QG Professional Services
- Cybersecurity
- Microsoft & Cloud
Exchange hybrid deployments (an on-premises Exchange server coexisting with Exchange Online) are extremely common, usually a migration waypoint that quietly became permanent. They are also a security liability that CISA has escalated guidance on, because the trust relationship that makes hybrid work is precisely what attackers exploit: a compromise of the on-premises Exchange server can pivot into the connected Microsoft 365 tenant. If you have an Exchange server still on-premises "just for hybrid," this concerns you directly.
Here is the risk and the hardening path.
Why hybrid is a security problem
The value of Exchange hybrid (seamless coexistence, shared address book, cross-environment calendaring) comes from a trust relationship between your on-premises Exchange and your cloud tenant. Historically, that trust ran through a shared service principal: on-premises Exchange and Exchange Online authenticated to each other through a shared identity in Entra ID. This is efficient and, as designed, dangerous: because it means the on-premises server holds credentials that are trusted by the cloud.
Add the reality that on-premises Exchange has been a persistent, high-value target (ProxyLogon, ProxyShell and successors), and the picture is stark: an internet-facing Exchange server is one of the most attacked assets in enterprise IT, and in a legacy hybrid configuration compromising it can extend into the cloud tenant. The on-premises box is not just a mail server: it is a foothold with a trust path into Microsoft 365.
The CVE-2025-53786 shared-identity issue
This is the specific problem behind the recent CISA urgency. The vulnerability concerns exactly the shared-service-principal trust model: in affected hybrid configurations, an attacker with control of the on-premises Exchange server could potentially escalate into the connected Exchange Online environment through the shared identity, in ways that are difficult to detect from the cloud side. Microsoft's remediation moves hybrid authentication to a dedicated hybrid application model: a distinct identity for the hybrid connection, so a compromised on-premises server no longer holds a shared key to the cloud.
CISA's guidance to affected organisations was unambiguous and time-bound. Emergency Directive ED 25-02, issued in August 2025, required federal civilian agencies to implement mitigations within days, and CISA urged every other organisation to do the same.
The support deadline that changes the calculation
There is a second date that matters at least as much, and it has already passed. Exchange Server 2016 and Exchange Server 2019 reached end of support on 14 October 2025. Paid Extended Security Updates were available only through 14 April 2026. Both dates are now behind us.
The implication is blunt: if you are still running Exchange 2016 or 2019 on-premises for hybrid, you are running an internet-exposed, historically heavily-targeted server that receives no security updates. The remaining supported on-premises option is Exchange Server Subscription Edition, which is a migration project in its own right. So the choice is no longer "patch or migrate" — it is "migrate to Exchange Server SE, or complete the move to Exchange Online and decommission". For most organisations still hybrid only because a migration stalled, the second is both cheaper and permanent.
The hardening programme
- Inventory and establish your support position. Confirm whether you run Exchange hybrid at all (many organisations forgot they still do), and identify the exact version and build. If it is 2016 or 2019, you are unsupported: that is the finding, and it outranks the patch level. Remove any Exchange servers no longer needed — the most-attacked server is the one you can decommission.
- Migrate to the dedicated hybrid application. Move off the shared service principal to the dedicated hybrid-app model per Microsoft's guidance. This is the specific fix for the shared-identity escalation path, and it is not optional if you are staying hybrid.
- Reduce the attack surface. Restrict and monitor access to on-premises Exchange, ensure it is not needlessly internet-exposed, and apply the current hardening baselines. Every service on that box that faces the internet is a door.
- Graph API readiness. As Microsoft retires legacy protocols, ensuring hybrid and integration components use current, supported authentication (Graph rather than deprecated APIs) closes another class of exposure.
- Then ask the real question: why are you still hybrid? For most organisations, hybrid was a migration stage, not a destination. The durable fix is completing the migration to Exchange Online and decommissioning on-premises Exchange entirely: you cannot compromise a server that no longer exists.
The strategic point
Hybrid hardening is worth doing immediately because the exposure is live. But hardening a permanent-hybrid posture is treating the symptom. The organisations carrying the most risk here are those where "temporary" hybrid has run for years with an unpatched, internet-facing Exchange server nobody owns. Completing the cloud migration removes the entire attack class (the shared-identity path, the on-premises target, the patch treadmill) at once. Pair the urgent hardening with a real decommissioning plan.
Practical steps
Confirm today whether you run Exchange hybrid and whether that server is patched to current: if nobody can answer immediately, that uncertainty is itself the finding. Apply Microsoft's updates and migrate to the dedicated hybrid app on CISA's timeline. Then scope decommissioning. QG runs CISA/NSA-aligned Exchange hybrid hardening (dedicated hybrid-app migration, CVE-2025-53786 mitigation and Graph API readiness) as a productised programme, and completes the underlying Exchange Online migration that makes the exposure permanent-past-tense.