Skip to content

ED 21-02, Mitigate Microsoft Exchange On-Premises Product Vulnerabilities

RetiredCISA · Emergency Directive · March 3, 2021

Summary

Required agencies running on-premises Microsoft Exchange servers to check them for signs of compromise, apply Microsoft's emergency patches or disconnect the servers, report findings to CISA, and harden the servers.

Read it on www.cisa.gov

What FedXchange has recorded

No changes recorded. The watch records a new document and any change in its status.

Issuer
Cybersecurity and Infrastructure Security Agency (CISA)
Type
Emergency Directive
Number
ED 21-02
Issued
March 3, 2021
Status
Retired

Closed by its issuer (CISA's term for a directive that has done its job).

Retired by CISA on January 8, 2026; supplemental directions on March 31 and April 13, 2021 added scanning and patching requirements.

Get new governance by email

A weekly email on Fridays, an alert on the day the watch finds something new, or both. Free.

Send me

We use your address only to send what you choose, and every email has a one-click unsubscribe. Read the privacy notice.