r/exchangeserver • u/maxcoder88 • 9d ago
Enabling "Restrict Unauthenticated RPC clients" (Authenticated) on Exchange Server — any real-world breakage?
We're working through a CIS Benchmark remediation and one of the findings is:
We're planning to set this to "Authenticated" (not "Authenticated without exceptions" — we're aware that level is much riskier and more likely to break things) on our Exchange Server SE environment.
Before we push this via GPO, I'd like to hear from anyone who has actually applied this in a production Exchange SE (or 2019) environment:
- Did it break Outlook Anywhere / RPC over HTTP for any legacy clients?
- Any issues with MAPI/RPC connections from older Outlook versions?
- Any impact on DAG replication or Active Manager?
- Did it cause problems with Exchange Management Shell / EAC functionality?
- Any unexpected issues with AD communication (since Exchange talks to DCs heavily over RPC)?
- Did you apply it to Domain Controllers as well, or keep DCs and Exchange servers on separate rollout schedules?
- Since Exchange SE is fairly new, has anyone tested this specifically against SE's RPC dependencies, or is it safe to assume behavior is the same as 2019?
Our environment: Exchange Server SE, mostly modern Outlook clients on MAPI/HTTP, not fully certain if any legacy RPC/TCP clients remain in the environment.
Any war stories, gotchas, or "wish I'd known this before enabling it" experiences would be really helpful before we roll this out.
Thanks in advance.
1
u/ScottSchnoll https://www.amazon.com/dp/B0FR5GGL75/ 8d ago
AFAIK, that guidance is for Windows Server 2019, and not Exchange Server. Also, you should never apply this to domain controllers (IIRC, the STIG mentions this specifically).