Microsoft has confirmed there will be no third Extended Security Update period for Exchange Server 2016 and 2019. The current Period 2 coverage—the final extension—expires when October 2026 ends. After that date, no new security fixes will be released for those products, even if a critical vulnerability surfaces. For the organizations still running these servers, the window to migrate is now measured in months, not quarters.

The Deadline Is Absolute: No Period 3, No Grace

The Extended Security Update (ESU) program was always intended as a temporary bridge. Period 1 ran from October 2025 through April 2026. When customers needed more time, Microsoft offered Period 2, covering May through October 2026, but it came with a clear caveat: it was a one-time accommodation, not a recurring subscription. On July 20, 2026, the Exchange Team publicly underlined that message—no third coverage period will be offered. Once October closes, the security update pipeline for Exchange 2016 CU23 and Exchange 2019 CU14/CU15 shuts down permanently.

This means organizations enrolled in Period 2 cannot renew, extend, or purchase additional months of protection. After October 31, 2026, if a researcher or attacker finds a new way to exploit those Exchange versions, there will be no official patch. The only defense left will be compensating controls—proxies, firewalls, network segmentation—none of which can fix the underlying code.

What Systems Are Affected—And What Isn’t Changing

The cutoff applies specifically to:

  • Exchange Server 2016 Cumulative Update 23 (CU23)
  • Exchange Server 2019 Cumulative Update 14 (CU14) and Cumulative Update 15 (CU15)

Servers running older cumulative updates are already unsupported and not covered by ESU at all. Even if your organization bought Period 2, an outdated CU version won’t receive patches; you must be on the eligible baseline first. Edge Transport servers, management tools, and hybrid components are all part of the same deadline—there’s no separate timeline for auxiliary Exchange roles.

One critical point: the deadline does not mean Exchange 2016 or 2019 will stop working. Mail flow, database mounts, and client connectivity may continue after October 2026. But from that moment on, you’ll be operating without a supported security-servicing path. The difference between “still running” and “safe to run” will widen with every newly discovered vulnerability.

Migration Paths: From Straightforward to Time-Consuming

Your upgrade route depends entirely on which Exchange version you’re running right now.

Exchange Server 2019 (CU14 or CU15 only)

These organizations have the cleanest path. Microsoft supports an in-place upgrade to Exchange Server Subscription Edition (Exchange SE) directly from CU14 or CU15. The initial Exchange SE release (RTM) is code-equivalent to Exchange 2019 CU15, apart from the product name, build number, and license changes. In practice, the upgrade feels more like installing a cumulative update than replacing the entire messaging stack.

What you must do:
1. Confirm every server is on CU14 or CU15 with the latest applicable security update.
2. Validate Active Directory health, backups, certificates, and third-party tool compatibility.
3. Run the Exchange SE installer in a maintenance window—Setup replaces binaries while preserving the server’s role in the organization.
4. After upgrading, verify mail flow, hybrid connectivity, client access, and all integrations.

Be aware: an in-place upgrade does not mean you can simultaneously jump to a newer Windows Server version. Microsoft does not support in-place OS upgrades while Exchange is installed. If your 2019 server sits on Windows Server 2019 or 2022 and you need Server 2025, a legacy migration to new hardware or VMs is the supported route.

Exchange Server 2016 (Any CU)

There is no direct in-place path from Exchange 2016 to Exchange SE. The only supported method is a legacy migration: deploy new Exchange SE servers (or intermediate Exchange 2019 servers), move mailboxes, public folders, connectors, and all dependencies, then decommission the 2016 systems cleanly. For many organizations, this is a multi-month project involving namespace changes, certificate refreshes, and application-relay updates.

A 2016 migration must handle more than user mailboxes. You’ll also need to move arbitration and system mailboxes, receive/send connectors, SMTP relay configurations, hybrid settings, and compliance integrations. And there’s a second hard deadline: Exchange SE CU2 is expected to block coexistence with unsupported Exchange versions. If any 2016 server remains in the organization by the time CU2 arrives, your migration options may become severely constrained.

Why the Stakes Are Higher Than a Typical End-of-Life

Historically, some organizations treat end-of-support as a soft deadline, citing functional systems and tight budgets. That logic doesn’t hold here. Exchange servers are high-value targets: they expose multiple services (HTTPS, SMTP, authentication), connect directly to Active Directory, and often carry privileged service accounts. Attack campaigns like Hafnium demonstrated how quickly an Exchange vulnerability can lead to domain-wide compromise. Running an unpatchable Exchange server after October 2026 is not a manageable risk—it’s an open invitation.

