Skip to main content
io4 Technologies

Modern Work

Exchange 2019 and 2016 end of support: no more security updates after October 31, 2026

The Extended Security Update program for Exchange Server 2016 and 2019 ends on October 31, 2026, with no further extension. The real timeline, the three exit paths and the coexistence trap with Exchange SE.

By Jordane Dours 5 min read

The Extended Security Update program for Exchange Server 2016 and 2019 ends on October 31, 2026, with no further extension. The real timeline, the three exit paths and the coexistence trap with Exchange SE.

On October 31, the reprieve for Exchange 2016 and 2019 ends

On October 31, 2026, Microsoft ships its last security updates for Exchange Server 2016 and 2019. After that date, no more fixes, even for organizations that paid for the Extended Security Update (ESU) program. Exchange 2019 and 2016 actually reached end of support on October 14, 2025: what is ending now is the reprieve.

The Exchange team has confirmed there will be no third period. Any organization still running an on-premises Exchange server, including the single hybrid server kept "for management", has four weeks to decide what comes next.

Exchange 2019 and 2016 end of support: the real timeline

The reprieve came in two stages, and the second one will not be renewed.

  • October 14, 2025: end of support for Exchange 2016 and Exchange 2019.
  • October 2025 to April 2026: first ESU period.
  • May 1 to October 31, 2026: second period, sold under a separate contract. Enrolment in the first period did not carry over.
  • After October 31, 2026: no fixes, however severe the vulnerability.

Narrow coverage, even during the reprieve

Only vulnerabilities rated Critical or Important by Microsoft were fixed, and only on Exchange 2016 CU23 and Exchange 2019 CU14 or CU15. A server left on an older cumulative update was not covered, ESU or not.

Why an unpatched Exchange server is a risk of its own

An Exchange server is not a file server hidden behind the firewall. It publishes Outlook on the web, ActiveSync and Autodiscover to the internet, it holds every mailbox in the organization and it has elevated rights in Active Directory. It is a well-known target: the ProxyLogon vulnerabilities of March 2021 were exploited at scale within days.

Keeping such a server without fixes is also a compliance issue. Quebec's Law 25 and the GDPR in France require reasonable security measures to protect personal information. An exposed system left unpatched on purpose is hard to defend after a privacy incident.

Three exit paths

The right choice depends on what is still on premises and why it is still there.

  • Exchange Server SE (Subscription Edition), to stay on premises. From Exchange 2019 CU14 or CU15, the upgrade is done in place, like a cumulative update. From Exchange 2016, there is no shortcut: you add new servers, move the mailboxes, then remove the old ones. The model moves to a subscription.
  • Exchange Online, to leave the patching cycle behind. Mailboxes move to Microsoft 365 and server updates are no longer your problem.
  • Removing the last hybrid server. Many organizations already on Exchange Online keep an Exchange 2016 or 2019 server only to manage recipients. Microsoft lets you remove it and switch to the Exchange Management Tools in PowerShell, under certain conditions: no mailboxes or public folders left on premises, synchronization through Entra ID Connect or cloud sync, and no need for the on-premises Exchange admin center or for auditing of administrative actions.

The coexistence trap

The smooth migration, where old and new servers run side by side while mailboxes move, has an expiry date. According to Microsoft documentation, Exchange SE CU2 setup will block coexistence with any Exchange version that is not supported when it is released. Exchange 2016 and 2019 will be in that situation. No release date has been announced so far.

In practice, an organization that waits may have to remove all its old servers before it can install the next Exchange SE update. That is a much harsher cutover than a gradual migration. And for those still running Exchange 2013 in their environment, Exchange SE already refuses to coexist with it from its very first release.

Four weeks: where to start

October 31 leaves no room for a big project, but it does leave time to decide and to reduce the risk.

  • Inventory every Exchange server, including hybrid and "forgotten" ones, with their version and cumulative update.
  • List what still runs through them: SMTP relay for applications and multifunction printers, shared mailboxes, public folders, connectors.
  • Pick a target for each server: Exchange SE, Exchange Online or outright removal.
  • If the migration runs past October 31, limit what is published to the internet and step up monitoring of the server in the meantime.

Conclusion: decide before the last fix

October 31 is not just another date on the Microsoft calendar. It is the last day an Exchange 2016 or 2019 server can still be patched. After that, every new vulnerability stays open for good.

If you don't know exactly how many Exchange servers are still running in your organization, or what depends on them, talk to an io4 expert. We take the inventory, recommend the right target for each server and run the migration to Exchange Online or Exchange SE.

Keywords:Exchange 2019 end of supportExchange 2016 end of supportExchange Server ESU October 2026Exchange Server SE migrationExchange Online migrationremove last Exchange hybrid server

Want to talk it through?

Let's spend 30 minutes on your situation.

A free assessment with an io4 architect. No commitment, no pressure.

Book my assessment
Let's talk about your project

30 minutes to frame what matters.

A direct conversation with one of our experts. No commitment, no pressure. You leave with a clear, reasoned perspective on your situation.

Or call us directly:+1 888 285 9583
Free assessment