Install an out-of-band Exchange Server security update (SU) only after confirming that its package matches the server’s Exchange version and cumulative update (CU). “Out-of-band” describes the emergency timing, not a different installation method. Plan the rollout for the server roles and DAG topology you actually run, install from an elevated command prompt, restart as recommended, and verify the result on every server.
Before you start: identify the server and the update
Do not choose an SU from its title or vulnerability description alone. Exchange SUs target specific CUs, and Microsoft says they are cumulative for the CU they target. Eligibility depends on the product’s support lifecycle: Microsoft’s general guidance is the last CU for Exchange in Extended support or the last two CUs in Mainstream support. Check current lifecycle and release details rather than relying on older CU examples.
Record the following for every Exchange server in scope:
- Exchange version, installed CU and build, and current SU/update state.
- Windows Server version and Exchange server roles.
- Whether the server is a member of a Database Availability Group (DAG), and the topology and maintenance procedures that apply to it.
- Any release-specific prerequisites or post-install actions listed for the emergency update.
Microsoft recommends using Exchange Health Checker to find servers that are behind on CUs or SUs or still require manual actions. Consult the Exchange Server update FAQ and the specific release notes, then obtain the package through Microsoft’s Exchange update channel. If you cannot confirm the correct package for the installed CU, stop and resolve that mismatch before installing.
Recommended Free Tools
#1 Best Overall
Plan the rollout for your topology
Microsoft’s general guidance is to update front-end Exchange Mailbox servers first, followed by back-end servers. Apply that order to the server roles in your environment, but do not treat it as a complete DAG runbook: the correct maintenance sequence depends on your actual topology and the named release’s instructions. Use the applicable procedure for each DAG member or standalone server, and schedule the work around its service impact.
For a new Exchange server, Microsoft’s deployment overview recommends installing the latest CU and latest SU before bringing it online. That general deployment recommendation does not identify the right package for an existing server; package selection still depends on the installed CU and release guidance.
Rank #2
Install the SU
- Prepare the server. Confirm the package, release notes, server role, update state, and any topology-specific maintenance steps. Make sure you can restart the server as part of the change.
- Restart before installation. Microsoft recommends restarting before and after installing an update, even if the installer does not request the final restart.
- Run the update elevated. Open an elevated command prompt and start the Microsoft-provided update package according to its release instructions. Do not run it in a non-elevated session.
- Restart after installation. Restart the server even if setup does not prompt you to do so.
- Repeat deliberately. Continue with the remaining servers in the planned order, following the release-specific and topology-specific procedure rather than assuming one server’s result applies to the rest.
Microsoft documents an OWA/ECP failure that can occur when an SU is manually installed without elevation while User Account Control (UAC) is enabled. Its recovery guidance is to reinstall the update from an elevated command prompt and restart. Check that guidance’s applicability to your Exchange version before using it: Microsoft’s troubleshooting articles can cover different Exchange releases.
Verify Exchange after the restart
Run Exchange Health Checker again on each updated server. Review its findings for remaining updates and manual actions, then check that Outlook on the web (OWA) and the Exchange admin center (ECP) are accessible and that mail flow is working.
If mail flow is disrupted, Microsoft’s troubleshooting guidance says to check that Exchange services that stopped are running and configured to start automatically, that the server is not still in maintenance mode, and that the queue database has adequate free space. Use the symptom and the specific release’s guidance to direct further troubleshooting.
If setup fails or the update does not take
Start with the exact error and Microsoft’s failed-update troubleshooting guidance. Examples of documented causes include an SU that does not match the installed CU and a pending-restart condition. Use SetupAssist when the applicable Microsoft instructions direct you to it. Avoid generic or destructive repair steps that are not tied to the observed error and the server’s version.
Check applicability before following a troubleshooting article: the Microsoft failed-update page currently identifies its applicability as Exchange Server Subscription Edition (SE), while some individual articles—such as the OWA/ECP guidance—cover older Exchange versions. The right recovery steps therefore depend on the server and the current documentation.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What “out-of-band” means for Exchange updates
Microsoft says Exchange SUs are released when needed, typically on Patch Tuesday unless an emergency release is required. Out-of-band means the update is issued outside the usual schedule; it does not, by itself, mean there is a separate installation mechanism. Microsoft’s update FAQ puts the operational expectation plainly: “Your on-premises environments should always be ready to take an emergency security update (this applies to Exchange, Windows, and any other products you use on-premises).”
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesThe Exchange Emergency Mitigation (EM) service can apply temporary mitigations for some threats, but Microsoft says those mitigations do not replace the SU that fixes the vulnerability. Treat an EM action as interim protection while you prepare and apply the fixing update; do not assume the service installs that SU for you.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