Compensating controls help, but they can’t substitute for vendor patches. A web application firewall can’t repair a flaw in Exchange’s IIS module. Network isolation might slow lateral movement, but it won’t stop an attacker who already has valid credentials. After the deadline, any new vulnerability becomes a permanent zero-day for your organization.

How We Got to This Point

Exchange 2016 and 2019 both reached their standard end of support on October 14, 2025. Microsoft aligned their lifecycles to pave the way for Exchange Server Subscription Edition, a new servicing model that moves away from traditional major releases. When large numbers of customers couldn’t meet the 2025 deadline, Microsoft introduced the paid ESU program. Period 1 bought six months; Period 2 bought another six. The creation of Period 2 sparked hope that Microsoft might keep extending if enough big customers lagged. The July announcement killed that hope definitively.

Exchange SE is designed to be an evergreen platform. Its initial release resembles Exchange 2019 CU15 by design, so the first step is a low-disruption identity change rather than a feature overhaul. New capabilities will arrive later through SE cumulative updates, but the immediate goal is simple: get onto a supported codebase before the security updates disappear.

What to Do Now: A Practical Timeline

With roughly three months remaining, you must move from planning to execution. Here’s how to break it down.

For Exchange 2019 Admins (CU14/CU15)

This week: Confirm every Exchange server is on a supported CU. Inventory all connectors, certificates, hybrid configurations, backup agents, and application relays. Reach out to vendors of any third-party Exchange tools to verify Exchange SE compatibility.

Next two weeks: Update any lagging servers to CU14 or CU15 and apply the latest security updates. Test mail flow, client access, and hybrid connectivity in a lab if possible.

By late September: Schedule an SE upgrade window for each production server. Perform the upgrade, then run a full validation: internal/external mail, Autodiscover, mobile devices, public folders, transport rules, journaling, and backups. Don’t forget to document the new licensing state—Exchange SE requires an active subscription or Software Assurance entitlement.

For Exchange 2016 Admins

This week: Audit all Exchange objects and dependencies. Identify every application or device that relays mail through the server using message tracking logs and connector configurations.

By early September: Choose your migration architecture—directly to Exchange SE (with new servers) or via Exchange 2019 CU15 as an intermediate step. Procure necessary Windows Server licenses and hardware/VMs.

By early October: Begin mailbox migrations and relay reconfiguration. Set up coexistence and test thoroughly. Move arbitration mailboxes and public folders. Update client access namespaces and certificates.

Before October 31: Complete decommissioning of all 2016 servers using a supported uninstallation process. Do not simply power them off; leftover objects in Active Directory can cause support and management problems later.

For Hybrid Environments

Many organizations claim to be “cloud-first” while retaining a single on-premises Exchange server for management. That server still counts. After October, an unpatched hybrid server is a high-risk doorway into your Microsoft 365 identity infrastructure. If you need to keep an on-premises Exchange presence for recipient management or relay, upgrade it to Exchange SE now. Alternatively, investigate Microsoft’s supported management tools that don’t require a full Exchange server—but only after confirming you no longer need server-based hybrid functions.

For Everyone: Don’t Wait for Patch Tuesday

Period 2 updates are delivered privately to enrolled customers, not through the public Microsoft Update Catalog. Make sure your organization’s procurement or security team knows how to receive and deploy those packages. Check for updates every Patch Tuesday through October 2026, even if none are released.

The Business Case: Migration Isn’t Just Damage Control

Rushing to meet a deadline feels like a cost, but migrating off Exchange 2016/2019 can deliver tangible improvements. Organizations can modernize their underlying Windows Server version, redesign storage, clean up obsolete relays, and tighten SMTP authentication rules. The inventory work alone often exposes undocumented service accounts and risky configurations. Moving to Exchange SE also forces a disciplined cumulative-update cadence, which may prevent the years-long patch gaps that made some environments vulnerable in the first place.

For smaller IT providers, this is a chance to standardize managed customer environments. Identify every client still running these versions now—waiting until October could create a surge of emergency projects with no available Exchange engineers.

The Clock Is Ticking—and It’s Loud

October 31, 2026 isn’t a suggestion. It’s the day Microsoft washes its hands of Exchange 2016 and 2019 security. While servers will likely keep running, every day after that brings an escalating risk of exploitation with no official remedy. The time for strategic deliberation ended when Period 2 was announced; what remains is the execution phase. Start your inventory today, pick your migration path by the end of August, and aim to complete all changes by mid-October at the latest. The final weeks should be reserved for validation, cleanup, and dealing with the one integration nobody remembered until the last day.

If leadership questions the urgency, frame it plainly: after October, a new Exchange vulnerability becomes a permanent threat. The cost of migrating now is predictable; the cost of a breach on an unsupported system is not.