Hotfix Update May 2025

Just before the weekend, the Exchange Server team has released a hotfix update for the supported versions of Exchange Server 2019 (CU14 & CU15) and Exchange Server 2016 (CU23).

As the name suggests, this is not a security update that closes newly discovered security vulnerabilities. Rather, this hotfix update addresses some “code glitches” of previous SUs and HUs.

The upgrade scenario for installing the May hotfix update is similar to the last updates.

  • If one of the three supported Exchange versions is already installed on your Exchange server, you can simply install the appropriate hotfix update.
  • If a cumulative update of a version is still installed, you must first update the affected systems to a supported cumulative update.
Flussdiagramm zum Update-Prozess von Exchange Server. Es zeigt zwei Pfade: Einer beginnt mit unterstützten CUs (Exchange Server 2016 CU23, 2019 CU14 oder CU15) und führt direkt zur Installation der Mai 2023 Hotfixes. Der andere beginnt mit nicht unterstützten CUs, führt zuerst zur Installation einer unterstützten CU und danach zu den Hotfixes. Am Ende steht ein grünes Feld mit dem Hinweis, dass Exchange aktuell ist, sowie ein Link zum Health Checker. Ein zusätzlicher Hinweis mit Warnsymbol verweist auf Hybrid-Konfigurationen und einen entsprechenden Microsoft-Link.
Source: Microsoft

Dedicated hybrid application

October 2025 has a few tasks in store for Exchange admins. On October 14, not only Exchange Server 2016 & 2019 reach their end of life, at least as far as the supported lifecycle is concerned, there is also extra work for hybrid Exchange environments.

In October, the so-called Service Principal of the first-party application Office 365 Exchange Online will be switched off. After the lockdown, a local Exchange organization can no longer authenticate with this service principal. As a result, all functions of the full hybrid position (rich coexistence) will no longer work. 

For this to continue to work, a dedicated company application, the so-called Exchange Hybrid Application, must be created and configured in Entra. The steps are described in this article.

We recommend setting this up before the switch-off date in October 2025, as this allows you to switch back to the old configuration at any time in order to carry out a fault analysis. After switching off the First-App Service Principal, commissioning is a bit like flying blind. Environments with a complex network infrastructure in particular present numerous hurdles that need to be overcome.

Incidentally, the company application itself is not deleted, as it is an integral part of conditional access filters.

Weitere Artikel