A professional services organization still depended on Exchange Server SE for a small on-premises mailbox population and rich coexistence with Exchange Online. Microsoft’s move from Exchange Web Services to Microsoft Graph meant the hybrid connection needed an update—but free/busy lookups, MailTips, and profile photos could not become collateral damage.
- ~460Total mailboxes
- 2Exchange SE servers
- 3Coexistence features tested
- 4 weeksAssessment through handoff
What success meant here: install the supported Exchange SE update, move the dedicated hybrid application to the required Microsoft Graph permissions, prove every user-facing coexistence path, and retain a clear rollback decision—not simply finish a script without errors.
The situation
Most users were already in Exchange Online, but a regulated business unit and several application workflows remained on-premises. Calendar availability crossed the boundary throughout the day. MailTips reduced misdirected messages, and executive assistants depended on consistent profile and scheduling behavior.
The organization had completed an earlier hybrid application change, but the Graph transition introduced a second set of prerequisites. The risk was not the update alone; it was the interaction among server build level, organization relationships, application consent, certificate state, network paths, and feature behavior in both directions.
Baseline findings
- Exchange Server SE was supported but had not yet received the hotfix level required for Graph-based hybrid features
- The dedicated Exchange hybrid application existed, but its permissions reflected the earlier configuration stage
- Free/busy worked today, yet there was no repeatable cross-premises test matrix
- Hybrid certificates were valid, though renewal ownership and monitoring were not documented
- Change approval focused on server health and did not include user-facing coexistence acceptance criteria
- Rollback steps existed in fragments across tickets and administrator notes
How we worked
Mapped the dependency chain before touching production
We documented both Exchange servers, hybrid applications, certificates, organization relationships, OAuth configuration, public endpoints, and mail flow. Test accounts represented cloud, on-premises, delegated-calendar, and mobile scenarios. That inventory established exactly what needed to remain true after the change.
Separated server maintenance from permission change
The required Exchange SE hotfix was installed and health-checked first. Database, transport, event-log, service, and certificate checks were completed before the Graph configuration was introduced. This prevented a server-update problem from being confused with an application-consent problem.
Updated the dedicated hybrid application deliberately
The supported configuration script was reviewed, the required Microsoft Graph application permissions were granted through an approved administrator, and the resulting application and service-principal state was recorded. Consent was treated as a controlled identity change, not a copy-and-paste step.
Piloted every direction
Free/busy, MailTips, and profile-photo behavior were validated from cloud to on-premises and from on-premises to cloud. We tested normal users, delegates, shared calendars, cached clients, Outlook on the web, and the failure signals administrators would see if permissions or endpoints drifted later.
Turned the update into an operating procedure
The handoff included a build baseline, consent record, post-update checks, certificate ownership, monitoring queries, and a decision tree for future security and hotfix updates. The next administrator would not need to reconstruct the transition from browser history.
Change sequence
| Phase | Change | Release gate |
|---|---|---|
| Discover | Inventory hybrid topology, applications, certificates, and feature paths | Known owners and rollback inputs |
| Update | Install supported Exchange SE hotfix and complete health checks | Clean server and transport validation |
| Configure | Apply supported hybrid application configuration and Graph consent | Expected permissions and configuration state |
| Pilot | Test coexistence in both directions with representative users | No unexplained feature failures |
| Operate | Document monitoring, renewal, update, and rollback responsibilities | Internal team can repeat the checks |
Results
- Hybrid rich coexistence moved to the supported Microsoft Graph path with no user-facing cutover window
- Free/busy, MailTips, and profile-photo sharing passed the bidirectional acceptance matrix
- The dedicated hybrid application had only the documented permissions required for the design
- Exchange server health, hybrid configuration, and user-experience testing became separate, repeatable gates
- Certificate and application ownership moved from institutional knowledge into the operations calendar
- The company gained a reusable runbook for future Exchange SE updates instead of another one-off maintenance event
What this engagement was not
It was not an argument to keep more mailboxes on-premises. The remaining hybrid footprint had a defined business reason and an exit review date. The project made today’s coexistence supportable while preserving the organization’s longer-term path to simplify it.
Technical context
Microsoft documents Microsoft Graph support for Exchange Server SE hybrid free/busy, profile photos, and partial MailTips beginning with the May 2026 Hotfix Update. Administrators should follow the current Microsoft instructions for their exact server build and tenant rather than treating this representative sequence as a command-level procedure.
Microsoft Support: Graph support for Exchange Server SE hybrid features
Is your Exchange hybrid configuration ready for Graph?
We can assess the server build, dedicated hybrid application, permissions, certificates, and coexistence paths, then give you a controlled update and validation plan.
Plan the hybrid update