Server Name |
exVM.corp.contoso.com |
Generation Time | 4/4/2024 12:42:15 PM |
Exchange Version | Exchange 2019 CU14 |
Build Number | 15.02.1544.004 |
| Not on the latest SU. More Information: https://aka.ms/HC-ExBuilds |
Server Role | Mailbox |
DAG Name | Standalone Server |
AD Site | Default-First-Site-Name |
MRS Proxy Enabled | False |
Internet Web Proxy | Not Set |
Common Services Not Running | |
| MSComplianceAudit - Status: Stopped - StartType: Automatic |
Extended Protection Enabled (Any VDir) | True |
Setting Overrides Detected | False |
Exchange Server Maintenance | Server is not in Maintenance Mode |
MAPI/HTTP Enabled | True |
Enable Download Domains | False |
AD Split Permissions | False |
Total AD Site Count | 1 |
OS Version | Windows Server 2019 Datacenter |
System Up Time | 0 day(s) 2 hour(s) 38 minute(s) 15 second(s) |
Time Zone | Coordinated Universal Time |
Dynamic Daylight Time Enabled | True |
.NET Framework | 4.8 |
PageFile | D:\pagefile.sys Size: 0MB |
| Error: On Exchange 2019, the recommended PageFile size is 25% (8192MB) of the total system memory (32768MB). |
| More information: https://aka.ms/HC-PageFile |
Power Plan | High performance |
Http Proxy Setting | None |
Visual C++ 2012 x64 | Redistributable (11.0.50727) is outdated |
Visual C++ 2013 x64 | Redistributable (12.0.21005) is outdated |
| Note: For more information about the latest C++ Redistributable please visit: https://aka.ms/HC-LatestVC
This is not a requirement to upgrade, only a notification to bring to your attention. |
Server Pending Reboot | True --- Warning a reboot is pending and can cause issues on the server. |
| HKLM:\SYSTEM\CurrentControlSet\Control\Session Manager\PendingFileRenameOperations |
| More Information: https://aka.ms/HC-RebootPending |
Hardware Type | HyperV |
Processor | Intel(R) Xeon(R) Platinum 8171M CPU @ 2.60GHz |
Number of Processors | 1 |
Number of Physical Cores | 4 |
Number of Logical Cores | 8 |
Hyper-Threading | Enabled --- Not Applicable |
All Processor Cores Visible | Passed |
Max Processor Speed | 2095 |
Physical Memory | 32 GB
Warning: We recommend for the best performance to have a minimum of 128GB of RAM installed on the machine. |
Interface Description | Microsoft Hyper-V Network Adapter [Ethernet] |
Driver Date | 2006-06-21 |
Driver Version | 10.0.17763.5122 |
MTU Size | 1500 |
Max Processors | 4 |
Max Processor Number | 6 |
Number of Receive Queues | 4 |
RSS Enabled | True |
Link Speed | 50000 Mbps --- This may not be accurate due to virtualized hardware |
IPv6 Enabled | True |
IPv4 Address | |
Address | 10.0.0.5/24 Gateway: 10.0.0.1 |
IPv6 Address | |
DNS Server | 10.0.0.4 |
Registered In DNS | True |
Packets Received Discarded | 0 |
TCPKeepAlive | Not Set
Error: Without this value the KeepAliveTime defaults to two hours, which can cause connectivity and performance issues between network devices such as firewalls and load balancers depending on their configuration.
