Microsoft 365

Remove the last Exchange server from a hybrid Exchange Online setup

Transfer Exchange-attribute source of authority to the cloud, tear down the hybrid configuration and uninstall the last on-premises Exchange server.

11 min read
On this page

You can now fully uninstall the last Exchange server in a hybrid deployment while keeping Entra Connect, provided you first move Exchange-attribute source of authority (SOA) to Exchange Online by setting IsExchangeCloudManaged on every synced mailbox and moving groups and contacts with Entra SOA transfer. After that, point MX and Autodiscover at Exchange Online, clear the SCP, remove relay dependencies and the hybrid objects, run Setup /m:Uninstall, and clean up the orphaned hybrid records in Exchange Online.

Who this is for and what you will have at the end

This guide is for administrators who have finished moving mailboxes to Exchange Online and are still running an on-premises Exchange server only because directory-synchronized recipients can't otherwise be edited. At the end you will have:

  • A decision on which decommission path fits your environment.
  • Exchange attributes managed in Exchange Online, with optional writeback to Active Directory.
  • DNS, Autodiscover and mail routing pointing only at Exchange Online.
  • The hybrid configuration removed on both sides and the last server uninstalled.

If you are still mid-migration, finish the mailbox moves and the DNS cutover first; the email migration cutover checklist covers that stage.

Why the last server was needed, and what changed

With directory synchronization, a synced user's Exchange attributes (proxy addresses, custom attributes, hidden-from-GAL and so on) are owned by on-premises Active Directory. Exchange Online won't let you edit them, and Microsoft only supports editing them with the on-premises Exchange recipient cmdlets such as Set-RemoteMailbox, not with ADSI Edit or Active Directory Users and Computers. That is the "last Exchange server" problem.

Two things changed it. In April 2022, Exchange Server 2019 Cumulative Update 12 shipped updated Exchange Management Tools (EMT) that can manage recipients without a running server, so the last server can be shut down but not uninstalled. More recently, Exchange Online gained cloud-based management of Exchange attributes: setting IsExchangeCloudManaged to $true moves Exchange-attribute SOA for a mailbox to the cloud, while identity attributes (names, department, UPN and similar) stay with Active Directory. Both phases of that feature, per-mailbox control and writeback through Entra Cloud Sync, are generally available.

Choose your path

SituationPathLast server
All mailboxes in the cloud, no directory sync neededDisable directory sync, remove hybrid, uninstall ExchangeUninstalled
Directory sync stays, you want recipient management in Exchange OnlineTransfer Exchange-attribute SOA, remove hybrid, uninstall (this guide)Uninstalled
Directory sync stays, you prefer to keep managing attributes in Active Directory with PowerShellExchange Management Tools, then shut down the serverShut down, never uninstalled
Exchange still provides SMTP relay or on-premises public foldersKeep a supported serverUpgraded to Exchange Server SE

Support for Exchange Server 2016 and 2019 ended on October 14, 2025. If any server stays, Microsoft recommends Exchange Server SE. If you already use EMT, Microsoft's guidance is to switch to cloud-based attribute management first and then uninstall, because EMT keeps Exchange-attribute SOA on-premises.

Prerequisites

  • Every user mailbox, archive and public folder migrated to Exchange Online or removed. Public folders left on-premises block uninstall.
  • Microsoft Entra Connect Sync version 2.5.190.0 or later, or Microsoft Entra Cloud Sync. Older Connect Sync builds try to push Exchange attributes for cloud-managed mailboxes and fail.
  • For optional writeback, the Entra provisioning agent version 1.1.1107.0 or later. Cloud Sync installs alongside Connect Sync; you don't have to replace Connect Sync.
  • An account with Exchange Administrator (recommended), Hybrid Identity Administrator or Global Administrator to set IsExchangeCloudManaged, using interactive sign-in to Exchange Online PowerShell. Certificate-based app-only sessions aren't supported for this change.
  • On-premises administrative rights to run Exchange Setup on the last server.
  • The Hybrid Identity Administrator role if you plan to configure attribute writeback or the tenant-wide default (the tenant-wide switch needs Hybrid Identity Administrator or Global Administrator; Exchange Administrator isn't enough for it).
  • A list of every device and application that relays mail through Exchange.

Step 1: Confirm nothing still lives on-premises

In the Exchange Management Shell, include the whole forest and check every mailbox type. All of these should return nothing:

Set-ADServerSettings -ViewEntireForest:$true
Get-Mailbox
Get-Mailbox -Archive
Get-Mailbox -PublicFolder
Get-Mailbox -Arbitration
Get-Mailbox -AuditLog

On-premises system mailboxes must be disabled before you uninstall. Arbitration and audit log mailboxes, and any offline address book generated by them, also block uninstall; Microsoft's article on removing a mailbox database covers the per-type procedure, including -DisableLastArbitrationMailboxAllowed.

Also check Get-OrganizationConfig | Format-List PublicFoldersEnabled. If the value is Remote and people still use public folders, migrate them to Exchange Online first.

Step 2: Transfer Exchange-attribute source of authority

Connect to Exchange Online PowerShell interactively and take an inventory:

$mailboxes = Get-Mailbox -ResultSize Unlimited | Where-Object { $_.IsDirSynced -eq $true }
$mailboxes | Select-Object DisplayName, PrimarySmtpAddress, IsExchangeCloudManaged |
    Export-Csv .\PreRemoval_MailboxInventory.csv -NoTypeInformation

Timing matters. After any on-premises change with Set-RemoteMailbox, or after a mailbox move completes, wait for a normal sync cycle plus 24 hours before flipping that mailbox. Flipping too early can let stale cloud recipient-type values overwrite the correct remote-mailbox values in Active Directory when writeback runs.

Then enable cloud management for the remaining mailboxes:

Get-Mailbox -ResultSize Unlimited |
    Where-Object { $_.IsDirSynced -eq $true -and $_.IsExchangeCloudManaged -eq $false } |
    ForEach-Object { Set-Mailbox -Identity $_.Alias -IsExchangeCloudManaged $true }
 
Get-Mailbox -Identity adele@contoso.com | Format-List Identity, IsExchangeCloudManaged

From now on, edit Exchange attributes in Exchange Online, for example Set-Mailbox -Identity adele@contoso.com -CustomAttribute1 'Finance'. Identity attributes such as first and last name are still edited in Active Directory.

IsExchangeCloudManaged applies only to mailboxes. Mail-enabled distribution groups, mail-enabled security groups and mail contacts need Group SOA and Contact SOA transfer in Entra ID, otherwise nobody can manage them after Exchange is gone.

Two optional pieces:

  • Writeback. If on-premises applications read attributes such as proxyAddresses or extensionAttribute1 to extensionAttribute15 from Active Directory, create an EXO to AD attribute sync configuration under Entra Connect > Cloud Sync in the Microsoft Entra admin center and start provisioning. This requires the Hybrid Identity Administrator role and a Cloud Sync provisioning agent that is installed and active. Writeback supports up to 600,000 cloud-managed mailboxes per tenant.
  • Tenant-wide default. If you keep creating users in Active Directory, Set-OrganizationConfig -ExchangeAttributesCloudManagedByDefault makes new mailboxes cloud-managed by default. Enable it only after every on-premises mailbox is migrated and you no longer create Exchange recipients on-premises.

New mailboxes are then created by adding the user in Active Directory, letting it sync, assigning an Exchange Online licence, and setting IsExchangeCloudManaged (unless the tenant-wide default is on). Deleting a user still means deleting the Active Directory account.

Step 3: Point mail and clients at Exchange Online

Update both internal and external DNS:

RecordValue
MX for contoso.comThe Exchange Online MX value shown for the domain in the Microsoft 365 admin center
Autodiscover CNAMEautodiscover.outlook.com
A record such as mail.contoso.comRemove or repurpose once nothing uses it

Domain-joined Outlook clients query the Active Directory service connection point (SCP) before DNS, so clear it:

Get-ClientAccessService | Set-ClientAccessService -AutoDiscoverServiceInternalUri $null

If Centralized Mail Transport is enabled, outbound mail from Exchange Online routes through on-premises Exchange and will break at uninstall. Turn it off by rerunning the Hybrid Configuration Wizard and clearing Enable Centralized Mail Transport, or in Exchange Online PowerShell:

Set-OutboundConnector -Identity '<Hybrid outbound connector name>' -RecipientDomains 'contoso.com' -RouteAllMessagesViaOnPremises:$false

Step 4: Remove SMTP relay dependencies

Uninstall removes every receive connector, and that loss of relay is permanent. Find the devices that depend on anonymous relay:

Get-ReceiveConnector | Where-Object { $_.PermissionGroups -match 'AnonymousUsers' } |
    Format-Table Name, Bindings, RemoteIPRanges -AutoSize

Move each device in RemoteIPRanges to Exchange Online SMTP relay, Azure Communication Services or another SMTP service. If you can't, stop here and keep the server running.

Step 5: Remove the hybrid configuration

Run these while Exchange is still installed. In the Exchange Management Shell:

Remove-HybridConfiguration
 
Get-IntraOrganizationConnector | Where-Object { $_.Name -like 'HybridIOC -*' } |
    Remove-IntraOrganizationConnector -Confirm:$false
 
$fedTrust = Get-FederationTrust -Identity 'Microsoft Federation Gateway' -ErrorAction SilentlyContinue
if ($fedTrust) { $fedTrust | Remove-FederationTrust -Confirm:$false }
 
$fedCert = Get-ExchangeCertificate | Where-Object { $_.Subject -eq 'CN=Federation' }
if ($fedCert) { $fedCert | Remove-ExchangeCertificate -Confirm:$false }
 
& $env:ExchangeInstallPath\Scripts\ConfigureExchangeHybridApplication.ps1 -ResetFirstPartyServicePrincipalKeyCredentials

In Exchange Online PowerShell, remove the Hybrid Configuration Wizard connectors, the intra-organization connector and the organization relationship:

Get-IntraOrganizationConnector | Where-Object { $_.Name -like 'HybridIOC -*' } |
    Remove-IntraOrganizationConnector -Confirm:$false
Get-InboundConnector  | Where-Object { $_.ConnectorSource -eq 'HybridWizard' } | Remove-InboundConnector
Get-OutboundConnector | Where-Object { $_.ConnectorSource -eq 'HybridWizard' } | Remove-OutboundConnector
Get-OrganizationRelationship | Where-Object { $_.Name -like 'O365 to On-Premises*' } | Remove-OrganizationRelationship

If you run Modern Hybrid, remove the hybrid application and uninstall the Hybrid Agent. On the agent machine, import C:\Program Files\Microsoft Hybrid Service\HybridManagement.psm1, read the AppId from the first label of the on-premises organization relationship's TargetSharingEpr host name, then run Remove-HybridApplication -AppId <AppId> -UserPrincipalName admin@contoso.onmicrosoft.com and uninstall the agent. Classic Hybrid environments skip this.

Step 6: Uninstall the last Exchange server

Re-check the four gates: no mailboxes or public folders on-premises; every synced mailbox cloud-managed (or its user SOA transferred); DNS, SCP and Centralized Mail Transport done; no relay dependencies. Then, from an elevated prompt on the server:

Setup.exe /m:Uninstall /IAcceptExchangeServerLicenseTerms

You can also uninstall from Programs and Features. Uninstall removes the CN=Microsoft Exchange organization container, the Exchange security groups, server objects and system mailboxes. It keeps the msExch* schema extensions, the per-user attribute values (proxy addresses, custom attributes and so on) and the CN=Microsoft Exchange Autodiscover container with its Exchange Online SCP, which redirects domain-joined Outlook clients to Exchange Online.

Step 7: Clean up Exchange Online

Look for orphaned hybrid records:

Get-IntraOrganizationConnector
Get-OrganizationRelationship
Get-OnPremisesOrganization
Get-MigrationEndpoint
Get-AcceptedDomain

Remove the on-premises organization object with Remove-OnPremisesOrganization and the hybrid migration endpoint with Remove-MigrationEndpoint. If your domain is still InternalRelay from hybrid, change it to Authoritative with Set-AcceptedDomain once every recipient exists in Exchange Online.

Verification

  1. Edit a custom attribute with Set-Mailbox in Exchange Online and confirm it sticks after the next sync cycle. If writeback is on, confirm the value arrives in Active Directory after about 20 minutes or by using Provision on demand.
  2. Send inbound and outbound test mail and trace it in the Exchange admin center under Mail flow > Message trace.
  3. Open Outlook on a domain-joined machine inside the network and confirm Autodiscover lands on Exchange Online.
  4. Confirm every former relay device can still send.

Troubleshooting

Cloud edits are overwritten or sync errors appear after the flip. Check the Entra Connect Sync version is 2.5.190.0 or later.

Recipient type wrong in Active Directory after writeback. The mailbox was likely flipped before post-move attributes finished syncing. Wait the full sync cycle plus 24 hours on new moves before flipping.

New on-premises users don't get the expected cloud recipient. Tenant-wide SOA was enabled while on-premises recipients were still being created. Disable it with Set-OrganizationConfig -ExchangeAttributesServerManagedByDefault, then run Set-User -Identity <user> -ExchangeAttributesServerManaged for each affected user.

Uninstall refuses to continue. A mailbox of some type still exists. Rerun the five Get-Mailbox checks from Step 1.

You used EMT and already ran CleanupActiveDirectoryEMT.ps1. If you wiped the server, no uninstall is needed. If you only shut it down, power it on and run Setup /m:Uninstall as a Domain Admin.

You need to move a mailbox back on-premises later. Set IsExchangeCloudManaged to $false first; otherwise on-premises updates are blocked and offboarding breaks.

Checklist

  • No user, archive, public folder, arbitration or audit mailboxes on-premises.
  • Entra Connect Sync 2.5.190.0 or later (or Cloud Sync) in place.
  • IsExchangeCloudManaged set on every synced mailbox; groups and contacts moved with Entra SOA transfer.
  • Writeback configured if on-premises apps read Exchange attributes.
  • MX, Autodiscover (internal and external) and SCP updated; Centralized Mail Transport off.
  • Relay devices moved.
  • Hybrid configuration, connectors, organization relationship, federation trust and certificate removed; OAuth credentials reset; Hybrid Agent removed.
  • Setup /m:Uninstall completed and Exchange Online orphans cleaned up.

References

Questions people ask

Can I uninstall the last Exchange server if I still use Entra Connect?

Yes, once Exchange-attribute source of authority has moved to the cloud. Set IsExchangeCloudManaged to true on every directory-synchronized mailbox (or transfer the whole user object's source of authority), move groups and contacts with Group and Contact SOA transfer, then follow Microsoft's last Exchange server procedure. Without that transfer, you still need an Exchange server or the Exchange Management Tools to edit Exchange attributes.

What is the difference between the Exchange Management Tools method and uninstalling?

The Exchange Management Tools method lets you shut down the last server and manage recipients with PowerShell, but you must not uninstall it, because uninstall removes Active Directory objects the tools depend on. The newer source of authority path moves management to Exchange Online, so the server can be fully uninstalled with Setup /m:Uninstall.

Do I need Exchange Server SE if I keep one server for management?

Support for Exchange Server 2016 and 2019 ended on October 14, 2025. If you keep any Exchange server, including one used only for recipient management, Microsoft recommends upgrading it to Exchange Server SE.

What happens to SMTP relay when I uninstall Exchange?

Uninstalling Exchange removes all receive connectors, so printers, scanners and applications that relay through the server stop sending mail. Move them to Exchange Online SMTP relay or another service before you uninstall, or keep the server running.

Exchange hybridExchange Server SEEntra ConnectExchange OnlinePowerShell
  1. Exchange 2016 and 2019 end of support: move to Exchange SE or Online

    Exchange 2016 and 2019 are out of support and the paid ESU ends with October 2026. Choose between Exchange Server SE and Exchange Online, then plan the upgrade or migration.

    Microsoft 36510 min read
  2. Exchange hybrid remote move migration: endpoints, batches and completion

    Move mailboxes from on-premises Exchange to Exchange Online with remote move migration: enable MRS Proxy, test the endpoint, build batches, schedule completion and clean up.

    Microsoft 36512 min read
  3. Exchange Online mail flow rules: disclaimers, external tags and blocking

    Build Exchange Online mail flow rules for outbound disclaimers, external sender warnings and attachment blocking, then test, order and troubleshoot them in the EAC and PowerShell.

    Microsoft 36514 min read