Link to home
Start Free TrialLog in
Avatar of CHI-LTD
CHI-LTDFlag for United Kingdom of Great Britain and Northern Ireland

asked on

Teams client getting certificate warning while i deploy new hybrid exchange server 2016

Hi
I am midway through installing a new exchange 2016 server (its currently about halfway) and one of my users had a certificate prompt come up in Microsoft Teams.  The cert was referencing the new server name and the certificate was autodiscover.domain.com

I have pre-populated some of the settings in DNS for the hybrid box, namely the autodiscover record and an A record for the mail.domain.com dns record

Ideas?  

Should the certificate be installed by GPO?  I recall the exchange server 2010 certs maybe in GPO..
Avatar of Hypercat (Deb)
Hypercat (Deb)
Flag of United States of America image

Unless your users are using Office 365 for email, try turning OFF autodiscover for O365.  This can be done in the registry but it has to be done on all workstations.  Of course it can be deployed by group policy if you have a large organization.  The regedit is:

  1. Find (or create if it doesn't exist) the following regkey: HKEY_Current_User\Software\Microsoft\Office\16.0\Outlook\Autodiscover.
  2. Add the following entry:  REG_DWORD, ExcludeExplicitO365Endpoint, Value =1



Avatar of CHI-LTD

ASKER

Yes all mailboxes are using exchange online.  
Then you're running in a hybrid configuration?
When the user accepted the certificate, did he get an error or did it just close the dialog box?
Avatar of CHI-LTD

ASKER

Not in a true sense of mailboxes on prem and online, no, but its still hybrid config on the 2010 setup/side and its used to migrate mailboxes and continue with SMTP traffic etc.
Avatar of CHI-LTD

ASKER

Closed the cert prompt.
If you install an on-premises Exchange server, it automatically adds its availability to AD.

To prevent this from being a problem, I recommend you install new Exchange servers into a "micro-site". An AD site that only contains a few addresses to hold the Exchange servers. Then, when installation and configuration is complete, change the IP address of the Exchange server to be in the primary/default/destination AD site.
It's difficult to answer without knowing your current configuration.  For example, do you have centralized routing enabled? ie. does autodiscover.yourdomain.com point to your on-prem server or exchange online.

This site has some troubleshooting steps: https://docs.microsoft.com/en-us/microsoftteams/troubleshoot/known-issues/teams-exchange-interaction-issue

Avatar of CHI-LTD

ASKER

We already have 2010 exchange on prem acting as hybrid. Why would a new 2016 server affect everyone?

Not sure i follow you re micro site..
Avatar of CHI-LTD

ASKER

nslookup for autodiscover.domain.local shows old exchange.  autodiscover.domain.com resolves to all 3 servers
So you need the certificate for autodiscover.domain.com on all three servers.  Either that or just point autodiscover to the servers that have certificates configured.

If any client connects to a server that doesn't have a certificate installed, it will get a certificate error.
Avatar of CHI-LTD

ASKER

ok i did wonder.
i've found this: https://www.alitajran.com/certificate-warning-during-or-after-a-new-exchange-server-installation/ which may negate the certificate?
ASKER CERTIFIED SOLUTION
Avatar of Daryl Ponting
Daryl Ponting
Flag of United Kingdom of Great Britain and Northern Ireland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of CHI-LTD

ASKER

I've installed the cert but cannot see it in the EAC..  Very strange.

Also us admins are not getting this warning, just users..
Avatar of CHI-LTD

ASKER

Running through the hybrid wizard and getting
User generated image
There's a load of stuff you need to do first such as configuring the virtual directories on the new server.

Look at this page: https://msexperttalk.com/exchange-2010-to-exchange-2016-migration-part-3/

Follow the instructions for exporting/importing the certificate and configuring the virtual directories to match the names on the certificate.
Avatar of CHI-LTD

ASKER

Great link.  prompts now gone by the looks of it.
should the 'Configure virtual directories in Exchange 2016 Server' and below be done?
Avatar of CHI-LTD

ASKER

Did you migrate all mailboxes across from 10 to 16?  I see that there are a few that probably arent required, but 2010 will be decommissioned soon, so..;
User generated image
interestingly i cannot access out admin mailbox using the https://mail.domain.com/owa/administrator@domain.com url.   
Migrate the administrator mailbox.
Migrate the arbitration mailboxes.  See here: https://www.alitajran.com/move-arbitration-mailboxes-in-exchange-server/

Can you access the admin mailbox if you go to: https://mail.domain.com/owa/  and sign in as the administrator?
Avatar of CHI-LTD

ASKER

i see i managed to reply top the other issue.

no, i cannot access the admin mailbox.
User generated image