More details: https://aka.ms/HC-TcpIpSettingsCheck |
RPC Minimum Connection Timeout | 0
More Information: https://aka.ms/HC-RPCSetting |
FipsAlgorithmPolicy-Enabled | 0 |
CtsProcessorAffinityPercentage | 0 |
Disable Async Notification | 0 |
Credential Guard Enabled | False |
EdgeTransport.exe.config Present | True |
NodeRunner.exe memory limit | 0 MB |
Open Relay Wild Card Domain | Not Set |
DisablePreservation | |
EXO Connector Present | False |
TLS 1.0 | Disabled |
TLS Settings 1.0 | RegistryKey | Location | Value |
Enabled | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.0\Server | 0 |
DisabledByDefault | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.0\Server | 1 |
Enabled | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.0\Client | 0 |
DisabledByDefault | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.0\Client | 1 |
|
TLS 1.1 | Disabled |
TLS Settings 1.1 | RegistryKey | Location | Value |
Enabled | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.1\Server | 0 |
DisabledByDefault | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.1\Server | 1 |
Enabled | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.1\Client | 0 |
DisabledByDefault | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.1\Client | 1 |
|
TLS 1.2 | Enabled |
TLS Settings 1.2 | RegistryKey | Location | Value |
Enabled | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Server | 1 |
DisabledByDefault | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Server | 0 |
Enabled | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Client | 1 |
DisabledByDefault | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Client | 0 |
|
TLS 1.3 | Disabled |
TLS Settings 1.3 | RegistryKey | Location | Value |
Enabled | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.3\Server | NULL |
DisabledByDefault | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.3\Server | NULL |
Enabled | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.3\Client | NULL |
DisabledByDefault | SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.3\Client | NULL |
|
TLS NET Settings | RegistryKey | Location | Value |
SystemDefaultTlsVersions | SOFTWARE\Microsoft\.NETFramework\v4.0.30319 | 1 |
SchUseStrongCrypto | SOFTWARE\Microsoft\.NETFramework\v4.0.30319 | NULL |
SystemDefaultTlsVersions | SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v4.0.30319 | 1 |
SchUseStrongCrypto | SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v4.0.30319 | NULL |
SystemDefaultTlsVersions | SOFTWARE\Microsoft\.NETFramework\v2.0.50727 | NULL |
SchUseStrongCrypto | SOFTWARE\Microsoft\.NETFramework\v2.0.50727 | NULL |
SystemDefaultTlsVersions | SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v2.0.50727 | NULL |
SchUseStrongCrypto | SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v2.0.50727 | NULL |
|
v4.0.30319 SchUseStrongCryptoValue | NULL --- Error: Value should be defined in registry for consistent results. |
v4.0.30319 WowSchUseStrongCryptoValue | NULL --- Error: Value should be defined in registry for consistent results. |
| Error: SystemDefaultTlsVersions or SchUseStrongCrypto is not set to the recommended value. Please visit on how to properly enable TLS 1.2 https://aka.ms/HC-TLSGuide |
| More Information: https://aka.ms/HC-TLSConfigDocs |
SecurityProtocol | Tls, Tls11, Tls12 |
TLS Cipher Suite | TlsCipherSuiteName | CipherSuite | Cipher | Certificate | Protocols |
TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 | 49196 | AES | ECDSA | TLS_1_2 & DTLS_1_1 |
TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 | 49195 | AES | ECDSA | TLS_1_2 & DTLS_1_1 |
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 | 49200 | AES | RSA | TLS_1_2 & DTLS_1_1 |
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 | 49199 | AES | RSA | TLS_1_2 & DTLS_1_1 |
TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384 | 49188 | AES | ECDSA | TLS_1_2 & DTLS_1_1 |
TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256 | 49187 | AES | ECDSA | TLS_1_2 & DTLS_1_1 |
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 | 49192 | AES | RSA | TLS_1_2 & DTLS_1_1 |
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 | 49191 | AES | RSA | TLS_1_2 & DTLS_1_1 |
|
AllowInsecureRenegoClients Value | 0 |
AllowInsecureRenegoServers Value | 0 |
LmCompatibilityLevel Settings | 3 |
AES256-CBC Protected Content Support | True |
SMB1 Installed | False |
SMB1 Blocked | True |
Certificate | |
FriendlyName | LE_CERT_2024-03-22-0913 |
Thumbprint | F7F97090DCB6A9E0E230963027D295ADCD8A3568 |
Lifetime in days | 76 |
Certificate has expired | False |
Certificate status | Valid |
Key size | 2048 |
Signature Algorithm | sha256RSA |
Signature Hash Algorithm | sha256 |
Bound to services | IMAP, POP, IIS, SMTP |
Internal Transport Certificate | True |
Current Auth Certificate | False |
Next Auth Certificate | False |
SAN Certificate | False |
Namespaces | |
| exchserverdns.westus.cloudapp.azure.com |
Certificate | |
FriendlyName | Microsoft Exchange Server Auth Certificate |
Thumbprint | CA6D0BA854DD0B6926BFEE7A55836AC3C1C99C15 |
Lifetime in days | 1785 |
Certificate has expired | False |
Certificate status | Valid |
Key size | 2048 |
Signature Algorithm | sha256RSA |
Signature Hash Algorithm | sha256 |
Bound to services | SMTP |
Internal Transport Certificate | False |
Current Auth Certificate | True |
Next Auth Certificate | False |
SAN Certificate | False |
Namespaces | |
| Microsoft Exchange Server Auth Certificate |
Certificate | |
FriendlyName | Microsoft Exchange |
Thumbprint | CCC5AB763449C5EC220F381F32CAC1305C1DA39C |
Lifetime in days | 1811 |
Certificate has expired | False |
Certificate status | Valid |
Key size | 2048 |
Signature Algorithm | sha256RSA |
Signature Hash Algorithm | sha256 |
Bound to services | IIS, SMTP |
Internal Transport Certificate | False |
Current Auth Certificate | False |
Next Auth Certificate | False |
SAN Certificate | True |
Namespaces | |
| exVM |
| exVM.corp.contoso.com |
Certificate | |
FriendlyName | WMSVC-SHA2 |
Thumbprint | 8F76E8704755075187107ECAA226511BE99A884D |
Lifetime in days | 3635 |
Certificate has expired | False |
Certificate status | Valid |
Key size | 2048 |
Signature Algorithm | sha256RSA |
Signature Hash Algorithm | sha256 |
Bound to services | None |
Internal Transport Certificate | False |
Current Auth Certificate | False |
Next Auth Certificate | False |
SAN Certificate | False |
Namespaces | |
| WMSvc-SHA2-exVM |
Valid Internal Transport Certificate Found On Server | True |
Valid Auth Certificate Found On Server | True |
AMSI Enabled | True |
SerializedDataSigning Enabled | True |
Strict Mode disabled | False |
BaseTypeCheckForDeserialization disabled | False |
Exchange Emergency Mitigation Service | Enabled |
Windows service | Running |
Pattern service | 200 - Reachable |
Mitigation applied | PING1 |
| Run: 'Get-Mitigations.ps1' from: 'C:\Program Files\Microsoft\Exchange Server\V15\scripts\' to learn more. |
Telemetry enabled | True |
IIS module anomalies detected | False |
Security Vulnerability | ADV24199947
See: https://portal.msrc.microsoft.com/security-guidance/advisory/ADV24199947 for more information. |
Security Vulnerabilities | CVE-2024-26198
See: https://portal.msrc.microsoft.com/security-guidance/advisory/CVE-2024-26198 for more information. Download Domains are not configured. You should configure them to be protected against CVE-2021-1730.
Configuration instructions: https://aka.ms/HC-DownloadDomains ADV24199947
See: https://portal.msrc.microsoft.com/security-guidance/advisory/ADV24199947 for more information.
