What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For supported on-premises Exchange Server deployments, safe patching starts by matching the security update (SU) to the installed cumulative update (CU), testing CUs outside production, then installing in Microsoft’s recommended server order and validating the result. A CU upgrade cannot be rolled back by uninstalling it; SU removal is different and should be considered only after careful review.

What is the difference between an Exchange CU and an SU?

A cumulative update (CU) is a cumulative product update. A security update (SU) is a security release that applies only to supported CU versions, so the SU must match the CU installed on the server. An incompatible pairing can prevent installation. Microsoft’s Exchange Server update FAQ explains update types and deployment considerations; check Microsoft’s current release information before choosing an update because supported versions and release details change.

Later SUs for the same CU include earlier SUs for that CU. In general, install the current SU that applies to the server’s CU rather than installing each missed SU individually. Verify the applicable release notes and prerequisites for the specific server before proceeding.

How do you identify the right update?

  1. Inventory the Exchange version and installed CU on each server.
  2. Confirm that the version and CU remain supported, then identify the current SU that Microsoft lists for that CU.
  3. Run Microsoft’s Exchange Server Health Checker to review CU and SU status and any manual actions reported.
  4. Read the applicable release notes and prerequisites. Do not proceed with an SU that does not match the installed CU.

Health Checker is useful both before deployment, to find servers that are behind, and after an SU, to identify additional actions. Microsoft notes that some vulnerability fixes require environment-dependent follow-up.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How should you test and prepare before production?

Microsoft recommends testing a CU in a non-production environment first so update problems do not affect the running production environment. Use a test environment that reflects the Exchange configuration and dependencies that matter to your organization. Exercise relevant mail flow, client access, and operational workflows as appropriate to the local environment; these are practical planning examples, not a Microsoft-prescribed universal test suite.

Before scheduling production work, review the update’s prerequisites and release notes, decide how staff will monitor the deployment, and establish how service will be restored if installation fails. There is no single backup or rollback recipe established for every Exchange topology, so validate recovery arrangements against your own configuration rather than assuming a generic procedure applies.

What order should you install updates in?

Microsoft recommends updating front-end Mailbox servers that handle client connections before back-end servers. For each server, restart before installing and restart again afterward, even if Setup does not prompt for the second restart. Use an elevated command prompt for CU or SU installation, following Microsoft’s deployment guidance.

  1. Restart the Exchange server before installation.
  2. Install the applicable CU or matching SU from an elevated command prompt, following the relevant Microsoft instructions.
  3. Restart the server after installation, including when Setup does not request it.
  4. Continue through the deployment sequence, updating front-end servers before back-end servers.
  5. After an SU, run Health Checker again and address any additional actions it identifies.

For the current sequence, restart recommendation, and validation guidance, consult Microsoft’s update FAQ.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Can you roll back an Exchange update?

Update or action What removal or recovery means Appropriate route
CU A newer CU cannot be uninstalled to restore the previous CU. Microsoft warns that uninstalling the newer version removes Exchange from the server. Do not treat a CU upgrade as a reversible in-place patch. Test before production and plan recovery for the specific environment.
SU or hotfix (HU) Removal is different from CU removal, but taking it off can reintroduce the security or other issue it addressed. Consider removal only after carefully vetting the cause and consequences; it is not the routine first response to an incident.
Failed update installation The remedy depends on the particular Setup error or failure. Use Microsoft’s issue-specific failed-update troubleshooting guidance.
Lost Exchange server Server recovery is a rebuild using configuration stored in Active Directory, with prerequisites such as using the lost server’s name. Use RecoverServer for disaster recovery, not as a normal patch rollback.
Emergency mitigation A mitigation is an interim measure until the corresponding SU is installed; it may have its own removal or rollback procedure. Follow current mitigation documentation for the applicable build.

Microsoft’s CU upgrade guidance distinguishes CU removal from SU/HU removal. Keep patch removal, server rebuild, and mitigation rollback separate in change plans: they are different operations with different risks.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should you do if an Exchange security update fails?

Start with the exact failure and follow the corresponding steps in Microsoft’s Fix failed Exchange Server updates article. One possible issue is an SU that does not match the installed CU; other failures can require different repairs, including restoring Exchange services that were active before installation. Do not substitute a generic uninstall or RecoverServer procedure for the troubleshooting path specified for the error.

If the server itself has been lost and must be rebuilt, use Microsoft’s separate Recover Exchange servers procedure. If an Emergency Mitigation Service mitigation is involved, check Microsoft’s mitigation documentation for the applicable build and its removal procedure.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.