Experience Stellar's software with confidence! 100% safe to download.
Free Download For Windows

Email Repair

How to Use Exchange Emergency Mitigation Service?

Summary:In this article we will be discussing the Exchange Emergency Mitigation (EM) Service. This service will assist you in the application of fixes to mitigate any vulnerabilities in your Exchange Server. We will also be discussing how to recover from a possible attack and recover data from a vulnerable or failed server due to an attack.

Free Download For Windows
Free Download For Windows

尽管你可能交换最新的版本n and all the Cumulative Updates (CU) installed, your Exchange Server might still be at risk of some potential threats in the wild. So, you need to make sure that your Exchange Servers are locked down and secure, especially when the Exchange Server connects to the internet for incoming and outgoing messages. To help you secure your Exchange Servers from such threats, Microsoft offers theExchange Emergency Mitigation (EM) Service. Below, we will be discussing the Exchange Emergency Mitigation (EM) service in detail and how to use it.

About the Exchange Emergency Mitigation Service

The Exchange Emergency Mitigation Service helps you tomitigate vulnerabilitieson your server and secure it as much as possible from any known vulnerabilities. Normally, these mitigations are implemented by a Security Administrator but Microsoft offers this service to automatically configure and enforce these mitigations. Mitigations which are of a general scale will be automatically applied. The service consists of a set of actions which are automatically applied on a server where such configurations are found to be of risk.

The service is not an update installer. So, updates such as security orinstalling cumulative updates (CU)need to be installed manually by the administrator of the server. This is because if something goes wrong with the installation, it may lead to the server failure. The service works on the following features:

  • IIS URL Rewrite Rules –Mitigations will block specific maliciousHTTPrequests which are coming to the server.
  • Exchange Service –这将自动禁用任何服务is eitherdeprecatedorrisky.
  • App Pool– This will go through the app pools in IIS which are related to Exchange anddisablethem if considered as risky.

It fixes mitigations, like the EEMS heartbeat probe andCVE-2022-41040in the URL rewrite engine.

How to Use the Exchange Emergency Mitigation Service?

To use the Exchange Emergency Mitigation (EM) service, you need to install it on a mailbox server. You will not be able to use it on an Edge Server. You need to have at least the September 2021 (CU) update on anExchange Server 2016or later, or have theExchange Server 2019installed. You will not be able to check for vulnerabilities on Edge Server with this.

Apart from this, the IIS installed needs to have the IIS URL Rewrite Model. The operating system should also have theUniversal C Runtime for Windows (KB2999226).

Since this is a cloud service, you need some connectivity requirements. You need to haveaccess to officeclient.microsoft.com/*onport 443. If your Exchange Server is behind a proxy, you need to execute the following commands to make the Exchange Server pass through the proxy.

Set-ExchangeServer -Identity /server name="" -InternetWebProxy /proxy server="" address:port="" /proxy=""

netsh winhttp set proxy /proxy server="" address:port="" /proxy

Before using the service, you need to also confirm that connectivity is successful. In theV15/Scripts, execute theTest-MitigationServiceConnectivity.ps1.

The output from PowerShell should be similar to the given below.

access to officeclient.microsoft.com

The service can apply such mitigations automatically. Sometimes, this may cause unnecessary downtime or issues. You can disable the automatic mitigation by running the below command.

Set-OrganizationConfig -Identity /server name="" -MitigationsEnabled $false /server

Set-OrganizationConfig

By default, this is set to true.

To view any applied mitigations, you can use the below command.

Get-ExchangeServer -Identity /server name=""/ | Format-List Name,MitigationsApplied

view any applied mitigations

This will show all the applied mitigations on the specified server.

If you want to roll back a mitigation applied on a specific server as it is causing system failure or stopping a functionality, you can use the following command. This willrestartthe service and eventuallyre-apply the mitigation.

Restart-Service MSExchangeMitigation

After ten minutes of the restart of the service, it will check for applied mitigations andre-applythem automatically. If for a reason something breaks, you can either remove or block the mitigation to be applied. To block a mitigation, you need to use the following command with the ID of the mitigation.

Set-ExchangeServer -Identity /server name=""/ -MitigationsBlocked @("id")

MitigationsBlocked

Once the issue is resolved, you can reapply the blocked mitigation by running the following command and then restart the service.

Set-ExchangeServer -Identity /server name=""/ -MitigationsBlocked @()

In case you want to view both the applied and blocked mitigations, you can run the following command.

Get-ExchangeServer | Format-List Name,MitigationsApplied,MitigationsBlocked

view both the applied and blocked mitigations

To get the full details of the applied mitigations, you can run the following command.

.\Get-Mitigations.ps1 -Identity /server name=""/ /server

get the full details of the applied mitigations

You can see all the changes and information on the service in the Event Viewer where the source would be “MSExchange Mitigation Service”.

What if a disaster strikes?

If your Exchange Server suffers a malware or ransomware attack, then this will leave your Exchange Server inaccessible. Also, the transaction logs get damaged and you will be unable to mount the databases. In this case, you can re-install the Exchange Server. However, you will not be able to reinstate or recover the data if the database or transaction logs are damaged and corrupted.Recover Exchange Serverfrom backup is not an option as this would result in data loss.

This is where applications, likeStellar Repair for Exchangecan assist you. It is a leading application for Exchange database recovery. It allows you to open multiple EDB files (healthy or damaged) from any version of Exchange Server, with no size limit. You can easily browse through the database files and granularly export the data to PST and other file formats. You can also export the EDB data directly to a live Exchange Server database or Office 365 tenant. You can process user mailboxes, shared mailboxes, disabled mailboxes, user archives, and even public folders.

progress
76% of people found this article helpful

WHY STELLAR®IS GLOBAL LEADER

Why Choose Stellar?
  • 0M+

    Customers

  • 0+

    Years of Excellence

  • 0+

    R&D Engineers

  • 0+

    Countries

  • 0+

    PARTNERS

  • 0+

    Awards Received

  • TUV SUD ISO 27001
  • TUV SUD ISO 9001
  • NIST
  • HIPAA Verified