Story perspectives
New Cybersecurity Guidelines to Secure Microsoft Exchange Servers
11/4/2025
1 of 1
Story summary
- Cybersecurity agencies from the United States, Australia, and Canada released new guidance to strengthen on-premise Microsoft Exchange servers.
- The guidance notes threats from misconfigured or outdated installations and emphasizes timely patching.
- It recommends implementing multi-factor authentication.
- It also calls for restricting administrative access, upgrading to supported Exchange versions, and adopting a zero-trust security model.
- Organizations should consider cloud-based email services to reduce risks from managing their own servers.
