First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/Exchange 2019 to Exchange Server SE In-Place Upgrade
Implementation

Exchange 2019 to Exchange Server SE In-Place Upgrade

Exchange 2019 to Exchange Server SE In-Place Upgrade moves each of your Exchange Server 2019 servers to Exchange Server Subscription Edition (SE) — the only on-premises Exchange release Microsoft still supports, now that Exchange 2019 left support on 14 October 2025 per Microsoft's product lifecycle — without new servers and without moving a mailbox. Microsoft supports the in-place upgrade only from Exchange 2019 CU14 or CU15 and describes it as identical to installing a cumulative update, so IT Partner's work is the discipline around that setup: a HealthChecker readiness pass on every server, the prerequisite CU15 and hotfix where a server is behind, your SE licensing confirmed and the SE product keys in hand before any change window, Exchange-aware backups with a written rollback position, DAG-aware sequencing that moves active databases off each member before it is upgraded so users stay online, Edge Transport servers in the same plan, the SE key applied and the edition verified, and a validation record per server — mail flow, Outlook, Outlook on the web, EWS and free/busy, ActiveSync, Autodiscover, certificates, hybrid where you have it, and HealthChecker again — before the as-built and a next-CU run book are handed over. $1,250 per server plus a $1,950 flat fee per Exchange organization (the tenant fee on our quote), fixed and quoted in writing before work begins; you pay after you approve delivery. About 2 weeks for a typical single-DAG deployment. Not included: Exchange 2016 sources (there is no in-place path from 2016), Windows Server or hardware changes, migration to Exchange Online, and patching after handover — each named below with where it belongs.

Timeline 2 weeksService owner Mike MackeyExchange ServerExchange Server Subscription EditionWindows Server

What this engagement is

Exchange Server 2019 left support on 14 October 2025, per Microsoft's product lifecycle — no more security updates, no more support cases, and, unlike Windows Server, no multi-year Extended Security Update bridge to buy time with. The supported on-premises release is Exchange Server Subscription Edition (SE), which Microsoft released in July 2025. Microsoft has also said that SE Cumulative Update 2 will refuse to install while Exchange 2016 or 2019 servers remain in the organization, and originally planned it for the second half of 2026; as of Microsoft's August 2026 update, CU1 had not shipped and had no date, so the side-by-side window is open today and closes on Microsoft's schedule with the lead time of a release note. An Exchange 2019 estate that is not on SE is unpatched now and will be unable to take the next cumulative updates once CU2 ships. The good news for 2019 estates is that this is an upgrade, not a migration. Exchange SE RTM is code-equivalent to Exchange 2019 CU15 with the May 2025 hotfix, and Microsoft supports an in-place upgrade from Exchange 2019 CU14 or CU15 that it describes as identical to installing a cumulative update: setup runs in upgrade mode, and the server keeps its name, databases, connectors, certificates and DAG membership. What changes is the licence agreement, the product name and version, and the product key — Microsoft issues Exchange SE keys separately from Exchange 2019 keys, and a server left without an SE key runs unlicensed. What does not change is everything that makes an Exchange cumulative update a controlled event rather than a Tuesday-night setup: prerequisites that fail late if nobody checked them, Active Directory preparation where the build requires it, one DAG member at a time behind maintenance mode, customised web.config and OWA settings that setup silently overwrites, Extended Protection that a load balancer doing SSL offloading breaks, and a validation list nobody should run from memory. IT Partner runs it as an engineering project. Before anything changes we run Microsoft's HealthChecker script on every server and read the organization as it is: cumulative update and hotfix level, Windows Server version, .NET Framework and Visual C++ prerequisites, Extended Protection state, certificate expiry, disk headroom, DAG and database-copy health, hybrid state. We confirm your licensing position — Exchange SE needs a Server licence and client access licences under subscription or active Software Assurance — and retrieve the SE product keys per server edition, because a Standard key on a server carrying six databases is a problem to catch before the window, not after. We take Exchange-aware backups and export IIS configuration, certificates with private keys, custom web.config and OWA settings and connector configuration, and write down the rollback position for each server. Then the windows: internet-facing site first, one DAG member per window with active databases moved off and maintenance mode on, standalone servers in an agreed outage window, Edge Transport servers last with EdgeSync re-verified — each server validated and returned to service before the next starts. When every server is on SE we validate the organization end to end, close the issue log, and hand over the as-built, the licence and key record, the validation results and a one-page run book for the next cumulative update, because SE only stays supported if you keep installing them. Who this is for: mid-size and enterprise organizations that must keep Exchange on-premises — regulated data, data residency, application relay and integration, or a hybrid server that has to stay — from a two-member DAG to a multi-site deployment. Multi-DAG estates, several Exchange organizations and resource-forest topologies are quoted per estate. Who it is not for: Exchange 2016 has no in-place path — Microsoft's route is new SE servers and mailbox moves, which is Exchange 2016 to Exchange Server SE Migration; if your real destination is Exchange Online, do not pay to upgrade servers you are about to retire — see Hybrid Microsoft 365 Migration from your own Exchange Server or the Cutover Exchange Online Migration; and a last server kept only for recipient management may be better replaced by Microsoft's Exchange Management Tools model and then removed with Exchange Server Decommissioning. If you are not yet sure which of these applies, the one-week Exchange Server SE Upgrade Readiness Assessment gives you the written answer first; and if the upgrade cannot start immediately, Out-of-Support Exchange Server Risk Containment reduces the exposure in the meantime.

Success criteria

01Every in-scope server reports Exchange Server SE in Get-ExchangeServer and the Exchange admin center, with the SE product key applied and the edition — Standard or Enterprise — matching the server's licence and its mounted database count.
02No mailbox was moved and no database was rebuilt: server names, database names, connectors, virtual-directory URLs and certificates are unchanged, verified line by line against the pre-upgrade inventory.
03DAG members were upgraded one at a time behind maintenance mode; after each, every database copy shows Healthy, Test-ReplicationHealth passes, and active databases are back on their preferred servers — users kept working throughout.
04Mail flows inbound, outbound and internally through every connector, including Edge Transport where present, EdgeSync verifies, and transport queues are empty at handover.
05Outlook desktop (MAPI over HTTP), Outlook on the web, the Exchange admin center, Exchange Web Services (free/busy and out-of-office), ActiveSync and Autodiscover each pass a scripted test and a real-user check on every server.
06Hybrid, where present: cross-premises free/busy and mail flow work and a test mailbox move in each direction succeeds, with the Hybrid Configuration Wizard re-run where validation showed it was needed.
07Your customisations survived: the web.config, OWA and transport settings that Exchange setup resets are re-applied from the pre-upgrade export and checked, certificate bindings on IIS and SMTP are intact, and Extended Protection is in the intended state.
08HealthChecker runs clean of new findings on every upgraded server, the as-built, licence and key record and next-CU run book are in your hands, and you approve delivery.

What you receive

Readiness report per server: Exchange 2019 cumulative update and hotfix level, Windows Server version, .NET Framework and Visual C++ prerequisites, Extended Protection state, certificate inventory and expiry, disk headroom, DAG and database-copy health, hybrid status, and HealthChecker's findings — with the items that must be fixed before setup will succeed listed first.
Licensing and key confirmation: what Exchange SE requires (a Server licence and client access licences under subscription or active Software Assurance, or the cloud subscriptions that carry the CAL-equivalent rights), which of it you hold, and the SE product keys retrieved from your volume-licensing portal and matched to each server's edition before the first change window. If something is missing we say so before we touch a server; procurement is separate.
Prerequisite remediation on each in-scope server: the CU15 install where a server is below CU14 (one extra maintenance window for that server), the latest hotfix or security update, the prerequisite packages Microsoft lists for SE, and Active Directory schema and domain preparation where the target build requires it, run once from a designated server.
Backup and rollback package: an Exchange-aware backup of each server's databases and system state confirmed as restorable; exports of IIS configuration, certificates with private keys, custom web.config and OWA settings, transport and connector configuration and the Exchange setup logs; and a written rollback position per server — which for a DAG member means the other copies stay on the old build until that member is validated.
Upgrade sequence and change plan: order of sites and servers (internet-facing site first, one DAG member at a time, standalone servers in an agreed window, Edge Transport servers last with EdgeSync re-verified), the maintenance-mode steps, the load-balancer drain and re-add points, expected downtime per server, go/no-go checks, and the people on call for each window.
The upgrade itself, per server: maintenance mode and active-database moves off the member, Exchange SE setup in upgrade mode, reboot, SE product key applied and edition verified, customisations re-applied, the member returned to service, a database copy re-seeded if it fails to catch up, and active databases redistributed to their preferred servers.
Post-upgrade validation record per server against the success criteria: service health, mail flow (internal, inbound, outbound, Edge), Outlook, Outlook on the web and the admin center, EWS free/busy and out-of-office, ActiveSync, Autodiscover, MAPI over HTTP, certificate bindings on IIS and SMTP, Extended Protection, DAG replication health, hybrid checks where present, and a fresh HealthChecker report.
Issue log: everything found before, during and after each window, what was fixed within scope, and what was deferred with the reason and the recommended owner.
As-built documentation and handover: the SE build per server, the licence and key record, the configuration exports, the validation results, and a one-page run book for the next cumulative update, walked through with your administrators.

