6469 words
32 minutes

Configure Exchange Server 2019

Cover image for Configure Exchange Server 2019

This article is for those looking for a detailed and clear guide on how to configure Exchange Server 2019.

IMPORTANT

We will consider the case when you already have two servers with the Windows Server 2019 operating system installed on them. In addition, one of the servers must have the Active Directory Domain Services role installed, and the second server must have Exchange Server 2019 installed.

NOTE

For step-by-step instructions on installing Exchange Server 2019 on Windows Server 2019, refer to my guide: Install Exchange Server 2019 on Windows Server 2019.

NOTE

To learn how to install Active Directory Domain Services on Windows Server 2019, read: Install Active Directory Domain Services on Windows Server 2019.

Open the Exchange Admin Center control panel, which is located at the link https://heva-server-2/ecp, where heva-server-2 is the name of my Exchange server. Accordingly, you need to provide the name or IP address of your server.

To access the Exchange Admin Center Control Panel, you will need to provide a username and password for an account that has Exchange Administrator rights.

Configure Exchange Server 2019 - Step 1

Let’s create a mailbox database.

In the “Servers” section, select the “Databases” subsection and click on the ”+” button.

Configure Exchange Server 2019 - Step 2

Next, you need to specify a name for the new database and select an Exchange server with the “Mailbox” role.

Specify the name of the database and click on the “Browse” button.

Configure Exchange Server 2019 - Step 3

Select the Exchange server with the “Mailbox” role and click on the “OK” button.

Configure Exchange Server 2019 - Step 4

Now you need to specify in which folder the mailbox database and its logs will be stored.

NOTE

You need to first create folders on the server in which you plan to store the database and its logs. In addition, it is better to store the database on a disk specially allocated for this task.

Configure Exchange Server 2019 - Step 5

In the “Database file path” field, specify the folder where the database will be stored.

In the “Log folder path” field, specify the folder in which the database logs will be stored.

Check the “Mount this database” box and click on the “Save” button.

Configure Exchange Server 2019 - Step 6

Now you need to restart the Microsoft Exchange Information Store service on the Exchange server.

Click on the “OK” button.

Configure Exchange Server 2019 - Step 7

Open “Server Manager” on the server with Exchange Server 2019 installed, then click on the “Tools” button in the upper right corner of the screen and select “Services”.

Configure Exchange Server 2019 - Step 8

Right-click on the “Microsoft Exchange Information Store” service and select “Restart”.

Configure Exchange Server 2019 - Step 9

The service has restarted successfully and the new database is ready to go.

Further, in the “Servers” section, select the “Databases” subsection, and then select a new database and double-click on it with the left mouse button.

Configure Exchange Server 2019 - Step 10

In the “Limits” section, you can configure the retention time for deleted mailboxes and letters.

Specify the required values and click on the “Save” button.

Configure Exchange Server 2019 - Step 11

Now let’s create a database for shared folders.

In the “Servers” section, select the “Databases” subsection and click on the ”+” button.

Configure Exchange Server 2019 - Step 12

Specify a name for the shared folder database and click the Browse button.

Configure Exchange Server 2019 - Step 13

Select the Exchange server with the “Mailbox” role and click on the “OK” button.

Configure Exchange Server 2019 - Step 14

Now you need to specify in which folder the database for public folders and its logs will be stored.

NOTE

You need to first create folders on the server in which you plan to store the database and its logs. In addition, it is better to store the database on a disk specially allocated for this task.

Configure Exchange Server 2019 - Step 15

In the “Database file path” field, specify the folder where the database will be stored.

In the “Log folder path” field, specify the folder in which the database logs will be stored.

Check the “Mount this database” box and click on the “Save” button.

Configure Exchange Server 2019 - Step 16

Now you need to restart the Microsoft Exchange Information Store service on the Exchange server.

Click on the “OK” button.

Configure Exchange Server 2019 - Step 17

We return to the “Server Manager” on the server with Exchange Server 2019 installed, click on the “Tools” button in the upper right corner of the screen, and select “Services”.

Configure Exchange Server 2019 - Step 18

Right-click on the “Microsoft Exchange Information Store” service and select “Restart”.

Configure Exchange Server 2019 - Step 19

The service has restarted successfully and the new database is ready to go.

Configure Exchange Server 2019 - Step 20

Next, go to the “Public Folders” section.

In the “Public Folders” section, select the “Public Folder Mailboxes” subsection and click on the ”+” button.

Configure Exchange Server 2019 - Step 21

Specify a name for the public folder mailbox and in the “Mailbox database” section click on the “Browse” button.

Configure Exchange Server 2019 - Step 22

Select the database for shared folders and click on the “OK” button.

Configure Exchange Server 2019 - Step 23

Nothing can be changed in the “Organization unit” section.

Click on the “Save” button.

Configure Exchange Server 2019 - Step 24

After the public folder mailbox is created, it appears under the Public Folder Mailboxes subsection.

Configure Exchange Server 2019 - Step 25

Now let’s add the trusted domain.

In the “Mail Flow” section, select the “Accepted Domains” subsection and click on the ”+” button.

Configure Exchange Server 2019 - Step 26

In the “Name” and “Accepted Domain” fields, specify the domain that you want to add to the trusted ones, then select “Authoritative Domain: E-mail is delivered only to valid recipients in this Exchange organization”.

Click on the “Save” button.

Configure Exchange Server 2019 - Step 27

After the domain is added to the trusted ones, it will appear in the “Accepted Domains” section.

Configure Exchange Server 2019 - Step 28

Now you need to create a policy for generating mailing addresses.

In the “Mail Flow” section, select the “Email Address Policies” subsection and click on the ”+” button.

Configure Exchange Server 2019 - Step 29

Next, you need to specify a name for the new policy and choose who it will be applied to, as well as determine how mail addresses will be generated in your organization.

NOTE

In this tutorial, mailing addresses will be based on “Alias”.

Specify a name for the policy for generating postal addresses and click the ”+” button.

Configure Exchange Server 2019 - Step 30

Specify the main domain and select “[email protected]”.

Click on the “Save” button.

Configure Exchange Server 2019 - Step 31

Now let’s add a second domain so that users can receive mail using the second domain name as well.

Click on the ”+” button.

Configure Exchange Server 2019 - Step 32

Specify the second domain and select “[email protected]”.

Click the “Save” button.

Configure Exchange Server 2019 - Step 33

After you have determined how mail addresses will be formed in your organization, click on the “Save” button.

Configure Exchange Server 2019 - Step 34

Pay attention to the warning. In order for the policy to take effect, you must click on the “Apply” button in the “E-mail Address Policies” subsection.

Configure Exchange Server 2019 - Step 35

After the policy is added, it will appear in the “E-mail Address Policies” subsection with the “Unapplied” status.

To apply a policy, select it and click on the “Apply” button.

Configure Exchange Server 2019 - Step 36

Next, a warning will appear stating that applying the policy may take a long time and you will not be able to perform other tasks while the policy is being applied.

Click on the “Yes” button.

Configure Exchange Server 2019 - Step 37

The policy for generating postal addresses has been successfully applied.

Click on the “Close” button.

Configure Exchange Server 2019 - Step 38

After the policy is applied, it will appear in the “E-mail Address Policies” subsection with the “Applied” status.

Configure Exchange Server 2019 - Step 39

Now you need to create a send connector: to be able to send mail outside the organization.

In the “Mail Flow” section, select the “Send Connectors” subsection and click on the ”+” button.

Configure Exchange Server 2019 - Step 40

Specify a name for the new Send Connector and select “Internet” in the “Type” section.

Click on the “Next” button.

Configure Exchange Server 2019 - Step 41

NOTE

In this example, mail will be sent according to MX records.

Select “MX record associated with recipient domain” and click on the “Next” button.

Configure Exchange Server 2019 - Step 42

Next, you need to specify for which domains the new connector will work.

Click on the ”+” button.

Configure Exchange Server 2019 - Step 43

In the “Full Qualified Domain Name (FQDN)” field, enter *. This way, the new Send Connector will handle all domains except yours.

Click on the “OK” button.

Configure Exchange Server 2019 - Step 44

After you have specified for which domains the new connector will work, click on the “Next” button.

Configure Exchange Server 2019 - Step 45

Next, you need to specify on which Exchange server the Send connector will be created.

Click on the ”+” button.

Configure Exchange Server 2019 - Step 46

Select the Exchange server on which the Send Connector will be created and click on the “OK” button.

Configure Exchange Server 2019 - Step 47

Everything is ready to create a send connector.

Click on the “Finish” button.

Configure Exchange Server 2019 - Step 48

Next, in the “Mail Flow” section, select the “Send Connectors” subsection, then select a new send connector and double-click on it with the left mouse button.

Configure Exchange Server 2019 - Step 49

In the “General” section of the “Maximum send message size (MB)” menu, you can configure the maximum size of mail attachments to be sent.

Configure Exchange Server 2019 - Step 50

Further, in the “Scoping” section, in the “Specify the FQDN this connector will provide in response to HELO or EHLO” field, specify the name by which your mail server is accessible from the Internet.

Click on the “Save” button.

Configure Exchange Server 2019 - Step 51

In the “Mail Flow” section, select the “Send Connectors” subsection. Then click on the ”…” button and select “Organization transport settings”.

Configure Exchange Server 2019 - Step 52

In the “Limits” section, you can configure the maximum size of mail attachments for sending and receiving.

Specify the required values and click on the “Save” button.

Configure Exchange Server 2019 - Step 53

Now you need to provide your Exchange Server 2019 license key.

In the “Servers” section, select the “Servers” subsection and click on the “Edit” button.

Configure Exchange Server 2019 - Step 54

In the “General” section, specify the Exchange Server 2019 license key and click on the “Save” button.

