Skip to content
Lambert Consulting

Artificial Intelligence: A Cross-Functional Offering

Results first. Infrastructure second.

An assistant for your documents, end-of-line verification, a platform for multiple services. Where artificial intelligence is applied is determined by your data, not by a catalog.

See all solutions
4Comparing Architectures, Criterion by Criterion
2 fieldsSoftware and hardware under one roof
All Use CasesUse cases first, technology last

Our first department

This is what needs to work every morning.

Your servers, your workstations, your phone systems, and your identities. The foundation that no one notices as long as it holds, but that everyone notices the day it fails.

View the department
Multi-siteNational and international projects
3Branches in French-speaking Switzerland
View our client projectsCase Studies and References
Let us know how you're doingGetting a quote is free

How We Work

A piece of advice, not a sales pitch.

Our approach is consultative: we tell you what we think, even when it’s not in our best interest. That’s what makes projects succeed.

About Us
1995First project, using Microsoft SMS
Family-orientedOn a human scale and sustainable

Our Branches

Vaud, headquarters9 Avenue des Baumettes, 1020 Renens+41 21 806 37 15
Valais134 Oscar-Bider Street, 1950 Sion+41 27 552 00 22
FribourgChemin de Montmoirin 18a, 1618 Châtel-Saint-Denis+41 26 322 59 05
Monday through Friday8:00 a.m. – 6:00 p.m.
Contact UsFirst 30-minute consultation, with no obligation

Your Exchange Server is no longer supported as of October 14, 2025

Exchange Server 2016 and 2019 have been end-of-support since October 14, 2025. Starting in the second week of September 2026, Microsoft will raise the patch level required for servers that submit mail to it via an on-premises inbound connector; at the next level, only two methods will remain compliant.

Publication Date
13 minReading time
Microsoft 365 and collaborationBlog Archive

Exchange Server 2016 and Exchange Server 2019 reached end of support on October 14, 2025. Since that date, Microsoft no longer publishes security updates for them on the Download Center or on Windows Update: instead, it provides them privately only to organizations that have purchased an Extended Security Updates contract. A server still running one of these two versions functions as before, and nothing on the users’ end indicates that it is no longer receiving updates.

How End of Support Affects a Production Server

The consequence is inevitable. A version that is no longer supported no longer receives security updates, and vulnerabilities discovered after support ends are therefore never patched. Microsoft adds one more point: as soon as a patch is released, malicious actors reverse-engineer it to figure out how to exploit the vulnerability on servers that haven’t installed it.

Vulnerabilities, meanwhile, continue to emerge. The security updates Exchange in July 2026 address vulnerabilities reported to Microsoft by partners and detected through its own processes. For Exchange Server 2016 and Exchange Server 2019, these patches are available only to organizations enrolled in the program described below.

The slowdown and subsequent halt in mail delivery to Exchange Online

This issue does not involve any attack. Exchange Online detects servers Exchange hosted by the customer that are significantly behind on patches, slows down the email they send, and then blocks it. Microsoft states that this mechanism now applies to all versions ofExchange Server, Exchange Server including 2019.

Before getting worried, you need to check where this server sends its email. Microsoft reiterated this on September 2, 2026: the mechanism applies only to servers that deliver their email Exchange Online via an OnPremises-type inbound connector. A server that sends its email by other means is not affected, and the mechanism does not apply, at this stage, to all of an organization’s servers either. Microsoft states that this scope may change. This type of connector is the one used by the domains served by the organization’s on-premises email system. Therefore, there are two questions to ask the server administrator: through which route does the server’s email enter Microsoft’s system, and what is the server’s current patching status?

What triggers this is the delay in patches, not the end of support. Microsoft states this in its April 15, 2026, announcement: a server that is already running slowly or has frozen is, in its words, about a year behind, and all that’s needed is to install the October 2025 updates—the last ones publicly released for Exchange Server 2016 and 2019—to resolve the issue, without needing the ESU contract. A server that remained at this level was therefore not affected as of that date. That same page announced that the October 2025 updates would in turn be slowed down and then blocked, without specifying when, and reiterated that a server that had installed them would remain out of support. Microsoft revisited this point on September 2, 2026: it specified the date for the intermediate phase and provided an estimate for the next one.

First phase: the second week of September 2026. At that time, Microsoft will set, for Exchange Server 2016 and 2019 models connected via this connector, the oldest permitted version will be the October 2025 updates. A server that remains exactly at this level will therefore still be accepted: this phase excludes older servers. Microsoft notes that these updates were previously implemented without announcement, and that this is the first one it is publicly announcing.

