Configure an on-premises BEMS to communicate with the Microsoft Exchange Server, Microsoft Exchange Online, or hybrid environment
When you configure BEMS in a Microsoft Exchange Online environment, it is recommended to use Microsoft Graph as the subscription type. For BEMS in a Microsoft Exchange on-premises environment, Microsoft Exchange Web Services (EWS) must be used. For more information on Microsoft Graph and EWS, see your Microsoft documentation.
- In an on-premises Microsoft Exchange Server environment: If you want to use the BEMS service account to authenticate with Microsoft Exchange Server, verify that the service account has impersonation rights on the Microsoft Exchange Server. For instructions, see "Grant application impersonation permission to the BEMS service account" in the Installation content.
- In a Microsoft Exchange Online environment: If you want to use client-certificate authentication, verify that you have enabled Modern Authentication using a Client Certificate.
- Obtain the Client Application ID with certificate based authentication
- Request and associate the .pfx certificate with the Entra app ID for BEMS
- In a hybrid environment and you want to enable Modern Authentication, make sure that the on-premises Microsoft Exchange Server is configured to use hybrid modern authentication. For more information, see the Microsoft resource How to configure Exchange Server on-premises to use Hybrid Modern Authentication. If the Microsoft Exchange Server is not configured appropriately, users won't receive email notifications.
- Review the Best practices for enabling autodiscovery.