The administration and maintenance of Microsoft Exchange Server to ensure secure, reliable, and efficient email and collaboration services across an organization.
Hi @Raymond Brooks
In the scenario you described, it is safe to delete the expired Federation certificate.
The Federation certificate in Exchange Server is primarily used for federation features such as Free/Busy sharing, organization relationships, and certain hybrid configurations. If your environment has already transitioned to SMTP-only and all mailboxes have been migrated, these federation features are typically no longer needed.
Before deleting the certificate, please make sure that:
-The certificate is not currently assigned to any services such as SMTP or IIS.
-There are no remaining hybrid or federation dependencies with Microsoft 365.
-The Federation Trust is no longer required in your environment.
If all of the above are confirmed, the expired Federation certificate can be safely removed.
I hope this information is helpful.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.