Server Name |
mx2022.fede.adventist.be |
Generation Time | 25/12/2024 8:01:09 |
Exchange Version | Exchange 2019 CU14 Nov24SU |
Build Number | 15.02.1544.013 |
Latest Install Time (SU/CU) | 14/11/2024 0:12:09 |
Exchange IU or Security Hotfix Detected | |
| Security Update for Exchange Server 2019 Cumulative Update 14 (KB5036401) - Installed on 14/11/2024 |
| Hotfix Update for Exchange Server 2019 Cumulative Update 14 (KB5037224) - Installed on 14/11/2024 |
| Security Update for Exchange Server 2019 Cumulative Update 14 (KB5044062) - Installed on 14/11/2024 |
| Not on the latest SU. More Information: https://aka.ms/HC-ExBuilds |
Known Issue Detected | True |
| This build has a known issue(s) which may or may not have been addressed. See the below link(s) for more information.
|
| Pulled Nov 2024 Security Update:
https://techcommunity.microsoft.com/blog/exchange/released-november-2024-exchange-server-security-updates/4293125 |
| Known Issue when sending email with Pickup Folder is using Admin Display Version vs Installed Version:
https://support.microsoft.com/topic/email-sent-through-pickup-folder-displays-admin-version-068ae880-5bbf-43f0-a1fa-24a78f31635f |
Server Role | Mailbox |
Edition | Standard |
DAG Name | Standalone Server |
AD Site | Default-First-Site-Name |
MRS Proxy Enabled | True
Keep MRS Proxy disabled if you do not plan to move mailboxes cross-forest or remote |
Exchange Server Membership | Failed |
| Unable to determine Local System Membership as the results were blank. |
| More Information: https://aka.ms/HC-ServerMembership |
Internet Web Proxy | Not Set |
Extended Protection Enabled (Any VDir) | True |
Setting Overrides Detected | False |
Monitoring Overrides Detected | True |
Monitoring Overrides | Identity | ItemType | PropertyName | PropertyValue | ApplyVersion | IsValid | IsGlobal | ExpirationTime |
HubTransport\Transport.ServerCertExpireSoon.Monitor | Monitor | MonitoringThreshold | 240 | Version 15.2 (Build 397.3) | True | True | 13/10/2020 14:51:37 |
|
Exchange Server Maintenance | Server is not in Maintenance Mode |
MAPI/HTTP Enabled | True |
Enable Download Domains | True |
AD Split Permissions | False |
Total AD Site Count | 1 |
Dynamic Distribution Group Public Folder Mailboxes Count | 1 |
Organization Hybrid Enabled | True |
On-Premises Smart Host Domain | mail.adventist.be |
Domain(s) configured for Hybrid use | |
| woordvanhoop.be |
| jeunesseadventiste.be |
| hopebible.be |
| esda-instituut.be |
| adventjeugd.be |
| adventiste.lu |
| adventist.lu |
| autod:adventist.be |
Receiving Transport Server(s) | |
| MX2022 |
Sending Transport Server(s) | |
| MX2022 |
TLS Certificate Name | CN=R11, O=Let's Encrypt, C=USCN=mail.adventist.be |
Feature(s) enabled for Hybrid use | |
| FreeBusy |
| MoveMailbox |
| Mailtips |
| MessageTracking |
| OwaRedirection |
| OnlineArchive |
| SecureMail |
| Photos |
Connector Name | Default Frontend MX2022 |
Connector Enabled | True |
Cloud Mail Enabled | True |
Connector Type | Receive |
TlsCertificateName | CN=R11, O=Let's Encrypt, C=USCN=mail.adventist.be |
Certificate Found On Server | True |
Certificate Thumbprint(s) | |
| 3776BCFC55E41AA7AD09CD847FB887B4831C167B |
Lifetime In Days | |
| 50 |
Certificate Matches Hybrid Certificate | True |
Connector Name | Outbound to Office 365 - aeb1ee1c-e8f7-4c14-8fc8-1f6f8935c2be |
Connector Enabled | True |
Cloud Mail Enabled | True |
Connector Type | Send |
TlsCertificateName | CN=R11, O=Let's Encrypt, C=USCN=mail.adventist.be |
Certificate Found On Server | True |
Certificate Thumbprint(s) | |
| 3776BCFC55E41AA7AD09CD847FB887B4831C167B |
Lifetime In Days | |
| 50 |
Certificate Matches Hybrid Certificate | True |
Connector Name | Outbound to Office 365 - 267d4df8-938c-4425-a7c0-ed9dfb4681a0 |
Connector Enabled | True |
Cloud Mail Enabled | True |
Connector Type | Send |
TlsCertificateName | CN=R3, O=Let's Encrypt, C=USCN=mail.adventist.be |
Certificate Found On Server | False |
| The configured 'TlsCertificateName' was not found on the server.
This may cause mail flow issues. More information: https://aka.ms/HC-HybridConnector |
OS Version | Windows Server 2022 Standard |
System Up Time | 14 day(s) 7 hour(s) 38 minute(s) 32 second(s) |
Time Zone | Romance Standard Time |
Dynamic Daylight Time Enabled | True |
.NET Framework | 4.8.1 |
PageFile | c:\pagefile.sys Size: 36864MB |
Power Plan | High performance |
Http Proxy Setting | None |
Visual C++ 2012 x64 | 11.0.61030 Version is current |
Visual C++ 2013 x64 | 12.0.40664 Version is current |
Server Pending Reboot | True --- Warning a reboot is pending and can cause issues on the server. |
| HKLM:\SYSTEM\CurrentControlSet\Control\Session Manager\PendingFileRenameOperations |
| More Information: https://aka.ms/HC-RebootPending |
Hardware Type | HyperV |
Processor | Intel(R) Xeon(R) CPU E5-2630 v4 @ 2.20GHz |
Current Total Processor Usage | 11,57 |
Number of Processors | 2 |
Number of Physical Cores | 10 |
Number of Logical Cores | 20 |
Hyper-Threading | Enabled --- Not Applicable |
All Processor Cores Visible | Passed |
Max Processor Speed | 2197 |
Physical Memory | 144 GB |
Dynamic Memory Detected | False |
Interface Description | Microsoft Hyper-V Network Adapter [Ethernet] |
Driver Date | 2006-06-21 |
Driver Version | 10.0.20348.2849 |
MTU Size | 1500 |
Max Processors | 10 |
Max Processor Number | 18 |
Number of Receive Queues | 10 |
RSS Enabled | True |
Link Speed | 10000 Mbps --- This may not be accurate due to virtualized hardware |
IPv6 Enabled | False |
IPv4 Address | |
Address | 192.168.21.10/24 Gateway: 192.168.21.1 |
IPv6 Address | |
DNS Server | 192.168.21.2 192.168.21.3 |
Registered In DNS | True |
Packets Received Discarded | 0 |
Disable IPv6 Correctly | True |
TCPKeepAlive | 1350000 |
RPC Minimum Connection Timeout | 0
More Information: https://aka.ms/HC-RPCSetting |
FipsAlgorithmPolicy-Enabled | 0 |
EnableEccCertificateSupport Registry Value | |
CtsProcessorAffinityPercentage | 0 |
Disable Async Notification | 0 |
Credential Guard Enabled | False |
EdgeTransport.exe.config Present | True |
NodeRunner.exe memory limit | 0 MB |
IanaTimeZoneMappings.xml invalid |
[Duplicate entry] - IANA: Asia/Bishkek Win: Central Asia Standard Time
More information: https://aka.ms/ExchangeIanaTimeZoneIssue |
Open Relay Wild Card Domain | Not Set |
DisablePreservation | |
EXO Connector Present | False |
UnifiedContent Auto Cleanup Configured | True |
TLS 1.0 | Disabled |
TLS Settings 1.0 | RegistryKey | Location | Value |
Enabled | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.0\Server | 0 |
DisabledByDefault | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.0\Server | 1 |
Enabled | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.0\Client | 0 |
DisabledByDefault | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.0\Client | 1 |
|
TLS 1.1 | Disabled |
TLS Settings 1.1 | RegistryKey | Location | Value |
Enabled | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.1\Server | 0 |
DisabledByDefault | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.1\Server | 1 |
Enabled | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.1\Client | 0 |
DisabledByDefault | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.1\Client | 1 |
|
TLS 1.2 | Enabled |
TLS Settings 1.2 | RegistryKey | Location | Value |
Enabled | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Server | 1 |
DisabledByDefault | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Server | 0 |
Enabled | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Client | 1 |
DisabledByDefault | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Client | 0 |
|
TLS 1.3 | Disabled |
TLS Settings 1.3 | RegistryKey | Location | Value |
Enabled | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.3\Server | NULL |
