Managed Exchange Server SE Administration and Patching
Managed Exchange Server SE Administration and Patching is a monthly operations service for organizations that keep Microsoft Exchange Server on-premises. For every Exchange Server Subscription Edition (SE) server in scope, IT Partner installs each security update, hotfix update and cumulative update inside Microsoft's support window, runs Microsoft's Exchange Health Checker and remediates what it flags, renews certificates before they expire, checks database availability group health, backups and transport queues, keeps your servers off Exchange Online's out-of-date-server enforcement report, and closes every quarter with a written report. It costs $395 per server per month with no long-term contract; administration beyond the monthly scope is billed by the hour at IT Partner's published rate and estimated in writing first. It is built for mid-size and enterprise estates already on Exchange SE — not for Exchange 2016 or 2019 servers, which reached end of support on 14 October 2025 and need an upgrade first, and not for Exchange Online, which has its own [Exchange Online Administrator on Demand](/services/exchange-online-administrator-on-demand) service.
What this engagement is
Exchange Server 2016 and 2019 reached end of support on 14 October 2025 per Microsoft's product lifecycle, and Exchange Server Subscription Edition (SE) is the supported on-premises successor. SE changed the deal for the people who run it. There is no ten-year support date to plan around: SE is serviced under Microsoft's Modern Lifecycle Policy, which means Microsoft supports current builds and expects you to stay on them. Microsoft's own Exchange Health Checker script flags any server not on one of the two most recently released cumulative updates as out of date, and separately reports whether the latest security update is installed. Between August 2025 and August 2026 Microsoft shipped nine SE security or hotfix updates — Health Checker's build table lists them, from the August 2025 security update to the August 2026 one — and none of them was optional in practice. A server that misses them is unsupported, exposed, and, if the estate is hybrid, on its way to Exchange Online's enforcement report. The skill to do this safely every month is exactly the skill many IT teams let go when most mailboxes moved to the cloud. This service is the operator that skill used to be. Each time Microsoft releases an update for SE, IT Partner schedules it into the window agreed with you, prepares the server (the .NET Framework and Visual C++ redistributable levels a release expects, Active Directory preparation when a cumulative update requires it, maintenance mode and database copy activation in a DAG), installs it, and validates the result: services, Outlook on the web, the Exchange admin center, Exchange Web Services, ActiveSync, Autodiscover, MAPI over HTTP, and inbound and outbound mail flow. Each month, Health Checker runs on every server and the findings are worked rather than filed — Extended Protection, AMSI integration, the Exchange Emergency Mitigation service and its reach to Microsoft's mitigation endpoint, TLS configuration, certificate lifetimes including the Exchange Server Auth certificate that silently breaks Outlook on the web and hybrid when it expires, the Exchange Online send connector's certificate and cloud-services settings, the dedicated Exchange hybrid application Microsoft now expects in hybrid estates, setting overrides, pagefile and IIS configuration, and known-vulnerability checks by build. Between releases the service watches what keeps mail moving: database availability group copy and replication health, activation preferences and witness state, database growth and whitespace, backup success and transaction-log truncation, transport queues and back pressure, and Edge subscription synchronization where an Edge Transport server exists. For hybrid estates it checks Exchange Online's mail-flow report for out-of-date on-premises servers every month. Microsoft has described a progressive enforcement — report, then throttle, then block — against persistently out-of-date servers that send to Exchange Online, with only a limited administrator-requested pause; the goal of this service is that your servers never appear on that report, and that if one does, it is fixed before throttling starts. The boundaries are priced honestly. The fee is $395 per Exchange SE server per month — Mailbox and Edge Transport roles both count as servers — and larger DAG estates and multi-site designs are quoted per estate. It covers keeping the platform current, healthy and supported. It does not cover the Windows Server operating system, hardware or hypervisor underneath, mailbox migrations, Exchange Online administration, or a 24x7 security operations center; recipient administration and troubleshooting beyond the monthly scope are on-demand hours at IT Partner's published hourly rate, estimated in writing before the work starts. Access follows the same least-privilege principle we publish for cloud tenants: named accounts in the narrowest Exchange role group that does the job, elevated only for a change window, never shared, and removed when the service ends.
Success criteria
What you receive
How the work unfolds
Named accounts are created for IT Partner engineers in the Exchange role groups agreed with you — View-Only Organization Management for the Health Checker runs, Organization Management only for change windows — with local administrator rights on the Exchange servers and access through your privileged-access route. We inventory every server, run Health Checker on each, verify backups and the DAG, read the Exchange Online enforcement report if the estate is hybrid, and deliver the baseline: what is current, what is not, what must be fixed first, and the update windows and thresholds the service will run to. Anything already broken or structurally risky is written down and either absorbed into the first cycles or scoped as a separate piece of work.
