{"id":4135,"date":"2023-03-21T03:00:09","date_gmt":"2023-03-21T03:00:09","guid":{"rendered":"https:\/\/www.sebae.net\/blog\/best-practices-for-migrating-from-exchange-server-2013-to-exchange-server-2019\/"},"modified":"2023-03-21T03:00:09","modified_gmt":"2023-03-21T03:00:09","slug":"best-practices-for-migrating-from-exchange-server-2013-to-exchange-server-2019","status":"publish","type":"post","link":"https:\/\/www.sebae.net\/blog\/best-practices-for-migrating-from-exchange-server-2013-to-exchange-server-2019\/","title":{"rendered":"Best Practices for Migrating from Exchange Server 2013 to Exchange Server 2019"},"content":{"rendered":"<div>\n<p><a href=\"https:\/\/techcommunity.microsoft.com\/t5\/exchange-team-blog\/exchange-server-2013-reaches-end-of-support-next-month\/ba-p\/3762083\" target=\"_self\" rel=\"noopener\">Time is up for Exchange Server 2013<\/a>, and you should be finalizing your migrations. If your migration is still ahead of you or nearing completion, then this post is for you.<\/p>\n<p>We wanted to provide Microsoft\u2019s best practices for preparing and planning your migration from Exchange 2013 to Exchange Server 2019. It\u2019s important to note that because of the many different possible topologies and configurations for Exchange 2013, we can\u2019t cover all migration scenarios, but the common steps are included here. That said, please plan your migration carefully and include all aspects of the environment, bearing in mind that some of the steps below may or may not apply to your situation (we will err on the side of over-communicating details).<\/p>\n<h1 id=\"toc-hId--1961145781\"><span id=\"prepare\">Prepare<\/span><\/h1>\n<p>Here are a few references that will be\u00a0useful to you throughout\u00a0your migration:<\/p>\n<ul>\n<li><a href=\"https:\/\/learn.microsoft.com\/exchange\/architecture\/architecture?view=exchserver-2019\" target=\"_blank\" rel=\"noopener noreferrer\">Exchange Server 2019 Architecture<\/a><\/li>\n<li><a href=\"https:\/\/learn.microsoft.com\/exchange\/plan-and-deploy\/system-requirements?view=exchserver-2019\" target=\"_blank\" rel=\"noopener noreferrer\">Exchange 2019 System Requirements<\/a><\/li>\n<li><a href=\"https:\/\/learn.microsoft.com\/Exchange\/plan-and-deploy\/supportability-matrix?view=exchserver-2019\" target=\"_blank\" rel=\"noopener noreferrer\">Exchange Server Supportability Matrix<\/a><\/li>\n<li><a href=\"https:\/\/learn.microsoft.com\/exchange\/architecture\/client-access\/load-balancing?view=exchserver-2019\" target=\"_blank\" rel=\"noopener noreferrer\">Load Balancing in Exchange 201<\/a><u>9<\/u><\/li>\n<li><a href=\"https:\/\/learn.microsoft.com\/exchange\/plan-and-deploy\/deployment-ref\/preferred-architecture-2019?view=exchserver-2019\" target=\"_blank\" rel=\"noopener noreferrer\">Exchange 2019 Preferred Architecture<\/a><\/li>\n<li><a href=\"https:\/\/learn.microsoft.com\/exchange\/plan-and-deploy\/deployment-ref\/preferred-architecture-2019?view=exchserver-2019#namespace-design\" target=\"_blank\" rel=\"noopener noreferrer\">Namespace Planning\u00a0in Exchange 201<\/a><u>9<\/u><\/li>\n<\/ul>\n<p>Also, be sure to download the <a href=\"https:\/\/www.microsoft.com\/en-us\/download\/details.aspx?id=102123\" target=\"_blank\" rel=\"noopener noreferrer\">Exchange 2019 Sizing Calculator<\/a> to correctly determine your Exchange 2019 hardware requirements.<\/p>\n<h1 id=\"toc-hId-526367052\"><span id=\"plan\">Plan<\/span><\/h1>\n<p>In previous posts, we discussed the benefits of using the <a href=\"https:\/\/setup.microsoft.com\/exchange\/deployment-assistant\" target=\"_blank\" rel=\"noopener noreferrer\">Exchange Deployment Assistant<\/a>\u00a0to plan and perform your migration. This post covers the manual steps required to perform a migration.<\/p>\n<p>One of the first decisions to be made is how much availability do you need. Using\u00a0the guidance in our\u00a0<a href=\"https:\/\/learn.microsoft.com\/Exchange\/high-availability\/plan-ha?view=exchserver-2019\" target=\"_blank\" rel=\"noopener noreferrer\">High Availability and Site Resilience<\/a>\u00a0documentation will\u00a0help you decide\u00a0<strong><em>how available\u00a0is available enough<\/em><\/strong>. When making that decision, consider all your failure domains, such as disk, network, server, virtualization loss (if applicable), datacenter failure, etc.<\/p>\n<ul>\n<li><em>Which of these failures will your design cover?<\/em><\/li>\n<li><em>Does your Exchange 2013 environment have any pain points that can be addressed by a new design with Exchange 2019?<\/em><\/li>\n<\/ul>\n<p>Your plan should additionally include all associated costs, such as licensing, rack space, hardware, disk, network, bandwidth, backups,\u00a0and if applicable, 3rd\u00a0party apps.<\/p>\n<h2 id=\"toc-hId-1216928526\"><span id=\"use-an-active-directory-deployment-site\">Use an Active Directory deployment\u00a0site<\/span><\/h2>\n<p>We recommend installing Exchange 2019 into an <a href=\"https:\/\/techcommunity.microsoft.com\/t5\/Exchange-Team-Blog\/Exchange-Active-Directory-Deployment-Site\/ba-p\/604329\" target=\"_blank\" rel=\"noopener\">Active Directory deployment site<\/a>. This prevents any internal domain-joined clients from looking up the SCP on Exchange 2019 servers.<\/p>\n<h2 id=\"toc-hId--590525937\"><span id=\"disable-legacy-tls\">Disable legacy TLS<\/span><\/h2>\n<p>We strongly recommend disabling TLS 1.0 and 1.1 in your organization\u00a0as part of your migration. Be sure to read the\u00a0guidance\u00a0for this carefully\u00a0since mistakes can cause big problems.<\/p>\n<ul>\n<li><a href=\"https:\/\/learn.microsoft.com\/exchange\/exchange-tls-configuration?view=exchserver-2019\" target=\"_blank\" rel=\"noopener noreferrer\">Exchange Server TLS configuration best practices<\/a><\/li>\n<li><a href=\"https:\/\/learn.microsoft.com\/mem\/configmgr\/core\/plan-design\/security\/enable-tls-1-2-client\" target=\"_blank\" rel=\"noopener noreferrer\">How to enable Transport Layer Security (TLS) 1.2 on clients<\/a><\/li>\n<li><a href=\"https:\/\/learn.microsoft.com\/mem\/configmgr\/core\/plan-design\/security\/enable-tls-1-2-server\" target=\"_blank\" rel=\"noopener noreferrer\">Enable TLS 1.2 on servers<\/a><\/li>\n<\/ul>\n<h2 id=\"toc-hId-1896986896\"><span id=\"use-office-online-server\">Use Office Online Server<\/span><\/h2>\n<p>We recommend using\u00a0<a href=\"https:\/\/learn.microsoft.com\/officeonlineserver\/deploy-office-online-server\" target=\"_blank\" rel=\"noopener noreferrer\">Office Online Server<\/a>\u00a0to\u00a0enhance the attachment experience for Outlook and Outlook on the web users. Follow the steps in <a href=\"https:\/\/learn.microsoft.com\/exchange\/plan-and-deploy\/install-office-online-server?view=exchserver-2019\" target=\"_blank\" rel=\"noopener noreferrer\">Install Office Online Server in an Exchange organization<\/a> to utilize this in your environment.