First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/Exchange Server SE Upgrade Readiness Assessment
AssessmentConsulting

Exchange Server SE Upgrade Readiness Assessment

A fixed-fee, one-week, read-only readiness assessment for organizations that must keep Exchange Server on-premises and need to get from Exchange 2016 or 2019 — both out of support since 14 October 2025, per Microsoft's product lifecycle — onto Exchange Server Subscription Edition (SE) before Microsoft closes the coexistence window. We inventory every server's version, cumulative update and security-update level; decide per server whether it qualifies for the in-place upgrade (Exchange 2019 at CU14 or CU15 only) or needs a new SE server (every Exchange 2016 server); confirm the licensing you will need — SE has no perpetual licence and requires an active subscription or Software Assurance on server licences and CALs; check the Windows Server, Active Directory, certificate, hybrid and third-party dependencies that break upgrades; and hand you a dated plan with a fixed written quote for the execution. $1,950 fixed, for up to four Exchange servers. If your real destination is Exchange Online, this is not your page — see the [hybrid](/services/hybrid-microsoft-365-migration-exchange-server) or [cutover](/services/cutover-exchange-online-migration) migration instead.

Timeline 1 weekService owner Mike MackeyExchange ServerExchange Server Subscription EditionWindows Server

What this engagement is

Most organizations still running Exchange Server on-premises in 2026 are doing so on purpose: a regulator or contract that keeps mail data inside your own perimeter, an air-gapped or government-adjacent network, an identity design that leans on on-premises Active Directory, or a hybrid estate where the last Exchange server is still doing real work. This assessment is for those organizations — mid-size to enterprise estates, not a ten-seat office with one server in a closet. It is deliberately not for organizations whose real destination is Exchange Online; that is a different engagement, and we link to it rather than pretend this page covers it. The clock is Microsoft's. Exchange Server 2016 and Exchange Server 2019 both left support on 14 October 2025, per Microsoft's product lifecycle. Their successor, Exchange Server Subscription Edition (SE), shipped in July 2025 and is now the only on-premises Exchange Microsoft supports. Two Microsoft mechanisms turn that from a policy into a problem with a date on it. The first is coexistence: SE RTM and SE CU1 can run alongside Exchange 2016 and 2019 while you migrate, but Microsoft has stated that SE CU2 — which Microsoft's published plan places in the second half of calendar 2026 — will block coexistence with every earlier version. An organization that has not finished the move when CU2 becomes the required baseline cannot install it, and is therefore locked out of the security updates that follow it. The second is mail flow: since February 2025, Exchange Online's transport enforcement has reported on, then throttled, then blocked mail from on-premises Exchange servers that are significantly out of date — every version, 2019 included — and Microsoft has announced that from the second week of September 2026 the oldest build it accepts from an Exchange 2016 or 2019 server over an on-premises inbound connector rises to the final public update of October 2025. If you are hybrid and behind on updates, the throttling appears in your mail flow report before anyone notices delayed mail. Over one week we take a read-only inventory of your Exchange organization, plan the upgrade to Exchange SE, and answer, in writing, five questions: 1. Which servers can take the in-place upgrade to SE — only Exchange 2019 at CU14 or CU15 qualifies, on a Windows Server version SE supports — and which must be replaced by new SE servers. That is every Exchange 2016 server, and any 2019 server whose operating system SE does not support: Microsoft does not support an in-place Windows upgrade underneath a running Exchange server, so an old OS means a new server, not a bigger patch window. 2. What your coexistence window looks like against Microsoft's current SE cumulative-update schedule, checked on the day the report is issued and not from memory, and the last responsible date to start. 3. What licensing you actually need. SE requires an active subscription: either SE server licences and CALs with active Software Assurance through Volume Licensing, or qualifying cloud subscriptions such as Microsoft 365 E3 or E5 for every user and device that touches the server. If the subscription lapses, your rights fall back to Exchange 2019 — which is unsupported. We state the gap between what you hold and what SE needs, and where the SE product keys will come from. 4. What will break. Certificates and TLS configuration; the Exchange hybrid configuration and Entra Connect; hybrid modern authentication; backup agents and their VSS writers; antivirus exclusions; archiving and journaling; load balancers and their health probes; SMTP relays; and the line-of-business applications, scanners and devices nobody documented. Each third-party product gets a dated vendor support statement for SE or a note that none could be obtained. 5. What it will cost and how long it will take, as a dated plan and a fixed written quote for the execution. You own the report. Hand it to your own Exchange team, take it to another vendor, or use it to justify the licensing budget internally — each is a legitimate outcome. If you do proceed with us, the execution — an in-place upgrade for Exchange 2019 estates, or new SE servers and mailbox moves for Exchange 2016 estates — is quoted directly from these findings, which is what makes a fixed price for that work possible.

Success criteria

The engagement is successful when you can approve an upgrade plan and its budget without needing another meeting. Specifically:

01A per-server verdict — in-place upgrade, replace with a new SE server, or decommission — with the reason for each written down.
02A coexistence window stated against Microsoft's current SE cumulative-update schedule, with the date after which your plan no longer works.
03A licensing position in writing: what SE requires for your server count and user and device population, what you already hold (Software Assurance, Microsoft 365 subscriptions), and the gap.
04A complete blocker register — every item that would stop or delay the upgrade, with the remediation and effort estimated for each.
05A hybrid and identity finding — whether your Exchange hybrid configuration, Entra Connect and modern-authentication setup survive the upgrade unchanged, and what has to change if not.
06A third-party compatibility matrix — backup, antivirus, archiving and journaling, load balancing, mobile device management, signature and relay products — with each vendor's SE support position recorded and dated.
07A dated upgrade plan and a fixed written quote for the execution, or a written explanation of what has to change before a fixed price is responsible.

What you receive

Exchange Server SE Readiness Report (typically 8–12 pages) covering the items below, delivered as a document you own.
Server inventory — every Exchange server with its roles, version, cumulative update and security-update level, Windows Server version and patch level, .NET Framework version, hardware or VM sizing, database and DAG membership, and mailbox count and size per database.
Per-server upgrade path — in-place upgrade (Exchange 2019 CU14 or CU15 on a Windows Server version SE supports) versus a new SE server build (every Exchange 2016 server; any 2019 server on an operating system SE does not support), with the order in which servers should move.
Coexistence window — your estate mapped against Microsoft's SE cumulative-update schedule as published on the day the report is issued, and the last responsible date to start.
Licensing position — SE server licences (Standard or Enterprise) and CALs (Standard, plus Enterprise where the features you use demand it), the subscription or Software Assurance requirement, cloud-subscription equivalence where you already hold Microsoft 365 E3 or E5, the hybrid-server licence rule, and where the SE product keys will come from.
Active Directory readiness — forest and domain functional levels, schema state, domain controller versions and placement, and the Exchange preparation steps the upgrade will need.
Certificate and TLS findings — every certificate in use with expiry and subject names, TLS protocol configuration on each server, and the changes SE expects.
Hybrid and identity findings — Exchange hybrid configuration, Entra Connect version and sync scope, hybrid modern authentication, OAuth and the Hybrid Agent where present, with the SE impact of each.
Mail-flow enforcement status — what Exchange Online's transport enforcement currently reports about your servers, and what changes for you when Microsoft's enforcement baseline moves.
Third-party compatibility matrix — backup, antivirus, archiving and journaling, load balancing, MDM, signatures, SMTP relays and integrated applications, each with a dated vendor support statement for SE or a note that none could be obtained.
Backup and recovery verification — whether current Exchange-aware backups complete and have been restored recently, because an upgrade with no tested restore is a gamble, not a plan.
Blocker register — every finding that would stop or delay the upgrade, with remediation effort per item.
A dated upgrade plan and a fixed-price quote for the execution.
A 60-minute findings walkthrough with the engineer who did the analysis.

How the work unfolds

Day 0 — Kickoff (45 minutes)

Confirm which servers are in scope, who owns the applications and devices that send mail through Exchange, what your downtime tolerance actually is, whether your estate is hybrid, and any constraint we must design around — air-gapped network, change freeze, regulator sign-off. Agree the read-only access, or the run-it-yourself collection route for environments that permit no external access.

Day 1 — Collection

Read-only collection across the Exchange organization: Exchange Management Shell exports of servers, databases, DAGs, connectors, virtual directories, certificates and hybrid configuration; Microsoft's Exchange Server Health Checker output per server; Active Directory functional levels, schema state and domain controller inventory; Entra Connect version and scope; and an inventory of backup, antivirus, archiving, load balancer, relay and integrated products. Nothing is installed, nothing is changed, no configuration is modified.

Day 2 — Lifecycle and licensing analysis

Map every server to its upgrade path and the estate to the coexistence window, checked against Microsoft's current SE cumulative-update schedule and the Exchange Online transport-enforcement baseline on the day — not from memory. Count SE server licences and CALs against the subscriptions and Software Assurance you hold and state the gap, the hybrid-server licence position, and where product keys will come from.

Day 3 — Dependency and compatibility analysis

Work through the things that break upgrades: certificates and TLS, hybrid and modern authentication, Entra Connect, backup and VSS, antivirus exclusions, archiving and journaling, load balancer configuration, SMTP relays, and Exchange 2016 features that do not exist in SE. Request a written SE support statement from each third-party vendor and record what came back, with the date.

Day 4 — Plan and quote

Sequence the work: which servers move first, where new SE servers are built and on what Windows Server version, when mailboxes and public folders move, when the last legacy server is removed, and where the change windows fall. Build the blocker register with remediation effort. Issue the fixed-price quote for the execution, or the written reasons a fixed price is not yet responsible.

Day 5 — Report and walkthrough

Deliver the written report and walk through it live for 60 minutes with your team. Answer the 'what if we did X instead' questions on the call rather than in a follow-up.

Prerequisites

An Exchange organization running Exchange Server 2016 and/or Exchange Server 2019. Exchange 2013 or older still present in the organization is a finding we will report — it is the first blocker, not a reason to decline the assessment.
Read access: an account in the Exchange View-Only Organization Management role group, read access to Active Directory, and local read access on each Exchange server to collect operating-system, certificate and installed-software details. We do not need Organization Management or Domain Admins for an assessment.
If your security policy does not permit external access at all — common in the air-gapped and regulated estates this page is written for — your own staff can run our collection scripts and Microsoft's Exchange Server Health Checker and return the output. We never need production credentials handed over in plain text.
A named technical contact who knows which applications, scanners, devices and relays send mail through Exchange, and who owns the Entra Connect server if you are hybrid.
Your current licensing position — the Microsoft agreements, Software Assurance status and Microsoft 365 subscriptions you hold — or Reader access to the Microsoft 365 admin center and your Volume Licensing portal so we can read them ourselves.
Vendor names and versions for backup, antivirus, archiving or journaling, load balancing, mobile device management, signature management and any other Exchange-integrated product.
Confirmation of which servers are in scope before Day 1 — the standard fee covers up to four Exchange servers, DAG members included. Larger and multi-site estates are quoted per estate in writing before we start.

Who does what

IT Partner

  • Provide and explain the read-only collection scripts, and point you to Microsoft's Exchange Server Health Checker if your staff run collection themselves.
  • Run or supervise collection and analysis without changing anything in your environment.
  • Check Microsoft's SE cumulative-update schedule, coexistence rules, licensing requirements and transport-enforcement baseline on the day the report is issued, and state that date in the report.
  • Request SE support statements from your third-party vendors and record the responses.
  • Produce the readiness report, per-server upgrade path, licensing position, blocker register, dated plan and fixed-price quote for the execution.
  • Deliver the findings walkthrough and answer the follow-up questions it raises.
  • Treat everything collected as confidential and request the least access the job needs.

Your team

  • Provide a named technical contact for the duration.
  • Grant the read access described above, or run collection on our behalf and return the output.
  • Provide your licensing agreements and subscription details, or read access to the portals that hold them.
  • Identify the applications, devices and relays that depend on Exchange, and their owners.
  • Confirm scope before Day 1.
  • Attend the Day 5 walkthrough.

What's not included

Changes to your environment — this is a read-only engagement: no cumulative updates installed, no schema preparation, no remediation, no test upgrade.
The upgrade itself — quoted from the report as a separate fixed-price engagement: an in-place upgrade for Exchange 2019 estates, or the Exchange 2016 to Exchange Server SE Migration — new SE servers and mailbox moves — for Exchange 2016 estates.
Migration to Exchange Online — if your destination is Microsoft 365, this assessment is the wrong purchase. The hybrid Microsoft 365 migration or the cutover Exchange Online migration is the right page, and we will tell you so on the discovery call rather than take this fee.
Removing the last on-premises Exchange server after a cloud migration — that is Exchange Server Decommissioning.
Moving public folders — sequenced in the plan, but the work is the on-premises public folders migration.
Licence procurement — we state what SE needs; buying it runs through Microsoft Volume Licensing or your existing agreement. Microsoft's subscription, Software Assurance and CAL fees are Microsoft's charges to you and are not part of this fee.
Windows Server, Active Directory, storage, virtualization or network remediation — findings are reported with the remediation each needs; doing it is separate work. Where Active Directory itself is the concern, the Active Directory Security Assessment and Hardening goes deeper than this engagement does.
Third-party product upgrades or vendor negotiations — we record each vendor's SE support position; upgrading or replacing their product is theirs or separately quoted.
Ongoing administration and patching of Exchange Server SE after the upgrade — that is Managed Exchange Server SE Administration and Patching, a separately priced monthly service, not part of the assessment.
Hardening the Exchange 2016 or 2019 servers you have while the plan runs — if the upgrade cannot finish before Microsoft's window closes, Out-of-Support Exchange Server Risk Containment is the interim security engagement; this assessment tells you whether you need it, it does not include it.
Estates larger than four Exchange servers, multiple DAGs or multi-site designs — scoped and quoted per estate in writing before we start.

Limitations & technical notes

!Findings are only as complete as the access granted. If collection is restricted, the report states what could not be examined and what risk that leaves open.
!Microsoft's SE cumulative-update schedule, coexistence rules and Exchange Online transport-enforcement baselines are Microsoft's to change and have changed before. The report cites the Exchange Team blog and Microsoft's product lifecycle pages as of the day it is issued, states that date, and should be re-checked before you commit budget. This page states Microsoft's published plan at the time of writing: SE CU2 in the second half of calendar 2026, and the September 2026 enforcement baseline change.
!End-of-support dates on this page — Exchange 2016 end of support and Exchange 2019 end of support both on 14 October 2025 — are per Microsoft's product lifecycle. Microsoft has offered a short, paid Extended Security Update bridge for Exchange 2016 and 2019 that Microsoft itself positions as inferior to upgrading; confirm its current terms and end date with your Microsoft account team. It buys time for the plan; it is not a substitute for one.
!Licensing is described as Microsoft publishes it at the time of writing — an active subscription or Software Assurance on SE server licences and CALs, or qualifying cloud subscriptions, with rights reverting to Exchange 2019 if the subscription lapses. The binding terms are Microsoft's Product Terms and your agreement. Microsoft's licensing fees are billed to you by Microsoft or your reseller and are not part of this fee.
!The fixed-price execution quote states its own validity period and assumes the environment does not materially change in that window; findings older than 60 days are re-verified before an upgrade starts.
!If the assessment concludes that a fixed-price upgrade is not responsible — Exchange 2013 still in the organization, an integrated product whose vendor will not support SE, or backups that have never been restored — we say so and quote time-and-materials instead. We would rather lose the fixed-price sale than commit to a number we cannot hold.
!Third-party SE support statements are the vendors' statements, recorded with a date; we cannot warrant them. Where a vendor does not respond within the week, the report says so and the plan treats that product as unverified.
!The assessment covers Exchange Mailbox and Edge Transport servers. Exchange 2016 Unified Messaging does not exist in Exchange 2019 or SE; if voicemail or auto attendants live there, the report flags it as a blocker and names the options, but designing the replacement is separate work.

Frequently asked questions

What do we actually get for $1,950?

A written readiness report, typically 8–12 pages: a per-server upgrade path, the coexistence window against Microsoft's current SE schedule, a licensing position with the gap stated, Active Directory, certificate, TLS, hybrid and identity findings, a third-party compatibility matrix with dated vendor statements, a backup verification, a blocker register, a dated upgrade plan and a fixed-price quote for the execution — plus a 60-minute walkthrough. One week end to end, for up to four Exchange servers.

Who is this not for?

Organizations whose real destination is Exchange Online. If you could move to Microsoft 365 and simply have not yet, this assessment answers the wrong question: the right engagement is the hybrid Microsoft 365 migration if you need coexistence, or the cutover Exchange Online migration if you do not. This page is for organizations that must keep Exchange on-premises — regulated, air-gapped, government-adjacent, or dependent on on-premises identity — and need to get there safely on Exchange Server SE.

Can we upgrade Exchange 2016 in place to SE?

No. Microsoft supports the in-place upgrade to SE only from Exchange 2019 at CU14 or CU15. An Exchange 2016 estate moves the way a 2016-to-2019 upgrade always did: new SE servers are built on a supported Windows Server version, mailboxes, public folders, connectors and client access move across, and the 2016 servers are removed. Microsoft's guidance at the time of writing is that SE RTM and SE CU1 coexist with Exchange 2016 at CU23 during that move, and that SE CU2 will not — so the whole sequence has to finish inside the window. Two things that surprise 2016 estates: Unified Messaging does not exist in SE, so voicemail needs a new home, and the Windows Server 2016 many of those servers run on leaves extended support on 12 January 2027, per Microsoft's product lifecycle, so the operating system refresh is coming either way. The execution for a 2016 estate is the Exchange 2016 to Exchange Server SE Migration, quoted from this report.

We are on Exchange 2019. Is the in-place upgrade really as simple as installing a CU?

Mechanically, it is close: on Exchange 2019 CU14 or CU15 the SE setup runs like a cumulative update on the same server. Everything around it is where upgrades fail. The server must be on a Windows Server version SE supports, and Microsoft does not support upgrading Windows in place underneath Exchange, so an old operating system means a new server. Licensing changes: SE needs an active subscription or Software Assurance, and you need the SE product keys in hand before the change window. Hybrid, certificates, load balancer probes, backup agents and antivirus exclusions all have to be checked against SE. The assessment confirms each of those before anyone runs setup, which is why we can quote the execution as a fixed price.

What are the Exchange SE licensing requirements?

An active subscription. Microsoft licenses SE either through SE server licences (Standard or Enterprise) and CALs with active Software Assurance bought through Volume Licensing, or through qualifying cloud subscriptions such as Microsoft 365 E3 or E5 covering every user and device that accesses the server. A Standard CAL is always required; an Enterprise CAL is an add-on for the advanced features. If the subscription or Software Assurance lapses, Microsoft states your rights revert to Exchange 2019 — which is out of support. The report counts your servers, users and devices against what you already hold and states the gap; the fees themselves are Microsoft's charges, billed to you by Microsoft or your reseller, not part of this engagement. The binding terms are Microsoft's Product Terms.

When exactly is the coexistence deadline?

Microsoft has not published a fixed day, which is why we do not print one. Microsoft's Exchange Team has stated that SE CU2 will block coexistence with Exchange 2016 and 2019, and its published plan at the time of writing places CU2 in the second half of calendar 2026. Because Exchange security updates are released for the current cumulative updates, an organization still coexisting when CU2 is required is cut off from patches. The report states Microsoft's current timing on the day it is issued, with the source, and the plan is built to finish before it — not on it.

We are hybrid. Does Exchange Online's transport enforcement affect us?

Yes, if your on-premises servers are behind on updates. Since February 2025, Exchange Online has reported on, then throttled — SMTP 450 delays — then blocked — SMTP 550 rejections — mail arriving from on-premises Exchange servers that are significantly out of date, on every version including 2019. Microsoft has announced that from the second week of September 2026 the oldest build it accepts from an Exchange 2016 or 2019 server over an on-premises inbound connector rises to the final public update of October 2025. Microsoft lets an administrator pause enforcement from the mail flow report for a limited period — up to 90 days per year at the time of writing — which is a bridge for the upgrade, not a way to avoid it. The report tells you what enforcement currently says about your servers and what changes when the baseline moves. If you need hands on the Exchange Online side while the on-premises work runs, Exchange Online Administrator on Demand covers that separately.

Is Microsoft's Extended Security Update for Exchange 2016 and 2019 an alternative to upgrading?

It is a bridge. Microsoft has offered a short, paid Extended Security Update program for Exchange 2016 and 2019 that Microsoft's own guidance positions as inferior to moving to SE, and third-party reporting places its end in October 2026 — confirm the current terms with your Microsoft account team, because they are Microsoft's to change. ESU does not reopen the SE coexistence window, does not satisfy Exchange Online's enforcement baseline by itself, and does not make the Windows Server underneath supported. If you need it to get through the plan, the report says so and sequences it; it is not a plan on its own. If the servers must keep running past the window, Out-of-Support Exchange Server Risk Containment is the interim measure.

Do you need admin access to production?

No. Exchange View-Only Organization Management, read access to Active Directory and local read access on the servers is enough. If your policy does not permit any external access — normal in the estates this page is written for — your own staff run our collection scripts and Microsoft's Exchange Server Health Checker and return the output. Least access is how we work on every engagement, not a concession for this one.

Will this touch production?

Collection is read-only. It runs Exchange Management Shell exports, Microsoft's Health Checker script and Active Directory reads; it does not install anything, change configuration, run setup, or generate meaningful load. It can be run during business hours, and in a change-frozen environment it can be run by your staff under your own change control.

What if you find something that means we cannot upgrade?

Then you have found it in a report instead of in a failed change window. The report states the blocker, the remediation and the effort — an Exchange 2013 server still in the organization, a 2019 server on a Windows Server version SE does not support, a journaling or archiving product whose vendor has no SE support statement, Unified Messaging still hosting voicemail, backups that have never been restored. Where a blocker makes a fixed price irresponsible, we quote the execution time-and-materials and say why.

Do we have to use you for the upgrade?

No. The report is written to be actionable by any competent Exchange team, including your own. It is not a proposal with findings attached. If you do proceed with us, the execution is a separate fixed-price engagement quoted directly from the report.

How does this fit with our Windows Server 2016 end-of-support work?

Closely, for Exchange 2016 estates. Exchange 2016 runs on Windows Server 2012 R2 or 2016, and Windows Server 2016 leaves extended support on 12 January 2027, per Microsoft's product lifecycle. SE will not run on those operating systems, so the Exchange move and the OS refresh are the same project whether you planned it that way or not. If Exchange is one of several Windows Server 2016 workloads you have to deal with, the Windows Server 2016 End of Support Assessment and Roadmap covers the estate; this assessment goes deeper on Exchange than that one does, and the two are designed to be read together.

We have a DAG, or more than four servers. Is the fee the same?

The standard fee covers up to four Exchange servers, DAG members included. Estates with more than four servers, multiple DAGs or a multi-site design are quoted per estate in writing before we start — the collection is the same, the analysis is not.

Why is this not free?

Because a free assessment is a sales call, and it produces a proposal rather than findings. Charging for it means we spend a week on your environment instead of an hour, and it means the report is yours — including the parts that say your vendor will not support SE, or that Exchange Online is the better answer after all. If you want a free conversation first, that is exactly what our 30-minute discovery session is for, and it will tell you honestly whether this assessment is worth $1,950 for your estate.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$1,950 per project
1 week
Book the readiness assessment