
When attempting to federate a domain hosted in Exchange on premises with Exchange Online. The error message displayed below appears.

To resolve this issue TLS 1.2 needs to be enabled on the Exchange Hybrid servers.
ALI TAJRAN has a excellent ARTICLE and script to enable TLS 1.2 on Exchange servers. Once this script has run on the Exchange Hybrid servers, the wizard to add a federated domain will complete successfully.
Note: TLS 1.3 is not supported on Exchange on premises yet.