Configure Exchange Server 2019 - Step 55

Now you need to configure DNS records for the domain. To do this, you need to open a web browser and go to the control panel for external DNS records for your domain.

This tutorial uses Amazon Route 53 to manage external DNS records for a domain.

Go to the AWS Management Console, sign in with an administrator account if prompted, and then click the “Services” button located in the upper-left corner of the screen.

Next, in the “Networking & Content Delivery” section, select “Route 53”.

Configure Exchange Server 2019 - Step 56

Next, select “Hosted zones”.

Configure Exchange Server 2019 - Step 57

Select the domain for which you want to configure DNS records.

Configure Exchange Server 2019 - Step 58

Now you need to create several DNS records to access the Exchange services.

Click on the “Create Record Set” button to create a new DNS record.

Configure Exchange Server 2019 - Step 59

Specify “mail” in the “Name” field.

In the “Type” field, select “A - IPv4 address”.

In the “TTL” field, enter “300”.

In the “Value” field, indicate the IP address by which your mail server is accessible from the Internet and click on the “Create” button.

Configure Exchange Server 2019 - Step 60

Click on the “Create Record Set” button to create another DNS record.

In the “Name” field, enter “mx01”.

In the “Type” field, select “A - IPv4 address”.

In the “TTL” field, enter “300”.

In the “Value” field, indicate the IP address by which your mail server is accessible from the Internet and click on the “Create” button.

Configure Exchange Server 2019 - Step 61

Click on the “Create Record Set” button to create another DNS record.

Specify “autodiscover” in the “Name” field.

In the “Type” field, select “A - IPv4 address”.

In the “TTL” field, enter “300”.

In the “Value” field, indicate the IP address by which your mail server is accessible from the Internet and click on the “Create” button.

Configure Exchange Server 2019 - Step 62

Click on the “Create Record Set” button to create another DNS record.

Leave the “Name” field blank.

In the “Type” field, select “MX - Mail exchange”.

In the “TTL” field, enter “300”.

In the “Value” field, specify the priority “10”, then indicate the previously created A-record with the name “mx01” and click on the “Create” button.

Configure Exchange Server 2019 - Step 63

Next, you need to make a request to your ISP to create a PTR record for your external IP address, where your mail server is accessible from the Internet. This is necessary in order for your IP address to resolve to a name.

NOTE

In this example, the IP 188.244.46.91 is translated to the name mail.heyvaldemar.net.

Now you need to create an SPF (Sender Policy Framework). Thanks to SPF, you can check if the sender’s domain has been tampered with. SPF allows you to specify a list of servers capable of sending mail messages on behalf of your domain.

You can get parameters for SPF recording using the SPF Wizard.

SPF example: v=spf1 mx a ip4:188.244.46.91 include:heyvaldemar.com -all

Leave the “Name” field blank.

In the “Type” field, select “SPF - Sender Policy Framework”.

NOTE

If there is no “SPF” record type in your control panel for external DNS records, then you need to select the “TXT” record type.

In the “TTL” field, enter “300”.

In the “Value” field, specify the SPF parameters obtained using the SPF Wizard and click on the “Create” button.

Configure Exchange Server 2019 - Step 64

DNS records for the domain have been configured successfully.

Configure Exchange Server 2019 - Step 65

Now you need to register the A-record on the internal DNS server.

Open “Server Manager” on the domain controller, then click on the “Tools” button in the upper right corner of the screen and select “DNS”.

Configure Exchange Server 2019 - Step 66

In the “Forward Lookup Zones” section, select the main domain and right-click on it, then select “New Host (A or AAAA)”.

Configure Exchange Server 2019 - Step 67

In the “Name (uses parent domain name if blank)” field, specify “Mail”.

In the “IP address” field, specify the IP address of the server on which Exchange Server 2019 is installed and click on the “Add Host” button.

Configure Exchange Server 2019 - Step 68

A record has been successfully added.

Click on the “OK” button.

Configure Exchange Server 2019 - Step 69

After the A-record is added, it will appear in the list with the rest of the records.

Configure Exchange Server 2019 - Step 70

For further configuration, you need a certification authority.

NOTE

In this tutorial, the Active Directory Certificate Services role will be installed on a domain controller.

Go back to the “Server Manager” on the domain controller, then click on the “Manage” button in the upper right corner of the screen and select “Add Roles and Features”.

Configure Exchange Server 2019 - Step 71

Click on the “Next” button.

Configure Exchange Server 2019 - Step 72

Select the installation type “Role-based or feature-based installation” and click on the “Next” button.

Configure Exchange Server 2019 - Step 73

Next, select the server on which the role will be installed.

Click on the “Next” button.

Configure Exchange Server 2019 - Step 74

Select the Active Directory Certificate Services role.

Configure Exchange Server 2019 - Step 75

In the next step, the Role Installation Wizard will warn you that several components need to be installed to install the Active Directory Certificate Services role.