Second phase: several months later. Microsoft states that the version required at that time will be more recent than any publicly released update for Exchange Server 2016 and 2019—and therefore more recent than those from October 2025, which are the latest. It identifies the two categories of organizations that will meet the required level to avoid being slowed down or blocked: those enrolled in the ESU program, and those that have upgraded to the Exchange Server Subscription Edition. Microsoft does not specify a date for this second phase other than “several months,” and it does not state whether enrollment in the ESU program must be active at that time, even though the second phase ends at the end of October 2026. An organization purchasing this contract for that reason alone therefore does not know what it will guarantee at the time of the second phase.

The process itself is documented, and it begins as soon as Microsoft detects the server:

  • During the first 30 days, the server is only mentioned in a report submitted to the administrator;
  • After this period, messages are delayed, and the delay increases every 10 days;
  • 60 days after detection, the block begins, and it also increases every 10 days;
  • 90 days after detection, Exchange Online no longer accepts any messages from this server.

A delayed message is eventually sent. A blocked message is not sent: the sender receives a non-delivery notice. An organization may suspend these delays and blocks for up to 90 days per calendar year.

Both options: Exchange Online or Exchange Server Subscription Edition

Go to Exchange Online. The server disappears, and its operation along with it. In addition to the mailboxes themselves, the migration must handle shared mailboxes, mailing lists, rules, delegations, and applications that send messages through this server without anyone even realizing it.

Upgrade to Exchange Server Subscription Edition. Microsoft has been releasing this version since July 1, 2025, and supports it under its modern lifecycle policy: it has no announced end date, unlike Exchange Server 2016 and 2019, both of which were subject to the fixed lifecycle policy.

The licensing model is changing. Microsoft states that theExchange Server Subscription Edition is the same as that of the SharePoint Server Subscription Edition: it requires subscription licenses or licenses with active Software Assurance for both the server and the users. The hybrid server license, however, remains free and continues to be issued by the Hybrid Configuration Wizard.

The upgrade path depends on the starting point:

  • Since Exchange Server 2019 CU14 or CU15, the upgrade is performed locally, through a process similar to installing a cumulative update;
  • Since Exchange Server 2016, it hasn’t been done on-site. You have to add the new servers to the infrastructure, move the mailboxes and resources to them, and then uninstall the old ones.

Before deciding to stay on your current system, there is one limitation you should be aware of: the installer for the second cumulative update forExchange Server Subscription Edition will not allow coexistence with any version ofExchange Server that is no longer supported at that time. An older version therefore cannot remain installed alongsideExchange Server Subscription Edition once this update is installed.

The ESU Program: Timeframes, Purchase Conditions, and Announced End Date

There is a third option, and it’s not a workaround. Microsoft sells Extended Security Updates for Exchange Server 2016 and Exchange Server 2019, in two separate periods. The first covered October 2025 through April 2026. The second, announced on April 15, 2026, covers early May 2026 through late October 2026, and Microsoft states that there will be no extension beyond that.

What this contract provides—and what it does not provide:

  • It provides the patches classified as "Critical" and "Important" that Microsoft decides to release during the period, distributed privately to registered organizations;
  • It does not extend support. The servers remain out of support, and no support cases can be opened for them, unless the issue relates to a patch released for customers in the program;
  • It does not guarantee any fixes. Microsoft does not commit to releasing them, as it only releases them when there is a security update classified as Critical or Important;
  • It is not provided automatically. It is not included in Volume Licensing or Software Assurance: it is a separate agreement purchased through the Microsoft account team, and the second option is intended for organizations with an Enterprise Agreement;
  • It is not automatically renewed. An organization registered for the first period had to renew the contract for the second;
  • It covers specific versions: Exchange Server 2016 CU23, Exchange Server 2019 CU14 and CU15.

For this purchase, enrollment is handled by the Microsoft account team, which has been selling the contract for the second term since April 15, 2026. This second term can be purchased without having subscribed to the first one, and therefore provides access only to updates released after its start date. However, Microsoft does not publish a subscription deadline or a price; the cost is provided on a per-server basis by the account team. We do not provide an estimate.

Note: Doing nothing is not a fourth option. It is the choice to keep a server in service whose future vulnerabilities will not be patched, and whose mail sent to Exchange Online will be slowed down and then blocked—if it goes through this connector—as soon as its patch backlog reaches the threshold described above.

The hybrid server that remained on site

An organization that moved its mailboxes to Exchange Online was able to keep a server Exchange on-site to manage accounts from the internal directory. This is a special case: the server no longer hosts any mailboxes, no one logs in to it, and it can remain in its original version without causing any inconvenience to anyone.

Yet it is a Exchange . The cleanup process that Microsoft documents for removing it illustrates the extent of its footprint: the provided script removes system folders, containers Exchange, security groups Exchange, and the permissions of those groups on the domain and directory configuration partitions. If it’s running on Exchange Server 2016 or 2019, all of the above applies to it, including the slowdown and eventual blocking of email when its patch backlog reaches the threshold described above.

