Microsoft 365

Hybrid Configuration Wizard errors and fixes with Exchange Server SE

Fix the Hybrid Configuration Wizard failures you hit with Exchange Server SE: TLS, HCW8001, HCW8057, HCW8078, HCW8064 and the dedicated Exchange hybrid app that rich coexistence now needs.

11 min read
On this page

Most Hybrid Configuration Wizard (HCW) failures with Exchange Server SE come from a short list of causes: TLS 1.2 disabled for WinHTTP on the machine running the wizard, Autodiscover or EWS not reachable from Exchange Online (HCW8057 and HCW8034), directory synchronization switched off in the tenant (HCW8001), migration endpoint creation being throttled (HCW8078), or the OAuth step failing (HCW8064). On top of that, rich coexistence now depends on the dedicated Exchange hybrid application in Microsoft Entra ID, which the HCW creates but doesn't enable, so free/busy can break even when the wizard reports success.

Who this is for and what you will have at the end

This guide is for administrators running the HCW against Exchange Server Subscription Edition (SE), either for a new hybrid deployment or a rerun after upgrading from Exchange 2016 or 2019. Use it when the wizard stops with an HCW error code, finishes with a warning, or completes but leaves free/busy, MailTips or migrations broken.

At the end you will have:

  • The error matched to its documented cause and fix.
  • The dedicated Exchange hybrid application created, enabled and verified.
  • A way to rerun only the failing part of the HCW without resetting the rest of your hybrid configuration.

Once the wizard succeeds, mailbox moves are covered in the hybrid remote move migration guide, and the connectors the HCW creates are explained in the Exchange Online connectors guide.

What changed for hybrid with Exchange Server SE

Exchange Server used to authenticate to Exchange Online through a shared, first-party service principal, and the HCW uploaded your Auth Certificate to it. That model is gone:

  • As of October 31, 2025, EWS access through the shared service principal is permanently blocked. Free/busy, MailTips and profile picture sharing only work through a dedicated Exchange hybrid application (ExchangeServerApp-{organization GUID}) registered in your tenant.
  • The HCW now deploys this application by default, adding the full_access_as_app EWS permission, asking you to grant tenant-wide admin consent, and uploading the current and next Auth Certificates.
  • The HCW does not turn the feature on in your Exchange organization. You must create a setting override afterwards.
  • Starting with the May 2026 Hotfix Update for Exchange Server SE, the dedicated app can use Microsoft Graph API permissions instead of EWS for most hybrid scenarios.

Supported builds for the dedicated app:

VersionBuildEWS-based flowGraph-based flow
Exchange Server SE RTM with May 2026 HU15.2.2562.41YesYes
Exchange Server SE RTM15.2.2562.17YesNo
Exchange Server 2019 CU15 with April 2025 HU15.2.1748.24YesNo
Exchange Server 2019 CU14 with April 2025 HU15.2.1544.25YesNo
Exchange Server 2016 CU23 with April 2025 HU15.1.2507.55YesNo

Servers on older builds can't use rich coexistence at all, whatever you do in the wizard.

Prerequisites before you rerun the wizard

  • The latest HCW from https://aka.ms/HybridWizard. The dedicated app and the Choose Exchange Hybrid Configuration options described here are in the latest version.
  • Permissions. On-premises, the account must be in the Organization Management role group. In Exchange Online, Global Administrator is required the first time you configure hybrid and for the OAuth and dedicated application options; most other granular options need Exchange Administrator for Classic Hybrid.
  • Certificates. A certificate from a trusted public CA on the IIS and transport services of the hybrid servers, with the EWS external URL and Autodiscover name in the SAN. A valid Auth Certificate for OAuth.
  • Publishing. Exchange Online must reach /autodiscover/autodiscover.svc, /autodiscover/autodiscover.svc/wssecurity, /ews/exchange.asmx/wssecurity and /ews/mrsproxy.svc over TCP 443, without pre-authentication on any reverse proxy.
  • Outbound access. For the dedicated app, the server running the configuration needs login.microsoftonline.com and graph.microsoft.com on port 443. Exchange servers also need outbound HTTP to ctldl.windowsupdate.com so Windows can maintain the Certificate Trust List.
  • Directory synchronization with Microsoft Entra Connect or Cloud Sync.

