Exchange 2019 End of Life: Support Ended, Your Options


For teams that run Exchange Server on-premises, the Exchange 2019 end of life date has already passed: support for both Exchange Server 2019 and Exchange Server 2016 ended on October 14, 2025. This is not a future planning deadline. Any Exchange 2016 or 2019 server still in production has been running without security updates for roughly ten months. This page lists the verified dates, what stopped on that date, the documented attack history against unpatched Exchange, and the three exit paths: an upgrade to Exchange Server Subscription Edition (SE), a migration to Exchange Online, or a hybrid configuration.
Exchange 2019 end of life: the dates
Both versions followed the Microsoft Fixed Lifecycle Policy and reached end of support on the same day. The dates below are taken from the Microsoft Lifecycle pages for Exchange Server 2019 and Exchange Server 2016.
| Product | End of mainstream support | End of support (end of life) |
|---|---|---|
| Exchange Server 2016 | October 13, 2020 | October 14, 2025 |
| Exchange Server 2019 | January 9, 2024 | October 14, 2025 |
| Exchange Server SE | Modern Lifecycle Policy; supported at least through December 31, 2035 | |
Unlike Windows Server or SQL Server, Exchange has no Extended Security Updates program. There is no paid bridge. Per the Exchange Server 2019 and 2016 end of support roadmap, Microsoft no longer provides technical support, bug fixes, security fixes, or time zone updates for either version.
What ended, what still runs
An Exchange 2016 or 2019 server did not stop working on October 14, 2025. Mail flow, mailbox access, and existing hybrid connections continue. What changed:
- No security updates. Vulnerabilities found after the date are not patched on 2016 or 2019. Because Exchange SE RTM is code-equivalent to Exchange 2019 CU15, security updates shipped for SE frequently document which components are exploitable on the unpatched older versions.
- No Microsoft support cases. Standard support paths for the product are closed. A database that fails to mount or a transport queue that stalls has no vendor escalation.
- No time zone updates. Calendar entries drift when jurisdictions change daylight-saving rules.
- Coexistence is being cut off. The setup process for Exchange Server SE CU2 blocks coexistence with any version of Exchange that is out of support, per the upgrade documentation. Organizations that wait lose the ability to run 2016/2019 alongside a current SE build during their own migration.
- Compliance exposure. PCI DSS requires vendor patches for known vulnerabilities; the HIPAA Security Rule requires protection against reasonably anticipated threats to ePHI. An internet-facing mail server that can no longer receive patches is difficult to defend in either framework, and cyber-insurance questionnaires ask about unsupported software directly.
The attack record on unpatched Exchange
The risk of running Exchange without patches is not hypothetical; it is documented by the US Cybersecurity and Infrastructure Security Agency. In March 2021, CISA issued Emergency Directive 21-02 and advisory AA21-062A after observing active exploitation of on-premises Exchange vulnerabilities (the ProxyLogon chain, attributed by Microsoft to the HAFNIUM actor), ordering federal agencies to patch or disconnect affected servers. In August 2025, weeks before end of support, CISA issued Emergency Directive 25-02 for CVE-2025-53786, a hybrid-deployment privilege-escalation vulnerability that allows an actor with administrative access to an on-premises Exchange server to pivot into the connected cloud environment.
Two facts follow from that record. On-premises Exchange is a recurring, actively exploited target; and the 2025 directive shows that a compromised on-premises server can be a path into Microsoft 365, so an unpatched 2016/2019 hybrid server is an exposure for the cloud tenant as well. Every vulnerability disclosed since October 14, 2025 remains open on those servers permanently.
Option 1: upgrade to Exchange Server SE
Exchange Server Subscription Edition is the only supported on-premises version. It follows the Modern Lifecycle Policy with no fixed end-of-support date, listed as supported at least through December 31, 2035. The upgrade path depends on the starting version, per the Microsoft upgrade documentation:
- From Exchange 2019: in-place upgrade, supported from CU14 or CU15. The process is the same as installing a cumulative update, because SE RTM is code-equivalent to 2019 CU15 apart from the license agreement, product name, and build number. Bring the server to CU14/CU15 first, then run SE setup over it.
- From Exchange 2016: no in-place upgrade exists. The path is a legacy upgrade: install new servers running Exchange SE (or 2019 CU15 as an interim hop, then in-place to SE), move mailboxes and resources across, and uninstall the 2016 servers. Exchange 2016 should be on CU23 before starting.
Licensing changed with SE: server licenses moved to a subscription model requiring Software Assurance or an equivalent subscription, and Microsoft raised server and CAL pricing effective August 2025. Details on builds, licensing, and the CU cadence are in our Exchange Server SE overview. The practical deadline inside this option is SE CU2: once it ships, its setup blocks coexistence with 2016 and 2019, which closes the normal side-by-side migration route.
Exchange 2016 end of life: the same date, a longer path
Exchange 2016 reached end of life on the same day as 2019, October 14, 2025, but its position is worse in two ways. First, mainstream support ended back in October 2020, so 2016 servers have received security-only servicing for five years and no in-place path to SE exists; every 2016 exit is a server build plus mailbox moves. Second, Exchange 2016 runs on Windows Server 2012 R2 or 2016 hosts in most deployments, and Windows Server 2016 itself reaches end of support in January 2027, so the host operating system is on its own clock. A 2016 organization choosing to stay on-premises does a legacy upgrade directly to SE on new Windows Server 2022/2025 hosts; the interim hop through 2019 CU15 only makes sense where existing hardware must be reused for an in-place finish. For most 2016 estates the shorter project is a migration to Exchange Online, since the mailbox-move work is required either way.
