Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Verify an Exchange Server security update by running Microsoft’s Exchange Server HealthChecker and confirming both the expected Build Number and the Exchange IU or Security Hotfix Detected entry. Then cross-check the installed ExSetup.exe version against Microsoft’s build table for that server’s exact Exchange release and cumulative update (CU). Do not rely on Get-ExchangeServer’s AdminDisplayVersion alone: it identifies the CU, not whether a security update or hotfix is installed.

Before checking, identify the exact Exchange version and update

Exchange build numbers vary by Exchange release and CU, so there is no single expected build number that applies to every server. Record the Exchange generation and installed CU for each server, then find the intended security update (SU), hotfix update (HU), and build entry in Microsoft’s Exchange Server build numbers and release dates table.

Check that the server is eligible for the update you expect. Microsoft states that Exchange Server 2016 and 2019 are out of support; customers enrolled in the Extended Security Update (ESU) program are eligible for December 2025 and later security updates. Organizations outside ESU are directed to migrate to Exchange Server Subscription Edition (SE) to continue receiving the latest security updates. Confirm the server’s entitlement and the relevant release entry on Microsoft’s current build page before treating a version as current.

Use HealthChecker as the primary post-update check

  1. Run Microsoft’s Exchange Server HealthChecker script on the updated server.
  2. In the report’s Exchange Information section, inspect Build Number and Exchange IU or Security Hotfix Detected.
  3. Confirm that both identify the expected release and update for the server’s Exchange generation and CU.
  4. After installing an SU, run HealthChecker again to identify whether additional post-update actions are required.

Microsoft recommends HealthChecker for build verification and post-SU checks. A build value confirms the installed version; the detected-update field helps establish that the expected security update or hotfix is present. Neither replaces review of setup errors if installation failed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Cross-check the local Exchange binary version

In Exchange Management Shell, Microsoft documents this command to retrieve the ExSetup.exe file-version information:

Get-Command Exsetup.exe | ForEach-Object {$_.FileVersionInfo}

Compare the reported ProductVersion or FileVersion with the matching entry in Microsoft’s build table. Match the exact Exchange release and CU; a number from another CU or Exchange generation is not a valid comparison.

Know what each verification method proves

Method What it can establish Important limitation
HealthChecker on the server Reports the build and whether an Exchange IU or security hotfix is detected; also identifies further post-update actions. Interpret the values against the intended release and CU.
ExSetup.exe file version Provides a local version value to cross-check against Microsoft’s build table. Must be matched to the correct Exchange release and CU.
Get-ExchangeServer and AdminDisplayVersion Identifies Exchange servers and their CU version. Microsoft explicitly says this option “doesn’t show the version of installed Security Updates (SUs) or Hotfix Updates (HUs).” It is not proof of SU/HU installation.
Windows Application log and ExchangeSetup.log Provides setup error context and a record of prerequisite/readiness checks, installation progress, and system configuration changes. Logs help diagnose an installation; the resulting version should still be verified separately.
Microsoft 365 admin center, Software updates (Preview) Shows high-level organization counts for Exchange CU/SU and out-of-support status. It does not identify the specific servers one or more builds behind. Microsoft labels the feature as preview and subject to change, so it is fleet context—not server-by-server proof.

Check logs when the update may not have completed cleanly

  1. Open Windows Event Viewer and review the Application log for Exchange setup events and errors.
  2. Inspect <system drive>:ExchangeSetupLogsExchangeSetup.log.
  3. Search for errors and read the surrounding details, including the relevant readiness checks and installation steps.
  4. Use the exact error text and Exchange version context to select a remediation in Microsoft’s Fix Failed Exchange Server Updates guidance. The linked troubleshooting page states that it applies to Exchange Server SE; do not assume its steps apply to another Exchange version without checking applicability.
  5. After resolving an issue, rerun HealthChecker and verify the build and detected-update entry again.

Microsoft’s Exchange installation verification guidance describes reviewing the Application log and setup log for errors. An installer success message by itself does not establish that no errors remain or that HealthChecker has no additional actions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Include every server and management-tools-only installation

Check each relevant Exchange server rather than extrapolating from one machine. Microsoft’s Exchange Server update FAQ recommends installing security updates on all Exchange servers and on servers or workstations that run only Exchange Management Tools. It also recommends restarting before and after updates, even when the installer does not prompt for a restart.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What a convincing verification looks like

For each server, the evidence should agree: HealthChecker reports the expected build and detected IU/security hotfix, and the local ExSetup.exe version matches the same release and CU in Microsoft’s build table. If the install raised concerns, the Application log and ExchangeSetup.log should have no unresolved setup errors. The CU-only AdminDisplayVersion value is useful for inventory, but cannot establish SU/HU status.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.