logo
search
Others

Impact of Sectigo Mutual TLS Certificate Changes on Exchange Hybrid

Maira MehtabMaira Mehtab Sep 22, 2026 869 views

Question details

The user needs to understand the potential impact on Exchange Online hybrid deployments when Sectigo removes the Client Authentication EKU from its mutual TLS certificates, and whether other Certificate Authorities will follow suit.

Product
Microsoft Exchange
Device & OS
not provided
Scenario
Evaluating infrastructure impact due to upcoming certificate authority policy changes in a hybrid environment.
Observed behavior
Seeking technical clarification on what specific services might break and how to prepare for the EKU removal.
Before you start

Before reaching out for support, gather your current Exchange Server build numbers, your exact Sectigo certificate properties, and the configuration details of your hybrid mail flow connectors.

Solution 1Recommended

Consult Microsoft Exchange Hybrid Specialists via Microsoft Learn

Because EKU changes involve complex enterprise infrastructure and mail routing, the most reliable way to assess the impact is to consult directly with Exchange Hybrid specialists.

Certificate requirements for Exchange Hybrid environments are strict. The removal of the Client Authentication EKU can potentially disrupt mutual TLS (mTLS) authentication between on-premises Exchange servers and Exchange Online.

Microsoft's dedicated engineers and community MVPs on the Microsoft Learn platform are best equipped to analyze your specific deployment and advise on compliant certificate alternatives.

1
Navigate to Microsoft Learn Q&A

Open your web browser and go to the official Microsoft Learn Q&A platform.

2
Locate the Exchange Hybrid Management Forum

Use the search or tag filtering system to find the 'Exchange Hybrid Management' specific forum, ensuring your question reaches the right experts.

3
Post Your Detailed Configuration

Create a new thread detailing your current Sectigo certificate, your hybrid setup, and your specific concerns regarding the Client Authentication EKU removal.

Free Microsoft Office alternative

Manage Your IT Infrastructure Documentation with WPS Office

While resolving complex Exchange Server issues requires specialized Microsoft channels, you still need reliable software to document your hybrid deployment plans, draft migration scripts, and analyze server logs. WPS Office offers a powerful, lightweight alternative to Microsoft Office for IT professionals.

  1. 1. Download the Installer: Visit the official WPS Office website and click on 'Download WPS Office Free'.
  2. 2. Install the Suite: Run the lightweight setup file and follow the on-screen instructions to complete the installation in minutes.
  3. 3. Manage IT Documents: Open your CSV log files, deployment spreadsheets, or server documentation seamlessly within the unified workspace.
Fully compatible with Microsoft Word, Excel, and PowerPoint file formats.Lightweight installation that won't consume heavy resources on administrative workstations.Built-in PDF toolkit for reading and annotating Certificate Authority policy documents and technical guides.Free to use with a familiar, tabbed interface for seamless task management.
QA img-9

Frequently Asked Questions

What is the Client Authentication EKU in a TLS certificate?

EKU stands for Extended Key Usage. The Client Authentication EKU is a specific attribute that dictates the certificate can be used by a client to prove its identity to a server during a mutual TLS (mTLS) handshake.

Why would removing the Client Authentication EKU break Exchange Hybrid?

Exchange Hybrid heavily relies on mutual TLS to secure mail flow and synchronize data between on-premises servers and Microsoft 365. If the certificate used for the hybrid connector lacks the required authentication properties, the connection may be rejected, halting mail flow.

Are other Certificate Authorities planning to remove this EKU?

Changes to EKU policies are often driven by industry-wide security standards, such as those set by the CA/Browser Forum. It is highly likely that other major Certificate Authorities will implement similar restrictions over time.

How can I check if my current Exchange certificate uses this EKU?

You can view your certificate details via the Exchange Admin Center or the local Windows Certificate Manager (certlm.msc). Double-click the certificate, navigate to the 'Details' tab, and look for 'Enhanced Key Usage' to see if 'Client Authentication' is listed.