You can now fully uninstall the last Exchange server in a hybrid deployment while keeping Entra Connect, provided you first move Exchange-attribute source of authority (SOA) to Exchange Online by setting IsExchangeCloudManaged on every synced mailbox and moving groups and contacts with Entra SOA transfer. After that, point MX and Autodiscover at Exchange Online, clear the SCP, remove relay dependencies and the hybrid objects, run Setup /m:Uninstall, and clean up the orphaned hybrid records in Exchange Online.
Who this is for and what you will have at the end
This guide is for administrators who have finished moving mailboxes to Exchange Online and are still running an on-premises Exchange server only because directory-synchronized recipients can't otherwise be edited. At the end you will have:
- A decision on which decommission path fits your environment.
- Exchange attributes managed in Exchange Online, with optional writeback to Active Directory.
- DNS, Autodiscover and mail routing pointing only at Exchange Online.
- The hybrid configuration removed on both sides and the last server uninstalled.
If you are still mid-migration, finish the mailbox moves and the DNS cutover first; the email migration cutover checklist covers that stage.
Why the last server was needed, and what changed
With directory synchronization, a synced user's Exchange attributes (proxy addresses, custom attributes, hidden-from-GAL and so on) are owned by on-premises Active Directory. Exchange Online won't let you edit them, and Microsoft only supports editing them with the on-premises Exchange recipient cmdlets such as Set-RemoteMailbox, not with ADSI Edit or Active Directory Users and Computers. That is the "last Exchange server" problem.
Two things changed it. In April 2022, Exchange Server 2019 Cumulative Update 12 shipped updated Exchange Management Tools (EMT) that can manage recipients without a running server, so the last server can be shut down but not uninstalled. More recently, Exchange Online gained cloud-based management of Exchange attributes: setting IsExchangeCloudManaged to $true moves Exchange-attribute SOA for a mailbox to the cloud, while identity attributes (names, department, UPN and similar) stay with Active Directory. Both phases of that feature, per-mailbox control and writeback through Entra Cloud Sync, are generally available.
Choose your path
| Situation | Path | Last server |
|---|---|---|
| All mailboxes in the cloud, no directory sync needed | Disable directory sync, remove hybrid, uninstall Exchange | Uninstalled |
| Directory sync stays, you want recipient management in Exchange Online | Transfer Exchange-attribute SOA, remove hybrid, uninstall (this guide) | Uninstalled |
| Directory sync stays, you prefer to keep managing attributes in Active Directory with PowerShell | Exchange Management Tools, then shut down the server | Shut down, never uninstalled |
| Exchange still provides SMTP relay or on-premises public folders | Keep a supported server | Upgraded to Exchange Server SE |
Support for Exchange Server 2016 and 2019 ended on October 14, 2025. If any server stays, Microsoft recommends Exchange Server SE. If you already use EMT, Microsoft's guidance is to switch to cloud-based attribute management first and then uninstall, because EMT keeps Exchange-attribute SOA on-premises.
Prerequisites
- Every user mailbox, archive and public folder migrated to Exchange Online or removed. Public folders left on-premises block uninstall.
- Microsoft Entra Connect Sync version 2.5.190.0 or later, or Microsoft Entra Cloud Sync. Older Connect Sync builds try to push Exchange attributes for cloud-managed mailboxes and fail.
- For optional writeback, the Entra provisioning agent version 1.1.1107.0 or later. Cloud Sync installs alongside Connect Sync; you don't have to replace Connect Sync.
- An account with Exchange Administrator (recommended), Hybrid Identity Administrator or Global Administrator to set
IsExchangeCloudManaged, using interactive sign-in to Exchange Online PowerShell. Certificate-based app-only sessions aren't supported for this change. - On-premises administrative rights to run Exchange Setup on the last server.
- The Hybrid Identity Administrator role if you plan to configure attribute writeback or the tenant-wide default (the tenant-wide switch needs Hybrid Identity Administrator or Global Administrator; Exchange Administrator isn't enough for it).
- A list of every device and application that relays mail through Exchange.
Step 1: Confirm nothing still lives on-premises
In the Exchange Management Shell, include the whole forest and check every mailbox type. All of these should return nothing:
Set-ADServerSettings -ViewEntireForest:$true
Get-Mailbox
Get-Mailbox -Archive
Get-Mailbox -PublicFolder
Get-Mailbox -Arbitration
Get-Mailbox -AuditLogOn-premises system mailboxes must be disabled before you uninstall. Arbitration and audit log mailboxes, and any offline address book generated by them, also block uninstall; Microsoft's article on removing a mailbox database covers the per-type procedure, including -DisableLastArbitrationMailboxAllowed.
Also check Get-OrganizationConfig | Format-List PublicFoldersEnabled. If the value is Remote and people still use public folders, migrate them to Exchange Online first.
Step 2: Transfer Exchange-attribute source of authority
Connect to Exchange Online PowerShell interactively and take an inventory:
$mailboxes = Get-Mailbox -ResultSize Unlimited | Where-Object { $_.IsDirSynced -eq $true }
$mailboxes | Select-Object DisplayName, PrimarySmtpAddress, IsExchangeCloudManaged |
Export-Csv .\PreRemoval_MailboxInventory.csv -NoTypeInformationTiming matters. After any on-premises change with Set-RemoteMailbox, or after a mailbox move completes, wait for a normal sync cycle plus 24 hours before flipping that mailbox. Flipping too early can let stale cloud recipient-type values overwrite the correct remote-mailbox values in Active Directory when writeback runs.
Then enable cloud management for the remaining mailboxes:
Get-Mailbox -ResultSize Unlimited |
Where-Object { $_.IsDirSynced -eq $true -and $_.IsExchangeCloudManaged -eq $false } |
ForEach-Object { Set-Mailbox -Identity $_.Alias -IsExchangeCloudManaged $true }
Get-Mailbox -Identity adele@contoso.com | Format-List Identity, IsExchangeCloudManagedFrom now on, edit Exchange attributes in Exchange Online, for example Set-Mailbox -Identity adele@contoso.com -CustomAttribute1 'Finance'. Identity attributes such as first and last name are still edited in Active Directory.
IsExchangeCloudManaged applies only to mailboxes. Mail-enabled distribution groups, mail-enabled security groups and mail contacts need Group SOA and Contact SOA transfer in Entra ID, otherwise nobody can manage them after Exchange is gone.
Two optional pieces:
- Writeback. If on-premises applications read attributes such as
proxyAddressesorextensionAttribute1toextensionAttribute15from Active Directory, create an EXO to AD attribute sync configuration under Entra Connect > Cloud Sync in the Microsoft Entra admin center and start provisioning. This requires the Hybrid Identity Administrator role and a Cloud Sync provisioning agent that is installed and active. Writeback supports up to 600,000 cloud-managed mailboxes per tenant. - Tenant-wide default. If you keep creating users in Active Directory,
Set-OrganizationConfig -ExchangeAttributesCloudManagedByDefaultmakes new mailboxes cloud-managed by default. Enable it only after every on-premises mailbox is migrated and you no longer create Exchange recipients on-premises.
New mailboxes are then created by adding the user in Active Directory, letting it sync, assigning an Exchange Online licence, and setting IsExchangeCloudManaged (unless the tenant-wide default is on). Deleting a user still means deleting the Active Directory account.
Step 3: Point mail and clients at Exchange Online
Update both internal and external DNS:
| Record | Value |
|---|---|
| MX for contoso.com | The Exchange Online MX value shown for the domain in the Microsoft 365 admin center |
| Autodiscover CNAME | autodiscover.outlook.com |
| A record such as mail.contoso.com | Remove or repurpose once nothing uses it |
Domain-joined Outlook clients query the Active Directory service connection point (SCP) before DNS, so clear it:
Get-ClientAccessService | Set-ClientAccessService -AutoDiscoverServiceInternalUri $nullIf Centralized Mail Transport is enabled, outbound mail from Exchange Online routes through on-premises Exchange and will break at uninstall. Turn it off by rerunning the Hybrid Configuration Wizard and clearing Enable Centralized Mail Transport, or in Exchange Online PowerShell:
Set-OutboundConnector -Identity '<Hybrid outbound connector name>' -RecipientDomains 'contoso.com' -RouteAllMessagesViaOnPremises:$falseStep 4: Remove SMTP relay dependencies
Uninstall removes every receive connector, and that loss of relay is permanent. Find the devices that depend on anonymous relay:
Get-ReceiveConnector | Where-Object { $_.PermissionGroups -match 'AnonymousUsers' } |
Format-Table Name, Bindings, RemoteIPRanges -AutoSizeMove each device in RemoteIPRanges to Exchange Online SMTP relay, Azure Communication Services or another SMTP service. If you can't, stop here and keep the server running.
