In response to growing threats to email infrastructure, the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), the Australian Cybersecurity Centre (ACSC), and the Canadian Cybersecurity Centre have published a comprehensive guideoutlining best practices for securing on-premises Microsoft Exchange Servers.

Titled “Microsoft Exchange Server Security Best Practices,” the document emphasizes preventative measures to strengthen amid ongoing attacks on these critical systems, which handle sensitive organizational communications.
This joint effort comes just weeks after support for older versions of Exchange ends on October 14, 2025. This increases the risks for out-of-date environments.
See also: Proton Data Breach Observatory: Notifies you when your personal data appears on the Dark Web
Microsoft Exchange Servers: What measures can organizations take?
The guide emphasizes the need to adopt a preventative approach, starting with maintenance security update and patch. Administrators are urged to apply the latest Cumulative Updates (CUs) twice a year and monthly security updates/patchesto address the rapid development of exploits by malicious actors.
Tools like Microsoft's Exchange Health Checker and SetupAssist are recommended to verify readiness and facilitate updates , reducing exposure to vulnerabilities over time.
For servers that have reached end-of-life (EOL), immediate migration to Exchange Server Subscription Edition (SE), the only supported on-premises edition, is critical (with interim isolation from the internet if full upgrades are delayed).
Organizations should also ensure they have the Exchange Emergency Mitigation (EM) Service enabled, as it provides automatic protections such as URL Rewrite rules against malicious HTTP requests.

CISA: Security Enhancement Guide
Beyond patches, the guidance recommends implementing established security baselines from vendors such as DISA, CIS, and Microsoft (to standardize settings across Exchange, Windows, and mail clients). Enabling built-in defenses such as Microsoft Defender Antivirus, Attack Surface Reduction rules , and application controls such as AppLocker, harden servers against malware and unauthorized execution.
See also: Gentlemen's RaaS: New Platform Advertised on Hacking Forums
Endpoint Detection and Response (EDR) tools are highlighted for advanced threat visibility, while Exchange anti-spam and anti-malware capabilities should be enabled to filter out malicious emails . To strengthen email authentication, organizations should manually implement DMARC, SPF, and DKIM standards , possibly through third-party add-ons or gateways.
Strengthening authentication and encryption is at the core of the recommendations. Configuring Transport Layer Security (TLS), consistently across all servers, prevents data tampering and impersonation, with Extended Protection (EP) added to prevent “adversary-in-the-middle” attacks via channel binding.
Transitioning from the deprecated NTLM to Kerberos and SMB is essential, including auditing the use of legacy versions and preparing for the removal of NTLM.
Modern Authentication with multi-factor authentication (MFA) via Active Directory Federation Services replaces vulnerable Basic Authentication, while certificate-based signing secures PowerShell serialization.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Former US Defense Contractor Executive Sold Exploits to Russia

Additional measures include HTTP Strict Transport Security (HSTS) to enforce HTTPS, Download Domains to reduce cross-site request forgery, and role-based access control (RBAC) with separated privileges to enforce least privileged access (restricting administrator access to dedicated workstations). P2 FROM header manipulations detection adds a layer of email spoofing protection.
This guide aligns with principles Zero Trust, promoting deny-by-default access, minimizing attack surfaces, and continuous assessment to protect email integrity.
As Microsoft Exchange Servers remain a prime target, as evidenced by previous exploits, organizations, especially in critical areas, are urged to adopt these best practices to strengthen their security.
