Exchange 2019 to Exchange Server SE In-Place Upgrade
Exchange 2019 to Exchange Server SE In-Place Upgrade moves each of your Exchange Server 2019 servers to Exchange Server Subscription Edition (SE) — the only on-premises Exchange release Microsoft still supports, now that Exchange 2019 left support on 14 October 2025 per Microsoft's product lifecycle — without new servers and without moving a mailbox. Microsoft supports the in-place upgrade only from Exchange 2019 CU14 or CU15 and describes it as identical to installing a cumulative update, so IT Partner's work is the discipline around that setup: a HealthChecker readiness pass on every server, the prerequisite CU15 and hotfix where a server is behind, your SE licensing confirmed and the SE product keys in hand before any change window, Exchange-aware backups with a written rollback position, DAG-aware sequencing that moves active databases off each member before it is upgraded so users stay online, Edge Transport servers in the same plan, the SE key applied and the edition verified, and a validation record per server — mail flow, Outlook, Outlook on the web, EWS and free/busy, ActiveSync, Autodiscover, certificates, hybrid where you have it, and HealthChecker again — before the as-built and a next-CU run book are handed over. $1,250 per server plus a $1,950 flat fee per Exchange organization (the tenant fee on our quote), fixed and quoted in writing before work begins; you pay after you approve delivery. About 2 weeks for a typical single-DAG deployment. Not included: Exchange 2016 sources (there is no in-place path from 2016), Windows Server or hardware changes, migration to Exchange Online, and patching after handover — each named below with where it belongs.
What this engagement is
Exchange Server 2019 left support on 14 October 2025, per Microsoft's product lifecycle — no more security updates, no more support cases, and, unlike Windows Server, no multi-year Extended Security Update bridge to buy time with. The supported on-premises release is Exchange Server Subscription Edition (SE), which Microsoft released in July 2025. Microsoft has also said that SE Cumulative Update 2 will refuse to install while Exchange 2016 or 2019 servers remain in the organization, and originally planned it for the second half of 2026; as of Microsoft's August 2026 update, CU1 had not shipped and had no date, so the side-by-side window is open today and closes on Microsoft's schedule with the lead time of a release note. An Exchange 2019 estate that is not on SE is unpatched now and will be unable to take the next cumulative updates once CU2 ships. The good news for 2019 estates is that this is an upgrade, not a migration. Exchange SE RTM is code-equivalent to Exchange 2019 CU15 with the May 2025 hotfix, and Microsoft supports an in-place upgrade from Exchange 2019 CU14 or CU15 that it describes as identical to installing a cumulative update: setup runs in upgrade mode, and the server keeps its name, databases, connectors, certificates and DAG membership. What changes is the licence agreement, the product name and version, and the product key — Microsoft issues Exchange SE keys separately from Exchange 2019 keys, and a server left without an SE key runs unlicensed. What does not change is everything that makes an Exchange cumulative update a controlled event rather than a Tuesday-night setup: prerequisites that fail late if nobody checked them, Active Directory preparation where the build requires it, one DAG member at a time behind maintenance mode, customised web.config and OWA settings that setup silently overwrites, Extended Protection that a load balancer doing SSL offloading breaks, and a validation list nobody should run from memory. IT Partner runs it as an engineering project. Before anything changes we run Microsoft's HealthChecker script on every server and read the organization as it is: cumulative update and hotfix level, Windows Server version, .NET Framework and Visual C++ prerequisites, Extended Protection state, certificate expiry, disk headroom, DAG and database-copy health, hybrid state. We confirm your licensing position — Exchange SE needs a Server licence and client access licences under subscription or active Software Assurance — and retrieve the SE product keys per server edition, because a Standard key on a server carrying six databases is a problem to catch before the window, not after. We take Exchange-aware backups and export IIS configuration, certificates with private keys, custom web.config and OWA settings and connector configuration, and write down the rollback position for each server. Then the windows: internet-facing site first, one DAG member per window with active databases moved off and maintenance mode on, standalone servers in an agreed outage window, Edge Transport servers last with EdgeSync re-verified — each server validated and returned to service before the next starts. When every server is on SE we validate the organization end to end, close the issue log, and hand over the as-built, the licence and key record, the validation results and a one-page run book for the next cumulative update, because SE only stays supported if you keep installing them. Who this is for: mid-size and enterprise organizations that must keep Exchange on-premises — regulated data, data residency, application relay and integration, or a hybrid server that has to stay — from a two-member DAG to a multi-site deployment. Multi-DAG estates, several Exchange organizations and resource-forest topologies are quoted per estate. Who it is not for: Exchange 2016 has no in-place path — Microsoft's route is new SE servers and mailbox moves, which is Exchange 2016 to Exchange Server SE Migration; if your real destination is Exchange Online, do not pay to upgrade servers you are about to retire — see Hybrid Microsoft 365 Migration from your own Exchange Server or the Cutover Exchange Online Migration; and a last server kept only for recipient management may be better replaced by Microsoft's Exchange Management Tools model and then removed with Exchange Server Decommissioning. If you are not yet sure which of these applies, the one-week Exchange Server SE Upgrade Readiness Assessment gives you the written answer first; and if the upgrade cannot start immediately, Out-of-Support Exchange Server Risk Containment reduces the exposure in the meantime.
