#MSExchange

dmstorkdmstork
2026-01-28

The only "irritation" I have is that this is the third time something got changed by the Exchange Team HOURS before an important meeting on breaking changes deadlines. COME ON! 😁

Read more: techcommunity.microsoft.com/bl

dmstorkdmstork
2026-01-28

Several hours ago the Team posted an update on the AUTH Basic timeline. To summarize: the original date of disabling the option of March 2026 is now delayed to H2 2027 for existing tenants. Newly created tenants will have to deal with this from December 2026.

Microsoft Exchange logo: an large X in several tints of blue, with in the middle-left a rounded blkue box with the capital letter E in white.
dmstorkdmstork
2025-12-24

Day 24 of . And this concludes yet another run. I hope you found some usefull tips, I had a nasty cold so that might have had an impact. In any case, happy holidays and see you in the next year! And yes, I haven't forgotten that and Start-of-authority blog post ;-)

Michel de Rooij :verified:mderooij@mastodon.cloud
2025-12-15

PSA: EWS block enforcement for Kiosk/Frontline SKUs has been moved back to the end of June xf.ms/NoEWSEnforced #MSExchange #Microsoft365

dmstorkdmstork
2025-12-12

My topic? "IAM and Exchange: Untangling frenemies in Hybrid organizations". The relationship between Identities in Active Directory and Exchange has always tightly integrated, being hybrid made it more complex. I will discuss important IAM considerations designing, managing and moving away from AD.

More info: exchange-summit.de/ or linkedin.com/posts/msexchange-

dmstorkdmstork
2025-12-12

Day 12 of . Short low effort self-plug as I'm a bit under the weather: I'll be speaking (in English) at the excellent in-person event Exchange Summit 2026 in Würzburg, Germany on 24/25 February 2026.

Promotional poster for Exchange Summit 2026 featuring Dave Stork and his talk on IAM and Exchange in hybrid organizations. Event dates: February 24–25, 2026 in Würzburg. Background includes email icons and a laptop with Dave’s photo.
Lukas Sassl :verified:JohnDoe_1987_@infosec.exchange
2025-12-09

We’ve just released Security Updates for #MSExchange Server SE. These updates are also available to customers under the ESU program.

More information: techcommunity.microsoft.com/bl

dmstorkdmstork
2025-12-04

Day 4 of . I always appreciated the idea of Zero-Hour Auto-Purge (ZAP): removing malicious retroactively increasing . It works for and messages, but you needed Defender for O365 Plan 2, but that changes with mc.merill.net/message/MC1187837

Michel de Rooij :verified:mderooij@mastodon.cloud
2025-12-02

Heads-up: EWS blockage for Exchange Online mailboxes with Kiosk/F1/F3 license, which officially do not offer EWS access, will be enforced March 2026 xf.ms/NoEWSEnforced #MSExchange

dmstorkdmstork
2025-12-02

Anyway, on that Start-of-Authority for groups and attributes: Learned a lot of the little things, gotcha's and all. It's really something anyone with a org transitioning to cloud-only needs to look into.

dmstorkdmstork
2025-12-02

Finished a little project removing the last server together with flipping the Start-of-Authority of Group objects and Exchange Attributes. Had to use ADSIEdit to remove some Exchange stuff, made it a bit more interesting šŸ¤“

Michel de Rooij :verified:mderooij@mastodon.cloud
2025-11-17

PSA: Exchange Online Admin API (EWS replacement subset) now available (preview). REST-like alternative for some EWS scenarios, but not full REST replacement; cmdlets still recommended for full functionality techcommunity.microsoft.com/bl #MSExchange #EWS

Stefano Piccospic@nrw.social
2025-10-16

Endlich mal konkrete Infos, von #Outlook zu #Thunderbird und von #MSExchange zu #OpenExchange šŸ‘ winfuture.de/news,154283.html

Lukas Sassl :verified:JohnDoe_1987_@infosec.exchange
2025-10-14

We’ve just released security updates for #MSExchange Server 2016-SE. These updates are the last publicly available SUs for Exchange Server 2016 and 2019.

Learn more: techcommunity.microsoft.com/bl

Michel de Rooij :verified:mderooij@mastodon.cloud
2025-10-09

Hybrid Exchange issues with Free/Busy? It's planned nudge day 3 of 3. Test-OAuthConnectivity likely shows 403 error, eg running (mix with) Exchange with pre-April patch levels. Affected? Act soon, permanent after EoM! bit.ly/ETOSecChanges #MSExchange

šŸ‡¬šŸ‡± KielKontrovers Blogkielkontrovers@norden.social
2025-09-24

MS Exchange gibt es seit 1996. SMTP gibt es seit 1982. Microsoft adaptierte die Technologie und zwang Firmen ihre Server auf. Im Internet spielt #MSExchange kaum eine Rolle. Fast 90% sind Open Source. Exchange kennt man primƤr daher, wenn mal Probleme mit Mailservern auftreten. Und dann bekommt man kryptische Fehlermeldungen, die nicht-standard SMTP sind. Das Krisenmanagement der Landesregierung ist aber schlecht. Der Weg aber richtig. Weg vom Monopol hin zu Standards .

dmstorkdmstork
2025-09-23

BTW: from October 1st new Accepted Domains will automatically use the new MX infrastructure, which will maken enabling DANE a little less of a hassle as there should be no change in your MX record. See MC1048624 or mc.merill.net/message/MC1048624

dmstorkdmstork
2025-09-23

You must enable DANE on your domain as this change is currently only present on the new mx.microsoft infrastructure. Currently for existing accepted domains this is the way to transition to the new infrastructure, although eventually new accepted domains will use this automatically (you do still need to enable DNSSEC & DANE). See more on DANE here learn.microsoft.com/en-us/purv

dmstorkdmstork
2025-09-23

Although for hosted services you do not have control over their certificate management, however I would find it reassuring if such a service would implement CAA. And: Since a few days Online now has CAA records!

dmstorkdmstork
2025-09-23

With upcoming changes in the maximum validity period of certificates (max 200 days in 2026, 100 in 2027, 47 in 2029) the use of ACME (Automated Certificate Management Environment) will certainly increase. The addition of CAA and combination with ACME is another layer in your security stack. It's recommended for Dutch governments.

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst