Try our new Certificate Revocation List Check Tool
CRLcheck.exe is a tool developed to verify digital signatures of executable files. It collects files from known paths on your client, checks their signature, and checks Certificate Revocation Lists (CRL) and OCSP download. This helps avoid delays in launching files.
Category published:  Exchange 2013 M365,AZURE,INTUNE   Click on the Category button to get more articles regarding that product.

Microsoft M365 O365 EXO throttles Exchange 2013 in HYBRID Exchange server version is out-of-date

Posted by admin on 04.03.2024

 

Microsoft M365 O365 EXO throttles Exchange 2013 in HYBRID Mode, Queue is growing

SMTP ERROR: Connecting Exchange server version is out-of-date

Since December 2023, Microsoft has been throttling or blocking on-premises Exchange 2013 servers that are in Hybrid Mode, connecting to their cloud environment. Even if 99% of the mailboxes are already in the cloud, it appears that this action may be a response to a security incident involving a mailbox from DEV internally last year.

• You are in Full Classic Hybrid Mode with Exchange 2013 and M365/O365/EXO.

• You may notice the queue on Exchange 2013 growing.

• You will be able to PAUSE that limitation/throttle for a maximum of 90 days.

 

Well, Microsoft finally forces us now to migrate everything and all. Partner may be stuck in migrations because of tjird party problems or compliance or because the do not trust the security AV/SPAM Flters of MS and keep that on-premises. They Exchange 2013 was isolated highly and allways secured with 2-.Form authentication since years.

There has always been throttling in Exchange on-premises, but this appears to be more of a rate or reputation-based IP/Partner rating, similar to services like FortiMail and others. We had not noticed this until 12.02.2024 this year and this i a high volume customer, We did a Public Folder Migration around that time to ginally demote the server so this may have triggered it.

In their statement in May 2023 the did only mention Exchnage 2007:

“Which versions of Exchange Server are affected by the enforcement system? Initially, only servers running Exchange Server 2007 that send mail to Exchange Online over an inbound connector type of OnPremises will be affected. Eventually, all versions of Exchange Server will be affected by the enforcement system, regardless of how they connect to Exchange Online.”

 

4.7.230 Connecting Exchange server version is out-of-date; connection to Exchange Online throttled for n mins/hr.

5.7.230 Connecting Exchange server version is out-of-date; connection to Exchange Online blocked for n mins/hr.

Last Error: 450 4.7.230 Connecting Exchange server version is out-of-date; connection to Exchange Online throttled for 20 mins/hr. For more information see https://aka.ms/ExchangeBuildCompliance. [ZR****16.eop-che01.prod.protection.outlook.com 2024-03-04T11:00:23.460Z 08DC3C2CC9670EBC]

 

On Exchange 2013 Hybrid Queue Viewer


Out-of-date connecting on-premises Exchange servers

To avoid mail delays or rejections, keep your on-premises Exchange servers up-to-date with the latest supported version (Exchange 2016 or 2019) and security update (published here). For security reasons, after a grace period, Exchange Online will throttle and/or block out-of-date Exchange servers sending mail over an inbound connector of type OnPremises.

See the affected servers and suggested actions below, or run the Exchange Online Powershell cmdlet Get-OnPremServerReportInfo. You can also create or extend an enforcement pause by running New-TenantExemptionInfo -BlockingScenario UnpatchedOnPremServer -NumberOfDays.

Powershell (Did not work for us):

Get-OnPremServerReportInfo


Or check in Exchange Admin Center

Reports > Mail flow > Out-of-date connecting on-premises Exchange servers

 

Open throttle for 30-90 days in Powerrshell or GUI (Powershell did not work on 04.03.2024, GUI M365 Console did work)

New-TenantExemptionInfo -BlockingScenario UnpatchedOnPremServer -NumberOfDays 90



 

 




 

 

https://techcommunity.microsoft.com/t5/exchange-team-blog/throttling-and-blocking-email-from-persistently-vulnerable/ba-p/3815328

 

 

 


 Category published:  Exchange 2013 M365,AZURE,INTUNE   Click on the Category button to get more articles regarding that product.