exchange servers
 Do NOT use TLS intercepting SMTP proxy servers
Hybrid Configuration Wizard
Transport Certificate
 Enter the external FQDN of the Exchange Organization
for inbound SMTP
 Hostname should match TLS certificate
 Hybrid mail flow requires Exchange to Exchange
communication
 Recommendation for centralized mail flow
 Use a dedicated host name, IP address, and TLS
certificate
 Use Edge Transport Server(s)
Hybrid Configuration Wizard
Organization FQDN
 Update and wait
 If updating fails
 HCW provides full log files
 %appdata%RoamingMicrosoftExchange
Hybrid Configuration
 Log file contains all PowerShell configuration steps
 Use Remote Connectivity Analyzer to check inbound
connectivity
 Issues
 Remote connectivity
 Firewall policies, proxy servers, DNS
 WinRM Windows service configuration issues
Hybrid Configuration Wizard
Microsoft Teams and
Exchange Server
 Microsoft Teams Client communicates with Teams Middle-Tier, not with Exchange directly
 Microsoft Teams Middle-Tier contacts Exchange Online first
 If user mailbox is not in Exchange Online, the Teams Backend receives an HTTP 302 Redirect to On-Premises
 On-premises endpoint is always discovered using AutoDiscover v2
 Exchange Redirect requires AAD Connect synchronization with Exchange Hybrid option enabled
 Authentication requires OAuth between Exchange Server and Exchange Online / Azure AD
 Use Hybrid Configuration Wizard to configure OAuth (preferred)
 Microsoft Teams Backend requires communication with AutoDiscover, EWS, and REST endpoints
Microsoft Teams and Exchange Server
 When using many different SMTP domain names, you need a dedicated AutoDiscover v2 endpoint for each domain
 Microsoft Teams backend services do not handle an on-premises HTTP 302 redirect correctly
 Publish an AutoDiscover endpoint for each SMTP domain
 Use an edge router if you cannot add all domains to a single SAN certificate, e.g., Traeffic
 Check Microsoft Teams Coexistence mode with Skype for Business Online
 Only Island, Teams Only, or Skype for Business with Teams Collaboration and Meeting support the calendar tab
 Verify that the calendar tab is enabled in Teams App Policy
 Ensure that Exchange Hybrid is enabled in Azure AD Connect
Microsoft Teams and Exchange Server
Thomas Stensitzki
Enterprise Consultant | Owner
Granikos GmbH & Co. KG
MVP | Office Apps & Services
Email thomas.stensitzki@granikos.eu
Twitter @Stensitzki
LinkedIn https://linkedin.com/in/thomasstensitzki
Blog http://JustCantGetEnough.Granikos.eu
Web https://www.stensitzki.de
1 of 28

Recommended

Office 365 migration by
Office 365 migrationOffice 365 migration
Office 365 migrationMotty Ben Atia
6.8K views36 slides
Email edge security architecture EOP by
Email edge security architecture EOPEmail edge security architecture EOP
Email edge security architecture EOPAmmar Hasayen
2.1K views1 slide
Microsoft 365 and Microsoft Cloud App Security by
Microsoft 365 and Microsoft Cloud App SecurityMicrosoft 365 and Microsoft Cloud App Security
Microsoft 365 and Microsoft Cloud App SecurityAlbert Hoitingh
323 views18 slides
Az 104 session 3 azure compute by
Az 104 session 3 azure compute Az 104 session 3 azure compute
Az 104 session 3 azure compute AzureEzy1
12.9K views45 slides
Understanding Azure AD by
Understanding Azure ADUnderstanding Azure AD
Understanding Azure ADNew Horizons Ireland
3.9K views55 slides
Overview of Microsoft Exchange Online by
Overview of Microsoft Exchange OnlineOverview of Microsoft Exchange Online
Overview of Microsoft Exchange OnlineMicrosoft Private Cloud
8.6K views27 slides

More Related Content

What's hot

Microsoft 365 by
Microsoft 365Microsoft 365
Microsoft 365Jeannette Browning
2.6K views8 slides
Azure Security Overview by
Azure Security OverviewAzure Security Overview
Azure Security OverviewAllen Brokken
1.6K views44 slides
SCCM Intune Windows 10 Co Management Architecture Decisions by
SCCM Intune Windows 10 Co Management Architecture DecisionsSCCM Intune Windows 10 Co Management Architecture Decisions
SCCM Intune Windows 10 Co Management Architecture DecisionsAnoop Nair
3K views21 slides
Deep Dive on GSLB with VMware NSX Advanced Load Balancer (Avi Networks) by
Deep Dive on GSLB with VMware NSX Advanced Load Balancer (Avi Networks)Deep Dive on GSLB with VMware NSX Advanced Load Balancer (Avi Networks)
Deep Dive on GSLB with VMware NSX Advanced Load Balancer (Avi Networks)Avi Networks
1.4K views14 slides
Office 365 introduction and technical overview by
Office 365 introduction and technical overviewOffice 365 introduction and technical overview
Office 365 introduction and technical overviewMotty Ben Atia
18.3K views45 slides
Azure Cloud PPT by
Azure Cloud PPTAzure Cloud PPT
Azure Cloud PPTAniket Kanitkar
74.9K views13 slides