<\/p>\n<h2 id=\"toc-hId-89532433\"><span id=\"exchange-2019-client-namespace-planning\">Exchange 2019 client namespace planning<\/span><\/h2>\n<p>Our <a href=\"https:\/\/learn.microsoft.com\/exchange\/plan-and-deploy\/deployment-ref\/preferred-architecture-2019?view=exchserver-2019#namespace-design\" target=\"_blank\" rel=\"noopener noreferrer\">namespace guidance<\/a> hasn\u2019t changed much since Exchange 2013, so understanding your existing configuration will help you migrate to Exchange 2019. If your organization has Exchange namespaces, but they aren\u2019t documented, you can fetch your organization\u2019s namespaces using the following script:<\/p>\n<p style=\"background: #F0F0F0; padding: .5em; margin: 1em 0 1em 0;\">The results show each unique namespace per protocol. If multiple results are returned in a single protocol, validate whether this configuration is required for a <a href=\"https:\/\/techcommunity.microsoft.com\/t5\/Exchange-Team-Blog\/Namespace-Planning-in-Exchange-2016\/ba-p\/604072#bound\" target=\"_blank\" rel=\"noopener\">bound namespace<\/a> model. We recommend that the internal URL and external URL be the same, and that split DNS is used for clients.<\/p>\n<p>\u00a0<\/p>\n<pre class=\"lia-code-sample language-powershell\"><code>#Retrieve Result\n$ClientAccess = Get-ClientAccessServer -ErrorAction:SilentlyContinue -WarningAction:SilentlyContinue\n$MapiVdir = Get-MapiVirtualDirectory -ADPropertiesOnly\n$EWSVdir = Get-WebservicesVirtualDirectory -ADPropertiesOnly\n$EASVdir = Get-ActiveSyncVirtualDirectory -ADPropertiesOnly\n$OWAVdir = Get-OwaVirtualDirectory -ADPropertiesOnly\n$ECPVdir = Get-EcpVirtualDirectory -ADPropertiesOnly\n$OABVdir = Get-OabVirtualDirectory -ADPropertiesOnly\n$RPCVdir = Get-OutlookAnywhere -ADPropertiesOnly\n#Find unique namespaces\n[string[]]$AutodiscoverNS = $ClientAccess.AutoDiscoverServiceInternalUri.DNSSafeHost | Select-Object -Unique\n[string[]]$MapiNS = $MapiVdir.InternalURL.DNSSafeHost | Select-Object -Unique\n[string[]]$EWSNS = $EWSVdir.InternalURL.DNSSafeHost | Select-Object -Unique\n[string[]]$EASNS = $EASVdir.InternalURL.DNSSafeHost | Select-Object -Unique\n[string[]]$OWANS = $OWAVdir.InternalURL.DNSSafeHost | Select-Object -Unique\n[string[]]$ECPNS = $ECPVdir.InternalURL.DNSSafeHost | Select-Object -Unique\n[string[]]$OABNS = $OABVdir.InternalURL.DNSSafeHost | Select-Object -Unique\n[string[]]$RPCNS = $RPCVdir.Internalhostname.Hostnamestring | Select-Object -Unique\n[string[]]$RPCNS += $RPCVdir.Externalhostname.Hostnamestring | Select-Object -Unique\n[string[]]$RPCNS = $RPCNS | Select-Object -Unique\n[string[]]$OWADownloadNS = $OWAvdir.ExternalDownloadHostname | Select-Object -Unique\n[string[]]$OWADownloadNS += $OWAvdir.InternalDownloadHostname | Select-Object -Unique\n[string[]]$OWADownloadNS = $OWADownloadNS | Select-Object -Unique\n#List individual protocols\nWrite-Host \u201cAutoDiscover: $AutodiscoverNS\u201c; Write-Host \u201cMapi: $MapiNS\u201d ; Write-Host \u201cEWS:\u201d $EWSNS ; Write-Host \u201cEAS: $EASNS\u201d ; Write-Host \u201cOWA: $OWANS\u201d ; Write-Host \u201cECP: $ECPNS\u201d ; Write-Host \u201cOAB: $OABNS\u201d ; Write-Host \u201cRPC: $RPCNS\u201d ;  Write-Host \u201cOWA Downloads: $OWADownloadNS\u201d<\/code><\/pre>\n<p>\u00a0<\/p>\n<h2 id=\"toc-hId--1717922030\"><span id=\"public-folders\">Public folders<\/span><\/h2>\n<p>Supported <a href=\"https:\/\/learn.microsoft.com\/exchange\/plan-and-deploy\/supportability-matrix?view=exchserver-2019#clients\" target=\"_blank\" rel=\"noopener noreferrer\">Outlook clients for Exchange Server<\/a> can access public folders. We recommend you migrate Exchange 2013 public folder mailboxes to Exchange 2019.<\/p>\n<ul>\n<li><a href=\"https:\/\/learn.microsoft.com\/exchange\/collaboration\/public-folders\/faq?view=exchserver-2019\" target=\"_blank\" rel=\"noopener noreferrer\">FAQ: Public folders<\/a><\/li>\n<li><a href=\"https:\/\/techcommunity.microsoft.com\/t5\/exchange-team-blog\/announcing-support-for-controlled-connections-to-public-folders\/ba-p\/608591\" target=\"_blank\" rel=\"noopener\">Announcing Support for Controlled Connections to Public Folders in Outlook<\/a><\/li>\n<\/ul>\n<h2 id=\"toc-hId-769590803\"><span id=\"kerberos-with-internal-outlook-clients\">Kerberos\u00a0with internal Outlook clients<\/span><\/h2>\n<p>Our guidance for this is based on whether your namespaces are shared between your Exchange 2013 and Exchanger 2019 servers. If they are, then you can use a single Alternative Service Account (ASA), which should ALWAYS be a computer account and not a user account.<\/p>\n<p>Before making any changes, verify your existing configuration and then plan for your Exchange 2019 namespaces. You can also choose to create a new ASA with an updated naming convention, but that isn\u2019t necessary for Kerberos to function.<\/p>\n<p style=\"background: #F0F0F0; padding: .5em; margin: 1em 0 1em 0;\">In Exchange 2016 and later, use the Get-ClientAccessService cmdlet. You\u2019ll see a warning if you use Get-ClientAccessServer, but it\u2019s still functional.<\/p>\n<p>\u00a0<\/p>\n<pre class=\"lia-code-sample language-powershell\"><code>Get-ClientAccessServer E15 -IncludeAlternateServiceAccountCredentialStatus | FL AlternateServiceAccountConfiguration\nIdentity: E15\nAlternateServiceAccountConfiguration: Latest: &lt;Not Set&gt; Previous:  &lt;Not Set&gt;<\/code><\/pre>\n<p>\u00a0<\/p>\n<p>The Latest\/Previous values will show <em>&lt;Not set&gt;<\/em> if this isn\u2019t configured. It will show values for date\/time when properly configured:<\/p>\n<p>\u00a0<\/p>\n<pre class=\"lia-code-sample language-powershell\"><code>Get-ClientAccessServer E15 -IncludeAlternateServiceAccountCredentialStatus | FL AlternateServiceAccountConfiguration\nIdentity: E15\nAlternateServiceAccountConfiguration: Latest: 3\/9\/2023 6:15:57 PM, contosoEX2013-ASA$\n\t\t\t     Previous: &lt;Not Set&gt;<\/code><\/pre>\n<p>\u00a0<\/p>\n<p>After installing Exchange 2019, you can run the RollAlternateServiceAccountPassword and target your Exchange 2019 server:<\/p>\n<p>\u00a0<\/p>\n<pre class=\"lia-code-sample language-powershell\"><code>CD $ExScripts\n.RollAlternateServiceAccountPassword.ps1 -ToSpecificServer E19.contoso.com -CopyFrom E15.contoso.com<\/code><\/pre>\n<p>\u00a0<\/p>\n<p>Now to verify this has been updated properly you can query the Exchange 2019 server:<\/p>\n<p>\u00a0<\/p>\n<pre class=\"lia-code-sample language-powershell\"><code>Get-ClientAccessService E19 -IncludeAlternateServiceAccountCredentialStatus | FL AlternateServiceAccountConfiguration\nIdentity: E19\nAlternateServiceAccountConfiguration: Latest: 3\/9\/2023 6:15:57 PM, contosoEX2013-ASA$\n\t\t\t     Previous: &lt;Not Set&gt;<\/code><\/pre>\n<p>\u00a0<\/p>\n<p>In our <a href=\"https:\/\/learn.microsoft.com\/exchange\/architecture\/client-access\/kerberos-auth-for-load-balanced-client-access?view=exchserver-2019\" target=\"_blank\" rel=\"noopener noreferrer\">documentation<\/a> for setting up Kerberos you\u2019ll see that:<\/p>\n<ul>\n<li>The ASA must be a computer account to remain within support boundaries<\/li>\n<li>You can use one ASA for both Exchange 2013 and Exchange 2019<\/li>\n<\/ul>\n<p>We don\u2019t walk through the steps in this post, but we wanted to call attention to the above points. It should also be noted that there is a current limitation with this cross-version where you\u2019ll want to make sure you\u2019re looking up the ASA details from the local machine. Otherwise, you\u2019ll get this error:<\/p>\n<p><span class=\"lia-inline-image-display-wrapper lia-image-align-center\" image-alt=\"E2013mig01.jpg\" style=\"width: 999px;\"><img decoding=\"async\" src=\"https:\/\/techcommunity.microsoft.com\/t5\/image\/serverpage\/image-id\/452250iFDF4E99A6CFBEA16\/image-size\/large?v=v2&amp;px=999\" role=\"button\" title=\"E2013mig01.jpg\" alt=\"E2013mig01.jpg\"><\/span><\/p>\n<h2 id=\"toc-hId--1037863660\"><span id=\"pop3-and-imap-clients\">POP3 and IMAP clients<\/span><\/h2>\n<p>POP3 and IMAP4 services are set to Manual startup by default in Exchange 2019. If you have any clients that use these protocols, you\u2019ll want to set these services to Automatic startup and keep them running. If you set these services to Automatic, you should disable POP and IMAP access at the mailbox level.<\/p>\n<p>If you don\u2019t need these services, we recommend leaving them set to Manual. Don\u2019t set them to Disabled, or Managed Availability will believe the server has health issues.<\/p>\n<p>Be sure to compare the values for ProtocolLogEnabled, InternalConnectionSettings, ExternalConnectionSettings, and x509CertificateName between servers for consistency in configuration.<\/p>\n<h2 id=\"toc-hId-1449649173\"><span id=\"unified-messaging\">Unified Messaging<\/span><\/h2>\n<p>This post does not cover Unified Messaging, because that feature has been removed from <a href=\"https:\/\/learn.microsoft.com\/exchange\/new-features\/discontinued-features?view=exchserver-2019#architecture\" target=\"_blank\" rel=\"noopener noreferrer\">Exchange 2019<\/a>. For detailed steps on migrating Unified Messaging to another solution, see <a href=\"https:\/\/learn.microsoft.com\/SkypeForBusiness\/hybrid\/plan-um-migration\" target=\"_blank\" rel=\"noopener noreferrer\">Plan for Skype for Business Server and Exchange Server migration &#8211; Skype for Business Hybrid<\/a>. Note, though, if your Exchange 2013 users have UM-enabled mailboxes, do not move them to Exchange 2019 before you move them to Skype for Business Server 2019, or they will have a voice messaging outage.<\/p>\n<h1 id=\"toc-hId-1186881730\"><span id=\"deploy\">Deploy<\/span><\/h1>\n<p>When you are ready to deploy, create your own document\u00a0or\u00a0spreadsheet and add\u00a0additional items that fit within your organization\u2019s configuration needs.<\/p>\n<h2 id=\"toc-hId--491490014\"><span id=\"prepare-active-directory\">Prepare\u00a0Active Directory<\/span><\/h2>\n<p>Be sure to review <a href=\"https:\/\/learn.microsoft.com\/exchange\/plan-and-deploy\/prepare-ad-and-domains?view=exchserver-2019\" target=\"_blank\" rel=\"noopener noreferrer\">Preparing AD\u00a0and domains<\/a>.\u00a0The account you use must be a member of the Schema Admins and\u00a0Enterprise Admins security groups\u00a0to run \/PrepareSchema, and\u00a0a member of the Enterprise Admins security group\u00a0to run \/PrepareAD.<\/p>\n<p>Examples:<\/p>\n<li-wrapper><i><\/i><\/li-wrapper>\n<p><em><strong>Setup.exe \/IAcceptExchangeServerLicenseTerms_DiagnosticDataON \/PrepareSchema<br \/>Setup.exe \/IAcceptExchangeServerLicenseTerms_DiagnosticDataON \/PrepareAD<\/strong><\/em><\/p>\n<p>If you prepare Active Directory from a machine that is not an Exchange server, that machine must have the appropriate tools, including RSAT ADDS and .NET Framework 4.8.<\/p>\n<p>If Active Directory preparation is not done before you install your first Exchange 2019 server, then Setup will try to perform these tasks during your first server installation.\u00a0In that case, be sure to use an account that has the proper permissions.<\/p>\n<p>If your forest consists of multiple domains, you\u00a0will\u00a0need to prepare\u00a0each one. If you have only one domain, \/PrepareAD will prepare it.<\/p>\n<p>Examples:<br \/><em><strong>Setup.exe \/IAcceptExchangeServerLicenseTerms_DiagnosticDataON \/PrepareDomain<br \/>Setup.exe \/IAcceptExchangeServerLicenseTerms_DiagnosticDataON \/PrepareAllDomains<\/strong><\/em><\/p>\n<h2 id=\"toc-hId-1996022819\"><span id=\"install-windows-server\">Install Windows\u00a0Server<\/span><\/h2>\n<p>This post does not\u00a0cover installing Windows\u00a0Server. Please follow the guidance in <a href=\"https:\/\/learn.microsoft.com\/exchange\/plan-and-deploy\/prerequisites?view=exchserver-2019\" target=\"_blank\" rel=\"noopener noreferrer\">Exchange Server prerequisites, Exchange 2019 system requirements, Exchange 2019 requirements<\/a>\u00a0to plan your OS installation. \u00a0After Windows Server is installed, and before you install Exchange Server, be sure to install the latest updates for Windows Server.<\/p>\n<h2 id=\"toc-hId-188568356\"><span id=\"pre-requisite-script-setup-assist\">Pre-requisite\u00a0script\u00a0(Setup Assist)<\/span><\/h2>\n<p>Review the\u00a0optional\u00a0<a href=\"https:\/\/microsoft.github.io\/CSS-Exchange\/Setup\/SetupAssist\/\" target=\"_blank\" rel=\"noopener nofollow noreferrer\">Setup Assist<\/a>\u00a0script and consider using it to prepare for installing Exchange 2019.\u00a0This script is provided\u00a0\u201cas is\u201d<strong>\u00a0<\/strong>and is not supported, so be sure to test this script in your environment before\u00a0using it in production.<\/p>\n<h2 id=\"toc-hId--1618886107\"><span id=\"net-framework\">.NET\u00a0Framework<\/span><\/h2>\n<p>The pre-requisite script should ask you to install the appropriate\u00a0version of the .NET Framework, but it\u2019s worth calling out that\u00a0the version installed\u00a0should be\u00a0a supported version and listed\u00a0in\u00a0the\u00a0<a href=\"https:\/\/learn.microsoft.com\/exchange\/plan-and-deploy\/supportability-matrix?view=exchserver-2019#microsoft-net-framework\" target=\"_blank\" rel=\"noopener noreferrer\">Exchange Server supportability matrix<\/a>.<\/p>\n<h2 id=\"toc-hId-868626726\"><span id=\"install-mailbox-role\">Install mailbox role<\/span><\/h2>\n<p>To demonstrate how to install the Mailbox role, we\u2019re running Setup in unattended mode via an elevated command prompt, as documented in <a href=\"https:\/\/learn.microsoft.com\/exchange\/plan-and-deploy\/deploy-new-installations\/unattended-installs?view=exchserver-2019\" target=\"_blank\" rel=\"noopener noreferrer\">Use unattended mode in Exchange Setup<\/a>.\u00a0Always install the latest build of Exchange 2019, which you can determine <a href=\"https:\/\/learn.microsoft.com\/exchange\/new-features\/build-numbers-and-release-dates?view=exchserver-2019\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>.\u00a0Also see the section below about <a href=\"https:\/\/techcommunity.microsoft.com\/#_Configure_Anti-Virus_Exclusions\" target=\"_blank\" rel=\"noopener nofollow noreferrer\">configuring anti-virus exclusions<\/a>.<\/p>\n<p><strong>Setup.exe \/IAcceptExchangeServerLicenseTerms_DiagnosticDataON \/mode:Install \/r:MB<\/strong><\/p>\n<p style=\"background: #F0F0F0; padding: .5em; margin: 1em 0 1em 0;\">There may be other Setup switches that are needed, so refer to the unattended mode document above for details.<\/p>\n<h2 id=\"toc-hId--938827737\"><span id=\"configure-exchange-2019-url-based-on-namespace\">Configure Exchange 2019 URL based on namespace<\/span><\/h2>\n<p>Based on the values identified during Exchange 2019 client namespace planning, you will want to update the values below based on your organization\u2019s desired configuration. The sample below configures the URLs to be unique per protocol, using the root domain Contoso.com, and also configures the downloads domain for Outlook on the web to address this <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-1730\" target=\"_blank\" rel=\"noopener noreferrer\">CVE<\/a>.