Click on the “Add Features” button.

Configure Exchange Server 2019 - Step 76

Click on the “Next” button.

Configure Exchange Server 2019 - Step 77

At the stage of adding components, we leave all the default values.

Click on the “Next” button.

Configure Exchange Server 2019 - Step 78

Next, the Role Installation Wizard invites you to learn more about the Active Directory Certificate Services role.

Click on the “Next” button.

Configure Exchange Server 2019 - Step 79

Now you need to select the required services.

We select “Certification Authority Web Enrollment”.

Configure Exchange Server 2019 - Step 80

In the next step, the Install Roles Wizard will warn you that several components need to be installed to install the Certification Authority Web Enrollment.

Click on the “Add Features” button.

Configure Exchange Server 2019 - Step 81

Next, select “Online Responder”.

Configure Exchange Server 2019 - Step 82

The Role Installation Wizard will warn you that several components need to be installed to install Online Responder.

Click on the “Add Features” button.

Configure Exchange Server 2019 - Step 83

After all the necessary services are selected, click on the “Next” button.

Configure Exchange Server 2019 - Step 84

In the next step, the “Role Installation Wizard” will warn you that the “Internet Information Services” webserver role will be additionally installed for the “Active Directory Certificate Services” role.

Configure Exchange Server 2019 - Step 85

At the stage of adding components, we leave all the default values.

Click on the “Next” button.

Configure Exchange Server 2019 - Step 86

In order to start the installation of the selected role, click on the “Install” button.

Configure Exchange Server 2019 - Step 87

The installation of the selected role and the components required for it has begun.

Configure Exchange Server 2019 - Step 88

Installation of the Active Directory Domain Services role is now complete.

Now you need to configure the role.

Click on the button “Configure Active Directory Certificate Services on the destination server”.

Configure Exchange Server 2019 - Step 89

Click on the “Next” button.

Configure Exchange Server 2019 - Step 90

Next, you need to select the services that you want to configure.

Select “Certification Authority”, “Certification Authority Web Enrollment” and “Online Responder” and click on the “Next” button.

Configure Exchange Server 2019 - Step 91

The server is a member of the domain, so select “Enterprise CA” and click on the “Next” button.

Configure Exchange Server 2019 - Step 92

There are no other servers with the Active Directory Certificate Services role in the domain, so select “Root CA” and click on the “Next” button.

Configure Exchange Server 2019 - Step 93

Next, you need to create a new private key.

Select “Create a new private key” and click on the “Next” button.

Configure Exchange Server 2019 - Step 94

Next, you can select the cryptography settings.

Leave the settings unchanged and click on the “Next” button.

Configure Exchange Server 2019 - Step 95

In the “Common name for this CA” field, specify the name for the new certification authority and click on the “Next” button.

Configure Exchange Server 2019 - Step 96

Now we select the validity period of the certificate and click on the “Next” button.

Configure Exchange Server 2019 - Step 97

Next, you can specify where the certificate database and its logs will be stored.

Leave the settings unchanged and click on the “Next” button.

Configure Exchange Server 2019 - Step 98

Everything is ready to configure the role.

Click on the “Configure” button.

Configure Exchange Server 2019 - Step 99

The Active Directory Certificate Services role is now configured.

Click on the “Close” button.

Configure Exchange Server 2019 - Step 100

Click on the “Close” button to close the role installation window.

Configure Exchange Server 2019 - Step 101

Now you need to enable the SAN (Subject Alternative Name) function on the CA server. This feature is useful when publishing the “Autodiscover” service.

On the keyboard, press the key combination “Win” and “x” and in the menu that opens, select “Windows PowerShell (Admin)”.

Configure Exchange Server 2019 - Step 102

We enable the SAN function using the command:

Terminal window
certutil -setreg policy\EditFlags +EDITF_ATTRIBUTESUBJECTALTNAME2

Configure Exchange Server 2019 - Step 103

Now you need to restart the “CertSvc” service.

Stop the “CertSvc” service using the command:

Terminal window
net stop certsvc

Configure Exchange Server 2019 - Step 104

We start the “CertSvc” service using the command:

Terminal window
net start certsvc

Configure Exchange Server 2019 - Step 105

Service “CertSvc” restarted successfully.

Configure Exchange Server 2019 - Step 106

Now let’s make a request to create a new Exchange certificate.

We return to the Exchange Admin Center control panel.

In the “Servers” section, select the “Certificates” subsection and click on the ”+” button.

Configure Exchange Server 2019 - Step 107

Select “Create a request for a certificate from a certification authority” and click on the “Next” button.

Configure Exchange Server 2019 - Step 108

Specify a name for the new certificate and click on the “Next” button.

Configure Exchange Server 2019 - Step 109

Then leave the settings unchanged and click on the “Next” button.

Configure Exchange Server 2019 - Step 110

Now you need to specify the Exchange server where the certificate request will be stored.

Click on the “Browse” button.

Configure Exchange Server 2019 - Step 111

Select the Exchange server where the certificate request will be stored and click on the “OK” button.

Configure Exchange Server 2019 - Step 112

After the Exchange server is specified, click on the “Next” button.

Configure Exchange Server 2019 - Step 113

Now you need to specify the domain names that need to be included in the certificate for all types of access.

Select “Outlook Web App (when accessed from the Internet)” and click on the “Edit” button.

Configure Exchange Server 2019 - Step 114

Specify the name by which your mail server is accessible from the Internet for the “Outlook Web App” access type, and click on the “OK” button.

Configure Exchange Server 2019 - Step 115

Select OAB (when accessed from the Internet) ”, and click on the” Edit “(Pencil) button.

Configure Exchange Server 2019 - Step 116

We indicate the name by which your mail server is accessible from the Internet for the access type “OAB”, and click on the “OK” button.

Configure Exchange Server 2019 - Step 117

Select “Exchange Web Services (when accessed from the Internet)”, and click on the “Edit” button.

Configure Exchange Server 2019 - Step 118

Specify the name by which your mail server is accessible from the Internet for the “Exchange Web Services” access type, and click on the “OK” button.

Configure Exchange Server 2019 - Step 119

Select “Exchange ActiveSync (when accessed from the Internet)” and click on the “Edit” button.

Configure Exchange Server 2019 - Step 120

Specify the name by which your mail server is accessible from the Internet for the “Exchange ActiveSync” access type, and click on the “OK” button.

Configure Exchange Server 2019 - Step 121

Select “POP” and click on the “Edit” button.

Configure Exchange Server 2019 - Step 122

We indicate the name by which your mail server is accessible from the Internet for the “POP” access type, and click on the “OK” button.

Configure Exchange Server 2019 - Step 123

Select “IMAP” and click on the “Edit” button.

Configure Exchange Server 2019 - Step 124

We indicate the name by which your mail server is accessible from the Internet for the type of access “IMAP”, and click on the “OK” button.

Configure Exchange Server 2019 - Step 125

Select “Outlook Anywhere” and click on the “Edit” button.

Configure Exchange Server 2019 - Step 126

Specify the name by which your mail server is accessible from the Internet for the “Outlook Anywhere” access type and click on the “OK” button.

Configure Exchange Server 2019 - Step 127

The domain names that must be included in the certificate for all types of access are indicated.

Click on the “Next” button.

Configure Exchange Server 2019 - Step 128

Below is a list of domains that will be included in the certificate.

Click on the “Next” button.

Configure Exchange Server 2019 - Step 129

Next, you must specify the name of the organization, department, and geographic location of the company.

This guide is based on an organization based in Los Angeles, USA.

We indicate the necessary information and click on the “Next” button.

Configure Exchange Server 2019 - Step 130

Now you need to specify the folder where the Exchange certificate request will be saved.

NOTE

In this tutorial, the certificate request will be saved to the local “C” drive on the Exchange server.

Specify where the Exchange certificate request will be saved and click on the “Finish” button.

Configure Exchange Server 2019 - Step 131

After the certificate request is created, it will appear in the “Certificates” subsection with the “Pending request” status.

Configure Exchange Server 2019 - Step 132

Now you need to validate your Exchange certificate with a CA.

On the Exchange server, go to the link http://heva-server-1/certsrv, where heva-server-1 is the name of my certification authority server. Accordingly, you need to specify the name of your server.

We go under an account with administrator rights and click on the “OK” button.

Configure Exchange Server 2019 - Step 133

Now let’s add the address of the certification server to “Trusted sites”.

Click on the “Add” button.

Configure Exchange Server 2019 - Step 134

In the “Add this website to the zone” field, specify the address of the certification server and click on the “Add” button.

Configure Exchange Server 2019 - Step 135

Click on the “Close” button.

Configure Exchange Server 2019 - Step 136

Now select “Request a certificate”.

Configure Exchange Server 2019 - Step 137

Next, select “Advanced certificate request”.

Configure Exchange Server 2019 - Step 138

Now select “Submit a certificate request by using a base-64-encoded CMC or PKCS #10 file, or submit a renewal request by using a base-64-encoded PKCS #7 file”.

Configure Exchange Server 2019 - Step 139

Next, open “Explorer” and go to the local drive “C” where the Exchange certificate request was saved.

Click on the certificate request file twice with the left mouse button.

Configure Exchange Server 2019 - Step 140

Click on the “Try an app on this PC” button.

Configure Exchange Server 2019 - Step 141

Select “Notepad” and click on the “OK” button.

Configure Exchange Server 2019 - Step 142

Copy the contents of the request file.

Configure Exchange Server 2019 - Step 143

Next, insert the contents of the request file into the “Saved Request” field, then in the “Certificate Template” section, select “Web Server” and click on the “Submit” button.

Configure Exchange Server 2019 - Step 144

Select “DER encoded” and click on the “Download certificate” button.

Configure Exchange Server 2019 - Step 145

In the “Save” menu, select “Save as”.

Configure Exchange Server 2019 - Step 146

Assign a name and save the Exchange certificate to the Downloads folder.

Click on the “Save” button.

Configure Exchange Server 2019 - Step 147

Now you need to download the CA certificate.

Click on the “Home” button in the upper right corner of the screen.

Select “Download a CA certificate, certificate chain, or CRL”.

Configure Exchange Server 2019 - Step 148

In the “Encoding method” section, select “DER” and click on the “Download CA certificate” button.

Configure Exchange Server 2019 - Step 149

In the “Save” menu, select “Save as”.

Configure Exchange Server 2019 - Step 150

We assign a name and save the certificate of the certification authority in the “Downloads” folder.

Click on the “Save” button.

Configure Exchange Server 2019 - Step 151

To successfully validate your Exchange certificate request, you must import the CA certificate into the Trusted Root Certification Authorities on the Exchange server.

On the keyboard, press the key combination “Win” and “R”, then enter “certlm.msc” and click on the “OK” button.

Configure Exchange Server 2019 - Step 152

In the “Certificates (Local Computer)” section, select the “Trusted Root Certification Authorities” subsection, then right-click on the “Certificates” subsection and select “All Tasks”, then “Import”.

Configure Exchange Server 2019 - Step 153

Click on the “Next” button.

Configure Exchange Server 2019 - Step 154

Next, you need to specify the path to the certificate of the certification authority.

Click on the “Browse” button.

Configure Exchange Server 2019 - Step 155

Select the certificate of the certification authority and click on the “Open” button.

Configure Exchange Server 2019 - Step 156

After the path to the certificate of the certification authority is indicated, click on the “Next” button.

Configure Exchange Server 2019 - Step 157

Then leave the settings unchanged and click on the “Next” button.

Configure Exchange Server 2019 - Step 158

Everything is ready to import the certificate into the “Trusted Root Certification Authorities”.

Click on the “Finish” button.

Configure Exchange Server 2019 - Step 159

The CA certificate has been successfully imported.

Click on the “OK” button.

Configure Exchange Server 2019 - Step 160

We return to the Exchange Admin Center control panel.

In the “Servers” section, select the “Certificates” subsection. Then select the new Exchange certificate and click on the “Complete” button on the right.

Configure Exchange Server 2019 - Step 161

Next, you need to specify the path to the Exchange certificate.

Specify the path to the Exchange certificate and click on the “OK” button.

Configure Exchange Server 2019 - Step 162

After the certificate is confirmed, it will appear in the “Certificates” subsection with the “Valid” status.

Now you need to assign a new Exchange certificate for SMTP and IIS services.

Select a new certificate and double-click on it with the left mouse button.

Configure Exchange Server 2019 - Step 163

In the “Services” section, check the boxes for “SMTP”, “IMAP”, “POP”, and “IIS”, then click on the “Save” button.

Configure Exchange Server 2019 - Step 164

Next, a warning will appear asking you to overwrite the existing certificate for SMTP.

Configure Exchange Server 2019 - Step 165

After the Exchange certificate is assigned to the services, the list of services in the “Assigned to services” field is updated.

Configure Exchange Server 2019 - Step 166

Now let’s take a look at the Outlook Web App settings.

In the “Servers” section, select the “Virtual Directories” subsection and select the “owa (Default Web Site)” virtual folder, and then double-click on it with the left mouse button.

Configure Exchange Server 2019 - Step 167

In the “General” section, in the “External URL” field, specify the name by which your mail server is accessible from the Internet, and also specify “/owa”.

Configure Exchange Server 2019 - Step 168

Now let’s configure user authorization by login without having to specify a domain.

In the “Authentication” section in the “Use forms-based authentication” section, select “User name only”.

Next, you need to select the main domain, click on the “Browse” button.

Configure Exchange Server 2019 - Step 169

Select the main domain and click on the “OK” button.

Configure Exchange Server 2019 - Step 170

After the domain is specified, click on the “Save” button.

Configure Exchange Server 2019 - Step 171

Next, a warning will appear asking you to restart IIS.

IIS will restart later.

Click on the “OK” button.

Configure Exchange Server 2019 - Step 172

Now let’s write the address where your mail server is accessible from the Internet in the Exchange server configuration.

In the “Servers” section, select the “Virtual Directories” subsection and select the “ecp (Default Web Site)” virtual folder, and then double-click on it with the left mouse button.

Configure Exchange Server 2019 - Step 173

In the “General” section, in the “External URL” field, specify the name by which your mail server is accessible from the Internet, and also specify “/ecp”.

Click on the “Save” button.

Configure Exchange Server 2019 - Step 174

In the “Servers” section, select the “Virtual Directories” subsection and select the “EWS (Default Web Site)” virtual folder, and then double-click on it with the left mouse button.