How the work unfolds

Days 1–2 — Kickoff and readiness

Kickoff with your Exchange, Active Directory, network and security owners. Read-only discovery of the organization — servers, versions, DAGs, databases, connectors, certificates, hybrid state — and HealthChecker on every server. The readiness report follows, blocking items first.

Days 2–4 — Licensing, keys and prerequisites

Confirm the SE licensing position and retrieve the product keys per server edition; agree the change windows and the on-call approver for each. Install CU15 and the latest hotfix on servers that are behind, the prerequisite packages, and Active Directory preparation where required; fix or escalate the blocking findings.

Days 4–5 — Backups, exports and the rollback position

Exchange-aware backups confirmed restorable; configuration, certificate and customisation exports taken; the load-balancer drain plan agreed with your network team; the rollback position written per server; go/no-go for the first window.

Days 5–9 — Upgrade windows

Servers upgraded in the agreed sequence: internet-facing site first, one DAG member per window behind maintenance mode with active databases moved off, standalone servers in their outage window, Edge Transport servers last. Each server is validated and returned to service before the next window starts; a failed validation stops the sequence, not your users.

Days 9–10 — Organization-wide validation

With every server on SE: end-to-end mail flow including hybrid, database redistribution, EdgeSync, certificate and Extended Protection review, HealthChecker on all servers, and the issue log closed or deferred in writing.

Day 10 — Documentation and handover

As-built, licence and key record, validation results and the next-CU run book walked through with your administrators; you approve delivery. A typical single-DAG deployment fits in about 2 weeks; more members or more sites extend the calendar at the same per-server price, and the quote states the real dates.

Prerequisites

Exchange Server 2019 — not 2016 — on every in-scope server, in one Exchange organization. Servers below CU14 are brought to CU15 as part of this engagement (one extra window each); Exchange 2016 servers have no in-place path and are a separate engagement.
Windows Server 2019 or later on each server (a requirement of Exchange 2019 itself), in a supported and patched state. The operating system is not changed in this engagement: Microsoft does not support upgrading Windows underneath an installed Exchange server.
Exchange SE licensing in place or in procurement — a Server licence and client access licences under subscription or active Software Assurance, or cloud subscriptions that carry the CAL-equivalent rights — and the SE product keys available from your volume-licensing portal before the first change window. Microsoft Volume Licensing if you want the licences quoted through us.
A working, Exchange-aware backup of each server that you can restore from, verified before the first window. If you have none, Azure Backup for physical or virtual servers can be set up first.
Healthy Active Directory: the domain controllers and global catalogs the Exchange servers use are reachable and replicating, and an account with Schema Admins and Enterprise Admins rights is available for AD preparation if the build requires it. For IT Partner: Organization Management in Exchange and local administrator on each server, granted before kickoff and removable by you at the end.
DAG health as a starting point: every database copy Healthy, no long-running reseeds, a reachable witness server, and enough passive copies that each member can be taken out of service one at a time. Copies in a failed state are fixed first or scoped as extra work before the sequence starts.
Agreed maintenance windows and a named person on your side who can approve go/no-go for each: no user impact for DAG members done one at a time; an outage of roughly the setup-and-reboot time for a standalone server.
Your network team available to drain and re-add servers on the load balancer and to make firewall or DNS changes a validation step needs; hybrid estates need a Microsoft 365 Global or Exchange Administrator available for the hybrid checks.
Disclosure of customisations and integrations before the first window: custom web.config or OWA changes, transport rules and agents, third-party backup, antivirus, archiving and signature agents, and SMTP relay from applications and devices — so each is exported, re-applied and re-tested rather than discovered.

