OWA Light Is Gone for Good After Microsoft’s August Exchange Update
Microsoft has released the August 2026 Exchange Server security updates for Exchange Server Subscription Edition, Exchange Server 2019, and Exchange Server 2016.
The new Exchange Server security updates address several vulnerabilities, with most of the fixes targeting spoofing and elevation of privilege issues.
OWA Light is now permanently disabled
The August security updates permanently disable Outlook Web App Light in Exchange Server.
Microsoft announced the feature’s deprecation several years ago and reminded Exchange administrators in July that it would start disabling OWA Light in August 2026.
Organizations that cannot install the latest Exchange Server updates should manually disable OWA Light to reduce potential security risks.
Known Exchange hybrid issue remains
The August release also carries forward a known issue that Microsoft first documented in June 2026.
It affects Exchange Server Subscription Edition, Exchange Server 2019, and Exchange Server 2016 in certain hybrid configurations involving shared mailboxes hosted in Exchange Online and mailboxes hosted on-premises.
The problem can appear when organizations use Send As or Send on Behalf permissions while enabling MessageCopyForSentAsEnabled or MessageCopyForSendOnBehalfEnabled.
In affected environments, messages sent as or on behalf of a shared mailbox can also appear in the shared mailbox’s inbox. Exchange delivers the original message as an attachment inside a separate wrapper message.
Microsoft plans to fix the issue in a future Exchange Server release.
Exchange 2016 and 2019 updates have limited availability
The Exchange Server Subscription Edition update is available to all customers.
However, Microsoft provides the Exchange Server 2019 and Exchange Server 2016 security updates privately only to customers enrolled in Period 2 of Extended Security Updates.
Period 2 ESU coverage provides Exchange Server 2016 and 2019 security updates through October 2026.
The Exchange fixes arrived alongside Microsoft’s wider August security rollout. The August 2026 Patch Tuesday updates fixed around 400 vulnerabilities, including dozens rated Critical.
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages