its_Tricky83 please follow the instructions here to ensure a proper TLS configuration: https://docs.microsoft.com/en-us/Exchange/exchange-tls-configuration?view=exchserver-2019
Please note: Some steps are marked as optional and so are not a hard requirement for Extended Protection. Also note that some steps are marked as OR. For example, it's not required to disable TLS 1.0 and 1.1 if you need to stay on these protocol versions. You must ensure that they are properly configured, and that the configuration is consistent on all Exchange servers within the organization.
null-null it's possible to explicitly include or exclude servers with the ExchangeServerNames and SkipExchangeServerNames parameters (see: https://microsoft.github.io/CSS-Exchange/Security/ExchangeExtendedProtectionManagement). However, it'll break server-to-server connectivity if the servers need to communicate with each other and are not ready for Extended Protection support (on an older build which doesn't support Extended Protection or Extended Protection was not configured on them). Please be careful. See Nino's comment on this: https://techcommunity.microsoft.com/t5/exchange-team-blog/released-august-2022-exchange-server-security-updates/bc-p/3598190/highlight/true#M33650
Johnny_Yao_Taiwan thanks for sharing your experience with us and the community!