HomeSecurityCISA: Security Guide for Microsoft Exchange Servers

CISA: Security Guide for Microsoft Exchange Servers

In response to growing threats to email infrastructure, the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), the Australian Cybersecurity Centre (ACSC), and the Canadian Cybersecurity Centre have published a comprehensive guideoutlining best practices for securing on-premises Microsoft Exchange Servers.

Microsoft Exchange Servers CISA

Titled “Microsoft Exchange Server Security Best Practices,” the document emphasizes preventative measures to strengthen amid ongoing attacks on these critical systems, which handle sensitive organizational communications.

This joint effort comes just weeks after support for older versions of Exchange ends on October 14, 2025. This increases the risks for out-of-date environments.

See also: Proton Data Breach Observatory: Notifies you when your personal data appears on the Dark Web

Microsoft Exchange Servers: What measures can organizations take?

The guide emphasizes the need to adopt a preventative approach, starting with maintenance security update and patch. Administrators are urged to apply the latest Cumulative Updates (CUs) twice a year and monthly security updates/patchesto address the rapid development of exploits by malicious actors.

Tools like Microsoft's Exchange Health Checker and SetupAssist are recommended to verify readiness and facilitate updates , reducing exposure to vulnerabilities over time.

For servers that have reached end-of-life (EOL), immediate migration to Exchange Server Subscription Edition (SE), the only supported on-premises edition, is critical (with interim isolation from the internet if full upgrades are delayed).

Organizations should also ensure they have the Exchange Emergency Mitigation (EM) Service enabled, as it provides automatic protections such as URL Rewrite rules against malicious HTTP requests.

CISA: Security Guide for Microsoft Exchange Servers

CISA: Security Enhancement Guide

Beyond patches, the guidance recommends implementing established security baselines from vendors such as DISA, CIS, and Microsoft (to standardize settings across Exchange, Windows, and mail clients). Enabling built-in defenses such as Microsoft Defender Antivirus, Attack Surface Reduction rules , and application controls such as AppLocker, harden servers against malware and unauthorized execution.

See also: Gentlemen's RaaS: New Platform Advertised on Hacking Forums

Endpoint Detection and Response (EDR) tools are highlighted for advanced threat visibility, while Exchange anti-spam and anti-malware capabilities should be enabled to filter out malicious emails . To strengthen email authentication, organizations should manually implement DMARC, SPF, and DKIM standards , possibly through third-party add-ons or gateways.

Strengthening authentication and encryption is at the core of the recommendations. Configuring Transport Layer Security (TLS), consistently across all servers, prevents data tampering and impersonation, with Extended Protection (EP) added to prevent “adversary-in-the-middle” attacks via channel binding.

Transitioning from the deprecated NTLM to Kerberos and SMB is essential, including auditing the use of legacy versions and preparing for the removal of NTLM.

Modern Authentication with multi-factor authentication (MFA) via Active Directory Federation Services replaces vulnerable Basic Authentication, while certificate-based signing secures PowerShell serialization.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Former US Defense Contractor Executive Sold Exploits to Russia

CISA: Security Guide for Microsoft Exchange Servers

Additional measures include HTTP Strict Transport Security (HSTS) to enforce HTTPS, Download Domains to reduce cross-site request forgery, and role-based access control (RBAC) with separated privileges to enforce least privileged access (restricting administrator access to dedicated workstations). P2 FROM header manipulations detection adds a layer of email spoofing protection.

This guide aligns with principles Zero Trust, promoting deny-by-default access, minimizing attack surfaces, and continuous assessment to protect email integrity.

As Microsoft Exchange Servers remain a prime target, as evidenced by previous exploits, organizations, especially in critical areas, are urged to adopt these best practices to strengthen their security.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS