<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Exchange Team Blog articles</title>
    <link>https://techcommunity.microsoft.com/t5/exchange-team-blog/bg-p/Exchange</link>
    <description>Exchange Team Blog articles</description>
    <pubDate>Sat, 25 Jul 2026 17:22:56 GMT</pubDate>
    <dc:creator>Exchange</dc:creator>
    <dc:date>2026-07-25T17:22:56Z</dc:date>
    <item>
      <title>Reminder: Exchange 2016 and 2019 ESU Program Ends in October 2026</title>
      <link>https://techcommunity.microsoft.com/t5/exchange-team-blog/reminder-exchange-2016-and-2019-esu-program-ends-in-october-2026/ba-p/4539033</link>
      <description>&lt;P&gt;Over the last several weeks we have received several questions about possible extension of the Exchange Server 2016/2019 ESU program past October 2026. After all, in our &lt;A href="https://techcommunity.microsoft.com/blog/exchange/announcing-exchange-2016--2019-extended-security-update-program/4433495" target="_blank"&gt;original Exchange 2016/2019 ESU announcement&lt;/A&gt; we said that there would be no extensions, but then we ended up creating a &lt;A href="https://techcommunity.microsoft.com/blog/exchange/announcing-period-2-exchange-20162019-extended-security-update-esu-program/4511603" target="_blank"&gt;Period 2 Exchange ESU program&lt;/A&gt; that is scheduled to end with October 2026. We are just about at the mid-point of Period 2 Exchange ESU now.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;There will be no further extension of Exchange 2016/2019 ESU program timeline. &lt;/STRONG&gt;Once October 2026 ends, there will be no further updates for Exchange 2016/2019, even if you currently have a Period 2 ESU.&lt;/P&gt;
&lt;P&gt;If your organization still uses Exchange 2016 or 2019 in production:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;See &lt;A href="https://techcommunity.microsoft.com/blog/exchange/upgrading-your-organization-from-current-versions-to-exchange-server-se/4241305" target="_blank"&gt;Upgrading your organization from current versions to Exchange Server SE | Microsoft Community Hub&lt;/A&gt; – which lays out the path for how to migrate to Exchange SE if you plan to keep Exchange on-premises.&lt;/LI&gt;
&lt;LI&gt;&lt;A style="font-style: normal; font-weight: 400; background-color: rgb(255, 255, 255);" href="https://techcommunity.microsoft.com/blog/exchange/why-%E2%80%9Cin-place-upgrade%E2%80%9D-from-exchange-2019-to-exchange-se-is-low-risk/4410173" target="_blank"&gt;Why “in-place upgrade” from Exchange 2019 to Exchange SE is low risk | Microsoft Community Hub&lt;/A&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt; – which explains why in-place upgrade from Exchange 2019 CU14/CU15 to Exchange SE RTM is not a significant technological change and is low risk.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Please review &lt;A href="https://www.microsoft.com/en-us/microsoft-365/exchange/microsoft-exchange-licensing-faq-email-for-business" target="_blank"&gt;Microsoft Exchange Online and Exchange Server Licensing FAQs&lt;/A&gt; especially "What is Exchange Server Subscription Edition (SE) and how is it licensed?” section. Exchange 2019 and Exchange SE licensing requirements are the same.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-12"&gt;The Exchange Server Team&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2026 18:10:45 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/exchange-team-blog/reminder-exchange-2016-and-2019-esu-program-ends-in-october-2026/ba-p/4539033</guid>
      <dc:creator>The_Exchange_Team</dc:creator>
      <dc:date>2026-07-20T18:10:45Z</dc:date>
    </item>
    <item>
      <title>Released: July 2026 Exchange Server Security Updates</title>
      <link>https://techcommunity.microsoft.com/t5/exchange-team-blog/released-july-2026-exchange-server-security-updates/ba-p/4534146</link>
      <description>&lt;P&gt;Microsoft has released Security Updates (SUs) for vulnerabilities found in:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Exchange Server Subscription Edition (SE)&lt;/LI&gt;
&lt;LI&gt;Exchange Server 2019&lt;/LI&gt;
&lt;LI&gt;Exchange Server 2016&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;SUs are available for the following specific versions of Exchange Server:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://www.microsoft.com/en-us/download/details.aspx?id=108746" target="_blank" rel="noopener"&gt;Exchange SE RTM&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Exchange Server 2019&amp;nbsp;CU14&amp;nbsp;and&amp;nbsp;CU15 (to access, organization must be enrolled into the &lt;A href="https://techcommunity.microsoft.com/blog/exchange/announcing-period-2-exchange-20162019-extended-security-update-esu-program/4511603" target="_blank" rel="noopener"&gt;Period 2 ESU program&lt;/A&gt;)&lt;/LI&gt;
&lt;LI&gt;Exchange Server 2016&amp;nbsp;CU23 (to access, organization must be enrolled into the &lt;A href="https://techcommunity.microsoft.com/blog/exchange/announcing-period-2-exchange-20162019-extended-security-update-esu-program/4511603" target="_blank" rel="noopener"&gt;Period 2 ESU program&lt;/A&gt;)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The July 2026 SUs address vulnerabilities responsibly reported to Microsoft by security partners and found through Microsoft’s internal processes.&lt;/P&gt;
&lt;P&gt;These vulnerabilities affect Exchange Server. Exchange Online customers are already protected from the vulnerabilities addressed by these SUs and do not need to take any action other than updating any Exchange servers or Exchange Management tools workstations in their environment.&lt;/P&gt;
&lt;P&gt;More details about specific CVEs can be found in the&amp;nbsp;&lt;A href="https://msrc.microsoft.com/update-guide/" target="_blank" rel="noopener"&gt;Security Update Guide&lt;/A&gt;&amp;nbsp;(filter on ‘Server Software’ under Product Family for Exchange SE and ‘ESU’ under Product Family for Exchange 2016 and 2019).&lt;/P&gt;
&lt;H3&gt;Check for presence of legacy Exchange security groups&lt;/H3&gt;
&lt;P&gt;While not directly related to our July 2026 SU release, we wanted to call out that &lt;A href="https://aka.ms/ExchangeHealthChecker" target="_blank" rel="noopener"&gt;Exchange Health Checker script&lt;/A&gt; will now also check for the presence of very old, deprecated Exchange Server security groups, namely &lt;STRONG&gt;Exchange Domain Servers&lt;/STRONG&gt; and &lt;STRONG&gt;Exchange Enterprise Servers&lt;/STRONG&gt;. Those groups have been deprecated since Exchange 2007, should not be in use, and should be deleted as they might provide more permissions than modern Exchange security groups. Please see related documentation &lt;A href="https://learn.microsoft.com/en-us/previous-versions/office/exchange-server-2010/gg576862(v=exchg.141)" target="_blank" rel="noopener"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Customers who have removed last on-premises Exchange Server from their organizations should also check for the presence of those groups and delete them to help prevent their possible abuse. Note that if you no longer have any Exchange servers on premises, you might want to perform a more comprehensive Active Directory cleanup as per &lt;A href="https://learn.microsoft.com/en-us/exchange/manage-hybrid-exchange-recipients-with-management-tools#active-directory-clean-up" target="_blank" rel="noopener"&gt;this article&lt;/A&gt;.&lt;/P&gt;
&lt;H3&gt;Remove CVE-2026-42897 mitigations after installation&lt;/H3&gt;
&lt;P&gt;Installing the July 2026 update &lt;EM&gt;does not&lt;/EM&gt; automatically remove already applied CVE-2026-42897 mitigations. Therefore, once you install July SU, you should:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;If mitigation was applied using Exchange Emergency Mitigation (EM) Service:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/Exchange/plan-and-deploy/post-installation-tasks/security-best-practices/exchange-emergency-mitigation-service#rollback-procedures-for-released-mitigations" target="_blank" rel="noopener"&gt;Remove the mitigation M2.1.0 IIS rules&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;If mitigation was applied using the downloadable EOMT script &lt;/STRONG&gt;&lt;A href="https://aka.ms/UnifiedEOMT" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;https://aka.ms/UnifiedEOMT&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;: &lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://microsoft.github.io/CSS-Exchange/Security/EOMT/#roll-back-a-mitigation" target="_blank" rel="noopener"&gt;Roll back the mitigation&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Exchange 2016 and 2019 updates are available &lt;EM&gt;only&lt;/EM&gt; under the Period 2 ESU program&lt;/H3&gt;
&lt;P&gt;Exchange Server 2016 and 2019 are &lt;A href="https://techcommunity.microsoft.com/blog/exchange/support-for-exchange-server-2016-and-exchange-server-2019-ends-today/4461192" target="_blank" rel="noopener"&gt;out of support&lt;/A&gt;. Only customers who enrolled in the &lt;A href="https://techcommunity.microsoft.com/blog/exchange/announcing-period-2-exchange-20162019-extended-security-update-esu-program/4511603" target="_blank" rel="noopener"&gt;Period 2 Extended Security Update (ESU) program&lt;/A&gt; are eligible to receive Exchange Server 2016 and 2019 security updates released between May and October 2026.&lt;/P&gt;
&lt;P&gt;If you are not part of the Period 2 ESU program, &lt;A href="https://techcommunity.microsoft.com/blog/exchange/upgrading-your-organization-from-current-versions-to-exchange-server-se/4241305" target="_blank" rel="noopener"&gt;migrate to Exchange Server Subscription Edition (SE)&lt;/A&gt; to keep receiving the latest security updates.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;If you have already purchased the Period 2 ESU&lt;/EM&gt; and need information on accessing the latest Security Updates, please contact us by sending an email to &lt;A href="mailto:ExchangeandSfBServerESUInquiry@service.microsoft.com?subject=We%20purchased%20Exchange%20ESU%20need%20access" target="_blank" rel="noopener"&gt;ExchangeandSfBServerESUInquiry@service.microsoft.com&lt;/A&gt;.&lt;/P&gt;
&lt;H3&gt;Known issues with this release&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://support.microsoft.com/en-us/servicing/exchange/server/hotfix/2026/5105719" target="_blank" rel="noopener"&gt;Wrapper messages appear in shared mailbox inbox in hybrid environments | Microsoft Support&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Update installation&lt;/H3&gt;
&lt;P&gt;The following update paths are available:&lt;/P&gt;
&lt;img /&gt;
&lt;UL&gt;
&lt;LI&gt;Inventory your Exchange Servers to determine which updates are needed using the &lt;A href="https://aka.ms/ExchangeHealthChecker" target="_blank" rel="noopener"&gt;Exchange Server Health Checker script&lt;/A&gt;. Running this script will tell you if any of your Exchange Servers are behind on updates (CUs, SUs, or manual actions).&lt;/LI&gt;
&lt;LI&gt;Install the latest CU. Use the &lt;A href="https://aka.ms/ExchangeUpdateWizard" target="_blank" rel="noopener"&gt;Exchange Update Wizard&lt;/A&gt; to choose your current CU and your target CU to get directions.&lt;/LI&gt;
&lt;LI&gt;Re-run the Health Checker after you install an update to see if any further actions are needed.&lt;/LI&gt;
&lt;LI&gt;After setup is completed, please reboot the server and check that all Exchange services have started properly. If some services are in a disabled state, that indicates that something interrupted installation of the update. Please see the Workaround 1 in &lt;A href="https://support.microsoft.com/en-us/topic/file-version-error-when-you-try-to-install-exchange-server-november-2024-su-a650da30-f8fb-469d-a449-47396cab0a15" target="_blank" rel="noopener"&gt;this article&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;If you encounter errors during or after installation of Exchange Server, run the &lt;A href="https://aka.ms/ExSetupAssist" target="_blank" rel="noopener"&gt;SetupAssist script&lt;/A&gt;. If something does not work properly after updates, see &lt;A href="https://aka.ms/ExchangeFAQ" target="_blank" rel="noopener"&gt;Repair failed installations of Exchange Cumulative and Security updates&lt;/A&gt;. Also please see &lt;A href="https://support.microsoft.com/topic/file-version-error-when-you-try-to-install-exchange-server-november-2024-su-a650da30-f8fb-469d-a449-47396cab0a15" target="_blank" rel="noopener"&gt;File version error when you try to install Exchange Server updates&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H1&gt;FAQs&lt;/H1&gt;
&lt;P&gt;&lt;STRONG&gt;When CVE-2026-42897 mitigation was released, there were several reported known issues. Are those addressed in this update?&lt;BR /&gt;&lt;/STRONG&gt;Yes, when July 2026 SU is installed &lt;U&gt;and mitigation is removed&lt;/U&gt;, mitigation known issues should be resolved too.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;If we update some of our servers but cannot update others, can servers that will not receive update stay with CVE-2026-42897 mitigations? Is it OK to have some servers updated and some still using mitigations?&lt;/STRONG&gt;&lt;BR /&gt;You can continue using mitigations on any servers that you cannot update to July 2026 SU (or newer). But note that known issues from mitigations will continue to apply to those servers. Additionally, after applying this update, Office Online Server (OOS) integration with Exchange Server might not function as expected until all Exchange servers in the organization have been updated.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Our organization is in Hybrid mode with Exchange Online. Do we need to do anything?&lt;/STRONG&gt;&lt;BR /&gt;Exchange Online is already protected, but this SU needs to be installed on your Exchange servers, even if they are used only for management purposes. If you change the auth certificate after installing an SU, you should re-run the Hybrid Configuration Wizard.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;The last SU/HU we installed is a few months old. Do we need to install all SUs in order to install the latest one?&lt;/STRONG&gt;&lt;BR /&gt;SUs are cumulative. If you are running a CU supported by the SU, you do not need to install all SUs or HUs in sequential order; simply install the latest SU. Please see&amp;nbsp;&lt;A href="https://techcommunity.microsoft.com/t5/exchange-team-blog/why-exchange-server-updates-matter/ba-p/2280770" target="_blank" rel="noopener"&gt;this blog post&lt;/A&gt;&amp;nbsp;for more information.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Do we need to install SUs on all Exchange Servers within our organization? What about ‘Management Tools only’&amp;nbsp;machines?&lt;/STRONG&gt;&lt;BR /&gt;Our recommendation is to install SUs on&amp;nbsp;&lt;U&gt;all&lt;/U&gt;&amp;nbsp;Exchange Servers and all servers and workstations running the Exchange Management Tools to ensure compatibility between management tools clients and servers. If you are trying to update the Exchange Management Tools in the environment with no running Exchange servers, please see&amp;nbsp;&lt;A href="https://learn.microsoft.com/exchange/manage-hybrid-exchange-recipients-with-management-tools#update-the-exchange-server-management-tools-only-role-with-no-running-exchange-server-to-a-newer-cumulative-or-security-update" target="_blank" rel="noopener"&gt;this&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Our organization does not have the Exchange 2016 and 2019 Period 2 ESU. How can we get current Exchange 2016 or 2019 updates?&lt;/STRONG&gt;&lt;BR /&gt;Since Exchange 2016 and 2019 are now &lt;A href="https://techcommunity.microsoft.com/blog/exchange/support-for-exchange-server-2016-and-exchange-server-2019-ends-today/4461192" target="_blank" rel="noopener"&gt;out of support&lt;/A&gt;, only customers who have enrolled into the &lt;A href="https://techcommunity.microsoft.com/blog/exchange/announcing-period-2-exchange-20162019-extended-security-update-esu-program/4511603" target="_blank" rel="noopener"&gt;Period 2 ESU program&lt;/A&gt; (which is valid between May and October 2026) can obtain Exchange 2016 or 2019 updates released after May 2026. For all other customers still running Exchange 2016 or 2019, we recommend that you &lt;A href="https://techcommunity.microsoft.com/blog/exchange/upgrading-your-organization-from-current-versions-to-exchange-server-se/4241305" target="_blank" rel="noopener"&gt;upgrade your organization to Exchange SE&lt;/A&gt; as soon as possible.&lt;/P&gt;
&lt;P style="background: #F0F0F0; padding: .5em; margin: 1em 0 1em 0;"&gt;Documentation may not be fully available at the time this post is published.&lt;/P&gt;
&lt;P&gt;This post might receive future updates; they will be listed here (if available).&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-12"&gt;The Exchange Server Team&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jul 2026 18:41:35 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/exchange-team-blog/released-july-2026-exchange-server-security-updates/ba-p/4534146</guid>
      <dc:creator>The_Exchange_Team</dc:creator>
      <dc:date>2026-07-24T18:41:35Z</dc:date>
    </item>
    <item>
      <title>Cross-Tenant Message Recall in Exchange Online</title>
      <link>https://techcommunity.microsoft.com/t5/exchange-team-blog/cross-tenant-message-recall-in-exchange-online/ba-p/4535800</link>
      <description>&lt;P&gt;Since we released cloud-based Message Recall in April 2023 (see &lt;A href="https://techcommunity.microsoft.com/t5/exchange-team-blog/cloud-based-message-recall-in-exchange-online/ba-p/3744714" target="_blank"&gt;Cloud-based Message Recall in Exchange Online&lt;/A&gt;), we’ve continued to expand where and how recall works – including &amp;nbsp;support for Outlook on the web and mobile, recipient recall notifications, a maximum recallable message age, and support for external round-trip routing (see &lt;A href="https://techcommunity.microsoft.com/blog/exchange/exchange-online-message-recall-updates/4226568" target="_blank"&gt;Exchange Online Message Recall Updates&lt;/A&gt;).&lt;/P&gt;
&lt;P&gt;Until now, all these capabilities shared one boundary: Message Recall only worked within a single tenant. Today, we’re pleased to announce one of our most requested cross-organization enhancements:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Cross-Tenant Message Recall, controlled by a tenant admin allow list&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;The intra-tenant boundary&lt;/H3&gt;
&lt;P&gt;By design due to privacy concerns, Message Recall operates within the Exchange Online service boundary, and until now it has been limited to intra-tenant messages – those where the sender and the recipients belong to the same Microsoft 365 tenant. When a sender tried to recall a message they had sent to recipients in a different tenant, the recall would fail, even between organizations that work closely together and trust one another.&lt;/P&gt;
&lt;P&gt;Customers told us this was a gap. Partners, subsidiaries, and affiliated organizations that collaborate daily across tenant boundaries wanted the same recall experience they already had inside their own tenant.&lt;/P&gt;
&lt;H3&gt;Introducing cross-tenant Message Recall&lt;/H3&gt;
&lt;P&gt;With Cross-Tenant Message Recall, a tenant admin can add other Microsoft 365 tenants to an allow list. Once a tenant is on the list, senders from those allow-listed tenants can recall messages they’ve sent to recipients in the receiving tenant – just as they would for an intra-tenant recall.&lt;/P&gt;
&lt;P&gt;Control sits with the &lt;STRONG&gt;receiving tenant&lt;/STRONG&gt; – the organization whose users received the messages. A cross-tenant recall is only honored when the receiving tenant’s admin has explicitly allow-listed the sender’s tenant. This keeps the receiving organization in full control of which external tenants are permitted to recall messages from its users’ mailboxes. The feature is disabled by default; no cross-tenant recall occurs until an admin adds at least one tenant to the allow list.&lt;/P&gt;
&lt;H3&gt;How it works&lt;/H3&gt;
&lt;P&gt;Consider two organizations that work together, Contoso and Fabrikam, both of whom are hosted in Microsoft 365:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;A Contoso admin adds Fabrikam’s tenant to Contoso’s cross-tenant recall allow list.&lt;/LI&gt;
&lt;LI&gt;A sender at Fabrikam recalls a message they previously sent to a recipient at Contoso.&lt;/LI&gt;
&lt;LI&gt;Because Contoso has allow-listed Fabrikam, the recall is honored and processed like a standard recall against the Contoso recipient’s mailbox.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;If Fabrikam is &lt;EM&gt;not&lt;/EM&gt; on Contoso’s allow list, the recall fails and the Fabrikam sender will see in the recall status report that the message can’t be recalled across organizations. Allow-listing governs inbound recalls into the receiving tenant, so each organization decides independently which external tenants it trusts to recall messages from its mailboxes.&lt;/P&gt;
&lt;H2&gt;Configuring with Exchange Online PowerShell&lt;/H2&gt;
&lt;P&gt;Admins can configure these settings using Exchange Online PowerShell.&lt;/P&gt;
&lt;P&gt;Enable or disable cross-tenant message recall for the tenant. Setting this parameter to $True turns on the capability; $False (default) turns it off:&lt;/P&gt;
&lt;PRE class="lia-indent-padding-left-30px"&gt;Set-CrossTenantRecallConfiguration -CrossTenantRecallEnabled [$true | $false]&lt;/PRE&gt;
&lt;P&gt;Specify external tenants to add or remove from the allowed list. Add the tenant IDs of the organizations you trust to perform recalls:&lt;/P&gt;
&lt;PRE class="lia-indent-padding-left-30px"&gt;Set-CrossTenantRecallConfiguration -AllowedSenderTenantIds @{Add="&amp;lt;tenantId 1&amp;gt;","&amp;lt;tenantId 2&amp;gt;"}; {Remove="&amp;lt;tenantId 1&amp;gt;","&amp;lt;tenantId 2&amp;gt;"}&amp;nbsp;&lt;/PRE&gt;
&lt;H3&gt;What senders and recipients see&lt;/H3&gt;
&lt;P&gt;When a sender in an allow-listed tenant recalls a message, recipients in the receiving tenant experience the recall exactly as they would an intra-tenant recall. If the receiving tenant has enabled recipient recall notifications, those notifications apply to cross-tenant recalls as well. If the sender’s tenant is not on the receiving tenant’s allow list, the sender receives a notification that the message can’t be recalled across organizations.&lt;/P&gt;
&lt;H3&gt;Availability&lt;/H3&gt;
&lt;P&gt;Cross-Tenant Message Recall will start to deploy to worldwide, GCC, GCC High, DoD and Microsoft 365 operated by 21Vianet starting mid-August, completing by mid-September. We hope you’ll find this enhancement useful, and we look forward to your feedback.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-12"&gt;Microsoft 365 Messaging Team&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jul 2026 15:38:58 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/exchange-team-blog/cross-tenant-message-recall-in-exchange-online/ba-p/4535800</guid>
      <dc:creator>The_Exchange_Team</dc:creator>
