Exchange Server and Office 365: Access to attachments and images possible without authentication

Under certain circumstances, Microsoft Office 365 and Exchange Server allow access to attachments and images in emails without the need for authentication. In most cases it should be difficult to exploit this problem, but reader L. Herzog writes to me that this problem could be exploited in his environment. L. Herzog has ... Read more

Microsoft deactivates Basic-Auth on 01.10.2022

Microsoft announced some time ago that Basic-Auth (standard authentication) will be deactivated in all tenants for the MAPIoverHTTP, EWS, POP, IMAP and ActiveSync protocols in Exchange Online from October 1, 2022. From October 1, 2022, it will therefore no longer be possible to use Basic-Auth (transmission of user name and password via HTTPS) in Exchange Online for ... Read more

Microsoft 365: Automatically assign a license to users

If user accounts are synchronized using Azure AD Connect, no Microsoft 365 (formerly Office 365) license is assigned by default. In the default setting, a corresponding license must therefore be assigned manually so that the users can use the Microsoft 365 services. However, this process can also be carried out automatically. So that users are automatically assigned a Microsoft ... Read more

Exchange Server: Determine TLS versions of servers / clients

In this article, I already pointed out that Office 365 will only support TLS 1.2 from October 2018. However, before switching to the current TLS 1.2 version, the clients / servers with which the local Exchange server does not yet communicate via TLS 1.2 should be identified. The following small script can be used ... Read more

Exchange Server and TLS 1.2

Three detailed articles on Exchange Server and TLS 1.2 have been published on the Exchange Team Blog. The articles are not only very worth reading, but also have an important background: From October 2018, Office 365 will require TLS 1.2 and will not accept mails from servers that only support TLS 1.0 or TLS 1.1. In plain language ... Read more

Exchange 2016: Hybrid mode with Office 365 (part 4)

This is the fourth part of the series "Exchange 2016 Hybrid Mode with Office 365". In this part, Exchange Hybrid Mode is activated and initial tests are carried out. Here are the links to the previous articles: Exchange 2016: Hybrid Mode with Office 365 (Part 1) Exchange 2016: Hybrid Mode with Office 365 (Part 2) Exchange 2016: ... Read more

Exchange 2016: Hybrid mode with Office 365 (part 3)

This is the third part of the series "Exchange 2016 Hybrid Mode with Office 365". This part deals with the synchronization of local user accounts to Office 365 or Azure Active Directory. Here are the links to the previous articles: Exchange 2016: Hybrid mode with Office 365 (Part 1) Exchange 2016: Hybrid mode with Office ... Read more

Caution: New limits for Office 365 / Exchange Online

As a side note, new limits will be introduced in Exchange Online and therefore also in Office 365 from 01.06.2018. Specifically, these are new limits for authenticated SMTP connections (SMTP Authenticated submission): Sent mails will be saved in the "Sent items" folder of the mailbox Only three simultaneous connections per mailbox are now permitted Depending on the configuration ... Read more