Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

License Error HCW8078

HCW8078: the hybrid migration endpoint could not be created by the wizard

11 min read Updated October 5, 2026 Exchange Server

Fix it now

HCW8078 means the wizard could not create the migration endpoint. Microsoft’s documented cause is throttling rather than anything in your organisation: the Graph endpoint is rate-limiting the wizard, and the underlying exception says the last connection attempt happened too recently. There are two documented fixes and neither of them involves changing your publishing.

Exchange Online PowerShell. Create the endpoint yourself rather than waiting for the wizard

New-MigrationEndpoint -Name "Hybrid Migration Endpoint" -ExchangeRemoteMove -Autodiscover -EmailAddress admin@contoso.com -Credentials (Get-Credential)
Get-MigrationEndpoint | Format-List Identity,RemoteServer,EndpointType
  1. Look in the wizard log for MigrationConnectionTestedTooRecentlyException. “The last connection attempt happened too recently” is the throttling message, and it confirms you are in the documented case.
  2. Create the migration endpoint in Exchange Online PowerShell with New-MigrationEndpoint. This is Microsoft’s first documented solution and it removes the wizard from the loop entirely.
  3. Or rerun the wizard and skip the step: choose Exchange Hybrid Configuration, select Next, then untick the Migration Endpoint option and complete the rest of the wizard.
  4. Use the second option if you have no current migration to or from Exchange Online, since the endpoint is only needed when mailboxes are actually moving.
  5. Confirm afterwards with Get-MigrationEndpoint that the endpoint exists and names the server you intended.

Do not start rebuilding publishing, certificates or firewall rules on the strength of this code alone. The documented cause is throttling of the wizard’s own requests, and the checks in the next section matter for a working endpoint rather than for this error.

If the endpoint exists and a test move starts, you are finished. If the endpoint is created and then cannot reach your server, the next section covers the things that genuinely have to be true.

Why it happens

A migration endpoint is the object Exchange Online uses to reach your on-premises servers when it moves mailboxes: the remote server name, the credentials and the endpoint type. The wizard creates it as one of its final steps, and HCW8078 is what it reports when that creation does not happen.

The reason it does not happen is the part most articles get wrong. Microsoft’s page for HCW8078 quotes the underlying error, MigrationConnectionTestedTooRecentlyException with the text “The last connection attempt happened too recently. Please wait until <time stamp> before trying to connect to an endpoint”, and gives the cause as the Graph endpoint throttling requests from the HCW application. It is a rate limit on the wizard, not a verdict on your environment.

Both documented solutions follow from that. Create the endpoint yourself with New-MigrationEndpoint in Exchange Online PowerShell, which is not subject to the wizard’s throttling. Or rerun the wizard with the Migration Endpoint option unticked, which Microsoft recommends where you have no current migration in either direction – the rest of the hybrid configuration completes and you create the endpoint later, when you actually need it.

That does not make the publishing checks irrelevant, and this is worth being precise about. An endpoint that exists still has to be able to reach your organisation when a move actually runs: the mailbox replication proxy has to be enabled on the web services directory, the external name has to resolve, and the certificate has to be one a service will accept. Those are requirements for a working migration. They are not the documented cause of HCW8078, and rebuilding them in response to this code is how a two-minute fix becomes an afternoon.

The wizard is being throttled

You have this one if The log contains MigrationConnectionTestedTooRecentlyException, or the message about the last connection attempt happening too recently.

  1. Create the endpoint in Exchange Online PowerShell with New-MigrationEndpoint, using the parameters for an Exchange remote move endpoint.
  2. Or rerun the wizard, choose Exchange Hybrid Configuration, and untick the Migration Endpoint option before continuing.
  3. Confirm the result with Get-MigrationEndpoint | Format-List Identity,RemoteServer,EndpointType.
  4. Do not keep rerunning the wizard hoping the throttle clears; that is what produced it.

Both of these are Microsoft’s own solutions for this error, in the order it lists them.

The mailbox replication proxy is not enabled

You have this one if The endpoint exists, and a move or a connectivity test cannot reach the on-premises server.

  1. Check the current state: Get-WebServicesVirtualDirectory | Format-List Server,Name,ExternalUrl,MRSProxyEnabled.
  2. Enable it on every server that will serve migrations: Set-WebServicesVirtualDirectory -Identity <identity> -MRSProxyEnabled $true.
  3. Restart the application pool serving web services, or run iisreset /noforce in a change window.
  4. Retest with Test-MigrationServerAvailability -ExchangeRemoteMove -RemoteServer mail.contoso.com -Credentials (Get-Credential).

The proxy is off by default on a freshly installed server, so a new server added to an existing hybrid organisation will not serve moves until somebody turns it on.

The certificate is not acceptable to the service

You have this one if The connection is refused during the TLS handshake, or the test reports a trust or name problem rather than a network one.

  1. Check what is installed and assigned: Get-ExchangeCertificate | Format-List Subject,CertificateDomains,NotAfter,Services.
  2. Use a certificate from a public authority covering the external web services name. A self-signed or internal certificate will not be accepted from outside.
  3. Confirm the intermediate certificates are served. A chain that resolves in a browser can still fail for a service, because the browser fills gaps that a service will not.
  4. Assign it with Enable-ExchangeCertificate -Thumbprint <thumbprint> -Services IIS and retest.

The path from outside is blocked or interfered with

You have this one if The name resolves and the certificate is fine, but the connection times out or is challenged by something that is not Exchange.

  1. Confirm 443 is open inbound to the published address and that the web services path is published, not only the mail path.
  2. Check whether a reverse proxy or firewall is pre-authenticating, inspecting TLS or requiring a client certificate on that path. Any of those breaks the connection the service makes.
  3. Check for geographic or reputation-based blocking that may be rejecting connections from the service’s addresses.
  4. Test from outside your own network, not from a machine on the LAN.

The credentials stored in the endpoint are stale

You have this one if The endpoint was created and worked, and moves now fail with an authorisation error while nothing else has changed.

  1. Remember the credentials are stored in the endpoint, so a password change breaks moves without breaking anything else.
  2. Use an account with sufficient rights over the mailboxes you intend to move, whose password is managed deliberately rather than by a user.
  3. Recreate the endpoint with New-MigrationEndpoint when the stored credentials are stale.
  4. Confirm the account is not blocked by a conditional access policy that applies to the sign-in the service performs.

Full reference

The two documented solutions, in order

Solution How When to use it
Create the endpoint yourself New-MigrationEndpoint in Exchange Online PowerShell You have a migration to run now
Skip the step in the wizard Rerun HCW, choose Exchange Hybrid Configuration, untick Migration Endpoint You have no current migration in either direction

Microsoft is explicit that the second option is the right one when there is no migration under way. The migration endpoint is not needed for mail flow, for the shared namespace or for free/busy: it exists so mailboxes can move. Configuring hybrid without it and adding it later is a supported sequence, not a compromise.

What a working endpoint still needs

Requirement How to check
MRS Proxy enabled on the web services directory Get-WebServicesVirtualDirectory | Format-List Server,Name,ExternalUrl,MRSProxyEnabled
External web services name resolves publicly A DNS query for the name from outside your network
Publicly trusted certificate covering that name Get-ExchangeCertificate | Format-List Subject,CertificateDomains,NotAfter,Services
443 open inbound to the published address A connection test from outside, not from the LAN
Credentials that still work Test-MigrationServerAvailability -ExchangeRemoteMove -RemoteServer <fqdn> -Credentials (Get-Credential)

The sibling codes in this family

Code Published by Microsoft?
HCW8078 Yes. Migration Endpoint cannot be created, caused by Graph endpoint throttling of the wizard
HCW8018 Yes. The external IP addresses on the Hybrid Configuration Active Directory object were not properly cleared during the upgrade of the hybrid configuration
HCW8056 No. Only community threads discuss it
HCW8125 No. A search of Microsoft’s documentation returns nothing

HCW8018 has a one-command fix and it is worth knowing because it appears in the same runs. Microsoft’s resolution is Get-HybridConfiguration | Set-HybridConfiguration -ExternalIPAddresses $null, followed by rerunning the wizard. It clears external IP addresses left behind on the hybrid configuration object by an upgrade, which then stop the current run from completing.

Testing a migration path honestly

  1. Enable the mailbox replication proxy on every server that will serve moves, not just the one you are looking at.
  2. Run Test-MigrationServerAvailability -ExchangeRemoteMove from Exchange Online PowerShell with the credentials the endpoint will use.
  3. Move one test mailbox before you plan a batch, and let it complete rather than judging from the first percentage.
  4. Check the move report rather than the status field when something fails, because the report names the item or the permission.
  5. Repeat the availability test after any certificate change, because that is what breaks a working endpoint most often.

Rerunning the Hybrid Configuration Wizard writes to both the on-premises organisation and the tenant. Record your current connector and organisation relationship settings before a rerun so you can tell afterwards what it changed.

When a licence is the actual fix

Nothing in the fixes above costs money. Creating the endpoint, skipping the wizard step, enabling the mailbox replication proxy and publishing a name are all changes you make yourself, and the Hybrid Configuration Wizard is free. The licensing question sits next to this problem rather than inside it: a migration endpoint exists so mailboxes can move to Exchange Online, and every mailbox that lands there needs a licence that includes an Exchange Online plan. Microsoft 365 Business Standard is the common choice for smaller organisations because it bundles the mailbox with the desktop applications, but plans differ in mailbox features, compliance capability and eligibility by organisation size, so the right answer depends on what you are actually moving. Arco supplies Microsoft 365 Business Standard and will check which plan matches the mailboxes and the features you rely on before you commit to a seat count.

Every code this article covers

Code What it points at Source
HCW8078 Migration Endpoint cannot be created. Microsoft’s documented cause is the Graph endpoint throttling requests from the wizard, surfacing as MigrationConnectionTestedTooRecentlyException Microsoft Learn
HCW8056 A wizard failure reported around connector configuration. Microsoft publishes nothing for this code; read the log line it appears on not published by the vendor
HCW8018 The external IP addresses on the Hybrid Configuration Active Directory object were not properly cleared during the upgrade of the hybrid configuration Microsoft Learn
HCW8125 A wizard failure recorded in the same run. Microsoft publishes nothing for this code not published by the vendor

Confirm the fix worked

  1. Get-MigrationEndpoint | Format-List Identity,RemoteServer,EndpointType shows the endpoint you expect.
  2. Test-MigrationServerAvailability -ExchangeRemoteMove -RemoteServer <fqdn> succeeds with the credentials the endpoint uses.
  3. Get-WebServicesVirtualDirectory | Format-List Server,MRSProxyEnabled shows the proxy enabled on every server that will serve moves.
  4. A single test mailbox move completes end to end.
  5. Rerunning the wizard afterwards finishes without HCW8078 or HCW8018.

Questions people ask about this

Do I have to fix my firewall to clear HCW8078?

Not for this code. Microsoft’s documented cause is the Graph endpoint throttling the wizard’s own requests, and the two published fixes are to create the endpoint with New-MigrationEndpoint or to rerun the wizard with the Migration Endpoint option unticked. Publishing and certificates matter for a working migration, not for this error.

Can I finish hybrid without the migration endpoint?

Yes. Microsoft recommends exactly that where you have no current migration in either direction: untick the Migration Endpoint option and complete the rest of the wizard. The endpoint is only needed when mailboxes actually move, and you can create it later.

Does the migration endpoint cost anything?

No. The endpoint is an object in Exchange Online and the wizard is free. What costs money is the licence each mailbox needs once it lands in Exchange Online.

Why did moves work last month and fail now?

Check the credentials stored in the endpoint and the certificate on the on-premises server. Both are stored or trusted at a point in time, and a password change or a certificate renewal breaks moves without breaking anything else.

What is HCW8056?

Microsoft publishes nothing for it. It appears in wizard logs around connector configuration, and the only discussion of it is community threads. Read the log line it appears on rather than the code.

Related error codes

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

License Error 550 5.7.606 banned sending IP: getting your Exchange server delisted Free Fix Event ID 2153 and Event ID 4113: DAG database redundancy checks are failing Free Fix 550 5.1.1 and 550 5.1.10: Exchange cannot find the recipient mailbox License Error Event ID 1069 and Event ID 1146: cluster faults that take a whole DAG offline
โ† Back to Knowledge Base