%3CLINGO-SUB%20id%3D%22lingo-sub-1138543%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20and%20SameSite%20Updates%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1138543%22%20slang%3D%22en-US%22%3E%3CP%3EAre%20there%20any%20details%20posted%20of%20how%20it%20will%20affect%20Exchange%202016%2F2019%20OWA%3F%20The%20additional%20information%20page%20really%20doesn't%20provide%20much%20in%20terms%20of%20what%20exactly%20will%20break.%20It's%20also%20disappointing%20that%20Microsoft%20apparently%20has%20no%20plans%20to%20offer%20a%20fix%20to%20on-premises%20customers%20prior%20to%20this%20change%20being%20implemented.%20This%20really%20is%20something%20that%20should%20have%20been%20in%20the%20December%202019%20CU.%20If%20MS%20thinks%20this%20method%20of%20support%20makes%20me%20as%20an%20admin%20want%20to%20go%20running%20to%20O365%20for%20email%2C%20it%20actually%20doesn't%20-%20quite%20the%20opposite.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1139565%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20and%20SameSite%20Updates%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1139565%22%20slang%3D%22en-US%22%3E%3CP%3EIm%20also%20not%20sure%20about%20exactly%20that%20this%20means.%20Please%20can%20you%20describe%20exactly%20what%20problems%20could%20be%20experienced%3F%20Is%20it%20that%20the%20exchange%20admin%20centre%20wont%20load%20when%20using%20Chrome%3F%20or%20could%20it%20be%20that%20OWA%20(%3CA%20href%3D%22https%3A%2F%2Foutlook.office.com%2Fmail%2Finbox%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Foutlook.office.com%2Fmail%2Finbox%3C%2FA%3E)%20will%20stop%20working%20for%20users%20that%20use%20Chrome%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20for%20any%20further%20advice.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1139884%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20and%20SameSite%20Updates%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1139884%22%20slang%3D%22en-US%22%3E%3CP%3ESame%20question.%20What%20is%20actually%20impacted%20and%20in%20what%20situations%3F%20I'm%20running%20Exchange%202013%20and%202019%20with%20ADFS%20forms%20based%20sign%20in%20(ADFS%20servers%20do%20not%20yet%20have%20January%20patches).%20But%20OWA%20and%20ECP%20load%20just%20fine%20when%20accessed%20in%20a%20browser%20configured%20to%20test%20this%20change.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhat%20is%20the%20actual%20impact%20here%3F%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1127984%22%20slang%3D%22en-US%22%3EExchange%20and%20SameSite%20Updates%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1127984%22%20slang%3D%22en-US%22%3E%3CP%20class%3D%22note%22%3EPost%20updated%3A%2031st%20January%202020%3C%2FP%3E%0A%3CP%3EThe%20Stable%20release%20of%20the%20Google%20Chrome%20web%20browser%20(build%2080%2C%20scheduled%20for%20release%20beginning%20February%2017%2C%202020)%20features%20a%20change%20in%20how%20cookies%20are%20handled.%20Although%20the%20change%20is%20intended%20to%20discourage%20malicious%20cookie%20tracking%2C%20it's%20also%20expected%20to%20severely%20affect%20many%20applications%20and%20services%20that%20are%20based%20on%20open%20standards.%3C%2FP%3E%0A%3CP%3EFor%20more%20information%2C%20see%20%3CA%20href%3D%22https%3A%2F%2Fwww.chromium.org%2Fupdates%2Fsame-site%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3ESameSite%20Updates%3C%2FA%3E%20on%20the%20Chromium%20Projects%20website.%3C%2FP%3E%0A%3CP%3EMicrosoft%20is%20committed%20to%20addressing%20this%20change%20in%20behavior%20in%20its%20products%20and%20services%20where%20possible%20before%20the%20February%2017%2C%202020%20rollout%20date%20to%20ensure%20our%20customers%20are%20minimally%20impacted.%3C%2FP%3E%0A%3CP%3EExchange%20Online%20has%20already%20rolled%20out%20changes%20necessary%20to%20support%20this%20change%20and%20we%20do%20not%20anticipate%20any%20issues.%3C%2FP%3E%0A%3CP%3EExchange%20Server%20testing%20to%20date%20has%20determined%20that%20only%20a%20few%20admin%20hybrid%20related%20scenarios%20in%20the%20Exchange%20Admin%20Center%20are%20impacted%20by%20this%20change.%20We%20have%20seen%20no%20issues%20with%20day%20to%20day%20OWA%20scenarios%20at%20this%20time%20for%20any%20current%20and%20supported%20version%20of%20the%20product.%26nbsp%3B%3C%2FP%3E%0A%3CP%3EExchange%20Server%E2%80%99s%20March%20Cumulative%20Updates%20will%20contain%20changes%20necessary%20to%20support%20this%20change.%20We%20will%20issue%20CU%E2%80%99s%20for%20Exchange%20Server%202016%20and%202019%20and%20we%20recommend%20upgrading%20to%20these%20versions%20to%20ensure%20compatibility.%20We're%20investigating%20solutions%20for%20earlier%20versions%20of%20Exchange%20Server.%3C%2FP%3E%0A%3CP%3EGiven%20the%20date%20of%20our%20scheduled%20CU%E2%80%99s%20comes%20after%20Google%20Chrome%E2%80%99s%20release%20date%20of%20February%2017%3CSUP%3Eth%3C%2FSUP%3E%20there%20might%20be%20some%20issues%20experienced%20by%20admins%20in%20hybrid%20deployments.%3C%2FP%3E%0A%3CP%3ETo%20avoid%20issues%2C%20we%20recommend%20users%20switch%20to%20an%20alternate%20browser%2C%20or%20configure%20the%20EAC%20site%2FURL%20used%20by%20admins%20to%20be%20excluded%20from%20the%20SameSite%20enforcement%20behavior%20in%20Chrome%20by%20using%20the%20%3CSTRONG%3ELegacySameSiteCookieBehaviorEnabledForDomainList%20setting%3C%2FSTRONG%3E.%3C%2FP%3E%0A%3CP%3EAdditional%20information%20can%20be%20found%20on%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Foffice365%2Ftroubleshoot%2Fmiscellaneous%2Fchrome-behavior-affects-applications%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ethis%3C%2FA%3E%20page.%3C%2FP%3E%0A%3CP%3E%3CFONT%20color%3D%22%23ff6600%22%3EThe%20Exchange%20Team%3C%2FFONT%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-1127984%22%20slang%3D%22en-US%22%3E%3CP%3EThe%20Stable%20release%20of%20the%20Google%20Chrome%20web%20browser%20scheduled%20for%20release%20beginning%20February%2017%2C%202020%20features%20a%20change%20in%20how%20cookies%20are%20handled.%20Microsoft%20is%20committed%20to%20addressing%20this%20change%20in%20behavior%20in%20its%20products%20and%20services%20before%20the%20February%204%2C%202020%20rollout%20date%20to%20ensure%20our%20customers%20are%20minimally%20impacted.%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1127984%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAnnouncements%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EExchange%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EExchange%20Online%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Emicrosoft%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOn%20Premises%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOWA%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1148471%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20and%20SameSite%20Updates%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1148471%22%20slang%3D%22en-US%22%3E%3CP%3ELooks%20like%20this%20was%20updated%20with%20info%20for%20on%20premises%20customers%20-%20thanks.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1158121%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20and%20SameSite%20Updates%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1158121%22%20slang%3D%22en-US%22%3E%3CP%3EWhat%20about%20Exchange%202013%3F%20Is%20it%20affected%2C%20and%20if%20yes%2C%20how%20this%20will%20be%20handled%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E

