New security updates for Exchange Server (All versions)

Microsoft has released security updates for Exchange Server today. Specifically, these are the following vulnerabilities: CVE-2019-0817: Microsoft Exchange Spoofing Vulnerability CVE-2019-0858: Microsoft Exchange Spoofing Vulnerability CVE-2019-0817 applies to all currently supported Exchange Server versions (including Exchange 2010). CVE-2019-0858 affects Exchange from version 2013 onwards. Even though the vulnerability is "only" rated as "Important", it ... Read more

Exchange Server Dashboards with ELK (ElasticSearch, Logstash, Kibana) Part 3

In part 2 of this article series, I described the installation of the ELK stack on Debian 9.8. This part is about the configuration of the individual components and the data of the Exchange Server message tracking logs. Introduction In this article, the ElasticStack components and the Exchange Server are configured. This article refers directly to ... Read more

Exchange Server Dashboards with ELK (Elasticsearch, Logstash, Kibana) Part 2

As already announced, I would like to realize dashboards for Exchange Server with Elasticsearch, more precisely, the Elastic Stack (ELK). This part is about the installation of the Elastic Stack on a Debian 9.8 VM. Introduction I have described the installation and configuration in this article so that the environment can be recreated if you are interested. When I ... Read more

Exchange Server Dashboards with ELK (ElasticSearch, Logstash, Kibana) Part 1

Unfortunately, Exchange Server does not offer a build-in option to clearly display the status of the environment or certain performance parameters on a dashboard. Even many monitoring tools quickly reach their limits when it comes to clearly displaying the number of emails received or sent, for example. In this series of articles, I would therefore like to take a look at ELK, or the Elastic Stack ... Read more

Manage Exchange out-of-office notifications centrally

Most users manage the absence notifications themselves via Outlook. Before a planned absence, such as vacation, the user enters the desired message and, if necessary, specifies a deputy. In addition, the helpdesk or a user's line manager should usually also be able to enter an absence notification for users; this is usually useful for an unplanned absence, ... Read more

Windows updates from February 2019 important for Exchange Server

The updates for Windows Server which were released on February 19, 2019 after the regular patchday are also important for Exchange Server running on Windows Server 2016. Specifically, it is about a problem that has existed since September 2018: KB4457127 causes problems on DCs in connection with Exchange KB4457127 causes problems after installation ... Read more

Exchange Server: New updates (February 2019)

New updates have just been released for all supported Exchange Server versions, which also fix the critical vulnerability from CVE-2018-8581. The updates should therefore be installed as soon as possible, as an exploit for this vulnerability has existed for some time. Click here to download the updates for Exchange 2010, 2013 and 2016: Cumulative Update 12 ... Read more

Exchange DAG: Change database and logfile path

It can happen that the paths or the storage location of Exchange databases and log files have to be changed, for example when changing the storage system. This article is in response to a reader's question about how to do this with as little downtime as possible. There are several options for moving the database and log file paths, ... Read more

Active Directory and Exchange Server vulnerable via EWS API

There is currently a security vulnerability in all Exchange Server versions, which makes it possible to obtain domain administrator authorizations via EWS or, for example, to redirect emails. What makes this vulnerability particularly critical is that it can be exploited remotely. The attacker only needs to have access to a mailbox on the Exchange Server. Since the EWS API and often also ... Read more