First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/Managed Exchange Server SE Administration and Patching
Managed Services

Managed Exchange Server SE Administration and Patching

Managed Exchange Server SE Administration and Patching is a monthly operations service for organizations that keep Microsoft Exchange Server on-premises. For every Exchange Server Subscription Edition (SE) server in scope, IT Partner installs each security update, hotfix update and cumulative update inside Microsoft's support window, runs Microsoft's Exchange Health Checker and remediates what it flags, renews certificates before they expire, checks database availability group health, backups and transport queues, keeps your servers off Exchange Online's out-of-date-server enforcement report, and closes every quarter with a written report. It costs $395 per server per month with no long-term contract; administration beyond the monthly scope is billed by the hour at IT Partner's published rate and estimated in writing first. It is built for mid-size and enterprise estates already on Exchange SE — not for Exchange 2016 or 2019 servers, which reached end of support on 14 October 2025 and need an upgrade first, and not for Exchange Online, which has its own [Exchange Online Administrator on Demand](/services/exchange-online-administrator-on-demand) service.

Timeline 30 daysService owner Mike MackeyExchange ServerWindows Server

What this engagement is

Exchange Server 2016 and 2019 reached end of support on 14 October 2025 per Microsoft's product lifecycle, and Exchange Server Subscription Edition (SE) is the supported on-premises successor. SE changed the deal for the people who run it. There is no ten-year support date to plan around: SE is serviced under Microsoft's Modern Lifecycle Policy, which means Microsoft supports current builds and expects you to stay on them. Microsoft's own Exchange Health Checker script flags any server not on one of the two most recently released cumulative updates as out of date, and separately reports whether the latest security update is installed. Between August 2025 and August 2026 Microsoft shipped nine SE security or hotfix updates — Health Checker's build table lists them, from the August 2025 security update to the August 2026 one — and none of them was optional in practice. A server that misses them is unsupported, exposed, and, if the estate is hybrid, on its way to Exchange Online's enforcement report. The skill to do this safely every month is exactly the skill many IT teams let go when most mailboxes moved to the cloud. This service is the operator that skill used to be. Each time Microsoft releases an update for SE, IT Partner schedules it into the window agreed with you, prepares the server (the .NET Framework and Visual C++ redistributable levels a release expects, Active Directory preparation when a cumulative update requires it, maintenance mode and database copy activation in a DAG), installs it, and validates the result: services, Outlook on the web, the Exchange admin center, Exchange Web Services, ActiveSync, Autodiscover, MAPI over HTTP, and inbound and outbound mail flow. Each month, Health Checker runs on every server and the findings are worked rather than filed — Extended Protection, AMSI integration, the Exchange Emergency Mitigation service and its reach to Microsoft's mitigation endpoint, TLS configuration, certificate lifetimes including the Exchange Server Auth certificate that silently breaks Outlook on the web and hybrid when it expires, the Exchange Online send connector's certificate and cloud-services settings, the dedicated Exchange hybrid application Microsoft now expects in hybrid estates, setting overrides, pagefile and IIS configuration, and known-vulnerability checks by build. Between releases the service watches what keeps mail moving: database availability group copy and replication health, activation preferences and witness state, database growth and whitespace, backup success and transaction-log truncation, transport queues and back pressure, and Edge subscription synchronization where an Edge Transport server exists. For hybrid estates it checks Exchange Online's mail-flow report for out-of-date on-premises servers every month. Microsoft has described a progressive enforcement — report, then throttle, then block — against persistently out-of-date servers that send to Exchange Online, with only a limited administrator-requested pause; the goal of this service is that your servers never appear on that report, and that if one does, it is fixed before throttling starts. The boundaries are priced honestly. The fee is $395 per Exchange SE server per month — Mailbox and Edge Transport roles both count as servers — and larger DAG estates and multi-site designs are quoted per estate. It covers keeping the platform current, healthy and supported. It does not cover the Windows Server operating system, hardware or hypervisor underneath, mailbox migrations, Exchange Online administration, or a 24x7 security operations center; recipient administration and troubleshooting beyond the monthly scope are on-demand hours at IT Partner's published hourly rate, estimated in writing before the work starts. Access follows the same least-privilege principle we publish for cloud tenants: named accounts in the narrowest Exchange role group that does the job, elevated only for a change window, never shared, and removed when the service ends.

Success criteria

01Every Exchange SE server in scope is on Microsoft's current build — the latest cumulative update plus the latest security or hotfix update — within the update window agreed at onboarding, and Health Checker's build-currency and latest-security-update checks are green on every server in every monthly run.
02In hybrid estates, no in-scope server appears on Exchange Online's out-of-date-server mail-flow report; if one appears, it is remediated before throttling begins and the remediation is documented.
03No certificate on an in-scope server — including the Exchange Server Auth certificate — reaches 30 days to expiry without a renewal scheduled, and no outage in the quarter is caused by an expired certificate.
04Health Checker findings rated as errors are remediated within the monthly cycle or formally accepted by you in writing with the reason recorded; warnings are triaged and either fixed or scheduled.
05Database availability group copies are healthy, backups complete with transaction-log truncation confirmed, and transport queues stay within the thresholds set at onboarding — each verified and reported monthly.
06Requests raised through the agreed intake receive first response within IT Partner's published SLA of 1 business hour, and any request outside the monthly scope is named as such and estimated in writing before work starts.
07The quarterly report is delivered on schedule and is specific enough — dates, builds, findings, decisions — to answer an auditor or a cyber-insurance questionnaire without rework.

What you receive

Onboarding baseline (first monthly cycle): inventory of every Exchange SE server — role, build and update level, Windows Server version, DAG membership and topology, namespaces, certificates with expiry dates, send and receive connectors, hybrid state, backup product — a first Health Checker run per server with a written remediation list, and the agreed update windows, escalation contacts and thresholds.
Update installation per server: each Microsoft security update and hotfix update installed inside the agreed window after release, and each cumulative update installed with its prerequisites (.NET Framework and Visual C++ redistributable levels, Active Directory schema and domain preparation where the release requires it), DAG-aware sequencing through maintenance mode and copy activation, and a post-update validation checklist covering services, client protocols and mail flow.
Monthly Health Checker cycle on every server, with remediation of findings: build currency and latest security update, Extended Protection, AMSI integration, Exchange Emergency Mitigation service configuration and endpoint reachability, TLS settings, certificate lifetimes and key strength, Exchange Online connector configuration, the dedicated Exchange hybrid application, setting overrides, pagefile, IIS and known-vulnerability checks.
Certificate lifecycle management: a certificate calendar for every in-scope server, renewal and rebinding of namespace and SAN certificates to Exchange services, Exchange Server Auth certificate renewal, and coordination with whoever administers your load balancer, reverse proxy and Edge Transport servers so the new certificate lands everywhere it must.
DAG, backup and transport checks every month: database copy status, replication and content index health, activation preferences and witness state, database growth and whitespace, backup success with transaction-log truncation confirmed, transport queues and back pressure, and Edge subscription synchronization where present.
Exchange Online transport-enforcement compliance for hybrid estates: a monthly check of the Exchange admin center mail-flow report for out-of-date on-premises servers, remediation of any listed server before throttling begins, and validation of the hybrid send connector's certificate name and cloud-services settings that Health Checker flags.
Server-side fixes inside the fee: connector corrections, certificate rebinding, setting overrides and configuration changes that Health Checker or the monthly checks show are needed to keep the platform current, healthy and supported.
On-demand administration through the agreed intake, outside the fee: recipient and policy administration, troubleshooting of user-reported issues, and small projects — each identified at intake, estimated in writing at IT Partner's published hourly rate, and billed only as approved.
A monthly update note per server after each release cycle — what was installed, on which date, what was validated, what Health Checker found and what was fixed — and a quarterly report: patch compliance by server with dates and builds, Health Checker trend, the certificate calendar, DAG, backup and queue status, Exchange Online enforcement status, incidents and decisions, and recommendations for the next quarter.
Escalation to Microsoft, where a case needs it, through IT Partner's Microsoft Premier Support agreement — offered as a paid add-on, never as a hidden line in the monthly fee.

How the work unfolds

1. Onboarding and baseline (first monthly cycle)

Named accounts are created for IT Partner engineers in the Exchange role groups agreed with you — View-Only Organization Management for the Health Checker runs, Organization Management only for change windows — with local administrator rights on the Exchange servers and access through your privileged-access route. We inventory every server, run Health Checker on each, verify backups and the DAG, read the Exchange Online enforcement report if the estate is hybrid, and deliver the baseline: what is current, what is not, what must be fixed first, and the update windows and thresholds the service will run to. Anything already broken or structurally risky is written down and either absorbed into the first cycles or scoped as a separate piece of work.

2. Update cycle (each Microsoft release)

When Microsoft releases a security update, hotfix update or cumulative update for Exchange SE, we confirm the known-issues state, schedule the installation into your agreed window, prepare each server, install DAG members one at a time through maintenance mode, and validate client protocols and mail flow before handing the server back. Standalone servers get an agreed outage window. Out-of-band security updates are treated as urgent and you are asked for a shorter window.

3. Monthly health cycle

Health Checker runs on every server and its findings are triaged: errors are fixed in the cycle or accepted by you in writing, warnings are fixed or scheduled. The same cycle checks the DAG, backups, queues and certificate calendar, and — for hybrid estates — the Exchange Online out-of-date-server report. Certificates inside 60 days of expiry go onto the renewal plan; inside 30 days they are renewed.

4. Requests and on-demand administration

Your named contacts raise requests through the agreed intake, with first response inside IT Partner's published SLA of 1 business hour. Server-side fixes needed to keep the platform healthy are handled inside the fee. Recipient administration, user-facing troubleshooting and small projects are named as on-demand work at intake and estimated in writing at the published hourly rate before anything starts — the monthly fee is never silently stretched, and never silently exceeded.

5. Quarterly report and roadmap

Every third cycle closes with the quarterly report: patch compliance per server with dates and builds, Health Checker trend, certificate calendar, DAG, backup and queue status, Exchange Online enforcement status, incidents and decisions. It ends with a short roadmap — what Microsoft has announced for SE that affects you, what technical debt is worth paying down, and an honest note when the right next step is a project rather than another month of operations.

Prerequisites

Exchange Server Subscription Edition servers — Mailbox and/or Edge Transport roles — running on a Windows Server version Microsoft supports for SE. Exchange 2016 and 2019 servers are not accepted into this service as-is: they reached end of support on 14 October 2025 and need an upgrade or migration first, which we scope separately.
Valid Exchange SE licensing — Microsoft's Product Terms list Exchange Server Subscription Edition Standard and Enterprise server licenses and Standard and Enterprise CALs, held by subscription or under active Software Assurance. Entitlement is yours and is verified, not sold, at onboarding; if you need licensing help, start with Microsoft Volume Licensing.
Named administrative accounts for IT Partner engineers in the agreed Exchange role groups, local administrator rights on the Exchange servers, and access through your privileged-access route (VPN, jump host or privileged access workstation) — consistent with the least-privilege principle in our published access policy.
An agreed update window per server or DAG, a change-approval contact, and a decision on how quickly out-of-band security updates may be installed.
A working, application-aware backup of Exchange. We verify it every month; we do not provide it. If you need one, Managed Backup and Backup-Restore is the companion service.
Access to certificate procurement — your public certificate authority account or internal CA — and either access to the load balancer and reverse proxy configuration or a named contact who administers them.
For hybrid estates: a delegated role in the Microsoft 365 tenant sufficient to read the Exchange admin center mail-flow reports and validate connectors, granted through least-privilege GDAP that you approve.
Windows Server operating system patching for the Exchange hosts handled by your team or by IT Infrastructure Monitoring and Support, coordinated with the update windows agreed here.
Outbound access from Mailbox servers to the Microsoft endpoints Exchange depends on — the Exchange Emergency Mitigation service's Office Config Service endpoint and Microsoft's update downloads — or an agreed alternative such as offline update staging.

Who does what

IT Partner

  • Install every Exchange SE security, hotfix and cumulative update inside the agreed window, with DAG-aware sequencing and post-update validation.
  • Run Health Checker on every server monthly and remediate or formally escalate its findings.
  • Maintain the certificate calendar and renew certificates before they expire.
  • Check DAG, backup, queue and — for hybrid estates — Exchange Online enforcement status every month.
  • Respond to intake requests within the published SLA and name, in writing, any request that falls outside the monthly scope before estimating it.
  • Deliver the monthly update notes and the quarterly report, and track Microsoft's Exchange SE announcements that affect your estate.
  • Use named, least-privilege accounts, keep them out of shared use, and remove them when the service ends.

Your team

  • Maintain Exchange SE and Windows Server licensing, hardware, hypervisor, storage and network for the servers in scope.
  • Approve update windows and out-of-band exceptions promptly — an update held past Microsoft's release leaves the server unsupported until it is installed.
  • Provide and maintain the privileged-access route, the backup platform, and certificate procurement.
  • Patch the Windows Server operating system on the Exchange hosts, or subscribe to IT Partner's infrastructure support for it, coordinated with the agreed windows.
  • Keep a named contact for approvals and tell us early about changes — new servers, DAG changes, namespace changes, hybrid changes — that affect the estate.
  • Review the quarterly report and decide on recommendations that require project work.

What's not included

Windows Server operating system patching, firmware, hypervisor, storage, network and load-balancer administration. We coordinate reboot windows and certificate rebinding with whoever runs them; running them is IT Infrastructure Monitoring and Support or your own team.
Exchange 2016 and 2019 servers. They are out of support and cannot be made supported by patching; the path is an in-place upgrade from Exchange 2019 or a side-by-side migration from Exchange 2016 to Exchange SE, scoped as a project — or a move to Exchange Online. Servers that must keep running meanwhile need a containment engagement, not a monthly fee.
Migrations to Exchange Online — Hybrid Microsoft 365 Migration and Cutover Exchange Online Migration — and the removal of the last on-premises server, which is Exchange Server Decommissioning.
Exchange Online and Microsoft 365 tenant administration. Mailbox, transport, anti-spam and admin center work in the cloud is Exchange Online Administrator on Demand; this service reads the tenant's enforcement report and validates hybrid connectors, and stops there.
Recipient and policy administration on the servers — mailbox creation, permissions, distribution groups, transport rules, retention and Outlook on the web policies — and troubleshooting of user-reported issues. These are on-demand hours at IT Partner's published hourly rate, estimated in writing at intake.
24x7 monitoring, security operations and incident response. Checks and alert handling in this service run in business hours; round-the-clock detection and response is Managed Detection and Response.
Backup software, licensing and restores beyond verification. We confirm backups complete and logs truncate; operating the backup platform and running restores is Managed Backup and Backup-Restore or your backup team.
Microsoft's and third parties' charges: Exchange SE subscription or Software Assurance, CALs, Windows Server licensing, public certificates, and the Microsoft Premier Support escalation add-on — each billed by its vendor, never marked up into this fee.
Email authentication and deliverability — SPF, DKIM and DMARC design is DMARC, DKIM and SPF Email Authentication Implementation and the monitoring is Managed DMARC and Email Deliverability Monitoring; both pair well with this service.
Administration of third-party products installed on the Exchange servers — antivirus, backup agents, archiving and journaling connectors, monitoring agents. We verify Exchange's antivirus exclusions and flag conflicts; the products themselves belong to their vendors and administrators.

Limitations & technical notes

!Microsoft's release cadence is Microsoft's. Exchange SE security and hotfix updates arrive when Microsoft ships them — nine between August 2025 and August 2026 by Health Checker's build table, some out of band — and the update windows agreed at onboarding must accommodate that. An urgent security update may need a window sooner than the standing schedule; we ask, we do not assume.
!The support rule is Microsoft's too. Health Checker treats any server not on one of the two most recently released cumulative updates as out of date, and checks separately for the latest security update; a server you hold back from an approved window is unsupported until the update lands. At the time of writing Exchange SE has shipped as its July 2025 release plus security and hotfix updates, and Microsoft has said a future SE cumulative update will end coexistence with Exchange 2016 and 2019 — check Microsoft's current timing before relying on it.
!Exchange Online's enforcement against out-of-date on-premises servers is a Microsoft system. Microsoft has described it as report, then throttle, then block, with a limited pause an administrator can request; we manage the estate to stay off the report. A server already throttled or blocked when onboarding starts is treated as an incident in the first cycle — we do not promise Microsoft's timing for lifting enforcement.
!Every update means a reboot. In a DAG, members are updated one at a time behind maintenance mode with no user-visible outage when the design allows it; a standalone server means an outage window, and you approve it.
!Cumulative updates cannot be uninstalled and security updates only partially so. Our safeguards are Microsoft's known-issues page, a verified backup before the change, DAG-member-first installation, and a validation checklist afterward — not a promise that Microsoft's update is defect-free.
!Health Checker is Microsoft's script, run as Microsoft publishes it; findings reflect its checks and our reading of them, and some become accepted risks you sign off rather than changes we make.
!The fee is per server for standalone servers and typical DAGs; larger DAG estates and multi-site designs are quoted per estate, and we say which applies at scoping, in writing, before onboarding.
!Support requests receive first response within IT Partner's published SLA of 1 business hour, with monthly support statistics published openly since December 2023, including the months we missed.

Frequently asked questions

What is Managed Exchange Server SE Administration and Patching?

A recurring monthly service in which IT Partner operates your on-premises Exchange Server Subscription Edition servers: every Microsoft security, hotfix and cumulative update installed inside the support window, a monthly Health Checker run with findings remediated, certificate renewals, DAG, backup and transport-queue checks, Exchange Online enforcement compliance for hybrid estates, and a quarterly report. It costs $395 per server per month with no long-term commitment.

Who is this service for?

Mid-size and enterprise organizations that keep Exchange on-premises — because a regulator or contract requires mail to stay in their datacenter, because hybrid recipient management still runs through a server, or because the estate simply is not leaving — and that no longer have an engineer whose job is to keep it current. If your Exchange servers are patched when someone remembers, or your last cumulative update was installed by a contractor who has since left, this service is the missing role.

How does the per-server billing work, and what about a DAG?

The monthly bill is $395 for each Exchange SE server in scope — Mailbox and Edge Transport roles alike. A typical two- or four-member DAG is billed per member. Larger DAG estates and multi-site designs are quoted per estate, and the quote is written before onboarding so there is no surprise on the first invoice. Adding or retiring a server is handled through the intake and the bill follows the servers actually in scope that month.

What does "inside Microsoft's support window" mean for Exchange SE?

Exchange SE is serviced under Microsoft's Modern Lifecycle Policy, so there is no end-of-support date to plan around — instead Microsoft supports current builds. Microsoft's own Health Checker script marks any server that is not on one of the two most recently released cumulative updates as out of date, and reports separately whether the latest security update is installed. In practice that means installing each security and hotfix update within your agreed window after Microsoft releases it and each cumulative update before the older one drops out of the window.

Why does Exchange Online care whether my on-premises server is patched?

Because your server sends mail into Microsoft's cloud. Microsoft's Exchange team has described transport-based enforcement against persistently out-of-date on-premises Exchange servers: the server is listed in an Exchange admin center mail-flow report first, then its mail to Exchange Online is throttled, then blocked, with only a limited pause an administrator can request. For a hybrid estate that is a business-continuity issue, not a compliance footnote. This service checks the report every month and keeps your servers off it.

We are still on Exchange 2016 or 2019. Can you take us on?

Not as-is, and we will say so on the first call. Both versions reached end of support on 14 October 2025; no amount of patching makes them supported again, and Exchange Online's enforcement treats them as out of date. The honest path is an in-place upgrade from Exchange 2019 or a side-by-side migration from Exchange 2016 to Exchange SE — or a move to Exchange Online — scoped as a project. Once the servers are on SE, this service takes over from the day of handoff.

What is Health Checker, and what do you do with what it finds?

