Mitigations Cloud endpoint is not reachable Exchange 2019 Deployment

ZIYAD MORSI 0 Reputation points
2025-03-06T07:37:01.5233333+00:00

I receieve below warning during Exchange 2019 deployment
Mitigations Cloud endpoint is not reachable

https://learn.microsoft.com/en-us/exchange/plan-and-deploy/deployment-ref/ms-exch-setupreadiness-mitigationscloudendpointunreachable?view=exchserver-2019

Microsoft Exchange Hybrid Management
Microsoft Exchange Hybrid Management
Microsoft Exchange: Microsoft messaging and collaboration software.Hybrid Management: Organizing, handling, directing or controlling hybrid deployments.
2,250 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Kaiyue Gong (Shanghai Wicresoft Co Ltd) 710 Reputation points Microsoft External Staff
    2025-03-07T07:34:40.0733333+00:00

    Hi @ZIYAD MORSI,

    Thank you for posting your question in the Microsoft Q&A forum.

    Based on your description, your issue is that you are experiencing a warning that Mitigations Cloud endpoint is not reachable when deploying exchange2019.

    1. about the warning:

    • You can ignore the warning to continue installing Exchange 2019, but the Exchange Emergency Mitigation (EM) service may not work properly.

    2. About the EM service:

    • The Exchange Emergency Mitigation Service (EM Service) helps secure Exchange Server by applying mitigations to address any potential threats against the server. It uses the cloud-based Office Config Service (OCS) to check and download available mitigations and sends diagnostic data to Microsoft. o EM is an optional service.
    • EM is an optional service that administrators have the ability to disable. In fact, on Exchange servers without an Internet connection, EM needs to be disabled because it does not work without an Internet connection. In this case, or when you do not want to use automatic mitigation, it is recommended to use EOMT to manually apply the available mitigation features.
    • If you have an outbound Internet connection but are using restrictions, you need to enable the outbound connection to the OCS, i.e. https://officeclient.microsoft.com.

    3. Ways to resolve the warning:

    • Check the connection: using the ‘Test-NetConnection officeclient.microsoft.com -Port 443’ command, check the connection between the computer with Exchange Server installed and this endpoint. If ‘TcpTestSucceeded: False’ is returned, you need to troubleshoot firewall or proxy issues.
    • Firewall issues: Make sure that connections to officeclient.microsoft.com are excluded from SSL checking workflows performed by firewalls or third-party software such as AntiVirus, as this may break the certificate validation logic built into the EM service.
    • Web proxy issues: If a web proxy is deployed for outbound connections, the InternetWebProxy parameter needs to be configured on the Exchange server.

    More details can be found in the document: https://learn.microsoft.com/en-us/exchange/plan-and-deploy/post-installation-tasks/security-best-practices/exchange-emergency-mitigation-service?view=exchserver-2019#connectivity

    If the answer is helpful, please click on “Accept answer” as it could help other members of the Microsoft Q&A community who have similar questions and are looking for solutions.

    Thank you for your support and understanding.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.