Hybrid and Edge servers

Matthew Ridley 171 Reputation points
2022-04-28T10:53:24.07+00:00

Hi,

We are planning the move from Exchange On-premises to Exchange Hybrid and I have a few questions about the Edge Transport server and how it fits in.

The plan is to place an Edge Transport server in our DMZ so that incoming email from EOP will go via the Edge server before reaching the Exchange servers. This is to limit the exposure of our Exchange servers to the Internet
Does the Malware and Anti-Spam need to be enabled and configured on this edge server? Is there a recommendation for this?

We currently have a third party mail system that we use for email security and emails generated from servers on the DMZ are directed to this server and the email security server routes the emails either internally or to the Internet. This server will be going. Will we need an additional Edge transport server separate to the one used for Hybrid for this or can the Hybrid Edge transport server be used? I am not quite sure if the Edge transport server used for Hybrid can only be used for the Hybrid and nothing else.

Thank you

Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,373 questions
Microsoft Exchange Hybrid Management
Microsoft Exchange Hybrid Management
Microsoft Exchange: Microsoft messaging and collaboration software.Hybrid Management: Organizing, handling, directing or controlling hybrid deployments.
1,904 questions
0 comments No comments
{count} votes

1 additional answer

Sort by: Most helpful
  1. Andy David - MVP 142.5K Reputation points MVP
    2022-04-28T11:11:23.703+00:00

    You can install anti -spam on the Edge, yes.
    https://learn.microsoft.com/en-us/exchange/antispam-and-antimalware/antispam-protection/antispam-protection?view=exchserver-2019#antispam-agents-on-edge-transport-servers

    Anti-malware is already enabled:
    https://learn.microsoft.com/en-us/exchange/antispam-and-antimalware/antimalware-protection/antimalware-procedures?view=exchserver-2019

    I would argue that you dont need anti-spam however and would not enble on the Edge if you are routing everything to and from the internet through EOP ( Set your mx to EOP as soon as possible)