Success criteria
What you receive
How the work unfolds
Kickoff with your Exchange, Active Directory, network and security owners. Read-only discovery of the organization — servers, versions, DAGs, databases, connectors, certificates, hybrid state — and HealthChecker on every server. The readiness report follows, blocking items first.
Confirm the SE licensing position and retrieve the product keys per server edition; agree the change windows and the on-call approver for each. Install CU15 and the latest hotfix on servers that are behind, the prerequisite packages, and Active Directory preparation where required; fix or escalate the blocking findings.
Exchange-aware backups confirmed restorable; configuration, certificate and customisation exports taken; the load-balancer drain plan agreed with your network team; the rollback position written per server; go/no-go for the first window.
Servers upgraded in the agreed sequence: internet-facing site first, one DAG member per window behind maintenance mode with active databases moved off, standalone servers in their outage window, Edge Transport servers last. Each server is validated and returned to service before the next window starts; a failed validation stops the sequence, not your users.
With every server on SE: end-to-end mail flow including hybrid, database redistribution, EdgeSync, certificate and Extended Protection review, HealthChecker on all servers, and the issue log closed or deferred in writing.
As-built, licence and key record, validation results and the next-CU run book walked through with your administrators; you approve delivery. A typical single-DAG deployment fits in about 2 weeks; more members or more sites extend the calendar at the same per-server price, and the quote states the real dates.
Prerequisites
Who does what
IT Partner
- Run the kickoff, the discovery and HealthChecker pass, and deliver the readiness report.
- Confirm the licensing position, retrieve and record the SE product keys per server edition, and not start a window until they are in hand.
- Install the prerequisite CU, hotfix and packages, run Active Directory preparation where required, and fix blocking findings within scope.
- Take and verify the backups and configuration exports, and write the rollback position per server.
- Execute each upgrade window: maintenance mode, database moves, SE setup, product key, customisations, return to service, replication health and redistribution.
- Validate each server and then the whole organization against the success criteria, keep the issue log, and re-run the Hybrid Configuration Wizard where validation shows it is needed.
- Deliver the as-built, licence and key record, validation results and next-CU run book, and walk your administrators through them.
Your team
- Own the licensing: buy or renew the Exchange SE Server licence, client access licences or the qualifying subscriptions, and give us access to the volume-licensing portal or the keys themselves. Microsoft's licence charges are yours and are never part of this fee.
- Provide the administrative accounts, the change windows and a named on-call approver for each window, and raise change tickets in your own process.
- Drain and re-add servers on load balancers, and make the firewall or DNS changes we identify, with your network team.
- Keep the server hardware, hypervisor and Windows Server in a supported, patched state before and after the engagement.
- Disclose customisations, integrations and third-party agents before the first window, and make application owners available to re-test relay and integrations.
- Confirm the restorability of your backup platform where we cannot; the backup platform itself is yours.
- Review each server's validation record and the final deliverables and approve delivery, or report defects, within the schedule.
What's not included
Limitations & technical notes
Frequently asked questions
Can Exchange 2019 be upgraded in place to Exchange Server SE?
Yes — if the server is on Exchange 2019 CU14 or CU15. Microsoft supports the in-place upgrade from those two builds only and describes it as identical to installing a cumulative update, because Exchange SE RTM is code-equivalent to Exchange 2019 CU15 with the May 2025 hotfix. Setup runs in upgrade mode; the server keeps its name, databases, connectors, certificates and DAG membership, and what changes is the licence agreement, the version and the product key. A server on CU13 or older takes CU15 first, which we include with one extra window. Exchange 2016 has no in-place path at all.
