

Get-AutodiscoverVirtualDirectory | FL server,*url* Get-OABVirtualDirectory | FL server,*url* Get-ClientAccessServer | fl Name, AutodiscoverServiceInternalUri Get-WebServicesVirtualDirectory | FL server,*url* Run these commands on-premises: Get-MapiVirtualDirectory | FL server,*url* All the URLs that might be used to connect from on-premises to Azure Active Directory (Azure AD) must be registered in Azure AD (this includes both internal and external namespaces).įirst, gather all the URLs that you need to add in AAD. SPNs are used by client machines and devices during authentication and authorization. Run the commands that assign your on-premises web service URLs as Azure AD SPNs. Add on-premises web service URLs as SPNs in Azure AD In addition, publishing Outlook Web App and Exchange Control Panel through Azure AD Application Proxy is unsupported. Outlook Web App and Exchange Control Panel do not work with hybrid Modern Authentication. In case EXCH is in hybrid with multiple tenants, these on-premises web service URLs must be added as SPNs in the Azure AD of all the tenants which are in hybrid with EXCH.Įnsuring all Virtual Directories are enabled for HMAĬhecking for the EvoSTS Auth Server object Requirements about linked mailboxes to be inserted.Īdding on-premises web service URLs as Service Principal Names (SPNs) in Azure AD.

Do this before you begin any of the steps in this article.

Since many prerequisites are common for both Skype for Business and Exchange, Hybrid Modern Authentication overview and prerequisites for using it with on-premises Skype for Business and Exchange servers. Enabling Hybrid Modern Authenticationīeing sure you meet the prereqs before you begin. Definitionsīefore we begin, you should be familiar with some definitions:Īlso, if a graphic in this article has an object that's 'grayed-out' or 'dimmed' that means the element shown in gray is not included in HMA-specific configuration. Hybrid Modern Authentication (HMA) is a method of identity management that offers more secure user authentication and authorization, and is available for Exchange server on-premises hybrid deployments. This article applies to both Microsoft 365 Enterprise and Office 365 Enterprise.
