March 2021 is a very bad month for anyone still exposing on-premises Exchange to the internet. The HAFNIUM-associated ProxyLogon chain and related CVEs turned “we’ll migrate next fiscal year” into an emergency triage: patch, mitigate, isolate, hunt. This post is what we are doing on client estates right now — not a complete forensic manual, but the operational order that keeps bad from becoming worse.
Assume internet-facing Exchange is hostile until proven clean
If OWA/ECP/ActiveSync were reachable from the world, treat the server as potentially compromised until investigation says otherwise. Patching alone is necessary and not always sufficient if attackers already landed.
Order we drive:
- Inventory internet-facing Exchange versions and URLs
- Mitigate / block exposure where patch lags (WAF, publish shutdown, restrict to VPN)
- Patch to fixed builds per Microsoft’s guidance as of today
- Hunt with Microsoft’s IOCs and script guidance — IIS logs, anomalous ASPX, unusual processes
- Credential and cert hygiene — especially if webshell indicators appear
- Plan exit — hybrid-minimal and Online moves accelerate under board pressure
Why hybrid-minimal footprints paid off
Estates that already moved mailboxes to Exchange Online and left a small hybrid anchor had less blast radius: fewer mailbox DBs to distrust, clearer “this server is only for hybrid” scope. Estates running full on-prem DAG farms for everyone are living a longer week.
This is not smugness. It is the bill for delayed migration coming due as a security event.
Patch vs isolate vs accelerate migration
- Patch now even if migration is planned — migration is not a same-day patch
- Isolate legacy Exchange that cannot be patched quickly
- Accelerate Online for remaining mailboxes where identity allows
- Do not open RDP “to fix faster” from the internet
The “last server” conversation
Every hybrid estate eventually asks how long the last Exchange server must live. This month, the answer gains urgency: every extra year of internet-facing Exchange is residual risk. If the server must remain for recipient management or hybrid features, remove it from the open internet and monitor it like tier-0.
Comms to leadership
Speak plainly: widespread exploitation is public; unpatched Exchange is material risk; migration debt is now a security program. Budget for incident response and for migration acceleration as related line items.
Extended practice notes (2021)
The remaining gap between a short checklist and a usable field note is usually scenario detail. In practice, the same engagement type described above still requires explicit answers to: what is in scope this quarter, what is deferred with a date, who can halt a wave, and how success is measured in production — not in a lab.
We document those answers before the first production change. When stakeholders disagree, the disagreement is resolved in writing, not on the bridge at cutover. That habit is independent of whether the workload is mail, identity, virtualization, desktop delivery, or security hardening.
Repeatable detail also includes communication: who tells users what changes, when the freeze starts, where status is posted, and how exceptions are requested. Technical excellence without communication still produces an outage from the user's point of view.
If you're facing this
If you still run on-prem Exchange published to the internet, treat this week as incident response plus strategy, not as a normal CU cycle. We help estates triage ProxyLogon exposure and accelerate hybrid-to-Online paths — bring version inventory and whether OWA is world-reachable.