Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To reduce the risk of Microsoft Exchange Autodiscover leaking credentials, patch Exchange, block untrusted Autodiscover.<TLD> lookups at enterprise DNS or firewall controls, retire Basic Authentication where possible, and investigate any suspected exposure. Patching and Exchange server mitigations address server-side vulnerabilities; refusing untrusted Autodiscover names addresses the specific client-side fail-up behavior behind this leak.

How the Autodiscover credential leak works

Autodiscover helps clients such as Microsoft Outlook find Exchange configuration. The problem identified in 2021 was not the protocol’s basic purpose, but how some clients behaved when expected organization-controlled endpoints failed: they tried progressively broader hostnames, including names such as Autodiscover.<TLD>. If an attacker controlled one of those names, a client could send HTTP Basic credentials to a server outside the organization’s trust boundary.

Basic Authentication sends a reusable username and password representation in each request; it is not encryption. TLS can protect credentials while they travel to a server, but it does not make an untrusted destination safe: the destination server can still receive the authentication material. Guardicore Labs/Akamai reported that a controlled domain experiment captured 372,072 Windows domain credentials, including 96,671 unique credentials, from April 16 through August 25, 2021. These figures describe that experiment, not a census of Exchange users.

Mitigation steps for Exchange administrators

  1. Patch supported Exchange servers

    Bring on-premises Exchange servers to a supported Cumulative Update and install all available security updates. Microsoft describes this as the best and most complete remediation for Exchange vulnerabilities. This is essential for server security, but it does not by itself prevent clients from resolving an untrusted Autodiscover hostname.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
    #1 Best Overall
    Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
    • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
    • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
    • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
    • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
    • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
  2. Apply Microsoft’s Exchange mitigations

    Where supported, enable the Exchange Emergency Mitigation Service and follow Microsoft’s current mitigation guidance for the specific server version and attack path. Microsoft documents IIS URL Rewrite request-blocking rules for relevant Exchange threats, including patterns involving Autodiscover and PowerShell. Treat these as server-side mitigations, not a substitute for controlling client DNS lookups. Microsoft says the directed mitigation has no known Exchange functionality impact; validate it in your environment and confirm the applicable product guidance before deployment.

  3. Refuse untrusted Autodiscover names

    At enterprise DNS or firewall controls, prevent resolution or access to untrusted Autodiscover.<TLD> names, while maintaining a tested allowlist for the organization’s legitimate Autodiscover namespaces. Central DNS controls work for clients that use those resolvers; devices that bypass corporate DNS may require additional endpoint or network controls. Do not casually point these names to 127.0.0.1: published guidance warns that loopback handling can create a credential-trick condition. Test the chosen policy with legitimate Outlook and Exchange configurations before broad rollout.

    Rank #2
    Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
    • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
    • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
    • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
    • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
    • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
  4. Retire Basic Authentication where feasible

    Prefer modern authentication and enforce multifactor authentication (MFA) where supported by your identity architecture. Microsoft has documented the deprecation path for Basic Authentication in Exchange Online; Exchange Online and on-premises deployments have different configurations and servicing considerations, so check the guidance for the environment you operate. Modern authentication and MFA reduce the usefulness of captured credentials, but they do not replace DNS controls or endpoint protections.

  5. Review exposure and contain compromised credentials

    If logs or other evidence indicate that credentials reached an untrusted endpoint, use the organization’s identity-response plan to rotate affected passwords and revoke relevant sessions or tokens. Scope resets using available evidence about affected clients and accounts rather than assuming every user was exposed. Microsoft’s Exchange threat guidance also recommends investigating servers, running full antivirus scans, and using advanced hunting for signs of compromise.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
    Rank #3
    Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
    • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
    • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
    • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
    • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
    • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

How the main controls differ

Control What it addresses Coverage and trade-offs
Supported Exchange updates Exchange server vulnerabilities Applies to the servers you update; does not independently prevent a client from resolving an untrusted Autodiscover name.
Exchange Emergency Mitigation Service and IIS URL Rewrite rules Specific server-side Exchange attack paths covered by Microsoft’s current guidance Use only where supported and applicable to the server version. Validate against legitimate Exchange traffic and keep the relevant Microsoft guidance at hand.
Enterprise DNS or firewall refusal of untrusted names The fail-up lookup to untrusted Autodiscover.<TLD> hosts Effective for traffic governed by the control; clients using other resolvers may need separate controls. An allowlist and testing help preserve legitimate Autodiscover.
Modern authentication and MFA Reduces reliance on reusable Basic Authentication credentials and can limit the value of stolen passwords Depends on identity and client support. It does not stop DNS resolution or prevent an untrusted server from receiving a request.
Log review and threat hunting Detection and scoping of possible exposure or server compromise Can reveal suspicious requests and activity when relevant telemetry is retained and available; it is investigative, not preventive.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What to do if Outlook may have sent credentials

  1. Identify the destination and affected clients

    Review DNS and proxy records for requests to unexpected Autodiscover domains. Correlate timestamps and client information with Exchange and IIS logs where available. Determine which users and devices could have made the requests; a suspicious lookup alone does not establish that credentials were successfully captured.

  2. Check for account and server compromise

    Investigate suspicious authentication activity and account creation, and inspect exposed Exchange servers for web shells or malware. Use Microsoft’s current Exchange investigation guidance, full antivirus scanning, and advanced hunting capabilities available to your organization.

    Rank #4
    Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
    • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
    • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
    • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
    • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
    • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
  3. Contain based on evidence

    When evidence indicates credentials were sent to an untrusted endpoint, rotate the affected passwords and revoke sessions or tokens as directed by your identity-response plan. Apply stronger containment if investigation finds account misuse or server compromise. Continue monitoring authentication activity after containment.

  4. Close the path that allowed the request

    Correct the DNS or firewall policy, verify that legitimate Autodiscover still works, and check whether any clients bypass the central control. Do not treat a password reset or client reconfiguration as a replacement for correcting the underlying resolution path.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to keep the mitigation current

Exchange servicing and mitigation behavior can change. Confirm the supported status, cumulative update, security updates, and applicable mitigation guidance for each server and tenant before implementation. Document the approved Autodiscover namespaces, retain useful DNS, proxy, IIS, and Exchange telemetry, and re-test the control when clients, identity settings, or Exchange versions change.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.