Microsoft is beginning to sever outdated on-premises Exchange servers from cloud mail more sternly. From the second week of September 2026, Exchange Online will start to restrict, and thereafter block, messages from Exchange Server 2016 and 2019 unless the servers have been updated at least to the final public level of October 2025. For companies that have deferred updating their corporate mail for years, the warnings have, in effect, come to an end.
Microsoft’s new requirements affect servers that dispatch mail to Exchange Online through an inbound connector of the OnPremises type. The rule does not entail the instant disconnection of every aged Exchange Server, nor does it extend automatically to all methods of mail delivery. Bearing the brunt above all are hybrid infrastructures, where a local Exchange interacts with Microsoft 365.
Throttling First, Then Outright Blocking
Exchange Online inspects the version of the connecting server and gradually tightens its restrictions. At first, the cloud service begins to delay mail and returns a temporary SMTP error, 450 4.7.230. Should the administrator persist in ignoring the problem, Exchange Online proceeds to blocking with the error 550 5.7.230. In that event, the message no longer awaits a retry in the queue; instead, the sender receives a non-delivery notification.
Microsoft is not employing such a mechanism for the first time. For several years the company has been progressively raising the “minimally acceptable” version of Exchange Server, first laid out when it announced the throttling and blocking of persistently vulnerable servers, and explaining the blocking by the risk posed by servers on which security fixes have gone uninstalled for months. Since February 2025, the verification system has extended to Exchange Server 2019 as well, where the installed build lags significantly behind the current one.
A Steeper Threshold Than Before
The September change is far more conspicuous than its predecessors. The minimum bar rises at once to the last update that Microsoft publicly released for Exchange Server 2016 and 2019 in October 2025. As the company plainly notes in its announcement, the package appeared almost a year ago, and organizations had ample time to install it.
Support for Exchange Server 2016 and 2019 concluded on October 14, 2025. Ordinary owners of the old versions no longer receive security fixes, and fresh patches are available only to members of the paid Extended Security Update program. As Microsoft’s end-of-support guidance explains, the company invites everyone else to move to Exchange Server Subscription Edition or to migrate their mail infrastructure to Microsoft 365.
The Next Increase Will Sting Even More
The next elevation of the minimum version will prove yet more painful. Microsoft expects to change the threshold within several months, after which Exchange Server 2016 and 2019 will require a build newer than the last public update. Only ESU participants will be able to obtain such a version. Owners of Exchange Server Subscription Edition will continue to receive ordinary updates and will not fall under the restrictions arising from the end of support for the old branches.
Even ESU grants only a brief reprieve. Microsoft has confirmed that the extended-update program for Exchange 2016 and 2019 will conclude definitively in October 2026, and the company has no intention of prolonging it again. Thereafter, the sole supported on-premises option will remain Exchange Server Subscription Edition.
The Backdrop: Tens of Thousands of Vulnerable Servers
This stern policy has emerged against the persistence of a great many vulnerable Exchange servers on the internet. In early September, Shadowserver specialists counted nearly 22,000 servers that had not received the fix for CVE-2026-62911. The vulnerability permits access, after compromise, to other users’ mailboxes, and exploitation code has already surfaced in the public domain. At the time of the research’s publication, there was no confirmation of mass attacks.
For administrators, the September measure transforms the installation of old updates from a security recommendation into a condition for the normal operation of hybrid mail. A server may continue to function within the organization, but a build too old will gradually lose the ability to convey messages properly to Exchange Online. Microsoft is, in essence, wielding its own cloud infrastructure as a lever, compelling owners of long-unsupported Exchange to update at last, or to move to a new platform.
Support Our Threat Intelligence
Find our tech and OS security coverage helpful? Support our work today and unlock a 100% ad-free reading experience!