Configure Exchange Server 2019 - Step 175

In the “General” section, in the “External URL” field, specify the name by which your mail server is accessible from the Internet, and also specify “/EWS/Exchange.asmx”.

Click on the “Save” button.

Configure Exchange Server 2019 - Step 176

In the “Servers” section, select the “Virtual Directories” subsection and select the “mapi (Default Web Site)” virtual folder, and then double-click on it with the left mouse button.

Configure Exchange Server 2019 - Step 177

In the “General” section, in the “External URL” field, specify the name by which your mail server is accessible from the Internet, and also specify “/mapi”.

Click on the “Save” button.

Configure Exchange Server 2019 - Step 178

In the “Servers” section, select the “Virtual Directories” subsection and select the “Microsoft-Server-ActiveSync (Default Web Site)” virtual folder, and then double-click on it with the left mouse button.

Configure Exchange Server 2019 - Step 179

In the “General” section, in the “External URL” field, specify the name by which your mail server is accessible from the Internet, and also specify “/Microsoft-Server-ActiveSync”.

Click on the “Save” button.

Configure Exchange Server 2019 - Step 180

In the “Servers” section, select the “Virtual Directories” subsection and select the “OAB (Default Web Site)” virtual folder, and then double-click on it with the left mouse button.

Configure Exchange Server 2019 - Step 181

In the “General” section, in the “External URL” field, specify the name by which your mail server is accessible from the Internet, and also specify “/OAB”.

Click on the “Save” button.

Configure Exchange Server 2019 - Step 182

In the “Servers” section, select the “Virtual Directories” subsection and select the “PowerShell (Default Web Site)” virtual folder, and then double-click on it with the left mouse button.

Configure Exchange Server 2019 - Step 183

In the “General” section, in the “External URL” field, specify the name by which your mail server is accessible from the Internet, and also specify “/powershell”.

Click on the “Save” button.

Configure Exchange Server 2019 - Step 184

Now let’s configure the Outlook Anywhere service. This service is used to connect to the Exchange server via the Internet using “Outlook”.

In the “Servers” section, select the “Servers” subsection, select the Exchange server, and double-click on it with the left mouse button.

Configure Exchange Server 2019 - Step 185

Next, in the “Specify the external hostname such as contoso.com that users will use to connect to your organization” field, specify the name by which your mail server is accessible from the Internet. Then, in the “Specify the authentication method for external clients to use when connecting to your organization” menu, select “NTLM” and uncheck the “Allow SSL offloading” checkbox.

Click on the “Save” button.

Configure Exchange Server 2019 - Step 186

Now let’s restart IIS.

On the keyboard, press the key combination “Win” and “x” and in the menu that opens, select “Windows PowerShell (Admin)”.

Configure Exchange Server 2019 - Step 187

Restart IIS using the command:

Terminal window
iisreset /noforce

Configure Exchange Server 2019 - Step 188

IIS restarted successfully.

Configure Exchange Server 2019 - Step 189

Now let’s configure the ability to receive mail.

In the “Mail Flow” section, select the “Receive Connectors” subsection, select the “Default Frontend HEVA-SERVER-2” receive connector, where HEVA-SERVER-2 is the name of my Exchange server. Then click on it twice with the left mouse button.

Configure Exchange Server 2019 - Step 190

In the “General” section, in the “Maximum receive message size” field, you can configure the maximum allowable size of mail attachments for receiving.

Configure Exchange Server 2019 - Step 191

In the “Security” section, check for a checkmark on the “Anonymous users” item.

Click on the “Save” button.

Configure Exchange Server 2019 - Step 192

Now let’s create a new user with a mailbox.

In the “Recipients” section, select the “Mailboxes” subsection.

Configure Exchange Server 2019 - Step 193

Click on the ”+” button and select “User mailbox”.

Configure Exchange Server 2019 - Step 194

Now we specify the alias, first, and the last name for the new user.

Then you need to select the organization unit in which you plan to create a new user.

Click on the “Browse” button.

Configure Exchange Server 2019 - Step 195

Select the OU in which you want to place the new user, and click on the “OK” button.

Configure Exchange Server 2019 - Step 196

In the “User logon name” field, specify the login for the new user.

Next, specify a strong password and click on the “More options” button.

Configure Exchange Server 2019 - Step 197

Now you need to select the database in which the mailbox will be created for the new user.

In the “Mailbox database” section, click on the “Browse” button.

Configure Exchange Server 2019 - Step 198

Select the mailbox database and click on the “OK” button.

Configure Exchange Server 2019 - Step 199

Everything is ready to create a user with a mailbox.

Click on the “Save” button.

Configure Exchange Server 2019 - Step 200

After the user with the mailbox is created, it will appear in the “Mailboxes” section.

Configure Exchange Server 2019 - Step 201

Now you need to import the Exchange certificate into Trusted Root Certification Authorities on all computers in the domain.

Go to the domain controller, create a folder and copy the Exchange certificate into it.

