Impact of Sectigo Mutual TLS Certificate Changes on Exchange Hybrid
Question details
The user needs to understand the potential impact on Exchange Online hybrid deployments when Sectigo removes the Client Authentication EKU from its mutual TLS certificates, and whether other Certificate Authorities will follow suit.
- Product
- Microsoft Exchange
- Device & OS
- not provided
- Scenario
- Evaluating infrastructure impact due to upcoming certificate authority policy changes in a hybrid environment.
- Observed behavior
- Seeking technical clarification on what specific services might break and how to prepare for the EKU removal.
Before reaching out for support, gather your current Exchange Server build numbers, your exact Sectigo certificate properties, and the configuration details of your hybrid mail flow connectors.
Consult Microsoft Exchange Hybrid Specialists via Microsoft Learn
Because EKU changes involve complex enterprise infrastructure and mail routing, the most reliable way to assess the impact is to consult directly with Exchange Hybrid specialists.
Certificate requirements for Exchange Hybrid environments are strict. The removal of the Client Authentication EKU can potentially disrupt mutual TLS (mTLS) authentication between on-premises Exchange servers and Exchange Online.
Microsoft's dedicated engineers and community MVPs on the Microsoft Learn platform are best equipped to analyze your specific deployment and advise on compliant certificate alternatives.
Open your web browser and go to the official Microsoft Learn Q&A platform.
Use the search or tag filtering system to find the 'Exchange Hybrid Management' specific forum, ensuring your question reaches the right experts.
Create a new thread detailing your current Sectigo certificate, your hybrid setup, and your specific concerns regarding the Client Authentication EKU removal.
Manage Your IT Infrastructure Documentation with WPS Office
While resolving complex Exchange Server issues requires specialized Microsoft channels, you still need reliable software to document your hybrid deployment plans, draft migration scripts, and analyze server logs. WPS Office offers a powerful, lightweight alternative to Microsoft Office for IT professionals.
- 1. Download the Installer: Visit the official WPS Office website and click on 'Download WPS Office Free'.
- 2. Install the Suite: Run the lightweight setup file and follow the on-screen instructions to complete the installation in minutes.
- 3. Manage IT Documents: Open your CSV log files, deployment spreadsheets, or server documentation seamlessly within the unified workspace.

Frequently Asked Questions
What is the Client Authentication EKU in a TLS certificate?
EKU stands for Extended Key Usage. The Client Authentication EKU is a specific attribute that dictates the certificate can be used by a client to prove its identity to a server during a mutual TLS (mTLS) handshake.
Why would removing the Client Authentication EKU break Exchange Hybrid?
Exchange Hybrid heavily relies on mutual TLS to secure mail flow and synchronize data between on-premises servers and Microsoft 365. If the certificate used for the hybrid connector lacks the required authentication properties, the connection may be rejected, halting mail flow.
Are other Certificate Authorities planning to remove this EKU?
Changes to EKU policies are often driven by industry-wide security standards, such as those set by the CA/Browser Forum. It is highly likely that other major Certificate Authorities will implement similar restrictions over time.
How can I check if my current Exchange certificate uses this EKU?
You can view your certificate details via the Exchange Admin Center or the local Windows Certificate Manager (certlm.msc). Double-click the certificate, navigate to the 'Details' tab, and look for 'Enhanced Key Usage' to see if 'Client Authentication' is listed.




