Exchange 2010+ multi-org hybrid deployment
1. Prepare
Update each Exchange organization to n-1
Validate AutoDiscover is properly configured and published
in each Exchange organization
Validate public certificates for Exchange org are unique
Create 2 way forest trust (if using one ADFS)
2. Configure Mail Flow on-prem
Configure SMTP domain sharing as required
Configure mail flow between on-prem organizations
3. Configure Directory Synchronization
Configure FIM + AAD Connect to synchronize mail recipients
in each forest and the Office 365 tenant
4. Run Hybrid Configuration Wizard
Prepare Office 365 Tenant
Run the HCW in contoso.com and fabrikam.com
Validate mail flow between all entities
5. Configure ADFS
Configure ADFS in contoso.com (OPTIONAL)
Configure ADFS in fabrikam.com (OPTIONAL)
6. Configure Organization Relationships
Configure an Org Relationship between each Org
E2013
ADFS
AD
fabrikam.onmicrosoft.com
fabrikam.com contoso.com
E2013
ADFS
AD AADSYNC
Azure AD
Azure AD Auth
O365 Directory
ADFS
Proxy
ADFS
Proxy
SMTP
AAD Connect
2 way Forest Trust
FIM Management Agent
Federated Trust Relationship
SMTP/TLS Mail Flow
Federated Authentication
Organization Relationship