Comments on: It Really is Time to Say Goodbye to On-Premises Exchange Practical Office 365 News, Tips, and Tutorials Fri, 06 Oct 2023 15:57:18 +0000 hourly 1 By: Mark H. Fri, 06 Oct 2023 15:57:18 +0000 In reply to David.

Dude preaching to Tony Redmond about Exchange is like skater preaching to Tony Hawk about skateboarding.

By: John Sdao Wed, 19 Jul 2023 14:42:15 +0000 Managing Ex on prem for 15+ GW before that for years with minimal issues. There are more problems and outages in the cloud than there was on prem. This is just my optics, but I feel I have my hands in my pocket telling 50k users…Sorry cloud issue nothing I can do.

By: <div class="apbct-real-user-wrapper"> <div class="apbct-real-user-author-name">Tony Redmond</div> <div class="apbct-real-user-badge" onmouseover=" let popup = document.getElementById('apbct_trp_comment_id_266036'); = 'inline-flex'; "> <div class="apbct-real-user-popup" id="apbct_trp_comment_id_266036"> <div class="apbct-real-user-title"> <p class="apbct-real-user-popup-header">The Real Person!</p> <p class="apbct-real-user-popup-text">Author <b>Tony Redmond</b> acts as a real person and passed all tests against spambots. Anti-Spam by CleanTalk.</p> </div> </div> </div> </div> Wed, 14 Jun 2023 12:00:15 +0000 In reply to Marco.

Who knows? Microsoft isn’t saying and we never had very accurate data about the number of Exchange on-premises mailboxes to work with. If pushed into a corner, I’d say maybe 10% of the original base, which could be about 40 million accounts. But this is guessing.

By: Marco Wed, 14 Jun 2023 11:48:49 +0000 Hi Tony, thanks for sharing. When you say the bulk of the migration is over, do you have a sense of how many users or customers are still out there on prem?

By: <div class="apbct-real-user-wrapper"> <div class="apbct-real-user-author-name">Tony Redmond</div> <div class="apbct-real-user-badge" onmouseover=" let popup = document.getElementById('apbct_trp_comment_id_256547'); = 'inline-flex'; "> <div class="apbct-real-user-popup" id="apbct_trp_comment_id_256547"> <div class="apbct-real-user-title"> <p class="apbct-real-user-popup-header">The Real Person!</p> <p class="apbct-real-user-popup-text">Author <b>Tony Redmond</b> acts as a real person and passed all tests against spambots. Anti-Spam by CleanTalk.</p> </div> </div> </div> </div> Wed, 15 Mar 2023 15:38:28 +0000 In reply to Tom Gould.

Organizations that only use on-premises servers for mail relay are fine to do that. I am more concerned about mailboxes used by humans. However, it is absolutely critical to keep servers updated and patched, even if they’re only used for mail relay. There are many known vulnerabilities that can affect servers that run outdated software and those servers represent a real risk. So, run Exchange 2016 or Exchange 2019 on your mail relay servers and make sure that you apply cumulative and security updates as Microsoft releases updates and all will be well.

By: Tom Gould Wed, 15 Mar 2023 15:32:25 +0000 Does your opinion consider organizations with on-prem exchange servers only supporting mail relay functionality?? In an ideal world, all of our on-premises devices support modern authentication, but that isn’t always the case.

By: <div class="apbct-real-user-wrapper"> <div class="apbct-real-user-author-name">Tony Redmond</div> <div class="apbct-real-user-badge" onmouseover=" let popup = document.getElementById('apbct_trp_comment_id_256158'); = 'inline-flex'; "> <div class="apbct-real-user-popup" id="apbct_trp_comment_id_256158"> <div class="apbct-real-user-title"> <p class="apbct-real-user-popup-header">The Real Person!</p> <p class="apbct-real-user-popup-text">Author <b>Tony Redmond</b> acts as a real person and passed all tests against spambots. Anti-Spam by CleanTalk.</p> </div> </div> </div> </div> Fri, 10 Mar 2023 09:32:05 +0000 In reply to Artur Friedenreich.

Actually no. Exchange Online is split up across datacenter regions and forests so any compromise won’t penetrate everywhere. Also, compromises tend to rely on access to privileged accounts and there are very few of these, all of which have time-limited access to perform actions. There are other security measures in place that I won’t go into here. In the on-premises world, there are still thousands of unpatched and vulnerable servers in operation (you can’t expect the FBI to patch them all as they did for U.S. servers after Hafnium). That doesn’t happen in the cloud because all servers run the latest software. In comparing the two environments, I see a cloud system operated by the development group and protected by thousands of security professionals where holes like basic authentication are steadily being closed off. Against that, I see on-premises environments that don’t have the same protection and expertise (exceptions do prove the rule, but there are few) where known holes exist. So I conclude that the cloud option is best.

Happy to debate the point at length if you want to attend the TEC Europe Tour event in Frankfurt on April 21.

By: Artur Friedenreich Fri, 10 Mar 2023 03:19:41 +0000 Nice to read so far. From my point of view you could turn your phrase just the other way around:

“ Although Exchange Online spans over 200,000 physical mailbox servers, the risk of compromise is much lower than for any on-premises environment because of the security resources Microsoft dedicates to protecting its cloud infrastructure.”

When they are compromised then everybody is really fried. Not so much comments about the fact that MS relies also on the security of 3rd parties, just to name Solarwind. It was clear that the hackers who came through that door had access to the sources of Windows and and a few month after we have a zero day like Haffnium. I don’t want to put too much into it but is your recommendation really to put all economical eggs in just one basket?
Your argument is mostly about the complexity’s of maintenance and migration. I agree on that and I know what I’m talking because I work closely with Exchange since 5.5 and developed a lot of bad hacks against every version in order to solve issues or crashes of my clients.
You can’t sell it as a self healing worry free product. But tell everybody go to the cloud?
I’m not convinced…

By: <div class="apbct-real-user-wrapper"> <div class="apbct-real-user-author-name">Tony Redmond</div> <div class="apbct-real-user-badge" onmouseover=" let popup = document.getElementById('apbct_trp_comment_id_249360'); = 'inline-flex'; "> <div class="apbct-real-user-popup" id="apbct_trp_comment_id_249360"> <div class="apbct-real-user-title"> <p class="apbct-real-user-popup-header">The Real Person!</p> <p class="apbct-real-user-popup-text">Author <b>Tony Redmond</b> acts as a real person and passed all tests against spambots. Anti-Spam by CleanTalk.</p> </div> </div> </div> </div> Thu, 29 Dec 2022 22:51:18 +0000 In reply to Tyler.

Some government institutions are definitely among the last hold-outs of on-premises Exchange Server. I just hope that they secure those servers!

By: Tyler Thu, 29 Dec 2022 21:15:30 +0000 I don’t think on-premise will go 100% away because of the government. We have 3 of them and we’re just one org.
