Microsoft Exchange 2016 and 2019 Extended Security Updates end in October 2025
Organizations running legacy Exchange servers must migrate to newer versions or cloud solutions before losing security patch support, potentially exposing email infrastructure to unpatched vulnerabilities.
ESU program concludes after extended support
Microsoft will stop providing security updates for Exchange Server 2016 and 2019 through its Extended Security Update program in October 2025. The ESU program was designed to give organizations additional time to migrate away from on-premises email infrastructure.
Exchange 2016 reached mainstream end-of-life in October 2020, while Exchange 2019 entered extended support phase. Organizations that purchased ESU licenses received additional security patches beyond standard support periods.
Migration paths for affected customers
Organizations have two primary migration options: upgrading to Exchange Server Subscription Edition for continued on-premises deployment, or moving to Microsoft 365 cloud-hosted email services. Exchange Server Subscription Edition follows a continuous update model rather than traditional version releases.
Microsoft has positioned Microsoft 365 as the preferred path, offering built-in security features and eliminating the need for organizations to manage patch cycles and infrastructure maintenance.
Security implications for delayed migrations
Exchange servers have been frequent targets for attackers, with critical vulnerabilities like ProxyShell and ProxyLogon enabling remote code execution. Organizations that continue running unsupported versions after October will not receive patches for newly discovered vulnerabilities.
The deadline creates urgency for IT teams to complete migration planning, testing, and deployment before support ends. Email infrastructure typically requires careful migration planning due to business continuity requirements and data sensitivity.