Check outbound connectivity from the Exchange server before you start:

Test-NetConnection -ComputerName login.microsoftonline.com -Port 443
Test-NetConnection -ComputerName graph.microsoft.com -Port 443

Step 1: Read the log before changing anything

All HCW changes are logged on the server where you ran the wizard, by default in:

%UserProfile%\AppData\Roaming\Microsoft\Exchange Hybrid Configuration

Open the newest log and search for HCW8 and ERROR. The lines just before the error show which cmdlet failed (for example New-AuthServer, New-MigrationEndpoint or Set-OrganizationRelationship), which tells you which configuration area to fix. While the wizard is open, F12 opens the HCW Diagnostic Tools pane. Its Open Exchange Online PowerShell option is useful for reproducing connection errors such as the TLS failure below.

Step 2: Fix the error you actually have

The wizard can't connect to Office 365

Symptom:

Connecting to remote server outlook.office365.com failed with the following error message: The server certificate on the destination computer (outlook.office365.com:443) has the following errors: Encountered an internal error in the SSL library.

Microsoft 365 accepts only TLS 1.2, and the wizard's PowerShell session uses WinHTTP. On Windows Server 2012 R2 and later, TLS 1.2 is on by default, so look for a custom policy that disabled it. If WinHTTP needs it explicitly, add a DefaultSecureProtocols DWORD with the value 0x00000800 (TLS 1.2) under:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WinHttp
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\WinHttp

Back up the registry first, and check that TLS 1.2 is also enabled at the operating system level.

HCW8001: Unable to determine the Tenant Routing Domain

The log shows Unable to determine the routing domain for the cloud organization. The cause is that directory synchronization is disabled in the tenant; the contoso.mail.onmicrosoft.com routing domain is created when it's enabled. With a Global Administrator account:

Install-Module -Name Microsoft.Entra -Repository PSGallery -Scope CurrentUser -Force -AllowClobber
Connect-Entra -Scopes 'OnPremDirectorySynchronization.ReadWrite.All', 'Organization.ReadWrite.All'
Set-EntraDirSyncEnabled -EnableDirSync $true -Force

HCW8057 or HCW8034: Autodiscover can't be reached

HCW8057 Office 365 was unable to communicate with your on-premises Autodiscover endpoint. This is typically due to incorrect DNS or firewall configuration.
HCW8034 Failed to provision Organization Relationship for {0}

Documented causes and fixes:

CauseFix
The perimeter device pre-authenticates Autodiscover or EWSPublish the hybrid paths with a rule that doesn't require pre-authentication, ordered above other Exchange rules
The firewall blocks Exchange Online IP addressesAllow the ranges listed for Exchange Online in Microsoft 365 URLs and IP address ranges
An internal DNS zone doesn't forward and has no Autodiscover recordAdd an A record such as autodiscover.contoso.com pointing to the on-premises Exchange server
General on-premises configuration problemsWork through Microsoft's hybrid deployment troubleshooting guidance; the Microsoft Remote Connectivity Analyzer checks external connectivity to your Exchange organization

HCW8078: Migration Endpoint can't be created

The log may contain MigrationConnectionTestedTooRecentlyException ... The last connection attempt happened too recently. Microsoft attributes this to the Graph endpoint throttling requests from the HCW application. You have two options:

  • You're migrating: create the endpoint yourself in Exchange Online PowerShell, after checking that MRS Proxy is reachable:
$onprem = Get-Credential contoso\migadmin
Test-MigrationServerAvailability -ExchangeRemoteMove -RemoteServer mail.contoso.com -Credentials $onprem
New-MigrationEndpoint -Name "Hybrid Migration Endpoint - EWS (Default Web Site)" -ExchangeRemoteMove -RemoteServer mail.contoso.com -Credentials $onprem
  • You're not migrating: rerun the HCW, select Choose Exchange Hybrid Configuration, and clear Migration Endpoint.