What does the engagement include?
Per server: the readiness pass with HealthChecker, the prerequisite CU15 and hotfix where needed, Exchange-aware backups and configuration exports with a written rollback position, the upgrade window itself (maintenance mode and database moves for DAG members, SE setup, product key and edition check, customisations re-applied, return to service), and a validation record covering mail flow, Outlook, Outlook on the web, EWS, ActiveSync, Autodiscover, certificates, Extended Protection, replication health and hybrid where present. Per organization: the licensing and key confirmation, the sequence and change plan, Active Directory preparation where required, organization-wide validation, the issue log, and the as-built with a next-CU run book.
How much does it cost?
$1,250 per server plus a $1,950 flat fee per Exchange organization — the tenant fee on our quote — fixed and quoted in writing before work begins; you pay after you approve delivery. A two-member DAG with one Edge Transport server is three servers: $3,750 plus $1,950, or $5,700. A four-member DAG is $6,950. Standalone and Edge Transport servers count as servers. Multi-DAG estates and several Exchange organizations are quoted per estate. Exchange SE licences, client access licences and Software Assurance are Microsoft's charges through your licensing channel, not part of this fee.
How long does it take, and will users notice?
About 2 weeks for a typical single-DAG deployment: readiness and licensing in the first days, prerequisites and backups next, then the upgrade windows one server at a time, then organization-wide validation and handover. On a healthy DAG users do not notice: active databases are moved off each member before it is upgraded and back afterwards. A standalone server is unavailable to its users for the length of setup and reboot — typically an hour or two — in a window you agree. Larger member counts or more sites extend the calendar at the same per-server price, and the quote states the real dates.
It is only a CU. Why not run SE setup ourselves?
You can, and for a single well-maintained server many administrators do. Where it goes wrong is the same places a cumulative update goes wrong, plus the SE specifics: setup fails late on a prerequisite nobody checked; a DAG member is upgraded with active copies still on it; the SE key is not in hand, or is a Standard key on a server with more databases than Standard allows; web.config and OWA customisations vanish because setup rewrote them; Extended Protection and a load balancer doing SSL offloading stop talking; hybrid free/busy breaks and nobody tests it until Monday. Our value is the sequence, the backups and rollback position, the validation record per server, and the documentation — the parts that turn a setup into a controlled change your auditors and your successors can read.
What is the CU2 deadline everyone mentions?
Microsoft has said that Exchange SE Cumulative Update 2 will only coexist with other SE servers: it will not install while Exchange 2016 or 2019 servers remain in the organization, so the side-by-side migration window closes when it ships. Microsoft's original plan put CU2 in the second half of 2026; CU1, which still allows coexistence, was delayed several times and as of Microsoft's August 2026 update had no release date, so CU2 has none either. The practical reading: the window is open now and closes on Microsoft's schedule with the lead time of a release note. We re-check this page at each review cycle, and we would rather you upgrade while the door is open than plan around a date nobody has. If the upgrade genuinely cannot start yet, Out-of-Support Exchange Server Risk Containment reduces the exposure of the 2019 servers in the meantime.
What licences and product keys do we need?
Exchange SE is licensed the way SharePoint Server SE is: a Server licence and client access licences, each under either a subscription licence or a licence with active Software Assurance. Users covered by cloud subscriptions such as Microsoft 365 E3 or E5 usually hold the CAL-equivalent rights under Microsoft's Product Terms; the Server licence is still needed. Microsoft issues Exchange SE product keys separately from Exchange 2019 keys, you retrieve them from your volume-licensing portal, and the key sets the edition — Standard or Enterprise, with different mounted-database limits — so it must match the server. We confirm all of this in the first days and do not start a window without the keys. If you need the licences quoted, Microsoft Volume Licensing is where we do that.
We are on Exchange 2019 CU13 or older. Does that matter?
It adds a step, not a project. Microsoft supports the in-place upgrade only from CU14 or CU15, so a server on an older cumulative update takes CU15 first — a full cumulative-update install with its own maintenance window, which we include for that server — and then the SE upgrade. Because Exchange 2019 is out of support, the CU15 media and hotfix are the last 2019 builds Microsoft published; we confirm they are still downloadable and that their prerequisites are met before we schedule anything.
We run Exchange 2016. Can you upgrade it in place?