Step 5: Remove the hybrid configuration
Run these while Exchange is still installed. In the Exchange Management Shell:
Remove-HybridConfiguration
Get-IntraOrganizationConnector | Where-Object { $_.Name -like 'HybridIOC -*' } |
Remove-IntraOrganizationConnector -Confirm:$false
$fedTrust = Get-FederationTrust -Identity 'Microsoft Federation Gateway' -ErrorAction SilentlyContinue
if ($fedTrust) { $fedTrust | Remove-FederationTrust -Confirm:$false }
$fedCert = Get-ExchangeCertificate | Where-Object { $_.Subject -eq 'CN=Federation' }
if ($fedCert) { $fedCert | Remove-ExchangeCertificate -Confirm:$false }
& $env:ExchangeInstallPath\Scripts\ConfigureExchangeHybridApplication.ps1 -ResetFirstPartyServicePrincipalKeyCredentialsIn Exchange Online PowerShell, remove the Hybrid Configuration Wizard connectors, the intra-organization connector and the organization relationship:
Get-IntraOrganizationConnector | Where-Object { $_.Name -like 'HybridIOC -*' } |
Remove-IntraOrganizationConnector -Confirm:$false
Get-InboundConnector | Where-Object { $_.ConnectorSource -eq 'HybridWizard' } | Remove-InboundConnector
Get-OutboundConnector | Where-Object { $_.ConnectorSource -eq 'HybridWizard' } | Remove-OutboundConnector
Get-OrganizationRelationship | Where-Object { $_.Name -like 'O365 to On-Premises*' } | Remove-OrganizationRelationshipIf you run Modern Hybrid, remove the hybrid application and uninstall the Hybrid Agent. On the agent machine, import C:\Program Files\Microsoft Hybrid Service\HybridManagement.psm1, read the AppId from the first label of the on-premises organization relationship's TargetSharingEpr host name, then run Remove-HybridApplication -AppId <AppId> -UserPrincipalName admin@contoso.onmicrosoft.com and uninstall the agent. Classic Hybrid environments skip this.
Step 6: Uninstall the last Exchange server
Re-check the four gates: no mailboxes or public folders on-premises; every synced mailbox cloud-managed (or its user SOA transferred); DNS, SCP and Centralized Mail Transport done; no relay dependencies. Then, from an elevated prompt on the server:
Setup.exe /m:Uninstall /IAcceptExchangeServerLicenseTermsYou can also uninstall from Programs and Features. Uninstall removes the CN=Microsoft Exchange organization container, the Exchange security groups, server objects and system mailboxes. It keeps the msExch* schema extensions, the per-user attribute values (proxy addresses, custom attributes and so on) and the CN=Microsoft Exchange Autodiscover container with its Exchange Online SCP, which redirects domain-joined Outlook clients to Exchange Online.
Step 7: Clean up Exchange Online
Look for orphaned hybrid records:
Get-IntraOrganizationConnector
Get-OrganizationRelationship
Get-OnPremisesOrganization
Get-MigrationEndpoint
Get-AcceptedDomainRemove the on-premises organization object with Remove-OnPremisesOrganization and the hybrid migration endpoint with Remove-MigrationEndpoint. If your domain is still InternalRelay from hybrid, change it to Authoritative with Set-AcceptedDomain once every recipient exists in Exchange Online.
Verification
- Edit a custom attribute with
Set-Mailboxin Exchange Online and confirm it sticks after the next sync cycle. If writeback is on, confirm the value arrives in Active Directory after about 20 minutes or by using Provision on demand. - Send inbound and outbound test mail and trace it in the Exchange admin center under Mail flow > Message trace.
- Open Outlook on a domain-joined machine inside the network and confirm Autodiscover lands on Exchange Online.
- Confirm every former relay device can still send.
Troubleshooting
Cloud edits are overwritten or sync errors appear after the flip. Check the Entra Connect Sync version is 2.5.190.0 or later.
Recipient type wrong in Active Directory after writeback. The mailbox was likely flipped before post-move attributes finished syncing. Wait the full sync cycle plus 24 hours on new moves before flipping.
New on-premises users don't get the expected cloud recipient. Tenant-wide SOA was enabled while on-premises recipients were still being created. Disable it with Set-OrganizationConfig -ExchangeAttributesServerManagedByDefault, then run Set-User -Identity <user> -ExchangeAttributesServerManaged for each affected user.
Uninstall refuses to continue. A mailbox of some type still exists. Rerun the five Get-Mailbox checks from Step 1.
You used EMT and already ran CleanupActiveDirectoryEMT.ps1. If you wiped the server, no uninstall is needed. If you only shut it down, power it on and run Setup /m:Uninstall as a Domain Admin.
You need to move a mailbox back on-premises later. Set IsExchangeCloudManaged to $false first; otherwise on-premises updates are blocked and offboarding breaks.
Checklist
- No user, archive, public folder, arbitration or audit mailboxes on-premises.
- Entra Connect Sync 2.5.190.0 or later (or Cloud Sync) in place.
IsExchangeCloudManagedset on every synced mailbox; groups and contacts moved with Entra SOA transfer.- Writeback configured if on-premises apps read Exchange attributes.
- MX, Autodiscover (internal and external) and SCP updated; Centralized Mail Transport off.
- Relay devices moved.
- Hybrid configuration, connectors, organization relationship, federation trust and certificate removed; OAuth credentials reset; Hybrid Agent removed.
Setup /m:Uninstallcompleted and Exchange Online orphans cleaned up.
References
- Decommission the last Exchange Server after transferring SOA to cloud
- Cloud-based management of Exchange attributes for Remote Mailboxes in hybrid environments
- How and when to decommission your on-premises Exchange servers in a hybrid deployment
- Manage recipients in Exchange Hybrid environments using Management tools
- Exchange Server 2019 and 2016 End of Support Roadmap
- External Domain Name System records for Microsoft 365
- Message trace in the new EAC in Exchange Online