
"Microsoft Exchange Update: Extended Protection Enabled by Default"
Microsoft is automatically enabling Extended Protection (EP) on Exchange servers after installing the 2024 H1 Cumulative Update, aiming to strengthen Windows Server authentication functionality and mitigate authentication relay and man-in-the-middle attacks. Admins are advised to evaluate their environments and review documentation before toggling EP on their servers, with the option to use a provided PowerShell script to manage EP. Microsoft also released a decision flow graph to assist in enabling EP. This move follows the company's previous recommendations to keep Exchange servers up-to-date and ready to deploy emergency security patches.