      <dc:date>2026-07-10T15:38:58Z</dc:date>
    </item>
    <item>
      <title>Upcoming retirement of OWA Light in Exchange Server</title>
      <link>https://techcommunity.microsoft.com/t5/exchange-team-blog/upcoming-retirement-of-owa-light-in-exchange-server/ba-p/4534943</link>
      <description>&lt;P&gt;We are announcing our plan to retire and disable the OWA Light experience in Exchange Server in a future update. OWA Light was created for a much earlier era of the web, when browser support, bandwidth, and accessibility technologies were very different from today. Going forward, we want to invest in modern Outlook on the web experience that provides the cross-browser, accessible, and security-focused experience.&lt;/P&gt;
&lt;P&gt;Organizations that still rely on OWA Light must move users to the standard Outlook on the web experience and review any internal guidance, bookmarks, training material, helpdesk scripts, or accessibility workflows that reference OWA Light.&lt;/P&gt;
&lt;P&gt;This is how OWA Light looks like:&lt;/P&gt;
&lt;img /&gt;
&lt;H3&gt;What is changing&lt;/H3&gt;
&lt;P&gt;In an upcoming Exchange Server update (estimated in August 2026), we plan to disable and remove the OWA Light experience. After that change is introduced, users will no longer be able to choose or be redirected to OWA Light and should use the modern Outlook on the web experience instead.&lt;/P&gt;
&lt;P&gt;This announcement applies to Exchange Server (on-premises). We announced &lt;A href="https://support.microsoft.com/en-us/outlook/learn-more-about-the-light-version-of-outlook" target="_blank"&gt;deprecation of OWA Light in August 2024&lt;/A&gt;.&lt;/P&gt;
&lt;H3&gt;Why we are making this change&lt;/H3&gt;
&lt;P&gt;OWA Light served customers well for many years. It was designed for older browsers, slower connections, and scenarios where a simplified web interface helped users access mail in environments that could not support the full Outlook Web App experience.&lt;/P&gt;
&lt;P&gt;The web has changed significantly since OWA Light was introduced. Modern browsers are more capable and more consistent, network conditions have improved for many customers, and security landscape has changed significantly. Maintaining a separate legacy OWA Light experience increases complexity. Each additional content rendering path, control surface, and compatibility layer must be evaluated as we strengthen defenses against modern web threats.&lt;/P&gt;
&lt;P&gt;We recommend that Exchange Server administrators use this time to identify and prepare any users, processes, or documentation that still depend on OWA Light.&lt;/P&gt;
&lt;P&gt;To block OWA Light right away, you can create or update an existing OWA mailbox policy:&lt;/P&gt;
&lt;PRE&gt;Set-OwaMailboxPolicy -OwaLightEnabled $false&lt;/PRE&gt;
&lt;P&gt;Make sure that the OwaMailboxPolicy is assigned to all mailboxes. You can assign a OwaMailboxPolicy by using the &lt;STRONG&gt;Set-CasMailbox -OwaMailboxPolicy &amp;lt;Name&amp;gt;&lt;/STRONG&gt; cmdlet.&lt;/P&gt;
&lt;P&gt;Additionally, disable the OWA Light selection menu on the OWA logon page. You can do that by running:&lt;/P&gt;
&lt;PRE&gt;Set-OwaVirtualDirectory -LogonPageLightSelectionEnabled $false&lt;/PRE&gt;
&lt;P&gt;More information can be found in the &lt;A href="https://learn.microsoft.com/powershell/module/exchangepowershell/set-owamailboxpolicy?view=exchange-ps" target="_blank"&gt;Set-OwaMailboxPolicy&lt;/A&gt; &amp;nbsp;and &lt;A href="https://learn.microsoft.com/en-us/powershell/module/exchangepowershell/set-owavirtualdirectory" target="_blank"&gt;Set-OwaVirtualDirectory&lt;/A&gt; documentation.&lt;/P&gt;
&lt;H3&gt;Summary&lt;/H3&gt;
&lt;P&gt;OWA Light was an important compatibility experience when the web needed it. Today, the full Outlook on the web experience is the right place for us to focus. Retiring OWA Light will help reduce legacy surface area, simplify ongoing engineering work, and allow us to continue improving the experience customers use every day.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-12"&gt;The Exchange Server team&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jul 2026 13:08:33 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/exchange-team-blog/upcoming-retirement-of-owa-light-in-exchange-server/ba-p/4534943</guid>
      <dc:creator>The_Exchange_Team</dc:creator>
      <dc:date>2026-07-08T13:08:33Z</dc:date>
    </item>
    <item>
      <title>Introducing EWSAllowedAppIDs: Preparing for the Final Phase of EWS Retirement</title>
      <link>https://techcommunity.microsoft.com/t5/exchange-team-blog/introducing-ewsallowedappids-preparing-for-the-final-phase-of/ba-p/4529471</link>
      <description>&lt;P&gt;Exchange Web Services (EWS) retirement in Exchange Online is entering its final phase. Over the last several years, Microsoft has worked with product teams, independent software vendors (ISVs), and customers across the ecosystem to migrate workloads to Microsoft Graph and other modern APIs. Many of those migrations are complete, and many others are well underway.&lt;/P&gt;
&lt;P&gt;As phased EWS disablement in Exchange Online approaches in October 2026, we are introducing a new capability to help administrators prepare in a controlled and predictable way: &lt;STRONG&gt;EWSAllowedAppIDs&lt;/STRONG&gt;. This is the Allow List functionality that we mentioned in &lt;A href="https://techcommunity.microsoft.com/blog/exchange/exchange-online-ews-your-time-is-almost-up/4492361" target="_blank" rel="noopener"&gt;Exchange Online EWS, Your Time is Almost Up | Microsoft Community Hub&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;EWSAllowedAppIDs gives administrators a practical way to identify remaining dependencies, limit EWS access to approved applications, and reduce the risk of disruption as retirement enforcement begins.&lt;/P&gt;
&lt;P&gt;This feature is starting to roll out now. All tenants should be able to view the parameter when running Get-OrganizationConfig, but they won’t be able to set the list until the roll out reaches the tenant.&lt;/P&gt;
&lt;H3&gt;What is EWSAllowedAppIDs?&lt;/H3&gt;
&lt;P&gt;EWSAllowedAppIDs is a tenant-level allow list that lets Exchange Online administrators explicitly define which applications are still permitted to access EWS, based on their App ID.&lt;/P&gt;
&lt;P&gt;When configured, only applications whose App IDs appear in the allow list can continue using EWS in the tenant when EWSEnabled at the tenant level is set to True.&lt;/P&gt;
&lt;P&gt;This feature is designed to support the final transition away from broad, unrestricted EWS access and toward tightly scoped, intentional usage during the retirement window.&lt;/P&gt;
&lt;P&gt;Note: The EWSAllowList feature Exchange has had for many years is based on &lt;EM&gt;User Agent&lt;/EM&gt;, &lt;EM&gt;not App ID (and it applies to REST/Graph not just EWS by the way)&lt;/EM&gt;. Both can work together, but they operate on different aspects of the calling application.&lt;/P&gt;
&lt;P&gt;Administrators can use the feature to:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Identify which applications still require EWS&lt;/LI&gt;
&lt;LI&gt;Restrict EWS access to only approved applications&lt;/LI&gt;
&lt;LI&gt;Prepare for the final retirement of EWS in Exchange Online&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;How EWSAllowedAppIDs fits into the EWS endgame&lt;/H3&gt;
&lt;P&gt;We &lt;A href="https://techcommunity.microsoft.com/blog/exchange/exchange-online-ews-your-time-is-almost-up/4492361" target="_blank" rel="noopener"&gt;previously announced&lt;/A&gt; that phased EWS disablement in Exchange Online will begin in October 2026.&lt;/P&gt;
&lt;P&gt;To understand why EWSAllowedAppIDs matters, it helps to look at how Exchange Online behavior changes before and after that date. The retirement model uses the existing EWSEnabled organization-level setting together with the new EWSAllowedAppIDs allow list. (Refresh yourself on how the EWSEnabled switch works and how to set it &lt;A href="https://techcommunity.microsoft.com/blog/exchange/exchange-online-ews-your-time-is-almost-up/4492361" target="_blank" rel="noopener"&gt;here&lt;/A&gt;)&lt;/P&gt;
&lt;P&gt;Before October 2026, the behavior is intentionally permissive to give customers time to inventory dependencies, deploy an allow list, and validate which applications still require EWS.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Before October 2026&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;&lt;STRONG&gt;EWSEnabled Value&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;&lt;STRONG&gt;Allow List State&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;&lt;STRONG&gt;Behavior&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;&lt;STRONG&gt;Null (default)&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;Ignored&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;All EWS traffic allowed&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;&lt;STRONG&gt;True&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;Empty&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;All EWS traffic allowed&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;&lt;STRONG&gt;True&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;Populated&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;Only listed applications allowed&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;&lt;STRONG&gt;False&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;All EWS traffic blocked&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;This pre-October phase gives administrators room to deploy and test an allow list without immediately breaking existing applications.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What changes in October 2026&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Beginning in October 2026, Exchange Online starts transitioning tenants into retirement enforcement behavior.&lt;/P&gt;
&lt;P&gt;At that point, enabling EWS without configuring an allow list will no longer act as an unrestricted “allow everything” mode.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Starting October 2026&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 74.6296%; border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;&lt;STRONG&gt;EWSEnabled Value&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;&lt;STRONG&gt;Allow List State&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;&lt;STRONG&gt;Behavior&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;&lt;STRONG&gt;Null&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;Ignored&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;All EWS allowed (but tenant will have EWSEnabled set to False at some point as part of phased rollout by Microsoft)&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;&lt;STRONG&gt;True&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;Empty&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-8"&gt;All EWS traffic blocked&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;&lt;STRONG&gt;True&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;Populated&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;Only listed applications allowed&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;&lt;STRONG&gt;False&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;All EWS traffic blocked&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 20.6211%" /&gt;&lt;col style="width: 18.7578%" /&gt;&lt;col style="width: 60.4969%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;This is the most important behavioral change administrators need to understand: after enforcement begins, &lt;EM&gt;setting EWSEnabled=True without an allow list effectively becomes a block-all configuration&lt;/EM&gt;.&lt;/P&gt;
&lt;P&gt;This change is intentional. The goal is not to keep EWS available indefinitely, but to require explicit acknowledgement that EWS is still needed and to scope that usage down to known, approved applications.&lt;/P&gt;
&lt;P&gt;The goal of the retirement process is not simply to keep EWS “on” indefinitely, but to:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Force explicit acknowledgement that EWS is still required&lt;/LI&gt;
&lt;LI&gt;Scope usage down to known, approved applications&lt;/LI&gt;
&lt;LI&gt;Accelerate migration to Microsoft Graph and modern APIs&lt;/LI&gt;
&lt;/OL&gt;
&lt;H2&gt;What happens if a tenant admin does nothing?&lt;/H2&gt;
&lt;P&gt;Today, many tenants still have EWSEnabled unset (Null), which behaves as unrestricted access.&lt;/P&gt;
&lt;P&gt;As the phased retirement rollout starts in October 2026, those tenants will have EWS disabled (EWSEnabled set to False) as part of the staged shutdown process.&lt;/P&gt;
&lt;P&gt;Administrators who still require EWS at that point will need to take explicit action.&lt;/P&gt;
&lt;P&gt;The recommended path is:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Configure or validate the EWSAllowedAppIDs allow list (remember, we said we would populate this for tenants who have not done so in September – read more &lt;A href="https://techcommunity.microsoft.com/blog/exchange/exchange-online-ews-your-time-is-almost-up/4492361" target="_blank" rel="noopener"&gt;here&lt;/A&gt; – but the admin owns ensuring it’s correct).&lt;/LI&gt;
&lt;LI&gt;Set EWSEnabled=True&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Customers who complete this work proactively will be significantly less likely to experience disruption during the broader retirement rollout.&lt;/P&gt;
&lt;H3&gt;Why we strongly recommend enabling this feature now&lt;/H3&gt;
&lt;P&gt;Customers should not think of EWSAllowedAppIDs as a feature intended only for October 2026. Its greatest value is in the preparation period before enforcement begins.&lt;/P&gt;
&lt;P&gt;Deploying and validating the allow list now gives administrators time to find unknown dependencies, remove obsolete applications, engage vendors that still rely on EWS, and begin migrations to Microsoft Graph.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Discover unknown EWS dependencies&lt;/LI&gt;
&lt;LI&gt;Remove obsolete applications&lt;/LI&gt;
&lt;LI&gt;Contact vendors still requiring EWS&lt;/LI&gt;
&lt;LI&gt;Begin migrations to Graph APIs&lt;/LI&gt;
&lt;LI&gt;Validate which applications truly still require exceptions&lt;/LI&gt;
&lt;LI&gt;Reduce future support escalations and outages&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Administrators who wait until they are already impacted by phased disablement will have a much smaller remediation window and a significantly higher likelihood of disruption.&lt;/P&gt;
&lt;H2&gt;Recommended next steps for administrators&lt;/H2&gt;
&lt;P&gt;We strongly recommend that Exchange Online administrators begin this work now:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Inventory EWS usage&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Identify all applications and services currently using EWS in your organization. Use EWS usage reports where available in your tenant, and review Message Center posts that summarize tenant usage. Please see &lt;A href="https://techcommunity.microsoft.com/blog/exchange/notes-from-the-field-finding-and-remediating-ews-app-usage-before-retirement/4496469" target="_blank" rel="noopener"&gt;Notes From the Field: Finding and Remediating EWS App Usage Before Retirement | Microsoft Community Hub&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Build an allow list&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Create an EWSAllowedAppIDs allow list containing only applications that are known to still require EWS. This includes Microsoft first-party client apps such as Office, Power Query for Excel etc. If the app shows up in your usage report, and you want to keep using it, you need to add it to the list.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If an administrator already knows which applications they want to permit, they can create a new allow list directly by specifying one or more App IDs.&lt;/P&gt;
&lt;P&gt;For example:&lt;/P&gt;
&lt;PRE&gt;Set-OrganizationConfig -EwsAllowedAppIDs "11111111-2222-3333-4444-555555555555,aaaaaaaa-bbbb-cccc-dddd-eeeeeeeeeeee"&lt;/PRE&gt;
&lt;P&gt;This replaces the current value with the specified set of allowed applications.&lt;/P&gt;
&lt;P&gt;After setting the value, administrators can confirm the configured list using:&lt;/P&gt;
&lt;PRE&gt;Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy | Format-List EwsAllowedAppIDs&lt;/PRE&gt;
&lt;P style="background: #F0F0F0; padding: .5em; margin: 1em 0 1em 0;"&gt;The use of “RetrieveEwsOperationAccessPolicy” is required for performance reasons – we only want to retrieve this list if the admin explicitly asks for it.&lt;/P&gt;
&lt;P style="background: #F0F0F0; padding: .5em; margin: 1em 0 1em 0;"&gt;Administrators should be aware that setting the property writes the full list value. If the property already contains App IDs, they will be replaced unless included in the new command. See more below on this.&lt;/P&gt;
&lt;H3&gt;Test thoroughly&lt;/H3&gt;
&lt;P&gt;Validate that all applications on your allow list continue to work as expected, and check for any missed dependencies. If you need to add or remove an App ID, you must read the current list, compute the updated list, and then write the full value back. Today, this cmdlet does not support incremental add or remove operations.&lt;/P&gt;
&lt;P&gt;Here are two examples that show how to update the list:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Example: add a new App ID&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The common pattern is to read the current list, append the new App ID, and then write the full combined list back.&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;# Read the current allow list
$current = (Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy | Select-Object -ExpandProperty EwsAllowedAppIDs)
# Define the new App ID to add
$newAppId = "99999999-8888-7777-6666-555555555555"
# Combine existing and new values
$updated = @($current, $newAppId)
# Write the updated allow list back
Set-OrganizationConfig -EwsAllowedAppIDs ($updated -join ",")&lt;/LI-CODE&gt;
&lt;P&gt;&lt;STRONG&gt;Example: remove an App ID&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Because there is no single-item removal operation today, removal also requires recomputing the full list.&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;# Read the current allow list
$current = (Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy | Select-Object -ExpandProperty EwsAllowedAppIDs)
# Define the App ID to remove
$removeAppId = "99999999-8888-7777-6666-555555555555"
# Split the comma-separated list into individual App IDs
$appIds = $current -split ","
# Remove the specified App ID
$updated = $appIds | Where-Object { $_ -ne $removeAppId }
# Write the updated allow list back
Set-OrganizationConfig -EwsAllowedAppIDs ($updated -join ",")&lt;/LI-CODE&gt;
&lt;H3&gt;The bigger picture&lt;/H3&gt;
&lt;P&gt;EWS served the Exchange ecosystem for nearly two decades.&lt;/P&gt;
&lt;P&gt;However, modern requirements for security, reliability, compliance, and scale call for a more modern API platform. Microsoft Graph is the long-term strategic platform for most Exchange Online integration scenarios.&lt;/P&gt;
&lt;P&gt;EWSAllowedAppIDs is designed to make the final transition manageable and predictable while still encouraging rapid migration off EWS.&lt;/P&gt;
&lt;P&gt;Organizations that prepare early will navigate this transition most smoothly. Administrators who inventory dependencies now and validate their allow lists well before October 2026 will be far better positioned to avoid disruption as phased retirement begins.&lt;/P&gt;
&lt;P&gt;The time to prepare is now.&lt;/P&gt;
&lt;P&gt;For the latest on the overall plan, status on parity gaps and links to resources, please check the &lt;A href="https://learn.microsoft.com/exchange/clients-and-mobile-in-exchange-online/deprecation-of-ews-exchange-online" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Deprecation of Exchange Web Services in Exchange Online&lt;/STRONG&gt;&lt;/A&gt; page.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-12"&gt;The Exchange Team&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jun 2026 14:57:47 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/exchange-team-blog/introducing-ewsallowedappids-preparing-for-the-final-phase-of/ba-p/4529471</guid>
      <dc:creator>The_Exchange_Team</dc:creator>
      <dc:date>2026-06-29T14:57:47Z</dc:date>
    </item>
    <item>
      <title>Released: June 2026 Exchange Server Security Updates</title>
      <link>https://techcommunity.microsoft.com/t5/exchange-team-blog/released-june-2026-exchange-server-security-updates/ba-p/4524491</link>
      <description>&lt;P&gt;Microsoft has released Security Updates (SUs) for vulnerabilities found in:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Exchange Server Subscription Edition (SE)&lt;/LI&gt;
&lt;LI&gt;Exchange Server 2019&lt;/LI&gt;
&lt;LI&gt;Exchange Server 2016&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;SUs are available for the following specific versions of Exchange Server:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/download/details.aspx?id=108698" target="_blank" rel="noopener"&gt;Exchange SE RTM&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Exchange Server 2019&amp;nbsp;CU14&amp;nbsp;and&amp;nbsp;CU15 (to access, organization must be enrolled into the &lt;A href="https://techcommunity.microsoft.com/blog/exchange/announcing-period-2-exchange-20162019-extended-security-update-esu-program/4511603" target="_blank" rel="noopener"&gt;Period 2 ESU program&lt;/A&gt;)&lt;/LI&gt;
&lt;LI&gt;Exchange Server 2016&amp;nbsp;CU23 (to access, organization must be enrolled into the &lt;A href="https://techcommunity.microsoft.com/blog/exchange/announcing-period-2-exchange-20162019-extended-security-update-esu-program/4511603" target="_blank" rel="noopener"&gt;Period 2 ESU program&lt;/A&gt;)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The June 2026 SUs address vulnerabilities responsibly reported to Microsoft by security partners and found through Microsoft’s internal processes as well as &lt;A href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42897" target="_blank" rel="noopener"&gt;CVE-2026-42897&lt;/A&gt; that we announced: &lt;A href="https://techcommunity.microsoft.com/blog/Exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498/" target="_blank" rel="noopener"&gt;Addressing Exchange Server May 2026 vulnerability CVE-2026-42897 | Microsoft Community Hub&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;These vulnerabilities affect Exchange Server. Exchange Online customers are already protected from the vulnerabilities addressed by these SUs and do not need to take any action other than updating any Exchange servers or Exchange Management tools workstations in their environment.&lt;/P&gt;
&lt;P&gt;More details about specific CVEs can be found in the&amp;nbsp;&lt;A href="https://msrc.microsoft.com/update-guide/" target="_blank" rel="noopener"&gt;Security Update Guide&lt;/A&gt;&amp;nbsp;(filter on ‘Server Software’ under Product Family for Exchange SE and ‘ESU’ under Product Family for Exchange 2016 and 2019).&lt;/P&gt;
