<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Exchange Team Blog articles</title>
    <link>https://techcommunity.microsoft.com/t5/exchange-team-blog/bg-p/Exchange</link>
    <description>Exchange Team Blog articles</description>
    <pubDate>Wed, 09 Sep 2026 00:17:56 GMT</pubDate>
    <dc:creator>Exchange</dc:creator>
    <dc:date>2026-09-09T00:17:56Z</dc:date>
    <item>
      <title>Released: September 2026 Exchange Server Security Updates</title>
      <link>https://techcommunity.microsoft.com/t5/exchange-team-blog/released-september-2026-exchange-server-security-updates/ba-p/4554411</link>
      <description>&lt;P&gt;Microsoft has released Security Updates (SUs) for vulnerabilities found in:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Exchange Server Subscription Edition (SE)&lt;/LI&gt;
&lt;LI&gt;Exchange Server 2019&lt;/LI&gt;
&lt;LI&gt;Exchange Server 2016&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;SUs are available for the following specific versions of Exchange Server:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://www.microsoft.com/en-us/download/details.aspx?id=108825" target="_blank" rel="noopener"&gt;Exchange SE RTM&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Exchange Server 2019&amp;nbsp;CU14&amp;nbsp;and&amp;nbsp;CU15 (to access, organization must be enrolled into the &lt;A href="https://techcommunity.microsoft.com/blog/exchange/announcing-period-2-exchange-20162019-extended-security-update-esu-program/4511603" target="_blank" rel="noopener"&gt;Period 2 ESU program&lt;/A&gt;)&lt;/LI&gt;
&lt;LI&gt;Exchange Server 2016&amp;nbsp;CU23 (to access, organization must be enrolled into the &lt;A href="https://techcommunity.microsoft.com/blog/exchange/announcing-period-2-exchange-20162019-extended-security-update-esu-program/4511603" target="_blank" rel="noopener"&gt;Period 2 ESU program&lt;/A&gt;)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The September 2026 SUs address vulnerabilities responsibly reported to Microsoft by security partners and found through Microsoft’s internal processes.&lt;/P&gt;
&lt;P&gt;These vulnerabilities affect Exchange Server. Exchange Online customers are already protected from the vulnerabilities addressed by these SUs and do not need to take any action other than updating any Exchange servers or Exchange Management tools workstations in their environment.&lt;/P&gt;
&lt;P&gt;More details about specific CVEs can be found in the&amp;nbsp;&lt;A href="https://msrc.microsoft.com/update-guide/" target="_blank" rel="noopener"&gt;Security Update Guide&lt;/A&gt;&amp;nbsp;(filter on ‘Server Software’ under Product Family for Exchange SE and ‘ESU’ under Product Family for Exchange 2016 and 2019).&lt;/P&gt;
&lt;H3&gt;Exchange 2016 and 2019 updates are available &lt;EM&gt;only&lt;/EM&gt; under the Period 2 ESU program&lt;/H3&gt;
&lt;P&gt;Exchange Server 2016 and 2019 are &lt;A href="https://techcommunity.microsoft.com/blog/exchange/support-for-exchange-server-2016-and-exchange-server-2019-ends-today/4461192" target="_blank" rel="noopener"&gt;out of support&lt;/A&gt;. Only customers who enrolled in the &lt;A href="https://techcommunity.microsoft.com/blog/exchange/announcing-period-2-exchange-20162019-extended-security-update-esu-program/4511603" target="_blank" rel="noopener"&gt;Period 2 Extended Security Update (ESU) program&lt;/A&gt; are eligible to receive Exchange Server 2016 and 2019 security updates released between May and October 2026.&lt;/P&gt;
&lt;P&gt;If you are not part of the Period 2 ESU program, &lt;A href="https://techcommunity.microsoft.com/blog/exchange/upgrading-your-organization-from-current-versions-to-exchange-server-se/4241305" target="_blank" rel="noopener"&gt;migrate to Exchange Server Subscription Edition (SE)&lt;/A&gt; to keep receiving the latest security updates.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;If you have already purchased the Period 2 ESU&lt;/EM&gt; and need information on accessing the latest Security Updates, please contact us by sending an email to &lt;A href="mailto:ExchangeandSfBServerESUInquiry@service.microsoft.com?subject=We%20purchased%20Exchange%20ESU%20need%20access" target="_blank" rel="noopener"&gt;ExchangeandSfBServerESUInquiry@service.microsoft.com&lt;/A&gt;.&lt;/P&gt;
&lt;H3&gt;Known issues with this release&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://support.microsoft.com/en-us/servicing/exchange/server/update/2026/5126672" target="_blank" rel="noopener"&gt;Published calendar (.ics) returns HTTP 500 for calendar applications | Microsoft Support&lt;/A&gt; – to be resolved in a future update&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Issues resolved in this release&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://support.microsoft.com/en-us/servicing/exchange/server/hotfix/2026/5105719" target="_blank" rel="noopener"&gt;Wrapper messages appear in shared mailbox inbox in hybrid environments | Microsoft Support&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://support.microsoft.com/en-us/servicing/exchange/server/update/2026/5125804" target="_blank"&gt;Hybrid Free/Busy over MS Graph drops the requester timezone | Microsoft Support&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Update installation&lt;/H3&gt;
&lt;P&gt;The following update paths are available:&lt;/P&gt;
&lt;img /&gt;
&lt;UL&gt;
&lt;LI&gt;Inventory your Exchange Servers to determine which updates are needed using the &lt;A href="https://aka.ms/ExchangeHealthChecker" target="_blank" rel="noopener"&gt;Exchange Server Health Checker script&lt;/A&gt;. Running this script will tell you if any of your Exchange Servers are behind on updates (CUs, SUs, or manual actions).&lt;/LI&gt;
&lt;LI&gt;Install the latest CU. Use the &lt;A href="https://aka.ms/ExchangeUpdateWizard" target="_blank" rel="noopener"&gt;Exchange Update Wizard&lt;/A&gt; to choose your current CU and your target CU to get directions.&lt;/LI&gt;
&lt;LI&gt;After setup is completed, please reboot the server and check that all Exchange services have started properly. If some services are in a disabled state, that indicates that something interrupted installation of the update. Please see the Workaround 1 in &lt;A href="https://learn.microsoft.com/en-us/troubleshoot/exchange/client-connectivity/exchange-security-update-issues#services-dont-start-after-su-installation" target="_blank" rel="noopener"&gt;this article&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;If you encounter errors during or after installation of Exchange Server, run the &lt;A href="https://aka.ms/ExSetupAssist" target="_blank" rel="noopener"&gt;SetupAssist script&lt;/A&gt;. If something does not work properly after updates, see &lt;A href="https://aka.ms/ExchangeFAQ" target="_blank" rel="noopener"&gt;Repair failed installations of Exchange Cumulative and Security updates&lt;/A&gt;. Also please see &lt;A href="https://support.microsoft.com/topic/file-version-error-when-you-try-to-install-exchange-server-november-2024-su-a650da30-f8fb-469d-a449-47396cab0a15" target="_blank" rel="noopener"&gt;File version error when you try to install Exchange Server updates&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H1&gt;FAQs&lt;/H1&gt;
&lt;P&gt;&lt;STRONG&gt;Our organization is in Hybrid mode with Exchange Online. Do we need to do anything?&lt;/STRONG&gt;&lt;BR /&gt;Exchange Online is already protected, but this SU needs to be installed on your Exchange servers, even if they are used only for management purposes. If you change the auth certificate after installing an SU, you should re-run the Hybrid Configuration Wizard.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;The last SU/HU we installed is a few months old. Do we need to install all SUs in order to install the latest one?&lt;/STRONG&gt;&lt;BR /&gt;SUs are cumulative. If you are running a CU supported by the SU, you do not need to install all SUs or HUs in sequential order; simply install the latest SU. Please see&amp;nbsp;&lt;A href="https://techcommunity.microsoft.com/t5/exchange-team-blog/why-exchange-server-updates-matter/ba-p/2280770" target="_blank" rel="noopener"&gt;this blog post&lt;/A&gt;&amp;nbsp;for more information.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Do we need to install SUs on all Exchange Servers within our organization? What about ‘Management Tools only’&amp;nbsp;machines?&lt;/STRONG&gt;&lt;BR /&gt;Our recommendation is to install SUs on&amp;nbsp;&lt;U&gt;all&lt;/U&gt;&amp;nbsp;Exchange Servers and all servers and workstations running the Exchange Management Tools to ensure compatibility between management tools clients and servers. If you are trying to update the Exchange Management Tools in the environment with no running Exchange servers, please see&amp;nbsp;&lt;A href="https://learn.microsoft.com/exchange/manage-hybrid-exchange-recipients-with-management-tools#update-the-exchange-server-management-tools-only-role-with-no-running-exchange-server-to-a-newer-cumulative-or-security-update" target="_blank" rel="noopener"&gt;this&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;We installed an Exchange SU or HU update and are running Windows Server 2025. How do we uninstall updates as they are not listed on Windows Server 2025?&lt;/STRONG&gt;&lt;BR /&gt;We do not recommend uninstalling Security Updates. But see &lt;A href="https://support.microsoft.com/en-us/servicing/office/can-t-view-or-uninstall-exchange-security-or-hotfix-updates-in-control-panel-on-windows-server-2025" target="_blank" rel="noopener"&gt;Can't view or uninstall Exchange security or hotfix updates in Control Panel on Windows Server 2025 | Microsoft Support&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Our organization does not have the Exchange 2016 and 2019 Period 2 ESU. How can we get current Exchange 2016 or 2019 updates?&lt;/STRONG&gt;&lt;BR /&gt;Since Exchange 2016 and 2019 are now &lt;A href="https://techcommunity.microsoft.com/blog/exchange/support-for-exchange-server-2016-and-exchange-server-2019-ends-today/4461192" target="_blank" rel="noopener"&gt;out of support&lt;/A&gt;, only customers who have enrolled into the &lt;A href="https://techcommunity.microsoft.com/blog/exchange/announcing-period-2-exchange-20162019-extended-security-update-esu-program/4511603" target="_blank" rel="noopener"&gt;Period 2 ESU program&lt;/A&gt; (which is valid between May and October 2026) can obtain Exchange 2016 or 2019 updates released after May 2026. For all other customers still running Exchange 2016 or 2019, we recommend that you &lt;A href="https://techcommunity.microsoft.com/blog/exchange/upgrading-your-organization-from-current-versions-to-exchange-server-se/4241305" target="_blank" rel="noopener"&gt;upgrade your organization to Exchange SE&lt;/A&gt; as soon as possible.&lt;/P&gt;
&lt;P style="background: #F0F0F0; padding: .5em; margin: 1em 0 1em 0;"&gt;Documentation may not be fully available at the time this post is published.&lt;/P&gt;
&lt;P&gt;Updates to this blog post:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Sep 8, 2026:&lt;/STRONG&gt; Corrected one of issues addressed to the free/busy time zone issue over Graph&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This post might receive future updates; they will be listed here (if available).&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-12"&gt;The Exchange Server Team&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2026 20:40:02 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/exchange-team-blog/released-september-2026-exchange-server-security-updates/ba-p/4554411</guid>
      <dc:creator>The_Exchange_Team</dc:creator>
      <dc:date>2026-09-08T20:40:02Z</dc:date>
    </item>
    <item>
      <title>Exchange Server AD FS Modern Authentication: Expanded Outlook client support</title>
      <link>https://techcommunity.microsoft.com/t5/exchange-team-blog/exchange-server-ad-fs-modern-authentication-expanded-outlook/ba-p/4554410</link>
      <description>&lt;P&gt;&lt;STRONG&gt;We are pleased to announce expanded Outlook client support for Exchange Server AD FS Modern Authentication.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;In our &lt;A href="https://techcommunity.microsoft.com/blog/exchange/update-on-exchange-server-adfs-modern-authentication-support/4338563" target="_blank"&gt;previous update&lt;/A&gt;, we announced broad Outlook for Windows/Mac support and support for the native Mail app on iOS and macOS. We are now extending this support to Outlook for iOS and Outlook for Android.&lt;/P&gt;
&lt;P&gt;Outlook for iOS and Outlook for Android can now use AD FS Modern Authentication to access mailboxes in supported pure on-premises Exchange Server deployments.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Deployment context: &lt;/STRONG&gt;AD FS Modern Authentication is intended for pure on-premises Exchange organizations that don't use Microsoft Entra ID or an Exchange hybrid configuration. Exchange hybrid organizations should continue to use Hybrid Modern Authentication (HMA) with Microsoft Entra ID.&lt;/P&gt;
&lt;H1&gt;Supported clients at a glance&lt;/H1&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 706px; border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;&lt;STRONG&gt;Client&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;&lt;STRONG&gt;Supported release or OS&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;&lt;STRONG&gt;Administrator action&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;Outlook for Windows&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;Supported Microsoft 365 Apps channels and supported perpetual releases; Windows 11 22H2 or later&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;Install the required Windows update, trust the AD FS service URLs, and enable Exchange on-premises Modern Auth in Outlook.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;Outlook for Mac&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;Outlook for Mac in Microsoft 365, build 16.106 or later; macOS Sequoia or later&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;Use Exchange Server Subscription Edition with the December 2025 or later Security Update, and configure ADFSAuthorizedURLs.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;Outlook for iOS&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;Latest supported Outlook and iOS versions&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;Follow the Exchange and AD FS configuration guidance.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;Outlook for Android&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;Latest supported Outlook and Android versions&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;Follow the Exchange and AD FS configuration guidance.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;Native Mail app for iOS and macOS&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;iOS 17.6.1 or later; macOS Sequoia or later&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;Configure the documented native client application and permissions in the AD FS Outlook application group.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;H3&gt;Updated documentation&lt;/H3&gt;
&lt;P&gt;We have updated the deployment documentation to make the supported-client requirements easier to review:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;A new summary brings all supported clients and operating-system requirements together.&lt;/LI&gt;
&lt;LI&gt;Outlook for Windows build, Windows update, registry, and AD FS trusted-domain requirements are grouped under the Windows client.&lt;/LI&gt;
&lt;LI&gt;Outlook for Mac requirements include the ADFSAuthorizedURLs Terminal configuration, a multiple-namespace example, and the equivalent Mobile Device Management settings.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Learn more&lt;/H3&gt;
&lt;P&gt;For complete prerequisites and configuration steps, see &lt;A href="https://aka.ms/ExchangeADFSModernAuth" target="_blank"&gt;Enable Modern Auth in Exchange Server on-premises&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;For background on the earlier client expansion, see &lt;A href="https://techcommunity.microsoft.com/blog/exchange/update-on-exchange-server-adfs-modern-authentication-support/4338563" target="_blank"&gt;Update on Exchange Server ADFS Modern Authentication support&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-12"&gt;The Exchange Server Team&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2026 14:14:41 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/exchange-team-blog/exchange-server-ad-fs-modern-authentication-expanded-outlook/ba-p/4554410</guid>
      <dc:creator>The_Exchange_Team</dc:creator>
      <dc:date>2026-09-08T14:14:41Z</dc:date>
    </item>
    <item>
      <title>Take control of your EWSAllowedAppIDs list before EWS access changes</title>
      <link>https://techcommunity.microsoft.com/t5/exchange-team-blog/take-control-of-your-ewsallowedappids-list-before-ews-access/ba-p/4553534</link>
      <description>&lt;P&gt;As we prepare for the final phase of Exchange Web Services retirement, we are refining how &lt;A href="https://techcommunity.microsoft.com/blog/exchange/introducing-ewsallowedappids-preparing-for-the-final-phase-of-ews-retirement/4529471" target="_blank"&gt;EWSAllowedAppIDs&lt;/A&gt; setting (which you can use to define your EWS AppID allow list) will be applied. Our goal is to protect customers from unexpected disruption while keeping control of the allow list with each tenant administrator.&lt;/P&gt;
&lt;P style="background: #FFFF99; padding: .5em; margin: 1em 0 1em 0;"&gt;&lt;STRONG&gt;We strongly recommend that every customer review EWS usage and configure EWSAllowedAppIDs themselves. If an administrator has already configured EWSAllowedAppIDs, Microsoft will not overwrite or change the list. The customer-managed list remains authoritative.&lt;/STRONG&gt;&lt;/P&gt;
&lt;H3&gt;What happens during rollout&lt;/H3&gt;
&lt;P&gt;Beginning October 1, 2026, Microsoft will start enabling the updated behavior as outlined in &lt;A href="https://techcommunity.microsoft.com/blog/exchange/introducing-ewsallowedappids-preparing-for-the-final-phase-of-ews-retirement/4529471" target="_blank"&gt;previous blog post&lt;/A&gt;. With this logic change, if the customer has EWSEnabled set to True, EWS will require an Allowed AppID list. The timing will depend on when the change reaches that tenant's environment.&lt;/P&gt;
&lt;P&gt;If organization has:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;EWSEnabled = True&lt;/STRONG&gt; - Microsoft will ensure that each tenant has an EWSAllowedAppIDs list. If the customer has not created a list, Microsoft will populate one to reduce the risk of an outage when the cloud environment logic changes (and AppID allow list becomes required when EWSEnabled = True). The list will be based on the previous 60 days of usage, and so it may miss applications that run infrequently, and it may include apps you no longer want to have access. This will happen shortly before the logic change takes place.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;EWSEnabled = Null&lt;/STRONG&gt; - Microsoft will only populate EWSAllowedAppIDs, if the customer has not already done so. This will happen a few days before changing EWSEnabled to False during the per-tenant rollout of that setting. This means that tenants that did not change EWSEnabled property from Null could have no AppID allow list defined until later in October.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Customers that still require EWS should act now: configure EWSAllowedAppIDs to include only the applications that must continue using EWS, then set EWSEnabled to True. Continue planning to move applications from EWS to Microsoft Graph before EWS is retired. By controlling your own EWSAllowedAppIDs values, you can ensure that only applications that you really want to have EWS access after October rollouts start can still use EWS.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-12"&gt;The Exchange Team&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Sep 2026 14:47:38 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/exchange-team-blog/take-control-of-your-ewsallowedappids-list-before-ews-access/ba-p/4553534</guid>
      <dc:creator>The_Exchange_Team</dc:creator>
      <dc:date>2026-09-04T14:47:38Z</dc:date>
    </item>
    <item>
      <title>Exchange 2016/2019: Throttling and Blocking up to the Final Public Update Baseline</title>
      <link>https://techcommunity.microsoft.com/t5/exchange-team-blog/exchange-2016-2019-throttling-and-blocking-up-to-the-final/ba-p/4552717</link>
      <description>&lt;P&gt;Several years ago, we announced &lt;A href="https://techcommunity.microsoft.com/blog/exchange/throttling-and-blocking-email-from-persistently-vulnerable-exchange-servers-to-e/3815328" target="_blank" rel="noopener"&gt;Throttling and Blocking Email from Persistently Vulnerable Exchange Servers to Exchange Online&lt;/A&gt;. Since then, we have been periodically updating the “oldest acceptable version” as we keep releasing more security updates for Exchange Server.&lt;/P&gt;
&lt;P&gt;So far, these changes have been implemented silently. But, today, we are announcing that starting in the second week of September 2026, we will raise the oldest allowed version for Exchange 2016 or Exchange 2019 servers that connect to Exchange Online over an &lt;A href="https://learn.microsoft.com/en-us/exchange/mail-flow-best-practices/use-connectors-to-configure-mail-flow/inbound-connector-faq" target="_blank" rel="noopener"&gt;inbound connector type of OnPremises&lt;/A&gt; to &lt;EM&gt;at least&lt;/EM&gt; the &lt;A href="https://learn.microsoft.com/en-us/exchange/new-features/build-numbers-and-release-dates" target="_blank" rel="noopener"&gt;last available public update version, released in October 2025&lt;/A&gt;. This update level was released almost a year ago, and all organizations should have updated to it, since.&lt;/P&gt;
&lt;P&gt;A very important implication of this change:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;After going into effect, the oldest Exchange Server version allowed to send email to Exchange Online over the inbound OnPremises connector will be Exchange with October 2025 updates.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;The next time we update the oldest allowed Exchange Server version for sending email to Exchange Online, the &lt;U&gt;required version of Exchange Server 2016 or Exchange Server 2019 will be newer than any publicly available update&lt;/U&gt;&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;When the next adjustment happens (we estimate in several months), &lt;EM&gt;only customers who were enrolled into our &lt;/EM&gt;&lt;A href="https://techcommunity.microsoft.com/blog/exchange/announcing-period-2-exchange-20162019-extended-security-update-esu-program/4511603" target="_blank" rel="noopener"&gt;&lt;EM&gt;ESU program&lt;/EM&gt;&lt;/A&gt;&lt;EM&gt; and customers who migrated to Exchange SE will have the required update versions to not be throttled or blocked when sending email to Exchange Online&lt;/EM&gt;.&lt;/P&gt;
&lt;P&gt;As a reminder, throttling and blocking of email from persistently vulnerable Exchange servers to Exchange Online:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Applies to servers that connect to Exchange Online over an &lt;A href="https://learn.microsoft.com/en-us/exchange/mail-flow-best-practices/use-connectors-to-configure-mail-flow/inbound-connector-faq" target="_blank" rel="noopener"&gt;inbound connector type of OnPremises&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;DOES NOT apply to servers that send email to Exchange Online in other ways (different types of connectors etc.)&lt;/LI&gt;
&lt;LI&gt;DOES NOT (currently) apply to “all servers in your organization”, but only to servers that connect to Exchange Online over an &lt;A href="https://learn.microsoft.com/en-us/exchange/mail-flow-best-practices/use-connectors-to-configure-mail-flow/inbound-connector-faq" target="_blank" rel="noopener"&gt;inbound connector type of OnPremises&lt;/A&gt;. This might change in the future.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Finally, we wanted to be clear that the fact that the “oldest version to avoid throttling and blocking in Exchange Online” is always older than the &lt;A href="https://learn.microsoft.com/en-us/exchange/new-features/build-numbers-and-release-dates" target="_blank" rel="noopener"&gt;latest version available&lt;/A&gt; does not mean that we consider versions older than the latest security update “safe to use”. Anything older than the latest is vulnerable to everything we have fixed/released/announced since that older version. Especially in this calendar year, we have been releasing many security updates for Exchange Server and it is&amp;nbsp;&lt;A href="https://techcommunity.microsoft.com/blog/exchange/where-is-exchange-se-cu1-anyway/4546837" target="_blank" rel="noopener"&gt;likely that we will continue to do so for the foreseeable future&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;With a rapidly changing security landscape, &lt;EM&gt;no organization should consider it safe to run their organization's business email on an outdated version of Exchange Server&lt;/EM&gt;. Please see &lt;A href="https://learn.microsoft.com/en-us/exchange/plan-and-deploy/post-installation-tasks/security-best-practices/exchange-server-update-faq" target="_blank" rel="noopener"&gt;Exchange Server update FAQ&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Additional reading: &lt;A href="https://techcommunity.microsoft.com/blog/exchange/how-to-pause-throttling-and-blocking-of-out-of-date-on-premises-exchange-servers/4007169" target="_blank" rel="noopener"&gt;How to pause throttling and blocking of out-of-date on-premises Exchange Servers&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-12"&gt;The Exchange Server Team&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Sep 2026 15:34:48 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/exchange-team-blog/exchange-2016-2019-throttling-and-blocking-up-to-the-final/ba-p/4552717</guid>
      <dc:creator>The_Exchange_Team</dc:creator>
      <dc:date>2026-09-02T15:34:48Z</dc:date>
    </item>
    <item>
      <title>Tell us how you use ObjectGuid, SamAccountName, and DistinguishedName in Exchange Online</title>
