Exchange 2016 to Exchange Server SE Migration
Exchange Server 2016 has no in-place upgrade to Exchange Server SE, so this is a side-by-side migration delivered as a project — what Microsoft calls a legacy upgrade. IT Partner designs the SE topology (server count and placement, DAG layout, namespaces, load-balancer configuration, certificates, and a Windows Server version SE supports), prepares Active Directory, builds the SE servers inside your existing 2016 organization, runs the two versions in supported coexistence, moves the client namespaces and certificates to SE, migrates mailboxes, archives and modern public folders in scheduled batches, re-points any Exchange hybrid configuration to the new servers, and uninstalls the 2016 servers cleanly so nothing legacy is left in the directory. $12 per mailbox plus a $4,950 base fee, an estimate confirmed in a written quote before work starts; a typical single-site estate runs about 6 weeks, and estates above 2,000 mailboxes or with multi-site DAGs are quoted per estate. Two things to know first. Microsoft's support for Exchange 2016 ended on 14 October 2025 per its product lifecycle, and Microsoft has said that Exchange SE Cumulative Update 2 will refuse to coexist with Exchange 2016 at all — so the window for a supported side-by-side migration closes on Microsoft's timetable, not yours. And if keeping Exchange on-premises is no longer a requirement, Exchange Online is usually the better destination; we say so in scoping and point you to the hybrid or cutover migration instead.
What this engagement is
If you run Exchange Server 2016, you are running software Microsoft stopped supporting on 14 October 2025, per its product lifecycle. Microsoft built a paid bridge for organizations that could not move in time — an Extended Security Update program for Exchange 2016 and 2019 whose first period ran to April 2026 and whose second, purchased separately, covers May through October 2026 — and it has been clear that the bridge is a bridge, not a destination. The supported on-premises destination is Exchange Server Subscription Edition (SE), released in July 2025: the same code base as Exchange 2019 Cumulative Update 15 with later fixes, licensed as a subscription rather than a perpetual purchase, and the only version of on-premises Exchange that will keep receiving security updates. This page is for organizations that must keep Exchange on-premises — regulated workloads, air-gapped or sovereign environments, hybrid identity estates where the mailbox has to stay next to the directory — and need a supported place to stand. If that is not you, read the last paragraph first. Why a migration and not an upgrade: Microsoft's in-place upgrade to SE exists only from Exchange 2019 (CU14 or CU15). From Exchange 2016 the only route is the legacy upgrade — install SE servers into the same Active Directory organization, run the two versions side by side, move every mailbox and resource across, and uninstall 2016. Coexistence has conditions. Every 2016 server, including Edge Transport, must be on Cumulative Update 23 with a current security update before SE Setup will proceed, and only the SE RTM and CU1 builds coexist with 2016 at all: Microsoft has stated that Setup in SE CU2 will block coexistence with every unsupported version, 2016 and 2019 included, so the last 2016 server must be gone before CU2 can be installed. At the time of writing Microsoft has not published a date for CU1 (its August 2026 update said the build is coming without committing to one), and CU2 follows CU1. The deadline is real; its date belongs to Microsoft. Organizations still on Exchange 2013 or earlier cannot coexist with SE at all and need a two-hop plan, which we scope separately. What the engineering actually involves, because it is more than a mailbox move. The SE servers are new builds on Windows Server 2019, 2022 or 2025 — we recommend 2025 or 2022 for the longest runway, and Microsoft now recommends the Server Core installation — and the choice is for the life of the server, because Microsoft does not support an in-place operating-system upgrade with Exchange installed. Sizing follows the Exchange 2019 and SE requirements, which call for far more memory than a 2016 server ever ran on; re-using 2016 hardware rarely fits. A DAG cannot mix versions, so the SE servers form a new DAG with its own database layout and witness. Because a newer Exchange version proxies to an older one and not the reverse, the client namespaces — Autodiscover, Outlook, OWA, ActiveSync, EWS, OAB — move to SE first, the public certificate is exported and imported, and the load balancer's pools are re-pointed; SE ships with Windows Extended Protection enabled by default, which rules out SSL offloading at the load balancer, so that configuration is checked before cutover rather than discovered during it. Mail flow is rebuilt on SE: receive and send connectors, relay connectors for the printers and applications nobody remembers, transport rules, and a new SE Edge Transport server with a fresh Edge subscription where one exists. Mailboxes, archives and modern public folder mailboxes then move in online batches inside the organization while users keep working. Where a hybrid with Microsoft 365 exists, the Hybrid Configuration Wizard is re-run from SE using Microsoft's dedicated Exchange hybrid app — the shared service principal that hybrid used to rely on has been blocked for EWS since October 2025, and Microsoft requires the move to the app's Graph-based permission model by October 2026 — with free/busy, cross-premises moves and the MRS proxy validated afterwards. Only then do the 2016 servers come out, properly uninstalled rather than powered off, so no stale server objects, connectors or SCP records remain in Active Directory. The honest alternative. For most organizations that are not obliged to keep mail on-premises, Exchange Online is the better destination: the SE subscription plus Windows Server, hardware, backup and patching usually costs more per mailbox than the cloud service, and the operational burden — monthly security updates, cumulative updates, certificate renewals, the next hardware refresh — does not go away. We scope both paths on the same call and tell you which fits; the hybrid migration and the cutover migration to Exchange Online are the pages for that route. If you do stay on-premises, the SE subscription, CALs and Windows Server licensing are Microsoft's charges under Microsoft's terms, separate from our fee; our Volume Licensing practice can source them, and the target design states exactly what SE needs so nothing is bought twice or missed.
Which one applies to you
Three things an Exchange 2016 organization can do now. This service delivers the first column end to end; the second is referred to our Exchange Online migrations; the third is a containment posture, not a fix.
| Side-by-side migration to Exchange Server SE (this service) | Migrate to Exchange Online (referred) | Stay on Exchange 2016 under ESU (contain, do not settle) | |
|---|---|---|---|
| Who it fits | Organizations that must keep mailboxes on-premises: regulatory or data-residency obligations, air-gapped or sovereign networks, applications hard-wired to on-premises Exchange, hybrid identity estates that need the mailbox next to the directory. | Everyone else — and in our experience that is most mid-size organizations, once the SE subscription, Windows Server, hardware, backup and patching are priced honestly against Exchange Online. | Organizations that cannot complete either move before Microsoft's ESU coverage ends and need supported security updates while they plan one. |
| What happens technically | New SE servers and DAG built inside the existing organization on Windows Server 2019, 2022 or 2025; namespaces, certificates and mail flow moved to SE; mailboxes, archives and public folders moved in batches; hybrid re-pointed; 2016 uninstalled. | Hybrid Configuration Wizard and native migration batches (hybrid), or a one-time cutover for smaller estates; the on-premises servers are then decommissioned. | Exchange 2016 stays on CU23 with Microsoft's ESU security updates applied; attack surface reduced; no feature or version change. |
| The deadline that governs it | Coexistence works only with SE RTM and CU1; Microsoft has said SE CU2 Setup will block coexistence with 2016, and the last 2016 server must be removed before CU2 is installed. CU1 has no published date at the time of writing; CU2 follows it. | No coexistence deadline — Exchange Online is the destination — but the same ESU calendar applies to the on-premises servers while they are still in use. | ESU Period 2 for Exchange 2016 and 2019 covers May through October 2026 and is purchased separately from Period 1; Microsoft has not announced coverage beyond it at the time of writing. |
| Licensing afterwards | Exchange Server SE server licenses and CALs as subscription licenses or with active Software Assurance, or cloud subscription licenses such as Microsoft 365 E3 or E5 for every user and device — Microsoft's terms, Microsoft's charge. | Exchange Online or Microsoft 365 subscriptions per user; no server licenses, CALs or Windows Server for mail. | The ESU contract plus the existing 2016 licenses — a cost with no residual value once you migrate. |
| Our role | We deliver this end to end — this page. | We deliver this end to end through the hybrid and cutover migration services, and scope it beside this one so the comparison is real. | We can help you contain it, but we will not recommend it as an end state. |
Microsoft's guidance also lists a two-hop route — a legacy upgrade from 2016 to Exchange 2019 CU15 followed by an in-place upgrade to SE. It doubles the migration work, lands on a version that is itself out of support, and gains nothing over a direct move to SE, so we do not offer it as a standard path.
Success criteria
What you receive
How the work unfolds
Confirm scope, stakeholders, change windows, the date driving the project and access. Inventory the 2016 organization, run Microsoft's Exchange Health Checker on every server, capture mailbox and public folder sizes and the third-party dependency list, and record hybrid state. Anything that blocks coexistence — a server below CU23, a failing DAG copy, an expired certificate — is on the table by the end of the week.
Produce the target design and sizing, agree the Windows Server version, DAG layout, namespaces, load-balancer approach and hybrid plan, and confirm SE licensing and media are in hand. Bring the 2016 servers to CU23 with the current security update and remediate blocking findings. You approve the design before anything is built.
Prepare the schema, organization and domains for SE, build and patch the operating systems, install Exchange Server SE, complete post-installation configuration, create the DAG, seed database copies and confirm the witness. Health Checker runs clean on the new servers before they take any client traffic.
Import the certificate, re-point load-balancer pools and namespaces to SE, switch Autodiscover, and validate proxying to 2016 for every protocol. Build connectors and relay on SE, deploy the SE Edge Transport server where designed, re-run the Hybrid Configuration Wizard from SE where a hybrid exists, and move the pilot group with a full validation pass before the batch schedule starts.
Execute the batch schedule with move monitoring and failed-item handling, moving VIPs and the largest mailboxes in their agreed windows, arbitration and system mailboxes, and the public folder mailboxes in dependency order. Each batch is reconciled and signed off before the next; later batches move while earlier ones are validated.
Move the last resources off 2016, remove databases and DAG membership, transfer connector and OAB ownership, uninstall each 2016 server through Setup, verify Active Directory is clean, retire load-balancer, DNS, monitoring and backup references, and hand over the as-built documentation, patching runbook and closeout report.
Prerequisites
Who does what
IT Partner
- Run discovery and the Health Checker baseline, and produce the target design, sizing, licensing summary and migration plan for your approval.
- Bring the 2016 organization to the coexistence baseline within scope, prepare Active Directory, and build, patch and configure the Exchange Server SE servers and DAG.
- Execute the namespace, certificate, load-balancer and mail-flow cutover to SE, including the Edge Transport server where designed, and validate proxying and mail flow for every protocol in use.
- Re-run the Hybrid Configuration Wizard from SE with the dedicated hybrid app where a hybrid exists, and verify free/busy, cross-premises moves and the migration endpoint.
- Run the mailbox, archive and public folder migration batches, monitor and remediate failed moves within scope, and reconcile each batch.
- Uninstall the Exchange 2016 servers cleanly, verify Active Directory is clean, and re-point or retire the integrations, monitoring and backup references that named the old servers.
- Deliver the as-built documentation, patching runbook, post-migration Health Checker report and closeout report, and say plainly where Exchange Online would serve you better.
Your team
- Provide administrative access to Exchange, Active Directory, the hypervisor or hardware, the load balancer, DNS and the certificate, and the Schema and Enterprise Admins credentials for preparation.
- Procure Exchange Server SE licensing and media, Windows Server licensing, and the hardware or virtual capacity in the approved design, and own licensing compliance decisions.
- Approve the target design, the migration plan, the bad-item and large-item limits, and each cutover and batch window, and communicate with users using the templates provided.
- Perform or approve internal and external DNS changes and firewall changes, and coordinate third-party vendors whose products point at Exchange.
- Maintain current backups of the 2016 databases through the migration and confirm Exchange-aware backup of the SE servers.
- Provide a dedicated point of contact and the named owners above for the duration, and review and approve deliverables in a timely manner.
- Own the hardware, licensing and vendor upgrades the design identifies as outside the migration itself.
What's not included
Limitations & technical notes
Frequently asked questions
Why can't we just upgrade Exchange 2016 in place to Exchange Server SE?
Because Microsoft's in-place upgrade to SE exists only from Exchange 2019 CU14 or CU15 — SE is the 2019 code base with a new name and license, so 2019 can take it as if it were a cumulative update. Exchange 2016 is a different code base. From 2016 Microsoft's only supported route is the legacy upgrade: install SE servers into the same organization, coexist, move everything, uninstall 2016. That is what this service delivers.
What is Exchange Server SE, and how is it different from Exchange 2019?
Exchange Server Subscription Edition, released in July 2025, is functionally the same product as Exchange 2019 Cumulative Update 15 with later fixes and security updates; Microsoft's stated goal for the first release was to change nothing but the name, the license and the build number so that upgrades would be low-risk. The differences are commercial and lifecycle: SE is licensed as a subscription (or with active Software Assurance), it follows a modern lifecycle with continuous cumulative updates rather than a fixed end date, and it is the only on-premises Exchange that still receives security updates.
What is the actual deadline?
Three dates, all Microsoft's. Exchange 2016 support ended on 14 October 2025 per Microsoft's product lifecycle. Microsoft's paid Extended Security Update program for 2016 and 2019 has a second period covering May through October 2026, purchased separately, with nothing announced beyond it at the time of writing. And Microsoft has said that Exchange SE Cumulative Update 2 will block coexistence with 2016 and 2019 entirely — you must have removed 2016 before CU2 can be installed. CU1 has no published date as of Microsoft's August 2026 update, and CU2 follows it, so the honest answer is: sooner than is comfortable, on a date Microsoft will announce rather than negotiate.
What licensing do we need for SE?
Under Microsoft's terms, Exchange Server SE requires server licenses and CALs that are either subscription licenses or covered by active Software Assurance — or cloud subscription licenses such as Microsoft 365 E3 or E5 for every user and device that accesses the servers. A Standard CAL is always required; the Enterprise CAL is an add-on for specific features. Windows Server licensing for the new servers is separate. These are Microsoft's charges, not part of our fee; the target design states exactly what the environment needs, and our Volume Licensing practice can source it if you do not have a reseller.
Which Windows Server version should the SE servers run?
Microsoft supports SE on Windows Server 2019, 2022 and 2025, and recommends the Server Core installation. We generally recommend Windows Server 2025 or 2022 for the longest support runway, chosen once: Microsoft does not support an in-place operating-system upgrade on a server that has Exchange installed, so the version you build on is the version that server runs until it is replaced. The design also sizes memory and storage to Microsoft's SE requirements, which are well above what a 2016 server needed.
Will users notice anything?
Very little, if the namespace switch is done properly. Because SE proxies requests to mailboxes still on 2016, the client-facing names move to SE first and Outlook, mobile devices and Outlook on the web keep working without reconfiguration throughout coexistence. Each mailbox move is an online move: the user keeps working and gets a prompt to restart Outlook when the move completes. Downtime is confined to the short cutover windows for the namespace switch and mail flow, which we schedule with you.
We run a DAG. How is that handled?
A DAG cannot contain mixed Exchange versions, so the SE servers form a new DAG with its own databases, copies and witness, designed to your availability requirements rather than copied from the 2016 layout. Mailboxes move from the 2016 DAG's databases to the SE DAG's databases in batches. When the last mailbox is gone, the 2016 database copies and databases are removed, the servers leave the old DAG, and the DAG is deleted before the servers are uninstalled.
What happens to our public folders?
Exchange 2016 already uses modern public folders — they live in public folder mailboxes — so they move to SE the same way user mailboxes do, in the order the hierarchy requires, with item counts reconciled. If discovery finds public folder mailboxes at or beyond Microsoft's size limits or a structure that should be split, that remediation is scoped separately through our on-premises public folder migration service, and if you would rather retire public folders to Microsoft 365 that is an Exchange Online scope.
We have a hybrid with Microsoft 365. What changes?
The hybrid moves with you. Once the SE servers are in and the namespaces point to them, we re-run the Hybrid Configuration Wizard from SE using Microsoft's dedicated Exchange hybrid app, move the migration endpoint and MRS proxy to SE, verify OAuth, organization relationships and free/busy in both directions, and confirm mailbox moves to and from Exchange Online still work. Microsoft blocked the legacy shared service principal for EWS in October 2025 and requires the dedicated app's Graph-based permission model by October 2026, so if your hybrid has not made that change yet, it happens here.
What about the load balancer and certificates?
The public SAN certificate that covers your namespaces is normally re-used: exported from 2016 with its private key, imported and assigned on SE, and renewed on SE's schedule afterwards. The load balancer gets new pools and health probes for the SE servers, and one thing is checked early: SE enables Windows Extended Protection by default, which does not work with SSL offloading, so a load balancer configured to offload is switched to SSL bridging before the namespaces move.
Should we just go to Exchange Online instead?
Possibly, and we will tell you if so. Organizations with a regulatory, data-residency, air-gap or application reason to keep mailboxes on-premises are the audience for this page. If none of those apply, Exchange Online usually costs less per mailbox once the SE subscription, Windows Server, hardware, backup and patching are counted honestly, and it removes the next migration from your calendar. We scope the hybrid or cutover Exchange Online migration beside this one on the same call so the comparison is on real numbers.
How much does it cost, and what does the estimate cover?
$12 per mailbox plus a $4,950 base fee, as an estimate confirmed in a written quote before work begins — you pay after you approve delivery. A 500-mailbox organization with a two-server SE DAG comes to $10,950 on those figures. The base fee covers design, Active Directory preparation, the SE build, the namespace and mail-flow cutover and the 2016 decommission; the per-mailbox fee covers the batch moves and reconciliation. Estates above 2,000 mailboxes or with multi-site DAGs are quoted per estate. Microsoft licensing, Windows Server and hardware are separate and yours.
What happens to the old Exchange 2016 servers?
They are uninstalled through Exchange Setup, not powered off. Powering off leaves server objects, connectors and Autodiscover records in Active Directory that break hybrid wizards, confuse clients and haunt every future upgrade. The decommission moves the last system mailboxes, removes databases and DAG membership, transfers connector and address-book ownership to SE, uninstalls each server, and then verifies the directory is clean and that load balancer, DNS, monitoring and backup no longer reference the old names.
What does keeping SE healthy look like after the project?
SE is a subscription product with continuous servicing: Microsoft ships security updates when needed and cumulative updates on its own cadence, and it supports only the most recent ones, so a server left alone for a year is both insecure and unsupported. The closeout hands you a patching runbook and the as-built documentation. Organizations that do not want to own that cadence can have us run it as a managed service, scoped separately from this migration.
We are still on Exchange 2013 or 2010. Does this apply?
Not directly. SE coexists only with Exchange 2016 CU23 and Exchange 2019 CU14 or CU15, so an organization on 2013 or earlier cannot install SE into it. The route is a two-hop plan — 2013 to 2016 or 2019 first, then to SE — or, far more often, a direct migration to Exchange Online, which has no such constraint. Tell us the version on the scoping call and we will lay out both.