{"id":45283,"date":"2025-09-17T08:59:45","date_gmt":"2025-09-17T08:59:45","guid":{"rendered":"https:\/\/daacdigital.com\/?p=45283"},"modified":"2025-09-17T08:59:45","modified_gmt":"2025-09-17T08:59:45","slug":"end-of-support-for-exchange-2016-2019-facts-and-action-plan","status":"publish","type":"post","link":"https:\/\/daacdigital.com\/en\/end-of-support-for-exchange-2016-2019-facts-and-action-plan\/","title":{"rendered":"End of support for Exchange 2016\/2019: facts and action plan"},"content":{"rendered":"<div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-1 fusion-flex-container nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-padding-right:30px;--awb-padding-left:30px;--awb-padding-right-small:0px;--awb-padding-left-small:0px;--awb-flex-wrap:wrap;\" ><div class=\"fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"max-width:1372.8px;margin-left: calc(-4% \/ 2 );margin-right: calc(-4% \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-0 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-text fusion-text-1\" style=\"--awb-content-alignment:left;\"><p>Extended support (End of Support, EoS) for Microsoft Exchange Server 2016 and 2019 will end on <strong>October 14, 2025<\/strong>. This means that security updates for these versions will cease completely. Running these systems after this date creates a direct and high risk of compromising corporate email infrastructure. The only supported on-premises version will be <strong>Exchange Server Subscription Edition (SE)<\/strong>.<br \/>\n<strong>&nbsp;<\/strong><\/p>\n<p><strong>Risks of the perpetual licensing model<\/strong><\/p>\n<p>The &#8220;perpetual license&#8221; model (CapEx) is incompatible with modern cybersecurity requirements. The threat landscape is constantly evolving, and software that does not receive regular updates inevitably becomes vulnerable. <\/p>\n<p>Corporate system security is an ongoing process. The subscription model (OpEx) ensures continuous vendor funding for development and release of security updates. Microsoft&#8217;s transition of Exchange Server to a subscription model confirms that, under current conditions, support and updates are integral parts of the product.  <\/p>\n<p><strong>&nbsp;<\/strong><br \/>\n<strong>Recommendation: Migrate email services to the cloud<\/strong><\/p>\n<p>The most secure strategy is to process email outside the corporate perimeter. Cloud platforms such as <strong>Microsoft 365<\/strong> and <strong>Google Workspace<\/strong> provide a level of protection unattainable for most internal IT teams. <\/p>\n<p>By moving email services to the cloud, an organization removes one of the most vulnerable public-facing services from its perimeter, eliminating it as a constant source of compromise. This removes from the organization the risks associated with administering and protecting on-premises email servers, which are prime targets for attacks (e.g., ProxyLogon\/ProxyShell vulnerabilities). <\/p>\n<p><strong>&nbsp;<\/strong><br \/>\n<strong>Action plan for on-premises infrastructure<\/strong><\/p>\n<p>For organizations retaining email servers within their perimeter for regulatory or technical reasons, the following steps are necessary:<\/p>\n<ol>\n<li><strong>Plan and perform an upgrade to Exchange Server Subscription Edition (SE).<\/strong> This is a mandatory requirement to continue receiving security updates and maintain an acceptable level of protection.<\/li>\n<li><strong>Strengthen internal network traffic monitoring.<\/strong> Perimeter firewall protection is insufficient. It is necessary to implement network segmentation to isolate critical systems and deploy Network Detection and Response (NDR) solutions to analyze internal (&#8220;east-west&#8221;) traffic for detecting anomalous activity and preventing lateral movement by attackers within the network. <\/li>\n<\/ol>\n<\/div><div class=\"fusion-text fusion-text-2\" style=\"--awb-content-alignment:left;--awb-margin-top:20px;\"><p><strong>Author: <\/strong><span style=\"background-color: rgba(0, 0, 0, 0);\"><i>Alexey Shulenkov (Cybersecurity Solutions Consultant, DAAC digital)<\/i><\/span><\/p>\n<\/div><div class=\"fusion-separator fusion-full-width-sep\" style=\"align-self: center;margin-left: auto;margin-right: auto;margin-top:30px;margin-bottom:15px;width:100%;\"><div class=\"fusion-separator-border sep-single sep-solid\" style=\"--awb-height:20px;--awb-amount:20px;--awb-sep-color:var(--awb-color2);border-color:var(--awb-color2);border-top-width:1px;\"><\/div><\/div><div class=\"fusion-text fusion-text-3\" style=\"--awb-content-alignment:left;\"><p>For detailed information about our cybersecurity solutions, please visit the dedicated page: <a href=\"https:\/\/daacdigital.com\/en\/?page_id=5922\" target=\"_blank\" rel=\"noopener\"><strong>Cyber Security.<\/strong><\/a><\/p>\n<\/div><\/div><\/div><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"","protected":false},"author":1,"featured_media":45273,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"iawp_total_views":18,"footnotes":""},"categories":[140,139,611],"tags":[541,683,545],"class_list":["post-45283","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","category-blog-en","category-blog-cybersecurity","tag-ai-en","tag-ai-threats","tag-cyber-security"],"_links":{"self":[{"href":"https:\/\/daacdigital.com\/en\/wp-json\/wp\/v2\/posts\/45283","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/daacdigital.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/daacdigital.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/daacdigital.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/daacdigital.com\/en\/wp-json\/wp\/v2\/comments?post=45283"}],"version-history":[{"count":2,"href":"https:\/\/daacdigital.com\/en\/wp-json\/wp\/v2\/posts\/45283\/revisions"}],"predecessor-version":[{"id":45285,"href":"https:\/\/daacdigital.com\/en\/wp-json\/wp\/v2\/posts\/45283\/revisions\/45285"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/daacdigital.com\/en\/wp-json\/wp\/v2\/media\/45273"}],"wp:attachment":[{"href":"https:\/\/daacdigital.com\/en\/wp-json\/wp\/v2\/media?parent=45283"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/daacdigital.com\/en\/wp-json\/wp\/v2\/categories?post=45283"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/daacdigital.com\/en\/wp-json\/wp\/v2\/tags?post=45283"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}