      <link>https://techcommunity.microsoft.com/t5/exchange-team-blog/tell-us-how-you-use-objectguid-samaccountname-and/ba-p/4550939</link>
      <description>&lt;P&gt;As Exchange Online continues its multi-year directory modernization, we are evaluating the future of several long-standing identifier properties: &lt;STRONG&gt;ObjectGuid &lt;/STRONG&gt;(most would recognize this property as &lt;STRONG&gt;Guid&lt;/STRONG&gt;)&lt;STRONG&gt;, SamAccountName, and DistinguishedName&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;Today, multiple properties can identify the same object in &lt;STRONG&gt;Exchange Online&lt;/STRONG&gt;. While this has provided flexibility and compatibility, some of these identifiers reflect design decisions from an earlier era and can add complexity for customers building and maintaining automation, integrations, and administrative workflows.&lt;/P&gt;
&lt;P&gt;As part of our modernization efforts, we are exploring whether a smaller and more consistent set of identifiers could better support the future of the service. &lt;STRONG&gt;No decisions have been made.&lt;/STRONG&gt; Before determining a path forward, we want to better understand how these properties are used today, what the impact of potential changes could be, and what alternatives, notice periods, and migration assistance customers would need.&lt;/P&gt;
&lt;P&gt;We are particularly interested in hearing from customers, partners, and solution providers who use these properties in scripts, automation, reporting, applications, provisioning systems, or operational processes.&lt;/P&gt;
&lt;P&gt;The potential changes discussed in this survey apply only to the &lt;STRONG&gt;Exchange Online directory&lt;/STRONG&gt; and do not represent changes to on-premises Active Directory or Exchange Server.&lt;/P&gt;
&lt;P&gt;Please take a few minutes to complete our survey. Your feedback will help inform our evaluation and any future decisions in this area.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Take the Survey: &lt;A href="https://forms.cloud.microsoft/r/iuAzV3940x" target="_blank" rel="noopener"&gt;Exchange Online Directory: Identifier Properties Survey – Fill out form&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Thank you!&lt;BR /&gt;&lt;SPAN class="lia-text-color-12"&gt;The Exchange Team&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Sep 2026 17:31:16 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/exchange-team-blog/tell-us-how-you-use-objectguid-samaccountname-and/ba-p/4550939</guid>
      <dc:creator>The_Exchange_Team</dc:creator>
      <dc:date>2026-09-02T17:31:16Z</dc:date>
    </item>
    <item>
      <title>Help us shape Exchange Server on-premises to different online org Free/Busy after EWS retirement</title>
      <link>https://techcommunity.microsoft.com/t5/exchange-team-blog/help-us-shape-exchange-server-on-premises-to-different-online/ba-p/4549691</link>
      <description>&lt;P&gt;As shared in &lt;A href="https://techcommunity.microsoft.com/blog/exchange/exchange-online-ews-your-time-is-almost-up/4492361" target="_blank"&gt;Exchange Online EWS, Your Time is Almost Up&lt;/A&gt;, Exchange Web Services in Exchange Online will begin phased disablement in October 2026 and will be fully disabled in April 2027. As part of this work, we are addressing the remaining Exchange Server collaboration scenarios that currently depend on the Exchange Online EWS endpoint.&lt;/P&gt;
&lt;P&gt;Most Exchange Server Free/Busy scenarios will not change. Free/Busy between two Exchange Server (purely on-premises) organizations will continue using Federation/DAuth and Organization Relationships. Exchange hybrid organization can continue sharing Free/Busy between Exchange Server and its own Exchange Online tenant using OAuth and IntraOrganizationConnectors through the dedicated &lt;A href="https://learn.microsoft.com/en-us/exchange/hybrid-deployment/deploy-dedicated-hybrid-app" target="_blank"&gt;Exchange hybrid app&lt;/A&gt;, with Graph replacing EWS in the modern hybrid flow.&lt;/P&gt;
&lt;P&gt;The scenario requiring a new path is an &lt;STRONG&gt;&lt;SPAN class="lia-text-color-11"&gt;Exchange Server organization retrieving Free/Busy or MailTips from another organization's Exchange Online tenant&lt;/SPAN&gt;&lt;/STRONG&gt; through an EWS-dependent Organization Relationship. For Exchange Server to external Exchange Online scenario, we are evaluating leveraging &lt;A href="https://learn.microsoft.com/en-us/exchange/sharing/migrate-to-m365-xtap" target="_blank"&gt;Microsoft 365 Cross-Tenant Access Policy&lt;/A&gt; which is also becoming the standard for Free/Busy, calendar, and MailTips collaboration between Microsoft 365 tenants.&lt;/P&gt;
&lt;P&gt;Before finalizing the direction, we want feedback from customers and partners - particularly organizations that operate Exchange Server without an existing M365 tenant.&lt;/P&gt;
&lt;P&gt;Please share your feedback on this approach through the form: &lt;A href="https://forms.cloud.microsoft/r/BmHCNzncEf" target="_blank"&gt;Survey&lt;/A&gt;&lt;/P&gt;
&lt;P style="background: #F0F0F0; padding: .5em; margin: 1em 0 1em 0;"&gt;This feedback request is specifically about &lt;STRONG&gt;Exchange Server (Organization A) to a different Exchange Online (Organization B) collaboration&lt;/STRONG&gt;. Exchange Server-to-Exchange Server Organization Relationships (two purely on-premises organizations) are &lt;EM&gt;not in scope and will continue unchanged&lt;/EM&gt;.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-12"&gt;The Exchange Team&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Aug 2026 16:57:31 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/exchange-team-blog/help-us-shape-exchange-server-on-premises-to-different-online/ba-p/4549691</guid>
      <dc:creator>The_Exchange_Team</dc:creator>
      <dc:date>2026-08-24T16:57:31Z</dc:date>
    </item>
    <item>
      <title>Notes from the field: testing EWSAllowedAppIDs safely</title>
      <link>https://techcommunity.microsoft.com/t5/exchange-team-blog/notes-from-the-field-testing-ewsallowedappids-safely/ba-p/4548568</link>
      <description>&lt;P&gt;As customers prepare for the final phase of Exchange Web Services (EWS) retirement in Exchange Online, many are asking the same practical question: how can I prove that &lt;EM&gt;EWSAllowedAppIDs&lt;/EM&gt; is working before I depend on it? This field guide walks through a controlled positive-and-negative test, explains what the result means, and highlights an important naming trap that we are already seeing in customer conversations.&lt;/P&gt;
&lt;H3&gt;A note from the field&lt;/H3&gt;
&lt;P&gt;The most common confusion is not about the PowerShell syntax. It is about two similarly named controls that operate at different layers. &lt;STRONG&gt;EWSAllowedAppIDs&lt;/STRONG&gt; is the new application-ID control for EWS. The older &lt;STRONG&gt;EWSAllowList&lt;/STRONG&gt; and &lt;STRONG&gt;EWSBlockList&lt;/STRONG&gt; settings are user-agent controls associated with &lt;STRONG&gt;EwsApplicationAccessPolicy&lt;/STRONG&gt;, and they can affect both EWS and REST traffic.&lt;/P&gt;
&lt;H3&gt;Understand the two controls before testing&lt;/H3&gt;
&lt;P&gt;EWSAllowedAppIDs is a tenant-level list of application (client) IDs. When EWS is enabled and the list contains one or more Application IDs, only the listed applications are permitted to access EWS. This is the control to validate when you are testing an application's EWS access during the retirement transition.&lt;/P&gt;
&lt;P&gt;EWSAllowList and EWSBlockList are older, user-agent-based controls. Despite their names, the underlying access policy is not limited to EWS; it can also affect REST requests. Customers that already use these settings may still need them for REST access control after EWS retirement.&lt;/P&gt;
&lt;P&gt;The controls are evaluated independently. In practical terms, an EWS request must pass the application-ID control and then any applicable user-agent control. A successful App-ID test therefore does not prove that a separate user-agent policy is configured correctly.&lt;/P&gt;
&lt;H3&gt;What the test proves&lt;/H3&gt;
&lt;P&gt;A valid before-and-after test demonstrates the EWSAllowedAppIDs behavior only when all of the following are true:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The application can obtain an OAuth token.&lt;/LI&gt;
&lt;LI&gt;The application has EWS application permission and tenant-wide admin consent.&lt;/LI&gt;
&lt;LI&gt;EWSEnabled is set to True for the test.&lt;/LI&gt;
&lt;LI&gt;The test mailbox contains at least one item in the Inbox.&lt;/LI&gt;
&lt;LI&gt;The App ID is present for the positive test and absent for the negative test.&lt;/LI&gt;
&lt;LI&gt;At least 24 hours has elapsed after each allow-list change.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Before you start&lt;/H3&gt;
&lt;P style="background: #F0F0F0; padding: .5em; margin: 1em 0 1em 0;"&gt;Perform this procedure in a test tenant if you can. Removing an application from the list can stop a production workload from accessing EWS after the configuration change has propagated.&lt;/P&gt;
&lt;P&gt;Prepare the following:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;A test mailbox with at least one Inbox item.&lt;/LI&gt;
&lt;LI&gt;An app registration in the same tenant as the mailbox.&lt;/LI&gt;
&lt;LI&gt;EWS application permission with tenant-wide admin consent.&lt;/LI&gt;
&lt;LI&gt;A client secret or certificate for application authentication. Treat a client secret as a password and do not place it in a shared script or source-control repository.&lt;/LI&gt;
&lt;LI&gt;Exchange Online PowerShell access and permission to run Get-OrganizationConfig and Set-OrganizationConfig.&lt;/LI&gt;
&lt;LI&gt;Download the &lt;A class="lia-external-url" href="https://github.com/David-Barrett-MS/PowerShell-EWS-Scripts/blob/master/Legacy/Test-EWSAppAccess.ps1" target="_blank"&gt;Test-EWSAppAccess.ps1&lt;/A&gt; script. This is a test script that you can use unless you want to test with a real app. Script documentation can be found at &lt;A class="lia-external-url" href="https://github.com/David-Barrett-MS/PowerShell-EWS-Scripts/wiki/Testing-EWS-App-Access" target="_blank"&gt;Testing EWS App Access&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Record the tenant ID, application (client) ID, test mailbox SMTP address, and the selected authentication material before starting.&lt;/P&gt;
&lt;H3&gt;Test 1: Confirm access while the app is allowed&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;Connect to Exchange Online PowerShell.&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI-CODE lang="powershell"&gt;Connect-ExchangeOnline&lt;/LI-CODE&gt;
&lt;UL&gt;
&lt;LI&gt;Inspect the current EWS state and capture the complete existing App-ID list.&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI-CODE lang="powershell"&gt;Get-OrganizationConfig | Format-List EWSEnabled
Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy | Format-List EwsAllowedAppIDs&lt;/LI-CODE&gt;
&lt;UL&gt;
&lt;LI&gt;For a controlled test, set EWSEnabled to $null (all EWS allowed, AppID Allow List ignored).&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI-CODE lang="powershell"&gt;Set-OrganizationConfig -EWSEnabled $null&lt;/LI-CODE&gt;
&lt;UL&gt;
&lt;LI&gt;Add the test App ID without overwriting any existing entries. The EwsAllowedAppIDs command writes the complete list, so preserve the current value.&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI-CODE lang="powershell"&gt;$current = (Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy).EwsAllowedAppIDs
$updated = @($current -split "," | ForEach-Object { $_.Trim() } | Where-Object { $_ }; $appId) | Select-Object -Unique
Set-OrganizationConfig -EwsAllowedAppIDs ($updated -join ",")&lt;/LI-CODE&gt;
&lt;UL&gt;
&lt;LI&gt;Verify that the App ID was written.&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI-CODE lang="powershell"&gt;Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy | Format-List EwsAllowedAppIDs&lt;/LI-CODE&gt;
&lt;UL&gt;
&lt;LI&gt;Wait for the change to propagate. Because of the Exchange Online configuration caching, this can take &lt;SPAN class="lia-text-color-8"&gt;up to 24 hours&lt;/SPAN&gt;.&lt;/LI&gt;
&lt;LI&gt;Set EWSEnabled to True&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI-CODE lang="powershell"&gt;Set-OrganizationConfig -EWSEnabled $true&lt;/LI-CODE&gt;
&lt;UL&gt;
&lt;LI&gt;Wait for &lt;SPAN class="lia-text-color-8"&gt;1 hour&lt;/SPAN&gt;, for the change to become effective.&lt;/LI&gt;
&lt;LI&gt;Download&amp;nbsp;&lt;A href="https://github.com/David-Barrett-MS/PowerShell-EWS-Scripts/blob/master/Legacy/Test-EWSAppAccess.ps1" target="_blank"&gt;Test-EWSAppAccess.ps1&lt;/A&gt; and run Test-EWSAppAccess.ps1 with application authentication. The Mailbox parameter is required when using application permissions.&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI-CODE lang="powershell"&gt;.\Test-EWSAppAccess.ps1 -AppId $appId -TenantId $tenantId -Mailbox $mailbox -SecretKey $secretKey&lt;/LI-CODE&gt;
&lt;UL&gt;
&lt;LI&gt;A successful test should report that the application accessed the mailbox.&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI-CODE lang="powershell"&gt;Application &amp;lt;appid&amp;gt; successfully accessed mailbox &amp;lt;mailbox&amp;gt;&amp;lt;/mailbox&amp;gt;&amp;lt;/appid&amp;gt;&lt;/LI-CODE&gt;
&lt;UL&gt;
&lt;LI&gt;Confirm that $LASTEXITCODE is 0 and save the output with your change record.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Test 2: Remove the app and confirm access is blocked&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;Remove only the test App ID, preserving every other entry.&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI-CODE lang="powershell"&gt;$current = (Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy).EwsAllowedAppIDs
$updated = $current -split "," | ForEach-Object { $_.Trim() } | Where-Object { $_ -and $_ -ne $appId }
Set-OrganizationConfig -EwsAllowedAppIDs ($updated -join ",")&lt;/LI-CODE&gt;
&lt;UL&gt;
&lt;LI&gt;Confirm that the App ID is no longer present.&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI-CODE lang="powershell"&gt;Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy | Format-List EwsAllowedAppIDs&lt;/LI-CODE&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN class="lia-text-color-8"&gt;Wait at least 24 hours before retesting&lt;/SPAN&gt;. An immediate success can simply mean that an Exchange Online server still has the previous configuration cached.&lt;/LI&gt;
&lt;LI&gt;Run the same Test-EWSAppAccess.ps1 command again.&lt;/LI&gt;
&lt;LI&gt;After propagation, the expected result is a failure.&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI-CODE lang="powershell"&gt;Application &amp;lt;appid&amp;gt; failed to access mailbox &amp;lt;mailbox&amp;gt;&amp;lt;/mailbox&amp;gt;&amp;lt;/appid&amp;gt;&lt;/LI-CODE&gt;
&lt;P&gt;Confirm that the process returns exit code 1. If the first test failed too, troubleshoot authentication, permissions, consent, mailbox access, and script dependencies before concluding that the allow list caused the failure.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Restore the test App ID to the full list, verify the configuration, wait for propagation, and repeat the successful-access test.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="background: #FFFF99; padding: .5em; margin: 1em 0 1em 0;"&gt;Do not leave a production tenant with an unintentionally empty or incomplete App ID allow list.&lt;/P&gt;
&lt;H3&gt;The fastest way to re-enable EWS after App ID blocking&lt;/H3&gt;
&lt;P&gt;Let’s say you are testing this process in a tenant and after setting both EWSEnabled = True and populating EWSAllowedAppIDs you do not see results that you expected and need the quickest way to undo your changes and re-enable the use of EWS in your tenant.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Changes to EWSAllowedAppIDs take ~24 hours to fully apply to your tenant.&lt;/LI&gt;
&lt;LI&gt;Changes to EWSEnabled take about 1 hour.&lt;/LI&gt;
&lt;LI&gt;EWSAllowedAppIDs (Allow List) is ignored if EWSEnabled is set to Null.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Therefore, the quickest way to re-enable EWS in an unrestricted way is to &lt;STRONG&gt;set EWSEnabled back to Null&lt;/STRONG&gt;. One hour later, EWS will be unrestricted:&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;Set-OrganizationConfig -EWSEnabled $null&lt;/LI-CODE&gt;
&lt;H3&gt;EWSEditor is another option&lt;/H3&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://github.com/dseph/EwsEditor" target="_blank"&gt;EWSEditor&lt;/A&gt; is also available for administrators and developers who prefer an interactive EWS API explorer. It can be useful for making a real EWS call against a test mailbox while using the same application identity you are validating.&lt;/P&gt;
&lt;P&gt;You still need a correctly configured OAuth application, EWS permissions and consent, a controlled test mailbox, a recorded baseline, and enough time for EWSAllowedAppIDs changes to propagate.&lt;/P&gt;
&lt;H3&gt;Common pitfalls to avoid&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;Running the negative test immediately after removing the App ID.&lt;/LI&gt;
&lt;LI&gt;Replacing the entire list instead of preserving existing App IDs.&lt;/LI&gt;
&lt;LI&gt;Testing with an empty Inbox when the test script reads the first Inbox item.&lt;/LI&gt;
&lt;LI&gt;Treating an OAuth, permission, consent, or credential failure as proof that EWSAllowedAppIDs blocked the request.&lt;/LI&gt;
&lt;LI&gt;Confusing the user-agent-based EWSAllowList or EWSBlockList with the new App-ID-based EWSAllowedAppIDs control.&lt;/LI&gt;
&lt;LI&gt;Adding an App ID for a workload that uses REST but does not call EWS.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Customer guidance in one paragraph&lt;/H3&gt;
&lt;P&gt;If an application calls EWS and requires temporary access during the retirement transition, validate its application ID with EWSAllowedAppIDs in a test tenant. If a tenant already uses EwsApplicationAccessPolicy, assess its EWSAllowList or EWSBlockList separately because those user-agent settings can also affect REST. The similar names do not make the controls interchangeable.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;The simple rule: use EWSAllowedAppIDs for the new EWS application-ID gate; use EWSAllowList or EWSBlockList only for the older user-agent policy. Test each layer independently.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;This distinction matters because we are already seeing customers assume that any setting beginning with “EWS” is part of the EWS retirement exception process. It is not. Making that mistake can create unnecessary configuration changes or interrupt REST workloads that were never using EWS.&lt;/P&gt;
&lt;H3&gt;Sources and further reading&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;Testing EWS App Access, PowerShell-EWS-Scripts Wiki: &lt;A href="https://github.com/David-Barrett-MS/PowerShell-EWS-Scripts/wiki/Testing-EWS-App-Access" target="_blank"&gt;https://github.com/David-Barrett-MS/PowerShell-EWS-Scripts/wiki/Testing-EWS-App-Access&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;EWSEditor project: &lt;A href="https://github.com/dseph/EwsEditor" target="_blank"&gt;https://github.com/dseph/EwsEditor&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-12"&gt;David Barrett&lt;/SPAN&gt;&lt;BR /&gt;(All-round good guy and Exchange development expert)&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2026 14:21:26 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/exchange-team-blog/notes-from-the-field-testing-ewsallowedappids-safely/ba-p/4548568</guid>
      <dc:creator>The_Exchange_Team</dc:creator>
      <dc:date>2026-08-20T14:21:26Z</dc:date>
    </item>
    <item>
      <title>Understanding the new 100 GB mailbox entitlement for Microsoft 365 Business suites</title>
      <link>https://techcommunity.microsoft.com/t5/exchange-team-blog/understanding-the-new-100-gb-mailbox-entitlement-for-microsoft/ba-p/4548243</link>
      <description>&lt;P&gt;Microsoft 365 Business Basic, Business Standard, and Business Premium now include an additional 50 GB of primary email storage for eligible users. This brings the supported primary mailbox entitlement from 50 GB to a maximum of 100 GB. We wanted to talk about this change, so Exchange Online administrators understand how this mailbox size increase is delivered. We will focus only on mailbox size in this post.&lt;/P&gt;
&lt;H3&gt;What changed for the Business suites&lt;/H3&gt;
&lt;P&gt;Microsoft &lt;A href="https://www.microsoft.com/en-us/licensing/news/2026-M365-Packaging-Pricing-Updates" target="_blank" rel="noopener"&gt;announced&lt;/A&gt; an additional 50 GB of email storage for Microsoft 365 Business Basic, Business Standard, and Business Premium as part of the 2026 Microsoft 365 packaging updates. The packaging changes are rolling out June - September 2026, with customers receiving advance notice through Message Center before the changes became available in their tenant.&lt;/P&gt;
&lt;P&gt;The additional storage changes the effective primary mailbox size for eligible Business suite users from 50 GB to 100 GB. The affected commercial product suites are:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Microsoft 365 Business Basic&lt;/LI&gt;
&lt;LI&gt;Microsoft 365 Business Standard&lt;/LI&gt;
&lt;LI&gt;Microsoft 365 Business Premium&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;After the rollout, all users that had the appropriate licenses assigned will have received a new service plan and the corresponding mailbox quota increase.&lt;/P&gt;
&lt;P&gt;Please note: this mailbox size increase applies only to the above-mentioned suite licenses; there can still be licenses (such as standalone Exchange Online Plan 1) that have the maximum mailbox size set at 50 GB.&lt;/P&gt;
&lt;H3&gt;The supported quota outcome&lt;/H3&gt;
&lt;P&gt;The additional storage establishes a maximum effective quota of 100 GB for the eligible Business suite scenario.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;A user whose highest applicable Exchange mailbox plan is the Business suite plan receives an effective 100 GB quota when the storage add-on is present.&lt;/LI&gt;
&lt;LI&gt;A user who also has an Enterprise or standalone Exchange license that already provides a 100 GB mailbox remains entitled to 100 GB.&lt;/LI&gt;
&lt;LI&gt;A user who has multiple licenses assigned, which contain multiple Exchange service plans (this is known as &lt;A href="https://techcommunity.microsoft.com/blog/exchange/introducing-support-for-concurrent-exchange-online-license-assignments/3721098" target="_blank" rel="noopener"&gt;Concurrent Licensing&lt;/A&gt;), will be granted the maximum quota provided by a single product – the quotas are not additive across products. For example, a user with one of the Business Suite and a separate Enterprise license containing Exchange Online Plan 2, will still be entitled to 100 GB. The quota increase for the Business suites affects the base mailbox size only. It does not provide archive capabilities.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;How the additional quota is implemented&lt;/H3&gt;
&lt;P&gt;The Business suite provides the total storage through a combination of service plans:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The Business suite Exchange plan is represented by BPOS_S_STANDARD, which grants 50 GB of storage.&lt;/LI&gt;
&lt;LI&gt;The additional entitlement is represented by the EXCHANGE_STORAGE_50GB service plan, which adds +50 GB, increasing the total quota to 100 GB.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Both plans must be enabled for the user to have the full 100 GB.&lt;/P&gt;
&lt;P&gt;In your Microsoft 365 admin center, this will look like the following – there is a “standard” license and there is an add-on:&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Custom mailbox quotas are preserved&lt;/H3&gt;
&lt;P&gt;If an administrator has configured a custom mailbox quota, the additional storage logic does not overwrite that setting. Likewise, removing the add-on does not replace a later administrator-defined custom value. This protects deliberate tenant-level mailbox management choices.&lt;/P&gt;
&lt;P&gt;For example, if an administrator configured the mailbox for user with a Business suite from the original default of 50 GB down to 20 GB, the user’s quota will remain at 20 GB even after the additional service plan is assigned to them.&lt;/P&gt;
&lt;H3&gt;Reviewing the user’s licenses and service plans&lt;/H3&gt;
&lt;P&gt;In the Microsoft 365 admin center, open Users &amp;gt; Active users, select the user, and review Licenses and apps. Confirm that the user has an eligible Microsoft 365 Business suite and that its included services are enabled. The Billing &amp;gt; Licenses page can also show whether the product was assigned directly or through group-based licensing.&lt;/P&gt;
&lt;P&gt;Microsoft Graph PowerShell can provide a more detailed service-plan view. The following example retrieves the assigned license details and searches for the storage service plan:&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;$licenses = Get-MgUserLicenseDetail -UserId user@contoso.com
$licenses.ServicePlans | Where-Object ServicePlanName -eq "EXCHANGE_STORAGE_50GB" | Select-Object ServicePlanName, ProvisioningStatus&lt;/LI-CODE&gt;
&lt;H3&gt;Review the effective Exchange mailbox quota&lt;/H3&gt;
&lt;P&gt;Exchange Online PowerShell shows the quota values that Exchange presents for the mailbox. For example:&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;Get-Mailbox -Identity user@contoso.com | Format-List IssueWarningQuota, ProhibitSendQuota, ProhibitSendReceiveQuota, UseDatabaseQuotaDefaults&lt;/LI-CODE&gt;
&lt;P&gt;For an eligible Business suite user with the additional storage service plan and no custom quota, the effective maximum mailbox quota should be 100 GB.&lt;/P&gt;
&lt;H3&gt;Common license and quota scenarios&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;Business suite with the +50 GB storage add-on: user’s effective primary mailbox maximum is 100 GB.&lt;/LI&gt;
&lt;LI&gt;Business suite without the +50 GB storage add-on: base Business mailbox quota continues to apply until the additional service plan is provisioned (should happen automatically).&lt;/LI&gt;
&lt;LI&gt;Business suite plus an Enterprise or standalone plan that already grants 100 GB: effective maximum remains 100 GB because Exchange uses the highest applicable entitlement rather than adding the quotas.&lt;/LI&gt;
&lt;LI&gt;Business suite plus a lower Exchange capability (for example, F3 license): Business plan remains the highest capability, so the add-on can raise the effective maximum to 100 GB.&lt;/LI&gt;
&lt;LI&gt;Custom quota: administrator-defined values remain in effect and are not replaced by the automatic +50 GB boost.&lt;/LI&gt;
&lt;LI&gt;+50 GB add-on explicitly removed: for a mailbox using default plan quotas, Exchange returns to the applicable plan default. A custom value set by an administrator remains custom.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Rollout and license propagation&lt;/H3&gt;
&lt;P&gt;The additional storage is represented through licensing data, so the service plan must be assigned and processed before Exchange can return the higher effective quota. During broad service-plan rollout or backfill operations, users in the same organization may not all reflect the change at the same time. It is possible that some of your users received additional 50 GB mailbox size increase while others did not – you should expect that this gets resolved automatically if users are licensed by one of affected business suite licenses.&lt;/P&gt;
&lt;P&gt;Administrators should &lt;EM&gt;not&lt;/EM&gt; remove and reassign an Exchange license solely to force a quota refresh unless Microsoft Support specifically directs that action. &lt;STRONG&gt;Removing a product license removes access to its services and starts the applicable data-retention lifecycle&lt;/STRONG&gt;. Please keep using your normal license-assignment processes.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-12"&gt;Exchange Online Team&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2026 20:25:03 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/exchange-team-blog/understanding-the-new-100-gb-mailbox-entitlement-for-microsoft/ba-p/4548243</guid>
      <dc:creator>The_Exchange_Team</dc:creator>
      <dc:date>2026-08-19T20:25:03Z</dc:date>
    </item>
    <item>
      <title>Where is Exchange SE CU1 anyway?</title>
      <link>https://techcommunity.microsoft.com/t5/exchange-team-blog/where-is-exchange-se-cu1-anyway/ba-p/4546837</link>
      <description>&lt;P&gt;We are getting questions from our customers on when they can expect us to release Exchange SE Cumulative Update 1 (CU1). After all, in the past we mentioned that it would be released by the end of the first half of calendar year 2026, later &lt;A href="https://techcommunity.microsoft.com/blog/exchange/upgrading-your-organization-from-current-versions-to-exchange-server-se/4241305" target="_blank"&gt;updated&lt;/A&gt; to “second half of 2026”. What is the deal? &lt;STRONG&gt;Where is CU1?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Over the last few months, various Microsoft execs made statements explaining how Microsoft is leveraging a variety of AI tools to help find vulnerabilities in our products (examples of such announcements can be found &lt;A href="https://blogs.windows.com/windowsexperience/2026/07/09/evolving-windows-vulnerability-management-to-meet-the-speed-of-ai-powered-discovery/" target="_blank"&gt;here&lt;/A&gt;, &lt;A href="https://www.microsoft.com/en-us/security/blog/2026/04/22/ai-powered-defense-for-an-ai-accelerated-threat-landscape/" target="_blank"&gt;here&lt;/A&gt; and &lt;A href="https://www.microsoft.com/en-us/msrc/blog/2026/04/strengthening-secure-software-global-scale-how-msrc-is-evolving-with-ai" target="_blank"&gt;here&lt;/A&gt;).&lt;/P&gt;
&lt;P&gt;It should come as no surprise that this is a Microsoft-wide initiative. Many teams, Exchange Server included, are working through reported issues – which includes validation that they are real security issues, reproducing, fixing, testing for regressions / issues after fixes are deployed and releasing updates monthly.&lt;/P&gt;
&lt;P&gt;We have been releasing security updates for Exchange Server regularly: &lt;A href="https://learn.microsoft.com/en-us/exchange/new-features/build-numbers-and-release-dates" target="_blank"&gt;May, June, July, August&lt;/A&gt;. You can expect this increased pace of security releases to continue. We are &lt;A href="https://blogs.microsoft.com/blog/2024/05/03/prioritizing-security-above-all-else/" target="_blank"&gt;prioritizing security above all else&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;While all of that is happening, we are also working on CU1; we are regularly rolling our monthly security payload into our internal CU1 build and plan to release Exchange SE CU1 as soon as we get a reasonable stable point and have a month without pressing security payload. We really do not want to try to release a new CU1 and then immediately supersede the new CU with security updates as that would create double the update work for many organization administrators. Even internally, trying to ensure that two major releases (Security Update and a CU) get appropriately tested so we can ensure high quality and nothing falls through the cracks would be very challenging as CU1 must be all inclusive of everything that we released since the RTM.&lt;/P&gt;
&lt;P&gt;In short: Exchange SE CU1 is coming; we do not have a date to give you. &lt;EM&gt;But we did not forget about it.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Until then, please keep &lt;A href="https://techcommunity.microsoft.com/blog/exchange/upgrading-your-organization-from-current-versions-to-exchange-server-se/4241305" target="_blank"&gt;Upgrading your organization to Exchange Server SE | Microsoft Community Hub&lt;/A&gt; and if you are already on Exchange Server SE, &lt;A href="https://learn.microsoft.com/en-us/exchange/new-features/build-numbers-and-release-dates" target="_blank"&gt;stay up to date&lt;/A&gt;!&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-12"&gt;The Exchange Server Team&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2026 21:05:31 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/exchange-team-blog/where-is-exchange-se-cu1-anyway/ba-p/4546837</guid>
      <dc:creator>The_Exchange_Team</dc:creator>
      <dc:date>2026-08-13T21:05:31Z</dc:date>
    </item>
    <item>
      <title>Released: August 2026 Exchange Server Security Updates</title>
      <link>https://techcommunity.microsoft.com/t5/exchange-team-blog/released-august-2026-exchange-server-security-updates/ba-p/4543951</link>
      <description>&lt;P&gt;Microsoft has released Security Updates (SUs) for vulnerabilities found in:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Exchange Server Subscription Edition (SE)&lt;/LI&gt;
&lt;LI&gt;Exchange Server 2019&lt;/LI&gt;
&lt;LI&gt;Exchange Server 2016&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;SUs are available for the following specific versions of Exchange Server:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://www.microsoft.com/en-us/download/details.aspx?id=108785" target="_blank" rel="noopener"&gt;Exchange SE RTM&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Exchange Server 2019&amp;nbsp;CU14&amp;nbsp;and&amp;nbsp;CU15 (to access, organization must be enrolled into the &lt;A href="https://techcommunity.microsoft.com/blog/exchange/announcing-period-2-exchange-20162019-extended-security-update-esu-program/4511603" target="_blank" rel="noopener"&gt;Period 2 ESU program&lt;/A&gt;)&lt;/LI&gt;
&lt;LI&gt;Exchange Server 2016&amp;nbsp;CU23 (to access, organization must be enrolled into the &lt;A href="https://techcommunity.microsoft.com/blog/exchange/announcing-period-2-exchange-20162019-extended-security-update-esu-program/4511603" target="_blank" rel="noopener"&gt;Period 2 ESU program&lt;/A&gt;)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The August 2026 SUs address vulnerabilities responsibly reported to Microsoft by security partners and found through Microsoft’s internal processes.&lt;/P&gt;
&lt;P&gt;These vulnerabilities affect Exchange Server. Exchange Online customers are already protected from the vulnerabilities addressed by these SUs and do not need to take any action other than updating any Exchange servers or Exchange Management tools workstations in their environment.&lt;/P&gt;
&lt;P&gt;More details about specific CVEs can be found in the&amp;nbsp;&lt;A href="https://msrc.microsoft.com/update-guide/" target="_blank" rel="noopener"&gt;Security Update Guide&lt;/A&gt;&amp;nbsp;(filter on ‘Server Software’ under Product Family for Exchange SE and ‘ESU’ under Product Family for Exchange 2016 and 2019).&lt;/P&gt;
&lt;H3&gt;OWA Light is disabled starting with this update&lt;/H3&gt;
&lt;P&gt;As we announced several weeks ago, this update (and any subsequent updates) permanently disables the OWA Light client when update is installed on an Exchange server. See related &lt;A href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62914" target="_blank" rel="noopener"&gt;CVE-2026-62914&lt;/A&gt; for more information.&lt;/P&gt;
&lt;P&gt;Customers who are not able to install August 2026 (or later) update should &lt;A href="https://techcommunity.microsoft.com/blog/exchange/upcoming-retirement-of-owa-light-in-exchange-server/4534943" target="_blank" rel="noopener"&gt;disable OWA Light on their servers&lt;/A&gt; to address this particular CVE.&lt;/P&gt;
&lt;H3&gt;Exchange 2016 and 2019 updates are available &lt;EM&gt;only&lt;/EM&gt; under the Period 2 ESU program&lt;/H3&gt;
&lt;P&gt;Exchange Server 2016 and 2019 are &lt;A href="https://techcommunity.microsoft.com/blog/exchange/support-for-exchange-server-2016-and-exchange-server-2019-ends-today/4461192" target="_blank" rel="noopener"&gt;out of support&lt;/A&gt;. Only customers who enrolled in the &lt;A href="https://techcommunity.microsoft.com/blog/exchange/announcing-period-2-exchange-20162019-extended-security-update-esu-program/4511603" target="_blank" rel="noopener"&gt;Period 2 Extended Security Update (ESU) program&lt;/A&gt; are eligible to receive Exchange Server 2016 and 2019 security updates released between May and October 2026.&lt;/P&gt;
&lt;P&gt;If you are not part of the Period 2 ESU program, &lt;A href="https://techcommunity.microsoft.com/blog/exchange/upgrading-your-organization-from-current-versions-to-exchange-server-se/4241305" target="_blank" rel="noopener"&gt;migrate to Exchange Server Subscription Edition (SE)&lt;/A&gt; to keep receiving the latest security updates.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;If you have already purchased the Period 2 ESU&lt;/EM&gt; and need information on accessing the latest Security Updates, please contact us by sending an email to &lt;A href="mailto:ExchangeandSfBServerESUInquiry@service.microsoft.com?subject=We%20purchased%20Exchange%20ESU%20need%20access" target="_blank" rel="noopener"&gt;ExchangeandSfBServerESUInquiry@service.microsoft.com&lt;/A&gt;.&lt;/P&gt;
&lt;H3&gt;Known issues with this release&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://support.microsoft.com/en-us/servicing/exchange/server/hotfix/2026/5105719" target="_blank" rel="noopener"&gt;Wrapper messages appear in shared mailbox inbox in hybrid environments | Microsoft Support&lt;/A&gt; – to be addressed in an upcoming update.&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;If a backend mailbox server is updated to August 2026 SU, but the frontend server proxying the inbound MRS connection is on an older version, MRS migration might fail with &lt;EM&gt;TooManyTransientFailureRetriesPermanentException&lt;/EM&gt; error. This can manifest on any MRS request, including Test-MigrationServerAvailability. Updating the front end server to the August 2026 SU should resolve this problem.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://support.microsoft.com/en-us/servicing/exchange/server/update/2026/5126672" target="_blank" rel="noopener"&gt;Published calendar (.ics) returns HTTP 500 for calendar applications | Microsoft Support&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://support.microsoft.com/en-us/servicing/exchange/server/update/2026/5125804" target="_blank"&gt;Hybrid Free/Busy over MS Graph drops the requester timezone | Microsoft Support&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Update installation&lt;/H3&gt;
&lt;P&gt;The following update paths are available:&lt;/P&gt;
&lt;img /&gt;
&lt;UL&gt;
&lt;LI&gt;Inventory your Exchange Servers to determine which updates are needed using the &lt;A href="https://aka.ms/ExchangeHealthChecker" target="_blank" rel="noopener"&gt;Exchange Server Health Checker script&lt;/A&gt;. Running this script will tell you if any of your Exchange Servers are behind on updates (CUs, SUs, or manual actions).&lt;/LI&gt;
&lt;LI&gt;Install the latest CU. Use the &lt;A href="https://aka.ms/ExchangeUpdateWizard" target="_blank" rel="noopener"&gt;Exchange Update Wizard&lt;/A&gt; to choose your current CU and your target CU to get directions.&lt;/LI&gt;
&lt;LI&gt;Re-run the Health Checker after you install an update to see if any further actions are needed.&lt;/LI&gt;
&lt;LI&gt;After setup is completed, please reboot the server and check that all Exchange services have started properly. If some services are in a disabled state, that indicates that something interrupted installation of the update. Please see the Workaround 1 in &lt;A href="https://support.microsoft.com/en-us/topic/file-version-error-when-you-try-to-install-exchange-server-november-2024-su-a650da30-f8fb-469d-a449-47396cab0a15" target="_blank" rel="noopener"&gt;this article&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;If you encounter errors during or after installation of Exchange Server, run the &lt;A href="https://aka.ms/ExSetupAssist" target="_blank" rel="noopener"&gt;SetupAssist script&lt;/A&gt;. If something does not work properly after updates, see &lt;A href="https://aka.ms/ExchangeFAQ" target="_blank" rel="noopener"&gt;Repair failed installations of Exchange Cumulative and Security updates&lt;/A&gt;. Also please see &lt;A href="https://support.microsoft.com/topic/file-version-error-when-you-try-to-install-exchange-server-november-2024-su-a650da30-f8fb-469d-a449-47396cab0a15" target="_blank" rel="noopener"&gt;File version error when you try to install Exchange Server updates&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H1&gt;FAQs&lt;/H1&gt;
&lt;P&gt;&lt;STRONG&gt;Our organization is in Hybrid mode with Exchange Online. Do we need to do anything?&lt;/STRONG&gt;&lt;BR /&gt;Exchange Online is already protected, but this SU needs to be installed on your Exchange servers, even if they are used only for management purposes. If you change the auth certificate after installing an SU, you should re-run the Hybrid Configuration Wizard.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;The last SU/HU we installed is a few months old. Do we need to install all SUs in order to install the latest one?&lt;/STRONG&gt;&lt;BR /&gt;SUs are cumulative. If you are running a CU supported by the SU, you do not need to install all SUs or HUs in sequential order; simply install the latest SU. Please see&amp;nbsp;&lt;A href="https://techcommunity.microsoft.com/t5/exchange-team-blog/why-exchange-server-updates-matter/ba-p/2280770" target="_blank" rel="noopener"&gt;this blog post&lt;/A&gt;&amp;nbsp;for more information.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Do we need to install SUs on all Exchange Servers within our organization? What about ‘Management Tools only’&amp;nbsp;machines?&lt;/STRONG&gt;&lt;BR /&gt;Our recommendation is to install SUs on&amp;nbsp;&lt;U&gt;all&lt;/U&gt;&amp;nbsp;Exchange Servers and all servers and workstations running the Exchange Management Tools to ensure compatibility between management tools clients and servers. If you are trying to update the Exchange Management Tools in the environment with no running Exchange servers, please see&amp;nbsp;&lt;A href="https://learn.microsoft.com/exchange/manage-hybrid-exchange-recipients-with-management-tools#update-the-exchange-server-management-tools-only-role-with-no-running-exchange-server-to-a-newer-cumulative-or-security-update" target="_blank" rel="noopener"&gt;this&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Our organization does not have the Exchange 2016 and 2019 Period 2 ESU. How can we get current Exchange 2016 or 2019 updates?&lt;/STRONG&gt;&lt;BR /&gt;Since Exchange 2016 and 2019 are now &lt;A href="https://techcommunity.microsoft.com/blog/exchange/support-for-exchange-server-2016-and-exchange-server-2019-ends-today/4461192" target="_blank" rel="noopener"&gt;out of support&lt;/A&gt;, only customers who have enrolled into the &lt;A href="https://techcommunity.microsoft.com/blog/exchange/announcing-period-2-exchange-20162019-extended-security-update-esu-program/4511603" target="_blank" rel="noopener"&gt;Period 2 ESU program&lt;/A&gt; (which is valid between May and October 2026) can obtain Exchange 2016 or 2019 updates released after May 2026. For all other customers still running Exchange 2016 or 2019, we recommend that you &lt;A href="https://techcommunity.microsoft.com/blog/exchange/upgrading-your-organization-from-current-versions-to-exchange-server-se/4241305" target="_blank" rel="noopener"&gt;upgrade your organization to Exchange SE&lt;/A&gt; as soon as possible.&lt;/P&gt;
&lt;P style="background: #F0F0F0; padding: .5em; margin: 1em 0 1em 0;"&gt;Documentation may not be fully available at the time this post is published.&lt;/P&gt;
&lt;P&gt;Major updates to this post:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Sep 8, 2026: &lt;/STRONG&gt;mentioned the correct known issue for August (Graph time zone issue)&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Aug 28, 2026:&amp;nbsp;&lt;/STRONG&gt;Linked to the KB article talking about the anonymous calendar publishing known issue.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Aug 25, 2026:&amp;nbsp;&lt;/STRONG&gt;Added a known issue with anonymous calendar publishing failing to update after SU is installed, with a workaround.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Aug 24, 2026:&lt;/STRONG&gt; Added a known issue that can happen with MRS migrations if not all servers are updated to August 2026 updat yet.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-12"&gt;The Exchange Server Team&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2026 20:41:07 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/exchange-team-blog/released-august-2026-exchange-server-security-updates/ba-p/4543951</guid>
      <dc:creator>The_Exchange_Team</dc:creator>
      <dc:date>2026-09-08T20:41:07Z</dc:date>
    </item>
    <item>
      <title>Cross-tenant Free/Busy, MailTips, and Calendar Sharing are moving to Cross-Tenant Access Policy</title>
      <link>https://techcommunity.microsoft.com/t5/exchange-team-blog/cross-tenant-free-busy-mailtips-and-calendar-sharing-are-moving/ba-p/4545169</link>
      <description>&lt;P&gt;If your organization shares Free/Busy, MailTips, or calendars with other Microsoft 365 organizations, there's a change coming that you'll want to understand and plan for. If it doesn't, you can stop reading in about two paragraphs. This post covers what's changing as &lt;A href="https://techcommunity.microsoft.com/blog/exchange/exchange-online-ews-your-time-is-almost-up/4492361" target="_blank" rel="noopener"&gt;Exchange Web Services (EWS) is deprecated&lt;/A&gt;, how the new Microsoft 365 Cross-Tenant Access Policy model replaces the old plumbing, how to tell whether your tenant is affected, and what to do about it. The official announcement is Message Center post &lt;A class="lia-external-url" href="https://admin.cloud.microsoft/?ref=MessageCenter/:/messages/MC1446796" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;MC1446796&lt;/STRONG&gt;&lt;/A&gt;; consider this the friendlier, more complete version with the context we wish the MC post had room for.&lt;/P&gt;
&lt;H3&gt;Is your organization impacted by this change?&lt;/H3&gt;
&lt;P&gt;&lt;STRONG&gt;Only if your organization shares Free/Busy, Calendars, or MailTips information with other Microsoft 365 organizations.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;This change affects cross-tenant / cross-organization collaboration - the ability for people in your organization (Organization A) and people in a partner's Microsoft 365 tenant (Organization B) to see each other's Free/Busy availability, shared calendars, and MailTips (such as out-of-office notices). If you've set up these relationships with subsidiaries, partners, vendors, or recently acquired companies, you need to understand this and take action before the deadline, or those experiences will break.&lt;/P&gt;
&lt;P&gt;Organization sharing is not set up by default – tenant admins must have set it up by themselves.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Not impacted scenarios:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Sharing Free/Busy availability, calendars, or MailTips within your organization.&lt;/LI&gt;
&lt;LI&gt;Sharing Free/Busy availability, calendars, or MailTips between your on-premises and online users in an Exchange Hybrid Deployment. You should work on your Dedicated Hybrid App as per our &lt;A href="https://techcommunity.microsoft.com/blog/exchange/update-your-exchange-se-hybrid-on-premises-rich-coexistence-to-graph/4517520" target="_blank" rel="noopener"&gt;previous announcements&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;Sharing Free/Busy availability, calendars, or MailTips with another organization running on-premises Exchange. Watch for future Message Center posts covering this scenario (no immediate impact but changes are coming). If you are sharing with a partner organization running both Exchange Online and on-premises, the sharing with Exchange Online is impacted.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The “How to check your sharing configurations?” section below has more information on how to verify.&lt;/P&gt;
&lt;H3&gt;What's changing, and why&lt;/H3&gt;
&lt;P&gt;Deprecation of Exchange Web Services (EWS) begins on October 1, 2026. Several cross-tenant collaboration features - Free/Busy, MailTips, and Calendar Sharing – currently use &amp;nbsp;Exchange Web Services under the hood. As EWS is retired in Exchange Online, the mechanism that carries those cross-tenant requests has to move somewhere else.&lt;/P&gt;
&lt;P&gt;That “somewhere else” is Microsoft 365 Cross-Tenant Access Policy. It replaces the EWS-based approach, and it becomes available starting September 2026. The end state is the same experience your users have today - someone sees a colleague's calendar availability across a tenant boundary - but it travels over a modern, Entra-governed path instead of legacy EWS. It's part of the broader push to retire legacy protocols and eliminate high-privilege access.&lt;/P&gt;
&lt;H3&gt;How the new model works&lt;/H3&gt;
&lt;P&gt;Today, three Exchange Online configurations drive cross-tenant sharing:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Organization Relationships - used to share Free/Busy and MailTips with other Microsoft 365 tenants.&lt;/LI&gt;
&lt;LI&gt;Availability Address Spaces - used to share Free/Busy with other Microsoft 365 tenants (specifically those set with AccessMethod: OrgWideFBToken).&lt;/LI&gt;
&lt;LI&gt;Sharing Policies - used to share calendars externally, either through invitations sent to recipients in other Microsoft 365 organizations, or calendars published for anonymous access via an internet URL.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Historically, each of these has used EWS to fetch availability and MailTips from the partner tenant. Going forward, that trust and data exchange is expressed through Microsoft 365 Cross-Tenant Access Policy instead. You still decide which partner organizations you collaborate with and what you share; only the mechanism carrying it changes. Migrating means understanding your current configuration, standing up the equivalent Cross-Tenant Access Policy, validating that sharing still works, and then removing the old configurations you no longer need.&lt;/P&gt;
&lt;H3&gt;How to check your sharing configurations?&lt;/H3&gt;
&lt;P&gt;MC1446796 was sent to every tenant but most admins who received it won't actually need to do anything. So before you plan a migration, confirm you're in scope. Run these three commands in Exchange Online PowerShell:&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;Get-OrganizationRelationship | Format-List Name, DomainNames, Enabled, FreeBusyAccessEnabled, FreeBusyAccessLevel, FreeBusyAccessScope, MailTipsAccessEnabled, MailTipsAccessLevel, MailTipsAccessScope&lt;/LI-CODE&gt;
&lt;P&gt;You're affected if the results show Enabled: True, and either FreeBusyAccessEnabled: True or MailTipsAccessEnabled: True, and the external organization is hosted in Microsoft 365. Otherwise, no action is needed.&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;Get-SharingPolicy | Format-List Name, Domains, Enabled, Default&lt;/LI-CODE&gt;
&lt;P&gt;You're affected if the results show Enabled: True, the Domains property contains at least one rule with a CalendarSharingFreeBusy access level (Simple, Detail, or Reviewer), the targeted external organization is hosted in Microsoft 365, and the policy is assigned to one or more mailboxes. Otherwise, no action is needed.&lt;/P&gt;
&lt;P&gt;One note on that last check: rules that begin with Anonymous: represent calendar publishing to anonymous internet recipients through a published URL, and they show up in the same output. If you have an Anonymous: rules with a CalendarSharingFreeBusy access level (Simple, Detail, or Reviewer) then you are affected.&lt;/P&gt;
&lt;P&gt;Sharing Free/Busy with another organization hosted in Microsoft 365 via Availability Address Space (with AccessMethod OrgWideFBToken) does not depend on Exchange Web Services and is not impacted by EWS deprecation. However, you may still wish to migrate these configurations to Microsoft 365 Cross-Tenant Access Policy, which supports additional security features and more granular configuration options. Run this command to check your Availability Address Space configurations:&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;Get-AvailabilityAddressSpace | Format-List ForestName, AccessMethod&lt;/LI-CODE&gt;
&lt;H3&gt;The rollout schedule for Cross-Tenant Access Policy&lt;/H3&gt;
