First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/Exchange 2016 to Exchange Server SE Migration
Migration

Exchange 2016 to Exchange Server SE Migration

Exchange Server 2016 has no in-place upgrade to Exchange Server SE, so this is a side-by-side migration delivered as a project — what Microsoft calls a legacy upgrade. IT Partner designs the SE topology (server count and placement, DAG layout, namespaces, load-balancer configuration, certificates, and a Windows Server version SE supports), prepares Active Directory, builds the SE servers inside your existing 2016 organization, runs the two versions in supported coexistence, moves the client namespaces and certificates to SE, migrates mailboxes, archives and modern public folders in scheduled batches, re-points any Exchange hybrid configuration to the new servers, and uninstalls the 2016 servers cleanly so nothing legacy is left in the directory. $12 per mailbox plus a $4,950 base fee, an estimate confirmed in a written quote before work starts; a typical single-site estate runs about 6 weeks, and estates above 2,000 mailboxes or with multi-site DAGs are quoted per estate. Two things to know first. Microsoft's support for Exchange 2016 ended on 14 October 2025 per its product lifecycle, and Microsoft has said that Exchange SE Cumulative Update 2 will refuse to coexist with Exchange 2016 at all — so the window for a supported side-by-side migration closes on Microsoft's timetable, not yours. And if keeping Exchange on-premises is no longer a requirement, Exchange Online is usually the better destination; we say so in scoping and point you to the hybrid or cutover migration instead.

Timeline 6 weeksService owner Mike MackeyExchange ServerWindows Server

What this engagement is

If you run Exchange Server 2016, you are running software Microsoft stopped supporting on 14 October 2025, per its product lifecycle. Microsoft built a paid bridge for organizations that could not move in time — an Extended Security Update program for Exchange 2016 and 2019 whose first period ran to April 2026 and whose second, purchased separately, covers May through October 2026 — and it has been clear that the bridge is a bridge, not a destination. The supported on-premises destination is Exchange Server Subscription Edition (SE), released in July 2025: the same code base as Exchange 2019 Cumulative Update 15 with later fixes, licensed as a subscription rather than a perpetual purchase, and the only version of on-premises Exchange that will keep receiving security updates. This page is for organizations that must keep Exchange on-premises — regulated workloads, air-gapped or sovereign environments, hybrid identity estates where the mailbox has to stay next to the directory — and need a supported place to stand. If that is not you, read the last paragraph first. Why a migration and not an upgrade: Microsoft's in-place upgrade to SE exists only from Exchange 2019 (CU14 or CU15). From Exchange 2016 the only route is the legacy upgrade — install SE servers into the same Active Directory organization, run the two versions side by side, move every mailbox and resource across, and uninstall 2016. Coexistence has conditions. Every 2016 server, including Edge Transport, must be on Cumulative Update 23 with a current security update before SE Setup will proceed, and only the SE RTM and CU1 builds coexist with 2016 at all: Microsoft has stated that Setup in SE CU2 will block coexistence with every unsupported version, 2016 and 2019 included, so the last 2016 server must be gone before CU2 can be installed. At the time of writing Microsoft has not published a date for CU1 (its August 2026 update said the build is coming without committing to one), and CU2 follows CU1. The deadline is real; its date belongs to Microsoft. Organizations still on Exchange 2013 or earlier cannot coexist with SE at all and need a two-hop plan, which we scope separately. What the engineering actually involves, because it is more than a mailbox move. The SE servers are new builds on Windows Server 2019, 2022 or 2025 — we recommend 2025 or 2022 for the longest runway, and Microsoft now recommends the Server Core installation — and the choice is for the life of the server, because Microsoft does not support an in-place operating-system upgrade with Exchange installed. Sizing follows the Exchange 2019 and SE requirements, which call for far more memory than a 2016 server ever ran on; re-using 2016 hardware rarely fits. A DAG cannot mix versions, so the SE servers form a new DAG with its own database layout and witness. Because a newer Exchange version proxies to an older one and not the reverse, the client namespaces — Autodiscover, Outlook, OWA, ActiveSync, EWS, OAB — move to SE first, the public certificate is exported and imported, and the load balancer's pools are re-pointed; SE ships with Windows Extended Protection enabled by default, which rules out SSL offloading at the load balancer, so that configuration is checked before cutover rather than discovered during it. Mail flow is rebuilt on SE: receive and send connectors, relay connectors for the printers and applications nobody remembers, transport rules, and a new SE Edge Transport server with a fresh Edge subscription where one exists. Mailboxes, archives and modern public folder mailboxes then move in online batches inside the organization while users keep working. Where a hybrid with Microsoft 365 exists, the Hybrid Configuration Wizard is re-run from SE using Microsoft's dedicated Exchange hybrid app — the shared service principal that hybrid used to rely on has been blocked for EWS since October 2025, and Microsoft requires the move to the app's Graph-based permission model by October 2026 — with free/busy, cross-premises moves and the MRS proxy validated afterwards. Only then do the 2016 servers come out, properly uninstalled rather than powered off, so no stale server objects, connectors or SCP records remain in Active Directory. The honest alternative. For most organizations that are not obliged to keep mail on-premises, Exchange Online is the better destination: the SE subscription plus Windows Server, hardware, backup and patching usually costs more per mailbox than the cloud service, and the operational burden — monthly security updates, cumulative updates, certificate renewals, the next hardware refresh — does not go away. We scope both paths on the same call and tell you which fits; the hybrid migration and the cutover migration to Exchange Online are the pages for that route. If you do stay on-premises, the SE subscription, CALs and Windows Server licensing are Microsoft's charges under Microsoft's terms, separate from our fee; our Volume Licensing practice can source them, and the target design states exactly what SE needs so nothing is bought twice or missed.

Which one applies to you

Three things an Exchange 2016 organization can do now. This service delivers the first column end to end; the second is referred to our Exchange Online migrations; the third is a containment posture, not a fix.

Side-by-side migration to Exchange Server SE (this service)Migrate to Exchange Online (referred)Stay on Exchange 2016 under ESU (contain, do not settle)
Who it fitsOrganizations that must keep mailboxes on-premises: regulatory or data-residency obligations, air-gapped or sovereign networks, applications hard-wired to on-premises Exchange, hybrid identity estates that need the mailbox next to the directory.Everyone else — and in our experience that is most mid-size organizations, once the SE subscription, Windows Server, hardware, backup and patching are priced honestly against Exchange Online.Organizations that cannot complete either move before Microsoft's ESU coverage ends and need supported security updates while they plan one.
What happens technicallyNew SE servers and DAG built inside the existing organization on Windows Server 2019, 2022 or 2025; namespaces, certificates and mail flow moved to SE; mailboxes, archives and public folders moved in batches; hybrid re-pointed; 2016 uninstalled.Hybrid Configuration Wizard and native migration batches (hybrid), or a one-time cutover for smaller estates; the on-premises servers are then decommissioned.Exchange 2016 stays on CU23 with Microsoft's ESU security updates applied; attack surface reduced; no feature or version change.
The deadline that governs itCoexistence works only with SE RTM and CU1; Microsoft has said SE CU2 Setup will block coexistence with 2016, and the last 2016 server must be removed before CU2 is installed. CU1 has no published date at the time of writing; CU2 follows it.No coexistence deadline — Exchange Online is the destination — but the same ESU calendar applies to the on-premises servers while they are still in use.ESU Period 2 for Exchange 2016 and 2019 covers May through October 2026 and is purchased separately from Period 1; Microsoft has not announced coverage beyond it at the time of writing.
Licensing afterwardsExchange Server SE server licenses and CALs as subscription licenses or with active Software Assurance, or cloud subscription licenses such as Microsoft 365 E3 or E5 for every user and device — Microsoft's terms, Microsoft's charge.Exchange Online or Microsoft 365 subscriptions per user; no server licenses, CALs or Windows Server for mail.The ESU contract plus the existing 2016 licenses — a cost with no residual value once you migrate.
Our roleWe deliver this end to end — this page.We deliver this end to end through the hybrid and cutover migration services, and scope it beside this one so the comparison is real.We can help you contain it, but we will not recommend it as an end state.

Microsoft's guidance also lists a two-hop route — a legacy upgrade from 2016 to Exchange 2019 CU15 followed by an in-place upgrade to SE. It doubles the migration work, lands on a version that is itself out of support, and gains nothing over a direct move to SE, so we do not offer it as a standard path.

Success criteria

01A written target design is approved before any server is built: SE server count and placement, DAG and database layout, Windows Server version and installation option, hardware or VM sizing against Microsoft's published requirements for SE, namespace plan, load-balancer configuration, certificate plan, Edge Transport and mail-flow design, and the hybrid plan where one exists.
02Every Exchange 2016 server, including Edge Transport, is confirmed at Cumulative Update 23 with the current security update, and Active Directory is prepared for SE (schema, organization and domains) with replication verified, before SE Setup runs.
03The SE servers are installed, patched to the agreed build, joined to the organization, and — where designed — form a healthy DAG with all database copies healthy; Microsoft's Exchange Health Checker script reports no critical findings on the new servers before the namespace switch.
04All client namespaces (Autodiscover, Outlook, Outlook on the web, ActiveSync, EWS, MAPI over HTTP, OAB) and SMTP are served by SE, with mailboxes still on 2016 reached through SE's proxying, and no reconfiguration is required on Outlook desktop or mobile clients during coexistence.
05Every in-scope mailbox, archive mailbox and public folder mailbox is moved to SE with move reports retained and item counts reconciled against the source, and no user, shared, resource, arbitration or public folder mailbox remains on Exchange 2016.
06Inbound, outbound and internal mail flows through SE — and through the SE Edge Transport server where one is designed — with accepted domains, send and receive connectors, application and device relay connectors, and transport rules reproduced and tested end to end.
07Where a hybrid with Microsoft 365 exists, the Hybrid Configuration Wizard has been re-run against SE with the dedicated Exchange hybrid app, and free/busy, cross-premises mailbox moves and the migration endpoint are verified working from the SE servers.
08The Exchange 2016 servers are uninstalled through Setup rather than powered off, no 2016 server, connector or Autodiscover SCP objects remain in Active Directory, load-balancer, DNS and third-party references to the old servers are removed, and the client receives as-built documentation and a closeout report.

What you receive

Discovery and readiness review of the Exchange 2016 organization: servers and build levels, DAG and database layout with sizes, mailbox, archive and public folder inventory with the largest items called out, namespaces and certificates, connectors and transport rules, hybrid state, client versions in use, and every third-party system that talks to Exchange — backup agents, antivirus, journaling and archiving, signature tools, fax, multifunction printers and applications relaying SMTP — with Microsoft's Exchange Health Checker output as the baseline.
Target design document: SE server roles, count and placement; DAG, database and witness layout; Windows Server version and installation option; sizing per Microsoft's requirements for SE; namespace and Autodiscover plan; load-balancer configuration including the Windows Extended Protection implications; certificate plan; Edge Transport plan; mail-flow design; hybrid plan; and the licensing SE will require, stated plainly so it can be bought once.
Prerequisite plan and execution within scope: bringing the 2016 servers to Cumulative Update 23 with the current security update where they are not already there, resolving Health Checker findings that would block Setup, and confirming Active Directory functional levels and replication health.
Active Directory preparation for Exchange Server SE — schema, organization and domain preparation — run with the credentials you provide, verified by replication and object checks before server installation.
SE server builds: operating-system configuration, Exchange prerequisites, Exchange Server SE installation, and post-installation configuration — virtual directory URLs, certificate assignment, Outlook Anywhere and MAPI settings, OAB, mailbox databases and paths, DAG creation with database copies and witness, and Exchange-aware backup readiness.
Coexistence configuration: certificate export and import, load-balancer pool and health-probe changes, namespace and Autodiscover SCP switch to SE, and validation that SE correctly proxies to mailboxes still on 2016 for every protocol in use.
Mail-flow build on SE: receive connectors including anonymous and authenticated relay for devices and applications, send connectors with source servers moved to SE, accepted domains and email address policies reviewed, transport rules verified, and — where designed — an SE Edge Transport server with a new Edge subscription and the old subscription removed.
Migration plan: pilot group, batch schedule and sizes, VIP and large-mailbox handling, bad-item and large-item limits agreed in writing, public folder mailbox move order, user communication templates, and rollback criteria per batch.
Mailbox, archive and public folder mailbox migration: batch execution with move monitoring, failed-item review and re-runs, arbitration and system mailbox moves, and per-batch reconciliation reports.
Hybrid re-pointing where a hybrid with Microsoft 365 exists: Hybrid Configuration Wizard run from SE, dedicated Exchange hybrid app configured on the current permission model, OAuth and organization relationships verified, migration endpoint and MRS proxy moved to SE, and free/busy tested in both directions.
Exchange 2016 decommissioning: remaining mailboxes and system mailboxes moved, database copies and databases removed, DAG membership removed, send connector and offline address book ownership moved, servers uninstalled through Setup, Active Directory verified clean, and load-balancer, DNS, monitoring, backup and third-party integrations re-pointed or retired.
Closeout package: as-built documentation of the SE environment, post-migration Health Checker report, a patching runbook for SE security updates and cumulative updates, a summary of the licensing the environment requires, and a project closeout report with acceptance criteria matching, outstanding items if any, and the final budget against the estimate.

How the work unfolds

1. Kickoff, discovery and health baseline (week 1)

Confirm scope, stakeholders, change windows, the date driving the project and access. Inventory the 2016 organization, run Microsoft's Exchange Health Checker on every server, capture mailbox and public folder sizes and the third-party dependency list, and record hybrid state. Anything that blocks coexistence — a server below CU23, a failing DAG copy, an expired certificate — is on the table by the end of the week.

2. Target design, licensing check and prerequisites (weeks 1–2)

Produce the target design and sizing, agree the Windows Server version, DAG layout, namespaces, load-balancer approach and hybrid plan, and confirm SE licensing and media are in hand. Bring the 2016 servers to CU23 with the current security update and remediate blocking findings. You approve the design before anything is built.

3. Active Directory preparation and SE server build (weeks 2–3)

Prepare the schema, organization and domains for SE, build and patch the operating systems, install Exchange Server SE, complete post-installation configuration, create the DAG, seed database copies and confirm the witness. Health Checker runs clean on the new servers before they take any client traffic.

4. Coexistence cutover, mail flow, hybrid re-point and pilot moves (weeks 3–4)

Import the certificate, re-point load-balancer pools and namespaces to SE, switch Autodiscover, and validate proxying to 2016 for every protocol. Build connectors and relay on SE, deploy the SE Edge Transport server where designed, re-run the Hybrid Configuration Wizard from SE where a hybrid exists, and move the pilot group with a full validation pass before the batch schedule starts.

5. Mailbox, archive and public folder migration waves (weeks 4–5)

Execute the batch schedule with move monitoring and failed-item handling, moving VIPs and the largest mailboxes in their agreed windows, arbitration and system mailboxes, and the public folder mailboxes in dependency order. Each batch is reconciled and signed off before the next; later batches move while earlier ones are validated.

6. Exchange 2016 decommission, validation and handover (week 6)

Move the last resources off 2016, remove databases and DAG membership, transfer connector and OAB ownership, uninstall each 2016 server through Setup, verify Active Directory is clean, retire load-balancer, DNS, monitoring and backup references, and hand over the as-built documentation, patching runbook and closeout report.

