Prevent/Fix: Guidance for On-Premises Connectors Configuration
Ensure On-Premises connectors use unique certificates with domains accepted by the tenant and avoid shared IPs across tenants. Misconfigurations can disrupt mail flow due to Exchange Online’s multi-tenant nature. Use unique Send Connectors per tenant and prefer certificate-based authentication for reliable email routing. We are reiterating the guidance for connector settings to ensure customers are using healthy configurations. The key problematic configurations we are seeing are: When a tenant has an Inbound connector of type OnPremises and the connector does certificate-based authentication using a certificate with a subject/SAN for a domain that is NOT an Accepted Domain of the tenant. When a tenant has an Inbound connector of type OnPremises and the connector does IP-based authentication, but the IP is used by other tenants. These anti-patterns typically occur when you are using a 3rd party service to relay email through Exchange Online but could also occur if your organization has a single on-premises Exchange Server connecting to multiple Exchange Online tenants. These configurations can cause incorrect mail flow because Exchange Online is a multi tenant service and relies on message attribution to determine which tenant an incoming message belongs to. When messages are received through an Inbound connector of type OnPremises, attribution is determined using the following priority order: The domain on the TLS certificate presented by the sending server The P1 MailFrom (envelope sender) domain The P1 RcptTo (recipient) domain How this will affect your organization: We may perform internal changes, such as tenant moves, without notice, which can impact mail flow if a tenant has a bad connector configuration. This means a misconfigured connector that works today may unexpectedly stop working. What you need to do to prepare: If you have a single on-premises Exchange Server connecting to multiple Exchange Online tenants, your on-premises Exchange environment must use a unique client certificate to send to each unique Exchange Online tenant belonging to your organization. You must configure a unique Send Connector on-premises for each unique tenant in Exchange Online that you want to route on-premises traffic to: Send connectors in Exchange Server | Microsoft Learn. You should also […]
The post Prevent/Fix: Guidance for On-Premises Connectors Configuration appeared first on M365 Admin.
Published on:
Learn moreWe can help you with Prevent/Fix: Guidance for On-Premises Connectors Configuration
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
OneDrive Photos on Windows: admin controls and policy support
OneDrive Photos, integrated into the OneDrive sync app for Windows 10/11, is currently available only for personal Microsoft accounts, with wo...
Admin app retiring in Teams, Outlook and Microsoft365.com
The Admin app for very small businesses in Teams, Outlook, and Microsoft365.com will retire by October 2026, with rollout starting August 2026...
Calls popout into a new window on the browser to support multi-tasking and collaboration during a meeting
Microsoft Teams for Web will introduce a Picture-in-Picture Call Monitor in October 2026, allowing users to manage meeting controls in a separ...
Microsoft Windows Autopatch: September 2026 Windows security update requires a restart for hotpatch-enabled devices
The September 2026 Windows security update requires a restart for hotpatch-enabled devices because it is a standard update. Devices will remai...
Outlook for iOS: Minimum system requirements updated to iOS 26 and above
Outlook for iOS will require iOS 26 or later starting mid-September 2026, supporting only the two latest iOS, iPadOS, and watchOS versions. Us...
Allow connections to copilot.cloud.microsoft before the Copilot URL redirect
Starting September 2026, Microsoft will redirect users from m365.cloud.microsoft to copilot.cloud.microsoft. Organizations must ensure network...
Prepare for the removal of WMIC from Windows 11
The Windows Management Instrumentation command-line (WMIC) utility has been removed from Windows 11, version 24H2 and later. It’s no longer av...
Microsoft Agent 365: Active Users export for agent usage reporting
Microsoft Agent 365 will add an Active Users export in the Microsoft 365 admin center, allowing AI and Global Admins to generate a CSV report ...
The August 2026 Windows non-security preview update is now available
The August 2026 non-security preview update is now available for Windows 11, versions 26H1, 25H2, and 24H2. Information about the contents of ...
Dynamics 365 Project Operations – Assign task level schedule mode for precise planning
We are announcing the ability to assign task level schedule mode for precise planning in Dynamics 365 Project Operations. This feature will re...