Jump to content

Recommended Posts

Posted

I'm trying to get off an onsite Exchange server up to O365. When I run the HCW, it gets to the point of validating my domain through a TXT file (which is there and it seems happy with), but then it says;

 

Failed - Unable to federate your domain. Your system time appears to be more than five minutes out of sync with the time on our federation servers. Ensure your system time is correct and retry the Hybrid Configuration Wizard.

 

The time (and timezone) is correct on the server. How do I check it against "our federation servers"? I can't find anything through Googling other than "This problem occurs if the system time of your local system and the system time of the server from which you're running the Hybrid Configuration wizard differ by five minutes or more." The local system and the server from which I'm running the HCW are the same system!

 

Anyone got anything please?

 

Stuart

Posted

Is there any time variance at all, from your local server to Microsoft’s own internet time servers? Often easiest to check with a smartphone.

 

You don’t do something funny with DST do you?

Posted
Are you removing outdated exchange servers from your hybrid? I started a new role in September where I had to replace some 2010 exchange servers and update the hybrid. When doing this we had the same issue, turned out to be an issue with the hybrid certificate that was initially created on the 2010 servers expiring. Which caused the same generic error.
Posted

Nothing funny with DST.

 

My time is apparently 0.017 seconds out, which by my reckoning is less than 5.

@jslate1980 - That's exactly what I'm trying to do. I'll take a look tomorrow. Thank you.

Posted
The error in the hybrid configuration logs for us was this "An error occurred while attempting to provision Exchange to the Partner STS. Detailed Information "An unexpected result was received from Windows Live. Detailed information: "1007 AccessDenied: Access Denied.". As it wasn't a time issue we checked federation certificate and it had expired a while ago. So it was suggested that we had to do this first https://learn.microsoft.com/en-us/previous-versions/exchange-server/exchange-160/mt779252(v=exchg.160)?redirectedfrom=MSDN#ReplaceExpired.
  • 2 weeks later...
Posted
Are you removing outdated exchange servers from your hybrid? I started a new role in September where I had to replace some 2010 exchange servers and update the hybrid. When doing this we had the same issue, turned out to be an issue with the hybrid certificate that was initially created on the 2010 servers expiring. Which caused the same generic error.

 

Picked this back up at last! I did have an expired certificate. I've removed the federation and am now trying to re-add. I've added it and am now running the "Manage Federation" wizard and it's getting through to the end of the wizard but then the proof of domain ownership is failing. "Make sure the TXT record for the specified domain blah blah blah". If I run "Nslookup.exe -querytype=txt " on the exchange server, it returns the info I'd expect to see when comparing it with running the "Get-FederatedDomainProof" command. I have two onsite DNS servers, both have the txt record in them. What did I miss?

Posted
I assumed that's where it would need to go, but everything I could find took you through adding it internally, so that's what I did. Felt wrong at the time as. Reckon it needs to be external too?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...