Microsoft provides instructions on how to do without it, subject to seven conditions that must all be met. All public mailboxes and folders are located in Exchange Online. The internal directory remains the tool for managing recipients, and synchronization occurs via Microsoft Entra Cloud Sync or Microsoft Entra Connect. The organization does not need the graphical administration interface Exchange installed on-premises, nor the permission delegations specific to Exchange. It agrees to manage recipients via the command line only. It does not need to log these operations. Only one server remains Exchange on-site, and it is used solely for recipient management. Finally, the organization wants to manage its recipients without running any servers Exchange. With all seven of these conditions met, the management tools forExchange Server are sufficient, and the last server can be shut down.

The documentation includes two warnings:

  • The last server shuts down; it is not uninstalled. Uninstallation removes information from the directory that management tools need, and breaks attribute management Exchange. Microsoft states that you must shut down the server, perform the recommended cleanup, and then wipe and reformat the machine;
  • Exchange -specific permission delegations cease to function as soon as the last server is shut down. Users who managed recipients through a role Exchange will lose this right; only domain administrators and members of a group created by a provided script will still be able to do so.

You should also verify that this server isn't used for anything else. Microsoft states this clearly: if it also serves as a sending relay, you should not shut it down.

Three questions to help you determine if this applies to you

  1. Do you still have an Exchange server running at your place? Even one that no longer hosts any email accounts.
  2. Which version, exactly? Exchange Server 2016 and Exchange Server 2019 are no longer supported. Exchange Server The Subscription Edition is supported.
  3. Does this server send email to Exchange Online, and through which route? The slowdown and blocking affect only email delivered via an on-premises-type incoming connector. If its email passes through this connector, check the server’s patch level: it is this delay—not the end of support—that triggers the slowdown and then the blocking.

What You Can Do Without a Service Provider

Three things, and none of them requires a project.

Compile a list of the servers Exchange that are still running and their exact versions. Next, check the administration Exchange Online to see if any of them are already flagged as overdue and what stage they’ve reached: this is the process Microsoft follows. Finally, list the applications, printers, and tools that send messages through this server. This final inventory takes a few hours for someone familiar with the system.

Our Reading

Between the two options, we prefer Exchange Online, and the reason isn’t technical: keeping email in-house requires maintaining a server—which is now subscription-based—for a service that offers the company no benefit from owning it. The Subscription Edition is justified when a real constraint prevents a switch: a written requirement, an architecture that cannot be separated, or an application dependency that cannot be moved. Such cases do exist. It’s better to verify them rather than assume they exist.

When it comes to the ESU program, our take is more clear-cut: it’s only useful to an organization whose migration is already underway and has a set end date. If purchased without an exit plan, it merely postpones the same decision by six months, and you’ll have to renew it to continue. Microsoft even states this itself in its announcement: it recommends not relying on this program and prefers that its customers complete their migration.

The update published on September 2, 2026, does not change this interpretation; it simply tightens the timeline. At the second tier, the ESU program is no longer used solely to receive patches: along with Exchange Server Subscription Edition, one of the two paths Microsoft specifies for maintaining a level of updates accepted by Exchange Online. An organization that maintains an on-premises server and uses it to forward email to Exchange Online via an on-premises-type inbound connector therefore has no third option at that point.

There is, however, one case where the right decision is to wait. If the last server also serves as a relay for application traffic, shutting it down before processing that relay would disrupt those application transmissions. Microsoft, in fact, states this clearly in its documentation. The relay must be processed first, and then the server can be taken offline.

Here's what you need to check, in this order

  1. Compile a list of the servers Exchange that are still running, along with their exact versions.
  2. Check to see if any of them have already been reported as late by Exchange Online, and what stage it has reached.
  3. Determine the route this server uses to deliver its mail to Exchange Online, since the slowdowns and blockages only affect the OnPremises-type incoming connector.
  4. List the applications, printers, and tools that send messages through this server, and address the relays before making any decision to shut it down.
  5. Identify what, within the organization, would actually prevent the email system from being taken offline, and in what form this constraint exists.
  6. Set a date for decommissioning the last server.

Lambert Consulting manages these migrations, including cases where the inventory of dependencies must be rebuilt from scratch. On the online side, several deadlines— Microsoft 365 , and Entra ID —apply to the same tenants through April 2027.

Microsoft Sources

After reading

What an article Can't Know

An article describes what applies to everyone. What varies from one organization to another is the inventory: which applications, which accounts, and which pieces of equipment are actually involved in your organization. The inventory determines the scope of the effort, and it cannot be summarized on a single page.

You'll be speaking directly with the engineers who will be doing the work, not with a middleman. We'll respond within 24 business hours.

If the topic has changed

Check what is still true

Announced dates are sometimes postponed, products are renamed, and conditions change. The blog tracks these topics over time: when a rule changes, a new post announces it.

Search for a topic in the blog