<\/p>\n<p>\u00a0<\/p>\n<pre class=\"lia-code-sample language-powershell\"><code>#Stage variables for namespace modifiers\n$InternetDomain = \u201ccontoso.com\u201d\n$EWSModifier = \"EWS\"\n$ASModifier = \"EAS\"\n$OWAModifier = \"OWA\"\n$OWADownloadModifier = \u201cDownloads\u201d\n$ECPModifier = \"ECP\"\n$OABModifer = \"OAB\"\n$MapiModifier = \"MAPI\"\n$RPCModifier = \"RPC\"\n\n#Stage variables containing the protocol\u2019s full URL\n\n$EwsUrl = \"https:\/\/\"+$EWSModifier+\".\"+$InternetDomain + \"\/EWS\/Exchange.asmx\"\n$AsUrl = \"https:\/\/\"+$ASModifier+\".\"+$InternetDomain + \"\/Microsoft-Server-ActiveSync\"\n$OwaUrl = \"https:\/\/\"+$OWAModifier+\".\"+$InternetDomain + \"\/owa\"\n$OWADownloadsHostName = $OWADownloadModifier + \".\" + $InternetDomain\n$EcpUrl = \"https:\/\/\"+$ECPModifier+\".\"+$InternetDomain + \"\/ecp\"\n$OabUrl = \"https:\/\/\"+$OABModifer+\".\"+$InternetDomain + \"\/OAB\"\n$MapiURL = \"https:\/\/\"+$MapiModifier+\".\"+$InternetDomain + \"\/mapi\"\n$RPCHostName = $RPCModifier + \".\" + $InternetDomain\n\n#Update the Exchange Virtual Directories\n\nGet-WebServicesVirtualDirectory -Server $Env:computername  | Set-WebServicesVirtualDirectory -InternalURL $EwsUrl -MRSProxyEnabled $true -ExternalURL $EwsUrl -WarningAction:SilentlyContinue -Confirm:$false \n\nGet-ActiveSyncVirtualDirectory -Server $Env:computername | Set-ActiveSyncVirtualDirectory -InternalURL $AsUrl -ExternalURL $AsUrl -WarningAction:SilentlyContinue -Confirm:$false\n\nGet-OWAVirtualDirectory -Server $Env:computername | Set-OwaVirtualDirectory -InternalURL $OwaUrl -ExternalURL $OwaUrl -InternalDownloadHostName $OWADownloadsHostName -ExternalDownloadHostName $OWADownloadsHostName\n-WarningAction:SilentlyContinue -Confirm:$false\n\nGet-ECPVirtualDirectory -Server $Env:computername| Set-EcpVirtualDirectory -InternalURL $EcpUrl -ExternalURL $EcpUrl -WarningAction:SilentlyContinue -Confirm:$false\n\nGet-OABVirtualDirectory -Server $Env:computername | Set-OabVirtualDirectory -InternalURL $OabUrl -ExternalURL $OabUrl -WarningAction:SilentlyContinue -Confirm:$false\n\nGet-MapiVirtualDirectory -Server $Env:computername | Set-MapiVirtualDirectory -InternalURL $MapiURL -ExternalURL $MapiURL -WarningAction:SilentlyContinue -Confirm:$false \n\nGet-OutlookAnywhere -Server $env:computername | Set-OutlookAnywhere -ExternalHostname $RPCHostName -SSLOffloading:$false -ExternalClientsRequireSsl:$True -InternalHostname $RPCHostName -InternalClientAuthenticationMethod:NTLM -InternalClientsRequireSsl:$true\n-ExternalClientAuthenticationMethod:Basic -WarningAction:SilentlyContinue -Confirm:$false<\/code><\/pre>\n<p>\u00a0<\/p>\n<h2 id=\"toc-hId-1548685096\"><span id=\"configure-autodiscover-scp-for-internal-clients\">Configure\u00a0Autodiscover\u00a0SCP\u00a0for internal clients<\/span><\/h2>\n<p>If you don\u2019t install Exchange in an\u00a0<a href=\"https:\/\/techcommunity.microsoft.com\/t5\/Exchange-Team-Blog\/Exchange-Active-Directory-Deployment-Site\/ba-p\/604329\" target=\"_blank\" rel=\"noopener\">Active Directory deployment site<\/a>\u00a0as we recommend,\u00a0follow\u00a0these steps\u00a0instead.<\/p>\n<p style=\"background: #F0F0F0; padding: .5em; margin: 1em 0 1em 0;\">The Get-ClientAccessService cmdlet is not available on Exchange 2013 and is used only for Exchange 2016 and later. In Exchange 2013 you need to run Get-ClientAccessServer.<\/p>\n<p>When you install Exchange 2019, the server is ready to respond to incoming requests for internal clients. To\u00a0prevent clients from accessing the newly installed server, we recommend that you point the SCP\u00a0either to the Exchange 2013 Client Access server or set it to a NULL value by running the following command:<\/p>\n<p>\u00a0<\/p>\n<pre class=\"lia-code-sample language-powershell\"><code>Set-ClientAccessService &lt;ServerName&gt; -AutodiscoverServiceInternalUri $NULL<\/code><\/pre>\n<p>\u00a0<\/p>\n<p>It is easier to point\u00a0the SCP to Exchange 2013,\u00a0so you do not have to change it again. If the SCP is pointed to a server FQDN, we recommend you set the value to NULL temporarily; you\u00a0can point this to\u00a0Exchange\u00a02019\u00a0later.<\/p>\n<p>First, determine where the SCP is currently pointed:<\/p>\n<p>\u00a0<\/p>\n<pre class=\"lia-code-sample language-powershell\"><code>Get-ClientAccessServer -Identity &lt;Ex2013 CASName&gt; | fl *auto*<\/code><\/pre>\n<p>\u00a0<\/p>\n<p>Capture the AutoDiscoverServiceInternalUri value you get from the above command and point the Exchange 2019 SCP to NULL:<\/p>\n<p>\u00a0<\/p>\n<pre class=\"lia-code-sample language-powershell\"><code>Set-ClientAccessService -Identity &lt;Ex2019 ServerName&gt; -AutoDiscoverServiceInternalURI $NULL<\/code><\/pre>\n<p>\u00a0<\/p>\n<h2 id=\"toc-hId--258769367\"><span id=\"configure-the-2019-databases-for-default-oab\">Configure the 2019 databases for default OAB<\/span><\/h2>\n<p>In Exchange 2013 and later, Offline Address Book (OAB) generation is managed by a mailbox assistant named OABGeneratorAssistant which runs under the Microsoft Exchange Mailbox Assistants service. OAB generation occurs in an arbitration mailbox.<\/p>\n<p>These arbitration mailboxes need to be migrated to Exchange 2019, which moves OAB generation to Exchange 2019. If you customize your OAB distribution and you have multiple OAB generation mailboxes; you don\u2019t to recreate the OAB. But be careful when assigning a new OAB to everyone as this action triggers a full download of the OAB for all clients, which could lead to network and performance issues. To check your configuration, run this command:<\/p>\n<p>\u00a0<\/p>\n<pre class=\"lia-code-sample language-powershell\"><code>Get-OfflineAddressBook | FL Identity, GeneratingMailbox\nGet-Mailbox \u2013Arbitration | ?{$_.PersistedCapabilities -like \u201cOrganizationCapabilityOABGen\u201d} | FL Identity, Database, AdminDisplayVersion<\/code><\/pre>\n<p>\u00a0<\/p>\n<ul>\n<li><a href=\"https:\/\/learn.microsoft.com\/exchange\/email-addresses-and-address-books\/offline-address-books\/offline-address-books?view=exchserver-2019\" target=\"_blank\" rel=\"noopener noreferrer\">Offline address books in Exchange Server<\/a><\/li>\n<li><a href=\"https:\/\/learn.microsoft.com\/exchange\/email-addresses-and-address-books\/offline-address-books\/oab-procedures?view=exchserver-2019\" target=\"_blank\" rel=\"noopener noreferrer\">Procedures for offline address books in Exchange Server<\/a><\/li>\n<\/ul>\n<h2 id=\"toc-hId--2066223830\"><span id=\"configure-exchange-2019-certificates\">Configure Exchange 2019 certificates<\/span><\/h2>\n<p>Depending on your plan, you may be using existing certificates or\u00a0planning on\u00a0creating new\u00a0ones.<\/p>\n<p style=\"background: #F0F0F0; padding: .5em; margin: 1em 0 1em 0;\">The Exchange Control Panel (ECP)-based certificate request was deprecated in Exchange 2019 CU12.<\/p>\n<p>If you plan to use an existing 3<sup>rd<\/sup> party certificate for Exchange 2019, you must do the following:<\/p>\n<p>1. Export the 3<sup>rd<\/sup> party certificate from Exchange 2013, using the instructions in <a href=\"https:\/\/learn.microsoft.com\/exchange\/architecture\/client-access\/export-certificates?view=exchserver-2019\" target=\"_blank\" rel=\"noopener noreferrer\">Export a certificate from an Exchange server<\/a><span>.