&lt;H3&gt;Update to ensure continued function of Exchange Emergency Mitigation (EM) and Feature Flighting services&lt;/H3&gt;
&lt;P&gt;Due to service-side change, the &lt;A href="https://learn.microsoft.com/en-us/exchange/plan-and-deploy/post-installation-tasks/security-best-practices/exchange-emergency-mitigation-service" target="_blank" rel="noopener"&gt;Exchange Emergency Mitigation (EM)&lt;/A&gt; and &lt;A href="https://learn.microsoft.com/exchange/plan-and-deploy/post-installation-tasks/feature-flighting" target="_blank" rel="noopener"&gt;Exchange Flighting&lt;/A&gt; services will be unable to use configuration files released in July 2026 or later, unless Exchange is updated to June 2026 update (or newer). Any mitigations already downloaded and applied will keep working, but servers will not be able to use any new mitigations starting in July 2026 unless updates are installed. Please see &lt;A href="https://support.microsoft.com/topic/e2d8ccf3-209f-4056-845e-07d3e4a28646" target="_blank" rel="noopener"&gt;Exchange mitigation and flighting services fail due to "Unknown Issuer" error&lt;/A&gt; for more details.&lt;/P&gt;
&lt;H3&gt;CVE-2026-42897 mitigations after installation&lt;/H3&gt;
&lt;P&gt;As part of our ongoing efforts to strengthen security and improve defenses across environments, we continue to enhance protections for cross-site scripting attacks. &lt;EM&gt;We recommend that customers keep CVE-2026-42897 mitigation in place.&lt;/EM&gt; The mitigation provides an additional layer of defense and helps ensure continuous protection as further improvements are released. Additional updates will be shared as they become available - now available, please see &lt;A href="https://techcommunity.microsoft.com/blog/exchange/released-july-2026-exchange-server-security-updates/4534146" target="_blank"&gt;Released: July 2026 Exchange Server Security Updates | Microsoft Community Hub&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Installing the June 2026 update &lt;EM&gt;does not&lt;/EM&gt; automatically remove already applied CVE-2026-42897 mitigations. Therefore, if you choose to remove mitigations after installation, you should:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;If mitigation was applied using Exchange Emergency Mitigation (EM) Service:&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/exchange/plan-and-deploy/post-installation-tasks/security-best-practices/exchange-emergency-mitigation-service#blocking-or-removing-mitigations" target="_blank" rel="noopener"&gt;Block the mitigation M2.1.0 from re-applying&lt;/A&gt;. Because of our recommendation to keep the CVE-2026-42897 mitigation in place, we are not yet updating the mitigation to not apply to servers that are updated to June 2026 SU. Therefore, at this time, you must block the mitigation from re-applying first.&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/Exchange/plan-and-deploy/post-installation-tasks/security-best-practices/exchange-emergency-mitigation-service#rollback-procedures-for-released-mitigations" target="_blank" rel="noopener"&gt;Remove the mitigation M2 IIS rules&lt;/A&gt;.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;If mitigation was applied using the downloadable EOMT script &lt;/STRONG&gt;&lt;A href="https://aka.ms/UnifiedEOMT" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;https://aka.ms/UnifiedEOMT&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;: &lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;A href="https://microsoft.github.io/CSS-Exchange/Security/EOMT/#roll-back-a-mitigation" target="_blank" rel="noopener"&gt;Roll back the mitigation&lt;/A&gt;.&lt;/LI&gt;
&lt;/OL&gt;
&lt;H3&gt;Exchange 2016 and 2019 updates are available &lt;EM&gt;only&lt;/EM&gt; under the Period 2 ESU program&lt;/H3&gt;
&lt;P&gt;Exchange Server 2016 and 2019 are &lt;A href="https://techcommunity.microsoft.com/blog/exchange/support-for-exchange-server-2016-and-exchange-server-2019-ends-today/4461192" target="_blank" rel="noopener"&gt;out of support&lt;/A&gt;. Only customers who enrolled in the &lt;A href="https://techcommunity.microsoft.com/blog/exchange/announcing-period-2-exchange-20162019-extended-security-update-esu-program/4511603" target="_blank" rel="noopener"&gt;Period 2 Extended Security Update (ESU) program&lt;/A&gt; are eligible to receive Exchange Server 2016 and 2019 security updates released between May and October 2026.&lt;/P&gt;
&lt;P&gt;If you are not part of the Period 2 ESU program, &lt;A href="https://techcommunity.microsoft.com/blog/exchange/upgrading-your-organization-from-current-versions-to-exchange-server-se/4241305" target="_blank" rel="noopener"&gt;migrate to Exchange Server Subscription Edition (SE)&lt;/A&gt; to keep receiving the latest security updates.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;If you have already purchased the Period 2 ESU&lt;/EM&gt; and need information on accessing the latest Security Updates, please contact us by sending an email to &lt;A href="mailto:ExchangeandSfBServerESUInquiry@service.microsoft.com?subject=We%20purchased%20Exchange%20ESU%20need%20access" target="_blank" rel="noopener"&gt;ExchangeandSfBServerESUInquiry@service.microsoft.com&lt;/A&gt;.&lt;/P&gt;
&lt;H3&gt;Known issues with this release&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://support.microsoft.com/en-us/servicing/exchange/server/hotfix/2026/5105719" target="_blank" rel="noopener"&gt;Wrapper messages appear in shared mailbox inbox in hybrid environments | Microsoft Support&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Update installation&lt;/H3&gt;
&lt;P&gt;The following update paths are available:&lt;/P&gt;
&lt;img /&gt;
&lt;UL&gt;
&lt;LI&gt;Inventory your Exchange Servers to determine which updates are needed using the &lt;A href="https://aka.ms/ExchangeHealthChecker" target="_blank" rel="noopener"&gt;Exchange Server Health Checker script&lt;/A&gt;. Running this script will tell you if any of your Exchange Servers are behind on updates (CUs, SUs, or manual actions).&lt;/LI&gt;
&lt;LI&gt;Install the latest CU. Use the &lt;A href="https://aka.ms/ExchangeUpdateWizard" target="_blank" rel="noopener"&gt;Exchange Update Wizard&lt;/A&gt; to choose your current CU and your target CU to get directions.&lt;/LI&gt;
&lt;LI&gt;Re-run the Health Checker after you install an update to see if any further actions are needed.&lt;/LI&gt;
&lt;LI&gt;After setup is completed, please reboot the server and check that all Exchange services have started properly. If some services are in a disabled state, that indicates that something interrupted installation of the update. Please see the Workaround 1 in &lt;A href="https://support.microsoft.com/en-us/topic/file-version-error-when-you-try-to-install-exchange-server-november-2024-su-a650da30-f8fb-469d-a449-47396cab0a15" target="_blank" rel="noopener"&gt;this article&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;If you encounter errors during or after installation of Exchange Server, run the &lt;A href="https://aka.ms/ExSetupAssist" target="_blank" rel="noopener"&gt;SetupAssist script&lt;/A&gt;. If something does not work properly after updates, see &lt;A href="https://aka.ms/ExchangeFAQ" target="_blank" rel="noopener"&gt;Repair failed installations of Exchange Cumulative and Security updates&lt;/A&gt;. Also please see &lt;A href="https://support.microsoft.com/topic/file-version-error-when-you-try-to-install-exchange-server-november-2024-su-a650da30-f8fb-469d-a449-47396cab0a15" target="_blank" rel="noopener"&gt;File version error when you try to install Exchange Server updates&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H1&gt;FAQs&lt;/H1&gt;
&lt;P&gt;&lt;STRONG&gt;When CVE-2026-42897 mitigations were released, there were several reported known issues. Are those solved in the CVE-2026-42897 fix (June 2026 SU)?&lt;BR /&gt;&lt;/STRONG&gt;Yes, when June 2026 SU is installed and mitigation is removed, known issues should be resolved too. But note that mitigations do not get removed automatically after installation of the SU (and we recommend that you keep then enabled for a little while longer).&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;If we update some of our servers but cannot update others, can servers that will not receive update stay with CVE-2026-42897 mitigations? Is it OK to have some servers updated and some still using mitigations?&lt;/STRONG&gt;&lt;BR /&gt;You can continue using mitigations on any servers that you cannot update to June 2026 SU (or newer). But note that known issues from mitigations will continue to apply to those servers. Additionally, after applying this update, Office Online Server (OOS) integration with Exchange Server might not function as expected until all Exchange servers in the organization have been updated.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;We updated our servers to June 2026 (or newer) update, but we still have trouble with known issues caused by mitigations. Why is this?&lt;/STRONG&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;Installing the June 2026 (or newer) update does not automatically remove mitigations. Please see the post above. Currently, we recommend that mitigations stay in place but they can be removed as per the above.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Our organization is in Hybrid mode with Exchange Online. Do we need to do anything?&lt;/STRONG&gt;&lt;BR /&gt;Exchange Online is already protected, but this SU needs to be installed on your Exchange servers, even if they are used only for management purposes. If you change the auth certificate after installing an SU, you should re-run the Hybrid Configuration Wizard.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;The last SU/HU we installed is a few months old. Do we need to install all SUs in order to install the latest one?&lt;/STRONG&gt;&lt;BR /&gt;SUs are cumulative. If you are running a CU supported by the SU, you do not need to install all SUs or HUs in sequential order; simply install the latest SU. Please see&amp;nbsp;&lt;A href="https://techcommunity.microsoft.com/t5/exchange-team-blog/why-exchange-server-updates-matter/ba-p/2280770" target="_blank" rel="noopener"&gt;this blog post&lt;/A&gt;&amp;nbsp;for more information.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Do we need to install SUs on all Exchange Servers within our organization? What about ‘Management Tools only’&amp;nbsp;machines?&lt;/STRONG&gt;&lt;BR /&gt;Our recommendation is to install SUs on&amp;nbsp;&lt;U&gt;all&lt;/U&gt;&amp;nbsp;Exchange Servers and all servers and workstations running the Exchange Management Tools to ensure compatibility between management tools clients and servers. If you are trying to update the Exchange Management Tools in the environment with no running Exchange servers, please see&amp;nbsp;&lt;A href="https://learn.microsoft.com/exchange/manage-hybrid-exchange-recipients-with-management-tools#update-the-exchange-server-management-tools-only-role-with-no-running-exchange-server-to-a-newer-cumulative-or-security-update" target="_blank" rel="noopener"&gt;this&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Our organization does not have the Exchange 2016 and 2019 Period 2 ESU. How can we get current Exchange 2016 or 2019 updates?&lt;/STRONG&gt;&lt;BR /&gt;Since Exchange 2016 and 2019 are now &lt;A href="https://techcommunity.microsoft.com/blog/exchange/support-for-exchange-server-2016-and-exchange-server-2019-ends-today/4461192" target="_blank" rel="noopener"&gt;out of support&lt;/A&gt;, only customers who have enrolled into the &lt;A href="https://techcommunity.microsoft.com/blog/exchange/announcing-period-2-exchange-20162019-extended-security-update-esu-program/4511603" target="_blank" rel="noopener"&gt;Period 2 ESU program&lt;/A&gt; (which is valid between May and October 2026) can obtain Exchange 2016 or 2019 updates released after May 2026. For all other customers still running Exchange 2016 or 2019, we recommend that you &lt;A href="https://techcommunity.microsoft.com/blog/exchange/upgrading-your-organization-from-current-versions-to-exchange-server-se/4241305" target="_blank" rel="noopener"&gt;upgrade your organization to Exchange SE&lt;/A&gt; as soon as possible.&lt;/P&gt;
&lt;P style="background: #F0F0F0; padding: .5em; margin: 1em 0 1em 0;"&gt;Documentation may not be fully available at the time this post is published.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Significant updates to this post:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;7/14/2026: Added a link to &lt;A href="https://techcommunity.microsoft.com/blog/exchange/released-july-2026-exchange-server-security-updates/4534146" target="_blank"&gt;Released: July 2026 Exchange Server Security Updates | Microsoft Community Hub&lt;/A&gt;. When installed, remove the CVE-2026-42897 mitigation to address known issues&lt;/LI&gt;
&lt;LI&gt;7/13/2026: Added a Known issues section&lt;/LI&gt;
&lt;LI&gt;6/15/2026: Clarification of mitigation blocking&lt;/LI&gt;
&lt;LI&gt;6/11/2026: Removed the banner with documentation publishing issues (now resolved)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-12"&gt;The Exchange Server Team&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2026 17:23:34 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/exchange-team-blog/released-june-2026-exchange-server-security-updates/ba-p/4524491</guid>
      <dc:creator>The_Exchange_Team</dc:creator>
      <dc:date>2026-07-14T17:23:34Z</dc:date>
    </item>
    <item>
      <title>How to determine which Resource Mailboxes are being actively used</title>
      <link>https://techcommunity.microsoft.com/t5/exchange-team-blog/how-to-determine-which-resource-mailboxes-are-being-actively/ba-p/4521577</link>
      <description>&lt;P&gt;Today we wanted to take a few minutes to discuss a topic that has come up several times. Consider the scenario where your organization has created Resource mailboxes, and you want to know which ones are actually being used. Seems like a fair request.&lt;/P&gt;
&lt;P&gt;This would include Room and Equipment mailboxes as well as Workspaces. Unfortunately, there are no native reports (at the time of this writing) that include details on Resource mailbox utilization. We are going to provide a few options you can use to find this information out, and you can choose which one works for you.&lt;/P&gt;
&lt;H3&gt;Option 1: Use Get-CalendarViewDiagnostics&lt;/H3&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/troubleshoot/exchange/calendars/cdl/get-meeting-id#use-exchange-online-powershell" target="_blank" rel="noopener"&gt;Get the ID of a meeting - Exchange | Microsoft Learn&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;This will check the calendar of the specified mailbox and will provide the output of all meetings on the calendar during the specified time window.&lt;/P&gt;
&lt;P&gt;The following example will provide a list of meetings on the calendar going back 6 months in the past and 6 months in the future:&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;Get-CalendarViewDiagnostics resource@contoso.com -WindowStartUtc (Get-Date).AddMonths(-6) -WindowEndUtc (Get-Date).AddMonths(6)&lt;/LI-CODE&gt;
&lt;P&gt;This returns data quickly and only targets the calendar. The possible downside of this approach is that the meeting subject is not a property that is exposed. But if you are only looking to see which rooms have meetings scheduled, or get an overall count, this should work great for you.&lt;/P&gt;
&lt;P&gt;The upside to this approach is that Exchange Online PowerShell has rich filtering capabilities, so for example you could easily target your command to all Room mailboxes or all Equipment mailboxes.&lt;/P&gt;
&lt;P&gt;Example:&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;$roommailboxes = Get-Mailbox -ResultSize Unlimited -RecipientTypeDetails RoomMailbox
$roommailboxes | ForEach { Write-Host “Processing Mailbox $($_.Displayname)” ; Get-CalendarViewDiagnostics $_ -WindowStartUtc (Get-Date).AddMonths(-6) -WindowEndUtc (Get-Date).AddMonths(6) }&lt;/LI-CODE&gt;
&lt;H3&gt;Option 2: Use Graph to get the details of calendar events.&lt;/H3&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/graph/api/calendar-list-calendarview?view=graph-rest-1.0&amp;amp;tabs=powershell" target="_blank" rel="noopener"&gt;List calendarView - Microsoft Graph v1.0 | Microsoft Learn&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;On the bottom of the article, see example requests. To use this with PowerShell, you need the Microsoft.Graph.Calendar module and you need an Entra ID App registration which has the appropriate Graph permissions added.&lt;/P&gt;
&lt;P&gt;You can either use Delegated permissions or Application permissions.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Delegated permissions mean Graph API is being accessed using a user account and will prompt for sign-in information.&lt;/LI&gt;
&lt;LI&gt;Application permissions would be used for non-interactive applications/scripts where a sign-in prompt cannot be used.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Example using Application permissions:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Create Entra ID App registration&lt;/LI&gt;
&lt;LI&gt;Add Graph Application Calendars.Read API permission. This allows the application to read calendar data from all mailboxes.&lt;/LI&gt;
&lt;LI&gt;Create either a client secret or upload a certificate to be used for authentication. If you use a certificate, note that it can be a self-signed certificate.&lt;/LI&gt;
&lt;LI&gt;Launch PowerShell and import the Graph module&lt;LI-CODE lang="powershell"&gt;Import-Module Microsoft.Graph&lt;/LI-CODE&gt;&lt;/LI&gt;
&lt;LI&gt;Connect to Graph using PowerShell with a certificate&lt;LI-CODE lang="powershell"&gt;Connect-MgGraph -ClientId &amp;lt;app id=""&amp;gt; -TenantId &amp;lt;your tenant="" id=""&amp;gt; -CertificateThumbprint &amp;lt;cert thumbprint=""&amp;gt;&amp;lt;/cert&amp;gt;&amp;lt;/your&amp;gt;&amp;lt;/app&amp;gt;&lt;/LI-CODE&gt;
&lt;P&gt;or&lt;/P&gt;
&lt;P&gt;Connect to Graph using a client secret&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;Connect-MgGraph -ClientSecretCredential -TenantId &amp;lt;your tenant="" id=""&amp;gt;&amp;lt;/your&amp;gt;&lt;/LI-CODE&gt;&lt;/LI&gt;
&lt;LI&gt;Display a list of calendar items for a given time period and specify a few properties to show, such as the Organizer, Subject and Start/End time. We will use the same example as with Get-CalendarViewDiagnostics, going back 6 months in the past and 6 months in the future.&lt;LI-CODE lang="powershell"&gt;Get-MgUserCalendarView -UserId resource@contoso.com -StartDateTime (Get-Date).AddMonths(-6) -EndDateTime (Get-Date).AddMonths(6) | select @{n='Organizer';e={$_.Organizer.EmailAddress.Name}}, subject, @{n='StartTime';e={$_.Start.DateTime}},@{n='EndTime';e={$_.End.DateTime}}&lt;/LI-CODE&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Graph does have filtering capabilities, though for me it isn’t quite as easy as filtering in Exchange Online PowerShell. If you can connect to both Exchange Online PowerShell and Graph PowerShell in the same session, you could combine the two and run your command against the list of mailboxes in your variable.&lt;/P&gt;
&lt;P&gt;Example:&lt;/P&gt;
&lt;P&gt;Get the list of mailboxes from Exchange Online PowerShell:&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;$roommailboxes = Get-Mailbox -ResultSize Unlimited -RecipientTypeDetails RoomMailbox&lt;/LI-CODE&gt;
&lt;P&gt;Then use Graph PowerShell to get the Calendar events:&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;$roommailboxes | foreach {Write-Host "Processing Mailbox $($_.DisplayName)"; Get-MgUserCalendarView -UserId $_.PrimarySmtpAddress -StartDateTime (Get-Date).AddMonths(-6) -EndDateTime (Get-Date).AddMonths(6) | select @{n='Organizer';e={$_.Organizer.EmailAddress.Name}}, subject, @{n='StartTime';e={$_.Start.DateTime}},@{n='EndTime';e={$_.End.DateTime}}}&lt;/LI-CODE&gt;
&lt;P&gt;Note that there are additional properties available in addition to what was provided in the example above. You would need to determine which ones you want to show. Some of them (like Organizer and Start/End) are Type properties, so you must build an expression to handle them like we did above. Graph is also exposed to many other languages as well (HTTP, C#, Java, etc.)&lt;/P&gt;
&lt;P&gt;Using the Graph solution, it is also possible to restrict access to only certain mailboxes (such as only Resource mailboxes).&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/exchange/permissions-exo/application-rbac" target="_blank" rel="noopener"&gt;Role Based Access Control for Applications in Exchange Online | Microsoft Learn&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;This would allow you to control which mailboxes the Entra ID app could pull calendar details from.&lt;/P&gt;
&lt;P&gt;It involves configuring a management scope that defines the list of mailboxes (via a recipient filter). Once that is done, the Graph permissions in Entra ID needs to be removed, and they can then be granted in Exchange Online via RBAC (New-ManagementRoleAssignment).&lt;/P&gt;
&lt;H3&gt;Option 3: Use Get-MailboxFolderStatistics&lt;/H3&gt;
&lt;P&gt;For a very simplistic approach to checking resource mailbox usage, Get-MailboxFolderStatistics might provide what you need. Using the IncludeOldestAndNewestItems along with the FolderScope allows you to target the Calendar folder.&lt;/P&gt;
&lt;P&gt;Example:&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;Get-MailboxFolderStatistics resource@contoso.com -IncludeOldestAndNewestItems -FolderScope Calendar&lt;/LI-CODE&gt;
&lt;P&gt;Similar to Get-CalendarViewDiagnostics, you have the ability to run in bulk against multiple recipients.&lt;/P&gt;
&lt;P&gt;Example:&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;$roommailboxes | Foreach { Get-MailboxFolderStatistics $_ -IncludeOldestAndNewestItems -FolderScope Calendar}&lt;/LI-CODE&gt;
&lt;H3&gt;&lt;EM&gt;Do&amp;nbsp;not&lt;/EM&gt; use Get-CalendarDiagnosticObjects for this purpose!&lt;/H3&gt;
&lt;P&gt;One last method that we’ve seen customers try use is using Calendar Diagnostic Logs with the &lt;EM&gt;Get-CalendarDiagnosticObjects&lt;/EM&gt; cmdlet. &lt;EM&gt;Please DON’T use this method&lt;/EM&gt;.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/troubleshoot/exchange/calendars/cdl/get-calendar-diagnostic-logs" target="_blank" rel="noopener"&gt;Get Calendar diagnostic logs for Exchange Online mailboxes - Exchange | Microsoft Learn&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;While it technically will work to pull meeting details, it really was not designed for bulk gathering of calendar events. Instead, it was designed to help troubleshoot problems with individual meetings. Calendar Diagnostic Log data includes not only data from the Calendar, but also all other folders where calendar-related information can be stored, including the Inbox, Sent Items, Deleted Items and Recoverable Items folders such as Calendar Logging. Querying even for a single meeting can sometimes produce in excess of 1000 logs. As such, running this in bulk for lots of meetings against a mailbox may fail, might timeout or produce errors. If you are using this method and reach out to Support because you have issues (which is very likely), we will direct you to one of the other options.&lt;/P&gt;
