Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To assess an on-premises Exchange Server deployment, identify each server’s exact version and build, check its support and update eligibility, install the applicable security update, then run Microsoft Exchange Server Health Checker and complete any follow-up actions it reports. A server that appears to work normally may still be missing security updates, and an emergency mitigation is not a substitute for a code-fixing update.

Does a normally working Exchange server still need security updates?

Yes. Normal operation does not show whether a server has the latest applicable security fixes. Microsoft recommends keeping on-premises Exchange current and installing available Security Updates (SUs). It also warns that lower-severity issues can sometimes be combined into an attack chain. See Microsoft’s Exchange Server update FAQ.

This guidance is for Exchange Server installations that your organization operates. It is not a way to determine the patch state of Exchange Online, which Microsoft operates as a hosted service. Nor can a general article establish whether a particular server is exposed: that depends on its version and build, update eligibility, configuration, and other environment-specific details.

How can you tell whether your servers need attention?

  1. Inventory each Exchange server. Record its version, build, roles, installed Cumulative Update (CU) and SU, and whether it is covered by support or an applicable Extended Security Update (ESU). Microsoft recommends Exchange Server Health Checker to identify servers behind on CUs, SUs, or required manual actions. Find the tool and guidance through Microsoft’s update FAQ.
  2. Check support and update eligibility. Compare the installed version and build with Microsoft’s Exchange Server build numbers and release dates and current update information. Applicability depends on the product’s support status and installed CU; do not infer eligibility from a vulnerability headline alone.
  3. Use the organization dashboard as an overview, if available. In the Microsoft 365 admin center, the Software updates (Preview) page has an Exchange tab that summarizes counts of servers needing CUs, needing SUs, or out of support. It does not identify which individual servers are one or more builds behind, and Microsoft labels the feature preview documentation, so availability may be limited or change. See View software update status for Exchange Server installations.
  4. Assess the actual environment. Internet reachability, enabled features, proxy or hybrid architecture, and applied mitigations can affect practical risk. A build comparison or dashboard count is not, by itself, a per-server exposure diagnosis.

Which type of Exchange update applies?

Microsoft describes three update types. Check the current build information and release notes for the version and CU you run rather than assuming a particular update applies to every Exchange server.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Update type Purpose What to check
Cumulative Update (CU) A cumulative product update issued on a regular release cadence. Confirm the target CU is applicable to your Exchange version and plan for its installation using Microsoft’s current release information.
Security Update (SU) A security fix released as needed to address security issues. Confirm the SU applies to your installed version and CU, and review its instructions for any additional actions.
Hotfix Update (HU) A feature update issued when needed sooner than a CU. Consult the relevant Microsoft release details to determine whether it applies to your deployment.

Microsoft’s Updates for Exchange Server page and its update FAQ: update types and best practices describe update types and best practices. Release timing is not a substitute for checking the current release and its applicability.

What is a safe patching sequence?

  1. Bring the installation to an applicable CU. Microsoft’s update FAQ recommends installing the latest applicable CU. Check the build and release information first, and plan the change for your topology.
  2. Use Health Checker to establish what is behind. Inventory all servers, not just one representative server, and note any manual actions the tool identifies.
  3. Install applicable SUs as released. Follow the instructions for the specific SU and Exchange build. Microsoft also advises being ready to apply emergency updates across on-premises products, including Windows.
  4. Plan availability measures for high-availability environments. Microsoft discusses Database Availability Groups (DAGs) and Maintenance mode as part of a graceful update process. Validate the procedure against your current topology and Microsoft’s applicable instructions; the exact steps depend on the environment.
  5. After the SU, rerun Health Checker and complete follow-up actions. Some vulnerabilities may require administrator actions beyond installing the update. Also ensure the underlying Windows Server operating system is updated, as Microsoft advises in its Exchange Server update FAQ.

Do emergency mitigations fix the vulnerability?

