The first priority is to reduce exposure while waiting for a patch. Security teams should follow Microsoft’s mitigation guidance, especially blocking exposed Remote PowerShell ports, then verify whether Outlook Web App is internet-facing and whether that exposure is still required. If hybrid migration was involved, confirm on-premises Exchange servers were actually taken offline. Fast exposure reduction matters most when remediation is unavailable.
Reduce exposure first, because patching is not the first control available
When a zero-day is already being exploited against on-premises Exchange, the first move is to shrink the attack surface before you wait on a fix. The practical priority is to remove or constrain the most exposed paths, then confirm whether the affected servers are still internet-reachable. That is especially important when the compromise path depends on remote management or web-facing services.
The key decision is to treat exposure reduction as an emergency containment step, not as a routine hardening task. If the vulnerable service is still reachable from the internet, the attacker can keep using it while remediation is pending, so the team should act on reachability first and verification second.
- Block exposed Remote PowerShell access where Microsoft’s guidance allows it.
- Check whether Outlook Web App is internet-facing and whether that exposure is still required.
- Confirm whether any hybrid Exchange servers were truly retired, rather than assumed offline.
What to verify before you assume the environment is contained
For Exchange zero-days, the first question is not only whether a patch exists, but whether the deployed configuration still provides an attacker with a live path in. Internet-facing OWA, remote administration endpoints, and residual hybrid dependencies can leave a server exploitable even after teams believe they have reduced risk.
This is why validation matters as much as mitigation. Security teams should verify the actual network exposure, the current administrative pathways, and the operational status of any server that was supposed to be taken out of service. A mitigation that is only documented, but not enforced, does not stop active exploitation.
- Confirm the exact services still reachable externally.
- Validate that any hybrid migration cleanup actually removed the old on-premises role from production use.
- Re-check after changes, because a stale firewall rule or forgotten reverse proxy can restore exposure.
Risk and Threat Considerations
Active exploitation changes the priority from normalization to containment. The main risk is that exposed Exchange endpoints remain available long enough for adversaries to continue intrusion, harvest mail data, or pivot into adjacent systems while the organisation waits for vendor remediation.
Failure mechanism: Publicly reachable Exchange services, especially web-facing or remote administration paths, preserve a valid attack surface during the period when no patch is yet available. If hybrid components were not fully decommissioned, a supposedly retired server can still function as an attack entry point.
Impact: Continued exploitation can lead to mailbox compromise, persistence, lateral movement, and broader enterprise exposure, so exposure reduction is the fastest way to limit blast radius before full remediation is possible.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8, NIST CSF 2.0, NIST SP 800-63 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS Control 4 — Secure Configuration of Enterprise Assets and Software | Exchange exposure reduction depends on removing or constraining externally reachable services and weak configurations. |
| CIS Control 12 — Network Infrastructure Management | Blocking Remote PowerShell and validating internet-facing OWA are network exposure decisions. | |
| Recommendation — Harden exposed Exchange services and disable unnecessary remote administration paths. Restrict public access to Exchange management and web endpoints. | ||
| NIST CSF 2.0 | PR.AC-3 — Remote Access Is Managed | Active Exchange exploitation is reduced by tightly managing remote administrative access. |
| PR.PT-3 — Least Functionality Is Applied | The answer centers on removing unnecessary exposed services before remediation is available. | |
| DE.CM-1 — Networks and Network Services Are Monitored | Teams must verify whether Exchange remains internet-facing and whether mitigation actually took effect. | |
| Recommendation — Limit remote administrative access to only approved, monitored paths. Disable unneeded Exchange-facing services until exposure is confirmed necessary. Monitor external reachability of Exchange services during containment. | ||
| NIST SP 800-63 | IAL — Identity Assurance Level | Exchange remote administration exposes privileged access paths that require strong identity verification and control. |
| Recommendation — Require stronger assurance for any remaining administrative access path. | ||
| NIST Zero Trust (SP 800-207) | PDP/PEP — Policy Decision Point / Policy Enforcement Point | Blocking exposed endpoints aligns with enforcing access decisions at the boundary during active exploitation. |
| Recommendation — Enforce access decisions at the network boundary for Exchange management traffic. | ||
Practitioner Guidance
What to prioritise: Treat the mitigation guidance as an ordered containment playbook, not a checklist of equal options. If Remote PowerShell is exposed, that is a high-priority reduction step because it preserves administrative access paths while the zero-day is active.
What to verify: Do not trust migration records or decommissioning tickets by themselves. Verify from the network side that OWA is not unnecessarily internet-facing and that any on-premises Exchange server in a hybrid design is actually offline or isolated.
Practitioner takeaway: When exploitation is already happening, the fastest risk reduction comes from eliminating reachable attack paths first, then moving to patching, recovery, and post-exposure review.
Related resources from NHI Mgmt Group
- How should security teams protect Exchange Server admin access against credential abuse during zero-day exploitation?
- How should security teams defend CI/CD pipelines against zero-day exploits in dependencies and build steps?
- How should security teams harden a secrets manager against zero-day exploitation when patching is not enough?
- How should security teams defend browsers against AI-generated zero-day exploits that change during execution?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 19, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org