What's hot(20)

Azure Security Overview by Allen Brokken
Azure Security OverviewAzure Security Overview
Azure Security Overview
Allen Brokken1.6K views
SCCM Intune Windows 10 Co Management Architecture Decisions by Anoop Nair
SCCM Intune Windows 10 Co Management Architecture DecisionsSCCM Intune Windows 10 Co Management Architecture Decisions
SCCM Intune Windows 10 Co Management Architecture Decisions
Anoop Nair3K views
Deep Dive on GSLB with VMware NSX Advanced Load Balancer (Avi Networks) by Avi Networks
Deep Dive on GSLB with VMware NSX Advanced Load Balancer (Avi Networks)Deep Dive on GSLB with VMware NSX Advanced Load Balancer (Avi Networks)
Deep Dive on GSLB with VMware NSX Advanced Load Balancer (Avi Networks)
Avi Networks1.4K views
Office 365 introduction and technical overview by Motty Ben Atia
Office 365 introduction and technical overviewOffice 365 introduction and technical overview
Office 365 introduction and technical overview
Motty Ben Atia18.3K views
AWS Direct Connect: Deep Dive (NET403) - AWS re:Invent 2018 by Amazon Web Services
AWS Direct Connect: Deep Dive (NET403) - AWS re:Invent 2018AWS Direct Connect: Deep Dive (NET403) - AWS re:Invent 2018
AWS Direct Connect: Deep Dive (NET403) - AWS re:Invent 2018
Amazon Web Services4.6K views
Azure Information Protection by Robert Crane
Azure Information ProtectionAzure Information Protection
Azure Information Protection
Robert Crane6.2K views
Az 104 session 5: Azure networking by AzureEzy1
Az 104 session 5: Azure networkingAz 104 session 5: Azure networking
Az 104 session 5: Azure networking
AzureEzy112.1K views
Office 365 Mail migration strategies by Fulvio Salanitro
Office 365 Mail migration strategiesOffice 365 Mail migration strategies
Office 365 Mail migration strategies
Fulvio Salanitro3.5K views
Introduction to Azure by Robert Crane
Introduction to AzureIntroduction to Azure
Introduction to Azure
Robert Crane7.7K views
Azure security architecture by Karl Ots
Azure security architectureAzure security architecture
Azure security architecture
Karl Ots2.2K views
Jump-start your application migration to AWS with CloudEndure - STG305 - New ... by Amazon Web Services
Jump-start your application migration to AWS with CloudEndure - STG305 - New ...Jump-start your application migration to AWS with CloudEndure - STG305 - New ...
Jump-start your application migration to AWS with CloudEndure - STG305 - New ...
Amazon Web Services1.3K views
Microsoft 365 eEnterprise E5 Overview by David J Rosenthal
Microsoft 365 eEnterprise E5 OverviewMicrosoft 365 eEnterprise E5 Overview
Microsoft 365 eEnterprise E5 Overview
David J Rosenthal1.3K views
Microsoft M365 Cross Tenant Migration Book by Thomas Poett
Microsoft M365 Cross Tenant Migration BookMicrosoft M365 Cross Tenant Migration Book
Microsoft M365 Cross Tenant Migration Book
Thomas Poett1.8K views
Office 365: Migrating Your Business to Office 365! by Michael Frank
Office 365: Migrating Your Business to Office 365!Office 365: Migrating Your Business to Office 365!
Office 365: Migrating Your Business to Office 365!
Michael Frank3.8K views

Similar to MCT Summit Middle East 2021 - Exchange Hybrid - What, Why, and How

Exchange Server Hybrid - Was, Warum und Wie by
Exchange Server Hybrid - Was, Warum und WieExchange Server Hybrid - Was, Warum und Wie
Exchange Server Hybrid - Was, Warum und WieThomas Stensitzki
634 views30 slides
Microsoft Exchange 2013 Platform Options by
Microsoft Exchange 2013 Platform OptionsMicrosoft Exchange 2013 Platform Options
Microsoft Exchange 2013 Platform OptionsDavid J Rosenthal
822 views1 slide
Take a Leap into the Connected Cloud; 3 Trending Hybrid Cloud Scenarios by
Take a Leap into the Connected Cloud; 3 Trending Hybrid Cloud ScenariosTake a Leap into the Connected Cloud; 3 Trending Hybrid Cloud Scenarios
Take a Leap into the Connected Cloud; 3 Trending Hybrid Cloud ScenariosGina Montgomery, V-TSP
816 views41 slides
Session 1: The SOAP Story by
Session 1: The SOAP StorySession 1: The SOAP Story
Session 1: The SOAP Storyukdpe
581 views41 slides
10135 a 12 by
10135 a 1210135 a 12
10135 a 12Bố Su
814 views25 slides
1. WCF Services - Exam 70-487 by
1. WCF Services - Exam 70-4871. WCF Services - Exam 70-487
1. WCF Services - Exam 70-487Bat Programmer
2.2K views51 slides

Similar to MCT Summit Middle East 2021 - Exchange Hybrid - What, Why, and How(20)

Exchange Server Hybrid - Was, Warum und Wie by Thomas Stensitzki
Exchange Server Hybrid - Was, Warum und WieExchange Server Hybrid - Was, Warum und Wie
Exchange Server Hybrid - Was, Warum und Wie
Thomas Stensitzki634 views
Microsoft Exchange 2013 Platform Options by David J Rosenthal
Microsoft Exchange 2013 Platform OptionsMicrosoft Exchange 2013 Platform Options
Microsoft Exchange 2013 Platform Options
David J Rosenthal822 views
Take a Leap into the Connected Cloud; 3 Trending Hybrid Cloud Scenarios by Gina Montgomery, V-TSP
Take a Leap into the Connected Cloud; 3 Trending Hybrid Cloud ScenariosTake a Leap into the Connected Cloud; 3 Trending Hybrid Cloud Scenarios
Take a Leap into the Connected Cloud; 3 Trending Hybrid Cloud Scenarios
Session 1: The SOAP Story by ukdpe
Session 1: The SOAP StorySession 1: The SOAP Story
Session 1: The SOAP Story
ukdpe581 views
10135 a 12 by Bố Su
10135 a 1210135 a 12
10135 a 12
Bố Su814 views
1. WCF Services - Exam 70-487 by Bat Programmer
1. WCF Services - Exam 70-4871. WCF Services - Exam 70-487
1. WCF Services - Exam 70-487
Bat Programmer2.2K views
Application integration framework & Adaptor ppt by Aditya Negi
Application integration framework & Adaptor pptApplication integration framework & Adaptor ppt
Application integration framework & Adaptor ppt
Aditya Negi1.5K views
Office Track: Exchange 2013 in the real world - Michael Van Horenbeeck by ITProceed
Office Track: Exchange 2013 in the real world - Michael Van HorenbeeckOffice Track: Exchange 2013 in the real world - Michael Van Horenbeeck
Office Track: Exchange 2013 in the real world - Michael Van Horenbeeck
ITProceed976 views
WCF Fundamentals by Safaa Farouk
WCF Fundamentals WCF Fundamentals
WCF Fundamentals
Safaa Farouk1.3K views
24 Hours Of Exchange Server 2007 ( Part 15 Of 24) by Harold Wong
24  Hours Of  Exchange  Server 2007 ( Part 15 Of 24)24  Hours Of  Exchange  Server 2007 ( Part 15 Of 24)
24 Hours Of Exchange Server 2007 ( Part 15 Of 24)
Harold Wong599 views
10135 a xb by Bố Su
10135 a xb10135 a xb
10135 a xb
Bố Su543 views
Network Setup Guide: Deploying Your Cloudian HyperStore Hybrid Storage Service by Cloudian
Network Setup Guide: Deploying Your Cloudian HyperStore Hybrid Storage ServiceNetwork Setup Guide: Deploying Your Cloudian HyperStore Hybrid Storage Service
Network Setup Guide: Deploying Your Cloudian HyperStore Hybrid Storage Service
Cloudian1.8K views
Bpos Architectural Consideration Architectural Forum by ukdpe
Bpos   Architectural Consideration   Architectural ForumBpos   Architectural Consideration   Architectural Forum
Bpos Architectural Consideration Architectural Forum
ukdpe2.1K views
The Hitchhiker’s Guide to Hybrid Connectivity by Daniel Toomey
The Hitchhiker’s Guide to Hybrid ConnectivityThe Hitchhiker’s Guide to Hybrid Connectivity
The Hitchhiker’s Guide to Hybrid Connectivity
Daniel Toomey1.5K views
Exchange 2003 / 2010 Notes from the Field by Dave Kawula
Exchange 2003 / 2010 Notes from the FieldExchange 2003 / 2010 Notes from the Field
Exchange 2003 / 2010 Notes from the Field
Dave Kawula1.5K views
Exchange online real world migration challenges by Steve Goodman
Exchange online real world migration challengesExchange online real world migration challenges
Exchange online real world migration challenges
Steve Goodman8.7K views
Integration on windows azure by Sam Vanhoutte
Integration on windows azureIntegration on windows azure
Integration on windows azure
Sam Vanhoutte1.7K views
HP: Implementácia cloudu s HP by ASBIS SK
HP: Implementácia cloudu s HPHP: Implementácia cloudu s HP
HP: Implementácia cloudu s HP
ASBIS SK447 views

More from Thomas Stensitzki

19. Treffen der Teams User Group Berlin by
19. Treffen der Teams User Group Berlin19. Treffen der Teams User Group Berlin
19. Treffen der Teams User Group BerlinThomas Stensitzki
62 views57 slides
18. Treffen der Teams User Group Berlin by
18. Treffen der Teams User Group Berlin18. Treffen der Teams User Group Berlin
18. Treffen der Teams User Group BerlinThomas Stensitzki
85 views24 slides
Teams Nation 2022 - Securing Microsoft 365 data with service encryption by
Teams Nation 2022 - Securing Microsoft 365 data with service encryptionTeams Nation 2022 - Securing Microsoft 365 data with service encryption
Teams Nation 2022 - Securing Microsoft 365 data with service encryptionThomas Stensitzki
226 views43 slides
17. Treffen der Teams User Group Berlin by
17. Treffen der Teams User Group Berlin17. Treffen der Teams User Group Berlin
17. Treffen der Teams User Group BerlinThomas Stensitzki
97 views57 slides
16. Treffen der Teams User Group Berlin by
16. Treffen der Teams User Group Berlin16. Treffen der Teams User Group Berlin
16. Treffen der Teams User Group BerlinThomas Stensitzki
153 views58 slides
EXUSG - 2021 - Q4 - Exchange Emergency Mitigation Service by
EXUSG - 2021 - Q4 - Exchange Emergency Mitigation ServiceEXUSG - 2021 - Q4 - Exchange Emergency Mitigation Service
EXUSG - 2021 - Q4 - Exchange Emergency Mitigation ServiceThomas Stensitzki
157 views19 slides

More from Thomas Stensitzki(20)

Teams Nation 2022 - Securing Microsoft 365 data with service encryption by Thomas Stensitzki
Teams Nation 2022 - Securing Microsoft 365 data with service encryptionTeams Nation 2022 - Securing Microsoft 365 data with service encryption
Teams Nation 2022 - Securing Microsoft 365 data with service encryption
Thomas Stensitzki226 views
EXUSG - 2021 - Q4 - Exchange Emergency Mitigation Service by Thomas Stensitzki
EXUSG - 2021 - Q4 - Exchange Emergency Mitigation ServiceEXUSG - 2021 - Q4 - Exchange Emergency Mitigation Service
EXUSG - 2021 - Q4 - Exchange Emergency Mitigation Service
Thomas Stensitzki157 views
Tech Talk 13 - Teams Admin Center - Einführung by Thomas Stensitzki
Tech Talk 13 - Teams Admin Center - EinführungTech Talk 13 - Teams Admin Center - Einführung
Tech Talk 13 - Teams Admin Center - Einführung
Thomas Stensitzki108 views
Tech Talk 12 - Exchange Server Support Life-Cycle by Thomas Stensitzki
Tech Talk 12 - Exchange Server Support Life-CycleTech Talk 12 - Exchange Server Support Life-Cycle
Tech Talk 12 - Exchange Server Support Life-Cycle
Thomas Stensitzki157 views
Thomas' Tech Talk 4 - Lohnt sich ein Wechsel zu Exchange Server 2019? by Thomas Stensitzki
Thomas' Tech Talk 4 - Lohnt sich ein Wechsel zu Exchange Server 2019?Thomas' Tech Talk 4 - Lohnt sich ein Wechsel zu Exchange Server 2019?
Thomas' Tech Talk 4 - Lohnt sich ein Wechsel zu Exchange Server 2019?
Thomas Stensitzki148 views
Thomas' Tech Talk 3 - Exchange Server Hybrid by Thomas Stensitzki
Thomas' Tech Talk 3 - Exchange Server HybridThomas' Tech Talk 3 - Exchange Server Hybrid
Thomas' Tech Talk 3 - Exchange Server Hybrid
Thomas Stensitzki177 views
Thomas' Tech Talk 2 - Migration von Exchange Server zu Exchange Online by Thomas Stensitzki
Thomas' Tech Talk 2 - Migration von Exchange Server zu Exchange OnlineThomas' Tech Talk 2 - Migration von Exchange Server zu Exchange Online
Thomas' Tech Talk 2 - Migration von Exchange Server zu Exchange Online
Thomas Stensitzki136 views
Externe Dienstleister und sicherer E-Mail-Versand by Thomas Stensitzki
Externe Dienstleister und sicherer E-Mail-VersandExterne Dienstleister und sicherer E-Mail-Versand
Externe Dienstleister und sicherer E-Mail-Versand
Thomas Stensitzki770 views
6. Treffen der Teams Meetup Gruppe Berlin by Thomas Stensitzki
6. Treffen der Teams Meetup Gruppe Berlin6. Treffen der Teams Meetup Gruppe Berlin
6. Treffen der Teams Meetup Gruppe Berlin
Thomas Stensitzki327 views

Recently uploaded

Keynote Talk: Open Source is Not Dead - Charles Schulz - Vates by
Keynote Talk: Open Source is Not Dead - Charles Schulz - VatesKeynote Talk: Open Source is Not Dead - Charles Schulz - Vates
Keynote Talk: Open Source is Not Dead - Charles Schulz - VatesShapeBlue
178 views15 slides
What’s New in CloudStack 4.19 - Abhishek Kumar - ShapeBlue by
What’s New in CloudStack 4.19 - Abhishek Kumar - ShapeBlueWhat’s New in CloudStack 4.19 - Abhishek Kumar - ShapeBlue
What’s New in CloudStack 4.19 - Abhishek Kumar - ShapeBlueShapeBlue
191 views23 slides
Migrating VMware Infra to KVM Using CloudStack - Nicolas Vazquez - ShapeBlue by
Migrating VMware Infra to KVM Using CloudStack - Nicolas Vazquez - ShapeBlueMigrating VMware Infra to KVM Using CloudStack - Nicolas Vazquez - ShapeBlue
Migrating VMware Infra to KVM Using CloudStack - Nicolas Vazquez - ShapeBlueShapeBlue
147 views20 slides
Elevating Privacy and Security in CloudStack - Boris Stoyanov - ShapeBlue by
Elevating Privacy and Security in CloudStack - Boris Stoyanov - ShapeBlueElevating Privacy and Security in CloudStack - Boris Stoyanov - ShapeBlue
Elevating Privacy and Security in CloudStack - Boris Stoyanov - ShapeBlueShapeBlue
149 views7 slides
VNF Integration and Support in CloudStack - Wei Zhou - ShapeBlue by
VNF Integration and Support in CloudStack - Wei Zhou - ShapeBlueVNF Integration and Support in CloudStack - Wei Zhou - ShapeBlue
VNF Integration and Support in CloudStack - Wei Zhou - ShapeBlueShapeBlue
134 views54 slides
Ransomware is Knocking your Door_Final.pdf by
Ransomware is Knocking your Door_Final.pdfRansomware is Knocking your Door_Final.pdf
Ransomware is Knocking your Door_Final.pdfSecurity Bootcamp
81 views46 slides

Recently uploaded(20)

Keynote Talk: Open Source is Not Dead - Charles Schulz - Vates by ShapeBlue
Keynote Talk: Open Source is Not Dead - Charles Schulz - VatesKeynote Talk: Open Source is Not Dead - Charles Schulz - Vates
Keynote Talk: Open Source is Not Dead - Charles Schulz - Vates
ShapeBlue178 views
What’s New in CloudStack 4.19 - Abhishek Kumar - ShapeBlue by ShapeBlue
What’s New in CloudStack 4.19 - Abhishek Kumar - ShapeBlueWhat’s New in CloudStack 4.19 - Abhishek Kumar - ShapeBlue
What’s New in CloudStack 4.19 - Abhishek Kumar - ShapeBlue
ShapeBlue191 views
Migrating VMware Infra to KVM Using CloudStack - Nicolas Vazquez - ShapeBlue by ShapeBlue
Migrating VMware Infra to KVM Using CloudStack - Nicolas Vazquez - ShapeBlueMigrating VMware Infra to KVM Using CloudStack - Nicolas Vazquez - ShapeBlue
Migrating VMware Infra to KVM Using CloudStack - Nicolas Vazquez - ShapeBlue
ShapeBlue147 views
Elevating Privacy and Security in CloudStack - Boris Stoyanov - ShapeBlue by ShapeBlue
Elevating Privacy and Security in CloudStack - Boris Stoyanov - ShapeBlueElevating Privacy and Security in CloudStack - Boris Stoyanov - ShapeBlue
Elevating Privacy and Security in CloudStack - Boris Stoyanov - ShapeBlue
ShapeBlue149 views
VNF Integration and Support in CloudStack - Wei Zhou - ShapeBlue by ShapeBlue
VNF Integration and Support in CloudStack - Wei Zhou - ShapeBlueVNF Integration and Support in CloudStack - Wei Zhou - ShapeBlue
VNF Integration and Support in CloudStack - Wei Zhou - ShapeBlue
ShapeBlue134 views
Developments to CloudStack’s SDN ecosystem: Integration with VMWare NSX 4 - P... by ShapeBlue
Developments to CloudStack’s SDN ecosystem: Integration with VMWare NSX 4 - P...Developments to CloudStack’s SDN ecosystem: Integration with VMWare NSX 4 - P...
Developments to CloudStack’s SDN ecosystem: Integration with VMWare NSX 4 - P...
ShapeBlue120 views
State of the Union - Rohit Yadav - Apache CloudStack by ShapeBlue
State of the Union - Rohit Yadav - Apache CloudStackState of the Union - Rohit Yadav - Apache CloudStack
State of the Union - Rohit Yadav - Apache CloudStack
ShapeBlue218 views
Zero to Cloud Hero: Crafting a Private Cloud from Scratch with XCP-ng, Xen Or... by ShapeBlue
Zero to Cloud Hero: Crafting a Private Cloud from Scratch with XCP-ng, Xen Or...Zero to Cloud Hero: Crafting a Private Cloud from Scratch with XCP-ng, Xen Or...
Zero to Cloud Hero: Crafting a Private Cloud from Scratch with XCP-ng, Xen Or...
ShapeBlue128 views
Future of AR - Facebook Presentation by Rob McCarty
Future of AR - Facebook PresentationFuture of AR - Facebook Presentation
Future of AR - Facebook Presentation
Rob McCarty54 views
Import Export Virtual Machine for KVM Hypervisor - Ayush Pandey - University ... by ShapeBlue
Import Export Virtual Machine for KVM Hypervisor - Ayush Pandey - University ...Import Export Virtual Machine for KVM Hypervisor - Ayush Pandey - University ...
Import Export Virtual Machine for KVM Hypervisor - Ayush Pandey - University ...
ShapeBlue48 views
Extending KVM Host HA for Non-NFS Storage - Alex Ivanov - StorPool by ShapeBlue
Extending KVM Host HA for Non-NFS Storage -  Alex Ivanov - StorPoolExtending KVM Host HA for Non-NFS Storage -  Alex Ivanov - StorPool
Extending KVM Host HA for Non-NFS Storage - Alex Ivanov - StorPool
ShapeBlue56 views
Centralized Logging Feature in CloudStack using ELK and Grafana - Kiran Chava... by ShapeBlue
Centralized Logging Feature in CloudStack using ELK and Grafana - Kiran Chava...Centralized Logging Feature in CloudStack using ELK and Grafana - Kiran Chava...
Centralized Logging Feature in CloudStack using ELK and Grafana - Kiran Chava...
ShapeBlue74 views
How to Re-use Old Hardware with CloudStack. Saving Money and the Environment ... by ShapeBlue
How to Re-use Old Hardware with CloudStack. Saving Money and the Environment ...How to Re-use Old Hardware with CloudStack. Saving Money and the Environment ...
How to Re-use Old Hardware with CloudStack. Saving Money and the Environment ...
ShapeBlue97 views
Updates on the LINSTOR Driver for CloudStack - Rene Peinthor - LINBIT by ShapeBlue
Updates on the LINSTOR Driver for CloudStack - Rene Peinthor - LINBITUpdates on the LINSTOR Driver for CloudStack - Rene Peinthor - LINBIT
Updates on the LINSTOR Driver for CloudStack - Rene Peinthor - LINBIT
ShapeBlue138 views
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f... by TrustArc
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc130 views
Transitioning from VMware vCloud to Apache CloudStack: A Path to Profitabilit... by ShapeBlue
Transitioning from VMware vCloud to Apache CloudStack: A Path to Profitabilit...Transitioning from VMware vCloud to Apache CloudStack: A Path to Profitabilit...
Transitioning from VMware vCloud to Apache CloudStack: A Path to Profitabilit...
ShapeBlue86 views
Live Demo Showcase: Unveiling Dell PowerFlex’s IaaS Capabilities with Apache ... by ShapeBlue
Live Demo Showcase: Unveiling Dell PowerFlex’s IaaS Capabilities with Apache ...Live Demo Showcase: Unveiling Dell PowerFlex’s IaaS Capabilities with Apache ...
Live Demo Showcase: Unveiling Dell PowerFlex’s IaaS Capabilities with Apache ...
ShapeBlue52 views