When Microsoft releases a security update, hotfix update or cumulative update for Exchange SE, we confirm the known-issues state, schedule the installation into your agreed window, prepare each server, install DAG members one at a time through maintenance mode, and validate client protocols and mail flow before handing the server back. Standalone servers get an agreed outage window. Out-of-band security updates are treated as urgent and you are asked for a shorter window.
Health Checker runs on every server and its findings are triaged: errors are fixed in the cycle or accepted by you in writing, warnings are fixed or scheduled. The same cycle checks the DAG, backups, queues and certificate calendar, and — for hybrid estates — the Exchange Online out-of-date-server report. Certificates inside 60 days of expiry go onto the renewal plan; inside 30 days they are renewed.
Your named contacts raise requests through the agreed intake, with first response inside IT Partner's published SLA of 1 business hour. Server-side fixes needed to keep the platform healthy are handled inside the fee. Recipient administration, user-facing troubleshooting and small projects are named as on-demand work at intake and estimated in writing at the published hourly rate before anything starts — the monthly fee is never silently stretched, and never silently exceeded.
Every third cycle closes with the quarterly report: patch compliance per server with dates and builds, Health Checker trend, certificate calendar, DAG, backup and queue status, Exchange Online enforcement status, incidents and decisions. It ends with a short roadmap — what Microsoft has announced for SE that affects you, what technical debt is worth paying down, and an honest note when the right next step is a project rather than another month of operations.
Prerequisites
Who does what
IT Partner
- Install every Exchange SE security, hotfix and cumulative update inside the agreed window, with DAG-aware sequencing and post-update validation.
- Run Health Checker on every server monthly and remediate or formally escalate its findings.
- Maintain the certificate calendar and renew certificates before they expire.
- Check DAG, backup, queue and — for hybrid estates — Exchange Online enforcement status every month.
- Respond to intake requests within the published SLA and name, in writing, any request that falls outside the monthly scope before estimating it.
- Deliver the monthly update notes and the quarterly report, and track Microsoft's Exchange SE announcements that affect your estate.
- Use named, least-privilege accounts, keep them out of shared use, and remove them when the service ends.
Your team
- Maintain Exchange SE and Windows Server licensing, hardware, hypervisor, storage and network for the servers in scope.
- Approve update windows and out-of-band exceptions promptly — an update held past Microsoft's release leaves the server unsupported until it is installed.
- Provide and maintain the privileged-access route, the backup platform, and certificate procurement.
- Patch the Windows Server operating system on the Exchange hosts, or subscribe to IT Partner's infrastructure support for it, coordinated with the agreed windows.
- Keep a named contact for approvals and tell us early about changes — new servers, DAG changes, namespace changes, hybrid changes — that affect the estate.
- Review the quarterly report and decide on recommendations that require project work.
What's not included
Limitations & technical notes
Frequently asked questions
What is Managed Exchange Server SE Administration and Patching?
A recurring monthly service in which IT Partner operates your on-premises Exchange Server Subscription Edition servers: every Microsoft security, hotfix and cumulative update installed inside the support window, a monthly Health Checker run with findings remediated, certificate renewals, DAG, backup and transport-queue checks, Exchange Online enforcement compliance for hybrid estates, and a quarterly report. It costs $395 per server per month with no long-term commitment.
Who is this service for?
Mid-size and enterprise organizations that keep Exchange on-premises — because a regulator or contract requires mail to stay in their datacenter, because hybrid recipient management still runs through a server, or because the estate simply is not leaving — and that no longer have an engineer whose job is to keep it current. If your Exchange servers are patched when someone remembers, or your last cumulative update was installed by a contractor who has since left, this service is the missing role.
How does the per-server billing work, and what about a DAG?
The monthly bill is $395 for each Exchange SE server in scope — Mailbox and Edge Transport roles alike. A typical two- or four-member DAG is billed per member. Larger DAG estates and multi-site designs are quoted per estate, and the quote is written before onboarding so there is no surprise on the first invoice. Adding or retiring a server is handled through the intake and the bill follows the servers actually in scope that month.
What does "inside Microsoft's support window" mean for Exchange SE?
Exchange SE is serviced under Microsoft's Modern Lifecycle Policy, so there is no end-of-support date to plan around — instead Microsoft supports current builds. Microsoft's own Health Checker script marks any server that is not on one of the two most recently released cumulative updates as out of date, and reports separately whether the latest security update is installed. In practice that means installing each security and hotfix update within your agreed window after Microsoft releases it and each cumulative update before the older one drops out of the window.
Why does Exchange Online care whether my on-premises server is patched?
Because your server sends mail into Microsoft's cloud. Microsoft's Exchange team has described transport-based enforcement against persistently out-of-date on-premises Exchange servers: the server is listed in an Exchange admin center mail-flow report first, then its mail to Exchange Online is throttled, then blocked, with only a limited pause an administrator can request. For a hybrid estate that is a business-continuity issue, not a compliance footnote. This service checks the report every month and keeps your servers off it.
