exchange
2262 TopicsGoogle Workspace sender stuck at SCL=5 to all Microsoft-hosted recipients
Sending email from a new domain via Google Workspace. All mail to Microsoft-hosted recipients (both Outlook.com consumer accounts and Microsoft 365 Exchange Online tenants) is being routed to junk. Authentication passes perfectly on every message. This appears to be a domain reputation cold-start issue and I am looking for guidance on how to resolve it without waiting 2-4 weeks. Affected recipients are all Microsoft-hosted recipients tested (Outlook.com consumer + Microsoft 365 Exchange Online tenants). Please help me!!! Confirmed via X-MS-Exchange-Organization-SCL: 5 and delivery header dest:J;OFR:SpamFilterAuthJ;RF:JunkEmail on all test emails including ones with normal subject lines and body text. Content makes zero difference to the score. What has already been done: SPF hardened from ~all to -all DMARC upgraded from p=none to p=quarantine IP confirmed not listed on Microsoft's delist portal (sender.office.com) Domain confirmed not listed on Spamhaus DBL or SURBL Domain registered with Google Postmaster Tools JMRP enrollment attempted — not available to Google Workspace senders as SNDS requires IP ownership Outlook.com Postmaster support request submitted24Views0likes1CommentTechcommunity Follow email notification no longer working
Hello, Not sure if this is the right place to post this issue but I could not find another method to report this issue.. As an Exchange Admin in our invironment it's very usefull to stay up to date on the latest new posted in a variety of blogs on this website (Exchange Blog, M365 Blog, ...) This all went well until a few months ago where I started noticing I didn't receive any weekly updates anymore regarding new blogposts & tried to manually go check periodically, thinking it would be a temporary system. After investigation i've noticed that i'm not the only admin in our company that no longer receives these emails from mailto:email address removed for privacy reasons So I wonder if something bigger is up or if it's only my company being affected, not receiving these follow notifications anymore? Is there any other way that I should report this issue, to those managing this website so it can be investigated in detail if it's only us? Already tried to unfollow/delete follows in my profile - save - follow again, same on the respective blog pages, but this does not seem to change anything.26Views0likes2CommentsDecommission from one tenant to become separate tenant
A customer of mine has been using Office 365 A3 which was actually a tenant for their parent university. Now the child (my customer) wants to become separate entity by having their own Office 365 tenant. How can they move their mailboxes and other data from the parent company? How to route emails to the new tenant (child)? Please guide.2.6KViews1like5CommentsMoving Office 365 Mailboxes to IMAP Servers - What’s the Best Approach
I’ve recently been looking into scenarios where organizations need to move mailboxes from Microsoft 365 to IMAP based email servers, and I noticed this is still a common requirement in many migrations. In most cases, the challenge is not just moving emails, but making sure everything like folder structure, old emails, and user data stays intact without creating too much disruption for users. From what I’ve seen, doing this manually can get very complex, especially when there are multiple mailboxes or large data volumes involved. That’s where migration tools usually come into the picture. Most tools simplify things by handling: 1. Secure connection to Microsoft 365 accounts 2. Bulk mailbox migration 3. Preserving folder hierarchy 4. Reducing downtime during the move 5. Avoiding duplicate data issues One thing I’ve noticed is that running a small pilot migration first always helps. It gives a clear idea of how the actual migration will behave before moving all users. Has anyone here worked on Office 365 to IMAP migration at scale? Would be good to know what approaches or tools worked best in your case and what challenges you faced during the process.135Views0likes2CommentsI built a free, open-source M365 security assessment tool - looking for feedback
