Automated certificate renewal for Microsoft Exchange Server
Replacing the Exchange certificate means Import-ExchangeCertificate, Enable-ExchangeCertificate for the right services, and remembering not to touch the auth certificate. The Exchange package does exactly that, on every renewal.
package windows-exchange-target 3.0.0
importenableServicesverifyServicescleanupwhen configured
At a glance
- Package
windows-exchange-target 3.0.0- Compatibility
Exchange Server >=2016 <2026- Runs from
- A Windows agent on the server
- Mechanism
- PowerShell
- Authentication
- Local - no remote login
- Capabilities
- Import certificate and keyUpdate bindingVerify deploymentRemove old certificate
- Deployment steps
- import → enableServices → verifyServices → cleanup*
- Rollback
- None
- Key usage
- Server authentication
* conditional step
What it does
The agent on the Exchange server imports the renewed certificate through the Exchange Management Shell and enables it for the services you choose - IIS, SMTP, POP, IMAP, and UM, UMCallRouter or Federation where used. It then checks that those services are assigned to the new certificate.
Optionally, older certificates with the same subject whose services the new one now covers are removed. The Exchange auth certificate is never removed.
How it runs
- 01
import
The certificate is imported with Import-ExchangeCertificate.
- 02
enableServices
Enable-ExchangeCertificate assigns it to the configured services.
- 03
verifyServices
The package confirms the services now use the new certificate.
- 04
cleanup
Superseded certificates for the same subject are removed, if enabled - never the auth certificate.
What you configure
- Services to enable: IIS, SMTP, POP, IMAP, UM, UMCallRouter, Federation
- Whether the key may be exported later
- Whether to remove superseded certificates
Prerequisites
- A Windows agent on each Exchange server
- Exchange Management Shell available to the agent service
- A certificate whose SANs cover the namespaces clients use (for example mail and autodiscover)
Limitations
- Each Exchange server in a DAG runs its own agent and deploy target.
Doing it by hand
The documentation has a step-by-step guide for replacing this certificate manually - useful for a first install, or to see exactly what the package automates.
Related features
Solutions
More in Microsoft and Windows Server
Documentation
Frequently asked questions
Microsoft Exchange Server
Is the Exchange auth certificate affected?
No. The clean-up step explicitly never removes the Exchange auth certificate.
Can I use Let's Encrypt for Exchange?
Yes, for publicly resolvable names validated with DNS-01. Internal-only names can come from AD CS through the CA connector.
Automate Microsoft Exchange Server
Enroll an agent, attach the package, and the next renewal installs itself.
Community plan, no card required. Open registration - your account is ready in a few minutes.