&lt;P&gt;This feature becomes available starting September 2026, so your migration window opens as the rollout reaches your environment. Here's the schedule:&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; border-width: 1px;"&gt;&lt;thead&gt;&lt;tr&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;&lt;STRONG&gt;Environment&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;&lt;STRONG&gt;Rollout begins&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;&lt;STRONG&gt;Expected completion&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;&lt;STRONG&gt;Worldwide&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;August 2026&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;September 15, 2026&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;&lt;STRONG&gt;GCC&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;Early September 2026&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;September 30, 2026&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;&lt;STRONG&gt;GCC High&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;Early September 2026&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;September 30, 2026&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;&lt;STRONG&gt;DoD&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;Early September 2026&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;October 30, 2026&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;H3&gt;What happens if you do nothing?&lt;/H3&gt;
&lt;P&gt;Starting October 1, 2026, EWS will be gradually disabled in Exchange Online, in line with the deprecation communications we've been sending for a while now. As that rollout reaches your tenant, any cross-tenant Free/Busy, MailTips, and Calendar Sharing that still depends on EWS will stop working - people in your partner organizations may no longer see Free/Busy, MailTips, or shared calendars coming from your tenant. You may no longer be able to see Free/Busy, MailTips, or shared calendars from the partner organization. If you're in scope and take no action, that's the outcome.&lt;/P&gt;
&lt;H3&gt;Not ready by October? You have a runway&lt;/H3&gt;
&lt;P&gt;We realize that the window between this announcement and the start of the rollout is short. For organizations with many partner tenants and a tangled web of organization relationships, analyzing, testing, and executing a migration in a few weeks is a tall order, and we know it.&lt;/P&gt;
&lt;P&gt;There is a safety valve. You can keep the existing cross-tenant sharing working by setting &lt;STRONG&gt;EWSEnabled&lt;/STRONG&gt; to &lt;STRONG&gt;True&lt;/STRONG&gt;, following the guidance in our earlier post, &lt;A href="https://techcommunity.microsoft.com/blog/exchange/exchange-online-ews-your-time-is-almost-up/4492361" target="_blank" rel="noopener"&gt;Exchange Online EWS, Your Time Is Almost Up&lt;/A&gt;. That keeps the old path alive while you prepare and execute the migration. This extension remains available until the final EWS shutdown on April 1, 2027 - which is the hard deadline for completing the move.&lt;/P&gt;
&lt;P&gt;You do not need to specify AppIDs in your &lt;A href="https://techcommunity.microsoft.com/blog/exchange/introducing-ewsallowedappids-preparing-for-the-final-phase-of-ews-retirement/4529471" target="_blank" rel="noopener"&gt;tenant Allow List&lt;/A&gt; to keep the old method working, as it doesn’t rely on AppIDs (as it doesn’t use OAuth). &lt;EM&gt;If EWSEnabled is set to True, we’ll allow the cross-tenant flows covered here to continue working until April 2027, no matter the tenant Allow List state.&lt;/EM&gt;&lt;/P&gt;
&lt;H3&gt;What you need to do&lt;/H3&gt;
&lt;OL&gt;
&lt;LI&gt;Confirm scope. Run the checks above. If nothing flags, you're done.&lt;/LI&gt;
&lt;LI&gt;Plan your migration for after the rollout reaches your tenant and before EWS deprecation affects you. Review the migration guide for step-by-step instructions.&lt;/LI&gt;
&lt;LI&gt;Migrate - understand your current configurations, set up the new Microsoft 365 Cross-Tenant Access Policies, validate that sharing works, and remove the configurations you no longer need.&lt;/LI&gt;
&lt;LI&gt;If you can't finish by October 1, set EWSEnabled to True to keep sharing alive until you can migrate, no later than April 1, 2027.&lt;/LI&gt;
&lt;/OL&gt;
&lt;H3&gt;Further reading&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://admin.cloud.microsoft/?ref=MessageCenter/:/messages/MC1446796" target="_blank" rel="noopener"&gt;Message Center post MC1446796 - Migrate Free/Busy, MailTips, and Calendar Sharing before EWS deprecation&lt;/A&gt; (the official announcement in your tenant).&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/exchange/sharing/migrate-to-m365-xtap" target="_blank" rel="noopener"&gt;Migrating to Microsoft 365 Cross-Tenant Access Policy for sharing Free/Busy, Calendars, and MailTips&lt;/A&gt; (the migration guide).&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/exchange/exchange-online-ews-your-time-is-almost-up/4492361" target="_blank" rel="noopener"&gt;Exchange Online EWS, Your Time Is Almost Up&lt;/A&gt; (how to keep EWS running with EWSEnabled while you migrate).&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/exchange/clients-and-mobile-in-exchange-online/deprecation-of-ews-exchange-online" target="_blank" rel="noopener"&gt;Deprecation of EWS in Exchange Online&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Frequently Asked Questions&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;We cannot make the October deadline for this migration. Other than setting EWSEnabled to True for our tenant, do we need to add some AppID to the &lt;A href="https://techcommunity.microsoft.com/blog/exchange/introducing-ewsallowedappids-preparing-for-the-final-phase-of-ews-retirement/4529471" target="_blank" rel="noopener"&gt;tenant EWS Allow List&lt;/A&gt;?&lt;/STRONG&gt;&lt;BR /&gt;Setting EWSEnabled to True is all that you need to do to keep your current configurations for sharing with other organizations working. You do not need to add anything to the EWSAllowedAppIDs tenant value. Please note that both your and your partner Microsoft 365 organization need to set EWSEnabled to True to continue bidirectional information sharing.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What happens if we set up sharing using the new model on my side but the partner organization does not?&lt;/STRONG&gt;&lt;BR /&gt;For bidirectional sharing, both organizations need to configure Microsoft 365 Cross-Tenant Access Policies and disable the old configurations before sharing will work in both directions.&lt;BR /&gt;For one-way sharing, only the resource tenant (the tenant with the mailboxes that contain the Free/Busy, Calendar, or MailTips information) needs to configure a Microsoft 365 Cross-Tenant Access Policy. Once configured, users in the home tenant (the tenant with users trying to access the shared information) will be able to access the information via Cross-Tenant Access Policy. Ensure both organizations disable old configurations for sharing as these will prevent requests from flowing through the new Cross-Tenant Access Policy.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What happens if we extend EWS deprecation in my tenant but the partner organization does not and we do not complete the migration before EWS deprecation starts?&lt;/STRONG&gt;&lt;BR /&gt;After EWS is disabled in the partner organization, users in your organization will no longer be able to access information shared from the partner organization. Users in the partner organization will continue to be able to access information shared from your organization.&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;&lt;STRONG&gt;We have a Sharing Policy with a Wildcard in the domain. Do we need to migrate it?&lt;/STRONG&gt;&lt;BR /&gt;&lt;/SPAN&gt;Yes, as long as the CalendarSharingFreeBusy access level is Simple, Detail, or Reviewer.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Our default Sharing Policy is defined (with a "{*:0}" wildcard domain) but is set to Enabled:False. This is because we want to prevent users from external calendar sharing. Do we need to migrate this policy?&lt;/STRONG&gt;&lt;BR /&gt;No action is needed. No Cross-Tenant Access Policy will have an equivalent effect to default Sharing Policy being disabled.&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;&lt;STRONG&gt;What if we are sharing with multiple domains that are in the same partner Tenant ID?&lt;/STRONG&gt;&lt;BR /&gt;&lt;/SPAN&gt;Create a single Microsoft 365 Cross-Tenant Access Policy to configure sharing with the partner Tenant ID. Any domains associated with the partner Tenant ID will be covered by the policy.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What if we have an Availability Address Space with Google Workspace for Google/Exchange Calendar Interop?&lt;/STRONG&gt;&lt;BR /&gt;You are not affected by this change. Users in Exchange Online can continue to access calendar information of users in Google Workspace via the Availability Address Space configuration. Users in Google Workspace can continue to access calendar information of users in Exchange Online via Microsoft Graph API. Ensure Google Workspace is configured to connect to Exchange Online via Microsoft Graph API and not the legacy EWS connection method. See:&amp;nbsp;&lt;A href="https://knowledge.workspace.google.com/admin/sync/allow-calendar-users-to-see-exchange-availability" target="_blank" rel="noopener"&gt;Allow Google Calendar users to see Exchange availability&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What if we have an Availability Address Space configuration for sharing Free/Busy between commercial cloud (most customers world-wide) and 21Vianet cloud?&lt;BR /&gt;&lt;/STRONG&gt;Availability Address Space (with AccessMethod OrgWideFBToken) does not depend on Exchange Web Services and is not impacted by EWS deprecation. However, you may still wish to migrate these configurations to Microsoft 365 Cross-Tenant Access Policy, which supports additional security features and more granular configuration options.&lt;/P&gt;
&lt;H6&gt;Major updates to this blog post:&lt;/H6&gt;
&lt;UL&gt;
&lt;LI&gt;9/3/2026: Removed a redundant section of the article.&lt;/LI&gt;
&lt;LI&gt;8/28/2026: Various updates to the post; timeline changes, several clarifications made.&lt;/LI&gt;
&lt;LI&gt;8/18/2026: Modified the FAQ related to AAS sharing with the 21Vianet cloud.&lt;/LI&gt;
&lt;LI&gt;8/10/2026: Added a FAQ that clarifies that default sharing policy that is set to be disabled does not need migration.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-12"&gt;The Exchange Online EWS Deprecation Team&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Sep 2026 14:47:12 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/exchange-team-blog/cross-tenant-free-busy-mailtips-and-calendar-sharing-are-moving/ba-p/4545169</guid>
      <dc:creator>The_Exchange_Team</dc:creator>
      <dc:date>2026-09-04T14:47:12Z</dc:date>
    </item>
    <item>
      <title>Writeback for Cloud-Managed Remote Mailboxes: Now Generally Available</title>
      <link>https://techcommunity.microsoft.com/t5/exchange-team-blog/writeback-for-cloud-managed-remote-mailboxes-now-generally/ba-p/4543507</link>
      <description>&lt;P&gt;In May, we announced the &lt;A href="https://techcommunity.microsoft.com/blog/exchange/writeback-for-cloud-managed-remote-mailboxes-now-in-public-preview/4520138" target="_blank"&gt;Public Preview of Writeback for Cloud-Managed Remote Mailboxes&lt;/A&gt;. Since then, many customers have enabled this feature and shared their feedback. Today, we're excited to announce that &lt;STRONG&gt;Writeback for Cloud-Managed Remote Mailboxes is now Generally Available (GA)&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;Writeback is available in WW, GCCH, DoD, and 21Vianet environments and supports up to &lt;STRONG&gt;600,000 cloud-managed mailboxes per tenant&lt;/STRONG&gt;.&lt;/P&gt;
&lt;H3&gt;A quick recap&lt;/H3&gt;
&lt;P&gt;Cloud-Managed Remote Mailboxes allow organizations to transfer the Source of Authority (SOA) for a directory-synchronized mailbox's Exchange attributes to Exchange Online by setting IsExchangeCloudManaged to true.&lt;/P&gt;
&lt;P&gt;The user identity remains synchronized from on-premises Active Directory but Exchange attributes become editable in Exchange Online. Administrators can update these properties through Exchange Online PowerShell, the Exchange admin center, or the Microsoft 365 admin center.&lt;/P&gt;
&lt;P&gt;Writeback extends this capability by synchronizing a critical set of Exchange attribute changes from Exchange Online back to on-premises Active Directory through Microsoft Entra Cloud Sync. This helps organizations whose on-premises line-of-business applications continue to read Exchange attributes from Active Directory.&lt;/P&gt;
&lt;P&gt;If you already use Microsoft Entra Connect Sync, you don't need to uninstall or replace it. Cloud Sync runs alongside Connect Sync:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Connect Sync continues to synchronize your directory identities and attributes as before.&lt;/LI&gt;
&lt;LI&gt;Cloud Sync handles Exchange attribute writeback.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;What's new at GA&lt;/H3&gt;
&lt;H4&gt;Support for up to 600,000 cloud-managed mailboxes&lt;/H4&gt;
&lt;P&gt;During Public Preview, writeback supported tenants with fewer than 200,000 cloud-managed mailboxes. At GA, the supported scale increases to &lt;STRONG&gt;600,000 cloud-managed mailboxes per tenant&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;This expanded scale enables larger organizations to adopt cloud-managed Exchange attributes while keeping the required Exchange attribute values current in on-premises Active Directory.&lt;/P&gt;
&lt;H4&gt;Writeback for the MAIL attribute&lt;/H4&gt;
&lt;P&gt;One of the most requested feature during Public Preview was support for writing the mail attribute back to on-premises Active Directory.&lt;/P&gt;
&lt;P&gt;Based on this feedback, GA adds the mail attribute to the supported writeback set. Changes made to WindowsEmailAddress in Exchange Online can now be written back to the corresponding mail attribute in Active Directory.&lt;/P&gt;
&lt;P&gt;The supported writeback set now includes &lt;STRONG&gt;24 attributes&lt;/STRONG&gt;, including:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;PRE&gt;extensionAttribute1 through extensionAttribute15&lt;/PRE&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;PRE&gt;msExchExtensionCustomAttribute1 through msExchExtensionCustomAttribute5&lt;/PRE&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;PRE&gt;msExchRecipientDisplayType&lt;/PRE&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;PRE&gt;msExchRecipientTypeDetails&lt;/PRE&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;PRE&gt;proxyAddresses&lt;/PRE&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;PRE&gt;mail&lt;/PRE&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;For the complete attribute list, see &lt;A class="lia-external-url" href="https://learn.microsoft.com/exchange/hybrid-deployment/enable-exchange-attributes-cloud-management#identity-exchange-attributes-and-writeback" target="_blank"&gt;Identity, Exchange Attributes and Writeback&lt;/A&gt;.&lt;/P&gt;
&lt;H3&gt;Existing Public Preview configurations require one update&lt;/H3&gt;
&lt;P&gt;Exchange attribute writeback configurations created on or after August 3, 2026 will have mail writeback enabled by default. No additional action is required for newly created configurations.&lt;/P&gt;
&lt;P&gt;Configurations created before August 3, 2026 aren't updated automatically to writeback mail attribute. If you enabled writeback during Public Preview:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Open your Exchange Online attribute writeback configuration in the Microsoft Entra admin center.&lt;/LI&gt;
&lt;LI&gt;Select &lt;STRONG&gt;Attribute mapping&lt;/STRONG&gt; and then &lt;STRONG&gt;Restore default mappings&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;After the synchronization job restarts, mail writeback will be enabled.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Detailed guidance is available in the&amp;nbsp;&lt;A class="lia-external-url" href="https://learn.microsoft.com/exchange/hybrid-deployment/enable-exchange-attributes-cloud-management#frequently-asked-questions" target="_blank"&gt;Frequently Asked Questions&lt;/A&gt; section of the documentation.&lt;/P&gt;
&lt;H3&gt;Important reminder about tenant-wide SOA&lt;/H3&gt;
&lt;P&gt;Tenant-wide Exchange attribute SOA is intended for organizations that have completed mailbox migration to Exchange Online and no longer create Exchange mailboxes, mail-enabled users, or remote mailboxes on-premises.&lt;/P&gt;
&lt;P&gt;Don't enable tenant-wide SOA while on-premises mailbox migration or recipient creation is still ongoing. Doing so can cause a newly synchronized Exchange recipient to appear in Microsoft Entra ID as an identity-only user without the MailUser required in Exchange Online. This blocks mailbox onboarding and migration.&lt;/P&gt;
&lt;P&gt;Review the prerequisites and guidance in &lt;A class="lia-external-url" href="https://learn.microsoft.com/exchange/hybrid-deployment/enable-exchange-attributes-cloud-management" target="_blank"&gt;Cloud-based management of Exchange attributes for Remote Mailboxes in hybrid environments&lt;/A&gt; before enabling tenant-wide SOA.&lt;/P&gt;
&lt;H3&gt;A path towards removing the last Exchange Server&lt;/H3&gt;
&lt;P&gt;Cloud-managed Exchange attributes and writeback help organizations continue using Active Directory for identity while removing their dependency on an on-premises Exchange Server for recipient management.&lt;/P&gt;
&lt;P&gt;When you're ready to remove the server, follow &lt;A href="https://learn.microsoft.com/exchange/hybrid-deployment/decommission-last-exchange-server" target="_blank"&gt;Decommission the last Exchange Server after transferring SOA to cloud&lt;/A&gt;. The guide covers prerequisites, hybrid cleanup, Exchange Server uninstall, and post-uninstall cleanup in Exchange Online.&lt;/P&gt;
&lt;P&gt;Exchange-attribute SOA applies to user objects with Exchange Online mailboxes. Organizations that want to manage mail-enabled groups or mail contacts from the cloud should use Group SOA or Contact SOA transfer.&lt;/P&gt;
&lt;H3&gt;Get started&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;Review &lt;A class="lia-external-url" href="https://learn.microsoft.com/exchange/hybrid-deployment/enable-exchange-attributes-cloud-management" target="_blank"&gt;Cloud-based management of Exchange attributes for Remote Mailboxes in hybrid environments&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;Follow &lt;A class="lia-external-url" href="https://learn.microsoft.com/exchange/hybrid-deployment/enable-exchange-attributes-cloud-management#how-to-enable-exchange-attribute-writeback" target="_blank"&gt;How to enable Exchange attribute writeback&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;Review the &lt;A class="lia-external-url" href="https://learn.microsoft.com/exchange/hybrid-deployment/enable-exchange-attributes-cloud-management#identity-exchange-attributes-and-writeback" target="_blank"&gt;complete writeback attribute list&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;Read the &lt;A class="lia-external-url" href="https://learn.microsoft.com/exchange/hybrid-deployment/decommission-last-exchange-server" target="_blank"&gt;last Exchange Server decommissioning guide&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Thank you to everyone who participated in the Public Preview and shared feedback. Your input led to us adding mail attribute writeback for GA.&lt;/P&gt;
&lt;P&gt;We look forward to hearing about your experience with the GA release.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-12"&gt;Exchange Online Management&lt;/SPAN&gt; and &lt;SPAN class="lia-text-color-12"&gt;Exchange Hybrid &lt;SPAN class="lia-text-color-21"&gt;teams&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2026 12:58:46 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/exchange-team-blog/writeback-for-cloud-managed-remote-mailboxes-now-generally/ba-p/4543507</guid>
      <dc:creator>The_Exchange_Team</dc:creator>
      <dc:date>2026-08-03T12:58:46Z</dc:date>
    </item>
    <item>
      <title>Reminder: Exchange 2016 and 2019 ESU Program Ends in October 2026</title>
      <link>https://techcommunity.microsoft.com/t5/exchange-team-blog/reminder-exchange-2016-and-2019-esu-program-ends-in-october-2026/ba-p/4539033</link>
      <description>&lt;P&gt;Over the last several weeks we have received several questions about possible extension of the Exchange Server 2016/2019 ESU program past October 2026. After all, in our &lt;A href="https://techcommunity.microsoft.com/blog/exchange/announcing-exchange-2016--2019-extended-security-update-program/4433495" target="_blank" rel="noopener"&gt;original Exchange 2016/2019 ESU announcement&lt;/A&gt; we said that there would be no extensions, but then we ended up creating a &lt;A href="https://techcommunity.microsoft.com/blog/exchange/announcing-period-2-exchange-20162019-extended-security-update-esu-program/4511603" target="_blank" rel="noopener"&gt;Period 2 Exchange ESU program&lt;/A&gt; that is scheduled to end with October 2026. We are just about at the mid-point of Period 2 Exchange ESU now.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;There will be no further extension of Exchange 2016/2019 ESU program timeline. &lt;/STRONG&gt;Once October 2026 ends, there will be no further updates for Exchange 2016/2019, even if you currently have a Period 2 ESU.&lt;/P&gt;
&lt;P&gt;If your organization still uses Exchange 2016 or 2019 in production:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;See &lt;A href="https://techcommunity.microsoft.com/blog/exchange/upgrading-your-organization-from-current-versions-to-exchange-server-se/4241305" target="_blank" rel="noopener"&gt;Upgrading your organization from current versions to Exchange Server SE | Microsoft Community Hub&lt;/A&gt; – which lays out the path for how to migrate to Exchange SE if you plan to keep Exchange on-premises.&lt;/LI&gt;
&lt;LI&gt;&lt;A style="font-style: normal; font-weight: 400; background-color: rgb(255, 255, 255);" href="https://techcommunity.microsoft.com/blog/exchange/why-%E2%80%9Cin-place-upgrade%E2%80%9D-from-exchange-2019-to-exchange-se-is-low-risk/4410173" target="_blank" rel="noopener"&gt;Why “in-place upgrade” from Exchange 2019 to Exchange SE is low risk | Microsoft Community Hub&lt;/A&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt; – which explains why in-place upgrade from Exchange 2019 CU14/CU15 to Exchange SE RTM is not a significant technological change and is low risk.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Please review &lt;A href="https://www.microsoft.com/en-us/microsoft-365/exchange/microsoft-exchange-licensing-faq-email-for-business" target="_blank" rel="noopener"&gt;Microsoft Exchange Online and Exchange Server Licensing FAQs&lt;/A&gt; especially "What is Exchange Server Subscription Edition (SE) and how is it licensed?” section. Exchange 2019 and Exchange SE licensing requirements are the same.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-12"&gt;The Exchange Server Team&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Aug 2026 18:21:08 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/exchange-team-blog/reminder-exchange-2016-and-2019-esu-program-ends-in-october-2026/ba-p/4539033</guid>
      <dc:creator>The_Exchange_Team</dc:creator>
      <dc:date>2026-08-14T18:21:08Z</dc:date>
    </item>
    <item>
      <title>Released: July 2026 Exchange Server Security Updates</title>
      <link>https://techcommunity.microsoft.com/t5/exchange-team-blog/released-july-2026-exchange-server-security-updates/ba-p/4534146</link>
      <description>&lt;P&gt;Microsoft has released Security Updates (SUs) for vulnerabilities found in:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Exchange Server Subscription Edition (SE)&lt;/LI&gt;
&lt;LI&gt;Exchange Server 2019&lt;/LI&gt;
&lt;LI&gt;Exchange Server 2016&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;SUs are available for the following specific versions of Exchange Server:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://www.microsoft.com/en-us/download/details.aspx?id=108746" target="_blank" rel="noopener"&gt;Exchange SE RTM&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Exchange Server 2019&amp;nbsp;CU14&amp;nbsp;and&amp;nbsp;CU15 (to access, organization must be enrolled into the &lt;A href="https://techcommunity.microsoft.com/blog/exchange/announcing-period-2-exchange-20162019-extended-security-update-esu-program/4511603" target="_blank" rel="noopener"&gt;Period 2 ESU program&lt;/A&gt;)&lt;/LI&gt;
&lt;LI&gt;Exchange Server 2016&amp;nbsp;CU23 (to access, organization must be enrolled into the &lt;A href="https://techcommunity.microsoft.com/blog/exchange/announcing-period-2-exchange-20162019-extended-security-update-esu-program/4511603" target="_blank" rel="noopener"&gt;Period 2 ESU program&lt;/A&gt;)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The July 2026 SUs address vulnerabilities responsibly reported to Microsoft by security partners and found through Microsoft’s internal processes.&lt;/P&gt;
&lt;P&gt;These vulnerabilities affect Exchange Server. Exchange Online customers are already protected from the vulnerabilities addressed by these SUs and do not need to take any action other than updating any Exchange servers or Exchange Management tools workstations in their environment.&lt;/P&gt;
&lt;P&gt;More details about specific CVEs can be found in the&amp;nbsp;&lt;A href="https://msrc.microsoft.com/update-guide/" target="_blank" rel="noopener"&gt;Security Update Guide&lt;/A&gt;&amp;nbsp;(filter on ‘Server Software’ under Product Family for Exchange SE and ‘ESU’ under Product Family for Exchange 2016 and 2019).&lt;/P&gt;
&lt;H3&gt;Check for presence of legacy Exchange security groups&lt;/H3&gt;