Who does what

IT Partner

  • Run the kickoff, the discovery and HealthChecker pass, and deliver the readiness report.
  • Confirm the licensing position, retrieve and record the SE product keys per server edition, and not start a window until they are in hand.
  • Install the prerequisite CU, hotfix and packages, run Active Directory preparation where required, and fix blocking findings within scope.
  • Take and verify the backups and configuration exports, and write the rollback position per server.
  • Execute each upgrade window: maintenance mode, database moves, SE setup, product key, customisations, return to service, replication health and redistribution.
  • Validate each server and then the whole organization against the success criteria, keep the issue log, and re-run the Hybrid Configuration Wizard where validation shows it is needed.
  • Deliver the as-built, licence and key record, validation results and next-CU run book, and walk your administrators through them.

Your team

  • Own the licensing: buy or renew the Exchange SE Server licence, client access licences or the qualifying subscriptions, and give us access to the volume-licensing portal or the keys themselves. Microsoft's licence charges are yours and are never part of this fee.
  • Provide the administrative accounts, the change windows and a named on-call approver for each window, and raise change tickets in your own process.
  • Drain and re-add servers on load balancers, and make the firewall or DNS changes we identify, with your network team.
  • Keep the server hardware, hypervisor and Windows Server in a supported, patched state before and after the engagement.
  • Disclose customisations, integrations and third-party agents before the first window, and make application owners available to re-test relay and integrations.
  • Confirm the restorability of your backup platform where we cannot; the backup platform itself is yours.
  • Review each server's validation record and the final deliverables and approve delivery, or report defects, within the schedule.

What's not included

Exchange 2016 servers. Microsoft offers no in-place upgrade from Exchange 2016; the supported route is new Exchange SE servers followed by mailbox, public-folder and connector moves — Exchange 2016 to Exchange Server SE Migration.
Windows Server upgrades, new server builds, hardware or hypervisor changes. Microsoft does not support upgrading the operating system under an installed Exchange server, so moving Exchange SE onto Windows Server 2022 or 2025 is a new-server build with mailbox moves, quoted separately. For the other servers in your estate that can take an in-place operating-system upgrade, see the Windows Server 2016 to 2025 Upgrade Service.
Migration to Exchange Online — mailboxes, public folders, archives or mail flow. That is Hybrid Microsoft 365 Migration from your own Exchange Server or the Cutover Exchange Online Migration; retiring the last server afterwards is Exchange Server Decommissioning.
Ongoing patching and operations after handover — the SE cumulative updates and security updates that keep SE supported, monitoring, HealthChecker on a schedule — are Managed Exchange Server SE Administration and Patching. Customers who buy their Microsoft licensing through IT Partner get break-fix support during business hours at no extra charge; see Microsoft 365 Break/Fix Support. Hourly Exchange administration by the same team is Exchange Online Administrator on Demand.
Exchange SE licences, client access licences, Software Assurance or subscriptions, and Microsoft support cases — Microsoft's charges, bought through your licensing channel; Microsoft Volume Licensing if you want them quoted through us. Escalation to Microsoft under our Premier Support agreement is available as a paid add-on where a case needs it.
Fixing what the readiness pass finds outside Exchange: failed Active Directory replication, expired or mis-issued certificates, storage or hypervisor faults, load-balancer or firewall misconfiguration. We report each with the fix; remediation is quoted or done by your team. Active Directory itself is Active Directory Security Assessment and Hardening.
Re-architecture: adding or removing DAG members, changing database layouts, introducing a new site, replacing the load balancer, or deploying Edge Transport where none exists.
Security hardening beyond the upgrade — Extended Protection redesign, TLS policy, receive-connector lockdown, email authentication — unless a finding blocks setup. DMARC, DKIM and SPF Email Authentication Implementation covers the sending-domain side.
Third-party products on the Exchange servers — backup agents, antivirus, archiving, journaling, signature and relay tools — are re-tested after the upgrade, but their reinstallation, upgrades and vendor support are the vendor's and yours.
Change windows outside business hours are normal for this work and are scheduled at kickoff; windows re-scheduled at short notice, emergency windows and on-site presence are quoted separately.

Limitations & technical notes

!Microsoft supports the in-place upgrade to Exchange SE only from Exchange 2019 CU14 or CU15. Servers on older cumulative updates take CU15 first, and Exchange 2016 servers cannot be upgraded in place at all.
!Exchange Server 2019 and Exchange Server 2016 left support on 14 October 2025, per Microsoft's product lifecycle. Servers still on 2019 receive no security updates; upgrading to SE is what restores them.
!Microsoft has stated that Exchange SE Cumulative Update 2 will not install while Exchange 2016 or 2019 servers remain in the organization, and originally scheduled it for the second half of 2026. As of Microsoft's August 2026 update, CU1 had not shipped and had no date, so neither did CU2: the coexistence window is open and closes on Microsoft's schedule. This page is re-checked at each review cycle.
!Exchange SE follows Microsoft's Modern Lifecycle Policy: there is no fixed end-of-support date, but support depends on staying current with cumulative updates. The upgrade buys supportability; keeping it is an operations commitment, which is why we hand over a next-CU run book and offer Managed Exchange Server SE Administration and Patching separately.
!Product keys and licences: Microsoft issues Exchange SE product keys separately from Exchange 2019 keys, and a server left without an SE key runs unlicensed. The key also sets the edition — Standard or Enterprise, with different mounted-database limits — so it must match the server. Licensing requires a Server licence and client access licences under subscription or active Software Assurance; users covered by cloud subscriptions such as Microsoft 365 E3 or E5 usually hold the CAL-equivalent rights under Microsoft's Product Terms. We confirm your position rather than assume it, and we do not start a window without the keys.
!Downtime: DAG members are upgraded one at a time with active databases moved off first, so users on a healthy DAG stay online. A standalone server is unavailable to its users for the length of setup and reboot — typically an hour or two — in a window agreed with you. Setup time varies with hardware and database count; we plan windows with margin rather than promise minutes.
!Rollback: there is no uninstall for a cumulative-update-style Exchange upgrade. The rollback position is a restore from the verified backup (standalone) or the remaining DAG members on the old build (DAG), and it is written down before each window. That is why backup verification is a prerequisite, not a courtesy.
!Exchange setup resets customised web.config settings, OWA customisations and some IIS settings; we export and re-apply the ones you disclose. Undisclosed customisations found afterwards are re-applied at the hourly rate.
!Hybrid: Exchange SE is supported for hybrid with Exchange Online. Where validation shows the hybrid configuration needs it, the Hybrid Configuration Wizard is re-run within scope; hybrid redesign, new hybrid deployments and identity changes are not.
!The $1,250 per server plus $1,950 flat fee is fixed for one Exchange organization with one DAG (of any member count), with standalone and Edge Transport servers counted as servers, and about two weeks of calendar for a typical single-DAG deployment. Multi-DAG estates, several Exchange organizations, resource-forest topologies and estates where the readiness pass finds work outside scope are quoted per estate in writing before anything starts.
!Technical content reviewed September 2026.

Frequently asked questions

Can Exchange 2019 be upgraded in place to Exchange Server SE?

Yes — if the server is on Exchange 2019 CU14 or CU15. Microsoft supports the in-place upgrade from those two builds only and describes it as identical to installing a cumulative update, because Exchange SE RTM is code-equivalent to Exchange 2019 CU15 with the May 2025 hotfix. Setup runs in upgrade mode; the server keeps its name, databases, connectors, certificates and DAG membership, and what changes is the licence agreement, the version and the product key. A server on CU13 or older takes CU15 first, which we include with one extra window. Exchange 2016 has no in-place path at all.

What does the engagement include?

Per server: the readiness pass with HealthChecker, the prerequisite CU15 and hotfix where needed, Exchange-aware backups and configuration exports with a written rollback position, the upgrade window itself (maintenance mode and database moves for DAG members, SE setup, product key and edition check, customisations re-applied, return to service), and a validation record covering mail flow, Outlook, Outlook on the web, EWS, ActiveSync, Autodiscover, certificates, Extended Protection, replication health and hybrid where present. Per organization: the licensing and key confirmation, the sequence and change plan, Active Directory preparation where required, organization-wide validation, the issue log, and the as-built with a next-CU run book.

How much does it cost?

$1,250 per server plus a $1,950 flat fee per Exchange organization — the tenant fee on our quote — fixed and quoted in writing before work begins; you pay after you approve delivery. A two-member DAG with one Edge Transport server is three servers: $3,750 plus $1,950, or $5,700. A four-member DAG is $6,950. Standalone and Edge Transport servers count as servers. Multi-DAG estates and several Exchange organizations are quoted per estate. Exchange SE licences, client access licences and Software Assurance are Microsoft's charges through your licensing channel, not part of this fee.

How long does it take, and will users notice?

About 2 weeks for a typical single-DAG deployment: readiness and licensing in the first days, prerequisites and backups next, then the upgrade windows one server at a time, then organization-wide validation and handover. On a healthy DAG users do not notice: active databases are moved off each member before it is upgraded and back afterwards. A standalone server is unavailable to its users for the length of setup and reboot — typically an hour or two — in a window you agree. Larger member counts or more sites extend the calendar at the same per-server price, and the quote states the real dates.

It is only a CU. Why not run SE setup ourselves?

You can, and for a single well-maintained server many administrators do. Where it goes wrong is the same places a cumulative update goes wrong, plus the SE specifics: setup fails late on a prerequisite nobody checked; a DAG member is upgraded with active copies still on it; the SE key is not in hand, or is a Standard key on a server with more databases than Standard allows; web.config and OWA customisations vanish because setup rewrote them; Extended Protection and a load balancer doing SSL offloading stop talking; hybrid free/busy breaks and nobody tests it until Monday. Our value is the sequence, the backups and rollback position, the validation record per server, and the documentation — the parts that turn a setup into a controlled change your auditors and your successors can read.

What is the CU2 deadline everyone mentions?

Microsoft has said that Exchange SE Cumulative Update 2 will only coexist with other SE servers: it will not install while Exchange 2016 or 2019 servers remain in the organization, so the side-by-side migration window closes when it ships. Microsoft's original plan put CU2 in the second half of 2026; CU1, which still allows coexistence, was delayed several times and as of Microsoft's August 2026 update had no release date, so CU2 has none either. The practical reading: the window is open now and closes on Microsoft's schedule with the lead time of a release note. We re-check this page at each review cycle, and we would rather you upgrade while the door is open than plan around a date nobody has. If the upgrade genuinely cannot start yet, Out-of-Support Exchange Server Risk Containment reduces the exposure of the 2019 servers in the meantime.

What licences and product keys do we need?

Exchange SE is licensed the way SharePoint Server SE is: a Server licence and client access licences, each under either a subscription licence or a licence with active Software Assurance. Users covered by cloud subscriptions such as Microsoft 365 E3 or E5 usually hold the CAL-equivalent rights under Microsoft's Product Terms; the Server licence is still needed. Microsoft issues Exchange SE product keys separately from Exchange 2019 keys, you retrieve them from your volume-licensing portal, and the key sets the edition — Standard or Enterprise, with different mounted-database limits — so it must match the server. We confirm all of this in the first days and do not start a window without the keys. If you need the licences quoted, Microsoft Volume Licensing is where we do that.

We are on Exchange 2019 CU13 or older. Does that matter?

It adds a step, not a project. Microsoft supports the in-place upgrade only from CU14 or CU15, so a server on an older cumulative update takes CU15 first — a full cumulative-update install with its own maintenance window, which we include for that server — and then the SE upgrade. Because Exchange 2019 is out of support, the CU15 media and hotfix are the last 2019 builds Microsoft published; we confirm they are still downloadable and that their prerequisites are met before we schedule anything.

We run Exchange 2016. Can you upgrade it in place?

No — nobody can. Microsoft offers no in-place upgrade from Exchange 2016 to SE; the supported route is to install new Exchange SE servers into the organization, move mailboxes, public folders and connectors, and then decommission the 2016 servers, and CU2 will eventually require that the 2016 servers are gone. That is Exchange 2016 to Exchange Server SE Migration. If your destination is really Exchange Online rather than another on-premises generation, Hybrid Microsoft 365 Migration from your own Exchange Server is usually the better use of the same effort.