&lt;P&gt;In summary, although there are no native reports available to check on which Resource Mailboxes are being used, there are several options available. If you are already connected to Exchange Online PowerShell, using Get-CalendarViewDiagnostics may be the simplest option for you. If you need more properties than what is exposed with Get-CalendarViewDiagnostics or want to be able to use a custom application that uses a different language, we recommend the Graph approach.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-12"&gt;Ben Winzenz&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jun 2026 13:57:46 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/exchange-team-blog/how-to-determine-which-resource-mailboxes-are-being-actively/ba-p/4521577</guid>
      <dc:creator>The_Exchange_Team</dc:creator>
      <dc:date>2026-06-26T13:57:46Z</dc:date>
    </item>
    <item>
      <title>Replacing IIS SMTP virtual server with Exchange Edge Transport</title>
      <link>https://techcommunity.microsoft.com/t5/exchange-team-blog/replacing-iis-smtp-virtual-server-with-exchange-edge-transport/ba-p/4521241</link>
      <description>&lt;P&gt;Years go by and we &lt;EM&gt;continue&lt;/EM&gt; to see customers still relying on the IIS 6.0 SMTP virtual server feature, which has been out of support for a looong time. To give you an idea just how old this component is, the &lt;A href="https://learn.microsoft.com/iis/application-frameworks/install-and-configure-php-on-iis/configure-smtp-e-mail-in-iis-7-and-above" target="_blank" rel="noopener"&gt;built-in IIS SMTP virtual server stack was tied to Windows Server 2003.&lt;/A&gt; This blog post aims to present practical options to help you retire IIS SMTP and replace it with supported Microsoft solutions (because IIS SMTP virtual server is long unsupported).&lt;/P&gt;
&lt;P&gt;Historically, we have encouraged customers to retain their last Exchange on‑premises server in &lt;A href="https://learn.microsoft.com/exchange/decommission-on-premises-exchange" target="_blank" rel="noopener"&gt;certain scenarios&lt;/A&gt;. One of the most common scenarios is on‑premises applications still depend on Exchange for email relay, even after all mailboxes have been migrated to Exchange Online.&lt;/P&gt;
&lt;P&gt;Then there are also cloud‑only Exchange Online customers who have already decommissioned their last on‑premises Exchange server (or never had one at all) and, for various reasons, are unable to configure their applications, Fax and printers to relay email directly through Exchange Online. When this scenario applies, the most straightforward and supported way to eliminate the use of IIS SMTP is to replace it with a &lt;STRONG&gt;standalone Exchange Edge Transport Server&lt;/STRONG&gt;. This also helps with centralized administration of one or few Edge servers instead of several applications and devices individually.&lt;/P&gt;
&lt;P&gt;You might not know this, but running a standalone Exchange Edge Transport server can be done with minimal overhead.&lt;/P&gt;
&lt;P&gt;It’s important to clarify what &lt;EM&gt;“standalone”&lt;/EM&gt; means in this context. A standalone Edge Transport server is &lt;STRONG&gt;not subscribed to an Active Directory site&lt;/STRONG&gt;. Whether or not the server is domain‑joined is irrelevant here; what truly matters is that the Edge Transport server is not Edge‑subscribed to Active Directory. In this configuration, Active Directory is effectively unaware of this Exchange server’s existence.&lt;/P&gt;
&lt;P&gt;Why does this matter? Because subscribing an Edge Transport server to an AD site introduces additional complexity such as EdgeSync, dedicated certificates for Direct Trust, and extra operational considerations. &lt;U&gt;The goal of this blog post is to provide a simple, low‑effort, and supported solution that allows you to finally retire use of legacy IIS 6.0 SMTP server without introducing unnecessary complexity into your environment&lt;/U&gt;.&lt;/P&gt;
&lt;P&gt;Let’s see the following flowchart to understand the big picture of options you have:&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;¹ It is important to consider if the application and devices send email to only Exchange online mailbox or also send to external domains. Based on the requirement, you will need to evaluate your options mentioned in this &lt;A href="https://learn.microsoft.com/exchange/mail-flow-best-practices/how-to-set-up-a-multifunction-device-or-application-to-send-email-using-microsoft-365-or-office-365" target="_blank" rel="noopener"&gt;article&lt;/A&gt;. If you want to send emails to external domains which essentially is relaying through Exchange online, you can:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Configure a&amp;nbsp;&lt;A href="https://learn.microsoft.com/exchange/mail-flow-best-practices/how-to-set-up-a-multifunction-device-or-application-to-send-email-using-microsoft-365-or-office-365#configure-a-tls-certificate-based-connector-for-smtp-relay" target="_blank" rel="noopener"&gt;TLS certificate-based connector for SMTP relay&lt;/A&gt; - this is a secure way to relay email. You need a certificate where the Subject or Subject Alternate Name (SAN) fields contain an &lt;A href="https://learn.microsoft.com/exchange/mail-flow-best-practices/manage-accepted-domains/manage-accepted-domains" target="_blank" rel="noopener"&gt;accepted domain&lt;/A&gt; in Microsoft 365.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Or you can&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Configure an&amp;nbsp;&lt;A href="https://learn.microsoft.com/exchange/mail-flow-best-practices/how-to-set-up-a-multifunction-device-or-application-to-send-email-using-microsoft-365-or-office-365#configure-an-ip-address-based-connector-for-smtp-relay" target="_blank" rel="noopener"&gt;IP address-based connector for SMTP relay&lt;/A&gt; - this is a less secure way to relay and is not recommended. With this method, the sender domain mentioned in the MAIL FROM must match one of the accepted domains of the tenant.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Whether you use Certificate based or IP Based connector, make sure you meet the requirements mentioned in this&amp;nbsp;&lt;A href="https://learn.microsoft.com/troubleshoot/exchange/email-delivery/office-365-notice" target="_blank" rel="noopener"&gt;article&lt;/A&gt;.&lt;/P&gt;
&lt;H5&gt;Is it feasible to redirect all on-premises applications to Exchange Online?&lt;/H5&gt;
&lt;P&gt;There may be multiple blockers, such as:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Applications that are not allowed to perform outbound external connectivity&lt;/LI&gt;
&lt;LI&gt;Legacy applications with unknown ownership or configuration&lt;/LI&gt;
&lt;LI&gt;Limited ability to update or reconfigure existing applications&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;There are several challenges to send or relay email directly from Application and devices. Applications and devices may not support TLS/STARTTLS, and managing certificates across multiple endpoints – such as printers in branch offices – can introduce significant operational complexity and potential security risks.&lt;/P&gt;
&lt;P&gt;A more suitable solution in this case is to deploy a standalone Edge Transport server. This allows you to centralize SMTP relay functionality and securely send messages to Exchange Online or external domains without requiring individual devices or applications to meet strict TLS and certificate requirements.&amp;nbsp;&lt;/P&gt;
&lt;H5&gt;What type of authentication is used by these applications?&lt;/H5&gt;
&lt;P&gt;For example, Basic Authentication or NTLM. If either is in use:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/Exchange/updated-exchange-online-smtp-auth-basic-authentication-deprecation-timeline/4489835" target="_blank" rel="noopener"&gt;SMTP Basic Authentication is being deprecated in Exchange Online&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;NTLM is not supported with Exchange Online for SMTP scenarios&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;As a result, reliance on these authentication methods may prevent Exchange Online use.&lt;/P&gt;
&lt;H3&gt;IIS 6.0 SMTP Assessment&lt;/H3&gt;
&lt;P&gt;Once you decide to replace your IIS SMTP server, one of the first and most critical steps is to perform a thorough assessment of its current usage.&lt;/P&gt;
&lt;P&gt;If logging is not already enabled, ensure it is configured by navigating to:&lt;BR /&gt;&lt;STRONG&gt;IIS → SMTP Virtual Server → Properties → Enable Logging → Properties → Advanced&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;From there, select all relevant extended logging fields that will help you identify which applications and systems are relying on the IIS SMTP server.&lt;/P&gt;
&lt;P&gt;It is recommended to allow logging to run for a sufficient period to capture a representative volume of data. This ensures that intermittent or less frequently used applications are also identified.&lt;/P&gt;
&lt;P&gt;Additional aspects that should be assessed include:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Access tab → Authentication&lt;/STRONG&gt;&lt;BR /&gt;Verify which authentication methods are enabled, such as:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Anonymous access&lt;/LI&gt;
&lt;LI&gt;Basic Authentication&lt;/LI&gt;
&lt;LI&gt;Integrated Windows Authentication&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Access tab → Relay Restrictions&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Confirm whether relay access is restricted to a defined list of IP addresses and review the scope of those restrictions.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Delivery tab → Advanced&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Determine how outbound email is being routed:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Whether the server uses a &lt;STRONG&gt;smart host&lt;/STRONG&gt; or performs &lt;STRONG&gt;direct DNS lookups&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If a smart host is configured:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Go back to &lt;STRONG&gt;Access tab → Outbound Security&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Verify whether authentication is required and which method is being used to connect to the smart host&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;To map these configurations to Exchange Edge Transport, keep the following in mind:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Settings configured under the &lt;STRONG&gt;“Access” &lt;/STRONG&gt;tab in IIS SMTP will typically correspond to the &lt;STRONG&gt;Receive Connector&lt;/STRONG&gt; on the Edge Transport server.&lt;/LI&gt;
&lt;LI&gt;Settings configured under the &lt;STRONG&gt;“Delivery” &lt;/STRONG&gt;tab will map to the &lt;STRONG&gt;Send Connector&lt;/STRONG&gt; on the Edge Transport server.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Once IIS SMTP logging has been enabled and sufficient data has been collected, the next step is to analyze the logs to identify key usage patterns, such as:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Source IP addresses of applications relying via the IIS SMTP server&lt;/LI&gt;
&lt;LI&gt;Sender SMTP addresses&lt;/LI&gt;
&lt;LI&gt;Recipient SMTP addresses&lt;/LI&gt;
&lt;LI&gt;Email volume per application and per day&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;IIS SMTP logs are not particularly user-friendly for analysis, especially at scale. As a result, you have few options to process and extract meaningful insights from this data:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Develop your own SQL query using &lt;A href="https://www.microsoft.com/en-us/download/details.aspx?id=24659" target="_blank" rel="noopener"&gt;Log Parser&lt;/A&gt; and &lt;A href="https://techcommunity.microsoft.com/blog/exchange/log-parser-studio-2-0-is-now-available/593266" target="_blank" rel="noopener"&gt;Log Parser Studio&lt;/A&gt; &lt;EM&gt;or&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;Share your IIS SMTP logs with Copilot and ask it to parse according to your needs&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Another important aspect to assess is how applications are configured to connect to the IIS SMTP server:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Do applications reference the IIS SMTP server via a hard-coded IP address, or via a DNS alias? The alias could be either a &lt;STRONG&gt;CNAME&lt;/STRONG&gt; or a &lt;STRONG&gt;host (A) &lt;/STRONG&gt;record.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If applications are using a DNS alias, the transition to Exchange Edge Transport is typically straightforward. In this case, you can redirect mail flow by simply updating the IP address associated with the alias in DNS. However, if applications are configured with a hard-coded IP address, the transition becomes more complex. In this scenario, you have two main options:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Update each application individually: Replace the IIS SMTP server IP with the Exchange Edge Transport IP. This is the cleanest approach; however, it is often the most time-consuming and operationally challenging.&lt;/LI&gt;
&lt;LI&gt;Reuse the existing IIS SMTP IP address: Assign the same IP address to the Exchange Edge Transport server as a secondary IP. While Microsoft generally discourages IP reuse in Exchange environments, this guidance primarily applies to AD-integrated Exchange roles. In this case, since the Edge Transport server is standalone and does not store objects on Active Directory, IP reuse can be acceptable if carefully planned and executed.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Once all relevant IIS SMTP data has been collected and analyzed, you can proceed with the Exchange Edge Transport deployment.&lt;/P&gt;
&lt;P&gt;If additional details are required for the assessment phase, refer to the FAQ section, where common caveats and IIS SMTP-specific considerations are covered.&lt;/P&gt;
&lt;H3&gt;Exchange Edge Transport considerations&lt;/H3&gt;
&lt;P&gt;Assuming you have decided to decommission IIS SMTP and use the Exchange Edge Transport role for email relay, the next key decision is whether the Edge Transport server should be deployed on a domain-joined machine.&lt;/P&gt;
&lt;P&gt;Microsoft generally recommends deploying the Edge Transport role on a non-domain-joined server. However, this guidance applies primarily to traditional Exchange environments where Edge Transport is installed in the perimeter network and is subscribed to an Active Directory site that includes Mailbox servers.&lt;/P&gt;
&lt;P&gt;In a scenario where no Exchange Mailbox role is present, the decision should be driven by your authentication, security, and management requirements. To help guide this choice, consider the following questions:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Do you need to enforce Basic Authentication or Integrated Windows Authentication using domain service accounts? If yes, deploying the Edge Transport on a domain-joined server is needed.&lt;/LI&gt;
&lt;LI&gt;Can you rely on local accounts for authentication (e.g., Basic Authentication without domain dependencies)? If yes, a non-domain-joined server is sufficient.&lt;/LI&gt;
&lt;LI&gt;Do you need to apply Group Policy Objects (GPOs) or centralized security baselines? If yes, consider a domain-joined deployment to enable centralized management and compliance enforcement.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Note that whether you install Edge on a domain joined machine or not, because you are not creating a subscription to Active Directory, installation of Edge will not require extending the schema and preparing AD for Exchange Server.&lt;/P&gt;
&lt;H3&gt;Requirements&lt;/H3&gt;
&lt;P&gt;Once the decision has been made, proceed with the installation of the Exchange Edge Transport role on an up-to-date server. Follow the &lt;A href="https://learn.microsoft.com/exchange/plan-and-deploy/prerequisites#exchange-server-edge-transport-server-role" target="_blank" rel="noopener"&gt;official prerequisites documentation&lt;/A&gt; to prepare the environment. Note that only a limited set of components is required:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;.NET Framework&lt;/LI&gt;
&lt;LI&gt;Visual C++ 2012 Redistributable&lt;/LI&gt;
&lt;LI&gt;Active Directory Lightweight Directory Services (AD LDS)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;No additional Exchange roles or dependencies are needed.&lt;/P&gt;
&lt;P&gt;Network and security:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;TCP port 25 must be permitted between the Edge server and applications or devices that will use Exchange Edge Transport for email relay. Typically, it should &lt;EM&gt;not&lt;/EM&gt; be exposed to internet assuming that these applications or devices are placed within the internal network.&lt;/LI&gt;
&lt;LI&gt;Outbound TCP port 25 must be permitted between the Edge server and external networks to enable SMTP mail flow.&lt;/LI&gt;
&lt;LI&gt;Ensure the server is properly hardened, following standard security best practices.&lt;/LI&gt;
&lt;LI&gt;Refer to this &lt;A href="https://learn.microsoft.com/exchange/antispam-and-antimalware/windows-antivirus-software" target="_blank" rel="noopener"&gt;article&lt;/A&gt; for Antivirus running on Exchange Server. The “Servers” column can be used to distinguish the necessary exclusions related to Edge Transport.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If high availability is required, consider deploying two standalone Edge Transport servers behind a load balancer, or DNS round-robin. This approach helps minimize service disruption during maintenance activities such as Windows or Exchange patching.&lt;/P&gt;
&lt;H3&gt;Accepted domain&lt;/H3&gt;
&lt;P&gt;Since the installation of the Exchange Edge Transport role is relatively straightforward, it will not be covered in this article. At this stage, we assume that the Edge Transport server has already been successfully deployed and is fully operational.&lt;/P&gt;
&lt;P&gt;The first step is to configure the Accepted Domains on the Edge Transport server. You can refer to the &lt;A href="https://learn.microsoft.com/powershell/module/exchangepowershell/new-accepteddomain?view=exchange-ps" target="_blank" rel="noopener"&gt;relevant documentation&lt;/A&gt; for the exact command syntax and parameters required.&lt;/P&gt;
&lt;P&gt;It is important to note that a standalone Edge Transport role does &lt;EM&gt;not&lt;/EM&gt; have &lt;EM&gt;Resolve&lt;/EM&gt; engines (e.g., no recipient or sender validation against Active Directory or ADAM). Because of this behavior, the distinction between Authoritative and Internal Relay domains does not have a functional impact on the Edge Transport server in this scenario.&lt;/P&gt;
&lt;H3&gt;Receive connector&lt;/H3&gt;
&lt;P&gt;Once the Edge Transport is installed, it will automatically create a Receive Connector as described in this &lt;A href="https://learn.microsoft.com/exchange/mail-flow/connectors/receive-connectors#default-receive-connectors-in-the-transport-service-on-edge-transport-servers" target="_blank" rel="noopener"&gt;article&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;To customize the Receive connector to satisfy your needs, you will need to understand how the IIS SMTP was used by your application for email relay. Assuming that your only Accepted Domain is contoso.com:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;If your applications are sending unauthenticated to contoso.com recipients (&lt;A href="mailto:app1@contoso.com" target="_blank" rel="noopener"&gt;app1@contoso.com&lt;/A&gt; sends to &lt;A href="mailto:john@contoso.com" target="_blank" rel="noopener"&gt;john@contoso.com&lt;/A&gt;): Use the default connector, no need to create a new one.&lt;/LI&gt;
&lt;LI&gt;If your applications are sending authenticated emails through Basic Auth or Integrated Windows using contoso.com as sender SMTP address to any recipient (&lt;A href="mailto:app1@contoso.com" target="_blank" rel="noopener"&gt;app1@contoso.com&lt;/A&gt; sends to &lt;A href="mailto:john@contoso.com" target="_blank" rel="noopener"&gt;john@contoso.com&lt;/A&gt; and &lt;A href="mailto:adele@fabrikam.com" target="_blank" rel="noopener"&gt;adele@fabrikam.com&lt;/A&gt;):&lt;/LI&gt;
&lt;/UL&gt;
&lt;OL&gt;
&lt;LI&gt;Create a new Receive Connector with &lt;STRONG&gt;ExchangeUsers &lt;/STRONG&gt;Permission Group, assign the Authentication mechanism as &lt;STRONG&gt;BasicAuth&lt;/STRONG&gt; and/or &lt;STRONG&gt;Integrated &lt;/STRONG&gt;and add the IP or range of your applications to &lt;STRONG&gt;RemoteIPRanges: &lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;PRE&gt;New-ReceiveConnector -Name "BasicAuth" -AuthMechanism BasicAuth -RemoteIPRanges "192.168.0.1" -PermissionGroups ExchangeUsers -Custom -Bindings 0.0.0.0:25&lt;/PRE&gt;
&lt;OL start="2"&gt;
&lt;LI&gt;And add the permission &lt;STRONG&gt;ms-Exch-SMTP-Accept-Authoritative-Domain-Sender &lt;/STRONG&gt;to the connector. As mentioned before, since Edge Transport doesn’t have Resolve engine, it cannot validate the primary SMTP address of the authenticated user, otherwise you will get the “&lt;EM&gt;550 5.7.60 SMTP; Client does not have permissions to send as this sender” &lt;/EM&gt;error.&lt;/LI&gt;
&lt;/OL&gt;
&lt;PRE&gt;Get-ReceiveConnector BasicAuth | Add-ADPermission -User "NT AUTHORITY\Authenticated Users" -ExtendedRights "ms-Exch-SMTP-Accept-Authoritative-Domain-Sender"&lt;/PRE&gt;
&lt;UL&gt;
&lt;LI&gt;If your applications require an &lt;EM&gt;open relay&lt;/EM&gt;, although not recommended, you can follow the steps described in this &lt;A href="https://learn.microsoft.com/exchange/mail-flow/connectors/allow-anonymous-relay" target="_blank" rel="noopener"&gt;article&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Send connector&lt;/H3&gt;
&lt;P&gt;In a fresh Exchange Edge Transport installation, no Send connector is created by default. Therefore, you will need to configure it from scratch.&lt;/P&gt;
&lt;P&gt;As highlighted earlier, it is essential to first understand how your existing IIS SMTP server handles outbound relay. This includes determining whether it uses:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Direct DNS resolution, or a smarthost (and any associated Basic authentication)&lt;/LI&gt;
&lt;LI&gt;Whether you want to have different routes per domain&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This information will directly influence the configuration of your Send connector on the Edge Transport server. You can refer to the relevant &lt;A href="https://learn.microsoft.com/powershell/module/exchangepowershell/new-sendconnector?view=exchange-ps" target="_blank" rel="noopener"&gt;documentation&lt;/A&gt; for detailed guidance on the required commands and parameters to properly create and configure the Send Connector.&lt;/P&gt;