Configure Exchange Server 2019 - Step 202

NOTE

In this tutorial, the certificate was copied to the “ExchangeCertificate” folder on the “C” drive.

Configure Exchange Server 2019 - Step 203

Go back to “Server Manager” on the domain controller, then click on the “Tools” button in the upper right corner of the screen and select “Group Policy Management”.

Configure Exchange Server 2019 - Step 204

Now let’s create a new Group Policy to import the certificate into Trusted Root Certification Authorities on all computers in the domain.

Right-click on the domain name and select “Create a GPO in this domain, and Link it here”.

Configure Exchange Server 2019 - Step 205

Specify a name for the new group policy and click on the “OK” button.

Configure Exchange Server 2019 - Step 206

Next, click on the new policy with the right mouse button and select “Edit”.

Configure Exchange Server 2019 - Step 207

In the Group Policy Editor, go to the “Computer Configuration” section, then to the “Windows Settings” subsection, then find the “Security Settings” section and select “Public Key Policies”, now right-click on “Trusted Root Certification Authorities” and select ” Import ”.

Configure Exchange Server 2019 - Step 208

Click on the “Next” button.

Configure Exchange Server 2019 - Step 209

Next, you need to specify the path to the Exchange certificate.

Click on the “Browse” button.

Configure Exchange Server 2019 - Step 210

Go to the folder with the Exchange certificate and click on the “Open” button.

Configure Exchange Server 2019 - Step 211

After the path to the certificate is specified, click on the “Next” button.

Configure Exchange Server 2019 - Step 212

Then leave the settings unchanged and click on the “Next” button.

Configure Exchange Server 2019 - Step 213

Everything is ready to import the certificate into the “Trusted Root Certification Authorities” for all computers in the domain.

Click on the “Finish” button.

Configure Exchange Server 2019 - Step 214

The Exchange certificate has been successfully imported into Group Policy settings.

Click on the “OK” button.

Configure Exchange Server 2019 - Step 215

After the certificate is imported into Group Policy settings, it will appear in the “Trusted Root Certification Authorities” section.

The Exchange certificate will now be imported to all computers covered by this policy.

Configure Exchange Server 2019 - Step 216


Patreon Exclusives#

🏆 Join my Patreon and dive deep into the world of Docker and DevOps with exclusive content tailored for IT enthusiasts and professionals. As your experienced guide, I offer a range of membership tiers designed to suit everyone from newbies to IT experts.


Tools I Personally Trust#

If you’re building things, breaking things, and trying to keep your digital life a little saner (like every good DevOps engineer), these are two tools that I trust and use daily:

🛸 Proton VPN - My shield on the internet. It keeps your Wi-Fi secure, hides your IP, and blocks those creepy trackers. Even if I’m hacking away on free café Wi-Fi, I know I’m safe.

🔑 Proton Pass - My password vault. Proper on-device encryption, 2FA codes, logins, secrets - all mine and only mine. No compromises.

These are partner links - you won’t pay a cent more, but you’ll be supporting DevOps Compass. Thanks a ton - it helps me keep this compass pointing the right way 💜


Gear & Books I Trust#

📕 Essential DevOps books
🖥️ Studio streaming & recording kit
📡 Streaming starter kit


Social Channels#

🎬 YouTube
🐦 X (Twitter)
🎨 Instagram
🐘 Mastodon
🧵 Threads
🎸 Facebook
🦋 Bluesky
🎥 TikTok
💻 LinkedIn
📣 daily.dev Squad
✈️ Telegram
🐈 GitHub


Community of IT Experts#

👾 Discord


Refill My Coffee Supplies#

💖 PayPal
🏆 Patreon
🥤 BuyMeaCoffee
🍪 Ko-fi
💎 GitHub
Telegram Boost

🌟 Bitcoin (BTC): bc1q2fq0k2lvdythdrj4ep20metjwnjuf7wccpckxc
🔹 Ethereum (ETH): 0x76C936F9366Fad39769CA5285b0Af1d975adacB8
🪙 Binance Coin (BNB): bnb1xnn6gg63lr2dgufngfr0lkq39kz8qltjt2v2g6
💠 Litecoin (LTC): LMGrhx8Jsx73h1pWY9FE8GB46nBytjvz8g


Is this content AI-generated?

No. Every article on this blog is written by me personally, drawing on decades of hands-on IT experience and a genuine passion for technology.

I use AI tools exclusively to help polish grammar and ensure my technical guidance is as clear as possible. However, the core ideas, strategic insights, and step-by-step solutions are entirely my own, born from real-world work.

Because of this human-and-AI partnership, some detection tools might flag this content. You can be confident, though, that the expertise is authentic. My goal is to share road-tested knowledge you can trust.

Configure Exchange Server 2019
https://www.heyvaldemar.com/configure-exchange-server-2019/
Author
Vladimir Mikhalev
Published at
2019-11-29
License
CC BY-NC-SA 4.0