&lt;P&gt;While not directly related to our July 2026 SU release, we wanted to call out that &lt;A href="https://aka.ms/ExchangeHealthChecker" target="_blank" rel="noopener"&gt;Exchange Health Checker script&lt;/A&gt; will now also check for the presence of very old, deprecated Exchange Server security groups, namely &lt;STRONG&gt;Exchange Domain Servers&lt;/STRONG&gt; and &lt;STRONG&gt;Exchange Enterprise Servers&lt;/STRONG&gt;. Those groups have been deprecated since Exchange 2007, should not be in use, and should be deleted as they might provide more permissions than modern Exchange security groups. Please see related documentation &lt;A href="https://learn.microsoft.com/en-us/previous-versions/office/exchange-server-2010/gg576862(v=exchg.141)" target="_blank" rel="noopener"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Customers who have removed last on-premises Exchange Server from their organizations should also check for the presence of those groups and delete them to help prevent their possible abuse. Note that if you no longer have any Exchange servers on premises, you might want to perform a more comprehensive Active Directory cleanup as per &lt;A href="https://learn.microsoft.com/en-us/exchange/manage-hybrid-exchange-recipients-with-management-tools#active-directory-clean-up" target="_blank" rel="noopener"&gt;this article&lt;/A&gt;.&lt;/P&gt;
&lt;H3&gt;Remove CVE-2026-42897 mitigations after installation&lt;/H3&gt;
&lt;P&gt;Installing the July 2026 update &lt;EM&gt;does not&lt;/EM&gt; automatically remove already applied CVE-2026-42897 mitigations. Therefore, once you install July SU, you should:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;If mitigation was applied using Exchange Emergency Mitigation (EM) Service:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/Exchange/plan-and-deploy/post-installation-tasks/security-best-practices/exchange-emergency-mitigation-service#rollback-procedures-for-released-mitigations" target="_blank" rel="noopener"&gt;Remove the mitigation M2.1.0 IIS rules&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;If mitigation was applied using the downloadable EOMT script &lt;/STRONG&gt;&lt;A href="https://aka.ms/UnifiedEOMT" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;https://aka.ms/UnifiedEOMT&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;: &lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://microsoft.github.io/CSS-Exchange/Security/EOMT/#roll-back-a-mitigation" target="_blank" rel="noopener"&gt;Roll back the mitigation&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Exchange 2016 and 2019 updates are available &lt;EM&gt;only&lt;/EM&gt; under the Period 2 ESU program&lt;/H3&gt;
&lt;P&gt;Exchange Server 2016 and 2019 are &lt;A href="https://techcommunity.microsoft.com/blog/exchange/support-for-exchange-server-2016-and-exchange-server-2019-ends-today/4461192" target="_blank" rel="noopener"&gt;out of support&lt;/A&gt;. Only customers who enrolled in the &lt;A href="https://techcommunity.microsoft.com/blog/exchange/announcing-period-2-exchange-20162019-extended-security-update-esu-program/4511603" target="_blank" rel="noopener"&gt;Period 2 Extended Security Update (ESU) program&lt;/A&gt; are eligible to receive Exchange Server 2016 and 2019 security updates released between May and October 2026.&lt;/P&gt;
&lt;P&gt;If you are not part of the Period 2 ESU program, &lt;A href="https://techcommunity.microsoft.com/blog/exchange/upgrading-your-organization-from-current-versions-to-exchange-server-se/4241305" target="_blank" rel="noopener"&gt;migrate to Exchange Server Subscription Edition (SE)&lt;/A&gt; to keep receiving the latest security updates.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;If you have already purchased the Period 2 ESU&lt;/EM&gt; and need information on accessing the latest Security Updates, please contact us by sending an email to &lt;A href="mailto:ExchangeandSfBServerESUInquiry@service.microsoft.com?subject=We%20purchased%20Exchange%20ESU%20need%20access" target="_blank" rel="noopener"&gt;ExchangeandSfBServerESUInquiry@service.microsoft.com&lt;/A&gt;.&lt;/P&gt;
&lt;H3&gt;Known issues with this release&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://support.microsoft.com/en-us/servicing/exchange/server/hotfix/2026/5105719" target="_blank" rel="noopener"&gt;Wrapper messages appear in shared mailbox inbox in hybrid environments | Microsoft Support&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Update installation&lt;/H3&gt;
&lt;P&gt;The following update paths are available:&lt;/P&gt;
&lt;img /&gt;
&lt;UL&gt;
&lt;LI&gt;Inventory your Exchange Servers to determine which updates are needed using the &lt;A href="https://aka.ms/ExchangeHealthChecker" target="_blank" rel="noopener"&gt;Exchange Server Health Checker script&lt;/A&gt;. Running this script will tell you if any of your Exchange Servers are behind on updates (CUs, SUs, or manual actions).&lt;/LI&gt;
&lt;LI&gt;Install the latest CU. Use the &lt;A href="https://aka.ms/ExchangeUpdateWizard" target="_blank" rel="noopener"&gt;Exchange Update Wizard&lt;/A&gt; to choose your current CU and your target CU to get directions.&lt;/LI&gt;
&lt;LI&gt;Re-run the Health Checker after you install an update to see if any further actions are needed.&lt;/LI&gt;
&lt;LI&gt;After setup is completed, please reboot the server and check that all Exchange services have started properly. If some services are in a disabled state, that indicates that something interrupted installation of the update. Please see the Workaround 1 in &lt;A href="https://support.microsoft.com/en-us/topic/file-version-error-when-you-try-to-install-exchange-server-november-2024-su-a650da30-f8fb-469d-a449-47396cab0a15" target="_blank" rel="noopener"&gt;this article&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;If you encounter errors during or after installation of Exchange Server, run the &lt;A href="https://aka.ms/ExSetupAssist" target="_blank" rel="noopener"&gt;SetupAssist script&lt;/A&gt;. If something does not work properly after updates, see &lt;A href="https://aka.ms/ExchangeFAQ" target="_blank" rel="noopener"&gt;Repair failed installations of Exchange Cumulative and Security updates&lt;/A&gt;. Also please see &lt;A href="https://support.microsoft.com/topic/file-version-error-when-you-try-to-install-exchange-server-november-2024-su-a650da30-f8fb-469d-a449-47396cab0a15" target="_blank" rel="noopener"&gt;File version error when you try to install Exchange Server updates&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H1&gt;FAQs&lt;/H1&gt;
&lt;P&gt;&lt;STRONG&gt;When CVE-2026-42897 mitigation was released, there were several reported known issues. Are those addressed in this update?&lt;BR /&gt;&lt;/STRONG&gt;Yes, when July 2026 SU is installed &lt;U&gt;and mitigation is removed&lt;/U&gt;, mitigation known issues should be resolved too.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;If we update some of our servers but cannot update others, can servers that will not receive update stay with CVE-2026-42897 mitigations? Is it OK to have some servers updated and some still using mitigations?&lt;/STRONG&gt;&lt;BR /&gt;You can continue using mitigations on any servers that you cannot update to July 2026 SU (or newer). But note that known issues from mitigations will continue to apply to those servers. Additionally, after applying this update, Office Online Server (OOS) integration with Exchange Server might not function as expected until all Exchange servers in the organization have been updated.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Our organization is in Hybrid mode with Exchange Online. Do we need to do anything?&lt;/STRONG&gt;&lt;BR /&gt;Exchange Online is already protected, but this SU needs to be installed on your Exchange servers, even if they are used only for management purposes. If you change the auth certificate after installing an SU, you should re-run the Hybrid Configuration Wizard.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;The last SU/HU we installed is a few months old. Do we need to install all SUs in order to install the latest one?&lt;/STRONG&gt;&lt;BR /&gt;SUs are cumulative. If you are running a CU supported by the SU, you do not need to install all SUs or HUs in sequential order; simply install the latest SU. Please see&amp;nbsp;&lt;A href="https://techcommunity.microsoft.com/t5/exchange-team-blog/why-exchange-server-updates-matter/ba-p/2280770" target="_blank" rel="noopener"&gt;this blog post&lt;/A&gt;&amp;nbsp;for more information.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Do we need to install SUs on all Exchange Servers within our organization? What about ‘Management Tools only’&amp;nbsp;machines?&lt;/STRONG&gt;&lt;BR /&gt;Our recommendation is to install SUs on&amp;nbsp;&lt;U&gt;all&lt;/U&gt;&amp;nbsp;Exchange Servers and all servers and workstations running the Exchange Management Tools to ensure compatibility between management tools clients and servers. If you are trying to update the Exchange Management Tools in the environment with no running Exchange servers, please see&amp;nbsp;&lt;A href="https://learn.microsoft.com/exchange/manage-hybrid-exchange-recipients-with-management-tools#update-the-exchange-server-management-tools-only-role-with-no-running-exchange-server-to-a-newer-cumulative-or-security-update" target="_blank" rel="noopener"&gt;this&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Our organization does not have the Exchange 2016 and 2019 Period 2 ESU. How can we get current Exchange 2016 or 2019 updates?&lt;/STRONG&gt;&lt;BR /&gt;Since Exchange 2016 and 2019 are now &lt;A href="https://techcommunity.microsoft.com/blog/exchange/support-for-exchange-server-2016-and-exchange-server-2019-ends-today/4461192" target="_blank" rel="noopener"&gt;out of support&lt;/A&gt;, only customers who have enrolled into the &lt;A href="https://techcommunity.microsoft.com/blog/exchange/announcing-period-2-exchange-20162019-extended-security-update-esu-program/4511603" target="_blank" rel="noopener"&gt;Period 2 ESU program&lt;/A&gt; (which is valid between May and October 2026) can obtain Exchange 2016 or 2019 updates released after May 2026. For all other customers still running Exchange 2016 or 2019, we recommend that you &lt;A href="https://techcommunity.microsoft.com/blog/exchange/upgrading-your-organization-from-current-versions-to-exchange-server-se/4241305" target="_blank" rel="noopener"&gt;upgrade your organization to Exchange SE&lt;/A&gt; as soon as possible.&lt;/P&gt;
&lt;P style="background: #F0F0F0; padding: .5em; margin: 1em 0 1em 0;"&gt;Documentation may not be fully available at the time this post is published.&lt;/P&gt;
&lt;P&gt;This post might receive future updates; they will be listed here (if available).&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-12"&gt;The Exchange Server Team&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jul 2026 18:41:35 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/exchange-team-blog/released-july-2026-exchange-server-security-updates/ba-p/4534146</guid>
      <dc:creator>The_Exchange_Team</dc:creator>
      <dc:date>2026-07-24T18:41:35Z</dc:date>
    </item>
    <item>
      <title>Cross-Tenant Message Recall in Exchange Online</title>
      <link>https://techcommunity.microsoft.com/t5/exchange-team-blog/cross-tenant-message-recall-in-exchange-online/ba-p/4535800</link>
      <description>&lt;P&gt;Since we released cloud-based Message Recall in April 2023 (see &lt;A href="https://techcommunity.microsoft.com/t5/exchange-team-blog/cloud-based-message-recall-in-exchange-online/ba-p/3744714" target="_blank"&gt;Cloud-based Message Recall in Exchange Online&lt;/A&gt;), we’ve continued to expand where and how recall works – including &amp;nbsp;support for Outlook on the web and mobile, recipient recall notifications, a maximum recallable message age, and support for external round-trip routing (see &lt;A href="https://techcommunity.microsoft.com/blog/exchange/exchange-online-message-recall-updates/4226568" target="_blank"&gt;Exchange Online Message Recall Updates&lt;/A&gt;).&lt;/P&gt;
&lt;P&gt;Until now, all these capabilities shared one boundary: Message Recall only worked within a single tenant. Today, we’re pleased to announce one of our most requested cross-organization enhancements:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Cross-Tenant Message Recall, controlled by a tenant admin allow list&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;The intra-tenant boundary&lt;/H3&gt;
&lt;P&gt;By design due to privacy concerns, Message Recall operates within the Exchange Online service boundary, and until now it has been limited to intra-tenant messages – those where the sender and the recipients belong to the same Microsoft 365 tenant. When a sender tried to recall a message they had sent to recipients in a different tenant, the recall would fail, even between organizations that work closely together and trust one another.&lt;/P&gt;
&lt;P&gt;Customers told us this was a gap. Partners, subsidiaries, and affiliated organizations that collaborate daily across tenant boundaries wanted the same recall experience they already had inside their own tenant.&lt;/P&gt;
&lt;H3&gt;Introducing cross-tenant Message Recall&lt;/H3&gt;
&lt;P&gt;With Cross-Tenant Message Recall, a tenant admin can add other Microsoft 365 tenants to an allow list. Once a tenant is on the list, senders from those allow-listed tenants can recall messages they’ve sent to recipients in the receiving tenant – just as they would for an intra-tenant recall.&lt;/P&gt;
&lt;P&gt;Control sits with the &lt;STRONG&gt;receiving tenant&lt;/STRONG&gt; – the organization whose users received the messages. A cross-tenant recall is only honored when the receiving tenant’s admin has explicitly allow-listed the sender’s tenant. This keeps the receiving organization in full control of which external tenants are permitted to recall messages from its users’ mailboxes. The feature is disabled by default; no cross-tenant recall occurs until an admin adds at least one tenant to the allow list.&lt;/P&gt;
&lt;H3&gt;How it works&lt;/H3&gt;
&lt;P&gt;Consider two organizations that work together, Contoso and Fabrikam, both of whom are hosted in Microsoft 365:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;A Contoso admin adds Fabrikam’s tenant to Contoso’s cross-tenant recall allow list.&lt;/LI&gt;
&lt;LI&gt;A sender at Fabrikam recalls a message they previously sent to a recipient at Contoso.&lt;/LI&gt;
&lt;LI&gt;Because Contoso has allow-listed Fabrikam, the recall is honored and processed like a standard recall against the Contoso recipient’s mailbox.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;If Fabrikam is &lt;EM&gt;not&lt;/EM&gt; on Contoso’s allow list, the recall fails and the Fabrikam sender will see in the recall status report that the message can’t be recalled across organizations. Allow-listing governs inbound recalls into the receiving tenant, so each organization decides independently which external tenants it trusts to recall messages from its mailboxes.&lt;/P&gt;
&lt;H2&gt;Configuring with Exchange Online PowerShell&lt;/H2&gt;
&lt;P&gt;Admins can configure these settings using Exchange Online PowerShell.&lt;/P&gt;
&lt;P&gt;Enable or disable cross-tenant message recall for the tenant. Setting this parameter to $True turns on the capability; $False (default) turns it off:&lt;/P&gt;
&lt;PRE class="lia-indent-padding-left-30px"&gt;Set-CrossTenantRecallConfiguration -CrossTenantRecallEnabled [$true | $false]&lt;/PRE&gt;
&lt;P&gt;Specify external tenants to add or remove from the allowed list. Add the tenant IDs of the organizations you trust to perform recalls:&lt;/P&gt;
&lt;PRE class="lia-indent-padding-left-30px"&gt;Set-CrossTenantRecallConfiguration -AllowedSenderTenantIds @{Add="&amp;lt;tenantId 1&amp;gt;","&amp;lt;tenantId 2&amp;gt;"}; {Remove="&amp;lt;tenantId 1&amp;gt;","&amp;lt;tenantId 2&amp;gt;"}&amp;nbsp;&lt;/PRE&gt;
&lt;H3&gt;What senders and recipients see&lt;/H3&gt;
&lt;P&gt;When a sender in an allow-listed tenant recalls a message, recipients in the receiving tenant experience the recall exactly as they would an intra-tenant recall. If the receiving tenant has enabled recipient recall notifications, those notifications apply to cross-tenant recalls as well. If the sender’s tenant is not on the receiving tenant’s allow list, the sender receives a notification that the message can’t be recalled across organizations.&lt;/P&gt;
&lt;H3&gt;Availability&lt;/H3&gt;
&lt;P&gt;Cross-Tenant Message Recall will start to deploy to worldwide, GCC, GCC High, DoD and Microsoft 365 operated by 21Vianet starting mid-August, completing by mid-September. We hope you’ll find this enhancement useful, and we look forward to your feedback.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-12"&gt;Microsoft 365 Messaging Team&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jul 2026 15:38:58 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/exchange-team-blog/cross-tenant-message-recall-in-exchange-online/ba-p/4535800</guid>
      <dc:creator>The_Exchange_Team</dc:creator>
      <dc:date>2026-07-10T15:38:58Z</dc:date>
    </item>
    <item>
      <title>Upcoming retirement of OWA Light in Exchange Server</title>
      <link>https://techcommunity.microsoft.com/t5/exchange-team-blog/upcoming-retirement-of-owa-light-in-exchange-server/ba-p/4534943</link>
      <description>&lt;P style="background: #66FF99; padding: .5em; margin: 1em 0 1em 0;"&gt;&lt;STRONG&gt;Update 8/13/2026:&lt;/STRONG&gt; This retirement is now complete, please see &lt;A href="https://techcommunity.microsoft.com/blog/exchange/released-august-2026-exchange-server-security-updates/4543951" target="_blank"&gt;Released: August 2026 Exchange Server Security Updates | Microsoft Community Hub&lt;/A&gt;. For customers who do not have access to August 2026 Exchange security updates, we recommend that you disable OWA Light as per instructions below.&lt;/P&gt;
&lt;P&gt;We are announcing our plan to retire and disable the OWA Light experience in Exchange Server in a future update. OWA Light was created for a much earlier era of the web, when browser support, bandwidth, and accessibility technologies were very different from today. Going forward, we want to invest in modern Outlook on the web experience that provides the cross-browser, accessible, and security-focused experience.&lt;/P&gt;
&lt;P&gt;Organizations that still rely on OWA Light must move users to the standard Outlook on the web experience and review any internal guidance, bookmarks, training material, helpdesk scripts, or accessibility workflows that reference OWA Light.&lt;/P&gt;
&lt;P&gt;This is how OWA Light looks like:&lt;/P&gt;
&lt;img /&gt;
&lt;H3&gt;What is changing&lt;/H3&gt;
&lt;P&gt;In an upcoming Exchange Server update (estimated in August 2026), we plan to disable and remove the OWA Light experience. After that change is introduced, users will no longer be able to choose or be redirected to OWA Light and should use the modern Outlook on the web experience instead.&lt;/P&gt;
&lt;P&gt;This announcement applies to Exchange Server (on-premises). We announced &lt;A href="https://support.microsoft.com/en-us/outlook/learn-more-about-the-light-version-of-outlook" target="_blank" rel="noopener"&gt;deprecation of OWA Light in August 2024&lt;/A&gt;.&lt;/P&gt;
&lt;H3&gt;Why we are making this change&lt;/H3&gt;
&lt;P&gt;OWA Light served customers well for many years. It was designed for older browsers, slower connections, and scenarios where a simplified web interface helped users access mail in environments that could not support the full Outlook Web App experience.&lt;/P&gt;
&lt;P&gt;The web has changed significantly since OWA Light was introduced. Modern browsers are more capable and more consistent, network conditions have improved for many customers, and security landscape has changed significantly. Maintaining a separate legacy OWA Light experience increases complexity. Each additional content rendering path, control surface, and compatibility layer must be evaluated as we strengthen defenses against modern web threats.&lt;/P&gt;
&lt;P&gt;We recommend that Exchange Server administrators use this time to identify and prepare any users, processes, or documentation that still depend on OWA Light.&lt;/P&gt;
&lt;P&gt;To block OWA Light right away, you can create or update an existing OWA mailbox policy:&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;Set-OwaMailboxPolicy -OwaLightEnabled $false&lt;/LI-CODE&gt;
&lt;P&gt;Make sure that the OwaMailboxPolicy is assigned to all mailboxes. You can assign a OwaMailboxPolicy by using the&amp;nbsp;&lt;STRONG&gt;Set-CasMailbox -OwaMailboxPolicy &lt;/STRONG&gt; cmdlet.&lt;/P&gt;
&lt;P&gt;Additionally, disable the OWA Light selection menu on the OWA logon page. You can do that by running:&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;Set-OwaVirtualDirectory -LogonPageLightSelectionEnabled $false&lt;/LI-CODE&gt;
&lt;P&gt;More information can be found in the&amp;nbsp;&lt;A href="https://learn.microsoft.com/powershell/module/exchangepowershell/set-owamailboxpolicy?view=exchange-ps" target="_blank" rel="noopener"&gt;Set-OwaMailboxPolicy&lt;/A&gt; &amp;nbsp;and &lt;A href="https://learn.microsoft.com/en-us/powershell/module/exchangepowershell/set-owavirtualdirectory" target="_blank" rel="noopener"&gt;Set-OwaVirtualDirectory&lt;/A&gt; documentation.&lt;/P&gt;
&lt;H3&gt;Summary&lt;/H3&gt;
&lt;P&gt;OWA Light was an important compatibility experience when the web needed it. Today, the full Outlook on the web experience is the right place for us to focus. Retiring OWA Light will help reduce legacy surface area, simplify ongoing engineering work, and allow us to continue improving the experience customers use every day.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-12"&gt;The Exchange Server team&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2026 15:52:59 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/exchange-team-blog/upcoming-retirement-of-owa-light-in-exchange-server/ba-p/4534943</guid>
      <dc:creator>The_Exchange_Team</dc:creator>
      <dc:date>2026-08-13T15:52:59Z</dc:date>
    </item>
    <item>
      <title>Introducing EWSAllowedAppIDs: Preparing for the Final Phase of EWS Retirement</title>
      <link>https://techcommunity.microsoft.com/t5/exchange-team-blog/introducing-ewsallowedappids-preparing-for-the-final-phase-of/ba-p/4529471</link>
      <description>&lt;P&gt;Exchange Web Services (EWS) retirement in Exchange Online is entering its final phase. Over the last several years, Microsoft has worked with product teams, independent software vendors (ISVs), and customers across the ecosystem to migrate workloads to Microsoft Graph and other modern APIs. Many of those migrations are complete, and many others are well underway.&lt;/P&gt;
&lt;P&gt;As phased EWS disablement in Exchange Online approaches in October 2026, we are introducing a new capability to help administrators prepare in a controlled and predictable way: &lt;STRONG&gt;EWSAllowedAppIDs&lt;/STRONG&gt;. This is the AppID Allow List functionality that we mentioned in&amp;nbsp;&lt;A href="https://techcommunity.microsoft.com/blog/exchange/exchange-online-ews-your-time-is-almost-up/4492361" target="_blank" rel="noopener"&gt;Exchange Online EWS, Your Time is Almost Up | Microsoft Community Hub&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;EWSAllowedAppIDs gives administrators a practical way to identify remaining dependencies, limit EWS access to approved applications, and reduce the risk of disruption as retirement enforcement begins.&lt;/P&gt;
&lt;P&gt;This feature is starting to roll out now. All tenants should be able to view the parameter when running Get-OrganizationConfig, but they won’t be able to set the list until the roll out reaches the tenant.&lt;/P&gt;
&lt;H3&gt;What is EWSAllowedAppIDs?&lt;/H3&gt;
&lt;P&gt;EWSAllowedAppIDs is a tenant-level AppID allow list that lets Exchange Online administrators explicitly define which applications are still permitted to access EWS, based on their App ID.&lt;/P&gt;
&lt;P&gt;When configured, only applications whose App IDs appear in the AppID allow list can continue using EWS in the tenant when EWSEnabled at the tenant level is set to True.&lt;/P&gt;
&lt;P&gt;This feature is designed to support the final transition away from broad, unrestricted EWS access and toward tightly scoped, intentional usage during the retirement window.&lt;/P&gt;
&lt;P&gt;Note: The EWSAllowList feature Exchange has had for many years is based on &lt;EM&gt;User Agent&lt;/EM&gt;, &lt;EM&gt;not App ID (and it applies to REST/Graph not just EWS by the way)&lt;/EM&gt;. Both can work together, but they operate on different aspects of the calling application.&lt;/P&gt;
&lt;P&gt;Administrators can use the feature to:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Identify which applications still require EWS&lt;/LI&gt;
&lt;LI&gt;Restrict EWS access to only approved applications&lt;/LI&gt;
&lt;LI&gt;Prepare for the final retirement of EWS in Exchange Online&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;How EWSAllowedAppIDs fits into the EWS endgame&lt;/H3&gt;
&lt;P&gt;We &lt;A href="https://techcommunity.microsoft.com/blog/exchange/exchange-online-ews-your-time-is-almost-up/4492361" target="_blank" rel="noopener"&gt;previously announced&lt;/A&gt; that phased EWS disablement in Exchange Online will begin in October 2026.&lt;/P&gt;
&lt;P&gt;To understand why EWSAllowedAppIDs matters, it helps to look at how Exchange Online behavior changes before and after that date. The retirement model uses the existing EWSEnabled organization-level setting together with the new EWSAllowedAppIDs allow list. (Refresh yourself on how the EWSEnabled switch works and how to set it &lt;A href="https://techcommunity.microsoft.com/blog/exchange/exchange-online-ews-your-time-is-almost-up/4492361" target="_blank" rel="noopener"&gt;here&lt;/A&gt;)&lt;/P&gt;