I work as an IT consultant, and a good chunk of my time is spent assessing Microsoft 365 environments for small and mid-sized businesses. Every engagement started the same way: connect to five different PowerShell modules, run dozens of commands across Entra ID, Exchange Online, Defender, SharePoint, and Teams, manually compare each setting against CIS benchmarks, then spend hours assembling everything into a report the client could actually read. The tools that automate this either cost thousands per year, require standing up Azure infrastructure just to run, or only cover one service area. I wanted something simpler: one command that connects, assesses, and produces a client-ready deliverable. So I built it. What M365 Assess does https://github.com/Daren9m/M365-Assess is a PowerShell-based security assessment tool that runs against a Microsoft 365 tenant and produces a comprehensive set of reports. Here is what you get from a single run: 57 automated security checks aligned to the CIS Microsoft 365 Foundations Benchmark v6.0.1, covering Entra ID, Exchange Online, Defender for Office 365, SharePoint Online, and Teams 12 compliance frameworks mapped simultaneously -- every finding is cross-referenced against NIST 800-53, NIST CSF 2.0, ISO 27001:2022, SOC 2, HIPAA, PCI DSS v4.0.1, CMMC 2.0, CISA SCuBA, and DISA STIG (plus CIS profiles for E3 L1/L2 and E5 L1/L2) 20+ CSV exports covering users, mailboxes, MFA status, admin roles, conditional access policies, mail flow rules, device compliance, and more A self-contained HTML report with an executive summary, severity badges, sortable tables, and a compliance overview dashboard -- no external dependencies, fully base64-encoded, just open it in any browser or email it directly The entire assessment is read-only. It never modifies tenant settings. Only Get-* cmdlets are used. A few things I'm proud of Real-time progress in the console. As the assessment runs, you see each check complete with live status indicators and timing. No staring at a blank terminal wondering if it hung. The HTML report is a single file. Logos, backgrounds, fonts -- everything is embedded. You can email the report as an attachment and it renders perfectly. It supports dark mode (auto-detects system preference), and all tables are sortable by clicking column headers. Compliance framework mapping. This was the feature that took the most work. The compliance overview shows coverage percentages across all 12 frameworks, with drill-down to individual controls. Each finding links back to its CIS control ID and maps to every applicable framework control. Pass/Fail detail tables. Each security check shows the CIS control reference, what was checked, what the expected value is, what the actual value is, and a clear Pass/Fail/Warning status. Findings include remediation descriptions to help prioritize fixes. Quick start If you want to try it out, it takes about 5 minutes to get running: # Install prerequisites (if you don't have them already) Install-Module Microsoft.Graph, ExchangeOnlineManagement -Scope CurrentUser Clone and run git clone https://github.com/Daren9m/M365-Assess.git cd M365-Assess .\Invoke-M365Assessment.ps1 The interactive wizard walks you through selecting assessment sections, entering your tenant ID, and choosing an authentication method (interactive browser login, certificate-based, or pre-existing connections). Results land in a timestamped folder with all CSVs and the HTML report. Requires PowerShell 7.x and runs on Windows (macOS and Linux are experimental -- I would love help testing those platforms). Cloud support M365 Assess works with: Commercial (global) tenants GCC, GCC High, and DoD environments If you work in government cloud, the tool handles the different endpoint URIs automatically. What is next This is actively maintained and I have a roadmap of improvements: More automated checks -- 140 CIS v6.0.1 controls are tracked in the registry, with 57 automated today. Expanding coverage is the top priority. Remediation commands -- PowerShell snippets and portal steps for each finding, so you can fix issues directly from the report. XLSX compliance matrix -- A spreadsheet export for audit teams who need to work in Excel. Standalone report regeneration -- Re-run the report from existing CSV data without re-assessing the tenant. I would love your feedback I have been building this for my own consulting work, but I think it could be useful to the broader community. If you try it, I would genuinely appreciate hearing: What checks should I prioritize next? Which security controls matter most in your environment? What compliance frameworks are most requested by your clients or auditors? How does the report land with non-technical stakeholders? Is the executive summary useful, or does it need work? macOS/Linux users -- does it run? What breaks? I have tested it on macOS, but not extensively. Bug reports, feature requests, and contributions are all welcome on GitHub. Repository: https://github.com/Daren9m/M365-Assess License: MIT (free for commercial and personal use) Runtime: PowerShell 7.x Thanks for reading. Happy to answer any questions in the comments.3.2KViews2likes2CommentsOffice 365 Mailbox Export to PST - Third Party Tools: What’s Your Experience?
