dgk62 We're actively working on the archiving thing.
A-CAST Which server role is installed? If this is a pure management box (means only the Exchange Management Tools are installed and no other Exchange server role), the SU is not required. If it runs any Exchange services, patching is required. If this is an Exchange Edge Transport server, Extended Protection can't be used and therefore cannot be enabled. For any other Exchange server role, Extended Protection should be turned on.
If you run a Modern Hybrid configuration, follow the steps outlined here: https://microsoft.github.io/CSS-Exchange/Security/Extended-Protection/#extended-protection-does-not-work-with-hybrid-servers-using-modern-hybrid-configuration