<br \/><\/span><\/p>\n<p>2. Import the 3<sup>rd<\/sup> party certificate into Exchange 2019, using the instructions at <a href=\"https:\/\/learn.microsoft.com\/exchange\/architecture\/client-access\/import-certificates?view=exchserver-2019\" target=\"_blank\" rel=\"noopener noreferrer\">Import or install a certificate on an Exchange server<\/a>. An example is shown below:<\/p>\n<p>\u00a0<\/p>\n<pre class=\"lia-code-sample language-powershell\"><code>Import-ExchangeCertificate -FileData ([System.IO.File]::ReadAllBytes('&lt;FilePathOrUNCPath&gt;')) [-Password (ConvertTo-SecureString -String '&lt;Password&gt; ' -AsPlainText -Force)] [-PrivateKeyExportable &lt;$true | $false&gt;] [-Server &lt;ServerIdentity&gt;]<\/code><\/pre>\n<p>\u00a0<\/p>\n<p style=\"background: #F0F0F0; padding: .5em; margin: 1em 0 1em 0;\">We recommend setting PrivateKeyExportable to $true when importing a certificate into Exchange Server. By enabling Private Key exportable, you can export the certificate with its private key.<\/p>\n<p>Soon after importing the certificate, you must assign a service to it (especially SMTP). If you leave the certificate without assigning the SMTP service to it, Exchange may choose the unassigned certificate for SMTP communication and TLS communication will fail.<\/p>\n<p>3. Assign services to the 3<sup>rd<\/sup> party certificate, using the instructions in <a href=\"https:\/\/learn.microsoft.com\/exchange\/architecture\/client-access\/assign-certificates-to-services?view=exchserver-2019\" target=\"_blank\" rel=\"noopener noreferrer\">Assign certificates to Exchange Server services<\/a>.<\/p>\n<ul>\n<li>When you assign the SMTP service, Exchange Server prompts you to overwrite the existing default self-signed certificate set in the transport configuration (which you can check by running <strong>Get-TransportService &lt;ServerName&gt; | ft name, InternalTransportCertificateThumbprint<\/strong>). The Transport service uses a built-in self-signed certificate for internal communication, so it is not necessary to overwrite the self-signed certificate with the 3<sup>rd<\/sup> party certificate.<\/li>\n<li>Make sure the new certificate is bound to the IIS Default Web Site.<\/li>\n<\/ul>\n<p>4. Follow step 2-3 to deploy the certificate on all other Exchange 2019 servers you add.<\/p>\n<p>If you plan to create a new 3<sup>rd<\/sup> party certificate, you must do the following:<\/p>\n<ol class=\"lia-list-style-type-lower-alpha\">\n<li>Use the Exchange Management Shell (EMS) and follow the instructions in <a href=\"https:\/\/learn.microsoft.com\/exchange\/architecture\/client-access\/create-ca-certificate-requests?view=exchserver-2019\" target=\"_blank\" rel=\"noopener noreferrer\">Create an Exchange Server certificate request for a certification authority<\/a>. If you plan to use a certificate with multiple Subject Alternative Names (SANs) in place of a wildcard certificate, make you\u2019re your certificate domains include all URLs set on your Exchange Server virtual directories and transport connectors.<\/li>\n<li>Complete pending request, using the instructions in <a href=\"https:\/\/learn.microsoft.com\/exchange\/architecture\/client-access\/complete-pending-certificate-requests?view=exchserver-2019\" target=\"_blank\" rel=\"noopener noreferrer\">Complete a pending Exchange Server certificate request<\/a>.<\/li>\n<li>Follow steps 1-4 in the previous section to import the new certificate on your Exchange 2019 servers.<\/li>\n<\/ol>\n<h2 id=\"toc-hId-1119450944\"><span id=\"create-database-availability-groups\">Create Database Availability Group(s)<\/span><\/h2>\n<p>Once you have familiarized yourself with the <a href=\"https:\/\/learn.microsoft.com\/exchange\/plan-and-deploy\/deployment-ref\/preferred-architecture-2019?view=exchserver-2019\" target=\"_blank\" rel=\"noopener noreferrer\">Exchange 2019 preferred architecture<\/a> and the <a href=\"https:\/\/learn.microsoft.com\/exchange\/plan-and-deploy\/deployment-ref\/storage-configuration?view=exchserver-2019\" target=\"_blank\" rel=\"noopener noreferrer\">Exchange Server storage configuration options<\/a>, you can create your DAGs following the guidance in <a href=\"https:\/\/learn.microsoft.com\/Exchange\/high-availability\/manage-ha\/create-dags?view=exchserver-2016\" target=\"_blank\" rel=\"noopener noreferrer\">Create a database availability group in Exchange Server<\/a>.<\/p>\n<p>When creating a DAG, you have the option of creating one with or without a cluster administrative access point. If you create a DAG with this access point, the cluster will not have a cluster name object (CNO) in Active Directory, and the cluster core resource group will not contain a network name resource or an IP address resource. We recommend this configuration because it means fewer resources are needed, making the DAG less complex. But note that in this configuration, you cannot use Failover Cluster Manager to manage the cluster. But since you should only manage DAGs using Exchange tools, you don\u2019t need to use Failover Cluster Manager to manage a DAG.<\/p>\n<h3 id=\"toc-hId--558920800\"><span id=\"log-truncation-in-exchange-2019\">Log truncation in Exchange 2019<\/span><\/h3>\n<p>Be aware of changes in behavior for log truncation in Exchange 2019. One of the reasons for these changes is due to how Workload Management (WLM) prioritizes threads on a server and balances this prioritization across our Exchange services (as it\u2019s intended). This results in a higher threshold for required logs before truncation will occur, and this threshold will be different as active users are moved to these databases.<\/p>\n<h2 id=\"toc-hId-1799509314\"><span id=\"configure-anti-virus-exclusions\">Configure anti-virus exclusions<\/span><\/h2>\n<p>For years we have been saying how running antivirus (AV) software on your Exchange Servers can enhance the security and health of your Exchange organization. We\u2019ve also said that if you are deploying file-level scanners on Exchange servers, make sure that the appropriate exclusions, such as directory exclusions, process exclusions, and file name extension exclusions, are in place for both scheduled and real-time scanning.<\/p>\n<p>When configuring antivirus software for Exchange Server, be sure to exclude\u00a0all the items described\u00a0<a href=\"https:\/\/learn.microsoft.com\/exchange\/antispam-and-antimalware\/windows-antivirus-software?view=exchserver-2019\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>\u00a0and\u00a0<a href=\"https:\/\/support.microsoft.com\/help\/822158\/virus-scanning-recommendations-for-enterprise-computers-that-are-runni\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>.\u00a0If you use Windows Defender, you can use a <a href=\"https:\/\/microsoft.github.io\/CSS-Exchange\/Setup\/Set-ExchAVExclusions\/\" target=\"_blank\" rel=\"noopener nofollow noreferrer\">script<\/a> we built to make this easier.<\/p>\n<h2 id=\"toc-hId--7945149\"><span id=\"configure-connectors\">Configure connectors<\/span><\/h2>\n<p>The next step is to configure <a href=\"https:\/\/learn.microsoft.com\/exchange\/mail-flow\/connectors\/connectors?view=exchserver-2019\" target=\"_blank\" rel=\"noopener noreferrer\">Connectors<\/a>.