Microsoft has announced a major shift in its cloud mail flow enforcement policy, setting stricter security standards for enterprise hybrid environments. Starting in the second week of September, Exchange Online will begin throttling email traffic originating from outdated local Exchange servers that fail to meet minimum patching requirements.

The updated policy primarily targets hybrid deployments running legacy platforms that lack the final set of public security fixes. IT administrators who do not update their infrastructure face delayed message delivery and eventual communication lockouts.

Microsoft Enforces New Minimum Security Baseline for Exchange Online

Microsoft is stepping up its transport-based enforcement mechanism to safeguard cloud infrastructure against persistent vulnerabilities found in unpatched on-premises systems. Under the refreshed policy, Exchange Online will enforce a mandatory update baseline for on-premises systems communicating via hybrid inbound connectors. To maintain uninterrupted mail delivery, organizations must have their local installations patched at least to the final public security update baseline released in October 2025.

Specifically, the minimum required levels are Security Update for Exchange Server 2019 CU15 SU5 (KB5066367) and Security Update for Exchange Server 2016 CU23 SU19 (KB5066369). Any server delivering messages through an on-premises inbound connector while running a build below these releases will be flagged by the transport enforcement system. This escalation reflects Microsoft's broader strategy to push organizations toward modern security practices. Recent security initiatives, such as automatically enabling Memory Integrity across enterprise endpoints, demonstrate a company-wide effort to reduce vulnerability vectors at every operational tier.

Throttling and Rejection Timeline for Legacy Exchange Servers

The enforcement process is structured into distinct phases designed to alert administrators before severe disruptions occur. When an outdated server attempts to deliver mail to an Exchange Online recipient, the cloud system initiates a series of graduated responses:

  • Reporting Phase: Outdated servers appear in the Mail Flow report within the Exchange Admin Center, allowing IT staff to spot non-compliant infrastructure.
  • Throttling Phase: Exchange Online deliberately delays email delivery by returning temporary SMTP 450 4.7.230 errors. Initially starting with brief delay windows each hour, the throttling gradually expands over several weeks if the underlying issue remains unaddressed.
  • Blocking Phase: If the server remains unpatched, Exchange Online progresses to full message rejection, generating permanent SMTP 550 5.7.230 Non-Delivery Reports (NDRs). Affected emails will fail to reach Microsoft 365 inboxes entirely.

To help administrators manage emergency remediations, Microsoft allows tenants to pause enforcement once per calendar year for up to 90 days using the Exchange Admin Center or PowerShell.

Why Transport-Based Enforcement Is Escalating

The decision to mandate the October 2025 security baseline stems from the high volume of automated attacks aimed at on-premises email infrastructure. Historically, threat actors have targeted exposed Exchange servers to establish persistence and compromise connected cloud environments. To mitigate these risks, Microsoft introduced its transport enforcement system to systematically sever vulnerable entry points.

Because Exchange Server 2016 and 2019 reached their official end-of-support milestone on October 14, 2025, public security updates for these legacy versions have ceased. By requiring the final public updates, Microsoft aims to ensure that no enterprise retains known unpatched flaws on active hybrid mail routes. As threat actors refine automated exploitation toolchains, securing underlying communication protocols is critical. Similar defensive strategies are evident across Microsoft's ecosystem, from combating malicious software designed to bypass security controls to improving system stability through driver verification.

Impact on Hybrid Deployments Running Exchange 2016 and 2019

This policy change directly impacts organizations operating hybrid mail topologies. Organizations relying on local Exchange servers strictly for management tasks or internal routing without active hybrid connectors to Exchange Online remain unaffected for now. However, enterprise environments where hybrid routing handles cross-boundary communication must audit their transport endpoints immediately.

In many enterprise setups, custom line-of-business applications and automated reporting systems route mail through local Exchange connectors before reaching the cloud. If those underlying local servers are operating on outdated builds, critical business notifications could experience severe delays or permanent failure during the September rollout.

Required Actions for IT Administrators

System administrators must audit all on-premises Exchange servers communicating with Microsoft 365. Microsoft provides dedicated diagnostic reports inside the Exchange Admin Center under the Mail Flow section, highlighting non-compliant servers currently making outbound connections.

IT teams should perform the following steps immediately:

  1. Review the Mail Flow report in the Exchange Admin Center to identify flagged on-premises IP addresses and server names.
  2. Apply the October 2025 Security Updates across all Exchange 2016 and 2019 edge and transport servers.
  3. Verify that inbound connector configurations match Microsoft Zero Trust recommendations.
  4. If immediate patching is not feasible due to change-control freezes, request an Enforcement Pause via PowerShell or the EAC to buy up to 90 days of operational buffer.

Proactive maintenance remains essential for system reliability. Just as enterprise teams prepare infrastructure for software migrations or optimize workstation footprints through developer toolchain updates, keeping core communication channels updated prevents sudden service outages.

Upgrading Security Baselines and Migration Paths

Because public support for Exchange 2016 and 2019 has ended, maintaining compliance beyond current baselines will require long-term planning. Microsoft has signaled that future minimum version requirements may eventually exceed the last free, publicly available security updates.

To remain compliant without incurring transport blocks, organizations have two main upgrade paths:

  • Extended Security Updates (ESU): Purchase ESU coverage for Exchange 2016 or 2019 to receive ongoing security updates that satisfy cloud transport requirements.
  • Migrate to Exchange Server Subscription Edition (SE): Upgrade local infrastructure to Exchange Server SE. Exchange SE offers a streamlined in-place upgrade path for servers running Exchange 2019 CU14 or CU15, allowing organizations to maintain on-premises hybrid features under a modern servicing model.

Alternatively, organizations can eliminate local server maintenance altogether by decommissioning on-premises Exchange servers and migrating remaining mailboxes and management roles directly to Exchange Online. As Microsoft expands cloud management capabilities, reducing local server footprints is becoming the standard approach for enterprise IT.

Closing Summary

Microsoft's September rollout of stricter Exchange Online transport controls marks an important enforcement deadline for hybrid email environments. By throttling and blocking traffic from servers lacking the October 2025 security baseline, Microsoft is reinforcing Zero Trust security policies across cloud boundaries. Organizations running Exchange 2016 or 2019 should inspect their build numbers, apply necessary patches, and formulate long-term migration strategies to ensure continuous, uninterrupted email delivery.