Disable OWA on exchange 2016

Dani Kaplan 61 Reputation points
2021-09-13T13:38:54.487+00:00

I was told my server was probably hacked via OWA vulnerability (server is patched by windows update but not with exchange upgrade versions.
Can I rename or remove the owa directory under IIS to block OWA
I want to keep active sync working.

Exchange | Exchange Server | Management
0 comments No comments
{count} votes

Accepted answer
  1. Andy David - MVP 158K Reputation points MVP Volunteer Moderator
    2021-09-13T16:29:53.117+00:00

    You can disable the OWA app pool in IIS.

    However, if the server is compromised that is not sufficient. You need to mitigate, apply the latest CUs and SUs and/or rebuild ASAP!

    0 comments No comments

2 additional answers

Sort by: Most helpful
  1. Dani Kaplan 61 Reputation points
    2021-09-13T18:08:28.317+00:00

    I've disabled MExcahageOWAAppPool and OWACalendarAppPool

    I am thinking about rebuild, but it's complicated as exchange server is also the single DC. (Small office)

    0 comments No comments

  2. Andy David - MVP 158K Reputation points MVP Volunteer Moderator
    2021-09-13T18:12:00.357+00:00

    Ok, then I would consider building a new DC and Exchange Server and move mailboxes.
    Seriously.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.