No — nobody can. Microsoft offers no in-place upgrade from Exchange 2016 to SE; the supported route is to install new Exchange SE servers into the organization, move mailboxes, public folders and connectors, and then decommission the 2016 servers, and CU2 will eventually require that the 2016 servers are gone. That is Exchange 2016 to Exchange Server SE Migration. If your destination is really Exchange Online rather than another on-premises generation, Hybrid Microsoft 365 Migration from your own Exchange Server is usually the better use of the same effort.
Our servers are on Windows Server 2019. Should we move to Windows Server 2025 at the same time?
Not in this engagement, and not in place. Microsoft does not support upgrading the operating system underneath an installed Exchange server, so a newer Windows Server means a new server build with mailbox moves — the same shape of work as a 2016-to-SE migration. Exchange SE runs on the Windows Server versions Microsoft lists for it, which include 2019, and Windows Server 2019 is in extended support until January 2029 per Microsoft's product lifecycle, so the in-place SE upgrade on your existing hosts is a supported, in-support outcome. If you want SE on Windows Server 2025 as well, we quote that as a separate new-server project.
We are hybrid with Exchange Online. What changes?
Exchange SE is supported for hybrid, and the in-place upgrade keeps the hybrid configuration on the server. We record the hybrid state at readiness, validate cross-premises free/busy and mail flow and run a test mailbox move in each direction after the upgrade, and re-run the current Hybrid Configuration Wizard if validation shows it is needed — that is in scope. If the server exists only to manage recipients for synchronized users, we tell you at readiness whether Microsoft's Exchange Management Tools model would let you retire it instead of licensing SE for it; that decision, and the decommissioning, are separate engagements.
What happens to our DAG during the upgrade?
One member at a time, the way Microsoft's own cumulative-update guidance describes: the member is drained on the load balancer, put into maintenance mode with Microsoft's StartDagServerMaintenance script or the equivalent manual steps, active databases are moved to other members, setup runs, the server reboots, the member is taken out of maintenance mode, every database copy is checked to Healthy with Test-ReplicationHealth, and active databases are redistributed to their preferred servers before the next member is touched. A copy that fails to catch up is re-seeded. The remaining members stay on the old build until the upgraded one is validated, which is the DAG's built-in rollback position.
What can go wrong, and what is the rollback?
The realistic failures are a setup that stops on a prerequisite or a stuck service (setup can usually be re-run once the cause is fixed, and Microsoft's SetupAssist script diagnoses most of them), a product key that is missing or the wrong edition, certificate bindings or customisations that setup reset, Extended Protection conflicts with a load balancer, and a database copy that does not catch up. Each has a known fix and is on our validation list. The rollback position is written before each window: for a DAG member, the other members are still on the old build and hold the active databases; for a standalone server, it is the verified Exchange-aware backup, because a cumulative-update-style upgrade has no uninstall. We do not open a window without both the backup and that written position.
What happens after handover?
Exchange SE stays supported only if you keep installing its cumulative updates and security updates, so you leave with a one-page run book for the next one, the as-built, and the validation results to compare against. Ongoing patching, monitoring and scheduled HealthChecker runs are Managed Exchange Server SE Administration and Patching, priced per server. Customers who buy their Microsoft licensing through IT Partner get break-fix support during business hours at no extra charge through Microsoft 365 Break/Fix Support; hourly administration by the same team is Exchange Online Administrator on Demand; and when the last server finally goes, Exchange Server Decommissioning removes it cleanly.
Do we need the readiness assessment before this upgrade?
Not as a rule. This engagement includes its own readiness pass in the first two days — HealthChecker on every server, the licensing and key check, the DAG and hybrid state — and it is scoped for organizations that already know SE on the existing servers is the destination. The Exchange Server SE Upgrade Readiness Assessment is the right first step when that decision is still open: 2016 and 2019 servers mixed, a hybrid server whose future is undecided, hosts you would rather rebuild, or a board that wants the options and costs in writing before committing. If you have done it, its report replaces our discovery and feeds the sequence directly; the per-server price is unchanged.
Who owns this service at IT Partner?
Mike Mackey, IT Partner's founder, is the named owner of this service and your escalation point during the change windows. Every window is run by an engineer working from the written sequence and rollback position, with go/no-go agreed with your named approver — and where a Microsoft case is needed, escalation under our Premier Support agreement is available as a paid add-on.