No. Microsoft states: “Mitigations are a temporary form of protection that should be used until the actual code fix is released.” An Exchange Emergency Mitigation (EM) service mitigation may reduce immediate risk from a known threat, but it does not fix the vulnerable code and does not replace an SU.

The optional EM service checks Microsoft’s Office Config Service for available mitigations and validates signed mitigation configuration before applying them. Microsoft documents mitigation types that include IIS URL Rewrite rules, Exchange service mitigations, and app-pool mitigations. Details and prerequisites are in Microsoft’s Exchange Emergency Mitigation Service documentation.

How do you check mitigation status and connectivity?

  • Use Exchange PowerShell to inspect the MitigationsApplied property with Get-ExchangeServer, and use Microsoft’s Get-Mitigations.ps1 script to view applied, blocked, or failed mitigation status.
  • Microsoft’s Test-MitigationServiceConnectivity.ps1 check must run on a Mailbox server; it is not intended for a Management Tools-only server.
  • The service requires outbound connectivity to officeclient.microsoft.com on port 443, as well as certificate-validation dependencies. Network inspection or proxy handling may affect connectivity, so check Microsoft’s current prerequisites before changing firewall or proxy configuration.

A successful connectivity or mitigation-status check indicates the state of that service or mitigation. It does not establish that vulnerable code has been fixed; use the applicable SU and post-update checks for that.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What is different for hybrid or lightly used servers?

A hybrid deployment does not make an on-premises Exchange server irrelevant to update management. Microsoft’s FAQ recommends staying current even when an on-premises server is not actively used. Assess the actual server’s version, build, support and update eligibility, and configuration; do not assume it is safe to leave unpatched because mailboxes are hosted elsewhere.

Hybrid architecture can affect practical risk and maintenance planning, but it does not change the need to establish the server’s precise update state. Use the same per-server inventory and Microsoft build and release checks described above.

What if Exchange Server 2016 or 2019 is out of support?

Microsoft’s build and release page states that Exchange Server 2016 and Exchange Server 2019 are out of support. It says customers enrolled in the Extended Security Update (ESU) program are eligible for December 2025 and later SUs for those versions; customers not in ESU are directed to migrate to Exchange Server Subscription Edition (SE). Because lifecycle and eligibility information can change, verify current status and your organization’s ESU entitlement against Microsoft’s build numbers and release dates page.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Should you enable Windows Extended Protection after patching?

Do not enable Extended Protection (EP) blindly. Microsoft describes EP as a defense against authentication relay and man-in-the-middle attacks, using channel-binding information that includes Channel Binding Tokens in TLS connections. Its compatibility depends on Exchange version and environment prerequisites; Microsoft also documents Public Folder hierarchy constraints for certain older CUs.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft says Exchange Server 2019 CU14 and later enables EP by default. For other configurations, review the version prerequisites and instructions before changing settings; some older supported configurations may require Microsoft’s management script. See Exchange Server support for Windows Extended Protection.

What should you do if an update fails or a service breaks?

Use the exact error, Exchange build, and symptom to find the matching Microsoft troubleshooting procedure in Fix Failed Exchange Server Updates. Do not treat one reported fix as a universal repair.

For example, Microsoft documents an issue where Outlook on the web or the Exchange admin center (ECP) returns HTTP 500 after a security update because an assembly is missing. For that specific issue, its documented resolution is to reinstall the SU from an elevated command prompt and restart the server. Apply that remedy only when the symptom and diagnosis match Microsoft’s procedure; other update failures require their corresponding steps.

What if a 24/7 business has no maintenance window?

Continuous service requirements make maintenance planning more important, not optional. Microsoft’s FAQ points administrators of high-availability deployments toward a graceful process using DAGs and Maintenance mode. Build the plan around the actual topology and current Microsoft instructions, and allow time to verify the updated servers and complete any Health Checker follow-up actions. A mitigation may be used as temporary protection while arranging the code-fixing update, but it does not replace that update.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.