Our servers are on Windows Server 2019. Should we move to Windows Server 2025 at the same time?

Not in this engagement, and not in place. Microsoft does not support upgrading the operating system underneath an installed Exchange server, so a newer Windows Server means a new server build with mailbox moves — the same shape of work as a 2016-to-SE migration. Exchange SE runs on the Windows Server versions Microsoft lists for it, which include 2019, and Windows Server 2019 is in extended support until January 2029 per Microsoft's product lifecycle, so the in-place SE upgrade on your existing hosts is a supported, in-support outcome. If you want SE on Windows Server 2025 as well, we quote that as a separate new-server project.

We are hybrid with Exchange Online. What changes?

Exchange SE is supported for hybrid, and the in-place upgrade keeps the hybrid configuration on the server. We record the hybrid state at readiness, validate cross-premises free/busy and mail flow and run a test mailbox move in each direction after the upgrade, and re-run the current Hybrid Configuration Wizard if validation shows it is needed — that is in scope. If the server exists only to manage recipients for synchronized users, we tell you at readiness whether Microsoft's Exchange Management Tools model would let you retire it instead of licensing SE for it; that decision, and the decommissioning, are separate engagements.

What happens to our DAG during the upgrade?

One member at a time, the way Microsoft's own cumulative-update guidance describes: the member is drained on the load balancer, put into maintenance mode with Microsoft's StartDagServerMaintenance script or the equivalent manual steps, active databases are moved to other members, setup runs, the server reboots, the member is taken out of maintenance mode, every database copy is checked to Healthy with Test-ReplicationHealth, and active databases are redistributed to their preferred servers before the next member is touched. A copy that fails to catch up is re-seeded. The remaining members stay on the old build until the upgraded one is validated, which is the DAG's built-in rollback position.

What can go wrong, and what is the rollback?

The realistic failures are a setup that stops on a prerequisite or a stuck service (setup can usually be re-run once the cause is fixed, and Microsoft's SetupAssist script diagnoses most of them), a product key that is missing or the wrong edition, certificate bindings or customisations that setup reset, Extended Protection conflicts with a load balancer, and a database copy that does not catch up. Each has a known fix and is on our validation list. The rollback position is written before each window: for a DAG member, the other members are still on the old build and hold the active databases; for a standalone server, it is the verified Exchange-aware backup, because a cumulative-update-style upgrade has no uninstall. We do not open a window without both the backup and that written position.

What happens after handover?

Exchange SE stays supported only if you keep installing its cumulative updates and security updates, so you leave with a one-page run book for the next one, the as-built, and the validation results to compare against. Ongoing patching, monitoring and scheduled HealthChecker runs are Managed Exchange Server SE Administration and Patching, priced per server. Customers who buy their Microsoft licensing through IT Partner get break-fix support during business hours at no extra charge through Microsoft 365 Break/Fix Support; hourly administration by the same team is Exchange Online Administrator on Demand; and when the last server finally goes, Exchange Server Decommissioning removes it cleanly.

Do we need the readiness assessment before this upgrade?

Not as a rule. This engagement includes its own readiness pass in the first two days — HealthChecker on every server, the licensing and key check, the DAG and hybrid state — and it is scoped for organizations that already know SE on the existing servers is the destination. The Exchange Server SE Upgrade Readiness Assessment is the right first step when that decision is still open: 2016 and 2019 servers mixed, a hybrid server whose future is undecided, hosts you would rather rebuild, or a board that wants the options and costs in writing before committing. If you have done it, its report replaces our discovery and feeds the sequence directly; the per-server price is unchanged.

Who owns this service at IT Partner?

Mike Mackey, IT Partner's founder, is the named owner of this service and your escalation point during the change windows. Every window is run by an engineer working from the written sequence and rollback position, with go/no-go agreed with your named approver — and where a Microsoft case is needed, escalation under our Premier Support agreement is available as a paid add-on.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$1,250 per server + $1,950 tenant fee
2 weeks
Get a fixed-price upgrade quote