Health Checker is Microsoft's published Exchange Server diagnostic script, maintained by Microsoft's Exchange support engineers and supporting Exchange 2016, 2019 and SE. It checks build currency, security-update level, Extended Protection, AMSI integration, the Emergency Mitigation service, TLS configuration, certificates, the Exchange Online connector, the dedicated hybrid application, setting overrides, hardware and operating-system settings, and known vulnerabilities by build. We run it on every server every month and work the output: errors are fixed within the cycle or accepted by you in writing with the reason recorded, warnings are fixed or scheduled, and the trend goes into the quarterly report.

What do you do about certificates?

We keep a certificate calendar for every server — the namespace and SAN certificates bound to IIS, SMTP and other Exchange services, and the Exchange Server Auth certificate that Exchange uses for OAuth and hybrid. Certificates inside 60 days of expiry go onto the renewal plan; inside 30 days they are renewed, rebound, and coordinated with whoever runs your load balancer, reverse proxy and Edge Transport servers. You provide the certificate authority account or internal CA; we do the rest. An expired Auth certificate breaks Outlook on the web and hybrid free/busy quietly, which is why it is on the calendar by name.

Do you patch the Windows Server operating system too?

No — the operating system, firmware, hypervisor and hardware are outside this service, and we say so rather than leave it ambiguous. We do handle the Exchange prerequisites Microsoft ties to a release, such as .NET Framework and Visual C++ redistributable levels, because an Exchange update will not install without them. Operating-system patching is coordinated with our update windows and done by your team or by IT Partner's IT Infrastructure Monitoring and Support.

What happens if an update breaks something?

Exchange cumulative updates cannot be uninstalled, and security updates only partially, so the protection is upstream of the install: Microsoft's known-issues page is checked before we schedule, a verified backup exists before the change, DAG members are updated one at a time so a problem shows on one server while the others carry the load, and every server passes a validation checklist before it is handed back. If a Microsoft defect does surface, we work Microsoft's documented workaround, and where the case needs Microsoft, we escalate through IT Partner's Premier Support agreement as a paid add-on.

What access do you need to our servers?

Named accounts for our engineers — never shared credentials — in the narrowest Exchange role group that does the job: View-Only Organization Management for the Health Checker runs, Organization Management only during change windows, plus local administrator rights on the Exchange servers, reached through your VPN, jump host or privileged access workstation. For hybrid estates we also need a least-privilege GDAP role in the tenant that you approve, sufficient to read the mail-flow reports and validate connectors. The same principle we publish for cloud access applies on-premises, and the accounts are removed when the service ends.

Does this include mailbox administration or a helpdesk?

No. The fee keeps the platform current, healthy and supported; it does not include recipient and policy administration — mailboxes, permissions, groups, transport rules, retention — or troubleshooting user-reported issues. Those are on-demand hours: raised through the same intake, named as on-demand at first response, estimated in writing at IT Partner's published hourly rate, and billed only as approved. The published rate for comparable work is $175 per hour, as listed for Exchange Online Administrator on Demand; your service agreement states the rate that applies.

Do you handle Exchange SE licensing?

We verify it; we do not bundle it. Microsoft's Product Terms list Exchange Server Subscription Edition Standard and Enterprise server licenses and Standard and Enterprise CALs, held by subscription or under active Software Assurance, and Microsoft's rules decide whether your existing Microsoft 365 subscriptions cover the CAL side. At onboarding we confirm the entitlement you hold matches the servers and users in scope; if it does not, or if you want the options laid out before renewal, IT Partner's Microsoft Volume Licensing consulting is the place for it.

How does billing work, and can we stop?

Monthly, at $395 per server in scope, invoiced monthly, with no long-term contract: stop any month, and all we ask is payment of previously approved invoices. Everything the service produced stays yours — the baseline inventory, the certificate calendar, every Health Checker report, every update note and quarterly report — and our accounts are removed the day the service ends.

How quickly can the service start?

The first monthly cycle is the onboarding: accounts, the inventory, a Health Checker run on every server, backup and DAG verification, the enforcement report for hybrid estates, and the update windows. From the second cycle the service is in steady state. If IT Partner performed your Exchange SE upgrade, the baseline already exists and onboarding is largely a handover to ourselves.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$395 per server
30 days
Start managed Exchange SE