Exporting Office 365 mailboxes to PST is still a common requirement in many Microsoft 365 environments, especially for backup, compliance, and migration scenarios. While Microsoft offers native options like Purview eDiscovery and Outlook export, many administrators also consider third-party tools when dealing with large mailboxes or bulk export requirements. In real-world scenarios, factors like speed, ease of use, permission handling, and consistency of exported data often influence the choice of tool. Some teams prefer native methods for compliance control, while others explore third-party solutions to simplify large-scale or repeated export tasks. For those working with Microsoft 365, what has your experience been with third-party PST export tools? Have they helped in your environment, or do you still rely mainly on Microsoft’s native options?214Views1like3Commentsmail@mydomain is causing a cert mismatch error in all browsers for Outlook.com
Hello, I have created a CNAME for our users in my domain so that they can access webmail. For example, it's called mail.mycustomdomain.com, and it is directed to Outlook.com But when I try to visit mail.mycustomdomain.com, it shows a security warning and recommends going back. I can understand because the SAN name in the certificate presented by Outlook doesn't include my CNAME. Is there anything I can do as a workaround so our users can enter the CNAME without encountering a Certificate Mismatch Error? It is causing repeated calls to the helpdesk, and we would like them to use something simple they can remember. Thanks103Views0likes3CommentsMicrosoft Wants PowerShell Developers to Change How They Download Microsoft Modules
A Microsoft blog describes some changes for PowerShell developers in terms of installing modules and the role of the Microsoft Artifact Registry (MAR). In a nutshell, Microsoft intends the MAR to be the go-to place to download first-party PowerShell modules and other artifacts. This solves the problem of potentially compromised modules found in the PowerShell Gallery, but MAR can’t work if it doesn’t contain the modules people use. https://office365itpros.com/2026/06/05/microsoft-artifact-registry/42Views0likes0Commentsneed exchange se for hybrid environment
We have a hybrid Office 365 environment with an Exchange Server 2016 that no longer performs any role. It does not host any mailboxes and is not used as an SMTP relay. We would like to keep an Exchange installation solely for administrative purposes through the GUI. Questions: 1. Can we keep Exchange Server 2016 installed? 2. If we need to install Exchange Server Subscription Edition (SE), do we need licenses for this installation, considering that all our Office 365 licenses are Business licenses? Thank you.74Views0likes1CommentOutlook Cached Mode Repeatedly Re-syncs Mailbox After Restart (Starts Again Around 3.99 GB)
Hi everyone, I’m experiencing a strange Outlook Cached Exchange Mode issue with a Microsoft 365 mailbox after a recent Windows rebuild and wanted to see if anyone has seen similar behavior. Environment: Microsoft 365 mailbox (Exchange Online) Outlook for Microsoft 365 Version 2605 Build 16.0.20026.20076 64-bit Windows 11 25H2 Fresh OS rebuild performed twice New Outlook profile created Office completely reinstalled OST recreated multiple times Issue: When Cached Exchange Mode is enabled, Outlook starts downloading/synchronizing mail normally, and the OST file continues to grow correctly. However, after every reboot or Outlook restart, Outlook again shows “Downloading…” starting from around 3.99 GB. Important observations: Online Mode works perfectly OUTLOOK.EXE closes properly after exit OST file is NOT deleted and continues growing Sync slider changes (1 month, 1 year, all mail) make no difference Disabling Outlook indexing did not help New Outlook profile did not help Reinstalling Office did not help Problem only started after OS rebuild Before rebuild, same mailbox worked normally in Cached Mode No pending office or windows update. It does not appear to actually re-download the mailbox from scratch because the OST size keeps increasing, but Outlook repeatedly processes/downloads from around the same 3.99 GB point after restart. Has anyone seen: Cached Mode replaying synchronization repeatedly after restart? Similar behavior on recent Current Channel builds? Security/EDR products interfering with OST synchronization state? Any known regressions with Outlook Version 2605 Build 16.0.20026.20076? Any suggestions or similar experiences would be appreciated.179Views0likes2Comments