logo

Microsoft Exchange update enables Extended Protection by default

ID: 1547514e-cd7d-5eda-9b4f-4e956c30f4d5

STIX ID: report--1547514e-cd7d-5eda-9b4f-4e956c30f4d5

Feed Name: Bleeping Computer

Threat Score
45/100

Date Published: 2024-02-14

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Microsoft will automatically enable Windows Extended Protection (EP) by default when installing Exchange Server 2019 CU14 (and later) to harden authentication against NTLM relay and MitM attacks (including mitigation tied to CVE-2024-21410 and prior CVEs). Administrators are advised to evaluate environment compatibility (e.g., SSL bridging, TLS mismatches), review and use the ExchangeExtendedProtectionManagement PowerShell script to enable/disable EP as needed, and may opt out during setup with provided switches if EP causes functionality issues.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.