Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

An out-of-band (OOB) Exchange security update is a Security Update (SU) Microsoft releases outside its usual schedule because an urgent security issue calls for it. It is still an Exchange SU—not a separate routine update type—and whether it applies depends on your Exchange version and cumulative update (CU). Treat it as an urgent deployment that still requires the normal checks for applicability, installation order, privileges, restarts, and validation.

What “out of band” means for Exchange

Microsoft says Exchange SUs are released “when needed,” typically on the second Tuesday of the month, unless an emergency release is required. An OOB release is therefore an exception to the usual timing, not a new Exchange servicing category. Microsoft’s Exchange update taxonomy includes Cumulative Updates (CUs), Security Updates (SUs), and Hotfix Updates (HUs); it does not define OOB as a separate update type. Microsoft’s Exchange update FAQ and release information are the relevant references for Exchange servicing. Do not assume that Windows OOB delivery mechanics or policies automatically describe how to service Exchange Server.

How an emergency SU differs from a CU

A CU is a cumulative product release; Microsoft generally targets two per year, with target release months of March and September. An SU addresses security issues and is released when needed, including outside the usual monthly timing. The distinction matters operationally: an emergency SU does not remove the need to check your installed CU, supported servicing state, and the package’s stated applicability.

Microsoft’s guidance describes SU availability for the last CU in Extended support, or the last two CUs in Mainstream support. Its general update guidance says critical product updates can typically be applied to the latest CU and the immediately previous CU. Confirm the specific release notes and current build information before deploying; do not infer eligibility from the word “emergency.”

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What to do when Microsoft releases an OOB Exchange SU

  1. Inventory the environment. Record Exchange versions, installed CUs, server roles, support status, and any servers or workstations that have Exchange Management Tools only. Microsoft recommends installing SUs on all Exchange servers and Management Tools-only machines.
  2. Confirm applicability and instructions. Read the release-specific Microsoft advisory and package notes. Check affected versions and CUs, prerequisites, known issues, required manual actions, and any relevant ESU eligibility. Current build and package information can change, so use Microsoft’s Exchange build numbers and release dates page alongside the specific SU documentation.
  3. Plan the rollout. Choose a maintenance window and follow Microsoft’s role-specific instructions. The general Exchange FAQ recommends updating front-end Mailbox servers before back-end servers. For CU work, DAG members may require maintenance-mode procedures; follow the directions for the exact update and server role rather than applying a generic sequence.
  4. Prepare and install with elevation. Back up and test in accordance with the deployment procedure; Microsoft’s CU guidance recommends nonproduction testing and tested Exchange and Active Directory backups. Install the CU or SU from an elevated command prompt, using the exact release instructions.
  5. Restart as directed. Microsoft recommends restarting the Exchange server before and after installation, even if Setup does not prompt for a restart.
  6. Update the full estate and validate. Apply the applicable SU to Exchange servers and Management Tools-only systems. Run Microsoft’s Health Checker afterward to verify build and SU status and identify additional required actions; also keep the underlying Windows Server updated.

Microsoft describes the Exchange servicing currency window as the latest CU or the immediately previous CU (N or N-1), amounting to one year under the stated release cadence. The actual support and update eligibility for a particular server should be checked against current Microsoft guidance.

Use Emergency Mitigation as a bridge, not a substitute

The optional Exchange Emergency Mitigation (EM) service can apply automatic mitigations for known threats. After installation, the service checks Microsoft’s Office Config Service hourly for mitigations, validates the configuration signature, and can apply URL Rewrite, Exchange service, or app-pool mitigations. These controls can reduce exposure while administrators prepare a patch, but Microsoft describes each mitigation as an interim fix until the SU is installed; the EM service is not a replacement for Exchange SUs.

Support ranges, requirements, connectivity needs, and the available mitigation list can change. Check the current Exchange Emergency Mitigation service documentation before relying on it, and verify mitigation status and service connectivity in your environment.

Check support and ESU eligibility before relying on an update

Microsoft’s update best-practice guidance assumes Exchange is still in support. Its build page says customers enrolled in the Extended Security Update (ESU) program are eligible to receive December 2025 and later SUs for Exchange Server 2016 and 2019. That eligibility is conditional: it does not mean every installation of those versions receives those updates. Confirm current ESU enrollment and access requirements, and verify the specific package’s applicability before scheduling deployment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Validate the result and troubleshoot failures

After installation, run Health Checker again and complete any manual actions it identifies. Having current CUs and SUs installed does not necessarily complete every security remediation; Microsoft notes that some vulnerabilities can require additional steps. If OWA, ECP, or another Exchange function fails after an update, use Microsoft’s OWA/ECP update troubleshooting guidance and the release-specific notes. One documented cause of OWA/ECP failure is manually installing an SU without elevation while User Account Control is enabled; Microsoft’s remedy is to reinstall it from an elevated command prompt.

Microsoft’s Exchange Server update FAQ puts the operational expectation plainly: “Your on-premises environments should always be ready to take an emergency security update (this applies to Exchange, Windows, and any other products you use on-premises).”

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.