0

Exchange Healthcheck Script – EWS Internal Bypass URL Set

Exchange Healthcheck InternalNLBBypassURL

The amazing Exchange Healthcheck script really has gotten to the point where Exchange Best Practices Analyser (ExBPA) used to be. Exchange admins should heavily use the Healthcheck script.  This should be done before and after maintenance tasks such as installing CUs and security updates.

There is a handy dandy shortcut URL to download the script:  https://aka.ms/ExchangeHealthChecker

Note that this… Read the rest “Exchange Healthcheck Script – EWS Internal Bypass URL Set”

0

How to Get Newer Version of PowerShellGet – Install, Don’t Upgrade

Update PowerShellGet

Current versions of Windows come with a version of PowerShellGet pre-installed.  The PowerShellGet and PackageManagement modules originally were released in Windows PowerShell 5.0 which itself was part of the Windows Management Framework (WMF) 5.0 RTM.  This was back in early 2016. The PowerShellGet module is also integrated with the PackageManagement module as a provider.

The 1.0.0.1 version of Powe… Read the rest “How to Get Newer Version of PowerShellGet – Install, Don’t Upgrade”

0

Exchange 2019 CU13 Released (2023 H1)

Exchange 2019 CU13 Download

Exchange 2019 CU13 has been released to the Microsoft Volume Licensing Center and the public Microsoft Download site!  Exchange 2019 has a different servicing strategy than Exchange 2007/2010 and utilises Cumulative Updates (CUs) rather than the Rollup Updates (RU/UR) which were used previously.    CUs are a complete installation of Exchange 2019 and can be used to install a fresh server or to upd… Read the rest “Exchange 2019 CU13 Released (2023 H1)”

0

End of Exchange 2013 Support

Exchange 2013 Support Lifecycle

Today Exchange 2013 reaches the end of the road and it will transition out of extended support.  Hopefully everyone has migrated to a newer version and/or Office 365.  But experience tells me that will not be the case.

Hopefully no one will have Exchange 2013 published to the Internet either, but again experience says otherwise…

Please note that Microsoft will not provide technical support, time zon… Read the rest “End of Exchange 2013 Support”

0

Out of SSPR Scope User Experience

Azure AD Self Service Password Reset (SSPR) has the ability to restrict which group of users are able to perform SSPR tasks.  It is a slightly limited administrator control as only a single group can be selected.  Azure AD administrator roles are able to perform SSPR even if they are not in scope of the selected group.

They typical user experience is that the person goes to https://aka.ms/SSPR and … Read the rest “Out of SSPR Scope User Experience”

0

Configure On-Premises Exchange For EOP Spam Thresholds

Exchange Online Anti Spam Threshold

A common issue when deploying Exchange Online Protection (EOP) and Microsoft Defender for Office 365 (MDO) with on-premises Exchange is making Exchange aware of the EOP spam filtering.  This is because EOP uses slightly different logic to stamp the spam results etc. into the message.  Exchange Server needs to be aware of this so that it can take action upon those settings.

On-Premises Spam Confiden

Read the rest “Configure On-Premises Exchange For EOP Spam Thresholds”
0

Azure AD Connect Sync Options

Active Directory synchronization was designed not just to move objects from on-premises AD to Azure AD, but to give administrators precise control over how identities were matched, transformed, and filtered.  This is not a new thing.  It dates back to very early days of Microsoft cloud hosted email, both commercial and educational orientated. Azure AD Connect evolved from earlier solutions such as… Read the rest “Azure AD Connect Sync Options”

0

SSPR Screenshots – December 2022

Entra ID SSPR

Self Service Password Reset (SSPR) in Microsoft Entra ID is one of those features that often goes unnoticed until it is urgently needed. It gives end users the ability to securely reset or unlock their account without calling the helpdesk, while administrators benefit from reduced support costs and improved security posture. Ideally users will have to use MFA to perform SSPR.  This means that lame… Read the rest “SSPR Screenshots – December 2022”

0

Kerberos Issues November 2022

Kerberos Issues November 2022

The November 8, 2022 and later Windows updates address a  security bypass and elevation of privilege vulnerability with Authentication Negotiation by using weak RC4-HMAC negotiation.

This update will set AES as the default encryption type for session keys on accounts that are not marked with a default encryption type already.

To help secure your environment, install the Windows update that is dated … Read the rest “Kerberos Issues November 2022”

0

Updated Guidance On Exchange Server Extended Protection

Extended Protection is set to Required on the OAB vDIR

Extended Protection (EP) was added to Windows back in 2009 as a new security feature. This feature enhances the protection and handling of credentials when authenticating network connections using Integrated Windows Authentication (IWA).

The update itself does not directly provide protection against specific attacks such as credential forwarding, but allows applications to opt-in to Extended Protect… Read the rest “Updated Guidance On Exchange Server Extended Protection”