Exchange 2016 Folders to exclude during antivirus scanning

Exclude the following folders from file-level scanning and memory-resident scanning on Exchange 2016 servers.

  • %SystemRoot%\Cluster

The cluster quorum database and other files for database availability groups (DAGs) on mailbox servers.

  • %SystemDrive%\DAGFileShareWitnesses\
The witness directory on the witness server that’s configured for the DAG. The witness server can be any Microsoft Windows server in the local AD forest that isn’t already a member of the DAG.
  • %ExchangeInstallPath%ClientAccess\OAB

Offline Address Book files on mailbox servers.

  • %ExchangeInstallPath%FIP-FS

Content scanning that’s used by the Malware agent and data loss prevention (DLP) on mailbox servers.

  • %ExchangeInstallPath%GroupMetrics

Group Metrics files that are used to calculate values for the Large Audience and External Recipients MailTips on Mailbox servers.

  • %ExchangeInstallPath%Logging
This folder contains many different types of Exchange logs in subfolders. For example:
    • Calendar Repair Assistant logs
    • Managed Folder Assistant logs
    • IMAP4 protocol logs
    • POP3 protocol logs 
  • %ExchangeInstallPath%Mailbox
Exchange databases, checkpoint files, and log files. By default, these files are located in subfolders based on the name of the database.
By default, database context index files are located in the same folder as the database files in a subfolder that’s named after the GUID of the database.
  • %ExchangeInstallPath%TransportRoles\Data\Adam

Active Directory Lightweight Directory Services (AD LDS) and log files on Edge transport servers.

  • %ExchangeInstallPath%TransportRoles\Data\IpFilter

IP filter database, checkpoint, and log files on Edge transport servers.

  • %ExchangeInstallPath%TransportRoles\Data\Queue

Queue database, checkpoint, and log files on Mailbox servers and Edge Transport servers.

  • %ExchangeInstallPath%TransportRoles\Data\SenderReputation

Sender Reputation database, checkpoint, and log files on Mailbox servers and Edge Transport servers.

  • %ExchangeInstallPath%TransportRoles\Data\Temp

Content conversion that’s done in the transport pipeline on Mailbox servers and Edge Transport servers.

  • %ExchangeInstallPath%TransportRoles\Logs
Mail flow and transport pipeline logs are located in subfolders on Mailbox servers and Edge Transport servers.
    • Agent logging
    • Connectivity logging
    • Message tracking
    • Pipeline tracing
    • Send and Receive connector protocol logging
  • %ExchangeInstallPath%TransportRoles\Pickup

The Pickup directory is used by administrators for mail flow testing or by applications that need to create and submit their own message files on Mailbox servers and Edge Transport server.

  • %ExchangeInstallPath%TransportRoles\Replay

The Replay directory receives messages from foreign gateway servers and can also be used to resubmit messages that administrators export from the queues of Exchange servers on Mailbox servers and Edge Transport server.

  • %ExchangeInstallPath%UnifiedMessaging\Grammars

Grammar files for different locales, for example en-EN or es-ES on Mailbox servers.

  • %ExchangeInstallPath%UnifiedMessaging\Prompts

Voice prompts, greetings, and informational message files on Mailbox servers.

  • %ExchangeInstallPath%UnifiedMessaging\Temp

Temporary files generated by Unified Messaging on Mailbox servers.

  • %ExchangeInstallPath%UnifiedMessaging\Voicemail

Voice mail files that are temporarily stored on Mailbox servers.

  • %ExchangeInstallPath%Working\OleConverter

Transport Neutral Encoding Format (TNEF), also known as Rich Text Format (RTF), to MIME/HTML conversions on Mailbox servers and Edge Transport server.

  • %SystemDrive%\inetpub\temp\IIS Temporary Compressed Files

Internet Information Services (IIS) compression folder that’s used with Outlook on the web on Mailbox servers.

  • %SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\Temporary ASP.NET Files
Temporary files that are used with Exchange services. These files are located in the following subfolders on Mailbox servers:
    • autodiscover
    • ecp
    • ews
    • mapi
    • mapi_emsmdb
    • microsoft-server-activesync
    • oab
    • owa
    • owa_calendar
    • powershell
    • root
    • rpc
  • %SystemRoot%\System32\Inetsrv

IIS system files on Mailbox servers.

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Google photo

You are commenting using your Google account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s

This site uses Akismet to reduce spam. Learn how your comment data is processed.