The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Reduce Exchange Server exposure by first identifying which servers and services are reachable from the Internet, then restricting unnecessary access and using only interim controls that fit your topology. These measures can lower risk while you prepare, but they do not fix a vulnerability: install the applicable Microsoft Security Update (SU) and verify the result. Microsoft says on-premises environments should always be ready to take an emergency security update.
Start by identifying what is exposed
Before changing firewall, authentication, or IIS settings, establish which Exchange servers are running, how they are published, and what depends on them. An inventory helps you select the right update and avoid cutting off required mail flow or client access.
- Record each server’s Exchange version, cumulative update (CU), installed SU level, and role.
- Map Internet-published Exchange services, inbound firewall rules, reverse proxies, load balancers, and TLS termination points.
- Document hybrid publishing and dependencies such as applications, connectors, and mail-flow routes.
- Use Microsoft’s Exchange Server Health Checker to identify missing CUs or SUs and any manual actions it reports. Check the server’s lifecycle and supported update path as well; CUs, SUs, and Hotfix Updates (HUs) serve different purposes and do not have interchangeable support eligibility.
Build and support information changes over time. Check Microsoft’s current Exchange release and update guidance for the exact version and CU in your environment rather than selecting an update from an old build list.
Reduce unnecessary Internet reachability
Review which inbound connections are genuinely required by users, partners, and applications. Restrict unnecessary paths at the network or publishing layer, while preserving the services and routes your organization needs. Make changes against a documented dependency map and validate them with the teams responsible for mail flow and hybrid connectivity.
Recommended Free Tools
#1 Best Overall
Consider perimeter mail flow where it fits
An Edge Transport server can handle Internet mail flow from a perimeter network and help reduce the need to expose internal Exchange servers directly to Internet threats. This is an architectural option, not an emergency switch: deployment, redundancy, routing, and hybrid dependencies require environment-specific planning. Do not add or reconfigure the role during an incident without understanding the effect on delivery and recovery.
Use interim mitigations only when they apply
The Exchange Emergency Mitigation (EM) service can apply temporary mitigations for certain known threats. Microsoft explicitly says, “The EM service isn’t a replacement for Exchange SUs.” Treat an EM action as a temporary risk-reduction measure while you continue toward the applicable update.
Rank #2
- Confirm that the service is installed and can connect to Microsoft’s Office Config Service.
- Check the reported mitigation state and confirm that the mitigation applies to your installed Exchange build and the threat at issue.
- Review the mitigation’s scope, possible feature impact, and rollback procedure before relying on or reversing it.
When configured and supported, the EM service checks for available mitigations every hour. Microsoft says supported Exchange 2016 and Exchange 2019 installations receive the service with the September 2021 CU or later. These are service-operation details, not measures of effectiveness; confirm applicability against current Microsoft documentation and your own server state.
Check Extended Protection prerequisites before enabling it
Extended Protection (EP) can help mitigate authentication relay and man-in-the-middle attacks, but enabling it changes compatibility assumptions. Its use depends on supported Exchange builds, consistent TLS settings, and compatible clients and network paths.
- Validate the Exchange version and build, TLS configuration, load-balancer behavior, and any hybrid configuration.
- Account for public-folder and Hybrid Agent considerations where they apply.
- Do not use SSL offloading with EP; Microsoft says SSL offloading is unsupported for this control.
- Use Microsoft’s EP deployment script and Health Checker to assess prerequisites, and understand the connectivity impact before making changes.
EP is a security control, not a substitute for installing the SU that addresses the vulnerability you are responding to. If its prerequisites are unclear during an incident, avoid enabling it blindly and prioritize a validated change plan.
Install and verify the applicable emergency update
Once you have identified the installed version and CU, follow Microsoft’s supported update path for that build. Microsoft’s update workflow calls for installing updates on front-end servers first, planning restarts before and after installation, and running Health Checker again after an SU to identify additional actions.
- Confirm the target update. Match the current Exchange version and CU to Microsoft’s current SU and support guidance. Do not assume an update for another CU or product version is applicable.
- Prepare the change. Review the relevant Microsoft instructions, maintenance window, dependencies, and recovery plan. Make sure the operators know which servers are front-end and back-end in the environment.
- Update front-end servers first. Follow Microsoft’s sequence for the applicable deployment, then proceed with the remaining servers as directed by the update guidance.
- Restart as required. Plan the required restart before and after installation rather than treating installation completion alone as proof the server is ready.
- Run Health Checker again. Review its post-SU findings and complete any additional actions it identifies.
- Validate the outcome. Confirm the expected SU/build is installed and test the Exchange services, mail flow, and access paths that matter to your topology.
Microsoft’s deployment guidance advises installing the latest SU before bringing a server online and keeping servers on the latest CU or the latest-minus-one CU. Because releases and support status change, verify the current recommendation before applying it to a specific server.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Keep mitigations, architecture, and patching distinct
| Option | What it can do | What it cannot do |
|---|---|---|
| Restrict unnecessary inbound access | Reduce reachable services when the change preserves required user, application, and mail-flow access. | Install an Exchange fix or make an incompatible publishing path safe. |
| Exchange Emergency Mitigation service | Apply certain temporary mitigations for known threats when the service and mitigation are applicable. | Replace the applicable Exchange SU. |
| Edge Transport architecture | Handle Internet mail flow in a perimeter network and help limit direct Internet exposure of internal Exchange. | Serve as a quick universal emergency change or a patch. |
| Extended Protection | Help mitigate authentication relay and man-in-the-middle attacks when version and configuration prerequisites are met. | Work with unsupported SSL offloading or bypass the need to patch. |
| Security Update | Provide the corrective update for the applicable vulnerability when installed through the supported path. | Remove the need to validate the build, restart as required, or check the resulting server state. |
Microsoft’s official Exchange update FAQ, Emergency Mitigation documentation, Edge Transport guidance, and Extended Protection guidance provide the relevant product instructions. The exact risk and appropriate controls depend on your Exchange build, publication path, hybrid topology, and operational requirements; use the current Microsoft documentation for those specifics.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




