ED 21-02, Mitigate Microsoft Exchange On-Premises Product Vulnerabilities
RetiredCISA · Emergency Directive · March 3, 2021
Summary
Required agencies running on-premises Microsoft Exchange servers to check them for signs of compromise, apply Microsoft's emergency patches or disconnect the servers, report findings to CISA, and harden the servers.
What FedXchange has recorded
No changes recorded. The watch records a new document and any change in its status.
- Issuer
- Cybersecurity and Infrastructure Security Agency (CISA)
- Type
- Emergency Directive
- Number
- ED 21-02
- Issued
- March 3, 2021
- Status
- Retired
Closed by its issuer (CISA's term for a directive that has done its job).
Retired by CISA on January 8, 2026; supplemental directions on March 31 and April 13, 2021 added scanning and patching requirements.
Get new governance by email
A weekly email on Fridays, an alert on the day the watch finds something new, or both. Free.