Event banner
Exchange AMA
Event details
We are excited to announce an Exchange AMA on Wednesday, May 10th at 9:00 AM Pacific time!
On March 23, 2023, Microsoft announced a new transport-based enforcement system in Exchange Online that is designed to increase customer awareness of unsupported and unpatched Exchange Servers of theirs that are sending email to Exchange Online, and to drive customer action to remediate their servers. There are two possible remediations:
- A server that cannot be patched (e.g., Exchange Server 2007, Exchange Server 2010, and Exchange 2013), must be permanently decommissioned.
- Servers that can be patched (Exchange 2016 and Exchange 2019) must be updated within 90 days from detection, or mail from that server to Exchange Online will be blocked.
Join us as our experts discuss these upcoming changes to Exchange Online.
This AMA will be a live text-based online event with no audio or video component similar to an “Ask Me Anything” on Reddit. This AMA gives you the opportunity to connect with Microsoft product experts who will be on hand to answer your questions and listen to feedback.
Feel free to post your questions now through the end of the live event in the comments below; however, questions will not be answered until the live event.
102 Comments
- LuisLopes4258Copper ContributorLike Thomas Roosens, I don't have the report also. according to MS article, the first information was sent to all costumers, and later, when servers will be trigger, we'll receive another information on Message Center. When it will happen? The report being available will mark the start of the server analysis and after that we could pause the trigger?
- ScottSchnollFormer EmployeeThe report is coming soon...in a few weeks. We had targeted May 23, but we may need to push that out a few weeks.
- LuisLopes4258Copper ContributorSo, in fact, when the throttling phase will begin? is there a clear calendar for it?
- troosensBrass ContributorI don't see the report in my Exchange Admin Center. When will this become available?
- JKenersoMSFT
Microsoft
The report will be available by the end of June - and will be phased in by Exchange Server version over time - ScottSchnollFormer EmployeeFor the first wave of customers, it is expected in the next few weeks.
- cameroninokBrass ContributorWhat will be the method of notification for Exchange Admins?
- ScottSchnollFormer EmployeeIn addition to the new report in the EAC, there's also the SMTP In logs, message tracking logs, and get-queue/message.
- JKenersoMSFT
Microsoft
The primary approach will be a new report - “Connecting Server Mail Flow Report” in the Exchange admin center in Exchange Online.- cameroninokBrass ContributorSo, this is not so much of a "notification". It is actually something that an admin will have to know that they need to be going to look for?
- Mario1012Copper ContributorWhat are the criteria for unpatched Exchange servers? Are they unpatched vulnerabilities (e.g. Extended Protection not enabled) or just missing security updates?
- ScottSchnollFormer EmployeeFor Exchange 2013 and earlier, its simply based on the version (and the fact that these versions are unsupported). For Exchange 2016/2019, we will work with engineering to determine the minimum compliant build, which will in part be based on the severity of any patched vulnerabilities.
- troosensBrass ContributorWhere will documentation about these criteria be posted? How will we know when this documentation is available? Any service we can subscribe to in order to received updates on available info?
- Ken_Harrell1145Brass ContributorWhat is the time frame of first notification for Exchange 2013?
- ScottSchnollFormer EmployeeExchange 2013 customers are expected to receive notification later this year.
- Ken_Harrell1145Brass Contributor
Later this year can be tomorrow :). Is later Q4? Assuming the Exchange 2013 servers have all the latestest CUs and SUs possible.
- justinlmartinCopper Contributorwhat is the time frame for enforcing the new update policy on Exchange 2019?
- ScottSchnollFormer EmployeeExchange 2016 and Exchange 2019 won't be in scope until early next year.
- justinlmartinCopper ContributorWould this be based on the CU or the monthly security updates?
- CorneliusUysCopper ContributorDoes this mean that our Exch2010 hybrid environment will stop working (not be able to send mail to EOL)? We are in a situation where we cannot raise our AD domain functional level to AD2012R2 since we are still running AD2003 servers to facilitate our outdated broadcast environment (National Broadcaster). The projected rollout completion date of the new broadcasting software is only April 2024.
- Eriq_VanBibberBrass ContributorAs Scott as said, upgrading/patching should be a first priority when possible. I'm sure you know it already. However, if you pass your mail thru a supported gateway (or non-Microsoft gateway) first before reaching Office 365, mail should still flow properly. You might look at something like mimecast, barracuda, or similar to do some second-level security/hygiene/dlp stuff before passing to office 365. this could give you more time to complete a migration or upgrade. @scott...not trying to circumvent, but some orgs are complicated and can't move quickly. Priasoft is 20+ years of migration stuff...so i'm familiar.
- CorneliusUysCopper ContributorExcellent thank you Eric! This might just buy us the time we need. Broadcasting is our core business and mail is critical to this. Will engage our ISP tomorrow to discuss.
- ScottSchnollFormer EmployeeEventually, yes; we will block email from Exchange 2010 servers that use an inbound connector type of OnPremises. We would strongly recommend you accelerate your plans to move off these outdated and unsupported platforms.
- CorneliusUysCopper ContributorThank you Scott. What timeframe are we talking about when you say "eventually"?
- SW-SoCo2Brass Contributor
Is there any ETA for being able to view the Status Reports for recalled messages - when the sender is a Shared Mailbox?
Same question - when sending as a Delegate?
Per this post 'https://techcommunity.microsoft.com/t5/exchange-team-blog/cloud-based-message-recall-in-exchange-online/ba-p/3744714' the Message Recall function technically WORKS in these scenarios, but the Status Report can't be viewed.- ScottSchnollFormer EmployeeHi Sara, the message recall feature is not the subject of this AMA. But if you send me your questions about it at schnoll@microsoft.com, I'll do my best to find an answer for you.
- Eriq_VanBibberBrass Contributor
Will the reporting/logging information collected be accessible via powershell, in the context of the Transport blocking unpatched exchange?
- ScottSchnollFormer EmployeeSome of it, yes. The details on the reports won't be accessible via PowerShell, but other data points, such as SMTP In logs, Message Tracking logs, and cmdlets like Get-Queue and Get-Message can be used to get details about any throttling or blocking activity.
- Eriq_VanBibberBrass ContributorI'm thinking about MSPs and monitoring and auto-responses. Would there be a way to setup a chron job to check for the blocking in order to setup a custom notification system to self or customers? Does that make sense?
- Meenah_KhosrawFormer Employee
Welcome to the Exchange Ask Microsoft Anything (AMA)! This text-based live hour event gives you the opportunity to ask questions and provide feedback to the product team. Post each question in the "Comment on this event…" box above.
- ScottSchnollFormer EmployeeHi folks! Welcome to our AMA. I'm Scott Schnoll, the product marketing manager for Exchange Online and Exchange Server. Very happy to answer your questions today regarding our blog post at https://techcommunity.microsoft.com/t5/exchange-team-blog/throttling-and-blocking-email-from-persistently-vulnerable/bc-p/3817538#M36305.