Option 2: migrate to Exchange Online / Microsoft 365
Microsoft's recommended destination is Exchange Online. The migration approaches are the standard set: cutover migration for small organizations moving everything at once, minimal or full hybrid for staged mailbox moves with coexistence, and IMAP or third-party tooling for edge cases. Mailbox data, public folders, and mail flow all have documented move paths from 2016 and 2019. The end-to-end procedure, including endpoint setup, batching, and DNS cutover, is covered in our Exchange to Office 365 migration walkthrough.
Points specific to the post-deadline situation:
- Exchange 2016 and 2019 can still connect to Exchange Online and run migration batches; end of support did not disable hybrid connectivity. Microsoft's roadmap document explicitly describes using the existing 2016/2019 servers to migrate mailboxes and then dealing with the servers afterward.
- CVE-2025-53786 applies to hybrid configurations. A hybrid server used as a migration bridge should have the April 2025 hotfix and dedicated hybrid app configuration applied before the project starts, since no further fixes will ship for it.
- Migration removes the patching problem entirely: Exchange Online is serviced by Microsoft with no customer-side version management.
Option 3: hybrid, and the last Exchange server
Organizations that move all mailboxes to Exchange Online but keep Microsoft Entra Connect synchronizing Active Directory have a known constraint: on-premises AD remains the source of authority for Exchange recipient attributes. The current guidance in the decommissioning documentation gives two supported endings. Either keep one Exchange server, upgraded to SE, for recipient management; or remove the last Exchange server entirely and manage recipients with the Exchange management tools, which install the management shell and AD PowerShell module without a running server. The management-tools path suits organizations with no on-premises mailboxes and no SMTP relay requirement; the retained-server path suits everyone else. What is not supported is editing Exchange attributes directly with ADSI Edit and no management tooling. A retained management server still needs to be a supported version, which means the last 2016/2019 box gets upgraded to SE or replaced even if it hosts nothing.
Decision table
| Situation | Sensible path |
|---|---|
| Exchange 2019 on CU14/CU15, staying on-premises for regulatory or data-residency reasons | In-place upgrade to Exchange SE now; before SE CU2 ships |
| Exchange 2016, staying on-premises | Legacy upgrade: new SE servers on Windows Server 2022/2025, move mailboxes, uninstall 2016 |
| No regulatory requirement to stay on-premises | Migrate to Exchange Online; cutover for small estates, hybrid batches for larger ones |
| Mailboxes already in Exchange Online, 2016/2019 kept for recipient management | Upgrade the last server to SE, or decommission it and use the Exchange management tools |
| Hybrid server exposed to the internet, unpatched since October 2025 | Apply CVE-2025-53786 mitigations immediately, then exit on the shortest path available |
| Exchange 2016 on Windows Server 2012 R2 | Two end-of-life products on one machine; prioritize above everything else |
Timeline arithmetic
As of August 2026, an Exchange 2016 or 2019 server has been out of support for more than nine months, spanning roughly ten monthly security-update cycles it did not receive. The forward deadline is SE CU2, which will refuse to coexist with out-of-support versions; after that, the standard migration pattern of running old and new servers side by side stops being available, leaving only offline or third-party move methods. An Exchange Online migration for a small organization takes weeks; a legacy upgrade from 2016 to SE with coexistence, mailbox moves, and hybrid reconfiguration takes one to three months for a typical estate. Neither project gets shorter by waiting, and the coexistence window only narrows.
FAQ
When was Exchange 2019 end of life?
October 14, 2025. Exchange Server 2016 ended on the same date. Both are past end of support now and receive no security updates.
Is there an ESU program for Exchange 2016 or 2019?
No. Unlike Windows Server and SQL Server, Exchange has no Extended Security Updates program. The only supported states are Exchange Server SE on-premises or Exchange Online.
Can Exchange 2019 be upgraded in place to Exchange Server SE?
Yes, from CU14 or CU15. The upgrade runs like a cumulative update installation because SE RTM is code-equivalent to 2019 CU15. Exchange 2016 has no in-place path and requires a legacy upgrade to new servers.
Does Exchange 2016 still work with Office 365 hybrid?
Hybrid connectivity and migration batches still function on 2016 and 2019. The servers themselves are unsupported, so the hybrid configuration receives no further security fixes; CISA's ED 25-02 addressed a hybrid privilege-escalation vulnerability in exactly this configuration.
Can the last Exchange server be removed after migrating to Exchange Online?
Yes, if Entra Connect synchronization remains, recipient management can move to the Exchange management tools instead of a running server. Organizations that need SMTP relay or prefer a management server keep one, upgraded to SE.
Protect your organization with expert healthcare IT support designed for HIPAA compliance.
HIPAA-Compliant IT SupportTopics

Sreenivasa Reddy G
Founder & CEO • 15+ years
Sreenivasa Reddy is the Founder and CEO of Medha Cloud, recognized as "Startup of the Year 2024" by The CEO Magazine. With over 15 years of experience in cloud infrastructure and IT services, he leads the company's vision to deliver enterprise-grade cloud solutions to businesses worldwide.
More in Exchange Server
View all
What Is Microsoft Exchange Server? Editions & Versions
9 min read

Exchange Server Management Tools: EMS, EAC & Options
9 min read

Exchange Hybrid: How It Works, Setup & Requirements
10 min read

Exchange Database Recovery: ESEutil & Dirty Shutdown
10 min read

Exchange DAG: Setup, Failover & Troubleshooting
9 min read

Exchange Admin Center: How to Access & Use the EAC
9 min read