<\/p>\n<h4 id=\"toc-hId--1557234174\"><span id=\"receive-connectors\">Receive connectors<\/span><\/h4>\n<p>Exchange 2019 has the same number of default <a href=\"https:\/\/learn.microsoft.com\/exchange\/mail-flow\/connectors\/receive-connectors?view=exchserver-2019\" target=\"_blank\" rel=\"noopener noreferrer\">receive connectors<\/a> as Exchange 2013. No modifications are needed if your default receive connectors were not customized in Exchange 2013.<\/p>\n<h4 id=\"toc-hId-930278659\"><span id=\"smtp-relay-receive-connector\">SMTP relay receive connector<\/span><\/h4>\n<p>Be sure to review any SMTP relay receive connector(s) on Exchange 2013 and configure an SMTP relay receive connector on Exchange 2019 with the same configuration. This is required for any on-premises applications that need to relay emails through Exchange 2019. For more information, see <a href=\"https:\/\/learn.microsoft.com\/exchange\/mail-flow\/connectors\/allow-anonymous-relay?view=exchserver-2019\" target=\"_blank\" rel=\"noopener noreferrer\">Allow anonymous relay on Exchange servers<\/a>.<\/p>\n<h4 id=\"toc-hId--877175804\"><span id=\"send-connectors\">Send connectors<\/span><\/h4>\n<li-wrapper><i><\/i><\/li-wrapper>\n<p>Replace any Exchange 2013 servers with Exchange 2019 server in the \u2018SourceTransportServers\u2019 for all <a href=\"https:\/\/learn.microsoft.com\/exchange\/mail-flow\/connectors\/send-connectors?view=exchserver-2019\" target=\"_blank\" rel=\"noopener noreferrer\">Send connectors<\/a>.<\/p>\n<p style=\"background: #F0F0F0; padding: .5em; margin: 1em 0 1em 0;\">If you have an Exchange hybrid environment, make sure that TLSCertificateName is configured correctly on your Connectors in both Exchange Server and Exchange Online. The Hybrid Configuration Wizard (HCW) is responsible for making the required changes on hybrid connectors.<\/p>\n<h2 id=\"toc-hId-1352171591\"><span id=\"edge-transport-server\">Edge transport server<\/span><\/h2>\n<p>You can use the following resources to deploy Exchange 2019 Edge Transport in your environment:<\/p>\n<ul>\n<li><a href=\"https:\/\/learn.microsoft.com\/exchange\/plan-and-deploy\/deploy-new-installations\/install-edge-transport-role?view=exchserver-2019\" target=\"_blank\" rel=\"noopener noreferrer\">Install Exchange Edge Transport servers using the Setup wizard<\/a><\/li>\n<li>Import 3<sup>rd<\/sup> party certificate and assign SMTP service. See <a href=\"https:\/\/learn.microsoft.com\/exchange\/architecture\/client-access\/import-certificates?view=exchserver-2019\" target=\"_blank\" rel=\"noopener noreferrer\">Import or install a certificate on an Exchange server<\/a>.<\/li>\n<li>Edge subscriptions are mandatory for hybrid mail flow. See <a href=\"https:\/\/learn.microsoft.com\/exchange\/architecture\/edge-transport-servers\/edge-subscriptions?view=exchserver-2019\" target=\"_blank\" rel=\"noopener noreferrer\">Edge Subscriptions<\/a>. In a hybrid environment, you also need to run the <a href=\"https:\/\/learn.microsoft.com\/en-us\/exchange\/hybrid-configuration-wizard\" target=\"_blank\" rel=\"noopener noreferrer\">HCW (Hybrid Configuration Wizard)<\/a>.<\/li>\n<li>If you add a new Mailbox server to a subscribed Active Directory site, and you it to participate in EdgeSync synchronization, you need to resubscribe your Edge Transport servers. See <a href=\"https:\/\/learn.microsoft.com\/exchange\/architecture\/edge-transport-servers\/edge-subscription-procedures?view=exchserver-2019\" target=\"_blank\" rel=\"noopener noreferrer\">Procedures for Edge Subscriptions<\/a>.<\/li>\n<\/ul>\n<h2 id=\"toc-hId--455282872\"><span id=\"run-the-exchange-server-health-checker\">Run\u00a0the Exchange\u00a0Server Health Checker<\/span><\/h2>\n<p><a href=\"http:\/\/aka.ms\/ExchangeHealthChecker\" target=\"_blank\" rel=\"noopener noreferrer\">Health Checker<\/a>\u00a0identifies potential critical issues. We strongly recommend running it and thoroughly review its findings.\u00a0You should implement\u00a0all\u00a0recommendations to avoid potential outages or performance issues. Health Checker isn\u2019t just for migration. It\u2019s for ongoing management of Exchange Server. Keep it handy, as it is one of your most value admin tools.<\/p>\n<h1 id=\"toc-hId-1903147242\"><span id=\"migrate\">Migrate<\/span><\/h1>\n<p>Now that we have completed the deployment of Exchange 2019,\u00a0the next step is to migrate.<\/p>\n<h2 id=\"toc-hId-922937439\"><span id=\"create-a-test-mailbox-on-2019\">Create a test mailbox on 2019<\/span><\/h2>\n<p>We recommend that you create a test mailbox (non-admin) and verify connectivity using the protocols your organization uses. Consider any workflows you have, such as connecting to an archive mailbox, using public folders, and delegation scenarios. Test Outlook, Free\/Busy, Outlook on the web, ActiveSync, out of office,\u00a0and any custom or third-party applications.<\/p>\n<h2 id=\"toc-hId--884517024\"><span id=\"test-connection-for-exchange-2013-mailbox\">Test connection for Exchange 2013 mailbox<\/span><\/h2>\n<p>Test\u00a0and verify that Exchange 2013 mailboxes\u00a0can\u00a0connect through Exchange 2019\u00a0by creating\u00a0a HOSTS file\u00a0entry\u00a0on a client machine with the IP address of an Exchange 2019 server\u00a0using the\u00a0load balanced namespace.\u00a0Check the <a href=\"https:\/\/support.microsoft.com\/help\/2737188\/description-of-the-connection-status-dialog-box-in-outlook\" target=\"_blank\" rel=\"noopener noreferrer\">Connection Status<\/a> window to verify that the proxy server column is\u00a0populated,\u00a0and the connection is HTTP or HTTPS.<\/p>\n<p>The Hosts file is in <strong>C:WindowsSystem32Driversetc<\/strong> directory.\u00a0It is protected and can only be edited through an elevated text editor, such as Notepad. An example host entry\u00a0that redirects your workstation traffic from your Load Balancer (mail.contoso.com) to a single server endpoint (192.168.1.5) would look like this:<\/p>\n<p>\u00a0<\/p>\n<pre class=\"lia-code-sample language-powershell\"><code>192.168.1.5    mail.contoso.com<\/code><\/pre>\n<p>\u00a0<\/p>\n<h2 id=\"toc-hId-1602995809\"><span id=\"point-the-scp-to-exchange-2019\">Point the SCP to Exchange 2019<\/span><\/h2>\n<p>If Exchange 2019 was installed into an existing site and the SCP\u00a0was temporarily moved\u00a0to Exchange 2013 or set to NULL,\u00a0it needs to be updated.\u00a0Depending on your configuration,\u00a0you should point the SCP to either\u00a0the\u00a0internal FQDN of the\u00a0Exchange 2019\u00a0server or to your load balanced namespace.<\/p>\n<h2 id=\"toc-hId--204458654\"><span id=\"move-arbitration-mailboxes\">Move arbitration mailboxes<\/span><\/h2>\n<p>Next, move the system and arbitration mailboxes from Exchange 2013 to Exchange 2019 prior to other mailboxes. This is required for many things to work properly, including the Exchange Admin Center (EAC). To see which system mailboxes are on Exchange 2013, run the following commands:<\/p>\n<p>\u00a0<\/p>\n<pre class=\"lia-code-sample language-powershell\"><code>Set-ADServerSettings -ViewEntireForest $True\nGet-Mailbox -Arbitration | FT Name, Database -AutoSize<\/code><\/pre>\n<p>\u00a0<\/p>\n<p>To migrate arbitration mailboxes from Exchange 2013 to Exchange 2019, run the following commands:<\/p>\n<p>\u00a0<\/p>\n<pre class=\"lia-code-sample language-powershell\"><code>Set-ADServerSettings -ViewEntireForest $True\nGet-Mailbox -Arbitration | New-MoveRequest -TargetDatabase &lt;Ex2019DatabaseName&gt;<\/code><\/pre>\n<p>\u00a0<\/p>\n<h2 id=\"toc-hId--2011913117\"><span id=\"namespace-changes\">Namespace changes<\/span><\/h2>\n<p>Once you have\u00a0verified client connectivity, change your DNS records from Exchange 2013 to Exchange 2019, modify any load balanced\u00a0pools, update firewall rules, NAT assignments,\u00a0etc.<\/p>\n<h1 id=\"toc-hId-346516997\"><span id=\"hybrid-configuration\">Hybrid configuration<\/span><\/h1>\n<p>After all dependencies (virtual directory URLs, Autodiscover, DNS, exchange certificates, etc.) are in place, you are ready to run the HCW.<\/p>\n<p>There are two options for\u00a0configuring\u00a0a hybrid organization:<\/p>\n<p><a href=\"https:\/\/learn.microsoft.com\/exchange\/exchange-hybrid\" target=\"_blank\" rel=\"noopener noreferrer\">The HCW<\/a>\u00a0is best for\u00a0complex hybrid deployments, especially those that require multi-forest,\u00a0sharing\u00a0policies, etc.<\/p>\n<p>The <a href=\"https:\/\/learn.microsoft.com\/exchange\/hybrid-deployment\/hybrid-agent\" target=\"_blank\" rel=\"noopener noreferrer\">Modern\u00a0Hybrid Agent<\/a>\u00a0(MHA)\u00a0is best for\u00a0simpler\u00a0deployments\u00a0that only require Free\/Busy and mailbox migration to Exchange Online.\u00a0 MHA does not support things like Hybrid Modern Authentication for on-premises, multi-forest exchange environment, cross-premises teams calendaring, and cross-premises message tracking. MHA is designed for organizations that do not already have a hybrid configuration in place.<\/p>\n<p>Run the\u00a0<a href=\"http:\/\/aka.ms\/HybridWizard\" target=\"_blank\" rel=\"noopener noreferrer\">HCW<\/a>\u00a0and\u00a0input the servers that\u00a0will be handling hybrid functions.<\/p>\n<h2 id=\"toc-hId--1331854747\"><span id=\"move-administrator-mailboxes\">Move administrator mailboxes<\/span><\/h2>\n<p>Use either EAC or the PowerShell to move administrator mailboxes to\u00a0Exchange 2019.<\/p>\n<p>PowerShell Example:<\/p>\n<p>\u00a0<\/p>\n<pre class=\"lia-code-sample language-powershell\"><code>New-MoveRequest-Identity user@domain.com -TargetDatabase &lt;Ex2019DatabaseName&gt;<\/code><\/pre>\n<p>\u00a0<\/p>\n<li-wrapper><i><\/i><\/li-wrapper>\n<h2 id=\"toc-hId-1155658086\"><span id=\"move-mailboxes\">Move\u00a0mailboxes<\/span><\/h2>\n<p>See <a href=\"https:\/\/learn.microsoft.com\/en-us\/Exchange\/architecture\/mailbox-servers\/manage-mailbox-moves?view=exchserver-2019\" target=\"_blank\" rel=\"noopener noreferrer\">Managing mailbox moves<\/a> for\u00a0more information about migrating mailboxes. When moving mailboxes, note that increased log generation will occur on both the\u00a0source and\u00a0target databases. Plan your moves to coincide\u00a0with\u00a0your backups to help manage free space for your databases. Otherwise, you risk\u00a0databases\u00a0dismounting during or after mailbox move operations.<\/p>\n<h2 id=\"toc-hId--651796377\"><span id=\"migrate-public-folders\">Migrate public folders<\/span><\/h2>\n<p>Our guidance for migrating public folders is in <a href=\"https:\/\/learn.microsoft.com\/exchange\/collaboration\/public-folders\/migrate-from-exchange-2013?view=exchserver-2019\" target=\"_blank\" rel=\"noopener noreferrer\">Migrate public folders from Exchange 2013 to Exchange 2016 or Exchange 2019<\/a>.<\/p>\n<h2 id=\"toc-hId-1835716456\"><span id=\"remove-legacy-exchange-versions\">Remove legacy Exchange versions<\/span><\/h2>\n<p>After you have finished deploying and configuring Exchange 2019, and moving all mailboxes and public folders, you can remove Exchange 2013. For more information, see <a href=\"https:\/\/techcommunity.microsoft.com\/t5\/exchange-team-blog\/decommissioning-exchange-server-2013\/ba-p\/3613793\" target=\"_blank\" rel=\"noopener\">Decommissioning Exchange Server 2013<\/a>.<\/p>\n<p>We want to thank the following people for helping with this post: Nino Bilic, Rob Whaley, Bhalchandra Atre, Paul Newell, Mike Brown, and Scott Schnoll.<\/p>\n<p><font color=\"#CF3600\">Jason Lockridge, Shashank Agarwal, Jason Burnside, David Loegering <font color=\"#000000\">and<\/font> Josh Hagen (Exchange)<\/font><\/p>\n<\/div>\n<p><a href=\"https:\/\/techcommunity.microsoft.com\/t5\/exchange-team-blog\/best-practices-for-migrating-from-exchange-server-2013-to\/ba-p\/3773084\">Read full article (Microsoft Exchange Blog)<\/a><\/p>\n<p>All content and images belong to their respected owners, this article is curated for informational purposes only.<\/p>\n","protected":false},"excerpt":{"rendered":"Time is up for Exchange Server 2013, and you should be finalizing your migrations. If your migration is&hellip;\n","protected":false},"author":2,"featured_media":2564,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"csco_singular_sidebar":"","csco_page_header_type":"","csco_appearance_grid":"","csco_page_load_nextpost":"","csco_post_video_location":[],"csco_post_video_location_hash":"","csco_post_video_url":"","csco_post_video_bg_start_time":0,"csco_post_video_bg_end_time":0,"footnotes":""},"categories":[15],"tags":[104,273,871],"coauthors":[48],"class_list":["post-4135","post","type-post","status-publish","format-standard","has-post-thumbnail","category-microsoft-exchange-server","tag-exchange","tag-server","tag-time","cs-entry","cs-video-wrap"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Best Practices for Migrating from Exchange Server 2013 to Exchange Server 2019 | Sebae Networks<\/title>\n<meta name=\"description\" content=\"View Best Practices for Migrating from Exchange Server 2013 to Exchange Server 2019 for free, here at Sebae. Discover more great posts on our website.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.sebae.net\/blog\/best-practices-for-migrating-from-exchange-server-2013-to-exchange-server-2019\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Best Practices for Migrating from Exchange Server 2013 to Exchange Server 2019 | Sebae Networks\" \/>\n<meta property=\"og:description\" content=\"View Best Practices for Migrating from Exchange Server 2013 to Exchange Server 2019 for free, here at Sebae. Discover more great posts on our website.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.sebae.net\/blog\/best-practices-for-migrating-from-exchange-server-2013-to-exchange-server-2019\/\" \/>\n<meta property=\"og:site_name\" content=\"Sebae Networks\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/sebaenetworks\" \/>\n<meta property=\"article:published_time\" content=\"2023-03-21T03:00:09+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/techcommunity.microsoft.com\/t5\/image\/serverpage\/image-id\/452250iFDF4E99A6CFBEA16\/image-size\/large?v=v2&amp;px=999\" \/>\n<meta name=\"author\" content=\"James Dean\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@sebaenetworks\" \/>\n<meta name=\"twitter:site\" content=\"@sebaenetworks\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"James Dean\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"19 minutes\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Best Practices for Migrating from Exchange Server 2013 to Exchange Server 2019 | Sebae Networks","description":"View Best Practices for Migrating from Exchange Server 2013 to Exchange Server 2019 for free, here at Sebae. Discover more great posts on our website.