A cloud-based service included in Microsoft 365, delivering scalable messaging and collaboration features with simplified management and automatic updates.
If the issue is a 403 for Exchange Online connectivity and one account started working after a policy change while the other still fails, the supported guidance in the available documentation is:
- Wait and retest if the change was recent. For 403 errors in Exchange hybrid configuration, a timing issue can prevent completion, and the documented resolution is to wait approximately 30 minutes and rerun the operation.
- If this is related to mailbox moves or remote connectivity through EWS/MRSProxy, verify the hybrid server EWS virtual directory configuration.
In Exchange Management Shell, run:
Get-WebServicesVirtualDirectory "ServerName\EWS (Default Web Site)" | FL Server,MRSProxyEnabled- If
MRSProxyEnabled : Falseis returned, that is a documented cause of 403 errors. - If
MRSProxyEnabled : Trueis returned, check Event Viewer > Application log for event 1309 withMRS proxy service is disabled.
- If
- If MRSProxy is disabled, enable it:
Then restart IIS withSet-WebServicesVirtualDirectory "<ServerName>\EWS (Default Web Site)" -MRSProxyEnabled $trueiisreset. - If MRSProxy appears enabled but is still effectively disabled, disable and re-enable it:
Wait a few minutes, then run:Set-WebServicesVirtualDirectory "<ServerName>\EWS (Default Web Site)" -MRSProxyEnabled $false
Then restart IIS withSet-WebServicesVirtualDirectory "<ServerName>\EWS (Default Web Site)" -MRSProxyEnabled $trueiisreset. - Test Exchange Online to on-premises EWS connectivity:
When prompted, use credentials inTest-MigrationServerAvailability -RemoteServer <on-premises mail server FQDN> -ExchangeRemoteMove -Credentials (Get-Credential)domain\administratorformat.
Based on the documented guidance, waiting can be valid for some 403 scenarios, but 8 hours is already well beyond the documented 30-minute timing case. The next supported checks are the EWS/MRSProxy state and connectivity test above.
References: