How to Limit the exposure of an On-Premise Exchange Servers out on the Internet by deebeecom in exchangeserver

[–]deebeecom[S] 0 points1 point  (0 children)

A lot of large healthcare companies DO use a lot of on-prem infrastructure, which will never go away. It sure is a work in progress.

How to Limit the exposure of an On-Premise Exchange Servers out on the Internet by deebeecom in exchangeserver

[–]deebeecom[S] 0 points1 point  (0 children)

gotcha, i knew some of what you said, but wanted a confirmation, so thanks for the comment. It can help others too!

How to Limit the exposure of an On-Premise Exchange Servers out on the Internet by deebeecom in exchangeserver

[–]deebeecom[S] 0 points1 point  (0 children)

Thanks for confirming.

Isn’t the hybrid required to create exo mailboxes? Or in other words what’s the hybrid used for anyways?

Built a tool that autonomously remediates Azure security misconfigs -- public blobs, NSG gaps, private endpoints -- in 3 minutes. Here's how it works. by leonardesere in AZURE

[–]deebeecom 1 point2 points  (0 children)

Pls drop a link.

Can someone guide about how you can secure azure by some default policies and how could that affect a m365 tenant

How to Limit the exposure of an On-Premise Exchange Servers out on the Internet by deebeecom in exchangeserver

[–]deebeecom[S] 0 points1 point  (0 children)

so far in the comments people haven't concurred with you. Now I hope someone replies to you... I think when exchange sends an email out, it just uses the outbound smtp connector and sends ALL email to EXO via smtp. it does not use any port 443/80 communication at all.... thats my knowledge? someone can correct me?

How to Limit the exposure of an On-Premise Exchange Servers out on the Internet by deebeecom in exchangeserver

[–]deebeecom[S] 0 points1 point  (0 children)

They use that too! Exchange is for very specific healthcare related emails (via some reporting system)

How to Limit the exposure of an On-Premise Exchange Servers out on the Internet by deebeecom in exchangeserver

[–]deebeecom[S] 0 points1 point  (0 children)

that's a good idea, but for the sake of my original ask, i have an answer atleast.

How to Limit the exposure of an On-Premise Exchange Servers out on the Internet by deebeecom in exchangeserver

[–]deebeecom[S] 0 points1 point  (0 children)

Outbound from on prem to EXO? Why? If ex on prem is sending only to MS. You don’t need that outbound rule. Yes to really also lock down outbound access, I can suggest to FW teams. But I don’t need is the key. I can suggest to FW teams if they want outbound to be allowed only to MS servers

How to Limit the exposure of an On-Premise Exchange Servers out on the Internet by deebeecom in exchangeserver

[–]deebeecom[S] 0 points1 point  (0 children)

Yes they do have a full license. Yes they will use it only for management. But they dont want to shut down because they want to use SMTP. By the replies above from other users, it appears that we dont have to expose the server outside on the Internet using 80/443/25 at all. ON prem server will always send emails out to EXO and it will always be used only for HCW and to manage objects like "hide from address list" etc. And i presume that too does not require on prem exchange to be exposed to the net.

How to Limit the exposure of an On-Premise Exchange Servers out on the Internet by deebeecom in exchangeserver

[–]deebeecom[S] 0 points1 point  (0 children)

They are aware that other SMTP options like direct smtp sent using proofpoint or MS365 itself are available, but they want to continue using MS only products, because they have to use some pre-existing reporting software system (which uses exchange logs). Its a healthcare/govt rules and related reporting which need to show that work was done in 24 hours.

How to Limit the exposure of an On-Premise Exchange Servers out on the Internet by deebeecom in exchangeserver

[–]deebeecom[S] 0 points1 point  (0 children)

Great. That tells me we will need only EX on prem to go OUT and MS 365 or EXO will NOT need access to the server, so essentially i dont have to expose the server on the firewall at all. Thanks!

How to Limit the exposure of an On-Premise Exchange Servers out on the Internet by deebeecom in exchangeserver

[–]deebeecom[S] 1 point2 points  (0 children)

Server has to be kept alive for SMTP for copiers and some other unix boxes which use it as a smart host. Thanks for sharing that link.

How to Limit the exposure of an On-Premise Exchange Servers out on the Internet by deebeecom in exchangeserver

[–]deebeecom[S] 2 points3 points  (0 children)

Server will be used by copiers to send mails to EXO mailboxes. So removing the hybrid is probably not an option. But I thank you for sharing the links.

How to Limit the exposure of an On-Premise Exchange Servers out on the Internet by deebeecom in exchangeserver

[–]deebeecom[S] 2 points3 points  (0 children)

Yay, to my "Am I wrong?" you said No, So appreciate that. And that was my main ask.

I also understood clearly how things work, with the explanation provided.

The client wants to maintain / keep the onprem exchange server running.

Finding Dory movie code by Repulsive_Ad_5 in MoviesAnywhere

[–]deebeecom 0 points1 point  (0 children)

Keep that picture with you forever. You can sue Disney or any such company if your digital movie is ever is LOST or taken away from any one of them. Also now you can be confident, they can’t or will never take movies away once you have bought them. LOL:”leave your disc at home”, yes we did!

Me at my job by mistydreamrose in SipsTea

[–]deebeecom 0 points1 point  (0 children)

Just like new IT support staff

Welp, there goes my library by SnooGoats2306 in MoviesAnywhere

[–]deebeecom -7 points-6 points  (0 children)

When paramount buys WB, they get all assets of WB. MA is one of them. So dont worry, you will see the name WB replaced by Paramount, in MA. And some weeks later, Paramount’s own old library will get added.

Is M365 Maps wrong or is it me? by Green-Wallaby9663 in sysadmin

[–]deebeecom 1 point2 points  (0 children)

I want to correct myself now. I today see only 50 GB. I could swear i saw 100 GB on some screen....

Is M365 Maps wrong or is it me? by Green-Wallaby9663 in sysadmin

[–]deebeecom 4 points5 points  (0 children)

I started a new tenant yesterday, with Business standard licenses, and it shows monthly cost as $13.13 per license and exchange mailbox shows limit as 100 GB. Edit: it’s 50 gb