&lt;P&gt;Before October 2026, the behavior is intentionally permissive to give customers time to inventory dependencies, deploy an AppID allow list, and validate which applications still require EWS.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Before October 2026&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;&lt;STRONG&gt;EWSEnabled Value&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;&lt;STRONG&gt;AppID Allow List State&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;&lt;STRONG&gt;Behavior&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;&lt;STRONG&gt;Null (default)&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;Ignored&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;All EWS traffic allowed&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;&lt;STRONG&gt;True&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;Empty or Null&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;All EWS traffic allowed&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;&lt;STRONG&gt;True&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;Populated&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;Only listed applications allowed&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;&lt;STRONG&gt;False&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;All EWS traffic blocked&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;This pre-October phase gives administrators room to deploy and test an AppID allow list without immediately breaking existing applications.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What changes in October 2026&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Beginning in October 2026, Exchange Online starts transitioning tenants into retirement enforcement behavior.&lt;/P&gt;
&lt;P&gt;At that point, enabling EWS without configuring an AppID allow list will no longer act as an unrestricted “allow everything” mode.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Starting October 2026&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 74.6296%; border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;&lt;STRONG&gt;EWSEnabled Value&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;&lt;STRONG&gt;AppID Allow List State&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;&lt;STRONG&gt;Behavior&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;&lt;STRONG&gt;Null&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;Ignored&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;All EWS allowed (but tenant will have EWSEnabled set to False at some point as part of phased rollout by Microsoft)&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;&lt;STRONG&gt;True&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;Empty or Null&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-8"&gt;All EWS traffic blocked &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-8"&gt;&lt;SPAN class="lia-text-color-21"&gt;(&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="lia-text-color-21"&gt;Org Relationships as announced in MC1447678 will work. Please see&amp;nbsp;&lt;A href="https://techcommunity.microsoft.com/blog/exchange/cross-tenant-freebusy-mailtips-and-calendar-sharing-are-moving-to-cross-tenant-a/4545169" target="_blank" rel="noopener"&gt;&lt;SPAN class="lia-text-color-10"&gt;&lt;U&gt;Cross-tenant Free/Busy, MailTips, and Calendar Sharing are moving to Cross-Tenant Access Policy | Microsoft Community Hub for more information&lt;/U&gt;&lt;/SPAN&gt;&lt;/A&gt;)&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;&lt;STRONG&gt;True&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;Populated&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;Only listed applications allowed&lt;/P&gt;
&lt;P&gt;(Org Relationships as announced in MC1447678 will also work)&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;&lt;STRONG&gt;False&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;Any&lt;/P&gt;
&lt;/td&gt;&lt;td style="border-width: 1px;"&gt;
&lt;P&gt;All EWS traffic blocked&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 20.6211%" /&gt;&lt;col style="width: 18.7578%" /&gt;&lt;col style="width: 60.4969%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;This is the most important behavioral change administrators need to understand: after enforcement begins, &lt;EM&gt;setting EWSEnabled=True without an AppID allow list effectively becomes a block-all configuration&lt;/EM&gt;.&lt;/P&gt;
&lt;P&gt;This change is intentional. The goal is not to keep EWS available indefinitely, but to require explicit acknowledgement that EWS is still needed and to scope that usage down to known, approved applications.&lt;/P&gt;
&lt;P&gt;The goal of the retirement process is not simply to keep EWS “on” indefinitely, but to:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Force explicit acknowledgement that EWS is still required&lt;/LI&gt;
&lt;LI&gt;Scope usage down to known, approved applications&lt;/LI&gt;
&lt;LI&gt;Accelerate migration to Microsoft Graph and modern APIs&lt;/LI&gt;
&lt;/OL&gt;
&lt;H2&gt;What happens if a tenant admin does nothing?&lt;/H2&gt;
&lt;P&gt;Today, many tenants still have EWSEnabled unset (Null), which behaves as unrestricted access.&lt;/P&gt;
&lt;P&gt;As the phased retirement rollout starts in October 2026, those tenants will have EWS disabled (EWSEnabled set to False) as part of the staged shutdown process.&lt;/P&gt;
&lt;P&gt;Administrators who still require EWS at that point will need to take explicit action.&lt;/P&gt;
&lt;P&gt;The recommended path is:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Configure or validate the EWSAllowedAppIDs allow list (remember, we said we would populate this for tenants who have not done so – read more&amp;nbsp;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/exchange/take-control-of-your-ewsallowedappids-list-before-ews-access-changes/4553534" target="_blank" rel="noopener" data-lia-auto-title="here" data-lia-auto-title-active="0"&gt;here&lt;/A&gt; – but the admin owns ensuring it’s correct).&lt;/LI&gt;
&lt;LI&gt;Set EWSEnabled=True&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Customers who complete this work proactively will be significantly less likely to experience disruption during the broader retirement rollout.&lt;/P&gt;
&lt;H3&gt;Why we strongly recommend enabling this feature now&lt;/H3&gt;
&lt;P&gt;Customers should not think of EWSAllowedAppIDs as a feature intended only for October 2026. Its greatest value is in the preparation period before enforcement begins.&lt;/P&gt;
&lt;P&gt;Deploying and validating the AppID allow list now gives administrators time to find unknown dependencies, remove obsolete applications, engage vendors that still rely on EWS, and begin migrations to Microsoft Graph.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Discover unknown EWS dependencies&lt;/LI&gt;
&lt;LI&gt;Remove obsolete applications&lt;/LI&gt;
&lt;LI&gt;Contact vendors still requiring EWS&lt;/LI&gt;
&lt;LI&gt;Begin migrations to Graph APIs&lt;/LI&gt;
&lt;LI&gt;Validate which applications truly still require exceptions&lt;/LI&gt;
&lt;LI&gt;Reduce future support escalations and outages&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Administrators who wait until they are already impacted by phased disablement will have a much smaller remediation window and a significantly higher likelihood of disruption.&lt;/P&gt;
&lt;H2&gt;Recommended next steps for administrators&lt;/H2&gt;
&lt;P&gt;We strongly recommend that Exchange Online administrators begin this work now:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Inventory EWS usage&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Identify all applications and services currently using EWS in your organization. Use EWS usage reports where available in your tenant, and review Message Center posts that summarize tenant usage. Please see &lt;A href="https://techcommunity.microsoft.com/blog/exchange/notes-from-the-field-finding-and-remediating-ews-app-usage-before-retirement/4496469" target="_blank" rel="noopener"&gt;Notes From the Field: Finding and Remediating EWS App Usage Before Retirement | Microsoft Community Hub&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Build an AppID allow list&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Create an EWSAllowedAppIDs allow list containing only applications that are known to still require EWS. This includes Microsoft first-party client apps such as Office, Power Query for Excel etc. If the app shows up in your usage report, and you want to keep using it, you need to add it to the list.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If an administrator already knows which applications they want to permit, they can create a new AppID allow list directly by specifying one or more App IDs.&lt;/P&gt;
&lt;P&gt;For example:&lt;/P&gt;
&lt;PRE&gt;Set-OrganizationConfig -EwsAllowedAppIDs "11111111-2222-3333-4444-555555555555,aaaaaaaa-bbbb-cccc-dddd-eeeeeeeeeeee"&lt;/PRE&gt;
&lt;P&gt;This replaces the current value with the specified set of allowed applications.&lt;/P&gt;
&lt;P&gt;After setting the value, administrators can confirm the configured list using:&lt;/P&gt;
&lt;PRE&gt;Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy | Format-List EwsAllowedAppIDs&lt;/PRE&gt;
&lt;P style="background: #F0F0F0; padding: .5em; margin: 1em 0 1em 0;"&gt;The use of “RetrieveEwsOperationAccessPolicy” is required for performance reasons – we only want to retrieve this list if the admin explicitly asks for it.&amp;nbsp;&lt;/P&gt;
&lt;P style="background: #F0F0F0; padding: .5em; margin: 1em 0 1em 0;"&gt;Changes to this list can take up to 24 hours to take effect. Again, for performance reasons, servers only refresh their in-memory cache once every 24 hours.&amp;nbsp;&lt;/P&gt;
&lt;P style="background: #F0F0F0; padding: .5em; margin: 1em 0 1em 0;"&gt;Administrators should be aware that setting the property writes the full list value. If the property already contains App IDs, they will be replaced unless included in the new command. See more below on this.&lt;/P&gt;
&lt;H3&gt;Test thoroughly&lt;/H3&gt;
&lt;P&gt;Validate that all applications on your AppID allow list continue to work as expected, and check for any missed dependencies. If you need to add or remove an App ID, you must read the current list, compute the updated list, and then write the full value back. Today, this cmdlet does not support incremental add or remove operations.&lt;/P&gt;
&lt;P&gt;Here are two examples that show how to update the list:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Example: add a new App ID&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The common pattern is to read the current list, append the new App ID, and then write the full combined list back.&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;# Read the current allow list 
$current = (Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy | Select-Object -ExpandProperty EwsAllowedAppIDs) 
# Define the new App ID to add 
$newAppId = "99999999-8888-7777-6666-555555555555" 
# Combine existing and new values 
$updated = @($current, $newAppId) 
# Write the updated allow list back 
Set-OrganizationConfig -EwsAllowedAppIDs ($updated -join ",")&lt;/LI-CODE&gt;
&lt;P&gt;&lt;STRONG&gt;Example: remove an App ID&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Because there is no single-item removal operation today, removal also requires recomputing the full list.&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;# Read the current allow list 
$current = (Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy | Select-Object -ExpandProperty EwsAllowedAppIDs) 
# Define the App ID to remove 
$removeAppId = "99999999-8888-7777-6666-555555555555" 
# Split the comma-separated list into individual App IDs 
$appIds = $current -split "," 
# Remove the specified App ID 
$updated = $appIds | Where-Object { $_ -ne $removeAppId } 
# Write the updated allow list back 
Set-OrganizationConfig -EwsAllowedAppIDs ($updated -join ",")&lt;/LI-CODE&gt;
&lt;H3&gt;The bigger picture&lt;/H3&gt;
&lt;P&gt;EWS served the Exchange ecosystem for nearly two decades.&lt;/P&gt;
&lt;P&gt;However, modern requirements for security, reliability, compliance, and scale call for a more modern API platform. Microsoft Graph is the long-term strategic platform for most Exchange Online integration scenarios.&lt;/P&gt;
&lt;P&gt;EWSAllowedAppIDs is designed to make the final transition manageable and predictable while still encouraging rapid migration off EWS.&lt;/P&gt;
&lt;P&gt;Organizations that prepare early will navigate this transition most smoothly. Administrators who inventory dependencies now and validate their AppID allow lists well before October 2026 will be far better positioned to avoid disruption as phased retirement begins.&lt;/P&gt;
&lt;P&gt;The time to prepare is now.&lt;/P&gt;
&lt;P&gt;For the latest on the overall plan, status on parity gaps and links to resources, please check the &lt;A href="https://learn.microsoft.com/exchange/clients-and-mobile-in-exchange-online/deprecation-of-ews-exchange-online" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Deprecation of Exchange Web Services in Exchange Online&lt;/STRONG&gt;&lt;/A&gt; page.&lt;/P&gt;
&lt;H3&gt;AppID Allow List FAQs&lt;/H3&gt;
&lt;P&gt;&lt;STRONG&gt;Can we set EWSEnabled=True in August without creating our own AppID Allow List?&lt;/STRONG&gt;&lt;BR /&gt;Yes, but we’d rather your tenant admin creates it, to ensure it’s exactly meeting your needs. We will be populating AppID Allow Lists for our customers automatically (based on each tenant’s usage). If you only set EWSEnabled=True in August and we will populate your AppID Allow List for you, we might also include apps in there you weren’t aware of (if they show usage). We recommend that admins create their own AppID Allow Lists to control exactly which EWS applications they want to allow after October 2026. See &lt;A href="https://techcommunity.microsoft.com/blog/exchange/take-control-of-your-ewsallowedappids-list-before-ews-access-changes/4553534" target="_blank" rel="noopener"&gt;Take control of your EWSAllowedAppIDs list before EWS access changes | Microsoft Community Hub&lt;/A&gt; for more information.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;If we create our own AppID Allow List, will Microsoft change it during automatic AppID Allow List processing for all tenants?&lt;/STRONG&gt;&lt;BR /&gt;No. If you create your own AppID Allow List, our automated process will not change your already created AppID Allow Lists. Your AppID Allow List will stay unchanged.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;If Microsoft auto-populates the list in for a tenant, can an administrator manually overwrite or append to that list via PowerShell afterward?&lt;/STRONG&gt;&lt;BR /&gt;Yes, Administrators will be able to change the content of AppID Allow List.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What about the EWSAllowList setting? Should we add application IDs there?&lt;/STRONG&gt;&lt;BR /&gt;EWSAllowList and EWSBlockList settings are related to the&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/exchange/client-developer/exchange-web-services/how-to-control-access-to-ews-in-exchange" target="_blank" rel="noopener"&gt;EwsApplicationAccessPolicy&lt;/A&gt;&amp;nbsp;feature that has existed for long time. This is&amp;nbsp;&lt;EM&gt;not related to EWS deprecation in Exchange Online&lt;/EM&gt;. EwsApplicationAccessPolicy is an older EWS application access control feature and requires USER AGENTS instead of AppIDs. Modifying EwsApplicationAccessPolicy simply adds additional "gate" a client application needs to pass to connect to Exchange Online, and application can pass it only after it has passed the AppID Allow List mentioned above. So, if you start to use this with EWSAllowedAppIDs, both the App ID and the correct User Agent for the request must both pass their individual logic, otherwise the request will be denied due to EWS being blocked.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Updates to this blog post:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;9/4/2026: Modified the FAQ and text to reflect the timing that we have published about when Microsoft will create the AppID allow list for tenants who have not done so yet. See &lt;A href="https://techcommunity.microsoft.com/blog/exchange/take-control-of-your-ewsallowedappids-list-before-ews-access-changes/4553534" target="_blank" rel="noopener"&gt;Take control of your EWSAllowedAppIDs list before EWS access changes | Microsoft Community Hub&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;9/1/2026: Added FAQs related to AppID Allow List / EWSAllowedAppIDs property&lt;/LI&gt;
&lt;LI&gt;9/1/2026: Clarified all mentions of "Allow list" to be "AppID Allow List" (the allow list that takes Application IDs, as opposed to user agent strings used by EwsApplicationAccessPolicy and it's EWSAllowList setting).&lt;/LI&gt;
&lt;LI&gt;8/14/2026: Updated the Allow List table to specify what happens when EWSEnabled = True and Allow List is populated.&lt;/LI&gt;
&lt;LI&gt;8/7/2026: Added a link to &lt;A href="https://techcommunity.microsoft.com/blog/exchange/cross-tenant-freebusy-mailtips-and-calendar-sharing-are-moving-to-cross-tenant-a/4545169" target="_blank" rel="noopener"&gt;Cross-tenant Free/Busy, MailTips, and Calendar Sharing are moving to Cross-Tenant Access Policy | Microsoft Community Hub&lt;/A&gt; related to Org Relationship announcement in MC1447678&lt;/LI&gt;
&lt;LI&gt;8/6/2026: Added a mention of Organization Relationships and that that EWS traffic is&amp;nbsp;&lt;EM&gt;not&lt;/EM&gt; related to or blocked by the state of Allow List (related to MC1447678)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-12"&gt;The Exchange Team&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Sep 2026 17:18:33 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/exchange-team-blog/introducing-ewsallowedappids-preparing-for-the-final-phase-of/ba-p/4529471</guid>
      <dc:creator>The_Exchange_Team</dc:creator>
      <dc:date>2026-09-04T17:18:33Z</dc:date>
    </item>
    <item>
      <title>Released: June 2026 Exchange Server Security Updates</title>
      <link>https://techcommunity.microsoft.com/t5/exchange-team-blog/released-june-2026-exchange-server-security-updates/ba-p/4524491</link>
      <description>&lt;P&gt;Microsoft has released Security Updates (SUs) for vulnerabilities found in:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Exchange Server Subscription Edition (SE)&lt;/LI&gt;
&lt;LI&gt;Exchange Server 2019&lt;/LI&gt;
&lt;LI&gt;Exchange Server 2016&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;SUs are available for the following specific versions of Exchange Server:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/download/details.aspx?id=108698" target="_blank" rel="noopener"&gt;Exchange SE RTM&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Exchange Server 2019&amp;nbsp;CU14&amp;nbsp;and&amp;nbsp;CU15 (to access, organization must be enrolled into the &lt;A href="https://techcommunity.microsoft.com/blog/exchange/announcing-period-2-exchange-20162019-extended-security-update-esu-program/4511603" target="_blank" rel="noopener"&gt;Period 2 ESU program&lt;/A&gt;)&lt;/LI&gt;
&lt;LI&gt;Exchange Server 2016&amp;nbsp;CU23 (to access, organization must be enrolled into the &lt;A href="https://techcommunity.microsoft.com/blog/exchange/announcing-period-2-exchange-20162019-extended-security-update-esu-program/4511603" target="_blank" rel="noopener"&gt;Period 2 ESU program&lt;/A&gt;)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The June 2026 SUs address vulnerabilities responsibly reported to Microsoft by security partners and found through Microsoft’s internal processes as well as &lt;A href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42897" target="_blank" rel="noopener"&gt;CVE-2026-42897&lt;/A&gt; that we announced: &lt;A href="https://techcommunity.microsoft.com/blog/Exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498/" target="_blank" rel="noopener"&gt;Addressing Exchange Server May 2026 vulnerability CVE-2026-42897 | Microsoft Community Hub&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;These vulnerabilities affect Exchange Server. Exchange Online customers are already protected from the vulnerabilities addressed by these SUs and do not need to take any action other than updating any Exchange servers or Exchange Management tools workstations in their environment.&lt;/P&gt;
&lt;P&gt;More details about specific CVEs can be found in the&amp;nbsp;&lt;A href="https://msrc.microsoft.com/update-guide/" target="_blank" rel="noopener"&gt;Security Update Guide&lt;/A&gt;&amp;nbsp;(filter on ‘Server Software’ under Product Family for Exchange SE and ‘ESU’ under Product Family for Exchange 2016 and 2019).&lt;/P&gt;
&lt;H3&gt;Update to ensure continued function of Exchange Emergency Mitigation (EM) and Feature Flighting services&lt;/H3&gt;
&lt;P&gt;Due to service-side change, the &lt;A href="https://learn.microsoft.com/en-us/exchange/plan-and-deploy/post-installation-tasks/security-best-practices/exchange-emergency-mitigation-service" target="_blank" rel="noopener"&gt;Exchange Emergency Mitigation (EM)&lt;/A&gt; and &lt;A href="https://learn.microsoft.com/exchange/plan-and-deploy/post-installation-tasks/feature-flighting" target="_blank" rel="noopener"&gt;Exchange Flighting&lt;/A&gt; services will be unable to use configuration files released in July 2026 or later, unless Exchange is updated to June 2026 update (or newer). Any mitigations already downloaded and applied will keep working, but servers will not be able to use any new mitigations starting in July 2026 unless updates are installed. Please see &lt;A href="https://support.microsoft.com/topic/e2d8ccf3-209f-4056-845e-07d3e4a28646" target="_blank" rel="noopener"&gt;Exchange mitigation and flighting services fail due to "Unknown Issuer" error&lt;/A&gt; for more details.&lt;/P&gt;
&lt;H3&gt;CVE-2026-42897 mitigations after installation&lt;/H3&gt;
&lt;P&gt;As part of our ongoing efforts to strengthen security and improve defenses across environments, we continue to enhance protections for cross-site scripting attacks. &lt;EM&gt;We recommend that customers keep CVE-2026-42897 mitigation in place.&lt;/EM&gt; The mitigation provides an additional layer of defense and helps ensure continuous protection as further improvements are released. Additional updates will be shared as they become available - now available, please see &lt;A href="https://techcommunity.microsoft.com/blog/exchange/released-july-2026-exchange-server-security-updates/4534146" target="_blank"&gt;Released: July 2026 Exchange Server Security Updates | Microsoft Community Hub&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Installing the June 2026 update &lt;EM&gt;does not&lt;/EM&gt; automatically remove already applied CVE-2026-42897 mitigations. Therefore, if you choose to remove mitigations after installation, you should:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;If mitigation was applied using Exchange Emergency Mitigation (EM) Service:&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/exchange/plan-and-deploy/post-installation-tasks/security-best-practices/exchange-emergency-mitigation-service#blocking-or-removing-mitigations" target="_blank" rel="noopener"&gt;Block the mitigation M2.1.0 from re-applying&lt;/A&gt;. Because of our recommendation to keep the CVE-2026-42897 mitigation in place, we are not yet updating the mitigation to not apply to servers that are updated to June 2026 SU. Therefore, at this time, you must block the mitigation from re-applying first.&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/Exchange/plan-and-deploy/post-installation-tasks/security-best-practices/exchange-emergency-mitigation-service#rollback-procedures-for-released-mitigations" target="_blank" rel="noopener"&gt;Remove the mitigation M2 IIS rules&lt;/A&gt;.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;If mitigation was applied using the downloadable EOMT script &lt;/STRONG&gt;&lt;A href="https://aka.ms/UnifiedEOMT" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;https://aka.ms/UnifiedEOMT&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;: &lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;A href="https://microsoft.github.io/CSS-Exchange/Security/EOMT/#roll-back-a-mitigation" target="_blank" rel="noopener"&gt;Roll back the mitigation&lt;/A&gt;.&lt;/LI&gt;
&lt;/OL&gt;
&lt;H3&gt;Exchange 2016 and 2019 updates are available &lt;EM&gt;only&lt;/EM&gt; under the Period 2 ESU program&lt;/H3&gt;
&lt;P&gt;Exchange Server 2016 and 2019 are &lt;A href="https://techcommunity.microsoft.com/blog/exchange/support-for-exchange-server-2016-and-exchange-server-2019-ends-today/4461192" target="_blank" rel="noopener"&gt;out of support&lt;/A&gt;. Only customers who enrolled in the &lt;A href="https://techcommunity.microsoft.com/blog/exchange/announcing-period-2-exchange-20162019-extended-security-update-esu-program/4511603" target="_blank" rel="noopener"&gt;Period 2 Extended Security Update (ESU) program&lt;/A&gt; are eligible to receive Exchange Server 2016 and 2019 security updates released between May and October 2026.&lt;/P&gt;
&lt;P&gt;If you are not part of the Period 2 ESU program, &lt;A href="https://techcommunity.microsoft.com/blog/exchange/upgrading-your-organization-from-current-versions-to-exchange-server-se/4241305" target="_blank" rel="noopener"&gt;migrate to Exchange Server Subscription Edition (SE)&lt;/A&gt; to keep receiving the latest security updates.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;If you have already purchased the Period 2 ESU&lt;/EM&gt; and need information on accessing the latest Security Updates, please contact us by sending an email to &lt;A href="mailto:ExchangeandSfBServerESUInquiry@service.microsoft.com?subject=We%20purchased%20Exchange%20ESU%20need%20access" target="_blank" rel="noopener"&gt;ExchangeandSfBServerESUInquiry@service.microsoft.com&lt;/A&gt;.&lt;/P&gt;
&lt;H3&gt;Known issues with this release&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://support.microsoft.com/en-us/servicing/exchange/server/hotfix/2026/5105719" target="_blank" rel="noopener"&gt;Wrapper messages appear in shared mailbox inbox in hybrid environments | Microsoft Support&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Update installation&lt;/H3&gt;
&lt;P&gt;The following update paths are available:&lt;/P&gt;
&lt;img /&gt;
&lt;UL&gt;
&lt;LI&gt;Inventory your Exchange Servers to determine which updates are needed using the &lt;A href="https://aka.ms/ExchangeHealthChecker" target="_blank" rel="noopener"&gt;Exchange Server Health Checker script&lt;/A&gt;. Running this script will tell you if any of your Exchange Servers are behind on updates (CUs, SUs, or manual actions).&lt;/LI&gt;
&lt;LI&gt;Install the latest CU. Use the &lt;A href="https://aka.ms/ExchangeUpdateWizard" target="_blank" rel="noopener"&gt;Exchange Update Wizard&lt;/A&gt; to choose your current CU and your target CU to get directions.&lt;/LI&gt;