DisabledByDefault | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.3\Server | NULL |
Enabled | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.3\Client | NULL |
DisabledByDefault | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.3\Client | NULL |
|
TLS NET Settings | RegistryKey | Location | Value |
SystemDefaultTlsVersions | SOFTWARE\Microsoft\.NETFramework\v4.0.30319 | 1 |
SchUseStrongCrypto | SOFTWARE\Microsoft\.NETFramework\v4.0.30319 | 1 |
SystemDefaultTlsVersions | SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v4.0.30319 | 1 |
SchUseStrongCrypto | SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v4.0.30319 | 1 |
SystemDefaultTlsVersions | SOFTWARE\Microsoft\.NETFramework\v2.0.50727 | NULL |
SchUseStrongCrypto | SOFTWARE\Microsoft\.NETFramework\v2.0.50727 | NULL |
SystemDefaultTlsVersions | SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v2.0.50727 | NULL |
SchUseStrongCrypto | SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v2.0.50727 | NULL |
|
SecurityProtocol | Tls12 |
TLS Cipher Suite | TlsCipherSuiteName | CipherSuite | Cipher | Certificate | Protocols |
TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 | 49196 | AES | ECDSA | TLS_1_2 & DTLS_1_1 |
TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 | 49195 | AES | ECDSA | TLS_1_2 & DTLS_1_1 |
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 | 49200 | AES | RSA | TLS_1_2 & DTLS_1_1 |
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 | 49199 | AES | RSA | TLS_1_2 & DTLS_1_1 |
TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384 | 49188 | AES | ECDSA | TLS_1_2 & DTLS_1_1 |
TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256 | 49187 | AES | ECDSA | TLS_1_2 & DTLS_1_1 |
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 | 49192 | AES | RSA | TLS_1_2 & DTLS_1_1 |
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 | 49191 | AES | RSA | TLS_1_2 & DTLS_1_1 |
|
AllowInsecureRenegoClients Value | 0 |
AllowInsecureRenegoServers Value | 0 |
LmCompatibilityLevel Settings | 3 |
AES256-CBC Protected Content Support | True |
SMB1 Installed | False |
SMB1 Blocked | True |
Certificate | |
FriendlyName | CN=BLF Enterprise Certificate Authority, DC=fede, DC=adventist, DC=be |
Thumbprint | 2F120E75D1F9EA82E22D0DB1F356EAD482E664E7 |
Lifetime in days | 348 |
Certificate has expired | False |
Certificate status | Valid |
Key size | 2048 |
ECC Certificate | False |
Signature Algorithm | sha256RSA |
Signature Hash Algorithm | sha256 |
Bound to services | None |
Internal Transport Certificate | False |
Current Auth Certificate | False |
Next Auth Certificate | False |
SAN Certificate | False |
Namespaces | |
| mx2022.fede.adventist.be |
Certificate | |
FriendlyName | [Manual] mail.adventist.be @ 2024/11/15 12:23:27 |
Thumbprint | 3776BCFC55E41AA7AD09CD847FB887B4831C167B |
Lifetime in days | 50 |
Certificate has expired | False |
Certificate status | Valid |
Key size | 3072 |
ECC Certificate | False |
Signature Algorithm | sha256RSA |
Signature Hash Algorithm | sha256 |
Bound to services | IMAP, POP, IIS, SMTP |
Internal Transport Certificate | True |
Current Auth Certificate | False |
Next Auth Certificate | False |
SAN Certificate | True |
Namespaces | |
| autodiscover.adventist.be |
| download.mail.adventist.be |
| ex2022.adventist.be |
| mail.adventist.be |
Certificate | |
FriendlyName | MX2022-II-dix |
Thumbprint | 7365EBAB143D62599E152357801F5BB4D6A2E9E4 |
Lifetime in days | 1117 |
Certificate has expired | False |
Certificate status | Valid |
Key size | 2048 |
ECC Certificate | False |
Signature Algorithm | sha256RSA |
Signature Hash Algorithm | sha256 |
Bound to services | None |
Internal Transport Certificate | False |
Current Auth Certificate | False |
Next Auth Certificate | False |
SAN Certificate | False |
Namespaces | |
| mx2022.fede.adventist.be |
Certificate | |
FriendlyName | MX2022-IIS |
Thumbprint | 5BF4850C1B12504A0CFA943FFFE8B34C25C6503E |
Lifetime in days | 21 |
Certificate has expired | False |
Certificate status | Valid |
Key size | 4096 |
ECC Certificate | False |
Signature Algorithm | sha256RSA |
Signature Hash Algorithm | sha256 |
Bound to services | None |
Internal Transport Certificate | False |
Current Auth Certificate | False |
Next Auth Certificate | False |
SAN Certificate | False |
Namespaces | |
| mx2022.fede.adventist.be |
Certificate | |
FriendlyName | Microsoft Exchange |
Thumbprint | 4920229798A6DE38C276AD1574C0BAAEEE9A3D87 |
Lifetime in days | 866 |
Certificate has expired | False |
Certificate status | Valid |
Key size | 2048 |
ECC Certificate | False |
Signature Algorithm | sha256RSA |
Signature Hash Algorithm | sha256 |
Bound to services | SMTP |
Internal Transport Certificate | False |
Current Auth Certificate | False |
Next Auth Certificate | False |
SAN Certificate | True |
Namespaces | |
| mx2022 |
| mx2022.fede.adventist.be |
Certificate | |
FriendlyName | Microsoft Exchange |
Thumbprint | 0129F0D1AA63DFA23FC9A5D61973C0B73FA3298A |
Lifetime in days | 754 |
Certificate has expired | False |
Certificate status | Valid |
Key size | 2048 |
ECC Certificate | False |
Signature Algorithm | sha256RSA |
Signature Hash Algorithm | sha256 |
Bound to services | IIS, SMTP |
Internal Transport Certificate | False |
Current Auth Certificate | False |
Next Auth Certificate | False |
SAN Certificate | True |
Namespaces | |
| mx2022 |
| mx2022.fede.adventist.be |
Certificate | |
FriendlyName | WMSVC-SHA2 |
Thumbprint | 7479ED2572AE6BF2124EE2BBE89FCA1ABCA0CC9E |
Lifetime in days | 2578 |
Certificate has expired | False |
Certificate status | Valid |
Key size | 2048 |
ECC Certificate | False |
Signature Algorithm | sha256RSA |
Signature Hash Algorithm | sha256 |
Bound to services | None |
Internal Transport Certificate | False |
Current Auth Certificate | False |
Next Auth Certificate | False |
SAN Certificate | False |
Namespaces | |
| WMSvc-SHA2-MX2022 |
Certificate | |
FriendlyName | Microsoft Exchange Server Auth Certificate |
Thumbprint | FE5E0C111907640558880109F7B04D28DA18663B |
Lifetime in days | 319 |
Certificate has expired | False |
Certificate status | Valid |
Key size | 2048 |
ECC Certificate | False |
Signature Algorithm | sha256RSA |
Signature Hash Algorithm | sha256 |
Bound to services | SMTP |
Internal Transport Certificate | False |
Current Auth Certificate | True |
Next Auth Certificate | False |
SAN Certificate | False |
Namespaces | |
| ACS |
Valid Internal Transport Certificate Found On Server | True |
Valid Auth Certificate Found On Server | True |
AMSI Enabled | True |
AMSI Request Body Scanning | False |
AMSI Request Body Size Block | False |
SerializedDataSigning Enabled | True |
Strict Mode disabled | False |
BaseTypeCheckForDeserialization disabled | False |
Exchange Emergency Mitigation Service | Enabled |
Windows service | Running |
Pattern service | 200 - Reachable |
Mitigation applied | PING1 |
| Run: 'Get-Mitigations.ps1' from: 'C:\Program Files\Microsoft\Exchange Server\V15\scripts\' to learn more. |
Telemetry enabled | True |
IIS module anomalies detected | False |
Security Vulnerability | CVE-2024-49040 - Override Is Set: False
See: https://portal.msrc.microsoft.com/security-guidance/advisory/CVE-2024-49040 for more information. |
Security Vulnerabilities | CVE-2024-49040 - Override Is Set: False
See: https://portal.msrc.microsoft.com/security-guidance/advisory/CVE-2024-49040 for more information.