&lt;H3&gt;Switch the mail flow&lt;/H3&gt;
&lt;P&gt;At this stage, the IIS SMTP assessment should already be complete, and you should understand how applications connect to it – a DNS record or a hard-coded IP address.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;If a DNS alias is used&lt;/STRONG&gt; (e.g., CNAME or A record):&lt;BR /&gt;The transition is typically straightforward. You can redirect mail flow by updating the DNS record to point to the Exchange Edge Transport server.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;If applications use a hard-coded IP address:&lt;/STRONG&gt;&lt;BR /&gt;Consider reusing the existing IIS SMTP IP address. The process is relatively simple:
&lt;UL&gt;
&lt;LI&gt;Disable the network interface (NIC) on the IIS SMTP server&lt;/LI&gt;
&lt;LI&gt;Assign the IIS SMTP server IP address as a secondary IP on the Exchange Edge Transport server&lt;/LI&gt;
&lt;LI&gt;Update the existing DNS A record associated with the IIS SMTP server to point to the Exchange Edge Transport server&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;As a best practice, always validate mail flow with a subset of applications before performing the full cutover. This helps identify potential issues early and ensures a smooth transition.&lt;/P&gt;
&lt;H3&gt;(Optional) Setting Exchange Online as a smarthost&lt;/H3&gt;
&lt;P&gt;If you have Exchange Online tenant, you can use your standalone Edge Transport to relay emails through Exchange Online by configuring your tenant MX as a smarthost in the Edge’s Send connector. Although not required, we encourage you to bind a certificate with the same domain name that you have in your Exchange Online as Accepted Domain. This would ensure a proper &lt;A href="https://techcommunity.microsoft.com/blog/exchange/office-365-message-attribution/749143" target="_blank" rel="noopener"&gt;message attribution&lt;/A&gt; process and your emails coming from Edge Transport will be marked as Originating.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;First, you need to figure out what is the MX record of your tenant, please follow this &lt;A href="https://learn.microsoft.com/exchange/mail-flow-best-practices/how-to-set-up-a-multifunction-device-or-application-to-send-email-using-microsoft-365-or-office-365#appendix-find-the-mx-record-for-the-chosen-accepted-domain-in-microsoft-365-or-office-365" target="_blank" rel="noopener"&gt;appendix&lt;/A&gt; to get this information.&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/powershell/module/exchangepowershell/set-sendconnector?view=exchange-ps#-smarthosts" target="_blank" rel="noopener"&gt;Add the value to your Send connector as a smarthost&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/powershell/module/exchangepowershell/enable-exchangecertificate?view=exchange-ps" target="_blank" rel="noopener"&gt;Import the certificate to the Personal computer container and assign the SMTP service to it&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Bind the certificate to the Send connector&lt;/LI&gt;
&lt;/UL&gt;
&lt;PRE&gt;$Cert = Get-ExchangeCertificate -Thumbprint "&amp;lt;new certificate thumbprint&amp;gt;"&lt;BR /&gt;&lt;BR /&gt;$TLSCertificateName = "&amp;lt;i&amp;gt;$($Cert.Issuer)&amp;lt;s&amp;gt;$($Cert.Subject)"&lt;BR /&gt;&lt;BR /&gt;Set-SendConnector -Identity "Send Connector Identity" -TlsCertificateName $TLSCertificateName&lt;/PRE&gt;
&lt;UL&gt;
&lt;LI&gt;Set the following properties on the connector:&lt;/LI&gt;
&lt;/UL&gt;
&lt;PRE&gt;Set-SendConnector -Identity "Send Connector Identity" -RequireTLS $True -TlsAuthLevel DomainValidation -TlsDomain mail.protection.outlook.com&lt;/PRE&gt;
&lt;UL&gt;
&lt;LI&gt;Now we need to create the Inbound connector in Exchange Online to attribute these messages coming from the Exchange Edge Transport:&lt;/LI&gt;
&lt;/UL&gt;
&lt;PRE&gt;New-InboundConnector -Name "FromEdgeTransport" -ConnectorType OnPremises -SenderDomains * -RequireTls $True -TlsSenderCertificateName "Your Certificate CN"&lt;/PRE&gt;
&lt;P&gt;Lastly, ensure to add the EOP and your Edge Transport public IP to the SPF record in the public DNS as described &lt;A href="https://learn.microsoft.com/microsoft-365/enterprise/external-domain-name-system-records?view=o365-worldwide#external-dns-records-required-for-spf" target="_blank" rel="noopener"&gt;here&lt;/A&gt;. This is an important step to avoid either external recipients marking your emails as spoofing or the EOP itself marking emails from your Edge as spoofing. If you want to increase your security posture, you can also &lt;A href="https://learn.microsoft.com/defender-office-365/email-authentication-dkim-configure" target="_blank" rel="noopener"&gt;enable DKIM&lt;/A&gt; and create your &lt;A href="https://learn.microsoft.com/defender-office-365/email-authentication-dmarc-configure" target="_blank" rel="noopener"&gt;DMARC policy for your domains&lt;/A&gt;.&lt;/P&gt;
&lt;H3&gt;FAQ&lt;/H3&gt;
&lt;P&gt;&lt;STRONG&gt;How to figure out domain or local accounts being used on IIS SMTP to send using Basic Authentication?&lt;BR /&gt;&lt;/STRONG&gt;Unfortunately, the IIS SMTP logs will not show what account has been used to perform basic authentication when sending emails. The following XML query can be used to filter Security event viewer logs:&lt;/P&gt;
&lt;PRE&gt;&amp;lt;QueryList&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;lt;Query Id="0" Path="Security"&amp;gt;&lt;BR /&gt;&amp;nbsp; &amp;lt;Select Path="Security"&amp;gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; *[System[(EventID=4624)]]&lt;BR /&gt;&amp;nbsp; &amp;nbsp; and&lt;BR /&gt;&amp;nbsp; &amp;nbsp; *[EventData[Data[@Name='LogonType']='3']]&lt;BR /&gt;&amp;nbsp; &amp;nbsp; and&lt;BR /&gt;&amp;nbsp; &amp;nbsp; *[EventData[Data[@Name='ProcessName']='C:\Windows\System32\inetsrv\inetinfo.exe']]&lt;BR /&gt;&amp;nbsp; &amp;nbsp;&amp;lt;/Select&amp;gt;&lt;BR /&gt;&amp;nbsp; &amp;lt;/Query&amp;gt;&lt;BR /&gt;&amp;lt;/QueryList&amp;gt;&lt;/PRE&gt;
&lt;P&gt;&lt;STRONG&gt;What’s the benefit of getting rid of IIS 6.0 SMTP and moving to an Exchange Edge Transport?&lt;BR /&gt;&lt;/STRONG&gt;IIS 6.0 is no longer supported, and therefore you should not expect any security updates or assistance from Microsoft Support. From a technical perspective, the Exchange Edge Transport role provides significantly more capabilities and control over mail flow, including:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Enhanced logs such as message tracking logs and pipeline tracing&lt;/LI&gt;
&lt;LI&gt;Improved security and control mechanisms&lt;/LI&gt;
&lt;LI&gt;The ability to implement transport rules (although more limited compared to a full Exchange Mailbox role)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Overall, Exchange Edge Transport represents a more modern, secure, and manageable solution compared to legacy IIS SMTP.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Can we use Address Rewrite feature in a standalone Edge Transport?&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;Yes, but there are important caveats to consider.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Inbound Address Rewrite is supported and works as expected on a standalone Edge Transport. You can safely follow the standard procedure described in the &lt;A href="https://learn.microsoft.com/exchange/architecture/edge-transport-servers/address-rewriting-procedures" target="_blank" rel="noopener"&gt;documentation&lt;/A&gt; to implement it.&lt;/P&gt;
&lt;P&gt;The Outbound Address Rewrite has some limitations that you should be aware of. This feature depends on the &lt;STRONG&gt;Address Rewriting Outbound Agent&lt;/STRONG&gt;, which is only triggered when the MAIL FROM is treated as authenticated. Specifically, the agent relies on the presence of the header: &lt;EM&gt;X-MS-Exchange-Organization-AuthAs: Internal.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;At first glance, you might assume that using Basic Authentication or Integrated Windows Authentication would satisfy this requirement. However, this is &lt;STRONG&gt;not the case&lt;/STRONG&gt; for a standalone Edge Transport deployment. Regardless of the authentication method used when submitting messages to a standalone Edge Transport, the header &lt;EM&gt;X-MS-Exchange-Organization-AuthAs&lt;/EM&gt; is always stamped as &lt;STRONG&gt;Anonymous&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;As a result, the Outbound Address Rewrite agent is never triggered under normal conditions.&lt;/P&gt;
&lt;P&gt;The only supported workaround to force the standalone Edge Transport to treat messages as internal – and therefore enable outbound address rewriting – is to configure the receive connector with the &lt;A href="https://learn.microsoft.com/exchange/mail-flow/connectors/allow-anonymous-relay#configure-the-connections-as-externally-secured" target="_blank" rel="noopener"&gt;&lt;EM&gt;ExternalAuthoritative&lt;/EM&gt;&lt;/A&gt; authentication mechanism. This effectively promotes the &lt;EM&gt;AuthAs&lt;/EM&gt; value to &lt;STRONG&gt;Internal&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;Enabling &lt;EM&gt;ExternalAuthoritative&lt;/EM&gt; effectively turns the receive connector into an &lt;EM&gt;open relay&lt;/EM&gt;. You must therefore implement appropriate restrictions (such as IP scoping and strict access controls) to secure the connector and prevent abuse. Refer to this &lt;A href="https://techcommunity.microsoft.com/blog/exchange/why-is-my-address-rewriting-not-working-as-expected/607458" target="_blank" rel="noopener"&gt;article&lt;/A&gt; for further information.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;How does Microsoft 365 IP throttling deal with messages coming from a standalone Edge Transport?&lt;/STRONG&gt;&lt;BR /&gt;In the same way as it handles in Hybrid mail flow if you followed our recommendation stated on “Setting Exchange Online as smarthost” section. If you had a Hybrid Exchange on-premises and are moving to a standalone Edge Transport, our advice is to keep the same public IP used by your previous Exchange Server on the new Edge Transport since this IP will have a sending history and clean reputation.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Can we deploy a standalone Edge Transport as an Azure VM?&lt;/STRONG&gt;&lt;BR /&gt;You can but consider that outbound SMTP on Azure VMs is only supported if you have Enterprise Agreement or Microsoft Customer Agreement for enterprise (MCA-E) subscriptions. For more information see this &lt;A href="https://learn.microsoft.com/troubleshoot/azure/virtual-network/troubleshoot-outbound-smtp-connectivity" target="_blank" rel="noopener"&gt;article&lt;/A&gt;. Additionally, you may need to establish proper network connectivity from your applications to the Azure VM. This typically requires configuring network routing – such as Azure ExpressRoute – to enable your on-premises traffic to reach the Edge Transport VM securely and reliably.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Edge Transport is configured to use Exchange Online as smarthost but emails are being received as “AuthAs:Anonymous”. Can we change this behavior marking messages as Internal?&lt;/STRONG&gt;&lt;BR /&gt;The Edge Transport role does not perform header promotion regardless if Edge is subscribed to a Mailbox Exchange Server or standalone. It is up to the Mailbox role to promote &lt;EM&gt;Organization&lt;/EM&gt; headers to &lt;EM&gt;CrossPremises&lt;/EM&gt; and then the Edge just honors the promotion. Refer to this &lt;A href="https://techcommunity.microsoft.com/blog/exchange/demystifying-and-troubleshooting-hybrid-mail-flow-when-is-a-message-internal/1420838" target="_blank" rel="noopener"&gt;article&lt;/A&gt; to find more information about header promotion. The only way to enforce “AuthAs:Internal” on messages coming from an Edge Transport is enabling &lt;A href="https://learn.microsoft.com/powershell/module/exchangepowershell/set-inboundconnector?view=exchange-ps#-treatmessagesasinternal" target="_blank" rel="noopener"&gt;&lt;EM&gt;TreatMessagesAsInternal&lt;/EM&gt;&lt;/A&gt;&lt;EM&gt; &lt;/EM&gt;attribute on Exchange Online Inbound connector. This option works only if sender domain matches an accepted domain in Exchange Online.&lt;/P&gt;
&lt;P&gt;Thanks to Arindam Thokder for his support and review of this article.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-12"&gt;Denis Vilaça Signorelli&lt;/SPAN&gt;&lt;BR /&gt;Cloud Solution Architect&lt;/P&gt;</description>
      <pubDate>Tue, 19 May 2026 14:14:31 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/exchange-team-blog/replacing-iis-smtp-virtual-server-with-exchange-edge-transport/ba-p/4521241</guid>
      <dc:creator>The_Exchange_Team</dc:creator>
      <dc:date>2026-05-19T14:14:31Z</dc:date>
    </item>
    <item>
      <title>Writeback for Cloud-Managed Remote Mailboxes: Now in Public Preview</title>
      <link>https://techcommunity.microsoft.com/t5/exchange-team-blog/writeback-for-cloud-managed-remote-mailboxes-now-in-public/ba-p/4520138</link>
      <description>&lt;P&gt;In our previous posts, we announced the &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/exchange/introducing-cloud-managed-remote-mailboxes-a-step-to-last-exchange-server-retire/4446042" data-lia-auto-title="Public Preview" data-lia-auto-title-active="0" target="_blank"&gt;Public Preview&lt;/A&gt; and the &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/exchange/cloud-managed-remote-mailboxes-now-generally-available/4461705" data-lia-auto-title=" General Availability " data-lia-auto-title-active="0" target="_blank"&gt;General Availability &lt;/A&gt;of Cloud-Managed Remote Mailboxes – a key step toward retiring the 'last Exchange Server' in your organization. The response from the community has been incredible, and your feedback continues to shape the roadmap.&lt;/P&gt;
&lt;P&gt;Today, we're excited to share two new milestones in this journey:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/exchange/hybrid-deployment/enable-exchange-attributes-cloud-management#how-to-enable-exchange-attribute-writeback" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Writeback for Cloud-Managed Remote Mailboxes&lt;/STRONG&gt;&lt;/A&gt; is now in &lt;STRONG&gt;Public Preview&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;For customers with no remaining dependency on their last Exchange Server, a guide for &lt;A href="https://learn.microsoft.com/exchange/hybrid-deployment/decommission-last-exchange-server" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;decommissioning your last Exchange Server&lt;/STRONG&gt;&lt;/A&gt; is now published on Microsoft Learn.&lt;/LI&gt;
&lt;/OL&gt;
&lt;H3&gt;Writeback for Cloud-Managed Remote Mailboxes: Public Preview&lt;/H3&gt;
&lt;P&gt;When you set IsExchangeCloudManaged to True on a directory-synchronized mailbox, the Exchange-attribute Source of Authority (SOA) transfers to Exchange Online. The SOA for identity attributes (name, department, and so on) stays on-premises in Active Directory, but the Exchange-related attributes (proxy addresses, hide-from-address-book, custom attributes, and similar) become editable in the cloud.&lt;/P&gt;
&lt;P&gt;Until now, after transferring Exchange-attribute SOA to cloud those Exchange attributes were edited cloud-side only – they didn't flow back to on-premises AD. That gap was a problem for organizations whose on-premises line-of-business applications still read attributes like proxyAddresses, custom attributes, and similar directly from AD. Once SOA flipped to the cloud, the on-premises AD copy of these attributes would start drifting out of sync with the cloud.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Writeback closes that gap.&lt;/STRONG&gt; With writeback enabled, changes made in Exchange Online to designated Exchange attributes are automatically pushed back to on-premises Active Directory through Microsoft Entra Cloud Sync. Your on-premises AD stays current, and your line-of-business applications keep working – even after the Exchange-attribute SOA has moved to the cloud.&lt;/P&gt;
&lt;H5&gt;How it works&lt;/H5&gt;
&lt;P&gt;Writeback uses &lt;STRONG&gt;Microsoft Entra Cloud Sync&lt;/STRONG&gt; as the transport from Exchange Online back to on-premises AD. If you already use Microsoft Entra Connect Sync, you do &lt;STRONG&gt;not&lt;/STRONG&gt; need to uninstall or replace it. Cloud Sync runs alongside Connect Sync – Connect Sync continues to handle your directory synchronization exactly as before, and Cloud Sync only handles the Exchange attribute writeback. There is no impact on your existing mailboxes, users, or sync configuration.&lt;/P&gt;
&lt;P&gt;Steps to install the Cloud Sync provisioning agent, configure the writeback synchronization job, and verify the round-trip flow are all in the documentation: &lt;A href="https://learn.microsoft.com/exchange/hybrid-deployment/enable-exchange-attributes-cloud-management" target="_blank" rel="noopener"&gt;Cloud-based management of Exchange attributes for Remote Mailboxes in hybrid environments&lt;/A&gt;.&lt;/P&gt;
&lt;H5&gt;Public Preview limits and GA timeline&lt;/H5&gt;
&lt;P&gt;During Public Preview, writeback supports tenants with &lt;STRONG&gt;fewer than 200,000 cloud-managed mailboxes&lt;/STRONG&gt;. We will raise this limit at General Availability, currently targeted for &lt;STRONG&gt;the end of June 2026&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;The complete list of attributes supported for writeback – which attributes flow back to AD and which don't – is available in &lt;A href="https://learn.microsoft.com/exchange/hybrid-deployment/enable-exchange-attributes-cloud-management#identity-exchange-attributes-and-writeback" target="_blank" rel="noopener"&gt;Identity, Exchange Attributes and Writeback&lt;/A&gt;.&lt;/P&gt;
&lt;H3&gt;New Documentation: Decommission the Last Exchange Server&lt;/H3&gt;
&lt;P&gt;Once your mailboxes are cloud-managed (and writeback is in place if your applications need it), the next question is the one this whole effort has been about: how do you actually retire the last Exchange Server?&lt;/P&gt;
&lt;P&gt;We've published a new end-to-end guide that walks through exactly that: &lt;A href="https://learn.microsoft.com/exchange/hybrid-deployment/decommission-last-exchange-server" target="_blank" rel="noopener"&gt;Decommission the last Exchange Server after transferring SOA to cloud&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;The guide covers:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Prerequisites&lt;/STRONG&gt; – confirming all mailboxes and public folders have moved to Exchange Online, all directory-synchronized mailboxes are cloud-managed, DNS and mail routing point at Exchange Online, and you've migrated any SMTP relay dependencies.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Pre-removal verification&lt;/STRONG&gt; – re-verifying each prerequisite immediately before starting, since the environment may have drifted.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Hybrid cleanup (while Exchange is still running)&lt;/STRONG&gt; – removing the Hybrid Configuration object, HCW-created intra-organization connector, hybrid connectors, organization relationship, federation trust and certificate, OAuth service principal credentials, and the Hybrid Agent (modern hybrid only).&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Uninstall the last Exchange Server&lt;/STRONG&gt; – final pre-uninstall checks and running Setup /m:Uninstall.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Hybrid cleanup in Exchange Online (post-uninstall)&lt;/STRONG&gt; – removing orphaned hybrid objects from the cloud side that the on-prem uninstall doesn't clean up.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If you've been holding off on removing your last Exchange Server because the procedure wasn't clearly documented end-to-end, this is the article you've been waiting for.&lt;/P&gt;
&lt;H3&gt;Get started&lt;/H3&gt;
&lt;P&gt;If you've been waiting for Writeback Public Preview to start your decommissioning journey, now is the time:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Review the &lt;A href="https://learn.microsoft.com/exchange/hybrid-deployment/enable-exchange-attributes-cloud-management" target="_blank" rel="noopener"&gt;updated documentation&lt;/A&gt; for the writeback setup walkthrough and the full attribute list.&lt;/LI&gt;
&lt;LI&gt;Read the &lt;A href="https://learn.microsoft.com/exchange/hybrid-deployment/decommission-last-exchange-server" target="_blank" rel="noopener"&gt;new decommissioning guide&lt;/A&gt; for the end-to-end uninstall procedure.&lt;/LI&gt;
&lt;LI&gt;In case the limit of 200k for Writeback feature blocks your adoption, please reach out to us through this &lt;A href="https://forms.cloud.microsoft/r/tAv0KeZ4RK" target="_blank" rel="noopener"&gt;form&lt;/A&gt;. As communicated, we will increasing the limit by GA timeframe, but it would be good to know what scale would unblock you.&lt;/LI&gt;
&lt;LI&gt;Share your experiences and suggestions in the comments below – your feedback shaped the previous releases, and we want it for this one too.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The era of maintaining an Exchange server "just because we sync our AD" is coming to an end.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-12"&gt;Exchange Online Management&lt;/SPAN&gt; and &lt;SPAN class="lia-text-color-12"&gt;Exchange Hybrid &lt;/SPAN&gt;teams&lt;/P&gt;</description>
      <pubDate>Fri, 15 May 2026 17:37:57 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/exchange-team-blog/writeback-for-cloud-managed-remote-mailboxes-now-in-public/ba-p/4520138</guid>
      <dc:creator>The_Exchange_Team</dc:creator>
      <dc:date>2026-05-15T17:37:57Z</dc:date>
    </item>
    <item>
      <title>Addressing Exchange Server May 2026 vulnerability CVE-2026-42897</title>
      <link>https://techcommunity.microsoft.com/t5/exchange-team-blog/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/ba-p/4518498</link>
      <description>&lt;P style="background: #66FF99; padding: .5em; margin: 1em 0 1em 0;"&gt;&lt;STRONG&gt;UPDATE July 14, 2026:&lt;/STRONG&gt; Please see our release blog post for July 2026 Security Update, which, once installed, removes our recommendation to keep CVE-2026-42897 mitigation in place:&lt;A href="https://techcommunity.microsoft.com/blog/exchange/released-july-2026-exchange-server-security-updates/4534146" target="_blank"&gt;&amp;nbsp;Released: July 2026 Exchange Server Security Updates | Microsoft Community Hub&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;On May 14, 2026, Microsoft disclosed&amp;nbsp;&lt;A href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42897" target="_blank" rel="noopener"&gt;CVE-2026-42897&lt;/A&gt;, a reported vulnerability affecting Exchange Outlook Web Access (OWA). An attacker could exploit this issue by sending a specially crafted email to a user. If the user opens the email in Outlook Web Access and certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.&lt;/P&gt;
&lt;P&gt;The following on-premises Exchange Server versions are impacted:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Exchange Server 2016 (any update level)&lt;/LI&gt;
&lt;LI&gt;Exchange Server 2019 (any update level)&lt;/LI&gt;
&lt;LI&gt;Exchange Server Subscription Edition (SE) (any update level)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;EM&gt;Exchange Online is not impacted by this vulnerability.&lt;/EM&gt;&lt;/P&gt;
&lt;H3&gt;Mitigations&lt;/H3&gt;
&lt;H5&gt;&lt;STRONG&gt;Option 1 (recommended): Exchange Emergency Mitigation (EM) Service&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;For customers who have the &lt;A href="https://learn.microsoft.com/exchange/plan-and-deploy/post-installation-tasks/security-best-practices/exchange-emergency-mitigation-service" target="_blank" rel="noopener"&gt;Exchange EM Service&lt;/A&gt; enabled, Microsoft released the automatic mitigation for Exchange Server 2016, 2019 and SE. The mitigation is already published and is enabled automatically.&lt;/P&gt;
&lt;P&gt;As a reminder – EM Service was released in September 2021 and is enabled by default. More information on this service can be found in &lt;A href="https://learn.microsoft.com/exchange/plan-and-deploy/post-installation-tasks/security-best-practices/exchange-emergency-mitigation-service" target="_blank" rel="noopener"&gt;Exchange Emergency Mitigation Service (Exchange EM Service) | Microsoft Learn&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Customers with EM Service enabled can verify that their servers have applied the mitigation for CVE-2026-42897 (the ID of mitigation is M2.1.x) by doing the following:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Follow the steps outlined in the documentation: &lt;A href="https://learn.microsoft.com/exchange/plan-and-deploy/post-installation-tasks/security-best-practices/exchange-emergency-mitigation-service#viewing-applied-mitigations" target="_blank" rel="noopener"&gt;Viewing Applied Mitigations&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;To quickly check the status of EM Service and applied mitigations in your organization, you can run Exchange Health Checker script:&amp;nbsp;&lt;A style="font-style: normal; font-weight: 400; background-color: rgb(255, 255, 255);" href="https://aka.ms/ExchangeHealthChecker" target="_blank" rel="noopener"&gt;https://aka.ms/ExchangeHealthChecker&lt;/A&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;. The HTML report will include a section on &lt;/SPAN&gt;&lt;A style="font-style: normal; font-weight: 400; background-color: rgb(255, 255, 255);" href="https://microsoft.github.io/CSS-Exchange/Diagnostics/HealthChecker/EEMSCheck/" target="_blank" rel="noopener"&gt;EEMS check&lt;/A&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt; results.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Using EM Service is the best way for your organization to mitigate this vulnerability right away. If you have EM Service currently disabled, we recommend you enable it right away.&lt;/P&gt;
&lt;P&gt;Please note that EM Service will not be able to check for new mitigations if your server is running Exchange Server version older than March 2023 as per &lt;A href="https://techcommunity.microsoft.com/blog/exchange/exchange-emergency-mitigation-service-might-not-work-for-servers-significantly-o/4370312" target="_blank" rel="noopener"&gt;this article&lt;/A&gt;. To check the exact version of Exchange currently in use, utilize Option 1 or Option 2 mentioned on this page: &lt;A href="https://learn.microsoft.com/exchange/new-features/build-numbers-and-release-dates" target="_blank" rel="noopener"&gt;Exchange Server build numbers and release dates | Microsoft Learn&lt;/A&gt;.&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;Option 2: Scripted application of mitigation&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;For customers who are unable to use the EM Service (for example, disconnected or air-gapped environments), we are providing the following process to enable this mitigation:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Download the latest version of the Exchange on-premises Mitigation Tool (EOMT) from:&lt;/LI&gt;
&lt;/OL&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;A href="https://aka.ms/UnifiedEOMT" target="_blank" rel="noopener"&gt;https://aka.ms/UnifiedEOMT&lt;/A&gt;&lt;/P&gt;
&lt;OL start="2"&gt;
&lt;LI&gt;Apply the mitigation on a per server base or on all servers at once by running the script via an elevated Exchange Management Shell (EMS):&lt;/LI&gt;
&lt;/OL&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;Single server:&lt;/STRONG&gt;&lt;/P&gt;
&lt;PRE class="lia-indent-padding-left-30px"&gt;.\EOMT.ps1 -CVE "CVE-2026-42897"&lt;/PRE&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;All servers:&lt;/STRONG&gt;&lt;/P&gt;
&lt;PRE class="lia-indent-padding-left-30px"&gt;Get-ExchangeServer | Where-Object { $_.ServerRole -ne "Edge" } | .\EOMT.ps1 -CVE "CVE-2026-42897"&lt;/PRE&gt;
&lt;P style="background: #F0F0F0; padding: .5em; margin: 1em 0 1em 0;"&gt;Please note that mitigations do not work if the client that is used to access OWA is Internet Explorer or Microsoft Edge using Internet Explorer Mode. Internet Explorer does not support Content Security Policy (CSP).&lt;/P&gt;
&lt;H4&gt;Known issues when mitigation is applied&lt;/H4&gt;
&lt;P&gt;We are aware of following known issues once CVE-2026-42897 mitigation is applied (using either option above):&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;OWA Print Calendar functionality might not work. As a workaround copy the data or screenshot the calendar you want to print or use Outlook Desktop client.&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Inline images might not display correctly in the recipients OWA reading pane. As a workaround, send images as email attachments or use Outlook Desktop client.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;OWA light (OWA URL ending in &lt;EM&gt;/?layout=light&lt;/EM&gt;) does not work properly. Please note that this feature has been &lt;A class="lia-external-url" href="https://support.microsoft.com/en-us/office/learn-more-about-the-light-version-of-outlook-2aec8c2d-da48-4707-ba37-c800e1c284cd" target="_blank" rel="noopener"&gt;deprecated several years ago&lt;/A&gt; and is not intended for regular production use. OWA light is going to be &lt;EM&gt;permanently disabled&lt;/EM&gt; in next several months. Please see &lt;A href="https://techcommunity.microsoft.com/blog/exchange/upcoming-retirement-of-owa-light-in-exchange-server/4534943" target="_blank" rel="noopener"&gt;Upcoming retirement of OWA Light in Exchange Server | Microsoft Community Hub&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;OWACalendar.Proxy healthset might start showing unhealthy once the mitigation is in effect. This can cause alerts if you use various monitoring solutions for your Exchange Server. If you see this problem, we recommend ignoring those alerts within your monitoring platform until the fix is out and mitigation is removed.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;Published calendars might not work with error 500.&lt;/LI&gt;
&lt;LI&gt;We are aware of the mitigation showing the "Mitigation invalid for this exchange version." in mitigation details. This issue is cosmetic and the mitigation DOES apply successfully if the status is shown as "Applied". We are investigating on how to address this.&lt;/LI&gt;
&lt;/UL&gt;
&lt;img /&gt;
&lt;H3&gt;Addressing the vulnerability permanently&lt;/H3&gt;
&lt;P&gt;Microsoft is working on and will release and announce a security update for impacted versions of Exchange Server in the future. Please read more about the update released: &lt;A href="https://techcommunity.microsoft.com/blog/exchange/released-june-2026-exchange-server-security-updates/4524491" target="_blank" rel="noopener"&gt;Released: June 2026 Exchange Server Security Updates | Microsoft Community Hub&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Please note that Exchange SE update will be released as a publicly available security update. Exchange 2016 and 2019 updates will be released only to customers who are enrolled in the Period 2 Exchange Server ESU program as per &lt;A href="https://techcommunity.microsoft.com/blog/exchange/announcing-period-2-exchange-20162019-extended-security-update-esu-program/4511603" target="_blank" rel="noopener"&gt;Announcing Period 2 Exchange 2016/2019 Extended Security Update (ESU) program&lt;/A&gt;. &lt;EM&gt;&lt;U&gt;Period 1 only ESU customers will not receive this update as that ESU program ended in April 2026&lt;/U&gt;&lt;/EM&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Updates to this blog post:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;7/8/2026: Added a note about upcoming permanent disablement of OWA light &lt;A href="https://techcommunity.microsoft.com/blog/exchange/upcoming-retirement-of-owa-light-in-exchange-server/4534943" target="_blank" rel="noopener"&gt;Upcoming retirement of OWA Light in Exchange Server | Microsoft Community Hub&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;6/9/2026: Update to reflect&amp;nbsp;&lt;A href="https://techcommunity.microsoft.com/blog/exchange/released-june-2026-exchange-server-security-updates/4524491" target="_blank" rel="noopener"&gt;Released: June 2026 Exchange Server Security Updates | Microsoft Community Hub&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;5/20/2026: Added a published calendars known issue.&lt;/LI&gt;
&lt;LI&gt;5/18/2026: Added a note that mitigations do not protect Internet Explorer or Microsoft Edge with Internet Explorer mode clients.&lt;/LI&gt;
&lt;LI&gt;5/17/2026: Added a known issue with OWACalendar.Proxy healthset showing unhelathy (impact if using Exchange Server monitoring).&lt;/LI&gt;
&lt;LI&gt;5/14/2026: Added a known issue with OWA Light.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;5/14/2026: Added the mitigation ID (M2.1.x).&lt;/LI&gt;
&lt;LI&gt;5/14/2026: Added a known issue with mitigation details displaying incorrect Description.&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-12"&gt;The Exchange Server Team&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2026 17:29:12 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/exchange-team-blog/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/ba-p/4518498</guid>
      <dc:creator>The_Exchange_Team</dc:creator>
      <dc:date>2026-07-14T17:29:12Z</dc:date>
    </item>
    <item>
      <title>No Exchange Server Security Updates for May 2026</title>
      <link>https://techcommunity.microsoft.com/t5/exchange-team-blog/no-exchange-server-security-updates-for-may-2026/ba-p/4519008</link>
      <description>&lt;P&gt;We wanted to let the Exchange Server community know that there are no security releases for any version of Exchange Server in May 2026, for customers with Exchange SE, or&amp;nbsp;&lt;A href="https://techcommunity.microsoft.com/blog/exchange/announcing-period-2-exchange-20162019-extended-security-update-esu-program/4511603" target="_blank" rel="noopener"&gt;Exchange 2016 or 2019 ESU&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Please keep &lt;A href="https://techcommunity.microsoft.com/blog/exchange/upgrading-your-organization-from-current-versions-to-exchange-server-se/4241305" target="_blank" rel="noopener"&gt;upgrading your organizations to Exchange SE&lt;/A&gt;.&lt;/P&gt;
&lt;P style="background: #F0F0F0; padding: .5em; margin: 1em 0 1em 0;"&gt;&lt;STRONG&gt;Update 5/14/2026: &lt;/STRONG&gt;While there is no security release (Security Update) in May 2026, please see our later blog post mentioning a mitigation for an Exchange Server CVE disclosed on May 14: &lt;A href="https://techcommunity.microsoft.com/blog/Exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498" target="_blank"&gt;Addressing Exchange Server May 2026 vulnerability CVE-2026-42897 | Microsoft Community Hub&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-12"&gt;The Exchange Team&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2026 17:07:44 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/exchange-team-blog/no-exchange-server-security-updates-for-may-2026/ba-p/4519008</guid>
      <dc:creator>The_Exchange_Team</dc:creator>
      <dc:date>2026-05-14T17:07:44Z</dc:date>
    </item>
    <item>
      <title>Retirement of Direct Exchange ActiveSync Certificate-Based Authentication by End of 2026</title>
      <link>https://techcommunity.microsoft.com/t5/exchange-team-blog/retirement-of-direct-exchange-activesync-certificate-based/ba-p/4517896</link>
      <description>&lt;P&gt;We are announcing the deprecation of &lt;STRONG&gt;Exchange ActiveSync (EAS) certificate-based authentication (CBA) directly to Exchange Online&lt;/STRONG&gt;. By the &lt;STRONG&gt;end of 2026&lt;/STRONG&gt;, Microsoft will &lt;STRONG&gt;no longer support direct CBA connections&lt;/STRONG&gt; from EAS mobile email clients to Exchange Online. After that date, &lt;STRONG&gt;any EAS clients using CBA will need to authenticate via Microsoft Entra ID &lt;/STRONG&gt;rather than sending client certificates directly to Exchange Online.&lt;/P&gt;
&lt;P&gt;With immediate effect, we will roll out blocks so no new tenants can use the legacy flow, ensuring they can take advantage of the benefits of using the Entra ID flow from the very start.&lt;/P&gt;
&lt;P style="background: #F0F0F0; padding: .5em; margin: 1em 0 1em 0;"&gt;&lt;STRONG&gt;Important:&lt;/STRONG&gt; This change &lt;STRONG&gt;does not affect other Exchange Online authentication scenarios such as Outlook Mobile or Exchange Server/on-premises&lt;/STRONG&gt;. It is &lt;EM&gt;specific to Exchange ActiveSync (EAS) clients (such as native built-in mobile email apps) using CBA against Exchange Online&lt;/EM&gt;. This retirement is part of our ongoing efforts to strengthen security by eliminating legacy auth patterns in Exchange Online.&lt;/P&gt;
&lt;H4&gt;Why Are We Retiring Direct EAS CBA?&lt;/H4&gt;
&lt;P&gt;Certificate-based authentication for EAS was introduced as a way for organizations to allow mobile device access without passwords, using client certificates for a highly secure, passwordless sign-in experience. With CBA, each user has a certificate verified by the tenant's root certificate authority, and the user can authenticate via a TLS handshake using the public key of that certificate – meaning no private key or password is ever sent over the network, providing a more secure alternative to basic authentication. The previously published guidance for this config is &lt;A href="https://techcommunity.microsoft.com/blog/exchange/certificate-based-authentication-cba-for-exchange-online/605173" target="_blank"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;However, the &lt;STRONG&gt;current direct-to-Exchange implementation of EAS CBA is considered a legacy authentication method&lt;/STRONG&gt;. In the present flow, user certificates are pushed to mobile devices during configuration. When users connect to EAS to sync email, Exchange receives the certificate and does all the onward processing and validation itself.&lt;/P&gt;
&lt;P&gt;This design presents a significant concern as the client itself never obtains a standard OAuth access token – a &lt;STRONG&gt;departure from modern authentication practices&lt;/STRONG&gt; – and Exchange relies on this internal, high-privilege mechanism to access data. Furthermore, Azure AD classifies direct certificate-based authentication between the client and Exchange Online as a form of "legacy authentication," meaning it will be blocked by any Azure AD conditional access policies that block legacy authentication. This creates an all-or-nothing challenge for administrators trying to enforce modern security controls while still allowing CBA.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;The new model requires EAS clients to perform certificate-based authentication directly via Microsoft Entra ID&lt;/STRONG&gt;, just as other client apps do. The proposed secure flow works as follows: the client sends its certificate to Entra ID (Azure AD) for validation; Entra ID validates the certificate and returns an OAuth access token to the client; the client then presents this OAuth token to Exchange Online for authentication. By moving certificate authentication fully into Microsoft Entra ID, &lt;STRONG&gt;admins can uniformly enforce modern security controls and policies&lt;/STRONG&gt; for all client access, with no exceptions for certain protocols.&lt;/P&gt;
&lt;P&gt;This change also continues our &lt;STRONG&gt;ongoing effort to modernize Exchange Online authentication stack&lt;/STRONG&gt;. Over the past few years, we have phased out older authentication methods like Basic Auth, and we recently introduced dedicated ActiveSync CBA endpoints – such as outlook-cba.office365.com for worldwide multi-tenant, outlook-dod-cba.office365.us for DoD, and outlook-cba.office365.us for GCC-High – to support TLS 1.3 and strengthen security and reliability. Requiring Entra-based CBA is the next logical step in this journey, closing one of the last remaining gaps in legacy auth removal.&lt;/P&gt;
&lt;img /&gt;
&lt;H4&gt;How do I know if I am Impacted?&lt;/H4&gt;
&lt;P&gt;If you aren’t sure if you use Exchange ActiveSync CBA or Entra-Based CBA, there’s a couple of ways you can figure that out.&lt;/P&gt;
&lt;P&gt;Firstly, ask the person who manages your Mobile Device Management (MDM) configuration. If the auth type used is set as Certificate, rather than OAuth, that could indicate you use this configuration.&lt;/P&gt;
&lt;P&gt;The other method is to check Entra’s sign-in event logs. Requests using Exchange CBA show up with the client app of ‘Exchange ActiveSync’, and Authentication Details will show a certificate is being used. Here’s how that flow looks in Entra’s sign-in logs reports:&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;"Certificate” would be shown as Authentication method:&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;We will send Message Center posts to tenants using Exchange CBA in the next week calling attention to this change. We’ll update this post once those posts have been sent.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Please note that CBA authentication is something that you must configure deliberately and if your organization never configured it, this deprecation does not impact you.&lt;/EM&gt;&lt;/P&gt;
&lt;H4&gt;How to Migrate to Entra-Based CBA&lt;/H4&gt;
&lt;P&gt;We understand that some organizations have been relying on CBA with Exchange ActiveSync to enhance mobile device security. To ensure a smooth transition, we recommend administrators start planning &lt;STRONG&gt;now&lt;/STRONG&gt; to move those devices to the new Entra ID-based CBA method well &lt;STRONG&gt;before the end-of-2026 deadline&lt;/STRONG&gt;. The PKI and CA setup for Entra CBA and EAS CBA are fundamentally the same, which should simplify the transition. Below are key steps and considerations for a successful migration:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Enable Microsoft Entra CBA for your Tenant:&lt;/STRONG&gt; Ensure your certificate authorities (CA) are configured in Microsoft Entra ID. At least one CA and any intermediate CAs must be configured, each user needs access to a certificate issued from a trusted PKI, and each CA should have a certificate revocation list (CRL) referenceable from an internet-facing URL. Microsoft provides detailed guidance on setting up Entra CBA in &lt;A href="https://learn.microsoft.com/entra/identity/authentication/how-to-certificate-based-authentication" target="_blank"&gt;documentation&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Prepare User Certificates:&lt;/STRONG&gt; Verify that each user's client certificate contains the correct identity information. &lt;STRONG&gt;For Exchange ActiveSync clients specifically, the certificate must include the user's routable email address&lt;/STRONG&gt; in Exchange Online, in either the Principal Name or the RFC822 Name value of the Subject Alternative Name (SAN) field. Microsoft Entra ID maps the RFC822 value to the Proxy Address attribute in the directory. More info &lt;A href="https://learn.microsoft.com/entra/identity/authentication/certificate-based-authentication-federation-get-started" target="_blank"&gt;here&lt;/A&gt;. If your current certificates were used for direct EAS CBA, they likely already meet this requirement – just verify the presence of the user's email in the certificate's SAN.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Update Device Configuration:&lt;/STRONG&gt; Plan how your mobile devices will perform certificate authentication against Entra ID. In many cases, this may involve updating the device's email profile or MDM/Intune device configuration profiles. The new flow might require collaboration with third-party client vendors to support the change. Consult your mobile device or mail app vendor for specific instructions on enabling Entra (Azure AD) authentication with client certificates. When the feature is configured, users will see a certificate selection prompt during sign-in rather than entering a password.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Test and Monitor:&lt;/STRONG&gt; We recommend testing the new Entra CBA login flow with a pilot group of devices and users before broad rollout. Monitor your Entra ID sign-in logs and Exchange ActiveSync device reports to identify any remaining devices using the legacy CBA method. Proactively reach out to users still on the old method and assist them in moving to the updated configuration.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Deprecation Timeline:&lt;/STRONG&gt; Keep the &lt;STRONG&gt;end-of-2026 deadline&lt;/STRONG&gt; in mind for planning. We suggest completing the transition well in advance of this date to avoid any service disruption. In the interim, we will share more details through the Message Center to directly impacted tenants, and update documentation as needed to support your migration.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;Conclusion&lt;/H4&gt;
&lt;P&gt;We strongly encourage any customer still using direct Exchange ActiveSync CBA to &lt;STRONG&gt;begin planning the move to Entra-based CBA now&lt;/STRONG&gt;. The Microsoft Entra method offers equal or better security – it's certificate-based, &lt;STRONG&gt;phishing-resistant, and passwordless&lt;/STRONG&gt;, but with far better integration into our modern authentication ecosystem and security controls. This change will help protect your organization's data by ensuring &lt;EM&gt;all&lt;/EM&gt; Exchange Online connections follow the most up-to-date security standards, and it eliminates the reliance on internal high-privilege tokens that carry unnecessary elevated rights.&lt;/P&gt;
&lt;P&gt;We understand that making changes to your authentication infrastructure can be challenging, which is why we've set a long runway until the end of 2026 for this transition. We'll continue to provide guidance and support throughout this period. &lt;STRONG&gt;Thank you for your cooperation in adopting these security improvements&lt;/STRONG&gt; – together, we can ensure a safer, more secure Exchange Online experience for all our customers. If you have any questions or need assistance with setting up Entra CBA, please reach out to Microsoft Support (Entra / Identity) or your account team. We're here to help make this transition as smooth as possible.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-12"&gt;The Exchange Online Team&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 May 2026 17:40:11 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/exchange-team-blog/retirement-of-direct-exchange-activesync-certificate-based/ba-p/4517896</guid>
      <dc:creator>The_Exchange_Team</dc:creator>
      <dc:date>2026-05-08T17:40:11Z</dc:date>
    </item>
    <item>
      <title>General Availability of Mailbox Import and Export Microsoft Graph APIs</title>
      <link>https://techcommunity.microsoft.com/t5/exchange-team-blog/general-availability-of-mailbox-import-and-export-microsoft/ba-p/4517854</link>
      <description>&lt;P&gt;As a part of our continuing march to Exchange Web Service (EWS) deprecation in Exchange Online (see &lt;A href="https://techcommunity.microsoft.com/blog/exchange/exchange-online-ews-your-time-is-almost-up/4492361" target="_blank"&gt;Exchange Online EWS, Your Time is Almost Up | Microsoft Community Hub&lt;/A&gt;) - the Microsoft Graph Team announced another milestone in enabling developers to efficiently manage, migrate, and integrate mailbox data in Exchange Online through Microsoft Graph:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://devblogs.microsoft.com/microsoft365dev/announcing-general-availability-of-the-mailbox-import-and-export-microsoft-graph-apis/" target="_blank"&gt;Announcing general availability of the mailbox import and export Microsoft Graph APIs - Microsoft 365 Developer Blog&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If you develop applications that access mailbox data, you might be very interested in that. Please see the post for more details on current scope and production expectations.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-12"&gt;Nino Bilic&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 May 2026 14:21:17 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/exchange-team-blog/general-availability-of-mailbox-import-and-export-microsoft/ba-p/4517854</guid>
      <dc:creator>Nino_Bilic</dc:creator>
      <dc:date>2026-05-08T14:21:17Z</dc:date>
    </item>
    <item>
      <title>Update Your Exchange SE Hybrid On-premises Rich Coexistence to Graph</title>
      <link>https://techcommunity.microsoft.com/t5/exchange-team-blog/update-your-exchange-se-hybrid-on-premises-rich-coexistence-to/ba-p/4517520</link>
      <description>&lt;P&gt;About a year ago, we announced &lt;A href="https://techcommunity.microsoft.com/blog/exchange/exchange-server-security-changes-for-hybrid-deployments/4396833" target="_blank" rel="noopener"&gt;Exchange Server Security Changes for Hybrid Deployments&lt;/A&gt;. This change impacted Exchange hybrid customers who host some of their mailboxes on-premises and their on-premises users need access to “rich coexistence” features (Free/Busy lookups, MailTips and profile picture sharing with Exchange Online users).&lt;/P&gt;
&lt;P&gt;This change was planned in two stages:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Stage 1&lt;/STRONG&gt;: transitioning to dedicated Exchange hybrid application. &lt;EM&gt;Completed in October 2025&lt;/EM&gt;. Exchange hybrid customers who host mailboxes on-premises now must create the dedicated Exchange hybrid application to maintain rich coexistence features for their on-premises users.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG style="color: rgb(30, 30, 30);"&gt;Stage 2&lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;: deprecation of EWS calls and switch to REST-based Microsoft Graph API calls for Exchange hybrid. This is the stage that we are in now. Please note that &lt;/SPAN&gt;&lt;EM style="color: rgb(30, 30, 30);"&gt;not all rich coexistence scenarios are fully supported yet&lt;/EM&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt; and &lt;/SPAN&gt;&lt;EM style="color: rgb(30, 30, 30);"&gt;not every cloud environment might support Graph API hybrid calls yet&lt;/EM&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt; (please see &lt;/SPAN&gt;&lt;A style="font-style: normal; font-weight: 400; background-color: rgb(255, 255, 255);" href="https://learn.microsoft.com/Exchange/hybrid-deployment/deploy-dedicated-hybrid-app#configure-graph-api-permissions" target="_blank" rel="noopener"&gt;documentation&lt;/A&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;).&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Deprecation of Exchange Web Services (EWS) in Exchange Online is nearing final stages – see &lt;A href="https://techcommunity.microsoft.com/blog/exchange/exchange-online-ews-your-time-is-almost-up/4492361" target="_blank" rel="noopener"&gt;Exchange Online EWS, Your Time is Almost Up&lt;/A&gt;. Because of this, all customers who require rich coexistence (even those who &lt;A href="https://techcommunity.microsoft.com/blog/exchange/exchange-server-security-changes-for-hybrid-deployments/4396833" target="_blank" rel="noopener"&gt;already finalized Stage 1&lt;/A&gt;) will need to install an Exchange Subscription Edition (SE) update on premises and switch the dedicated Exchange hybrid app permissions to a more granular Graph API permission model. &lt;STRONG&gt;This must be done before October 2026 (as we will turn off EWS by default then) with the latest date of April 2027 (when we will permanently turn off EWS in Exchange Online)&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;The following illustration shows the timeline of hybrid security improvements, Stage 2:&lt;/P&gt;
&lt;img /&gt;
&lt;H4&gt;Exchange Hybrid customers who want to start using Graph API in hybrid workflow should:&lt;/H4&gt;
&lt;P&gt;&lt;STRONG&gt;Step 1&lt;/STRONG&gt; – install the May 2026 Hotfix Update for Exchange SE (or newer) on your on-premises Exchange SE servers:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/exchange/released-may-2026-exchange-server-hotfix-update/4517516" target="_blank" rel="noopener" data-lia-auto-title="Released: May 2026 Exchange Server Hotfix Update" data-lia-auto-title-active="0"&gt;Released: May 2026 Exchange Server Hotfix Update&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Step 2&lt;/STRONG&gt; – once all your on-premises Exchange SE servers have the update installed, follow the steps as outlined in the &lt;A href="https://learn.microsoft.com/Exchange/hybrid-deployment/deploy-dedicated-hybrid-app" target="_blank" rel="noopener"&gt;documentation to enable the Graph API&lt;/A&gt; hybrid workflow for supported scenarios. Note that if you ran the script in the past, you need to re-run it again after installing the new update to activate new functionality.&lt;/P&gt;
&lt;P style="background: #F0F0F0; padding: .5em; margin: 1em 0 1em 0;"&gt;Note: &lt;A href="https://learn.microsoft.com/troubleshoot/exchange/administration/exchange-2019-2016-end-of-support" target="_blank" rel="noopener"&gt;Exchange 2016 and 2019 are out of support&lt;/A&gt;. We are &lt;EM&gt;not&lt;/EM&gt; releasing an update for those versions to use Graph API hybrid calls (even updates released under Exchange 2016 or 2019 &lt;A href="https://techcommunity.microsoft.com/blog/exchange/announcing-period-2-exchange-20162019-extended-security-update-esu-program/4511603" target="_blank" rel="noopener"&gt;ESU&lt;/A&gt; will not contain this functionality). Customers who are still using Exchange 2016 or 2019 servers to host mailboxes on premises will have to &lt;A href="https://techcommunity.microsoft.com/blog/exchange/exchange-online-ews-your-time-is-almost-up/4492361" target="_blank" rel="noopener"&gt;keep allowing EWS use in their tenant past October 2026&lt;/A&gt; and &lt;U&gt;must&lt;/U&gt; upgrade all servers to Exchange SE by April 2027 (when EWS is disabled in Exchange Online). Rich coexistence features on those unsupported versions will permanently stop working in April 2027. Please upgrade your on-premises environments from unsupported versions ASAP. &lt;EM&gt;By running unsupported versions, you might be putting your environment at risk!&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;The FAQ related to creation and use of dedicated hybrid app can be found in &lt;A href="https://learn.microsoft.com/Exchange/hybrid-deployment/deploy-dedicated-hybrid-app#frequently-asked-questions" target="_blank" rel="noopener"&gt;feature documentation&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Updates to this post:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;5/8/2026: Clarified that the script needs to be re-run to enable new functionality (Step 2 above) even if it was ran in the past already.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-clear-both"&gt;&lt;SPAN class="lia-text-color-12"&gt;The Exchange Team&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 May 2026 14:36:18 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/exchange-team-blog/update-your-exchange-se-hybrid-on-premises-rich-coexistence-to/ba-p/4517520</guid>
      <dc:creator>The_Exchange_Team</dc:creator>
      <dc:date>2026-05-08T14:36:18Z</dc:date>
    </item>
    <item>
      <title>Released: May 2026 Exchange Server Hotfix Update</title>
      <link>https://techcommunity.microsoft.com/t5/exchange-team-blog/released-may-2026-exchange-server-hotfix-update/ba-p/4517516</link>
      <description>&lt;P&gt;Microsoft has released Hotfix Update (HU) for:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Exchange Server Subscription Edition (SE)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;HU is available for the following specific version of Exchange Server:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://www.microsoft.com/en-us/download/details.aspx?id=108646" target="_blank" rel="noopener"&gt;Exchange SE RTM&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The May 2026 HU &lt;EM&gt;does not &lt;/EM&gt;contain any new Exchange Server security updates but contains new functionality. Please see the release KB article for more information.&lt;/P&gt;
&lt;H4&gt;Updating your Exchange rich hybrid coexistence to Graph API calls&lt;/H4&gt;
&lt;P&gt;May 2026 hotfix update contains functionality that will allow you to start switching your Exchange Server hybrid rich coexistence from using Exchange Web Services (EWS) to REST-based Microsoft Graph API calls. This is a continuation of work we announced in &lt;A href="https://techcommunity.microsoft.com/blog/exchange/exchange-server-security-changes-for-hybrid-deployments/4396833" target="_blank" rel="noopener"&gt;Exchange Server Security Changes for Hybrid Deployments&lt;/A&gt;.&lt;/P&gt;
&lt;P style="background: #F0F0F0; padding: .5em; margin: 1em 0 1em 0;"&gt;Note: &lt;A href="https://learn.microsoft.com/troubleshoot/exchange/administration/exchange-2019-2016-end-of-support" target="_blank" rel="noopener"&gt;Exchange 2016 and 2019 are out of support&lt;/A&gt;. We are &lt;EM&gt;not&lt;/EM&gt; releasing an update for those versions to use Graph API hybrid calls (even updates released under Exchange 2016 or 2019 &lt;A href="https://techcommunity.microsoft.com/blog/exchange/announcing-period-2-exchange-20162019-extended-security-update-esu-program/4511603" target="_blank" rel="noopener"&gt;ESU&lt;/A&gt; will not contain this functionality). Customers who are still using Exchange 2016 or 2019 servers to host mailboxes on premises will have to &lt;A href="https://techcommunity.microsoft.com/blog/exchange/exchange-online-ews-your-time-is-almost-up/4492361" target="_blank" rel="noopener"&gt;keep allowing EWS use in their tenant past October 2026&lt;/A&gt; and &lt;U&gt;must&lt;/U&gt; upgrade all servers to Exchange SE by April 2027 (when EWS is disabled in Exchange Online). Rich coexistence features on those unsupported versions will permanently stop working in April 2027. Please upgrade your on-premises environments from unsupported versions ASAP. &lt;EM&gt;By running unsupported versions, you might be putting your environment at risk!&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;More information can be found in &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/exchange/update-your-exchange-se-hybrid-on-premises-rich-coexistence-to-graph/4517520" target="_blank" rel="noopener" data-lia-auto-title="Update Your Exchange SE Hybrid On-premises Rich Coexistence to Graph" data-lia-auto-title-active="0"&gt;Update Your Exchange SE Hybrid On-premises Rich Coexistence to Graph&lt;/A&gt; and &lt;A href="https://learn.microsoft.com/en-us/Exchange/hybrid-deployment/deploy-dedicated-hybrid-app" target="_blank" rel="noopener"&gt;Deploy dedicated Exchange hybrid app&lt;/A&gt;.&lt;/P&gt;
&lt;H4&gt;Update installation&lt;/H4&gt;
&lt;P&gt;The following update paths are available:&lt;/P&gt;
&lt;img /&gt;
&lt;UL&gt;
&lt;LI&gt;Inventory your Exchange Servers to determine which updates are needed using the&amp;nbsp;&lt;A href="https://aka.ms/ExchangeHealthChecker" target="_blank" rel="noopener"&gt;Exchange Server Health Checker script&lt;/A&gt;. Running this script will tell you if any of your Exchange Servers are behind on updates (CUs, SUs, or manual actions).&lt;/LI&gt;
&lt;LI&gt;Install the latest CU. Use the &lt;A href="https://aka.ms/ExchangeUpdateWizard" target="_blank" rel="noopener"&gt;Exchange Update Wizard&lt;/A&gt; to choose your current CU and your target CU to get directions.&lt;/LI&gt;
&lt;LI&gt;Re-run the Health Checker after you install an update to see if any further actions are needed.&lt;/LI&gt;
&lt;LI&gt;After setup is completed, please reboot the server and check that all Exchange services have started properly. If some services are in a disabled state, that indicates that something interrupted installation of the update. Please see the Workaround 1 in &lt;A href="https://support.microsoft.com/en-us/topic/file-version-error-when-you-try-to-install-exchange-server-november-2024-su-a650da30-f8fb-469d-a449-47396cab0a15" target="_blank" rel="noopener"&gt;this article&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;If you encounter errors during or after installation of Exchange Server, run the &lt;A href="https://aka.ms/ExSetupAssist" target="_blank" rel="noopener"&gt;SetupAssist script&lt;/A&gt;. If something does not work properly after updates, see &lt;A href="https://learn.microsoft.com/troubleshoot/exchange/client-connectivity/exchange-security-update-issues" target="_blank" rel="noopener"&gt;Fix failed Exchange Server updates&lt;/A&gt;. Also please see &lt;A href="https://support.microsoft.com/en-us/topic/file-version-error-when-you-try-to-install-exchange-server-november-2024-su-a650da30-f8fb-469d-a449-47396cab0a15" target="_blank" rel="noopener"&gt;File version error when you try to install Exchange Server updates&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;Hotfix Update FAQs&lt;/H4&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Why did Microsoft decide to release this HU at the start of the month? Is this urgent?&lt;BR /&gt;&lt;/EM&gt;&lt;/STRONG&gt;Hotfix releases are not tied to the “patch Tuesday” release schedule as they do not contain security updates. Exchange Hotfix Updates are optional.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;We installed the last Security Update. Should we install the later Hotfix Update?&lt;BR /&gt;&lt;/EM&gt;&lt;/STRONG&gt;Exchange Server HUs are &lt;U&gt;optional updates&lt;/U&gt;, but they might introduce features or fixes that your organization can benefit from. Please see the release KB article for more details.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;We did not yet install the earlier Security Update. Do we have to install the last available SU first before installing the later HU?&lt;BR /&gt;&lt;/EM&gt;&lt;/STRONG&gt;All of Exchange updates (HUs or SUs) &lt;A href="https://learn.microsoft.com/exchange/plan-and-deploy/post-installation-tasks/security-best-practices/exchange-server-update-faq?view=exchserver-2019" target="_blank" rel="noopener"&gt;are cumulative&lt;/A&gt;. Therefore, a newer SU or HU will contain all the changes that a previous, older SU or HU has. If you have not installed the older updates yet, you can install the newer one directly and skip the older one.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Our Exchange servers update automatically through Windows / Microsoft Update. Will our servers automatically install the HU update?&lt;BR /&gt;&lt;/EM&gt;&lt;/STRONG&gt;This HU is an &lt;U&gt;optional update&lt;/U&gt; for your servers and the update will be shown as an optional update on Windows / Microsoft update a few days after general release on Download Center.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Will the new features and fixes released in the HU also be rolled into future updates, or must we install this specific HU to get them?&lt;BR /&gt;&lt;/EM&gt;&lt;/STRONG&gt;Content of this HU will be included in subsequent updates for Exchange Server SE.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Can HUs be uninstalled (if the need arises)?&lt;BR /&gt;&lt;/EM&gt;&lt;/STRONG&gt;Yes. HUs, like SUs, can be uninstalled.&lt;/P&gt;
&lt;P&gt;Documentation may not be fully available at the time this post is published.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Updates to this post:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;5/8/2026: Updated the FAQ related to Windows / Microsoft Update availability&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-12"&gt;The Exchange Server Team&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 May 2026 20:31:09 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/exchange-team-blog/released-may-2026-exchange-server-hotfix-update/ba-p/4517516</guid>
      <dc:creator>The_Exchange_Team</dc:creator>
      <dc:date>2026-05-08T20:31:09Z</dc:date>
    </item>
    <item>
      <title>Deprecating Legacy TLS and Endpoints for POP and IMAP in Exchange Online</title>
      <link>https://techcommunity.microsoft.com/t5/exchange-team-blog/deprecating-legacy-tls-and-endpoints-for-pop-and-imap-in/ba-p/4515201</link>
      <description>&lt;P&gt;Security on the internet continues to evolve, and older cryptographic protocols no longer provide the protections required for today’s threat landscape. As part of our ongoing work to help customers keep their email environments secure, we’re taking another step in modernizing Exchange Online connectivity.&lt;/P&gt;
&lt;H4&gt;What’s changing&lt;/H4&gt;
&lt;P&gt;We’re planning to &lt;STRONG&gt;fully&lt;/STRONG&gt; &lt;STRONG&gt;deprecate support for legacy TLS versions (TLS 1.0 and TLS 1.1)&lt;/STRONG&gt; for &lt;STRONG&gt;POP3 and IMAP4 connections&lt;/STRONG&gt; to Exchange Online. These older TLS versions have been industry‑deprecated for some time and are no longer considered secure.&lt;/P&gt;
&lt;P&gt;Modern email clients and libraries already support &lt;STRONG&gt;TLS 1.2 or higher&lt;/STRONG&gt;, and the vast majority of POP and IMAP traffic to Exchange Online today uses these newer protocols.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://techcommunity.microsoft.com/blog/exchange/new-opt-in-endpoint-for-pop3imap4-clients-that-need-legacy-tls/3710395" target="_blank" rel="noopener"&gt;Several years ago we started the move to block these older versions, but we did allow you to use them by opting-in&lt;/A&gt;, we’re now removing support for them entirely. Our expectation is that &lt;EM&gt;only customers who have explicitly opted into using those &lt;A href="https://learn.microsoft.com/exchange/clients-and-mobile-in-exchange-online/opt-in-exchange-online-endpoint-for-legacy-tls-using-pop3-or-imap4" target="_blank" rel="noopener"&gt;legacy endpoints&lt;/A&gt; are impacted by the deprecation we are announcing today&lt;/EM&gt;.&lt;/P&gt;
&lt;H4&gt;What customers should do&lt;/H4&gt;
&lt;P&gt;If you’re using POP or IMAP with Exchange Online, ensure that:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Your email clients, applications, and libraries support &lt;STRONG&gt;TLS 1.2 or later &lt;/STRONG&gt;and are not using &lt;A href="https://learn.microsoft.com/exchange/clients-and-mobile-in-exchange-online/opt-in-exchange-online-endpoint-for-legacy-tls-using-pop3-or-imap4" target="_blank" rel="noopener"&gt;legacy endpoints&lt;/A&gt; to connect to our service.&lt;/LI&gt;
&lt;LI&gt;Any custom or embedded applications (such as devices or legacy services) are updated accordingly.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If you aren’t sure if you are using legacy versions, check the configuration of your POP and IMAP clients and if you are, your application or device vendor can typically confirm TLS support and provide upgrade guidance.&lt;/P&gt;
&lt;H4&gt;What’s next&lt;/H4&gt;
&lt;P&gt;We will start to block legacy version connections starting in July 2026.&lt;/P&gt;
&lt;P&gt;As always, our goal is to make these transitions predictable and well‑communicated, while continuing to strengthen security across Microsoft 365.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-12"&gt;The Exchange Team&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2026 19:03:29 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/exchange-team-blog/deprecating-legacy-tls-and-endpoints-for-pop-and-imap-in/ba-p/4515201</guid>
      <dc:creator>The_Exchange_Team</dc:creator>
      <dc:date>2026-04-27T19:03:29Z</dc:date>
    </item>
    <item>
      <title>Modernizing DNS Security for Exchange Online Mail Flow</title>
      <link>https://techcommunity.microsoft.com/t5/exchange-team-blog/modernizing-dns-security-for-exchange-online-mail-flow/ba-p/4514248</link>
      <description>&lt;P&gt;The Domain Name System (DNS) protocol is used by clients to find mail servers over the internet. DNS is unencrypted and unauthenticated by default, making it vulnerable to spoofing, tampering, and adversary‑in‑the‑middle attacks. As threat actors increasingly target the foundational layers of email delivery, modern DNS security protocols have become essential to protecting organizations.&lt;/P&gt;
&lt;P&gt;To address these gaps, Exchange Online has invested heavily in &lt;STRONG&gt;modern, standards‑based DNS security &lt;/STRONG&gt;– including &lt;STRONG&gt;DNSSEC&lt;/STRONG&gt;, &lt;STRONG&gt;SMTP DANE&lt;/STRONG&gt;, and &lt;STRONG&gt;MTA‑STS&lt;/STRONG&gt; – to ensure mail is delivered over validated, encrypted, and tamper‑resistant channels by default wherever possible.&lt;/P&gt;
&lt;P&gt;In this post, we will provide updates on these efforts and discuss upcoming plans to keep raising the email security bar.&lt;/P&gt;
&lt;H4&gt;DNSSEC Enablement Wizard for Exchange Online&lt;/H4&gt;
&lt;P&gt;To simplify adoption of SMTP DANE with DNSSEC, in Q3 of calendar year 2026 we’re releasing a &lt;STRONG&gt;DNSSEC Enablement Wizard&lt;/STRONG&gt; in the Exchange Admin Center. This guided workflow:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Validates DNS prerequisites&lt;/LI&gt;
&lt;LI&gt;Provisions the customer-specific DNSSEC‑capable mail flow endpoint&lt;/LI&gt;
&lt;LI&gt;Reduces configuration risk during MX transition&lt;/LI&gt;