Prerequisites

An Exchange 2016 organization at Cumulative Update 23 on every server, including Edge Transport, with the current security update — Microsoft's baseline for coexistence with SE. Servers on older builds are brought to CU23 first; that work is scoped in the quote and needs its own maintenance windows.
Exchange Server SE licensing arranged before the build: SE server licenses and Standard (and, where features require, Enterprise) CALs as subscription licenses or with active Software Assurance, or cloud subscription licenses such as Microsoft 365 E3 or E5 covering every user and device that will access the servers — per Microsoft's licensing terms, confirmed with your reseller — and the SE installation media from your licensing portal. Our Volume Licensing practice can source both.
Windows Server 2019, 2022 or 2025 licensing and physical or virtual capacity sized to Microsoft's published requirements for SE — notably far more memory per Mailbox server than Exchange 2016 needed — with storage for the databases, logs and the copies the DAG design calls for.
A healthy Active Directory: forest and domain functional levels Microsoft supports for SE, replication clean, and Schema Admins and Enterprise Admins credentials available for the preparation steps. If the directory's state is unknown, the Active Directory Security Assessment runs first, and a domain-controller refresh is the Domain Services and Active Directory Roles Migration.
A public certificate covering the namespaces in the design — usually the existing SAN certificate, exportable with its private key — and access to the internal PKI if internal names are used.
Administrative access to the load balancer, or a network engineer available in the cutover windows, and a load balancer able to run SSL bridging rather than offloading, because SE enables Windows Extended Protection by default.
A current, verified backup of the 2016 mailbox databases before the first move, and an Exchange-aware backup solution ready for the SE servers from day one.
Named owners for the engagement: the Exchange administrator, network and load-balancer, Active Directory, security, and a business contact who can approve cutover and batch windows, plus your change-management calendar.
The list of everything that talks to Exchange — backup agents, antivirus, journaling and archiving, signature tools, fax, multifunction printers, line-of-business applications using SMTP or EWS — with a vendor contact for each; re-pointing them is in scope, upgrading or re-licensing them is yours.

Who does what

IT Partner

  • Run discovery and the Health Checker baseline, and produce the target design, sizing, licensing summary and migration plan for your approval.
  • Bring the 2016 organization to the coexistence baseline within scope, prepare Active Directory, and build, patch and configure the Exchange Server SE servers and DAG.
  • Execute the namespace, certificate, load-balancer and mail-flow cutover to SE, including the Edge Transport server where designed, and validate proxying and mail flow for every protocol in use.
  • Re-run the Hybrid Configuration Wizard from SE with the dedicated hybrid app where a hybrid exists, and verify free/busy, cross-premises moves and the migration endpoint.
  • Run the mailbox, archive and public folder migration batches, monitor and remediate failed moves within scope, and reconcile each batch.
  • Uninstall the Exchange 2016 servers cleanly, verify Active Directory is clean, and re-point or retire the integrations, monitoring and backup references that named the old servers.
  • Deliver the as-built documentation, patching runbook, post-migration Health Checker report and closeout report, and say plainly where Exchange Online would serve you better.

Your team

  • Provide administrative access to Exchange, Active Directory, the hypervisor or hardware, the load balancer, DNS and the certificate, and the Schema and Enterprise Admins credentials for preparation.
  • Procure Exchange Server SE licensing and media, Windows Server licensing, and the hardware or virtual capacity in the approved design, and own licensing compliance decisions.
  • Approve the target design, the migration plan, the bad-item and large-item limits, and each cutover and batch window, and communicate with users using the templates provided.
  • Perform or approve internal and external DNS changes and firewall changes, and coordinate third-party vendors whose products point at Exchange.
  • Maintain current backups of the 2016 databases through the migration and confirm Exchange-aware backup of the SE servers.
  • Provide a dedicated point of contact and the named owners above for the duration, and review and approve deliverables in a timely manner.
  • Own the hardware, licensing and vendor upgrades the design identifies as outside the migration itself.

What's not included

Exchange Online as the destination. If mailboxes are going to Microsoft 365 rather than to SE, the service is the Hybrid Microsoft 365 Migration from your own Exchange Server or, for smaller estates, the Cutover Exchange Online Migration; we scope them beside this one and tell you which fits.
Hardware, hypervisor capacity, storage, Windows Server licensing and the Exchange Server SE subscription, CALs or Software Assurance — Microsoft's and your suppliers' charges, separate from our fee. Our Microsoft Volume Licensing service can source the Microsoft licensing.
Migration of third-party email archives — Enterprise Vault, Mimecast, Proofpoint, GFI and similar — into Exchange or Microsoft 365, which is the Third-Party Email Archive Migration service.
Public folder restructuring, size-limit remediation or a move to Exchange Online public folders. Modern public folder mailboxes move to SE as part of this service; anything beyond a like-for-like move is the On-premises Public Folders Migration or an Exchange Online scope.
A replacement for Exchange Unified Messaging. UM was removed from Exchange 2019 and does not exist in SE; if 2016 UM provides voicemail or auto-attendants today, the replacement (Teams Phone with Cloud Voicemail or a third-party system) is scoped separately before this migration removes the last UM server.
Changes to line-of-business applications that authenticate or relay in ways SE does not accept, and upgrades of third-party products that do not support Exchange SE — we identify them in discovery and re-point what can be re-pointed; the vendor work is yours.
Client rollout: Outlook or mobile app upgrades for versions outside Microsoft's support matrix for SE, and desktop or device configuration.
Upgrading domain controllers or other Windows Server roles that surface in discovery, which is the Domain Services and Active Directory Roles Migration.
Security hardening beyond Microsoft's defaults for SE and the design's baseline — that is the Active Directory Security Assessment and Hardening or a dedicated hardening engagement.
Ongoing administration and patching of the SE environment after closeout — monthly security updates, cumulative updates, certificate renewals, DAG health — which is a managed service scoped separately.
Recovery of failed or unrecoverable Exchange 2016 servers or databases. This service assumes a functioning 2016 organization; emergency recovery is scoped as its own engagement first.

Limitations & technical notes

!Pricing is $12 per mailbox plus a $4,950 base fee as an estimate: the base covers design, Active Directory preparation, a single-site SE build with a DAG of up to two servers, the namespace and mail-flow cutover and the 2016 decommission; the per-mailbox fee covers batch planning, moves and reconciliation. Estates above 2,000 mailboxes, multi-site DAGs, more than one Edge Transport server, more than one hybrid tenant, or unusual third-party integration counts are quoted per estate. The written quote states the fixed figure before work begins.
!Dates on this page are Microsoft's, stated per its product lifecycle and announcements at the time of writing: Exchange 2016 and 2019 support ended 14 October 2025; the Exchange 2016 and 2019 Extended Security Update program's second period covers May through October 2026 and is purchased separately; Exchange SE CU1 has no published release date, and Microsoft has said SE CU2 Setup will block coexistence with 2016 and 2019. We re-check all of them at scoping and the plan is built to finish before any of them bite.
!Coexistence requires Exchange 2016 CU23 with a current security update on every server, Edge Transport included, and works only with the SE RTM and CU1 builds. If Microsoft releases CU2 while a project is in flight, the SE servers stay on the last coexistence-capable build until the final 2016 server is uninstalled and are updated immediately afterwards — Microsoft's servicing policy supports only the most recent cumulative updates, so the calendar should not assume a long runway.
!Exchange Server SE is licensed as a subscription: server licenses and CALs must be subscription licenses or carry active Software Assurance, or every user and device must hold a qualifying cloud subscription license such as Microsoft 365 E3 or E5. Those are Microsoft's terms and Microsoft's charge; a lapsed subscription removes the right to run SE. We state what is needed; your reseller or our licensing practice confirms it against your agreement.
!SE follows the Exchange 2019 hardware and operating-system requirements, including memory far above what Exchange 2016 needed and support only on Windows Server 2019, 2022 and 2025. Microsoft does not support an in-place operating-system upgrade on a server with Exchange installed, so the Windows Server version chosen at build time is the version for the server's lifetime. Virtualization is supported within Microsoft's published policy; re-using the 2016 hardware is assessed, not assumed.
!SE enables Windows Extended Protection by default, which is incompatible with SSL offloading at the load balancer; load balancers are reconfigured for SSL bridging, and any device, client or third-party product that cannot operate with Extended Protection is identified in discovery so the decision is made before cutover rather than at it.
!Mailbox move throughput depends on your storage, network and the health of the source databases, not on the tool. Corrupted or oversized items are governed by the bad-item and large-item limits agreed in writing before the batches start; items that exceed them are reported, not silently dropped, and the plan reserves time for re-runs.
!Where a hybrid with Microsoft 365 exists, the migration re-runs the Hybrid Configuration Wizard from SE using Microsoft's dedicated Exchange hybrid app. Microsoft blocked EWS through the legacy shared service principal in October 2025 and requires the app's Graph-based permission model by October 2026; if your hybrid has not yet made that change, it is completed as part of the re-point, and the closeout report records it.
!Unified Messaging does not exist in SE. Voicemail and auto-attendant services still running on 2016 UM need a replacement in place before the last UM-enabled server is removed; this service flags it in discovery and does not build the replacement.
!Where a mailbox move or hybrid function is stuck on a defect on Microsoft's side, we can open a case under our Microsoft Premier Support agreement as a paid add-on; Microsoft's response times are Microsoft's.
!The 6-week figure fits a single-site organization of a few 2016 servers and a few hundred to a couple of thousand mailboxes. Multi-site DAGs, large public folder estates, Edge Transport, hybrid re-pointing and long change-freeze calendars extend it, and the migration plan states the real dates.

Frequently asked questions

Why can't we just upgrade Exchange 2016 in place to Exchange Server SE?

Because Microsoft's in-place upgrade to SE exists only from Exchange 2019 CU14 or CU15 — SE is the 2019 code base with a new name and license, so 2019 can take it as if it were a cumulative update. Exchange 2016 is a different code base. From 2016 Microsoft's only supported route is the legacy upgrade: install SE servers into the same organization, coexist, move everything, uninstall 2016. That is what this service delivers.

What is Exchange Server SE, and how is it different from Exchange 2019?

Exchange Server Subscription Edition, released in July 2025, is functionally the same product as Exchange 2019 Cumulative Update 15 with later fixes and security updates; Microsoft's stated goal for the first release was to change nothing but the name, the license and the build number so that upgrades would be low-risk. The differences are commercial and lifecycle: SE is licensed as a subscription (or with active Software Assurance), it follows a modern lifecycle with continuous cumulative updates rather than a fixed end date, and it is the only on-premises Exchange that still receives security updates.

What is the actual deadline?

Three dates, all Microsoft's. Exchange 2016 support ended on 14 October 2025 per Microsoft's product lifecycle. Microsoft's paid Extended Security Update program for 2016 and 2019 has a second period covering May through October 2026, purchased separately, with nothing announced beyond it at the time of writing. And Microsoft has said that Exchange SE Cumulative Update 2 will block coexistence with 2016 and 2019 entirely — you must have removed 2016 before CU2 can be installed. CU1 has no published date as of Microsoft's August 2026 update, and CU2 follows it, so the honest answer is: sooner than is comfortable, on a date Microsoft will announce rather than negotiate.

What licensing do we need for SE?

Under Microsoft's terms, Exchange Server SE requires server licenses and CALs that are either subscription licenses or covered by active Software Assurance — or cloud subscription licenses such as Microsoft 365 E3 or E5 for every user and device that accesses the servers. A Standard CAL is always required; the Enterprise CAL is an add-on for specific features. Windows Server licensing for the new servers is separate. These are Microsoft's charges, not part of our fee; the target design states exactly what the environment needs, and our Volume Licensing practice can source it if you do not have a reseller.

Which Windows Server version should the SE servers run?

Microsoft supports SE on Windows Server 2019, 2022 and 2025, and recommends the Server Core installation. We generally recommend Windows Server 2025 or 2022 for the longest support runway, chosen once: Microsoft does not support an in-place operating-system upgrade on a server that has Exchange installed, so the version you build on is the version that server runs until it is replaced. The design also sizes memory and storage to Microsoft's SE requirements, which are well above what a 2016 server needed.

Will users notice anything?

Very little, if the namespace switch is done properly. Because SE proxies requests to mailboxes still on 2016, the client-facing names move to SE first and Outlook, mobile devices and Outlook on the web keep working without reconfiguration throughout coexistence. Each mailbox move is an online move: the user keeps working and gets a prompt to restart Outlook when the move completes. Downtime is confined to the short cutover windows for the namespace switch and mail flow, which we schedule with you.

We run a DAG. How is that handled?

