Exchange Server 2016 and 2019 went out of support on October 14, 2025, and Microsoft has said the paid Extended Security Update (ESU) program ends with October 2026, after which no more fixes ship for either version. You have two supported destinations: Exchange Server Subscription Edition (SE), which Exchange 2019 CU14 or CU15 servers can upgrade to in place and Exchange 2016 servers reach through a side-by-side legacy upgrade, or Exchange Online, reached through a hybrid or cutover migration. If you keep Active Directory as your source of authority, plan on at least one Exchange SE server even after every mailbox is in the cloud.
Who this is for and what you will have at the end
This guide is for administrators who still run Exchange 2016 or 2019 on-premises, whether as the main mail platform or as a hybrid server kept for management and relay. At the end you will have:
- A clear picture of what end of support means for you right now.
- A decision between Exchange Server SE, Exchange Online, or both.
- The step-by-step path for each option, including the commands that matter.
- A list of the blockers that stop upgrades and hybrid features, with fixes.
What end of support means in practice
Since October 14, 2025, Microsoft no longer provides the following for Exchange 2016 and 2019:
- Technical support for problems.
- Bug fixes for stability and usability issues.
- Security fixes for vulnerabilities.
- Time zone updates.
Your servers keep running and mail keeps flowing. The risk is that the next vulnerability in an internet-facing server never gets patched. Microsoft offered a paid ESU program to cover the gap; customers who enrolled receive the December 2025 and later security updates for Exchange 2016 and 2019. In July 2026 the Exchange team stated that once October 2026 ends there will be no further updates for Exchange 2016 or 2019, even for organizations with ESU, and that the program won't be extended again. At the time of writing (October 2026), that leaves only weeks.
Hybrid features have their own deadline that has already passed. Since October 31, 2025, free/busy, MailTips and profile photo sharing require the dedicated Exchange hybrid application, which only works on specific builds: Exchange 2016 CU23 and 2019 CU14 or CU15 with the April 2025 Hotfix Update or later, or Exchange Server SE.
Choose your destination
| Option | Starting point | How | Main constraint |
|---|---|---|---|
| In-place upgrade to Exchange SE | Exchange 2019 CU14 or CU15 | Run Exchange SE setup over the existing install, like a CU | Can't be uninstalled to roll back; customizations need re-applying |
| Legacy upgrade to Exchange SE | Exchange 2016 (or 2019 on old hardware or Windows) | Add SE servers, move mailboxes and services, remove old servers | All 2016 servers, including Edge, must run CU23 to coexist |
| Move to Exchange Online, keep one SE server | Any supported hybrid | Hybrid remote moves, then shrink on-premises to an SE management server | Still an on-premises server to patch |
| Move to Exchange Online, remove all servers | Any supported hybrid | Hybrid moves, then transfer Exchange attribute management to the cloud and decommission | More preparation for recipient management and relay |
Microsoft's own position is that a full move to Microsoft 365 gives the most value, but organizations with regulatory, data residency or specific on-premises requirements should upgrade to Exchange SE. The options also combine: mailboxes in Exchange Online, with an Exchange SE server kept for recipient management and SMTP relay.
Exchange SE facts that affect your plan
- Lifecycle. Exchange Server SE follows the Modern Lifecycle Policy and has been in support since July 1, 2025. There is no fixed end date, provided you keep current with updates.
- Builds. Exchange SE RTM is build
15.2.2562.17. At the time of writing, Microsoft's build list shows only RTM plus monthly security updates (the newest is RTM Sep26SUv2,15.2.2562.53, released October 2, 2026); no cumulative update after RTM is listed yet. - Coexistence. SE RTM setup blocks coexistence with Exchange 2013. Setup for SE CU2 will prohibit coexistence with any version that isn't supported at release, which means Exchange 2016 and 2019 must be gone before you install CU2.
- Product key. SE RTM doesn't need a new product key and keeps working after a legacy or in-place upgrade. Microsoft says a future cumulative update will introduce a new product key requirement.
- Active Directory. Microsoft's version table shows Exchange SE RTM with the same schema
rangeUpper(17003) and objectVersion values as Exchange 2019 CU15.
Prerequisites
- An account in the Organization Management role group for setup, plus Schema Admins and Enterprise Admins if Active Directory preparation is needed.
- A tested backup of Active Directory and Exchange.
- A record of customizations (
web.config,EdgeTransport.exe.config, TLS and cipher settings), because setup overwrites them. - Servers that meet the Exchange 2019 and SE system requirements and the supported Windows Server and .NET Framework versions in the Exchange Server supportability matrix.
Step 1: Inventory every server and build
Find the exact build on each server, including security updates:
Get-ExchangeServer | Format-List Name,Edition,AdminDisplayVersion
Get-Command Exsetup.exe | ForEach-Object {$_.FileVersionInfo}AdminDisplayVersion shows the CU only. The ExSetup.exe file version (run on each server) also reflects SUs and HUs. Microsoft recommends the Exchange HealthChecker script (https://aka.ms/exchangehealthchecker) for a full report. Compare the results with the build numbers page and write down which servers are 2016, which are 2019 CU14 or CU15, and which are Edge Transport servers.
Step 2: Path A, in-place upgrade from Exchange 2019 to SE
- Bring every 2019 server to CU14 or CU15 with the latest updates. Older CUs can't upgrade in place.
- Prepare Active Directory if needed. Microsoft's version table lists the same values for Exchange 2019 CU15 and SE RTM, while from CU14 the configuration
objectVersionmoves from 16762 to 16763. If your values differ from the SE row, prepare Active Directory before upgrading the first server, with an account in Schema Admins and Enterprise Admins:
E:\Setup.exe /IAcceptExchangeServerLicenseTerms_DiagnosticDataON /PrepareSchema
E:\Setup.exe /IAcceptExchangeServerLicenseTerms_DiagnosticDataON /PrepareADWait for replication to finish between steps.
- Put DAG members into maintenance mode one at a time, following the DAG maintenance procedure.
- Reboot the server first, then run setup from an elevated prompt with the Exchange SE ISO mounted:
E:\Setup.exe /IAcceptExchangeServerLicenseTerms_DiagnosticDataON /Mode:Upgrade- Restart, re-apply customizations, take the server out of maintenance mode and move to the next one.
Exchange 2019 CU13 and later back up and restore the most common configuration file changes, but TLS and cipher customizations at the operating system level are still overwritten. Remember that a CU-style upgrade can't be uninstalled to go back; uninstalling removes Exchange from the server entirely.
Step 3: Path B, legacy upgrade from Exchange 2016 to SE
Exchange 2016 can't be upgraded in place. The sequence is:
- Update every Exchange 2016 server, including Edge Transport servers, to CU23. That's the supported coexistence level with Exchange 2019 and SE.
- Prepare Active Directory with the Exchange SE media (
/PrepareSchema,/PrepareAD, and/PrepareAllDomainsor/PrepareDomainfor multi-domain forests). - Install new Exchange SE Mailbox servers on supported Windows Server versions, with certificates that cover your namespaces.
- Move client namespaces (Autodiscover, Outlook on the web, EWS, ActiveSync) and SMTP to the SE servers.
- Move mailboxes, archives and public folders to SE databases with local move batches, and move send connectors, receive connectors and relay configuration.
- If you have a hybrid deployment, rerun the Hybrid Configuration Wizard and select the SE servers for hybrid mail transport and the migration endpoint.
- Decommission the Exchange 2016 servers.
The Exchange Server Deployment Assistant generates a checklist for your exact combination of versions. Finish this path before SE CU2 ships, because CU2 setup won't run while 2016 servers remain.
Step 4: Path C, move mailboxes to Exchange Online
If the destination is the cloud, the end-of-support pressure argues for moving mailboxes first and only then deciding what stays on-premises. Microsoft describes two valid orders when you keep Entra Connect:
- Recommended: use your existing Exchange 2019 or 2016 hybrid servers to migrate mailboxes to Microsoft 365, then upgrade the remaining environment to Exchange SE and decommission the 2019 or 2016 servers.
