fromComputerworld
3 days agoCyber agencies produce 'long overdue' best practices for securing Microsoft Exchange Server
The guidance states admins should treat on-prem Exchange servers as being "under imminent threat," and itemizes key practices for admins: First, it notes, "the most effective defense against exploitation is ensuring all Exchange servers are running the latest version and Cumulative Update (CU)"; It points out that Microsoft Exchange Server Subscription Edition (SE) is the sole supported on-premises version of Exchange, since Microsoft ended support for previous versions on October 14, 2025; It urges admins to ensure Microsoft's Emergency Mitigation Service remains enabled for delivery of interim mitigations; Maintaining a security baseline enables administrators to identify non-conforming systems and those with incorrect security configurations, as well as allowing them to perform rapid remediation that reduces the attack surface available to an adversary;
Information security