Post updated: 31st January 2020

The Stable release of the Google Chrome web browser (build 80, scheduled for release beginning February 17, 2020) features a change in how cookies are handled. Although the change is intended to discourage malicious cookie tracking, it's also expected to severely affect many applications and services that are based on open standards.

For more information, see SameSite Updates on the Chromium Projects website.

Microsoft is committed to addressing this change in behavior in its products and services where possible before the February 17, 2020 rollout date to ensure our customers are minimally impacted.

Exchange Online has already rolled out changes necessary to support this change and we do not anticipate any issues.

Exchange Server testing to date has determined that only a few admin hybrid related scenarios in the Exchange Admin Center are impacted by this change. We have seen no issues with day to day OWA scenarios at this time for any current and supported version of the product. 

Exchange Server’s March Cumulative Updates will contain changes necessary to support this change. We will issue CU’s for Exchange Server 2016 and 2019 and we recommend upgrading to these versions to ensure compatibility. We're investigating solutions for earlier versions of Exchange Server.

Given the date of our scheduled CU’s comes after Google Chrome’s release date of February 17th there might be some issues experienced by admins in hybrid deployments.

To avoid issues, we recommend users switch to an alternate browser, or configure the EAC site/URL used by admins to be excluded from the SameSite enforcement behavior in Chrome by using the LegacySameSiteCookieBehaviorEnabledForDomainList setting.

Additional information can be found on this page.

The Exchange Team

2 Comments
Visitor

Looks like this was updated with info for on premises customers - thanks.

Occasional Visitor

What about Exchange 2013? Is it affected, and if yes, how this will be handled?