Configuring Exchange On-Premise

This guide explains how to configure the Nextcloud Exchange Connector to authenticate with Microsoft Exchange On-Premise environments (Exchange 2016, Exchange 2019).

Note:

Unlike Microsoft 365 Cloud environments that use OAuth app registrations, On-Premise setups rely on dedicated Service Accounts. To securely synchronize calendars and contacts without knowing every user's personal password, the connector utilizes the ApplicationImpersonation role in Exchange.

Pre-requirements

Before you begin configuring the Exchange Server, ensure you have the following:

  1. Administrative Access: You must have access to the Exchange Admin Center (EAC) with an account that holds "Organization Management" or "Role Management" permissions.

  2. Exchange Web Services (EWS): EWS must be enabled and externally accessible if your Nextcloud instance is hosted outside your local network.

Step 1. Create Exchange Service Accounts

Why this is needed: You must create dedicated user accounts in your Active Directory/Exchange environment that the connector will use to act as a background daemon.

  1. Open your Active Directory Users and Computers (ADUC) or Exchange Admin Center.

0.jpg
  1. Login as an Administrator.

  2. In the left-hand sidebar, select recipients.

  3. Select mailboxes.

2.jpg
  1. Select '+' → User mailbox.

3.jpg
  1. Fill in the required fields and press Save.

4.png

Pro Tip: Bypass Exchange Throttling

Microsoft Exchange enforces strict throttling limits on concurrent EWS connections per user account. If you are synchronizing hundreds or thousands of users, a single service account will quickly hit this limit, causing synchronization to bottleneck.

We highly recommend creating multiple service accounts (e.g., sync-admin-1, sync-admin-2) from the start. The connector will distribute the load across them automatically.

Step 2. Configure the Impersonation Role Group

  1. In the left-hand navigation pane, navigate to permissions and select the admin roles tab.

  2. Click the + (Add) icon to create a new role group.

5.jpg
  1. In the new window, enter a descriptive Name (e.g., Nextcloud Sync Impersonation) and an optional description.

  2. Scroll down to the Roles section and click the + (Add) icon.

6.jpg
  1. In the Select a Role window, select ApplicationImpersonation, click add ->, and then click OK.

    7.jpg

Step 3. Assign Service Accounts to the Role Group

  1. Still inside your newly created Role Group window, scroll down to the Members section.

  2. Click the + (Add) icon.

8.jpg
  1. Search for and select the service accounts you created in Step 1.

  2. Click add -> and then click OK.

9.jpg
  1. Click Save to create the Role Group and apply the permissions. It may take a few minutes for the permissions to fully propagate across your Exchange environment.

10.jpg

Step 4. Save Credentials for Installation

You have successfully prepared your Exchange environment. Put them on an EWS on-premise sync client in your .env file.

Configuration mapping cheat sheet

Graph does not apply to on-premise Exchange. Use Provider=Ews.

Do not use EventSyncClients__*__Settings__ExchangeOnPremUrl or ExchangeOnPremDomain. Those are the old global names. On the client the keys are OnPremUrl and OnPremDomain.

Kerberos (ExchangeType=2):

EventSyncClients__0__Identifier=ews
EventSyncClients__0__Provider=Ews
EventSyncClients__0__Settings__ExchangeType=2
EventSyncClients__0__Settings__OnPremUrl=https://exchange.example.com/EWS/Exchange.asmx
EventSyncClients__0__Settings__OnPremDomain=your_domain_here
EventSyncClients__0__Settings__UserName=sendent-sync-1
EventSyncClients__0__Settings__Password=SecurePassword1!
 
EventSyncClients__1__Identifier=dav
EventSyncClients__1__Provider=Dav
EventSyncClients__1__Settings__BaseUrl=https://cloud.example.com/
EventSyncClients__1__Settings__ServiceUsername=sync-admin
EventSyncClients__1__Settings__ServicePassword=your-password
EventSyncClients__1__Settings__SharedSecret=your-shared-secret
 
EventSync__Pairs__0__SourceClientId=ews
EventSync__Pairs__0__TargetClientId=dav
EventSync__CalendarPriorityOrder__0=ews
EventSync__CalendarPriorityOrder__1=dav

Basic Auth (ExchangeType=3) uses the same client keys as Kerberos.

ADFS (ExchangeType=4) uses OnPremUrl, OnPremAdfsAuthorityUrl, ClientId, and ClientSecret instead of UserName / Password / OnPremDomain.

admins.json is optional. Use it only if you created several service accounts for throttling. The first account can stay on the client above.

Next Step

Configuring Nextcloud


Was this article helpful?