&lt;LI&gt;Re-run the Health Checker after you install an update to see if any further actions are needed.&lt;/LI&gt;
&lt;LI&gt;After setup is completed, please reboot the server and check that all Exchange services have started properly. If some services are in a disabled state, that indicates that something interrupted installation of the update. Please see the Workaround 1 in &lt;A href="https://support.microsoft.com/en-us/topic/file-version-error-when-you-try-to-install-exchange-server-november-2024-su-a650da30-f8fb-469d-a449-47396cab0a15" target="_blank" rel="noopener"&gt;this article&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;If you encounter errors during or after installation of Exchange Server, run the &lt;A href="https://aka.ms/ExSetupAssist" target="_blank" rel="noopener"&gt;SetupAssist script&lt;/A&gt;. If something does not work properly after updates, see &lt;A href="https://aka.ms/ExchangeFAQ" target="_blank" rel="noopener"&gt;Repair failed installations of Exchange Cumulative and Security updates&lt;/A&gt;. Also please see &lt;A href="https://support.microsoft.com/topic/file-version-error-when-you-try-to-install-exchange-server-november-2024-su-a650da30-f8fb-469d-a449-47396cab0a15" target="_blank" rel="noopener"&gt;File version error when you try to install Exchange Server updates&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H1&gt;FAQs&lt;/H1&gt;
&lt;P&gt;&lt;STRONG&gt;When CVE-2026-42897 mitigations were released, there were several reported known issues. Are those solved in the CVE-2026-42897 fix (June 2026 SU)?&lt;BR /&gt;&lt;/STRONG&gt;Yes, when June 2026 SU is installed and mitigation is removed, known issues should be resolved too. But note that mitigations do not get removed automatically after installation of the SU (and we recommend that you keep then enabled for a little while longer).&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;If we update some of our servers but cannot update others, can servers that will not receive update stay with CVE-2026-42897 mitigations? Is it OK to have some servers updated and some still using mitigations?&lt;/STRONG&gt;&lt;BR /&gt;You can continue using mitigations on any servers that you cannot update to June 2026 SU (or newer). But note that known issues from mitigations will continue to apply to those servers. Additionally, after applying this update, Office Online Server (OOS) integration with Exchange Server might not function as expected until all Exchange servers in the organization have been updated.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;We updated our servers to June 2026 (or newer) update, but we still have trouble with known issues caused by mitigations. Why is this?&lt;/STRONG&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;Installing the June 2026 (or newer) update does not automatically remove mitigations. Please see the post above. Currently, we recommend that mitigations stay in place but they can be removed as per the above.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Our organization is in Hybrid mode with Exchange Online. Do we need to do anything?&lt;/STRONG&gt;&lt;BR /&gt;Exchange Online is already protected, but this SU needs to be installed on your Exchange servers, even if they are used only for management purposes. If you change the auth certificate after installing an SU, you should re-run the Hybrid Configuration Wizard.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;The last SU/HU we installed is a few months old. Do we need to install all SUs in order to install the latest one?&lt;/STRONG&gt;&lt;BR /&gt;SUs are cumulative. If you are running a CU supported by the SU, you do not need to install all SUs or HUs in sequential order; simply install the latest SU. Please see&amp;nbsp;&lt;A href="https://techcommunity.microsoft.com/t5/exchange-team-blog/why-exchange-server-updates-matter/ba-p/2280770" target="_blank" rel="noopener"&gt;this blog post&lt;/A&gt;&amp;nbsp;for more information.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Do we need to install SUs on all Exchange Servers within our organization? What about ‘Management Tools only’&amp;nbsp;machines?&lt;/STRONG&gt;&lt;BR /&gt;Our recommendation is to install SUs on&amp;nbsp;&lt;U&gt;all&lt;/U&gt;&amp;nbsp;Exchange Servers and all servers and workstations running the Exchange Management Tools to ensure compatibility between management tools clients and servers. If you are trying to update the Exchange Management Tools in the environment with no running Exchange servers, please see&amp;nbsp;&lt;A href="https://learn.microsoft.com/exchange/manage-hybrid-exchange-recipients-with-management-tools#update-the-exchange-server-management-tools-only-role-with-no-running-exchange-server-to-a-newer-cumulative-or-security-update" target="_blank" rel="noopener"&gt;this&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Our organization does not have the Exchange 2016 and 2019 Period 2 ESU. How can we get current Exchange 2016 or 2019 updates?&lt;/STRONG&gt;&lt;BR /&gt;Since Exchange 2016 and 2019 are now &lt;A href="https://techcommunity.microsoft.com/blog/exchange/support-for-exchange-server-2016-and-exchange-server-2019-ends-today/4461192" target="_blank" rel="noopener"&gt;out of support&lt;/A&gt;, only customers who have enrolled into the &lt;A href="https://techcommunity.microsoft.com/blog/exchange/announcing-period-2-exchange-20162019-extended-security-update-esu-program/4511603" target="_blank" rel="noopener"&gt;Period 2 ESU program&lt;/A&gt; (which is valid between May and October 2026) can obtain Exchange 2016 or 2019 updates released after May 2026. For all other customers still running Exchange 2016 or 2019, we recommend that you &lt;A href="https://techcommunity.microsoft.com/blog/exchange/upgrading-your-organization-from-current-versions-to-exchange-server-se/4241305" target="_blank" rel="noopener"&gt;upgrade your organization to Exchange SE&lt;/A&gt; as soon as possible.&lt;/P&gt;
&lt;P style="background: #F0F0F0; padding: .5em; margin: 1em 0 1em 0;"&gt;Documentation may not be fully available at the time this post is published.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Significant updates to this post:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;7/14/2026: Added a link to &lt;A href="https://techcommunity.microsoft.com/blog/exchange/released-july-2026-exchange-server-security-updates/4534146" target="_blank"&gt;Released: July 2026 Exchange Server Security Updates | Microsoft Community Hub&lt;/A&gt;. When installed, remove the CVE-2026-42897 mitigation to address known issues&lt;/LI&gt;
&lt;LI&gt;7/13/2026: Added a Known issues section&lt;/LI&gt;
&lt;LI&gt;6/15/2026: Clarification of mitigation blocking&lt;/LI&gt;
&lt;LI&gt;6/11/2026: Removed the banner with documentation publishing issues (now resolved)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-12"&gt;The Exchange Server Team&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2026 17:23:34 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/exchange-team-blog/released-june-2026-exchange-server-security-updates/ba-p/4524491</guid>
      <dc:creator>The_Exchange_Team</dc:creator>
      <dc:date>2026-07-14T17:23:34Z</dc:date>
    </item>
    <item>
      <title>How to determine which Resource Mailboxes are being actively used</title>
      <link>https://techcommunity.microsoft.com/t5/exchange-team-blog/how-to-determine-which-resource-mailboxes-are-being-actively/ba-p/4521577</link>
      <description>&lt;P&gt;Today we wanted to take a few minutes to discuss a topic that has come up several times. Consider the scenario where your organization has created Resource mailboxes, and you want to know which ones are actually being used. Seems like a fair request.&lt;/P&gt;
&lt;P&gt;This would include Room and Equipment mailboxes as well as Workspaces. Unfortunately, there are no native reports (at the time of this writing) that include details on Resource mailbox utilization. We are going to provide a few options you can use to find this information out, and you can choose which one works for you.&lt;/P&gt;
&lt;H3&gt;Option 1: Use Get-CalendarViewDiagnostics&lt;/H3&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/troubleshoot/exchange/calendars/cdl/get-meeting-id#use-exchange-online-powershell" target="_blank" rel="noopener"&gt;Get the ID of a meeting - Exchange | Microsoft Learn&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;This will check the calendar of the specified mailbox and will provide the output of all meetings on the calendar during the specified time window.&lt;/P&gt;
&lt;P&gt;The following example will provide a list of meetings on the calendar going back 6 months in the past and 6 months in the future:&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;Get-CalendarViewDiagnostics resource@contoso.com -WindowStartUtc (Get-Date).AddMonths(-6) -WindowEndUtc (Get-Date).AddMonths(6)&lt;/LI-CODE&gt;
&lt;P&gt;This returns data quickly and only targets the calendar. The possible downside of this approach is that the meeting subject is not a property that is exposed. But if you are only looking to see which rooms have meetings scheduled, or get an overall count, this should work great for you.&lt;/P&gt;
&lt;P&gt;The upside to this approach is that Exchange Online PowerShell has rich filtering capabilities, so for example you could easily target your command to all Room mailboxes or all Equipment mailboxes.&lt;/P&gt;
&lt;P&gt;Example:&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;$roommailboxes = Get-Mailbox -ResultSize Unlimited -RecipientTypeDetails RoomMailbox
$roommailboxes | ForEach { Write-Host “Processing Mailbox $($_.Displayname)” ; Get-CalendarViewDiagnostics $_ -WindowStartUtc (Get-Date).AddMonths(-6) -WindowEndUtc (Get-Date).AddMonths(6) }&lt;/LI-CODE&gt;
&lt;H3&gt;Option 2: Use Graph to get the details of calendar events.&lt;/H3&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/graph/api/calendar-list-calendarview?view=graph-rest-1.0&amp;amp;tabs=powershell" target="_blank" rel="noopener"&gt;List calendarView - Microsoft Graph v1.0 | Microsoft Learn&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;On the bottom of the article, see example requests. To use this with PowerShell, you need the Microsoft.Graph.Calendar module and you need an Entra ID App registration which has the appropriate Graph permissions added.&lt;/P&gt;
&lt;P&gt;You can either use Delegated permissions or Application permissions.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Delegated permissions mean Graph API is being accessed using a user account and will prompt for sign-in information.&lt;/LI&gt;
&lt;LI&gt;Application permissions would be used for non-interactive applications/scripts where a sign-in prompt cannot be used.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Example using Application permissions:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Create Entra ID App registration&lt;/LI&gt;
&lt;LI&gt;Add Graph Application Calendars.Read API permission. This allows the application to read calendar data from all mailboxes.&lt;/LI&gt;
&lt;LI&gt;Create either a client secret or upload a certificate to be used for authentication. If you use a certificate, note that it can be a self-signed certificate.&lt;/LI&gt;
&lt;LI&gt;Launch PowerShell and import the Graph module&lt;LI-CODE lang="powershell"&gt;Import-Module Microsoft.Graph&lt;/LI-CODE&gt;&lt;/LI&gt;
&lt;LI&gt;Connect to Graph using PowerShell with a certificate&lt;LI-CODE lang="powershell"&gt;Connect-MgGraph -ClientId &amp;lt;app id=""&amp;gt; -TenantId &amp;lt;your tenant="" id=""&amp;gt; -CertificateThumbprint &amp;lt;cert thumbprint=""&amp;gt;&amp;lt;/cert&amp;gt;&amp;lt;/your&amp;gt;&amp;lt;/app&amp;gt;&lt;/LI-CODE&gt;
&lt;P&gt;or&lt;/P&gt;
&lt;P&gt;Connect to Graph using a client secret&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;Connect-MgGraph -ClientSecretCredential -TenantId &amp;lt;your tenant="" id=""&amp;gt;&amp;lt;/your&amp;gt;&lt;/LI-CODE&gt;&lt;/LI&gt;
&lt;LI&gt;Display a list of calendar items for a given time period and specify a few properties to show, such as the Organizer, Subject and Start/End time. We will use the same example as with Get-CalendarViewDiagnostics, going back 6 months in the past and 6 months in the future.&lt;LI-CODE lang="powershell"&gt;Get-MgUserCalendarView -UserId resource@contoso.com -StartDateTime (Get-Date).AddMonths(-6) -EndDateTime (Get-Date).AddMonths(6) | select @{n='Organizer';e={$_.Organizer.EmailAddress.Name}}, subject, @{n='StartTime';e={$_.Start.DateTime}},@{n='EndTime';e={$_.End.DateTime}}&lt;/LI-CODE&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Graph does have filtering capabilities, though for me it isn’t quite as easy as filtering in Exchange Online PowerShell. If you can connect to both Exchange Online PowerShell and Graph PowerShell in the same session, you could combine the two and run your command against the list of mailboxes in your variable.&lt;/P&gt;
&lt;P&gt;Example:&lt;/P&gt;
&lt;P&gt;Get the list of mailboxes from Exchange Online PowerShell:&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;$roommailboxes = Get-Mailbox -ResultSize Unlimited -RecipientTypeDetails RoomMailbox&lt;/LI-CODE&gt;
&lt;P&gt;Then use Graph PowerShell to get the Calendar events:&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;$roommailboxes | foreach {Write-Host "Processing Mailbox $($_.DisplayName)"; Get-MgUserCalendarView -UserId $_.PrimarySmtpAddress -StartDateTime (Get-Date).AddMonths(-6) -EndDateTime (Get-Date).AddMonths(6) | select @{n='Organizer';e={$_.Organizer.EmailAddress.Name}}, subject, @{n='StartTime';e={$_.Start.DateTime}},@{n='EndTime';e={$_.End.DateTime}}}&lt;/LI-CODE&gt;
&lt;P&gt;Note that there are additional properties available in addition to what was provided in the example above. You would need to determine which ones you want to show. Some of them (like Organizer and Start/End) are Type properties, so you must build an expression to handle them like we did above. Graph is also exposed to many other languages as well (HTTP, C#, Java, etc.)&lt;/P&gt;
&lt;P&gt;Using the Graph solution, it is also possible to restrict access to only certain mailboxes (such as only Resource mailboxes).&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/exchange/permissions-exo/application-rbac" target="_blank" rel="noopener"&gt;Role Based Access Control for Applications in Exchange Online | Microsoft Learn&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;This would allow you to control which mailboxes the Entra ID app could pull calendar details from.&lt;/P&gt;
&lt;P&gt;It involves configuring a management scope that defines the list of mailboxes (via a recipient filter). Once that is done, the Graph permissions in Entra ID needs to be removed, and they can then be granted in Exchange Online via RBAC (New-ManagementRoleAssignment).&lt;/P&gt;
&lt;H3&gt;Option 3: Use Get-MailboxFolderStatistics&lt;/H3&gt;
&lt;P&gt;For a very simplistic approach to checking resource mailbox usage, Get-MailboxFolderStatistics might provide what you need. Using the IncludeOldestAndNewestItems along with the FolderScope allows you to target the Calendar folder.&lt;/P&gt;
&lt;P&gt;Example:&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;Get-MailboxFolderStatistics resource@contoso.com -IncludeOldestAndNewestItems -FolderScope Calendar&lt;/LI-CODE&gt;
&lt;P&gt;Similar to Get-CalendarViewDiagnostics, you have the ability to run in bulk against multiple recipients.&lt;/P&gt;
&lt;P&gt;Example:&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;$roommailboxes | Foreach { Get-MailboxFolderStatistics $_ -IncludeOldestAndNewestItems -FolderScope Calendar}&lt;/LI-CODE&gt;
&lt;H3&gt;&lt;EM&gt;Do&amp;nbsp;not&lt;/EM&gt; use Get-CalendarDiagnosticObjects for this purpose!&lt;/H3&gt;
&lt;P&gt;One last method that we’ve seen customers try use is using Calendar Diagnostic Logs with the &lt;EM&gt;Get-CalendarDiagnosticObjects&lt;/EM&gt; cmdlet. &lt;EM&gt;Please DON’T use this method&lt;/EM&gt;.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/troubleshoot/exchange/calendars/cdl/get-calendar-diagnostic-logs" target="_blank" rel="noopener"&gt;Get Calendar diagnostic logs for Exchange Online mailboxes - Exchange | Microsoft Learn&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;While it technically will work to pull meeting details, it really was not designed for bulk gathering of calendar events. Instead, it was designed to help troubleshoot problems with individual meetings. Calendar Diagnostic Log data includes not only data from the Calendar, but also all other folders where calendar-related information can be stored, including the Inbox, Sent Items, Deleted Items and Recoverable Items folders such as Calendar Logging. Querying even for a single meeting can sometimes produce in excess of 1000 logs. As such, running this in bulk for lots of meetings against a mailbox may fail, might timeout or produce errors. If you are using this method and reach out to Support because you have issues (which is very likely), we will direct you to one of the other options.&lt;/P&gt;
&lt;P&gt;In summary, although there are no native reports available to check on which Resource Mailboxes are being used, there are several options available. If you are already connected to Exchange Online PowerShell, using Get-CalendarViewDiagnostics may be the simplest option for you. If you need more properties than what is exposed with Get-CalendarViewDiagnostics or want to be able to use a custom application that uses a different language, we recommend the Graph approach.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-12"&gt;Ben Winzenz&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jun 2026 13:57:46 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/exchange-team-blog/how-to-determine-which-resource-mailboxes-are-being-actively/ba-p/4521577</guid>
      <dc:creator>The_Exchange_Team</dc:creator>
      <dc:date>2026-06-26T13:57:46Z</dc:date>
    </item>
    <item>
      <title>Replacing IIS SMTP virtual server with Exchange Edge Transport</title>
      <link>https://techcommunity.microsoft.com/t5/exchange-team-blog/replacing-iis-smtp-virtual-server-with-exchange-edge-transport/ba-p/4521241</link>
      <description>&lt;P&gt;Years go by and we &lt;EM&gt;continue&lt;/EM&gt; to see customers still relying on the IIS 6.0 SMTP virtual server feature, which has been out of support for a looong time. To give you an idea just how old this component is, the &lt;A href="https://learn.microsoft.com/iis/application-frameworks/install-and-configure-php-on-iis/configure-smtp-e-mail-in-iis-7-and-above" target="_blank" rel="noopener"&gt;built-in IIS SMTP virtual server stack was tied to Windows Server 2003.&lt;/A&gt; This blog post aims to present practical options to help you retire IIS SMTP and replace it with supported Microsoft solutions (because IIS SMTP virtual server is long unsupported).&lt;/P&gt;
&lt;P&gt;Historically, we have encouraged customers to retain their last Exchange on‑premises server in &lt;A href="https://learn.microsoft.com/exchange/decommission-on-premises-exchange" target="_blank" rel="noopener"&gt;certain scenarios&lt;/A&gt;. One of the most common scenarios is on‑premises applications still depend on Exchange for email relay, even after all mailboxes have been migrated to Exchange Online.&lt;/P&gt;
&lt;P&gt;Then there are also cloud‑only Exchange Online customers who have already decommissioned their last on‑premises Exchange server (or never had one at all) and, for various reasons, are unable to configure their applications, Fax and printers to relay email directly through Exchange Online. When this scenario applies, the most straightforward and supported way to eliminate the use of IIS SMTP is to replace it with a &lt;STRONG&gt;standalone Exchange Edge Transport Server&lt;/STRONG&gt;. This also helps with centralized administration of one or few Edge servers instead of several applications and devices individually.&lt;/P&gt;
&lt;P&gt;You might not know this, but running a standalone Exchange Edge Transport server can be done with minimal overhead.&lt;/P&gt;
&lt;P&gt;It’s important to clarify what &lt;EM&gt;“standalone”&lt;/EM&gt; means in this context. A standalone Edge Transport server is &lt;STRONG&gt;not subscribed to an Active Directory site&lt;/STRONG&gt;. Whether or not the server is domain‑joined is irrelevant here; what truly matters is that the Edge Transport server is not Edge‑subscribed to Active Directory. In this configuration, Active Directory is effectively unaware of this Exchange server’s existence.&lt;/P&gt;
&lt;P&gt;Why does this matter? Because subscribing an Edge Transport server to an AD site introduces additional complexity such as EdgeSync, dedicated certificates for Direct Trust, and extra operational considerations. &lt;U&gt;The goal of this blog post is to provide a simple, low‑effort, and supported solution that allows you to finally retire use of legacy IIS 6.0 SMTP server without introducing unnecessary complexity into your environment&lt;/U&gt;.&lt;/P&gt;
&lt;P&gt;Let’s see the following flowchart to understand the big picture of options you have:&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;¹ It is important to consider if the application and devices send email to only Exchange online mailbox or also send to external domains. Based on the requirement, you will need to evaluate your options mentioned in this &lt;A href="https://learn.microsoft.com/exchange/mail-flow-best-practices/how-to-set-up-a-multifunction-device-or-application-to-send-email-using-microsoft-365-or-office-365" target="_blank" rel="noopener"&gt;article&lt;/A&gt;. If you want to send emails to external domains which essentially is relaying through Exchange online, you can:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Configure a&amp;nbsp;&lt;A href="https://learn.microsoft.com/exchange/mail-flow-best-practices/how-to-set-up-a-multifunction-device-or-application-to-send-email-using-microsoft-365-or-office-365#configure-a-tls-certificate-based-connector-for-smtp-relay" target="_blank" rel="noopener"&gt;TLS certificate-based connector for SMTP relay&lt;/A&gt; - this is a secure way to relay email. You need a certificate where the Subject or Subject Alternate Name (SAN) fields contain an &lt;A href="https://learn.microsoft.com/exchange/mail-flow-best-practices/manage-accepted-domains/manage-accepted-domains" target="_blank" rel="noopener"&gt;accepted domain&lt;/A&gt; in Microsoft 365.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Or you can&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Configure an&amp;nbsp;&lt;A href="https://learn.microsoft.com/exchange/mail-flow-best-practices/how-to-set-up-a-multifunction-device-or-application-to-send-email-using-microsoft-365-or-office-365#configure-an-ip-address-based-connector-for-smtp-relay" target="_blank" rel="noopener"&gt;IP address-based connector for SMTP relay&lt;/A&gt; - this is a less secure way to relay and is not recommended. With this method, the sender domain mentioned in the MAIL FROM must match one of the accepted domains of the tenant.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Whether you use Certificate based or IP Based connector, make sure you meet the requirements mentioned in this&amp;nbsp;&lt;A href="https://learn.microsoft.com/troubleshoot/exchange/email-delivery/office-365-notice" target="_blank" rel="noopener"&gt;article&lt;/A&gt;.&lt;/P&gt;
&lt;H5&gt;Is it feasible to redirect all on-premises applications to Exchange Online?&lt;/H5&gt;
&lt;P&gt;There may be multiple blockers, such as:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Applications that are not allowed to perform outbound external connectivity&lt;/LI&gt;
&lt;LI&gt;Legacy applications with unknown ownership or configuration&lt;/LI&gt;
&lt;LI&gt;Limited ability to update or reconfigure existing applications&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;There are several challenges to send or relay email directly from Application and devices. Applications and devices may not support TLS/STARTTLS, and managing certificates across multiple endpoints – such as printers in branch offices – can introduce significant operational complexity and potential security risks.&lt;/P&gt;
&lt;P&gt;A more suitable solution in this case is to deploy a standalone Edge Transport server. This allows you to centralize SMTP relay functionality and securely send messages to Exchange Online or external domains without requiring individual devices or applications to meet strict TLS and certificate requirements.&amp;nbsp;&lt;/P&gt;
&lt;H5&gt;What type of authentication is used by these applications?&lt;/H5&gt;
&lt;P&gt;For example, Basic Authentication or NTLM. If either is in use:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/Exchange/updated-exchange-online-smtp-auth-basic-authentication-deprecation-timeline/4489835" target="_blank" rel="noopener"&gt;SMTP Basic Authentication is being deprecated in Exchange Online&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;NTLM is not supported with Exchange Online for SMTP scenarios&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;As a result, reliance on these authentication methods may prevent Exchange Online use.&lt;/P&gt;
&lt;H3&gt;IIS 6.0 SMTP Assessment&lt;/H3&gt;
&lt;P&gt;Once you decide to replace your IIS SMTP server, one of the first and most critical steps is to perform a thorough assessment of its current usage.&lt;/P&gt;
&lt;P&gt;If logging is not already enabled, ensure it is configured by navigating to:&lt;BR /&gt;&lt;STRONG&gt;IIS → SMTP Virtual Server → Properties → Enable Logging → Properties → Advanced&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;From there, select all relevant extended logging fields that will help you identify which applications and systems are relying on the IIS SMTP server.&lt;/P&gt;
&lt;P&gt;It is recommended to allow logging to run for a sufficient period to capture a representative volume of data. This ensures that intermittent or less frequently used applications are also identified.&lt;/P&gt;
&lt;P&gt;Additional aspects that should be assessed include:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Access tab → Authentication&lt;/STRONG&gt;&lt;BR /&gt;Verify which authentication methods are enabled, such as:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Anonymous access&lt;/LI&gt;
&lt;LI&gt;Basic Authentication&lt;/LI&gt;