|
IIS Sites Information | Name | State | HSTS Enabled | Protocol - Bindings - Certificate |
Default Web Site | Started | False | http - *:80: - NULL https - *:443:mx2022.fede.adventist.be - 7365EBAB143D62599E152357801F5BB4D6A2E9E4 https - *:443: - 3776BCFC55E41AA7AD09CD847FB887B4831C167B https - *:443:mail.adventist.be - 3776BCFC55E41AA7AD09CD847FB887B4831C167B https - *:443:autodiscover.adventist.be - 3776BCFC55E41AA7AD09CD847FB887B4831C167B |
Exchange Back End | Started | False | http - *:81: - NULL https - *:444: - 0129F0D1AA63DFA23FC9A5D61973C0B73FA3298A |
|
Application Pool Information | AppPoolName | State | GCServerEnabled | RestartConditionSet |
MSExchangeMapiFrontEndAppPool | Started | True | False |
MSExchangeOWAAppPool | Started | False | False |
MSExchangeECPAppPool | Started | False | False |
MSExchangeRestAppPool | Started | True | False |
MSExchangeMapiAddressBookAppPool | Started | False | False |
MSExchangeRpcProxyFrontEndAppPool | Started | False | False |
MSExchangePowerShellAppPool | Started | False | False |
MSExchangePowerShellFrontEndAppPool | Started | False | False |
MSExchangeRestFrontEndAppPool | Started | False | False |
MSExchangeMapiMailboxAppPool | Started | False | False |
MSExchangeOABAppPool | Started | False | False |
MSExchangePushNotificationsAppPool | Started | False | False |
MSExchangeOWACalendarAppPool | Started | False | False |
MSExchangeAutodiscoverAppPool | Started | False | False |
MSExchangeServicesAppPool | Started | True | False |
MSExchangeSyncAppPool | Started | True | False |
MSExchangeRpcProxyAppPool | Started | False | False |
|
Virtual Directory Locations | Name | ExtendedProtection | SslFlags | IPFilteringEnabled | URLRewrite | Authentication |
Default Web Site | None | False | False | | anonymous (default setting) |
Default Web Site/API | Require | True (128-bit) | False | | Windows (Negotiate,NTLM) anonymous (default setting) |
Default Web Site/Autodiscover | None | True (128-bit) | False | | Windows (Negotiate,NTLM) anonymous (default setting) basic |
Default Web Site/ecp | Require | True (128-bit) | False | | anonymous (default setting) basic |
Default Web Site/EWS | Allow | True (128-bit) | False | | Windows (Negotiate,NTLM) anonymous (default setting) |
Default Web Site/mapi | Require | True (128-bit) | False | | Windows (Negotiate,NTLM) |
Default Web Site/Microsoft-Server-ActiveSync | Allow | True (128-bit) | False | | basic |
Default Web Site/Microsoft-Server-ActiveSync/Proxy | Allow | True (128-bit) | False | | Windows (Negotiate,NTLM) |
Default Web Site/OAB | Allow | True (128-bit) | False | | Windows (Negotiate,NTLM) |
Default Web Site/owa | Require | True (128-bit) | False | | basic |
Default Web Site/PowerShell | Require | False Cert(Accept) | False | | |
Default Web Site/Rpc | Require | True (128-bit) | False | | Windows (Negotiate,NTLM) basic |
Exchange Back End | None | False | False | | anonymous (default setting) |
Exchange Back End/API | Require | True (128-bit) | False | | Windows (Negotiate,NTLM) anonymous (default setting) |
Exchange Back End/Autodiscover | None | True (128-bit) | False | | Windows (Negotiate,NTLM) anonymous (default setting) |
Exchange Back End/ecp | Require | True (128-bit) | False | | Windows (Negotiate,NTLM) anonymous (default setting) |
Exchange Back End/EWS | Require | True (128-bit) | False | | Windows (Negotiate,NTLM) anonymous (default setting) |
Exchange Back End/mapi/emsmdb | Require | True | False | | Windows (Negotiate,NTLM) |
Exchange Back End/mapi/nspi | Require | True | False | | Windows (Negotiate,NTLM) |
Exchange Back End/Microsoft-Server-ActiveSync | Require | True (128-bit) | False | | basic |
Exchange Back End/Microsoft-Server-ActiveSync/Proxy | Require | True (128-bit) | False | | Windows (Negotiate,NTLM) |
Exchange Back End/OAB | Require | True (128-bit) | False | | Windows (Negotiate,NTLM) |
Exchange Back End/owa | Require | True (128-bit) | False | | Windows (Negotiate,NTLM) anonymous (default setting) |
Exchange Back End/PowerShell | Require | True (128-bit) | False | | Windows (Negotiate,NTLM) |
Exchange Back End/Rpc | Require | True (128-bit) | False | | Windows (Negotiate,NTLM) |
Exchange Back End/RpcWithCert | Require | True (128-bit) | False | | Windows (Negotiate,NTLM) |
|