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.sebae.net\/blog\/best-practices-for-migrating-from-exchange-server-2013-to-exchange-server-2019\/","og_locale":"en_GB","og_type":"article","og_title":"Best Practices for Migrating from Exchange Server 2013 to Exchange Server 2019 | Sebae Networks","og_description":"View Best Practices for Migrating from Exchange Server 2013 to Exchange Server 2019 for free, here at Sebae. Discover more great posts on our website.","og_url":"https:\/\/www.sebae.net\/blog\/best-practices-for-migrating-from-exchange-server-2013-to-exchange-server-2019\/","og_site_name":"Sebae Networks","article_publisher":"https:\/\/www.facebook.com\/sebaenetworks","article_published_time":"2023-03-21T03:00:09+00:00","og_image":[{"url":"https:\/\/techcommunity.microsoft.com\/t5\/image\/serverpage\/image-id\/452250iFDF4E99A6CFBEA16\/image-size\/large?v=v2&amp;px=999","type":"","width":"","height":""}],"author":"James Dean","twitter_card":"summary_large_image","twitter_creator":"@sebaenetworks","twitter_site":"@sebaenetworks","twitter_misc":{"Written by":"James Dean","Estimated reading time":"19 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.sebae.net\/blog\/best-practices-for-migrating-from-exchange-server-2013-to-exchange-server-2019\/#article","isPartOf":{"@id":"https:\/\/www.sebae.net\/blog\/best-practices-for-migrating-from-exchange-server-2013-to-exchange-server-2019\/"},"author":{"name":"James Dean","@id":"https:\/\/www.sebae.net\/blog\/#\/schema\/person\/6d07e05e3d3e4483117c4e2c3315a89f"},"headline":"Best Practices for Migrating from Exchange Server 2013 to Exchange Server 2019","datePublished":"2023-03-21T03:00:09+00:00","mainEntityOfPage":{"@id":"https:\/\/www.sebae.net\/blog\/best-practices-for-migrating-from-exchange-server-2013-to-exchange-server-2019\/"},"wordCount":3381,"commentCount":0,"publisher":{"@id":"https:\/\/www.sebae.net\/blog\/#organization"},"image":{"@id":"https:\/\/www.sebae.net\/blog\/best-practices-for-migrating-from-exchange-server-2013-to-exchange-server-2019\/#primaryimage"},"thumbnailUrl":"https:\/\/www.sebae.net\/blog\/wp-content\/uploads\/2021\/11\/exchange-server-header.png","keywords":["Exchange","Server","time"],"articleSection":["Microsoft Exchange Server"],"inLanguage":"en-GB","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.sebae.net\/blog\/best-practices-for-migrating-from-exchange-server-2013-to-exchange-server-2019\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.sebae.net\/blog\/best-practices-for-migrating-from-exchange-server-2013-to-exchange-server-2019\/","url":"https:\/\/www.sebae.net\/blog\/best-practices-for-migrating-from-exchange-server-2013-to-exchange-server-2019\/","name":"Best Practices for Migrating from Exchange Server 2013 to Exchange Server 2019 | Sebae Networks","isPartOf":{"@id":"https:\/\/www.sebae.net\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.sebae.net\/blog\/best-practices-for-migrating-from-exchange-server-2013-to-exchange-server-2019\/#primaryimage"},"image":{"@id":"https:\/\/www.sebae.net\/blog\/best-practices-for-migrating-from-exchange-server-2013-to-exchange-server-2019\/#primaryimage"},"thumbnailUrl":"https:\/\/www.sebae.net\/blog\/wp-content\/uploads\/2021\/11\/exchange-server-header.png","datePublished":"2023-03-21T03:00:09+00:00","description":"View Best Practices for Migrating from Exchange Server 2013 to Exchange Server 2019 for free, here at Sebae. Discover more great posts on our website.","breadcrumb":{"@id":"https:\/\/www.sebae.net\/blog\/best-practices-for-migrating-from-exchange-server-2013-to-exchange-server-2019\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.sebae.net\/blog\/best-practices-for-migrating-from-exchange-server-2013-to-exchange-server-2019\/"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.sebae.net\/blog\/best-practices-for-migrating-from-exchange-server-2013-to-exchange-server-2019\/#primaryimage","url":"https:\/\/www.sebae.net\/blog\/wp-content\/uploads\/2021\/11\/exchange-server-header.png","contentUrl":"https:\/\/www.sebae.net\/blog\/wp-content\/uploads\/2021\/11\/exchange-server-header.png","width":1920,"height":1080,"caption":"exchange server header"},{"@type":"BreadcrumbList","@id":"https:\/\/www.sebae.net\/blog\/best-practices-for-migrating-from-exchange-server-2013-to-exchange-server-2019\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.sebae.net\/blog\/"},{"@type":"ListItem","position":2,"name":"Best Practices for Migrating from Exchange Server 2013 to Exchange Server 2019"}]},{"@type":"WebSite","@id":"https:\/\/www.sebae.net\/blog\/#website","url":"https:\/\/www.sebae.net\/blog\/","name":"Sebae Networks","description":"Tech Tips, News, Tutorials &amp; Advice","publisher":{"@id":"https:\/\/www.sebae.net\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.sebae.net\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Organization","@id":"https:\/\/www.sebae.net\/blog\/#organization","name":"Sebae","url":"https:\/\/www.sebae.net\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.sebae.net\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.sebae.net\/blog\/wp-content\/uploads\/2023\/06\/sebae-logo-icon.png","contentUrl":"https:\/\/www.sebae.net\/blog\/wp-content\/uploads\/2023\/06\/sebae-logo-icon.png","width":512,"height":512,"caption":"Sebae"},"image":{"@id":"https:\/\/www.sebae.net\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/sebaenetworks","https:\/\/x.com\/sebaenetworks"]},{"@type":"Person","@id":"https:\/\/www.sebae.net\/blog\/#\/schema\/person\/6d07e05e3d3e4483117c4e2c3315a89f","name":"James Dean","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.sebae.net\/blog\/wp-content\/uploads\/2021\/10\/avatar_user_2_1634496168-96x96.jpg72371c27260698ee55141397050ef40a","url":"https:\/\/www.sebae.net\/blog\/wp-content\/uploads\/2021\/10\/avatar_user_2_1634496168-96x96.jpg","contentUrl":"https:\/\/www.sebae.net\/blog\/wp-content\/uploads\/2021\/10\/avatar_user_2_1634496168-96x96.jpg","caption":"James Dean"},"sameAs":["https:\/\/www.sebae.net"],"url":"https:\/\/www.sebae.net\/blog\/author\/jdean\/"}]}},"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/www.sebae.net\/blog\/wp-json\/wp\/v2\/posts\/4135","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.sebae.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.sebae.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.sebae.net\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.sebae.net\/blog\/wp-json\/wp\/v2\/comments?post=4135"}],"version-history":[{"count":0,"href":"https:\/\/www.sebae.net\/blog\/wp-json\/wp\/v2\/posts\/4135\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.sebae.net\/blog\/wp-json\/wp\/v2\/media\/2564"}],"wp:attachment":[{"href":"https:\/\/www.sebae.net\/blog\/wp-json\/wp\/v2\/media?parent=4135"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.sebae.net\/blog\/wp-json\/wp\/v2\/categories?post=4135"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.sebae.net\/blog\/wp-json\/wp\/v2\/tags?post=4135"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.sebae.net\/blog\/wp-json\/wp\/v2\/coauthors?post=4135"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}