0

Exchange 2019 CU10 Released

Exchange 2019 CU10 has been released to the Microsoft Volume Licensing Center and the public Microsoft Download site!  Exchange 2019 has a different servicing strategy than Exchange 2007/2010 and utilises Cumulative Updates (CUs) rather than the Rollup Updates (RU/UR) which were used previously.    CUs are a complete installation of Exchange 2019 and can be used to install a fresh server or to update a previously installed one. Exchange 2013 and 2016 have the same servicing methodology.

Previously Exchange 2019 updates were only available through the Volume Licensing Centre.  This was changed during the March 2021 Hafnium attack.

Download Exchange 2019 CU10

Details for the release are contained in KB 5003612.

Updates Of Particular Note

Update 21-7-2021  “Object reference not set to an instance of an object” error and Setup fails in Exchange 2019 CU10 and 2016 CU21  - please note that setup will fail if the default computers Containers has been removed or renamed.

This CU contains the latest security updates at the time of release, specifically the recently released updates for Hafnium.

This release was slightly delayed as previously announced.  This was done to add in an additional security feature.  Exchange 2016 and 2019 now have integration with the Antimalware Scan Interface (AMSI), which you can read more about here.  This feature requires the underlying OS to support it, and that is present in Windows Server 2016 and 2019.  It is NOT present in Windows Server 2012 R2.   Thus Exchange 2019 must be installed onto Windows Server 2019 to be able to leverage AMSI.

AMSI integration allows an AMSI capable solution to scan content in the HTTP requests sent to Exchange and block malicious requests before those requests are processed by Exchange.  Scanning is performed in real time.

This is separate to the existing Antimalware capability which would scan a message after Exchange received it.

Note that there are some known issues when preparing AD which are discussed in the release KB.  There are additional operations required for multiple domain environments where /PrepareAD needs to be executed manually in the other domains.

This CU still has the Autodiscover EventID 1 error in the Application event log.  See KB 4532190 for details.

CU10 has Schema changes.  AD Schema version details for Exchange 2019 are here.

Note as of September 2020 the Exchange 2019 sizing calculator can be downloaded manually from: https://aka.ms/excalc

Previously it was only available via the Exchange 2019 CU media.

Issues Resolved

This cumulative update also fixes the issues that are described in the following Microsoft Knowledge Base articles:

  • 5004612 Message body not displayed in OWA if the message was added in Outlook to a new mailbox

  • 5004613 OutOfMemory exception when moving a public folder that has a large ICS sync state

  • 5004614 Korean text is garbled in calendar invitation to a user with a Chinese display name

  • 5004615 "InvalidOperationException" and Store Worker process crashes during mailbox move

  • 5004616 Changing the email address in EAC doesn't work in modern browsers

  • 5004617 TLS 1.2 is not set as default after you install Exchange 2019 with Edge Transport role

  • 5004618 MSExchangeMailboxAssistants 4999 Crash in ELCAssistant.InvokeInternalAssistant with System.NullReferenceException

  • 5004619 Mailbox creation through ECP fails after installing Exchange Server 2019 or 2016 April update

Some Items For Consideration

Exchange 2019 follows the same servicing paradigm for Exchange 2013 and 2016 which was previously discussed on the blog.  The CU package can be used to perform a new installation, or to upgrade an existing Exchange Server 2019 installation to this CU.  Cumulative Updates are well, cumulative.  What else can I say…

Customers with a hybrid Exchange deployment, must keep their on-premises Exchange servers updated to the latest update or the one immediately prior ( N or N-1).

  • Test the CU in a lab which is representative of your environment
  • Review this post to also factor in AD preparation which is to be done ahead of installing the CU onto the first Exchange server
  • Follow your organisation’s change management process, and factor the approval time into your change request
  • Provide appropriate notifications as per your process.  This may be to IT teams, or to end users.
  • After you install this cumulative update package, you cannot uninstall the cumulative update package to revert to an earlier version of Exchange. If you uninstall this cumulative update package, Exchange is removed from the server.
  • Place the server into SCOM maintenance mode prior to installing, confirm the install then take the server out of maintenance mode
  • Place the server into Exchange maintenance mode prior to installing, confirm the install then take the server out of maintenance mode
  • I personally like to restart prior to installing CUs.  This helps identifies if an issue was due to the CU or happened in this prior restart, and also completes any pending file rename operations.  3rd party AV products are often guilty of this
  • Restart the server after installing the CU
  • Ensure that all the relevant services are running
  • Ensure that event logs are clean, with no errors
  • Ensure that you consult with all 3rd party vendors which exist as part of your messaging environment.  This includes archive, backup, mobility and management services.
  • Ensure that you do not forget to install this update on management servers, jump servers/workstations and application servers where the management tools were installed for an application.  FIM and 3rd party user provisioning solutions are examples of the latter.
  • Ensure that the Windows PowerShell Script Execution Policy is set to “Unrestricted” on the server being upgraded or installed.  See this article on setting PowerShell to Unrestricted.
  • Disable file system antivirus prior to installing. Do this through the appropriate console.  Typically this will be a central admin console, not the local machine.
  • Verify file system antivirus is actually disabled
  • Once server has been restarted, re-enable file system antivirus.

Please enjoy the update responsibly!

What do I mean by that?  Well, you need to ensure that you are fully informed about the caveats with the CU  and are aware of all of the changes that it will make within your environment.  Additionally you will need to test the CU your lab which is representative of your production environment.

Cheers,

Rhoderick

Rhoderick Milne [MSFT]

Leave a Reply

Your email address will not be published. Required fields are marked *