&lt;LI&gt;Prepares the domain for SMTP DANE adoption&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;For customers who wish to fully enforce SMTP DANE with DNSSEC, PowerShell will remain the option for enabling SMTP DANE once DNSSEC-enablement is complete as per &lt;A href="https://learn.microsoft.com/purview/how-smtp-dane-works#set-up-inbound-smtp-dane-with-dnssec" target="_blank"&gt;Set up inbound SMTP DANE with DNSSEC&lt;/A&gt;.&lt;/P&gt;
&lt;H4&gt;Control Outbound SMTP DANE &amp;amp; MTA‑STS Validation on Connectors&lt;/H4&gt;
&lt;P&gt;With &lt;A href="https://techcommunity.microsoft.com/blog/exchange/announcing-smtp-dane--mta-sts-connector-modes-in-exchange-online/4501005" target="_blank"&gt;rollout started in late Feb 2026&lt;/A&gt;, we introduced a new capability that gives admins &lt;STRONG&gt;explicit control&lt;/STRONG&gt; over SMTP DANE and MTA‑STS validation behavior for messages sent over &lt;STRONG&gt;outbound connectors&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;The MtaStsMode and SmtpDaneMode parameters on New/Set/Get-OutboundConnector lets organizations choose how strictly Exchange Online enforces these security protocols on a per‑connector basis:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Opportunistic (default): &lt;/STRONG&gt;Exchange Online attempts SMTP DANE and/or MTA‑STS validation but still delivers mail if the destination doesn’t support them.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;None&lt;/STRONG&gt;: which applies to both MTA-STS and SMTP DANE and disables the validation entirely, therefore&amp;nbsp;reducing the security of emails sent over that connector&amp;nbsp;by removing MTA-STS and/or SMTP DANE protections designed to prevent downgrade attacks and spoofed MX redirection.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Mandatory (SMTP DANE only): &lt;/STRONG&gt;Enforces full SMTP DANE with DNSSEC validation and queues (then rejects) mail if validation fails or destination domain doesn’t support SMTP DANE with DNSSEC by end of queuing period.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This outbound connector capability makes it easier for customers to adopt stronger DNS‑based protections incrementally while maintaining compatibility with partner ecosystems.&lt;/P&gt;
&lt;H5&gt;What happened to auto-provisioning of DNSSEC-enabled mail flow records (A/AAA)?&lt;/H5&gt;
&lt;P&gt;Due to internal infrastructure projects, we had to delay this DNS provisioning change until second half of calendar year 2026. Gradually switching provisioning of all A records for new Accepted Domains into the new subdomains under mx.microsoft is still a priority for us, but making infrastructure changes is complex. Significant challenges have required us to re-order the work necessary to complete this change while maintaining service health and reliability.&lt;/P&gt;
&lt;P&gt;Original announcement: &lt;A href="https://techcommunity.microsoft.com/blog/exchange/implementing-inbound-smtp-dane-with-dnssec-for-exchange-online-mail-flow/3939694" target="_blank"&gt;Implementing Inbound SMTP DANE with DNSSEC for Exchange Online Mail Flow | Microsoft Community Hub&lt;/A&gt;.&lt;/P&gt;
&lt;H4&gt;Are there any planned updates to mail.protection.outlook.com?&lt;/H4&gt;
&lt;P&gt;Currently, there are no plans to enable DNSSEC on the mail flow domain &lt;STRONG&gt;mail.protection.outlook.com&lt;/STRONG&gt;. Customers who require DNSSEC for inbound mail will continue to need to transition the DNSSEC-capable dedicated subdomains within mx.microsoft. As MX changes can be operationally sensitive, we built the DNSSEC Enablement Wizard to ease the friction of this change.&lt;/P&gt;
&lt;P&gt;In early third quarter of 2026, mail.protection.outlook.com will receive TCP and EDNS support. This modernization improves reliability and enables future security enhancements at cloud scale. &amp;nbsp;&lt;/P&gt;
&lt;H4&gt;Raising the Security Bar – Together&lt;/H4&gt;
&lt;P&gt;Across these investments, our goal is simple: &lt;STRONG&gt;make strong email security the default&lt;/STRONG&gt;, without introducing additional operational complexity or overhead. DNSSEC, SMTP DANE, and MTA‑STS directly address long‑standing weaknesses in the global email ecosystem, and Exchange Online is committed to leading the industry in deploying these foundational protections at scale.&lt;/P&gt;
&lt;P&gt;By modernizing our DNS infrastructure, providing safer tooling for domain transitions, and giving customers finer control over protocol enforcement, we’re continuing to raise the security bar for all Exchange Online customers—and making it easier than ever to adopt modern DNS security.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-12"&gt;Microsoft 365 Messaging Team&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2026 21:00:39 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/exchange-team-blog/modernizing-dns-security-for-exchange-online-mail-flow/ba-p/4514248</guid>
      <dc:creator>The_Exchange_Team</dc:creator>
      <dc:date>2026-04-23T21:00:39Z</dc:date>
    </item>
    <item>
      <title>Change Optics Report released into Public Preview to showcase messages impacted by future changes</title>
      <link>https://techcommunity.microsoft.com/t5/exchange-team-blog/change-optics-report-released-into-public-preview-to-showcase/ba-p/4513047</link>
      <description>&lt;P&gt;Change Management is an important part of managing the improvements we make to our service that may sometimes disrupt our customers. The key is empowering customers to identify if they have messages that will be affected when we announce changes to the service. To that end, we’d like to announce the Public Preview for the Change Optics Report. It will be the central location for finding messages that could be affected by future changes to the service.&lt;/P&gt;
&lt;P&gt;As we improve or identify issues in Exchange Online, there is now a report to point customers to when we announce changes that could affect the sending and delivery of certain messages. This report will showcase multiple scenarios of interest and importance to admins preparing for change. It displays a &lt;STRONG&gt;sample&lt;/STRONG&gt; set of messages that have the characteristics that match those expected to be affected.&lt;/P&gt;
&lt;P&gt;These example messages give admins the information necessary to launch investigations that highlight where actions are needed to avoid disruption to their organizations as changes arrive. The report can then be used to observe the progress made to reduce those messages to a point where the risk has been removed ahead of the related change.&lt;/P&gt;
&lt;H4&gt;Initial Scenarios&lt;/H4&gt;
&lt;P&gt;The report is being released with two scenarios already included.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;OMC&lt;/STRONG&gt; represents Onmicrosoft.com traffic being sent externally. This is aimed at customers from large organizations still seeing usage they need to address before the traffic is throttled. &amp;nbsp;For more information, see &lt;A href="https://techcommunity.microsoft.com/blog/exchange/limiting-onmicrosoft-domain-usage-for-sending-emails/4446167" target="_blank"&gt;Limiting Onmicrosoft Domain Usage for Sending Emails | Microsoft Community Hub.&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG style="color: rgb(30, 30, 30);"&gt;DRS&lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt; represents Direct Send traffic being received by an organization’s tenant. This is useful for customers looking to use the Reject Direct Send setting and needing to first ensure all legitimate traffic is identified and catered for. For more information, see &lt;/SPAN&gt;&lt;A style="font-style: normal; font-weight: 400; background-color: rgb(255, 255, 255);" href="https://techcommunity.microsoft.com/blog/exchange/introducing-more-control-over-direct-send-in-exchange-online/4408790" target="_blank"&gt;Introducing more control over Direct Send in Exchange Online | Microsoft Community Hub.&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;Using the report&lt;/H4&gt;
&lt;P&gt;The report can be found in the Exchange Admin Center (&lt;A href="https://admin.cloud.microsoft/exchange" target="_blank"&gt;https://admin.cloud.microsoft/exchange&lt;/A&gt;) under &lt;STRONG&gt;Reports &lt;/STRONG&gt;&lt;STRONG&gt;&amp;gt; Mail flow &amp;gt;&lt;/STRONG&gt;&lt;STRONG&gt;&amp;nbsp;Change Optics Report&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;Change Optics Report: Use this report to view changes made to your Exchange Online configuration over time. You can filter by date range and change type to find specific changes.&lt;/P&gt;
&lt;P&gt;The report is divided into a Summary page and Details page.&lt;/P&gt;
&lt;H5&gt;Summary Page&lt;/H5&gt;
&lt;P&gt;This provides a summary chart tracking the volume of messages flag by the various scenarios being tracked. &amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;H5&gt;Details Page&lt;/H5&gt;
&lt;P&gt;The Details page allows you to see example messages per scenario. The main message properties are available for use in an investigation, and the table can be exported. Message Trace can be used to retrieve any additional information needed about a message.&lt;/P&gt;
&lt;P&gt;The scenario you are interested in can be selected from the dropdown menu.&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;Please provide any feedback in the Comments section. We will update this blog to announce when the report reaches GA.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-12"&gt;Microsoft 365 Messaging Team&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Apr 2026 16:03:10 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/exchange-team-blog/change-optics-report-released-into-public-preview-to-showcase/ba-p/4513047</guid>
      <dc:creator>The_Exchange_Team</dc:creator>
      <dc:date>2026-04-20T16:03:10Z</dc:date>
    </item>
    <item>
      <title>Announcing Period 2 Exchange 2016/2019 Extended Security Update (ESU) program</title>
      <link>https://techcommunity.microsoft.com/t5/exchange-team-blog/announcing-period-2-exchange-2016-2019-extended-security-update/ba-p/4511603</link>
      <description>&lt;P&gt;While both Exchange 2016 and 2019 are&amp;nbsp;&lt;A href="https://techcommunity.microsoft.com/blog/exchange/t-6-months-exchange-server-2016-and-exchange-server-2019-end-of-support/4403017" target="_blank" rel="noopener"&gt;out of support since October 2025&lt;/A&gt;, some of our customers who needed more time to finalize migrations to Exchange Subscription Edition (SE) have opted to enroll into the &lt;A href="https://techcommunity.microsoft.com/blog/exchange/announcing-exchange-2016--2019-extended-security-update-program/4433495" target="_blank" rel="noopener"&gt;Extended Security Update program&lt;/A&gt;. That ESU program started in October 2025 and is ending in April 2026 (“Period 1”).&lt;/P&gt;
&lt;P&gt;As end of April 2026 nears, some of our customers told us that they needed additional time to finalize their Exchange 2016/2019 migrations.&lt;/P&gt;
&lt;P&gt;Today we are announcing that we &lt;STRONG&gt;created a “Period 2” Exchange Server ESU program. This period will last from the start of May 2026 through the end of October 2026 (6 months)&lt;/STRONG&gt;. &lt;EM&gt;There will be no further extensions of this program after that&lt;/EM&gt;.&lt;/P&gt;
&lt;H4&gt;Conditions of Period 2 Exchange ESU program&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;Customers who wish to enroll into Period 2 program &lt;STRONG&gt;will have to re-purchase the Exchange ESU contract even if they were already enrolled into the Period 1 &lt;/STRONG&gt;&lt;A href="https://techcommunity.microsoft.com/blog/exchange/announcing-exchange-2016--2019-extended-security-update-program/4433495" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;ESU program (October 2025 – April 2026)&lt;/STRONG&gt;&lt;/A&gt;. Period 2 is not an “extension” of current Period 1 Exchange ESU program (which ends in April 2026). Your organization does not automatically enroll into Period 2 – you will have to purchase the ESU again for additional 6-month coverage through October 2026 (in the same way that you purchased the original ESU).&lt;/LI&gt;
&lt;LI&gt;In Period 2, we plan to provide security updates for &lt;STRONG&gt;Exchange Server 2016 CU23 and Exchange Server 2019 CU14/CU15&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;Any Exchange Server ESUs purchased starting with today’s date (April 15, 2026) will automatically be considered Period 2 and will be valid from May to October 2026. Your organization will receive information on how to download updates released under Period 2 ESU (your original ESU program instructions will not work for ESU updates released after April 2026).&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Starting today, customers can contact their Microsoft account team to get information about and purchase additional Period 2 Extended Security Update (ESU) for their Exchange 2016 CU23 or Exchange 2019 CU14/CU15 servers. Simply purchase the same product after today’s date.&lt;/STRONG&gt;&amp;nbsp;Your account teams will have information related to per server cost and additional details on how to purchase.&lt;/P&gt;
&lt;H4&gt;What does this mean?&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;This ESU is&amp;nbsp;&lt;EM&gt;not&lt;/EM&gt;&amp;nbsp;an “extension of the support lifecycle” (&lt;A href="https://learn.microsoft.com/en-us/lifecycle/" target="_blank" rel="noopener"&gt;Microsoft Lifecycle Policy | Microsoft Learn&lt;/A&gt;) for Exchange 2016 / 2019. Those servers are still out-of-support, and you will not be able to open support cases for them (unless directly related to an issue with an update released to ESU customers during the ESU period).&lt;/LI&gt;
&lt;LI&gt;This Period 2 ESU&amp;nbsp;&lt;EM&gt;is&lt;/EM&gt;&amp;nbsp;a way for customers who might not be able to finalize their Exchange 2016 or 2019 migrations to Exchange SE before the end of October 2026, to receive Critical and Important updates (as currently defined by&amp;nbsp;&lt;A href="https://www.microsoft.com/msrc/security-update-severity-rating-system" target="_blank" rel="noopener"&gt;Microsoft Security Response Center (MSRC) scoring&lt;/A&gt;) as security updates (SUs) that we might release during Period 2. If there are SUs that we need to release, we will&amp;nbsp;&lt;EM&gt;privately&lt;/EM&gt;&amp;nbsp;provide such SUs to ESU customers only.&lt;/LI&gt;
&lt;LI&gt;We are&amp;nbsp;&lt;EM&gt;not&lt;/EM&gt;&amp;nbsp;committing to actually releasing any SUs during the Period 2 ESU. Exchange Server does&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/exchange/new-features/build-numbers-and-release-dates" target="_blank" rel="noopener"&gt;not necessarily receive SU updates every month&lt;/A&gt;&amp;nbsp;on Patch Tuesday (2&lt;SUP&gt;nd&lt;/SUP&gt;&amp;nbsp;Tuesday of the month) as SUs are released only if there are Critical or Important security product changes. Therefore, if there are no SUs that we need to release during the time of ESU program, there will be no such updates provided. We will, however, confirm with ESU participants each Patch Tuesday whether an SU was provided or not.&lt;/LI&gt;
&lt;LI&gt;This Period 2 Exchange ESU will be valid until end of October 2026.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;Who is Period 2 Exchange ESU for?&lt;/H4&gt;
&lt;P&gt;This program is intended for customers with a &lt;A href="https://www.microsoft.com/en-us/licensing/licensing-programs/enterprise" target="_blank" rel="noopener"&gt;Microsoft Enterprise Agreement (EA)&lt;/A&gt; who are unable to finalize their Exchange 2016 or 2019 migrations to Exchange SE before end of April 2026 and still need Critical and Important security coverage for servers still in operation.&lt;/P&gt;
&lt;H1&gt;FAQs&lt;/H1&gt;
&lt;P&gt;&lt;STRONG&gt;Why does Microsoft require additional contract for Period 2 of Exchange ESU if our organization already has the original Exchange Server ESU?&lt;BR /&gt;&lt;/STRONG&gt;Period 2 is a separate contract that lasts until the end of October 2026. Many of our original ESU customers are finalizing their migrations by end of April 2026. Those few that need additional time have an option of getting a new ESU contract. Our preference is that our customers finalize their migrations instead (honestly – we’d be happy to not sell Period 2 Exchange ESU to anyone; please migrate instead!)&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Our organization did not purchase original Period 1 Exchange ESU (ending with April 2026). Can we purchase Period 2 ESU only?&lt;/STRONG&gt;&lt;BR /&gt;Period 2 ESU is separate from original Period 1 ESU and can be purchased independently. Purchasing the Period 2 ESU does not require purchase of Period 1. But note that purchase of Period 2 ESU will only get you update packages released after Period 2 starts. You will not get access to update packages released during Period 1 ESU. Seeing that&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/exchange/plan-and-deploy/post-installation-tasks/security-best-practices/exchange-server-update-faq" target="_blank" rel="noopener"&gt;all our updates are cumulative&lt;/A&gt;, fixes for issues released during Period 1 ESU will be included in Period 2 updates (when / if released).&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;How is Exchange Server ESU licensed and how are updates distributed?&lt;BR /&gt;&lt;/STRONG&gt;Updates released under Period 2 Exchange ESU will follow the same process as updates released under the Period 1 ESU program: once enrolled, your organization will be provided information on how to access any updates released under Period 2. There will be no special licenses or keys in the Microsoft 365 admin center or Volume Licensing. After purchase of Period 2 SKUs, you will receive a new ESU User Guide which will contain everything you need.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Our Exchange server is getting throttled or blocked when sending email to Exchange Online. How can Microsoft not make ESU updates available to all customers, so they can address this?&lt;BR /&gt;&lt;/STRONG&gt;If your server is currently affected by &lt;A href="https://techcommunity.microsoft.com/blog/exchange/throttling-and-blocking-email-from-persistently-vulnerable-exchange-servers-to-e/3815328" target="_blank" rel="noopener"&gt;Throttling and blocking of persistently vulnerable Exchange servers&lt;/A&gt; that indicates that the &lt;A href="https://learn.microsoft.com/en-us/exchange/new-features/build-numbers-and-release-dates" target="_blank" rel="noopener"&gt;version currently running&lt;/A&gt; in your organization is roughly a year out of date. To resolve the throttling or blocking immediately, please install October 2025 (last publicly available) updates for Exchange 2016 or 2019. &lt;EM&gt;ESU updates are not required&lt;/EM&gt;. There will come a day when October 2025 updates too will be throttled or blocked, but that is not currently the case. But note that even if you update to October 2025 updates your server is still out of support and out of date and you should migrate to a supported version ASAP.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Our organization has Microsoft Volume Licensing. Do we get the Exchange ESU automatically? Where can we buy Exchange ESU?&lt;/STRONG&gt; &lt;BR /&gt;Exchange ESU program is a separate contract that each organization must explicitly purchase via their Microsoft account team (requires &lt;A href="https://www.microsoft.com/en-us/licensing/licensing-programs/enterprise" target="_blank" rel="noopener"&gt;Microsoft Enterprise Agreement&lt;/A&gt;). Exchange ESU is not automatically included in Volume Licensing or Software Assurance.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Help! We purchased the ESU (Period 1 or Period 2) – but we do not know how to access the updates we paid for!&lt;BR /&gt;&lt;/STRONG&gt;&lt;EM&gt;If you have already purchased the ESU&lt;/EM&gt;&amp;nbsp;and need information on accessing the latest Security Updates, please contact us by sending an email to&amp;nbsp;&lt;U&gt;ExchangeandSfBServerESUInquiry@service.microsoft.com&lt;/U&gt;. You are welcome to add your account team to the email also.&lt;/P&gt;
&lt;P&gt;Please continue migrating to Exchange SE instead of taking advantage of this Period 2 ESU program. But if you really must, contact your Microsoft account team for more details on Period 2 ESU.&lt;/P&gt;
&lt;P&gt;A similar program extension is available for our Skype for Business 2015 / 2019 customers. Please read more&amp;nbsp;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/skype_for_business_blog/announcing-%E2%80%9Cperiod-2%E2%80%9D-for-skype-for-business-server-20152019-extended-security-u/4511619" data-lia-auto-title="here" data-lia-auto-title-active="0" target="_blank"&gt;&lt;U&gt;here&lt;/U&gt;&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-12"&gt;The Exchange Server Team&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2026 14:35:11 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/exchange-team-blog/announcing-period-2-exchange-2016-2019-extended-security-update/ba-p/4511603</guid>
      <dc:creator>The_Exchange_Team</dc:creator>
      <dc:date>2026-04-15T14:35:11Z</dc:date>
    </item>
    <item>
      <title>No Exchange Server Security Updates for April 2026</title>
      <link>https://techcommunity.microsoft.com/t5/exchange-team-blog/no-exchange-server-security-updates-for-april-2026/ba-p/4511262</link>
      <description>&lt;P&gt;Although &lt;A href="https://techcommunity.microsoft.com/blog/exchange/support-for-exchange-server-2016-and-exchange-server-2019-ends-today/4461192" target="_blank"&gt;Exchange 2016 and 2019 are now out of support&lt;/A&gt;, some customers have purchased the&amp;nbsp;&lt;A href="https://techcommunity.microsoft.com/blog/exchange/announcing-exchange-2016--2019-extended-security-update-program/4433495" target="_blank"&gt;Exchange 2016 and 2019 Extended Security Update (ESU)&lt;/A&gt;. We have therefore decided that until the end of this Exchange 2016 and 2019 ESU period (April 2026) we will make an explicit update related announcement even if we&amp;nbsp;&lt;EM&gt;DO NOT&lt;/EM&gt;&amp;nbsp;release anything for that&amp;nbsp;particular month.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;There are no security releases for any version of Exchange Server in April 2026, for customers with Exchange SE, or Exchange 2016 or 2019 ESU.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Please keep &lt;A href="https://techcommunity.microsoft.com/blog/exchange/upgrading-your-organization-from-current-versions-to-exchange-server-se/4241305" target="_blank"&gt;upgrading your organizations to Exchange SE&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-12"&gt;The Exchange Team&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2026 16:58:13 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/exchange-team-blog/no-exchange-server-security-updates-for-april-2026/ba-p/4511262</guid>
      <dc:creator>The_Exchange_Team</dc:creator>
      <dc:date>2026-04-14T16:58:13Z</dc:date>
    </item>
  </channel>
</rss>

