How to Fix Exchange Hybrid Configuration Wizard SSL and WinRM Errors
Question details
The user needs to resolve connection errors involving SSL, New-PSSession, and missing WinRM HTTPS certificates when running the Exchange Server Hybrid Configuration Wizard.

- Product
- Microsoft Exchange Server
- Device & OS
- not provided
- Scenario
- Setting up a hybrid environment between an on-premises Exchange Server and Microsoft 365.
- Observed behavior
- The hybrid configuration setup fails, displaying errors related to outlook.office365.com connections, New-PSSession failures, and a missing or invalid WinRM HTTPS certificate.
Ensure you have administrative privileges to the Exchange Server and your Microsoft 365 tenant, and verify that the server has an active, unrestricted internet connection.
Install and Bind a Valid SSL Certificate for WinRM
WinRM errors typically occur when the local computer lacks a suitable, unexpired certificate for an HTTPS listener.
The Windows Remote Management (WinRM) service requires a specific certificate structure to securely connect to Microsoft 365. If this certificate is expired, missing, or misconfigured, the Hybrid Configuration Wizard will fail to establish a remote session.
Open the local computer's certificate manager (certlm.msc) and ensure the SSL certificate's subject name exactly matches the server's host name.
Double-click the certificate, go to the Details tab, and confirm that the 'Enhanced Key Usage' property includes 'Server Authentication'.
Check the valid from/to dates to ensure the certificate has not expired. If it has, you must generate or purchase a new certificate and bind it to the HTTPS port.

Configure Network, Firewall, and TLS Settings
Connectivity to outlook.office365.com requires proper outbound routing, unrestricted proxy traversal, and secure TLS protocols.
Open a Microsoft 365 Support Request
Hybrid configuration involves complex backend routing and may require Microsoft support if local configurations are fully validated.
Try WPS Office: A Lightweight and Free Alternative for Your Daily Work
While resolving complex Exchange Server and Microsoft 365 hybrid configurations can be highly technical and time-consuming, managing your daily documents shouldn't be. WPS Office provides a free, lightweight, and highly compatible alternative to Microsoft Office, letting you handle Word, Excel, and PowerPoint files without the heavy overhead.
- 1. Download the Installer: Visit the official WPS Office website and download the free installation package for your operating system.
- 2. Install WPS Office: Run the setup file and follow the quick on-screen instructions to install the suite in minutes.
- 3. Open Your Files: Launch WPS Office to instantly open, edit, and save your existing Microsoft Office documents with perfect formatting.

Frequently Asked Questions
Why does the Hybrid Configuration Wizard throw a WinRM HTTPS certificate error?
This error occurs because the Windows Remote Management (WinRM) service requires a valid, unexpired SSL certificate with a subject name matching the server's hostname and enabled for Server Authentication to establish a secure listening port.
What are the network port requirements for the Exchange Hybrid Configuration Wizard?
The wizard primarily requires outbound HTTPS (port 443) connectivity from your on-premises Exchange Server to access Microsoft 365 services, such as outlook.office365.com, to establish remote PowerShell sessions.
Can antivirus software block the Hybrid Configuration Wizard from running?
Yes, strict antivirus or endpoint protection software can intercept or block the outbound HTTPS connections or the remote PowerShell scripts (New-PSSession) required during the setup. Temporarily disabling them or adding exclusions can help isolate the issue.