We are still on Exchange 2016 or 2019. Can you take us on?
Not as-is, and we will say so on the first call. Both versions reached end of support on 14 October 2025; no amount of patching makes them supported again, and Exchange Online's enforcement treats them as out of date. The honest path is an in-place upgrade from Exchange 2019 or a side-by-side migration from Exchange 2016 to Exchange SE — or a move to Exchange Online — scoped as a project. Once the servers are on SE, this service takes over from the day of handoff.
What is Health Checker, and what do you do with what it finds?
Health Checker is Microsoft's published Exchange Server diagnostic script, maintained by Microsoft's Exchange support engineers and supporting Exchange 2016, 2019 and SE. It checks build currency, security-update level, Extended Protection, AMSI integration, the Emergency Mitigation service, TLS configuration, certificates, the Exchange Online connector, the dedicated hybrid application, setting overrides, hardware and operating-system settings, and known vulnerabilities by build. We run it on every server every month and work the output: errors are fixed within the cycle or accepted by you in writing with the reason recorded, warnings are fixed or scheduled, and the trend goes into the quarterly report.
What do you do about certificates?
We keep a certificate calendar for every server — the namespace and SAN certificates bound to IIS, SMTP and other Exchange services, and the Exchange Server Auth certificate that Exchange uses for OAuth and hybrid. Certificates inside 60 days of expiry go onto the renewal plan; inside 30 days they are renewed, rebound, and coordinated with whoever runs your load balancer, reverse proxy and Edge Transport servers. You provide the certificate authority account or internal CA; we do the rest. An expired Auth certificate breaks Outlook on the web and hybrid free/busy quietly, which is why it is on the calendar by name.
Do you patch the Windows Server operating system too?
No — the operating system, firmware, hypervisor and hardware are outside this service, and we say so rather than leave it ambiguous. We do handle the Exchange prerequisites Microsoft ties to a release, such as .NET Framework and Visual C++ redistributable levels, because an Exchange update will not install without them. Operating-system patching is coordinated with our update windows and done by your team or by IT Partner's IT Infrastructure Monitoring and Support.
What happens if an update breaks something?
Exchange cumulative updates cannot be uninstalled, and security updates only partially, so the protection is upstream of the install: Microsoft's known-issues page is checked before we schedule, a verified backup exists before the change, DAG members are updated one at a time so a problem shows on one server while the others carry the load, and every server passes a validation checklist before it is handed back. If a Microsoft defect does surface, we work Microsoft's documented workaround, and where the case needs Microsoft, we escalate through IT Partner's Premier Support agreement as a paid add-on.
What access do you need to our servers?
Named accounts for our engineers — never shared credentials — in the narrowest Exchange role group that does the job: View-Only Organization Management for the Health Checker runs, Organization Management only during change windows, plus local administrator rights on the Exchange servers, reached through your VPN, jump host or privileged access workstation. For hybrid estates we also need a least-privilege GDAP role in the tenant that you approve, sufficient to read the mail-flow reports and validate connectors. The same principle we publish for cloud access applies on-premises, and the accounts are removed when the service ends.
Does this include mailbox administration or a helpdesk?
No. The fee keeps the platform current, healthy and supported; it does not include recipient and policy administration — mailboxes, permissions, groups, transport rules, retention — or troubleshooting user-reported issues. Those are on-demand hours: raised through the same intake, named as on-demand at first response, estimated in writing at IT Partner's published hourly rate, and billed only as approved. The published rate for comparable work is $175 per hour, as listed for Exchange Online Administrator on Demand; your service agreement states the rate that applies.
Do you handle Exchange SE licensing?
We verify it; we do not bundle it. Microsoft's Product Terms list Exchange Server Subscription Edition Standard and Enterprise server licenses and Standard and Enterprise CALs, held by subscription or under active Software Assurance, and Microsoft's rules decide whether your existing Microsoft 365 subscriptions cover the CAL side. At onboarding we confirm the entitlement you hold matches the servers and users in scope; if it does not, or if you want the options laid out before renewal, IT Partner's Microsoft Volume Licensing consulting is the place for it.
How does billing work, and can we stop?
Monthly, at $395 per server in scope, invoiced monthly, with no long-term contract: stop any month, and all we ask is payment of previously approved invoices. Everything the service produced stays yours — the baseline inventory, the certificate calendar, every Health Checker report, every update note and quarterly report — and our accounts are removed the day the service ends.
How quickly can the service start?
The first monthly cycle is the onboarding: accounts, the inventory, a Health Checker run on every server, backup and DAG verification, the enforcement report for hybrid estates, and the update windows. From the second cycle the service is in steady state. If IT Partner performed your Exchange SE upgrade, the baseline already exists and onboarding is largely a handover to ourselves.