Extended support (End of Support, EoS) for Microsoft Exchange Server 2016 and 2019 will end on October 14, 2025. This means that security updates for these versions will cease completely. Running these systems after this date creates a direct and high risk of compromising corporate email infrastructure. The only supported on-premises version will be Exchange Server Subscription Edition (SE).
 

Risks of the perpetual licensing model

The “perpetual license” model (CapEx) is incompatible with modern cybersecurity requirements. The threat landscape is constantly evolving, and software that does not receive regular updates inevitably becomes vulnerable.

Corporate system security is an ongoing process. The subscription model (OpEx) ensures continuous vendor funding for development and release of security updates. Microsoft’s transition of Exchange Server to a subscription model confirms that, under current conditions, support and updates are integral parts of the product.

 
Recommendation: Migrate email services to the cloud

The most secure strategy is to process email outside the corporate perimeter. Cloud platforms such as Microsoft 365 and Google Workspace provide a level of protection unattainable for most internal IT teams.

By moving email services to the cloud, an organization removes one of the most vulnerable public-facing services from its perimeter, eliminating it as a constant source of compromise. This removes from the organization the risks associated with administering and protecting on-premises email servers, which are prime targets for attacks (e.g., ProxyLogon/ProxyShell vulnerabilities).

 
Action plan for on-premises infrastructure

For organizations retaining email servers within their perimeter for regulatory or technical reasons, the following steps are necessary:

  1. Plan and perform an upgrade to Exchange Server Subscription Edition (SE). This is a mandatory requirement to continue receiving security updates and maintain an acceptable level of protection.
  2. Strengthen internal network traffic monitoring. Perimeter firewall protection is insufficient. It is necessary to implement network segmentation to isolate critical systems and deploy Network Detection and Response (NDR) solutions to analyze internal (“east-west”) traffic for detecting anomalous activity and preventing lateral movement by attackers within the network.

Author: Alexey Shulenkov (Cybersecurity Solutions Consultant, DAAC digital)

For detailed information about our cybersecurity solutions, please visit the dedicated page: Cyber Security.

Share the article, choose your platform!
Published On: September 17th, 2025
/
Categories: News, Blog, Blog Cybersecurity
/
Tags: , ,
/
Leave A Comment

Subscribe and get the latest IT news

Always up to date!