LukasSMSFT I saw you commenting to someone regarding the may updates and the prepare admin. I had contact with Nino on here who told me that, whatever the output was (at that time) when the /PrepareAllDomains run without errors it's OK.
We manage a bunch of Exchange Organizations (on premises/hybrid) and all return all green without security issues, except one. We ran the command severall times, checked AD, etc no issues what so ever. Maybe someone created some specific permission on which the script triggers that it's not completely done with that CVE. It's EX2019CU12, all fully updated, OS, etc. AD 2019 servers as well, DFL.FFL 2016.
Is that we something we can explicitly check? Like a verbose or manual check? I do remember that when we ran it for the first time, id did some AD management in the security log (managing groups etc). no errors in the AD logs and denied actions.