MCT Summit Middle East 2021 - Exchange Hybrid - What, Why, and How

  • 2. Thomas Stensitzki Enterprise Consultant | Owner Granikos GmbH & Co. KG MVP | Office Apps & Services MCT Regional Lead Email thomas.stensitzki@granikos.eu Twitter @Stensitzki LinkedIn https://linkedin.com/in/thomasstensitzki Blog http://JustCantGetEnough.Granikos.eu Web https://www.stensitzki.de
  • 4. On-Premises Exchange Organization Microsoft 365 Exchange Online Hybrid Configuration  Trusted relationship between an on-premises Exchange Organization and Exchange Online  Hybrid connections for mail flow (SMTP), and service access (HTTPS) for Exchange hybrid functionality  Hybrid Configuration Wizard (HCW) activates and configures the hybrid mode of operation What is Exchange Hybrid?
  • 5. Hybrid Mode Classic Express Minimal Full Modern Minimal Full Exchange Hybrid Two Modes – Three Variants
  • 6. On-Premises Exchange Organization Hybrid Configuration Perimeter Network Microsoft 365 Exchange Online Azure AD Company Network SMTP HTTPS  Active Directory Hybrid with Azure AD Connect  Exchange Hybrid option enabled  SMTP Connection between On-Premises and Exchange Online  Separate hostname (e.g., smtp365.company.com)  Additional public IP address  TLS certificate for hostname  Edge Transport Role in perimeter network (1)  Alternatively, direct inbound connection (2)  Inbound HTTPS connection to Client Access Service  Internal Exchange Servers published by a Reverse Proxy  Requires additional public IP address  Outbound HTTPS connections to Exchange Online  Exchange Server communication to Exchange Online Classic Full Hybrid
  • 7.  Active Directory Hybrid with Azure AD Connect  Exchange Hybrid option enabled  SMTP Connection between On-Premises and Exchange Online  Separate hostname (e.g., smtp365.company.com)  Additional public IP address  TLS certificate for hostname  Edge Transport Role in perimeter network (1)  Alternatively, direct inbound connection (2)  Outbound HTTPS connections to Exchange Online  Exchange Hybrid-Agent Exchange Online to Exchange on-premises communication  Exchange Server communication to Exchange Online  Install additional Hybrid-Agents for redundancy Hybrid Configuration Perimeter Network Microsoft 365 Exchange Online Azure AD Company Network On-Premises Exchange Organization HTTPS SMTP Modern Full Hybrid
  • 8. Full Full classic hybrid configuration, Exchange server published to the internet (SMTP/HTTPS)  permanent hybrid operation and Teams access to on-premises Minimal Hybrid configuration, without rich coexistence to migrate all on-premises mailboxes to Exchange Online  temporary hybrid operation for a few weeks / months Express Hybrid configuration, with Azure AD Connect Express settings, to migrate all on-premises mailboxes to Exchange Online  temporary hybrid operation for a few days / weeks Full Full Modern Hybrid configuration, for new hybrid setups based on Hybrid Agent deployment, with reduced hybrid functionality  permanent hybrid operation Minimal Modern Hybrid configuration, to migrate all on-premises mailboxes to Exchange Online  temporary hybrid operation for a few weeks / months Exchange Hybrid The Differences
  • 9. Why do you need Exchange Hybrid?
  • 10.  Coexistence between your on-premises Exchange Organization and Exchange Online  Mailbox migration to and from Exchange Online  Seamless public folder migration to Exchange Online  Microsoft Teams with on-premises mailboxes (calendar access)  Transition from an on-premises Exchange Organization to Exchange Online  Optimal migration experience for end users  Centralized mail flow for use of on-premises email solutions with user mailboxes in Exchange Online  Gateway-based S/MIME decryption/encryption, email disclaimer, archiving, journaling, …  Hybrid mail flow providing email relay functionality for on-premises legacy applications and devices with  No access to the internet  No support for TLS protocols 1.0 or 1.1  No support for SMTPAUTH user authentication  No support for SMTP modern authentication Why do you need Exchange Hybrid?
  • 11.  On-Premises Exchange Server 2019 hybrid endpoint  Microsoft Teams backend services use AutoDiscover v2 to discover on-premises EWS and REST endpoints  Client Access Endpoint accessible for Microsoft Teams backend services  Always use latest Exchange Server cumulative update  In-Place upgrade capability for Exchange Server vNEXT (H2 2021)  Use Third-Party TLS-certificate with all required subject alternate names (SAN) for incoming HTTPS connections  AutoDiscover  Exchange namespace  Exchange Virtual Directory’s external URL-Settings  Use a dedicated Third-Party TLS-certificate for SMTP when using centralized mail flow  Enable and configure OAUTH authentication using Hybrid Configuration Wizard  Exchange team provides detailed information on how to configure OAUTH manually  AutoDiscover DNS resource records for SMTP domains used for primary email addresses  Use Exchange Server 2016 if you need a coexistence server only Exchange Hybrid Recommendations
  • 13.  Know the differences of the Exchange hybrid variants and modes of operation available  Know the mode of operation for your Exchange Organization and hybrid requirements  Have your on-premises Exchange organization ready for hybrid configuration  Install latest Exchange Server Cumulative Updates on all Exchange Servers, including Edge Transport  Have required IP addresses & DNS hostnames for the Exchange namespace set up  Verify inbound connectivity to your Exchange organization using Remote Connectivity Analyzer (RCA)  When your firewall policy is restricted for inbound traffic, add the RCA IP addresses to that policy  RCA release notes  Have Edge Transport TLS certificates installed on internal an Exchange Server for selection by HCW, when using Edge  Do NOT enable this certificate for any Exchange service  Enable Exchange Hybrid option in Azure AD Connect first Exchange Hybrid Requirtements