- Alternative: upgrade to Exchange SE first, then use SE as the hybrid server for migration.
Either way, hybrid needs a working Hybrid Configuration Wizard run and the dedicated hybrid app; the HCW errors guide covers the failures you're likely to see, and the remote move migration guide covers endpoints, batches and completion.
What stays on-premises afterwards
When all mailboxes are in Exchange Online but Active Directory remains the source of authority for synchronized users, you can't edit Exchange recipient attributes in the cloud. Your options are:
- Keep one Exchange SE server (or the Exchange Management Tools) for recipient management, and keep it patched.
- Transfer Exchange-attribute source of authority to the cloud (set
IsExchangeCloudManagedon synchronized mailboxes, and use Group and Contact SOA transfer for groups and contacts), then uninstall the last server following Microsoft's procedure; the last Exchange server removal guide walks through it. Note that the Exchange Management Tools workaround only lets you shut the server down, not uninstall it.
Check SMTP relay before removing anything: devices and applications that relay through on-premises receive connectors stop working when those connectors disappear. Exchange Online connectors can take over relay; see the Exchange Online connectors guide.
Verify the result
- Every server reports an Exchange SE build (
15.2.2562.x) inExSetup.exeand HealthChecker output. Get-ExchangeServerlists no 2016 or 2019 servers once decommissioning is done, including Edge Transport servers.- In hybrid,
Test-OAuthConnectivity -Service EWS -TargetUri https://outlook.office365.com -Mailbox user@contoso.comreturnsSuccess, and free/busy works both ways. - Mail flow, Autodiscover and client connectivity work from inside and outside the network.
Troubleshooting
| Symptom | Cause | Fix |
|---|---|---|
| SE setup refuses to continue because Exchange 2013 exists | SE RTM blocks coexistence with Exchange 2013 | Remove the remaining Exchange 2013 servers first |
| In-place upgrade isn't offered on a 2019 server | The server runs a CU older than CU14 | Install CU14 or CU15, then run SE setup |
| Outlook on the web or transport behaves differently after the upgrade | Customized config files or TLS/cipher settings were overwritten | Re-apply the documented customizations |
| Setup readiness checks fail | Missing prerequisites or AD preparation | Fix the reported items and select Retry; run /PrepareAD with an account in Enterprise Admins |
| Free/busy and MailTips with the cloud stopped working | Shared service principal blocked since October 31, 2025, or servers on unsupported builds | Update to a supported build and configure the dedicated Exchange hybrid application |
| Can't edit cloud mailbox attributes after removing servers | Active Directory is still the source of authority | Keep an SE server or the management tools, or transfer attribute management to the cloud |
Checklist
- Record every Exchange server, role and exact build, including Edge.
- Decide per workload: Exchange SE, Exchange Online, or both.
- Exchange 2019 CU14/CU15: in-place upgrade to SE, one server at a time.
- Exchange 2016: bring all servers to CU23, add SE servers, move everything, remove 2016.
- Hybrid: put every server on a dedicated-app build and finish the hybrid app setup.
- Move mailboxes with hybrid remote moves; decide whether an SE management server stays.
- Remove all 2016 and 2019 servers before SE CU2 so future updates can install.
- Treat the end of October 2026 as the last date any Exchange 2016 or 2019 fix can arrive.
References
- Exchange Server 2019 and 2016 End of Support Roadmap
- Upgrading to Exchange Server Subscription Edition (SE)
- Exchange Server build numbers and release dates
- Exchange Server Subscription Edition lifecycle
- Exchange Server 2019 and SE system requirements
- Upgrade Exchange to the latest Cumulative Update
- Prepare Active Directory and domains for Exchange Server
- Deploy dedicated Exchange hybrid app
- Hybrid deployment prerequisites
- Decommission the last Exchange Server after transferring SOA to cloud
- Move mailboxes between on-premises and Exchange Online organizations in hybrid deployments
- Reminder: Exchange 2016 and 2019 ESU Program Ends in October 2026 (Exchange Team Blog)
- Microsoft to stop Exchange 2016 / 2019 security updates in October (BleepingComputer)