Exchange Online relay connector and TLS - Microsoft Q&A (2024)

Table of Contents
1 additional answer Your answer

Share via

Exchange Online relay connector and TLS - Microsoft Q&A (1)

Kenny Stern 51Reputation points

2021-11-18T15:11:29.687+00:00

Currently in hybrid mode with Exchange and Exchange Online. We've migrated all mailboxes but would like to keep using an Exchange on-prem server for SMTP relay. I have a connector in Exchange online for relay that is secured by verifying the IP address of the sender and I have the external IP address of the Exchange server added. This is working fine but I've noticed that RequireTLS is set to False and there is not TLSSenderCertificateName on this connector.
So my questions are...
Are emails that are relayed through our on-prem Exchange server to Exchange online encrypted?
If not, what do I need to do to ensure that they are?

Thanks

Microsoft Exchange Online Management

Microsoft Exchange Online Management

Microsoft Exchange Online: A Microsoft email and calendaring hosted service.Management: The act or process of organizing, handling, directing or controlling something.

4,486 questions

Exchange Server Management

Exchange Server Management

Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.

7,602 questions

Microsoft Exchange Hybrid Management

Sign in to follow

0 commentsNo comments

0{count} votes

    Sign in to comment

    Accepted answer

    1. Exchange Online relay connector and TLS - Microsoft Q&A (2)

      Andy David - MVP 147.6KReputation points MVP

      2021-11-18T15:53:35.097+00:00

      Yes, that TLSSenderCertificateName attribute only comes into play when TLS is forced.

      In a hybrid environment, you force TLS

      Exchange on-prem will send messages using TLS and Exchange Online will use TLS by default as well - so you are covered.

      THe only way it wont would be using a SMTP relay that doesnt support TLS or you created a connector that disabled that.

      1. Exchange Online relay connector and TLS - Microsoft Q&A (3)

        Kenny Stern 51Reputation points

        2021-11-18T16:54:40.637+00:00

        Excellent. thanks so much

      Sign in to comment

    1 additional answer

    Sort by: Most helpful
    1. Exchange Online relay connector and TLS - Microsoft Q&A (4)

      Andy David - MVP 147.6KReputation points MVP

      2021-11-18T15:14:48.213+00:00

      They are because it will use Opportunistic TLS.

      https://learn.microsoft.com/en-us/microsoft-365/compliance/exchange-online-uses-tls-to-secure-email-connections?view=o365-worldwide

      By default, Exchange Online always uses opportunistic TLS. This means Exchange Online always tries to encrypt connections with the most secure version of TLS first, then works its way down the list of TLS ciphers until it finds one on which both parties can agree. Unless you have configured Exchange Online to ensure that messages to that recipient are only sent through secure connections, then by default the message will be sent unencrypted if the recipient organization doesn't support TLS encryption. Opportunistic TLS is sufficient for most businesses. However, for business that have compliance requirements such as medical, banking, or government organizations, you can configure Exchange Online to require, or force, TLS. For instructions, see Configure mail flow using connectors in Office 365.

      If you want to force TLS you can:

      https://learn.microsoft.com/en-us/exchange/mail-flow-best-practices/use-connectors-to-configure-mail-flow/use-connectors-to-configure-mail-flow

      1. Exchange Online relay connector and TLS - Microsoft Q&A (5)

        Kenny Stern 51Reputation points

        2021-11-18T15:48:50.46+00:00

        Is that true even if the setting on the Exchange Online receive connector for TLSSenderCertificateName is blank? The concern is that emails going from our on-prem Exchange server, which is only used for SMTP relay, are not encrypted to 365. Sounds like you are saying they are but want to be sure.
        Thanks for the quick reply.

      Sign in to comment

    Sign in to answer

    Your answer

    Exchange Online relay connector and TLS - Microsoft Q&A (2024)
    Top Articles
    Bitgert, Binance Coin, Bitcoin, Ethereum - When the Bull Run Might Start
    Exiting out of Safe Mode or Android Recovery Mode | Samsung Australia
    Diario Las Americas Rentas Hialeah
    CLI Book 3: Cisco Secure Firewall ASA VPN CLI Configuration Guide, 9.22 - General VPN Parameters [Cisco Secure Firewall ASA]
    Overnight Cleaner Jobs
    My Boyfriend Has No Money And I Pay For Everything
    Santa Clara College Confidential
    Jefferson County Ky Pva
    Category: Star Wars: Galaxy of Heroes | EA Forums
    Joe Gorga Zodiac Sign
    Stream UFC Videos on Watch ESPN - ESPN
    Corporate Homepage | Publix Super Markets
    Anki Fsrs
    ‘Accused: Guilty Or Innocent?’: A&E Delivering Up-Close Look At Lives Of Those Accused Of Brutal Crimes
    Walmart Windshield Wiper Blades
    Georgia Vehicle Registration Fees Calculator
    Yakimacraigslist
    China’s UberEats - Meituan Dianping, Abandons Bike Sharing And Ride Hailing - Digital Crew
    Mychart Anmed Health Login
    Hdmovie 2
    Raz-Plus Literacy Essentials for PreK-6
    Baja Boats For Sale On Craigslist
    Silky Jet Water Flosser
    Il Speedtest Rcn Net
    Is Henry Dicarlo Leaving Ktla
    Downtown Dispensary Promo Code
    Will there be a The Tower season 4? Latest news and speculation
    My Reading Manga Gay
    Osrs Important Letter
    R/Mp5
    Fairwinds Shred Fest 2023
    Devin Mansen Obituary
    Craigslist Car For Sale By Owner
    Foolproof Module 6 Test Answers
    Bimar Produkte Test & Vergleich 09/2024 » GUT bis SEHR GUT
    Skill Boss Guru
    Vision Source: Premier Network of Independent Optometrists
    NHL training camps open with Swayman's status with the Bruins among the many questions
    Saybyebugs At Walmart
    2023 Nickstory
    Obituaries in Hagerstown, MD | The Herald-Mail
    Emily Browning Fansite
    Tattoo Shops In Ocean City Nj
    Dragon Ball Super Super Hero 123Movies
    Craigslist Pet Phoenix
    Definition of WMT
    Uno Grade Scale
    Mawal Gameroom Download
    Hy-Vee, Inc. hiring Market Grille Express Assistant Department Manager in New Hope, MN | LinkedIn
    Where To Find Mega Ring In Pokemon Radical Red
    Adams County 911 Live Incident
    Cataz.net Android Movies Apk
    Latest Posts
    Article information

    Author: Horacio Brakus JD

    Last Updated:

    Views: 6741

    Rating: 4 / 5 (51 voted)

    Reviews: 90% of readers found this page helpful

    Author information

    Name: Horacio Brakus JD

    Birthday: 1999-08-21

    Address: Apt. 524 43384 Minnie Prairie, South Edda, MA 62804

    Phone: +5931039998219

    Job: Sales Strategist

    Hobby: Sculling, Kitesurfing, Orienteering, Painting, Computer programming, Creative writing, Scuba diving

    Introduction: My name is Horacio Brakus JD, I am a lively, splendid, jolly, vivacious, vast, cheerful, agreeable person who loves writing and wants to share my knowledge and understanding with you.