&lt;LI&gt;Integrated Windows Authentication&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Access tab → Relay Restrictions&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Confirm whether relay access is restricted to a defined list of IP addresses and review the scope of those restrictions.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Delivery tab → Advanced&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Determine how outbound email is being routed:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Whether the server uses a &lt;STRONG&gt;smart host&lt;/STRONG&gt; or performs &lt;STRONG&gt;direct DNS lookups&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If a smart host is configured:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Go back to &lt;STRONG&gt;Access tab → Outbound Security&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Verify whether authentication is required and which method is being used to connect to the smart host&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;To map these configurations to Exchange Edge Transport, keep the following in mind:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Settings configured under the &lt;STRONG&gt;“Access” &lt;/STRONG&gt;tab in IIS SMTP will typically correspond to the &lt;STRONG&gt;Receive Connector&lt;/STRONG&gt; on the Edge Transport server.&lt;/LI&gt;
&lt;LI&gt;Settings configured under the &lt;STRONG&gt;“Delivery” &lt;/STRONG&gt;tab will map to the &lt;STRONG&gt;Send Connector&lt;/STRONG&gt; on the Edge Transport server.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Once IIS SMTP logging has been enabled and sufficient data has been collected, the next step is to analyze the logs to identify key usage patterns, such as:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Source IP addresses of applications relying via the IIS SMTP server&lt;/LI&gt;
&lt;LI&gt;Sender SMTP addresses&lt;/LI&gt;
&lt;LI&gt;Recipient SMTP addresses&lt;/LI&gt;
&lt;LI&gt;Email volume per application and per day&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;IIS SMTP logs are not particularly user-friendly for analysis, especially at scale. As a result, you have few options to process and extract meaningful insights from this data:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Develop your own SQL query using &lt;A href="https://www.microsoft.com/en-us/download/details.aspx?id=24659" target="_blank" rel="noopener"&gt;Log Parser&lt;/A&gt; and &lt;A href="https://techcommunity.microsoft.com/blog/exchange/log-parser-studio-2-0-is-now-available/593266" target="_blank" rel="noopener"&gt;Log Parser Studio&lt;/A&gt; &lt;EM&gt;or&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;Share your IIS SMTP logs with Copilot and ask it to parse according to your needs&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Another important aspect to assess is how applications are configured to connect to the IIS SMTP server:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Do applications reference the IIS SMTP server via a hard-coded IP address, or via a DNS alias? The alias could be either a &lt;STRONG&gt;CNAME&lt;/STRONG&gt; or a &lt;STRONG&gt;host (A) &lt;/STRONG&gt;record.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If applications are using a DNS alias, the transition to Exchange Edge Transport is typically straightforward. In this case, you can redirect mail flow by simply updating the IP address associated with the alias in DNS. However, if applications are configured with a hard-coded IP address, the transition becomes more complex. In this scenario, you have two main options:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Update each application individually: Replace the IIS SMTP server IP with the Exchange Edge Transport IP. This is the cleanest approach; however, it is often the most time-consuming and operationally challenging.&lt;/LI&gt;
&lt;LI&gt;Reuse the existing IIS SMTP IP address: Assign the same IP address to the Exchange Edge Transport server as a secondary IP. While Microsoft generally discourages IP reuse in Exchange environments, this guidance primarily applies to AD-integrated Exchange roles. In this case, since the Edge Transport server is standalone and does not store objects on Active Directory, IP reuse can be acceptable if carefully planned and executed.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Once all relevant IIS SMTP data has been collected and analyzed, you can proceed with the Exchange Edge Transport deployment.&lt;/P&gt;
&lt;P&gt;If additional details are required for the assessment phase, refer to the FAQ section, where common caveats and IIS SMTP-specific considerations are covered.&lt;/P&gt;
&lt;H3&gt;Exchange Edge Transport considerations&lt;/H3&gt;
&lt;P&gt;Assuming you have decided to decommission IIS SMTP and use the Exchange Edge Transport role for email relay, the next key decision is whether the Edge Transport server should be deployed on a domain-joined machine.&lt;/P&gt;
&lt;P&gt;Microsoft generally recommends deploying the Edge Transport role on a non-domain-joined server. However, this guidance applies primarily to traditional Exchange environments where Edge Transport is installed in the perimeter network and is subscribed to an Active Directory site that includes Mailbox servers.&lt;/P&gt;
&lt;P&gt;In a scenario where no Exchange Mailbox role is present, the decision should be driven by your authentication, security, and management requirements. To help guide this choice, consider the following questions:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Do you need to enforce Basic Authentication or Integrated Windows Authentication using domain service accounts? If yes, deploying the Edge Transport on a domain-joined server is needed.&lt;/LI&gt;
&lt;LI&gt;Can you rely on local accounts for authentication (e.g., Basic Authentication without domain dependencies)? If yes, a non-domain-joined server is sufficient.&lt;/LI&gt;
&lt;LI&gt;Do you need to apply Group Policy Objects (GPOs) or centralized security baselines? If yes, consider a domain-joined deployment to enable centralized management and compliance enforcement.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Note that whether you install Edge on a domain joined machine or not, because you are not creating a subscription to Active Directory, installation of Edge will not require extending the schema and preparing AD for Exchange Server.&lt;/P&gt;
&lt;H3&gt;Requirements&lt;/H3&gt;
&lt;P&gt;Once the decision has been made, proceed with the installation of the Exchange Edge Transport role on an up-to-date server. Follow the &lt;A href="https://learn.microsoft.com/exchange/plan-and-deploy/prerequisites#exchange-server-edge-transport-server-role" target="_blank" rel="noopener"&gt;official prerequisites documentation&lt;/A&gt; to prepare the environment. Note that only a limited set of components is required:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;.NET Framework&lt;/LI&gt;
&lt;LI&gt;Visual C++ 2012 Redistributable&lt;/LI&gt;
&lt;LI&gt;Active Directory Lightweight Directory Services (AD LDS)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;No additional Exchange roles or dependencies are needed.&lt;/P&gt;
&lt;P&gt;Network and security:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;TCP port 25 must be permitted between the Edge server and applications or devices that will use Exchange Edge Transport for email relay. Typically, it should &lt;EM&gt;not&lt;/EM&gt; be exposed to internet assuming that these applications or devices are placed within the internal network.&lt;/LI&gt;
&lt;LI&gt;Outbound TCP port 25 must be permitted between the Edge server and external networks to enable SMTP mail flow.&lt;/LI&gt;
&lt;LI&gt;Ensure the server is properly hardened, following standard security best practices.&lt;/LI&gt;
&lt;LI&gt;Refer to this &lt;A href="https://learn.microsoft.com/exchange/antispam-and-antimalware/windows-antivirus-software" target="_blank" rel="noopener"&gt;article&lt;/A&gt; for Antivirus running on Exchange Server. The “Servers” column can be used to distinguish the necessary exclusions related to Edge Transport.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If high availability is required, consider deploying two standalone Edge Transport servers behind a load balancer, or DNS round-robin. This approach helps minimize service disruption during maintenance activities such as Windows or Exchange patching.&lt;/P&gt;
&lt;H3&gt;Accepted domain&lt;/H3&gt;
&lt;P&gt;Since the installation of the Exchange Edge Transport role is relatively straightforward, it will not be covered in this article. At this stage, we assume that the Edge Transport server has already been successfully deployed and is fully operational.&lt;/P&gt;
&lt;P&gt;The first step is to configure the Accepted Domains on the Edge Transport server. You can refer to the &lt;A href="https://learn.microsoft.com/powershell/module/exchangepowershell/new-accepteddomain?view=exchange-ps" target="_blank" rel="noopener"&gt;relevant documentation&lt;/A&gt; for the exact command syntax and parameters required.&lt;/P&gt;
&lt;P&gt;It is important to note that a standalone Edge Transport role does &lt;EM&gt;not&lt;/EM&gt; have &lt;EM&gt;Resolve&lt;/EM&gt; engines (e.g., no recipient or sender validation against Active Directory or ADAM). Because of this behavior, the distinction between Authoritative and Internal Relay domains does not have a functional impact on the Edge Transport server in this scenario.&lt;/P&gt;
&lt;H3&gt;Receive connector&lt;/H3&gt;
&lt;P&gt;Once the Edge Transport is installed, it will automatically create a Receive Connector as described in this &lt;A href="https://learn.microsoft.com/exchange/mail-flow/connectors/receive-connectors#default-receive-connectors-in-the-transport-service-on-edge-transport-servers" target="_blank" rel="noopener"&gt;article&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;To customize the Receive connector to satisfy your needs, you will need to understand how the IIS SMTP was used by your application for email relay. Assuming that your only Accepted Domain is contoso.com:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;If your applications are sending unauthenticated to contoso.com recipients (&lt;A href="mailto:app1@contoso.com" target="_blank" rel="noopener"&gt;app1@contoso.com&lt;/A&gt; sends to &lt;A href="mailto:john@contoso.com" target="_blank" rel="noopener"&gt;john@contoso.com&lt;/A&gt;): Use the default connector, no need to create a new one.&lt;/LI&gt;
&lt;LI&gt;If your applications are sending authenticated emails through Basic Auth or Integrated Windows using contoso.com as sender SMTP address to any recipient (&lt;A href="mailto:app1@contoso.com" target="_blank" rel="noopener"&gt;app1@contoso.com&lt;/A&gt; sends to &lt;A href="mailto:john@contoso.com" target="_blank" rel="noopener"&gt;john@contoso.com&lt;/A&gt; and &lt;A href="mailto:adele@fabrikam.com" target="_blank" rel="noopener"&gt;adele@fabrikam.com&lt;/A&gt;):&lt;/LI&gt;
&lt;/UL&gt;
&lt;OL&gt;
&lt;LI&gt;Create a new Receive Connector with &lt;STRONG&gt;ExchangeUsers &lt;/STRONG&gt;Permission Group, assign the Authentication mechanism as &lt;STRONG&gt;BasicAuth&lt;/STRONG&gt; and/or &lt;STRONG&gt;Integrated &lt;/STRONG&gt;and add the IP or range of your applications to &lt;STRONG&gt;RemoteIPRanges: &lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;PRE&gt;New-ReceiveConnector -Name "BasicAuth" -AuthMechanism BasicAuth -RemoteIPRanges "192.168.0.1" -PermissionGroups ExchangeUsers -Custom -Bindings 0.0.0.0:25&lt;/PRE&gt;
&lt;OL start="2"&gt;
&lt;LI&gt;And add the permission &lt;STRONG&gt;ms-Exch-SMTP-Accept-Authoritative-Domain-Sender &lt;/STRONG&gt;to the connector. As mentioned before, since Edge Transport doesn’t have Resolve engine, it cannot validate the primary SMTP address of the authenticated user, otherwise you will get the “&lt;EM&gt;550 5.7.60 SMTP; Client does not have permissions to send as this sender” &lt;/EM&gt;error.&lt;/LI&gt;
&lt;/OL&gt;
&lt;PRE&gt;Get-ReceiveConnector BasicAuth | Add-ADPermission -User "NT AUTHORITY\Authenticated Users" -ExtendedRights "ms-Exch-SMTP-Accept-Authoritative-Domain-Sender"&lt;/PRE&gt;
&lt;UL&gt;
&lt;LI&gt;If your applications require an &lt;EM&gt;open relay&lt;/EM&gt;, although not recommended, you can follow the steps described in this &lt;A href="https://learn.microsoft.com/exchange/mail-flow/connectors/allow-anonymous-relay" target="_blank" rel="noopener"&gt;article&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Send connector&lt;/H3&gt;
&lt;P&gt;In a fresh Exchange Edge Transport installation, no Send connector is created by default. Therefore, you will need to configure it from scratch.&lt;/P&gt;
&lt;P&gt;As highlighted earlier, it is essential to first understand how your existing IIS SMTP server handles outbound relay. This includes determining whether it uses:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Direct DNS resolution, or a smarthost (and any associated Basic authentication)&lt;/LI&gt;
&lt;LI&gt;Whether you want to have different routes per domain&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This information will directly influence the configuration of your Send connector on the Edge Transport server. You can refer to the relevant &lt;A href="https://learn.microsoft.com/powershell/module/exchangepowershell/new-sendconnector?view=exchange-ps" target="_blank" rel="noopener"&gt;documentation&lt;/A&gt; for detailed guidance on the required commands and parameters to properly create and configure the Send Connector.&lt;/P&gt;
&lt;H3&gt;Switch the mail flow&lt;/H3&gt;
&lt;P&gt;At this stage, the IIS SMTP assessment should already be complete, and you should understand how applications connect to it – a DNS record or a hard-coded IP address.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;If a DNS alias is used&lt;/STRONG&gt; (e.g., CNAME or A record):&lt;BR /&gt;The transition is typically straightforward. You can redirect mail flow by updating the DNS record to point to the Exchange Edge Transport server.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;If applications use a hard-coded IP address:&lt;/STRONG&gt;&lt;BR /&gt;Consider reusing the existing IIS SMTP IP address. The process is relatively simple:
&lt;UL&gt;
&lt;LI&gt;Disable the network interface (NIC) on the IIS SMTP server&lt;/LI&gt;
&lt;LI&gt;Assign the IIS SMTP server IP address as a secondary IP on the Exchange Edge Transport server&lt;/LI&gt;
&lt;LI&gt;Update the existing DNS A record associated with the IIS SMTP server to point to the Exchange Edge Transport server&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;As a best practice, always validate mail flow with a subset of applications before performing the full cutover. This helps identify potential issues early and ensures a smooth transition.&lt;/P&gt;
&lt;H3&gt;(Optional) Setting Exchange Online as a smarthost&lt;/H3&gt;
&lt;P&gt;If you have Exchange Online tenant, you can use your standalone Edge Transport to relay emails through Exchange Online by configuring your tenant MX as a smarthost in the Edge’s Send connector. Although not required, we encourage you to bind a certificate with the same domain name that you have in your Exchange Online as Accepted Domain. This would ensure a proper &lt;A href="https://techcommunity.microsoft.com/blog/exchange/office-365-message-attribution/749143" target="_blank" rel="noopener"&gt;message attribution&lt;/A&gt; process and your emails coming from Edge Transport will be marked as Originating.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;First, you need to figure out what is the MX record of your tenant, please follow this &lt;A href="https://learn.microsoft.com/exchange/mail-flow-best-practices/how-to-set-up-a-multifunction-device-or-application-to-send-email-using-microsoft-365-or-office-365#appendix-find-the-mx-record-for-the-chosen-accepted-domain-in-microsoft-365-or-office-365" target="_blank" rel="noopener"&gt;appendix&lt;/A&gt; to get this information.&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/powershell/module/exchangepowershell/set-sendconnector?view=exchange-ps#-smarthosts" target="_blank" rel="noopener"&gt;Add the value to your Send connector as a smarthost&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/powershell/module/exchangepowershell/enable-exchangecertificate?view=exchange-ps" target="_blank" rel="noopener"&gt;Import the certificate to the Personal computer container and assign the SMTP service to it&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Bind the certificate to the Send connector&lt;/LI&gt;
&lt;/UL&gt;
&lt;PRE&gt;$Cert = Get-ExchangeCertificate -Thumbprint "&amp;lt;new certificate thumbprint&amp;gt;"&lt;BR /&gt;&lt;BR /&gt;$TLSCertificateName = "&amp;lt;i&amp;gt;$($Cert.Issuer)&amp;lt;s&amp;gt;$($Cert.Subject)"&lt;BR /&gt;&lt;BR /&gt;Set-SendConnector -Identity "Send Connector Identity" -TlsCertificateName $TLSCertificateName&lt;/PRE&gt;
&lt;UL&gt;
&lt;LI&gt;Set the following properties on the connector:&lt;/LI&gt;
&lt;/UL&gt;
&lt;PRE&gt;Set-SendConnector -Identity "Send Connector Identity" -RequireTLS $True -TlsAuthLevel DomainValidation -TlsDomain mail.protection.outlook.com&lt;/PRE&gt;
&lt;UL&gt;
&lt;LI&gt;Now we need to create the Inbound connector in Exchange Online to attribute these messages coming from the Exchange Edge Transport:&lt;/LI&gt;
&lt;/UL&gt;
&lt;PRE&gt;New-InboundConnector -Name "FromEdgeTransport" -ConnectorType OnPremises -SenderDomains * -RequireTls $True -TlsSenderCertificateName "Your Certificate CN"&lt;/PRE&gt;
&lt;P&gt;Lastly, ensure to add the EOP and your Edge Transport public IP to the SPF record in the public DNS as described &lt;A href="https://learn.microsoft.com/microsoft-365/enterprise/external-domain-name-system-records?view=o365-worldwide#external-dns-records-required-for-spf" target="_blank" rel="noopener"&gt;here&lt;/A&gt;. This is an important step to avoid either external recipients marking your emails as spoofing or the EOP itself marking emails from your Edge as spoofing. If you want to increase your security posture, you can also &lt;A href="https://learn.microsoft.com/defender-office-365/email-authentication-dkim-configure" target="_blank" rel="noopener"&gt;enable DKIM&lt;/A&gt; and create your &lt;A href="https://learn.microsoft.com/defender-office-365/email-authentication-dmarc-configure" target="_blank" rel="noopener"&gt;DMARC policy for your domains&lt;/A&gt;.&lt;/P&gt;
&lt;H3&gt;FAQ&lt;/H3&gt;
&lt;P&gt;&lt;STRONG&gt;How to figure out domain or local accounts being used on IIS SMTP to send using Basic Authentication?&lt;BR /&gt;&lt;/STRONG&gt;Unfortunately, the IIS SMTP logs will not show what account has been used to perform basic authentication when sending emails. The following XML query can be used to filter Security event viewer logs:&lt;/P&gt;
&lt;PRE&gt;&amp;lt;QueryList&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;lt;Query Id="0" Path="Security"&amp;gt;&lt;BR /&gt;&amp;nbsp; &amp;lt;Select Path="Security"&amp;gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; *[System[(EventID=4624)]]&lt;BR /&gt;&amp;nbsp; &amp;nbsp; and&lt;BR /&gt;&amp;nbsp; &amp;nbsp; *[EventData[Data[@Name='LogonType']='3']]&lt;BR /&gt;&amp;nbsp; &amp;nbsp; and&lt;BR /&gt;&amp;nbsp; &amp;nbsp; *[EventData[Data[@Name='ProcessName']='C:\Windows\System32\inetsrv\inetinfo.exe']]&lt;BR /&gt;&amp;nbsp; &amp;nbsp;&amp;lt;/Select&amp;gt;&lt;BR /&gt;&amp;nbsp; &amp;lt;/Query&amp;gt;&lt;BR /&gt;&amp;lt;/QueryList&amp;gt;&lt;/PRE&gt;
&lt;P&gt;&lt;STRONG&gt;What’s the benefit of getting rid of IIS 6.0 SMTP and moving to an Exchange Edge Transport?&lt;BR /&gt;&lt;/STRONG&gt;IIS 6.0 is no longer supported, and therefore you should not expect any security updates or assistance from Microsoft Support. From a technical perspective, the Exchange Edge Transport role provides significantly more capabilities and control over mail flow, including:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Enhanced logs such as message tracking logs and pipeline tracing&lt;/LI&gt;
&lt;LI&gt;Improved security and control mechanisms&lt;/LI&gt;
&lt;LI&gt;The ability to implement transport rules (although more limited compared to a full Exchange Mailbox role)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Overall, Exchange Edge Transport represents a more modern, secure, and manageable solution compared to legacy IIS SMTP.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Can we use Address Rewrite feature in a standalone Edge Transport?&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;Yes, but there are important caveats to consider.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Inbound Address Rewrite is supported and works as expected on a standalone Edge Transport. You can safely follow the standard procedure described in the &lt;A href="https://learn.microsoft.com/exchange/architecture/edge-transport-servers/address-rewriting-procedures" target="_blank" rel="noopener"&gt;documentation&lt;/A&gt; to implement it.&lt;/P&gt;
&lt;P&gt;The Outbound Address Rewrite has some limitations that you should be aware of. This feature depends on the &lt;STRONG&gt;Address Rewriting Outbound Agent&lt;/STRONG&gt;, which is only triggered when the MAIL FROM is treated as authenticated. Specifically, the agent relies on the presence of the header: &lt;EM&gt;X-MS-Exchange-Organization-AuthAs: Internal.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;At first glance, you might assume that using Basic Authentication or Integrated Windows Authentication would satisfy this requirement. However, this is &lt;STRONG&gt;not the case&lt;/STRONG&gt; for a standalone Edge Transport deployment. Regardless of the authentication method used when submitting messages to a standalone Edge Transport, the header &lt;EM&gt;X-MS-Exchange-Organization-AuthAs&lt;/EM&gt; is always stamped as &lt;STRONG&gt;Anonymous&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;As a result, the Outbound Address Rewrite agent is never triggered under normal conditions.&lt;/P&gt;
&lt;P&gt;The only supported workaround to force the standalone Edge Transport to treat messages as internal – and therefore enable outbound address rewriting – is to configure the receive connector with the &lt;A href="https://learn.microsoft.com/exchange/mail-flow/connectors/allow-anonymous-relay#configure-the-connections-as-externally-secured" target="_blank" rel="noopener"&gt;&lt;EM&gt;ExternalAuthoritative&lt;/EM&gt;&lt;/A&gt; authentication mechanism. This effectively promotes the &lt;EM&gt;AuthAs&lt;/EM&gt; value to &lt;STRONG&gt;Internal&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;Enabling &lt;EM&gt;ExternalAuthoritative&lt;/EM&gt; effectively turns the receive connector into an &lt;EM&gt;open relay&lt;/EM&gt;. You must therefore implement appropriate restrictions (such as IP scoping and strict access controls) to secure the connector and prevent abuse. Refer to this &lt;A href="https://techcommunity.microsoft.com/blog/exchange/why-is-my-address-rewriting-not-working-as-expected/607458" target="_blank" rel="noopener"&gt;article&lt;/A&gt; for further information.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;How does Microsoft 365 IP throttling deal with messages coming from a standalone Edge Transport?&lt;/STRONG&gt;&lt;BR /&gt;In the same way as it handles in Hybrid mail flow if you followed our recommendation stated on “Setting Exchange Online as smarthost” section. If you had a Hybrid Exchange on-premises and are moving to a standalone Edge Transport, our advice is to keep the same public IP used by your previous Exchange Server on the new Edge Transport since this IP will have a sending history and clean reputation.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Can we deploy a standalone Edge Transport as an Azure VM?&lt;/STRONG&gt;&lt;BR /&gt;You can but consider that outbound SMTP on Azure VMs is only supported if you have Enterprise Agreement or Microsoft Customer Agreement for enterprise (MCA-E) subscriptions. For more information see this &lt;A href="https://learn.microsoft.com/troubleshoot/azure/virtual-network/troubleshoot-outbound-smtp-connectivity" target="_blank" rel="noopener"&gt;article&lt;/A&gt;. Additionally, you may need to establish proper network connectivity from your applications to the Azure VM. This typically requires configuring network routing – such as Azure ExpressRoute – to enable your on-premises traffic to reach the Edge Transport VM securely and reliably.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Edge Transport is configured to use Exchange Online as smarthost but emails are being received as “AuthAs:Anonymous”. Can we change this behavior marking messages as Internal?&lt;/STRONG&gt;&lt;BR /&gt;The Edge Transport role does not perform header promotion regardless if Edge is subscribed to a Mailbox Exchange Server or standalone. It is up to the Mailbox role to promote &lt;EM&gt;Organization&lt;/EM&gt; headers to &lt;EM&gt;CrossPremises&lt;/EM&gt; and then the Edge just honors the promotion. Refer to this &lt;A href="https://techcommunity.microsoft.com/blog/exchange/demystifying-and-troubleshooting-hybrid-mail-flow-when-is-a-message-internal/1420838" target="_blank" rel="noopener"&gt;article&lt;/A&gt; to find more information about header promotion. The only way to enforce “AuthAs:Internal” on messages coming from an Edge Transport is enabling &lt;A href="https://learn.microsoft.com/powershell/module/exchangepowershell/set-inboundconnector?view=exchange-ps#-treatmessagesasinternal" target="_blank" rel="noopener"&gt;&lt;EM&gt;TreatMessagesAsInternal&lt;/EM&gt;&lt;/A&gt;&lt;EM&gt; &lt;/EM&gt;attribute on Exchange Online Inbound connector. This option works only if sender domain matches an accepted domain in Exchange Online.&lt;/P&gt;
&lt;P&gt;Thanks to Arindam Thokder for his support and review of this article.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-12"&gt;Denis Vilaça Signorelli&lt;/SPAN&gt;&lt;BR /&gt;Cloud Solution Architect&lt;/P&gt;</description>
      <pubDate>Tue, 19 May 2026 14:14:31 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/exchange-team-blog/replacing-iis-smtp-virtual-server-with-exchange-edge-transport/ba-p/4521241</guid>
      <dc:creator>The_Exchange_Team</dc:creator>
      <dc:date>2026-05-19T14:14:31Z</dc:date>
    </item>
  </channel>
</rss>

