Most Hybrid Configuration Wizard (HCW) failures with Exchange Server SE come from a short list of causes: TLS 1.2 disabled for WinHTTP on the machine running the wizard, Autodiscover or EWS not reachable from Exchange Online (HCW8057 and HCW8034), directory synchronization switched off in the tenant (HCW8001), migration endpoint creation being throttled (HCW8078), or the OAuth step failing (HCW8064). On top of that, rich coexistence now depends on the dedicated Exchange hybrid application in Microsoft Entra ID, which the HCW creates but doesn't enable, so free/busy can break even when the wizard reports success.
Who this is for and what you will have at the end
This guide is for administrators running the HCW against Exchange Server Subscription Edition (SE), either for a new hybrid deployment or a rerun after upgrading from Exchange 2016 or 2019. Use it when the wizard stops with an HCW error code, finishes with a warning, or completes but leaves free/busy, MailTips or migrations broken.
At the end you will have:
- The error matched to its documented cause and fix.
- The dedicated Exchange hybrid application created, enabled and verified.
- A way to rerun only the failing part of the HCW without resetting the rest of your hybrid configuration.
Once the wizard succeeds, mailbox moves are covered in the hybrid remote move migration guide, and the connectors the HCW creates are explained in the Exchange Online connectors guide.
What changed for hybrid with Exchange Server SE
Exchange Server used to authenticate to Exchange Online through a shared, first-party service principal, and the HCW uploaded your Auth Certificate to it. That model is gone:
- As of October 31, 2025, EWS access through the shared service principal is permanently blocked. Free/busy, MailTips and profile picture sharing only work through a dedicated Exchange hybrid application (
ExchangeServerApp-{organization GUID}) registered in your tenant. - The HCW now deploys this application by default, adding the
full_access_as_appEWS permission, asking you to grant tenant-wide admin consent, and uploading the current and next Auth Certificates. - The HCW does not turn the feature on in your Exchange organization. You must create a setting override afterwards.
- Starting with the May 2026 Hotfix Update for Exchange Server SE, the dedicated app can use Microsoft Graph API permissions instead of EWS for most hybrid scenarios.
Supported builds for the dedicated app:
| Version | Build | EWS-based flow | Graph-based flow |
|---|---|---|---|
| Exchange Server SE RTM with May 2026 HU | 15.2.2562.41 | Yes | Yes |
| Exchange Server SE RTM | 15.2.2562.17 | Yes | No |
| Exchange Server 2019 CU15 with April 2025 HU | 15.2.1748.24 | Yes | No |
| Exchange Server 2019 CU14 with April 2025 HU | 15.2.1544.25 | Yes | No |
| Exchange Server 2016 CU23 with April 2025 HU | 15.1.2507.55 | Yes | No |
Servers on older builds can't use rich coexistence at all, whatever you do in the wizard.
Prerequisites before you rerun the wizard
- The latest HCW from
https://aka.ms/HybridWizard. The dedicated app and the Choose Exchange Hybrid Configuration options described here are in the latest version. - Permissions. On-premises, the account must be in the Organization Management role group. In Exchange Online, Global Administrator is required the first time you configure hybrid and for the OAuth and dedicated application options; most other granular options need Exchange Administrator for Classic Hybrid.
- Certificates. A certificate from a trusted public CA on the IIS and transport services of the hybrid servers, with the EWS external URL and Autodiscover name in the SAN. A valid Auth Certificate for OAuth.
- Publishing. Exchange Online must reach
/autodiscover/autodiscover.svc,/autodiscover/autodiscover.svc/wssecurity,/ews/exchange.asmx/wssecurityand/ews/mrsproxy.svcover TCP 443, without pre-authentication on any reverse proxy. - Outbound access. For the dedicated app, the server running the configuration needs
login.microsoftonline.comandgraph.microsoft.comon port 443. Exchange servers also need outbound HTTP toctldl.windowsupdate.comso Windows can maintain the Certificate Trust List. - Directory synchronization with Microsoft Entra Connect or Cloud Sync.
Check outbound connectivity from the Exchange server before you start:
Test-NetConnection -ComputerName login.microsoftonline.com -Port 443
Test-NetConnection -ComputerName graph.microsoft.com -Port 443Step 1: Read the log before changing anything
All HCW changes are logged on the server where you ran the wizard, by default in:
%UserProfile%\AppData\Roaming\Microsoft\Exchange Hybrid ConfigurationOpen the newest log and search for HCW8 and ERROR. The lines just before the error show which cmdlet failed (for example New-AuthServer, New-MigrationEndpoint or Set-OrganizationRelationship), which tells you which configuration area to fix. While the wizard is open, F12 opens the HCW Diagnostic Tools pane. Its Open Exchange Online PowerShell option is useful for reproducing connection errors such as the TLS failure below.
Step 2: Fix the error you actually have
The wizard can't connect to Office 365
Symptom:
Connecting to remote server outlook.office365.com failed with the following error message: The server certificate on the destination computer (outlook.office365.com:443) has the following errors: Encountered an internal error in the SSL library.Microsoft 365 accepts only TLS 1.2, and the wizard's PowerShell session uses WinHTTP. On Windows Server 2012 R2 and later, TLS 1.2 is on by default, so look for a custom policy that disabled it. If WinHTTP needs it explicitly, add a DefaultSecureProtocols DWORD with the value 0x00000800 (TLS 1.2) under:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WinHttp
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\WinHttpBack up the registry first, and check that TLS 1.2 is also enabled at the operating system level.
HCW8001: Unable to determine the Tenant Routing Domain
The log shows Unable to determine the routing domain for the cloud organization. The cause is that directory synchronization is disabled in the tenant; the contoso.mail.onmicrosoft.com routing domain is created when it's enabled. With a Global Administrator account:
Install-Module -Name Microsoft.Entra -Repository PSGallery -Scope CurrentUser -Force -AllowClobber
Connect-Entra -Scopes 'OnPremDirectorySynchronization.ReadWrite.All', 'Organization.ReadWrite.All'
Set-EntraDirSyncEnabled -EnableDirSync $true -ForceHCW8057 or HCW8034: Autodiscover can't be reached
HCW8057 Office 365 was unable to communicate with your on-premises Autodiscover endpoint. This is typically due to incorrect DNS or firewall configuration.
HCW8034 Failed to provision Organization Relationship for {0}Documented causes and fixes:
| Cause | Fix |
|---|---|
| The perimeter device pre-authenticates Autodiscover or EWS | Publish the hybrid paths with a rule that doesn't require pre-authentication, ordered above other Exchange rules |
| The firewall blocks Exchange Online IP addresses | Allow the ranges listed for Exchange Online in Microsoft 365 URLs and IP address ranges |
| An internal DNS zone doesn't forward and has no Autodiscover record | Add an A record such as autodiscover.contoso.com pointing to the on-premises Exchange server |
| General on-premises configuration problems | Work through Microsoft's hybrid deployment troubleshooting guidance; the Microsoft Remote Connectivity Analyzer checks external connectivity to your Exchange organization |
HCW8078: Migration Endpoint can't be created
The log may contain MigrationConnectionTestedTooRecentlyException ... The last connection attempt happened too recently. Microsoft attributes this to the Graph endpoint throttling requests from the HCW application. You have two options:
- You're migrating: create the endpoint yourself in Exchange Online PowerShell, after checking that MRS Proxy is reachable:
$onprem = Get-Credential contoso\migadmin
Test-MigrationServerAvailability -ExchangeRemoteMove -RemoteServer mail.contoso.com -Credentials $onprem
New-MigrationEndpoint -Name "Hybrid Migration Endpoint - EWS (Default Web Site)" -ExchangeRemoteMove -RemoteServer mail.contoso.com -Credentials $onprem- You're not migrating: rerun the HCW, select Choose Exchange Hybrid Configuration, and clear Migration Endpoint.
If Test-MigrationServerAvailability fails, fix connectivity before you create the endpoint: check that MRSProxyEnabled is True on every Mailbox server's EWS virtual directory and that /ews/mrsproxy.svc is published without pre-authentication.
HCW8064: The OAuth portion didn't complete
The HCW has completed, but was not able to perform the OAuth portion of your Hybrid configuration.The cause can be transient or permanent. Rerun the wizard and, if it fails again, read which OAuth cmdlet failed in the log (for example New-AuthServer). Confirm the Auth Certificate is valid before you retry; the wizard's OAuth option depends on it. Then test from the Exchange Management Shell:
Test-OAuthConnectivity -Service EWS -TargetUri https://outlook.office365.com -Mailbox user@contoso.comIf the wizard keeps failing, Microsoft documents a manual OAuth configuration between Exchange and Exchange Online as the alternative.
Directory_ResourceSizeExceeded during a rerun
[Directory_ResourceSizeExceeded] The size of the object has exceeded its limit. Please reduce the number of values and retry your request.The OAuth option adds service principal names for every accepted domain, and Microsoft's tests show the practical limit is likely reached above roughly 800 SPNs. Rerun with Choose Exchange Hybrid Configuration and clear Oauth, Intra Organization Connector and Organization Relationship.
Step 3: Finish the dedicated Exchange hybrid app
If the HCW completed but free/busy, MailTips or photos don't work between on-premises and cloud users, the dedicated application is usually created but not enabled. Make sure every Exchange server runs a supported build, then run from an elevated Exchange Management Shell:
New-SettingOverride -Name "EnableExchangeHybrid3PAppFeature" -Component "Global" -Section "ExchangeOnpremAsThirdPartyAppId" -Parameters @("Enabled=true") -Reason "Enable dedicated Exchange hybrid app feature"
Get-ExchangeDiagnosticInfo -Process Microsoft.Exchange.Directory.TopologyService -Component VariantConfiguration -Argument RefreshAllow up to 60 minutes for Exchange processes to pick up the change; hybrid features can be unavailable during that time.
Things that break this configuration:
- Consent not granted or revoked. In the wizard's Exchange Server Application Configuration dialog, Grant Administrator Consent must stay selected. Clearing it on an existing app revokes consent.
- Rerunning the OAuth option. Selecting Oauth, Intra Organization Connector and Organization Relationship after the app exists uploads the Auth Certificate to the first-party service principal again. Clean it up afterwards (see below).
- 21Vianet tenants. The HCW can't create the app there; use the script instead.
The script alternative
Microsoft also publishes the ConfigureExchangeHybridApplication.ps1 script (https://aka.ms/ConfigureExchangeHybridApplication), and its all-in-one mode is the recommended path for most customers. Run it on a Mailbox server with outbound access to Microsoft Graph and Entra ID (it isn't compatible with Windows Server Core; use split execution mode there). It creates the app, configures the Auth Server and creates the setting override:
.\ConfigureExchangeHybridApplication.ps1 -FullyConfigureExchangeHybridApplicationAfter the switch, remove certificates left on the shared service principal, which also mitigates CVE-2025-53786:
.\ConfigureExchangeHybridApplication.ps1 -ResetFirstPartyServicePrincipalKeyCredentialsWhen the Auth Certificate is renewed, upload the new one to the app with .\ConfigureExchangeHybridApplication.ps1 -UpdateCertificate.
Graph API on Exchange Server SE
With the May 2026 HU, rerunning the script in all-in-one mode offers to add Graph API permissions and enable the Graph-based flow. Two cautions from Microsoft: only enable it in clouds where it's supported (Microsoft 365 Global when the documentation was last updated, not GCC High, DoD or 21Vianet), and don't remove the EWS permission if you use features Graph doesn't cover yet. MailTips is only partially supported via Graph (automatic replies), and moving items to a cloud archive still needs EWS.
Rerun only what you need
The Choose Exchange Hybrid Configuration option on the Hybrid Topology page lets you select individual configurations instead of letting the wizard reset everything. Useful combinations:
| Goal | Select only |
|---|---|
| Recreate the migration endpoint | Migration Endpoint |
| Renew the TLS certificate on all four connectors | Update Secure Mail Certificate for connectors |
| Create or repair the dedicated app | Deploy dedicated Exchange hybrid app |
| Copy organization settings to the cloud | Organization Configuration Transfer |
| Keep customized connectors untouched | Everything except the four connector options |
The option isn't available with Minimal Hybrid Configuration. Use Reset Choices if you change the selection by mistake.
Verify the result
Run the OAuth test from the Exchange Management Shell and confirm the token came from your dedicated app:
$result = Test-OAuthConnectivity -Service EWS -TargetUri https://outlook.office365.com -Mailbox user@contoso.com
$result.ResultType
if (($result.Detail.FullId) -match 'L:(?<guid>[0-9a-fA-F-]{36})-AS:') { $matches['guid'] }ResultType should be Success and the extracted GUID should match the application ID of ExchangeServerApp-... in Entra ID. Then:
- Check free/busy in both directions between an on-premises and a cloud mailbox.
- In Entra ID, open Monitoring > Sign-in logs > Service principal sign-ins and confirm successful sign-ins for the dedicated application.
- Confirm the migration endpoint with
Test-MigrationServerAvailability -Endpoint "Hybrid Migration Endpoint - EWS (Default Web Site)".
Checklist
- Download the latest HCW and run it from a server with TLS 1.2 enabled for WinHTTP.
- Read the HCW log and match the error code before changing anything.
- HCW8001: enable directory synchronization in the tenant.
- HCW8057/HCW8034: remove pre-authentication, open the firewall, fix internal Autodiscover DNS.
- HCW8078: create the endpoint in PowerShell or clear Migration Endpoint.
- HCW8064: rerun, then test with
Test-OAuthConnectivity. - Put every Exchange server on a supported build, then enable the dedicated app with
New-SettingOverride. - Clean the shared service principal after any OAuth rerun.
- Use Choose Exchange Hybrid Configuration for every rerun after the first.
References
- Hybrid Configuration wizard
- HCW Choose Exchange Hybrid Configuration feature
- Deploy dedicated Exchange hybrid app
- Hybrid deployment prerequisites
- Hybrid Configuration wizard FAQs
- Hybrid Configuration wizard doesn't connect to Office 365
- HCW8001 error when the Hybrid Configuration Wizard runs
- HCW8034 or HCW8057 when running Hybrid Configuration wizard
- HCW8078 error - Migration Endpoint could not be created
- Warning occurs when running Hybrid Configuration (HCW8064)
- Enable the MRS Proxy endpoint for remote moves
- Test-MigrationServerAvailability
- Test-OAuthConnectivity