If Test-MigrationServerAvailability fails, fix connectivity before you create the endpoint: check that MRSProxyEnabled is True on every Mailbox server's EWS virtual directory and that /ews/mrsproxy.svc is published without pre-authentication.

HCW8064: The OAuth portion didn't complete

The HCW has completed, but was not able to perform the OAuth portion of your Hybrid configuration.

The cause can be transient or permanent. Rerun the wizard and, if it fails again, read which OAuth cmdlet failed in the log (for example New-AuthServer). Confirm the Auth Certificate is valid before you retry; the wizard's OAuth option depends on it. Then test from the Exchange Management Shell:

Test-OAuthConnectivity -Service EWS -TargetUri https://outlook.office365.com -Mailbox user@contoso.com

If the wizard keeps failing, Microsoft documents a manual OAuth configuration between Exchange and Exchange Online as the alternative.

Directory_ResourceSizeExceeded during a rerun

[Directory_ResourceSizeExceeded] The size of the object has exceeded its limit. Please reduce the number of values and retry your request.

The OAuth option adds service principal names for every accepted domain, and Microsoft's tests show the practical limit is likely reached above roughly 800 SPNs. Rerun with Choose Exchange Hybrid Configuration and clear Oauth, Intra Organization Connector and Organization Relationship.

Step 3: Finish the dedicated Exchange hybrid app

If the HCW completed but free/busy, MailTips or photos don't work between on-premises and cloud users, the dedicated application is usually created but not enabled. Make sure every Exchange server runs a supported build, then run from an elevated Exchange Management Shell:

New-SettingOverride -Name "EnableExchangeHybrid3PAppFeature" -Component "Global" -Section "ExchangeOnpremAsThirdPartyAppId" -Parameters @("Enabled=true") -Reason "Enable dedicated Exchange hybrid app feature"
Get-ExchangeDiagnosticInfo -Process Microsoft.Exchange.Directory.TopologyService -Component VariantConfiguration -Argument Refresh

Allow up to 60 minutes for Exchange processes to pick up the change; hybrid features can be unavailable during that time.

Things that break this configuration:

  • Consent not granted or revoked. In the wizard's Exchange Server Application Configuration dialog, Grant Administrator Consent must stay selected. Clearing it on an existing app revokes consent.
  • Rerunning the OAuth option. Selecting Oauth, Intra Organization Connector and Organization Relationship after the app exists uploads the Auth Certificate to the first-party service principal again. Clean it up afterwards (see below).
  • 21Vianet tenants. The HCW can't create the app there; use the script instead.

The script alternative

Microsoft also publishes the ConfigureExchangeHybridApplication.ps1 script (https://aka.ms/ConfigureExchangeHybridApplication), and its all-in-one mode is the recommended path for most customers. Run it on a Mailbox server with outbound access to Microsoft Graph and Entra ID (it isn't compatible with Windows Server Core; use split execution mode there). It creates the app, configures the Auth Server and creates the setting override:

.\ConfigureExchangeHybridApplication.ps1 -FullyConfigureExchangeHybridApplication

After the switch, remove certificates left on the shared service principal, which also mitigates CVE-2025-53786:

.\ConfigureExchangeHybridApplication.ps1 -ResetFirstPartyServicePrincipalKeyCredentials

When the Auth Certificate is renewed, upload the new one to the app with .\ConfigureExchangeHybridApplication.ps1 -UpdateCertificate.

Graph API on Exchange Server SE

With the May 2026 HU, rerunning the script in all-in-one mode offers to add Graph API permissions and enable the Graph-based flow. Two cautions from Microsoft: only enable it in clouds where it's supported (Microsoft 365 Global when the documentation was last updated, not GCC High, DoD or 21Vianet), and don't remove the EWS permission if you use features Graph doesn't cover yet. MailTips is only partially supported via Graph (automatic replies), and moving items to a cloud archive still needs EWS.

Rerun only what you need

The Choose Exchange Hybrid Configuration option on the Hybrid Topology page lets you select individual configurations instead of letting the wizard reset everything. Useful combinations:

GoalSelect only
Recreate the migration endpointMigration Endpoint
Renew the TLS certificate on all four connectorsUpdate Secure Mail Certificate for connectors
Create or repair the dedicated appDeploy dedicated Exchange hybrid app
Copy organization settings to the cloudOrganization Configuration Transfer
Keep customized connectors untouchedEverything except the four connector options

The option isn't available with Minimal Hybrid Configuration. Use Reset Choices if you change the selection by mistake.

Verify the result

Run the OAuth test from the Exchange Management Shell and confirm the token came from your dedicated app:

$result = Test-OAuthConnectivity -Service EWS -TargetUri https://outlook.office365.com -Mailbox user@contoso.com
$result.ResultType
if (($result.Detail.FullId) -match 'L:(?<guid>[0-9a-fA-F-]{36})-AS:') { $matches['guid'] }

ResultType should be Success and the extracted GUID should match the application ID of ExchangeServerApp-... in Entra ID. Then:

  • Check free/busy in both directions between an on-premises and a cloud mailbox.
  • In Entra ID, open Monitoring > Sign-in logs > Service principal sign-ins and confirm successful sign-ins for the dedicated application.
  • Confirm the migration endpoint with Test-MigrationServerAvailability -Endpoint "Hybrid Migration Endpoint - EWS (Default Web Site)".

Checklist

  • Download the latest HCW and run it from a server with TLS 1.2 enabled for WinHTTP.
  • Read the HCW log and match the error code before changing anything.
  • HCW8001: enable directory synchronization in the tenant.
  • HCW8057/HCW8034: remove pre-authentication, open the firewall, fix internal Autodiscover DNS.
  • HCW8078: create the endpoint in PowerShell or clear Migration Endpoint.
  • HCW8064: rerun, then test with Test-OAuthConnectivity.
  • Put every Exchange server on a supported build, then enable the dedicated app with New-SettingOverride.
  • Clean the shared service principal after any OAuth rerun.
  • Use Choose Exchange Hybrid Configuration for every rerun after the first.

References

Questions people ask

Where are the Hybrid Configuration Wizard logs?

Every change the wizard makes is logged on the on-premises server where you ran it, by default in %UserProfile%\AppData\Roaming\Microsoft\Exchange Hybrid Configuration. Search the newest log for the HCW error code and the cmdlet that failed before you change anything.

Why did free/busy stop working after I ran the new HCW?

Since October 31, 2025, EWS access through the shared service principal is permanently blocked, so free/busy, MailTips and photos need the dedicated Exchange hybrid application. The HCW creates that application but doesn't enable it on-premises. You must run New-SettingOverride with the EnableExchangeHybrid3PAppFeature setting, and every Exchange server must run a supported build.

Can I rerun the HCW without resetting my custom connectors?

Yes. Choose the Choose Exchange Hybrid Configuration option on the Hybrid Topology page and clear the configurations you want to keep, such as the four connector options. The wizard then changes only what you selected and lists the excluded steps on its final page.

What does the HCW8064 warning mean?

HCW8064 means the wizard finished but couldn't complete the OAuth part of the hybrid configuration, because of a transient or permanent error. If you need features that rely on OAuth, rerun the wizard or configure OAuth between Exchange and Exchange Online manually, then confirm the result with Test-OAuthConnectivity.

Exchange hybridHybrid Configuration WizardExchange Server SEOAuthMicrosoft Entra ID
  1. Exchange 2016 and 2019 end of support: move to Exchange SE or Online

    Exchange 2016 and 2019 are out of support and the paid ESU ends with October 2026. Choose between Exchange Server SE and Exchange Online, then plan the upgrade or migration.

    Microsoft 36510 min read
  2. Remove the last Exchange server from a hybrid Exchange Online setup

    Transfer Exchange-attribute source of authority to the cloud, tear down the hybrid configuration and uninstall the last on-premises Exchange server.

    Microsoft 36511 min read
  3. Exchange hybrid remote move migration: endpoints, batches and completion

    Move mailboxes from on-premises Exchange to Exchange Online with remote move migration: enable MRS Proxy, test the endpoint, build batches, schedule completion and clean up.

    Microsoft 36512 min read