Microsoft has begun a strict, time‑boxed push to move Exchange hybrid customers off a Microsoft‑managed shared service principal and onto a dedicated Exchange hybrid app in Entra ID — a change driven by a high‑severity hybrid vulnerability and enforced through short, scheduled EWS traffic blocks...
Microsoft’s Exchange team has given hybrid administrators a clear-but-urgent migration mandate: switch to the dedicated Exchange hybrid app and update on‑prem servers now, or face temporary disruptions in September and October followed by a permanent enforcement that will stop rich coexistence...
admin consent
april 2025 hotfix
azure ad
cisa
cisa-ed-25-02
cve-2025-53786
entra id
ews
ews block
exchange hybrid
graph api
hcw
hybrid apps
hybrid coexistence
hybrid deployment
hybrid migration
it governance
keycredentials
microsoft 365
microsoft education
oauth
on-prem to online
phasedenforcement
security
security audits
security hardening
service principal
setting override