A DAG cannot contain mixed Exchange versions, so the SE servers form a new DAG with its own databases, copies and witness, designed to your availability requirements rather than copied from the 2016 layout. Mailboxes move from the 2016 DAG's databases to the SE DAG's databases in batches. When the last mailbox is gone, the 2016 database copies and databases are removed, the servers leave the old DAG, and the DAG is deleted before the servers are uninstalled.

What happens to our public folders?

Exchange 2016 already uses modern public folders — they live in public folder mailboxes — so they move to SE the same way user mailboxes do, in the order the hierarchy requires, with item counts reconciled. If discovery finds public folder mailboxes at or beyond Microsoft's size limits or a structure that should be split, that remediation is scoped separately through our on-premises public folder migration service, and if you would rather retire public folders to Microsoft 365 that is an Exchange Online scope.

We have a hybrid with Microsoft 365. What changes?

The hybrid moves with you. Once the SE servers are in and the namespaces point to them, we re-run the Hybrid Configuration Wizard from SE using Microsoft's dedicated Exchange hybrid app, move the migration endpoint and MRS proxy to SE, verify OAuth, organization relationships and free/busy in both directions, and confirm mailbox moves to and from Exchange Online still work. Microsoft blocked the legacy shared service principal for EWS in October 2025 and requires the dedicated app's Graph-based permission model by October 2026, so if your hybrid has not made that change yet, it happens here.

What about the load balancer and certificates?

The public SAN certificate that covers your namespaces is normally re-used: exported from 2016 with its private key, imported and assigned on SE, and renewed on SE's schedule afterwards. The load balancer gets new pools and health probes for the SE servers, and one thing is checked early: SE enables Windows Extended Protection by default, which does not work with SSL offloading, so a load balancer configured to offload is switched to SSL bridging before the namespaces move.

Should we just go to Exchange Online instead?

Possibly, and we will tell you if so. Organizations with a regulatory, data-residency, air-gap or application reason to keep mailboxes on-premises are the audience for this page. If none of those apply, Exchange Online usually costs less per mailbox once the SE subscription, Windows Server, hardware, backup and patching are counted honestly, and it removes the next migration from your calendar. We scope the hybrid or cutover Exchange Online migration beside this one on the same call so the comparison is on real numbers.

How much does it cost, and what does the estimate cover?

$12 per mailbox plus a $4,950 base fee, as an estimate confirmed in a written quote before work begins — you pay after you approve delivery. A 500-mailbox organization with a two-server SE DAG comes to $10,950 on those figures. The base fee covers design, Active Directory preparation, the SE build, the namespace and mail-flow cutover and the 2016 decommission; the per-mailbox fee covers the batch moves and reconciliation. Estates above 2,000 mailboxes or with multi-site DAGs are quoted per estate. Microsoft licensing, Windows Server and hardware are separate and yours.

What happens to the old Exchange 2016 servers?

They are uninstalled through Exchange Setup, not powered off. Powering off leaves server objects, connectors and Autodiscover records in Active Directory that break hybrid wizards, confuse clients and haunt every future upgrade. The decommission moves the last system mailboxes, removes databases and DAG membership, transfers connector and address-book ownership to SE, uninstalls each server, and then verifies the directory is clean and that load balancer, DNS, monitoring and backup no longer reference the old names.

What does keeping SE healthy look like after the project?

SE is a subscription product with continuous servicing: Microsoft ships security updates when needed and cumulative updates on its own cadence, and it supports only the most recent ones, so a server left alone for a year is both insecure and unsupported. The closeout hands you a patching runbook and the as-built documentation. Organizations that do not want to own that cadence can have us run it as a managed service, scoped separately from this migration.

We are still on Exchange 2013 or 2010. Does this apply?

Not directly. SE coexists only with Exchange 2016 CU23 and Exchange 2019 CU14 or CU15, so an organization on 2013 or earlier cannot install SE into it. The route is a two-hop plan — 2013 to 2016 or 2019 first, then to SE — or, far more often, a direct migration to Exchange Online, which has no such constraint. Tell us the version on the scoping call and we will lay out both.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$12 per mailbox + $4,950 tenant fee
6 weeks
Request a migration quote