Exchange On‑premises Mitigation Tool (EOMT)
Installation of the applicable Exchange Server Security Update is the only way to fully protect your servers . The mitigations applied by this tool are a temporary measure to reduce exposure until patching can be completed.
The Exchange On-premises Mitigation Tool (EOMT) applies IIS URL Rewrite mitigations for known Exchange Server CVEs. It replaces the legacy EOMT.ps1 and EOMTv2.ps1 scripts with a single, extensible tool that supports multiple CVEs from a unified interface.
The recommended way to use EOMT. If -CVE is not specified, an interactive prompt displays available mitigations sorted by priority and allows selection.
Requires Exchange Management Shell. Servers are checked for vulnerability before mitigations are applied. Servers that are already patched or unreachable are skipped automatically.
Restores the original IIS configuration from the JSON backup file created during apply.
Checks each target server and reports vulnerability status using four properties: Code Fix (whether the Exchange security update is installed), Mitigation (whether an enabled IIS URL Rewrite rule is present), Disabled Rules (rules matching behavior but currently disabled), and Rule Name Match (whether the expected rule name exists with different behavior). No changes are made.
The output uses color-coded status messages:
Q: What happens if I run the script without any parameters?
A: The script prompts you to select a CVE from the available mitigations. It then checks if your local server needs protection (by verifying both the security update and mitigation status) and applies the mitigation if needed.
Q: Can I apply mitigations for multiple CVEs at once?
A: Run the script once per CVE. Each CVE creates its own JSON backup file and can be rolled back independently.
Q: What if the mitigation was previously applied by the legacy EOMT.ps1 or EOMTv2.ps1?
A: The new EOMT applies the same IIS URL Rewrite rules as the legacy scripts. If the rule already exists, the apply operation completes without duplicating it. To roll back a mitigation applied by a legacy script, use that same legacy script's rollback mechanism, as the JSON backup file format differs.
Q: What if the mitigation rule is disabled or has a name conflict?
A: If a mitigation rule exists but is disabled, -ShowMitigationStatus reports it in red. If the expected rule name is in use by a different rule (name conflict), it is also flagged. In both cases, run -RollbackMitigation to remove the conflicting or disabled rule first, then re-run EOMT to apply a clean mitigation.
Q: Does this script make changes that affect Exchange functionality?
A: The URL Rewrite mitigations do not disable Exchange features. They add request filtering rules that block known attack patterns while allowing normal traffic.
Q: What if I don't have an internet connection?
A: The IIS URL Rewrite Module must be installed manually if not already present. Use -SkipAutoUpdate to skip the version check. MSERT requires internet access to download.
Use of the Exchange On-premises Mitigation Tool and the Microsoft Safety Scanner are subject to the terms of the Microsoft Privacy Statement .
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
