Microsoft has closed the door on further reprieves for Exchange Server 2016 and 2019. In a July 20, 2026 post, the Exchange Server team confirmed that the Extended Security Update (ESU) program ends when October 2026 ends, with no third coverage period.

What Microsoft said

There will be no further extension of Exchange 2016/2019 ESU program timeline. Once October 2026 ends, there will be no further updates for Exchange 2016/2019, even if you currently have a Period 2 ESU.”

Microsoft acknowledged the reason customers were asking: the original ESU announcement also said there would be no extensions, and then Period 2 was created anyway. This time the answer is final.

Reading our article? Try our product:

Full Protection for Windows Servers - Zero-Risk Trial

The Timeline

MilestoneDate
Exchange 2016 mainstream support endsOctober 2020
Exchange Server SE general availabilityJuly 1, 2025
Exchange 2019 mainstream support endsJanuary 2024
Exchange 2016 / 2019 end of supportOctober 14, 2025
ESU Period 1October 2025 – April 2026
Period 2 announcedApril 15, 2026
ESU Period 2May 1 – October 31, 2026
All updates stopEnd of October 2026

Period 2 was never an automatic rollover. Organizations had to purchase it separately, under an Enterprise Agreement, to get the additional six months. It covers Exchange Server 2016 CU23 and Exchange Server 2019 CU14/CU15, and only for vulnerabilities rated Critical or Important by the Microsoft Security Response Center.

Updates are distributed privately to enrolled customers rather than through the public update channels. It does not restore general technical support — the only cases Microsoft will take are issues caused by an ESU update itself. Microsoft also does not guarantee any updates will be released in a given month.

What this means operationally

After October 31, 2026, any new Exchange vulnerability affecting 2016 or 2019 goes unpatched permanently. Exchange servers are internet-facing by design and have a long history of being targeted through remote code execution flaws, so an unpatched deployment is a standing exposure, not a theoretical one. An on-premises Exchange server also sits close to identity and directory infrastructure, a compromise can expose mail, address book data, and authentication material, and can serve as a pivot point deeper into the Windows domain.

Compensating controls help but do not close the gap. Web application firewalls, network segmentation, EDR, restricted admin access, and Microsoft’s Exchange Emergency Mitigation Service can reduce specific risks. They are technique-specific and cannot cover every future vulnerability in a frozen codebase.

The governance side matters too. Regulated organizations may have to justify running a critical messaging platform with no vendor security fixes. Cyber-insurance terms, customer security questionnaires, contractual obligations, and internal risk policy may restrict or prohibit unsupported infrastructure outright. Expect knock-on updates to risk registers, audit documentation, continuity plans, and incident response procedures.

Migration paths

Exchange 2019 → Exchange Server SE

The shortest route. Exchange 2019 CU14 and CU15 support an in-place upgrade to the initial SE release, mechanically similar to applying a cumulative update, existing server, configuration, and databases are retained where prerequisites are met.

Two points to check before you start:

  • It is not a routine patch. Verify the CU level, confirm OS compatibility, review third-party integrations, back up, and test recovery. Run the Exchange Health Checker first and resolve unsupported or insecure configurations rather than carrying them forward.
  • It does not include an OS upgrade. Microsoft does not support upgrading Windows Server across major versions with Exchange installed. If you need a newer OS or new hardware, you are deploying a new SE server and performing a traditional migration, a materially larger project than an in-place upgrade.

Exchange 2016 → Exchange Server SE

This is a legacy upgrade, not an in-place one. Running the SE installer over an existing 2016 installation is not supported. Instead, deploy new SE servers into the organization and move mailboxes, connectors, certificates, and transport functions across before retiring the old system. The 2016 server never becomes an SE server. Some organizations will route through Exchange 2019 as an intermediate step, deploying 2019 on supported hardware and OS, migrating off 2016, then upgrading the 2019 servers to SE.

Exchange 2013 → must be removed first

Exchange Server SE RTM does not support coexistence with Exchange 2013, which left support in April 2023. Any remaining 2013 servers have to be removed through a supported migration sequence before SE can be introduced. Sequencing errors here can break mail flow, client connectivity, and hybrid integration.

Full details: Upgrading your organization from current versions to Exchange Server SE

Exchange SE is a different licensing and servicing model

Exchange Server SE went GA on July 1, 2025 and runs under Microsoft’s Modern Lifecycle Policy rather than the old numbered-version cadence. There is no predetermined retirement date, but that is conditional. Staying supported requires maintaining qualifying subscription rights, installing cumulative updates within Microsoft’s required timeframes, and keeping compatible operating systems, .NET Framework versions, and Active Directory prerequisites. Treating SE like a perpetual release that can sit untouched for years will put you back out of support.

Migrations involve more than moving mailboxes

Production Exchange deployments accumulate dependencies over years. Inventory at minimum:

  • Applications and appliances that submit mail, scanners, monitoring systems, line-of-business apps, multifunction printers
  • Send and receive connectors, transport rules, accepted domains
  • Certificates, namespaces, load balancers
  • Antivirus integrations, journaling, archive platforms, backup products
  • Public folders and arbitration mailboxes
  • Hybrid components: Hybrid Configuration Wizard state, OAuth configuration, mail-flow connectors
  • Client compatibility — older Outlook builds, mobile clients, custom software

Exchange writes configuration data into Active Directory, so retiring the last legacy server outside Microsoft’s supported process leaves dependencies behind and complicates recipient management.

Review security settings rather than copying them across. A migration is a natural point to remove obsolete protocols, restrict administrative interfaces, enable Extended Protection where supported, and cut unnecessary internet exposure.

If you are still on Period 2

  • Confirm your security or procurement team knows how to receive and deploy the privately distributed ESU packages.
  • Check each Patch Tuesday through October 2026, even in months where nothing ships.
  • Confirm every Exchange server and build present in the organization, and verify each is enrolled in the correct ESU period with all available updates installed.
  • Choose a destination architecture — SE, Exchange Online, or hybrid, and build the plan around Microsoft’s supported upgrade paths.

Bottom line

Do not plan around the final security update as the migration deadline. Procurement, architecture changes, hardware, change control, testing, and decommissioning all take time, and a problem found late leaves you running unsupported servers with no remaining safety net. Roughly three months remain.

Period 2 was a one-time accommodation for organizations mid-migration, and it is now past its midpoint. Anyone still planning around a possible Period 3 should stop. Exchange 2016 and 2019 will keep running after October, they will just do so permanently unpatched.

Full announcement: Reminder: Exchange 2016 and 2019 ESU Program Ends in October 2026

Fortify Your Server with Messageware Security

Data breaches have increased by 72%, servers are compromised in under 90 minutes. Ensure you have multiple layers of security software protecting your Windows Servers.

Server Threat Guard (STG) for All Windows Servers: Next-gen server protection, providing detection, alerting, and response (MDR) to zero-day and server penetration cyber-attacks. No need to research complicated deployments and no learning curve to install and manage.

EPG Guard for Exchange Servers: Real-time security. Stop AD account lockouts, eliminate password attacks, intelligent GEO blocking, and prevent Exchange Server vulnerability probing.

Don’t leave your critical infrastructure vulnerable, be proactive and stay ahead of evolving threats.