  • 14.  Click-2-Run Setup  https://aka.ms/HybridWizard  .application file type requires mapping to Internet Explorer  Note the HCW version information  Current: v17  Uninstall v16 first  HCW is updated regularly  HCW downloads a newer version automatically when started  HCW configuration steps vary depending on your Exchange Organization configuration Hybrid Configuration Wizard
  • 15.  HCW detects the optimal Exchange Server for configuration automatically  Specify a CAS server manually, if needed  Select the appropriate Office 365 target infrastructure  Office 365 Worldwide is the default for commercial customers Hybrid Configuration Wizard On-Premises Organization
  • 16.  HCW connects to on-premises Exchange and Exchange Online to gather the current organizational configuration  Adjust credentials as needed   Check, if WinRM allows Basic Authentication Hybrid Configuration Wizard Gathering Organization Configuration
  • 17.  Select hybrid features to configure  Minimal Hybrid  Full Hybrid  Enable Organization Configuration Transfer  One-time transfer of selected configuration objects  Available objects depend on the on-premises Exchange Server version Hybrid Organization Configuration Transfer Documentation Hybrid Configuration Wizard Hybrid Features
  • 18.  Select Hybrid Topology  Exchange Classic Hybrid  Exchange Modern Hybrid  Modern Hybrid uses the Modern Hybrid Agent  Azure Application Proxy-style component using HTTPS outbound connectivity only  Automatic download and installation of  Hybrid Updater  Hybrid Agent  HCW uninstalls and unregisters the Modern Hybrid Agent when switching from Modern Hybrid Hybrid Configuration Wizard Hybrid Topology
  • 19.  Configure hybrid mail flow  Direct to/from internal Exchange Servers  Via Edge Transport Servers in perimeter network, already subscribed to Active Directory site  Centralized mail flow  Route all mail flow to/from Exchange Online mailboxes via on-premises Exchange Organization Hybrid Configuration Wizard Hybrid Mail Flow
  • 20.  Select the Exchange server used for receiving email messages from Exchange Online  Select the Exchange Server published to the Internet  HCW configures the default frontend receive connector  HCW might select the wrong receive connector  You use additional receive connectors with a remote IP address range 0.0.0.0 – 255.255.255.255  The default frontend connector uses individual remote IP address ranges configuration  Compare TlsCertificateName and TlsDomainCapabilities connector properties afterwards Hybrid Configuration Wizard Receive Connector
  • 21.  Select Exchange server for sending email messages from the on-premises Exchange Organization to Exchange Online  HCW configures Send Connector  Exchange Server needs outbound connectivity to Exchange Online  EdgeSync transfers the Edge Servers’ Send Connector configuration (when using Edge Transport) Hybrid Configuration Wizard Send Connector
  • 22.  Select TLS certificate to secure the trusted mail flow between on-premises Exchange and Exchange Online  With Edge Transport  Ensure that the dedicated TLS certificate is installed in the certificate store of one of the internal Exchange servers  Import the TLS certificate prior to executing HCW into the local Exchange Server certificate store  Do NOT enable the TLS certificate for any Exchange service  Avoid using NAT between Edge Transport Servers and internal Exchange servers  Do NOT use TLS intercepting SMTP proxy servers Hybrid Configuration Wizard Transport Certificate
  • 23.  Enter the external FQDN of the Exchange Organization for inbound SMTP  Hostname should match TLS certificate  Hybrid mail flow requires Exchange to Exchange communication  Recommendation for centralized mail flow  Use a dedicated host name, IP address, and TLS certificate  Use Edge Transport Server(s) Hybrid Configuration Wizard Organization FQDN
  • 24.  Update and wait  If updating fails  HCW provides full log files  %appdata%RoamingMicrosoftExchange Hybrid Configuration  Log file contains all PowerShell configuration steps  Use Remote Connectivity Analyzer to check inbound connectivity  Issues  Remote connectivity  Firewall policies, proxy servers, DNS  WinRM Windows service configuration issues Hybrid Configuration Wizard
  • 26.  Microsoft Teams Client communicates with Teams Middle-Tier, not with Exchange directly  Microsoft Teams Middle-Tier contacts Exchange Online first  If user mailbox is not in Exchange Online, the Teams Backend receives an HTTP 302 Redirect to On-Premises  On-premises endpoint is always discovered using AutoDiscover v2  Exchange Redirect requires AAD Connect synchronization with Exchange Hybrid option enabled  Authentication requires OAuth between Exchange Server and Exchange Online / Azure AD  Use Hybrid Configuration Wizard to configure OAuth (preferred)  Microsoft Teams Backend requires communication with AutoDiscover, EWS, and REST endpoints Microsoft Teams and Exchange Server
  • 27.  When using many different SMTP domain names, you need a dedicated AutoDiscover v2 endpoint for each domain  Microsoft Teams backend services do not handle an on-premises HTTP 302 redirect correctly  Publish an AutoDiscover endpoint for each SMTP domain  Use an edge router if you cannot add all domains to a single SAN certificate, e.g., Traeffic  Check Microsoft Teams Coexistence mode with Skype for Business Online  Only Island, Teams Only, or Skype for Business with Teams Collaboration and Meeting support the calendar tab  Verify that the calendar tab is enabled in Teams App Policy  Ensure that Exchange Hybrid is enabled in Azure AD Connect Microsoft Teams and Exchange Server
  • 28. Thomas Stensitzki Enterprise Consultant | Owner Granikos GmbH & Co. KG MVP | Office Apps & Services Email thomas.stensitzki@granikos.eu Twitter @Stensitzki LinkedIn https://linkedin.com/in/thomasstensitzki Blog http://JustCantGetEnough.Granikos.eu Web https://www.stensitzki.de