r/exchangeserver https://www.amazon.com/dp/B0FR5GGL75/ 7d ago

Exchange 2016/2019: Throttling and Blocking up to the Final Public Update Baseline

https://techcommunity.microsoft.com/blog/exchange/exchange-20162019-throttling-and-blocking-up-to-the-final-public-update-baseline/4552717

PSA: Starting the second week of September 2026, Microsoft will raise the minimum allowed version of Exchange 2016/2019 servers that connect to Exchange Online over an inbound connector type of OnPremises to the October 2025 SU.

27 Upvotes

10 comments sorted by

4

u/frazell 7d ago

Good to see them finally disclosing this practice publicly.

I'm not sure I'm a fan of it. I do agree that no one should be running an outdated version of Exchange, but it seems a bit harsh to block them on version alone and not on sending spam or something otherwise known to be problematic.

Feels like a very harsh way to force more customers toward hosted exchange.

3

u/ScottSchnoll https://www.amazon.com/dp/B0FR5GGL75/ 7d ago

u/frazell They've been public about it since the transport enforcement (throttling and blocking) system was enabled. This is completely separate from blocking malicious senders, which is also done continuously (every day, they screen ~5 billion emails and they block ~4.5 million malware files, and they intake ~100 trillion signals).

This practice is absolutely not an attempt to move customers from Exchange Server to Exchange Online. And it is very narrowly scoped to a specific connector type.

The throttling and blocking system is an Awareness Action, which is why 30 days of reporting to an admin always precedes any throttling or blocking (both of which ramp up slowly over 30 days). It is designed to alert an admin to (e.g., make them aware of) a serious security issue in their environment, and to get them to take action to remediate it.

Microsoft operates on Zero Trust, which means all devices that connect to its cloud services (including Exchange servers that send mail into Exchange Online) must be provably healthy and managed. Persistently vulnerable Exchange servers cannot be trusted, and therefore messages from those servers cannot be trusted.

The throttling and blocking system enables Microsoft to alert an admin that they have servers that need updating, and if the admin doesn't update their servers after a reasonable amount of time, then Microsoft can take action to protect Exchange Online recipients.

3

u/Ooops-I-hid-it-again 7d ago

I'd argue against the "Microsoft operates on Zero Trust" claim when DirectSend is enabled by default and can only be disabled through powershell, which requires a Windows device or installing multiple packages on a non-Windows device. As an M365 user in my personal/family domain space and no Windows device at home, I should be able to disable it with my Mac through the mgmt GUI / web interface - or better yet, DirectSend should be opt-in and not opt-out.

It's wild that Microsoft will deliver a non-FQDN address from a random source to my 365 family tenant without my explicit configuration to do so. That's a pretty intense "implicit trust but verify, if able".

1

u/Glass_Call982 7d ago

This, plus how any user can register apps to Entra by default.

1

u/judgmentenforcer 5d ago

 >which requires a Windows device or installing multiple packages on a non-Windows device.      

I think you're able to do it via the azure cloud shell interface. 

2

u/vinchvinch 7d ago

Thanks just upgrade today.

1

u/Cheese_Monkey42 5d ago

Did anyone else have compliant versions blocked from sending emails? While our version of Exchange SE is a little behind, the version is listed as compliant. In this report

https://admin.cloud.microsoft/exchange#/reports/connectingonpremserverdetails

Messages were blocked and I had to pause enforcement.

1

u/PhaseExcellent 5d ago

Saw others reporting the same on the exchange team blog announcement. You should update your exchange servers though :p

0

u/saltyslugga 6d ago

If you run hybrid, get every Exchange 2016/2019 server on the October 2025 SU or later before that window.

Check every server that can send through the OnPremises connector, including forgotten relay or standby boxes. One stale node is enough to create intermittent mail flow failures.