|
IIS Sites Information | Name | State | HSTS Enabled | Protocol - Bindings - Certificate |
Default Web Site | Started | False | http - *:80: - NULL https - :443: - F7F97090DCB6A9E0E230963027D295ADCD8A3568 http - 127.0.0.1:80: - NULL https - 127.0.0.1:443: - F7F97090DCB6A9E0E230963027D295ADCD8A3568 |
Exchange Back End | Started | False | http - *:81: - NULL https - *:444: - CCC5AB763449C5EC220F381F32CAC1305C1DA39C |
|
Application Pool Information | AppPoolName | State | GCServerEnabled | RestartConditionSet |
MSExchangeMapiFrontEndAppPool | Started | True | False |
MSExchangeOWAAppPool | Started | False | False |
MSExchangeECPAppPool | Started | False | False |
MSExchangeRestAppPool | Started | False | False |
MSExchangeMapiAddressBookAppPool | Started | False | False |
MSExchangeRpcProxyFrontEndAppPool | Started | False | False |
MSExchangePowerShellAppPool | Started | False | False |
MSExchangePowerShellFrontEndAppPool | Started | False | False |
MSExchangeRestFrontEndAppPool | Started | False | False |
MSExchangeMapiMailboxAppPool | Started | False | False |
MSExchangeOABAppPool | Started | False | False |
MSExchangePushNotificationsAppPool | Started | False | False |
MSExchangeOWACalendarAppPool | Started | False | False |
MSExchangeAutodiscoverAppPool | Started | False | False |
MSExchangeServicesAppPool | Started | False | False |
MSExchangeSyncAppPool | Started | True | False |
MSExchangeRpcProxyAppPool | Started | False | False |
|
Virtual Directory Locations | Name | ExtendedProtection | SslFlags | IPFilteringEnabled | URLRewrite | Authentication |
Default Web Site | None | False | False | | anonymous (default setting) |
Default Web Site/API | Require | True (128-bit) | False | | Windows (Negotiate,NTLM) anonymous (default setting) |
Default Web Site/Autodiscover | None | True (128-bit) | False | | Windows (Negotiate,NTLM) anonymous (default setting) basic |
Default Web Site/ecp | Require | True (128-bit) | False | | anonymous (default setting) basic |
Default Web Site/EWS | Allow | True (128-bit) | False | | Windows (Negotiate,NTLM) anonymous (default setting) |
Default Web Site/mapi | Require | True (128-bit) | False | | Windows (Negotiate,NTLM) |
Default Web Site/Microsoft-Server-ActiveSync | Allow | True (128-bit) | False | | basic |
Default Web Site/Microsoft-Server-ActiveSync/Proxy | Allow | True (128-bit) | False | | Windows (Negotiate,NTLM) |
Default Web Site/OAB | Allow | True (128-bit) | False | | Windows (Negotiate,NTLM) |
Default Web Site/owa | Require | True (128-bit) | False | | basic |
Default Web Site/PowerShell | None | False Cert(Accept) | False | | |
Default Web Site/Rpc | Require | True (128-bit) | False | | Windows (Negotiate,NTLM) basic |
Exchange Back End | None | False | False | | anonymous (default setting) |
Exchange Back End/API | Require | True (128-bit) | False | | Windows (Negotiate,NTLM) anonymous (default setting) |
Exchange Back End/Autodiscover | None | True (128-bit) | False | | Windows (Negotiate,NTLM) anonymous (default setting) |
Exchange Back End/ecp | Require | True (128-bit) | False | | Windows (Negotiate,NTLM) anonymous (default setting) |
Exchange Back End/EWS | Require | True (128-bit) | False | | Windows (Negotiate,NTLM) anonymous (default setting) |
Exchange Back End/mapi/emsmdb | Require | True | False | | Windows (Negotiate,NTLM) |
Exchange Back End/mapi/nspi | Require | True | False | | Windows (Negotiate,NTLM) |
Exchange Back End/Microsoft-Server-ActiveSync | Require | True (128-bit) | False | | basic |
Exchange Back End/Microsoft-Server-ActiveSync/Proxy | Require | True (128-bit) | False | | Windows (Negotiate,NTLM) |
Exchange Back End/OAB | Require | True (128-bit) | False | | Windows (Negotiate,NTLM) |
Exchange Back End/owa | Require | True (128-bit) | False | | Windows (Negotiate,NTLM) anonymous (default setting) |
Exchange Back End/PowerShell | Require | True (128-bit) | False | | Windows (Negotiate,NTLM) |
Exchange Back End/Rpc | Require | True (128-bit) | False | | Windows (Negotiate,NTLM) |
Exchange Back End/RpcWithCert | Require | True (128-bit) | False | | Windows (Negotiate,NTLM) |
|