Monitoring

Exchange Server Subscription Edition: what to monitor when you leave Exchange 2016 and 2019

Exchange 2016 and 2019 are out of support and hybrid is changing under your feet. What to record before you move to Exchange SE, which failures to watch while old and new servers coexist, and which hybrid changes to check, with the Microsoft cmdlets for each step.

11 min read Neptune Group

Navy illustration: an example Exchange Auth certificate that expires in 18 days, flagged in coral, above a row of upgrade checks: internal mail 4 s, DAG copy queue 0, client access passing and mail to Exchange Online 38 s.

Exchange Server Subscription Edition (SE) is the on-premises Exchange version that follows Exchange 2016 and 2019, which reached end of support on 14 October 2025. Getting there means an in-place upgrade or a mailbox migration, and old and new servers run side by side for a while. Monitoring tells you whether mail still flows after each step.

Mail rarely fails, so it is tempting to stop watching it. An upgrade is when problems are easiest to miss, which is why our Exchange monitoring approach treats the move as something to watch closely from start to finish.

Is Exchange 2016 or 2019 still supported?

No. Exchange Server 2016 and 2019 reached end of support on 14 October 2025, as Microsoft's lifecycle page for Exchange Server 2019 shows. Microsoft then offered a paid Extended Security Update (ESU) programme, in two periods, with security fixes only.

Paid extended security updates for Exchange 2016 and 2019 cover updates released up to the end of October 2026, and Microsoft has said there will be no further extension. After October 2026, no more updates are released for these versions, even for organisations enrolled in the second ESU period (Exchange Team reminder).

Staying put also has a mail cost in hybrid. Exchange Online throttles, then blocks, mail from out-of-date Exchange 2016 and 2019 servers that connect over an inbound connector of the OnPremises type. On 2 September 2026, Microsoft announced that from the second week of September 2026 the oldest version accepted on that connector would be the October 2025 update level, the last public one, and that at the following increase only ESU customers and Exchange SE servers would meet the bar (throttling and blocking announcement). Servers that send to Exchange Online through other connector types are outside this rule.

What is Exchange Server Subscription Edition, and which route applies to you?

Exchange SE has been available since 1 July 2025 and follows Microsoft's Modern Lifecycle Policy: there is no fixed end date as long as you stay current. It needs subscription licences or Software Assurance: on top of the server licences and CALs, either Software Assurance on them or cloud subscription licences, such as Microsoft 365 E3 or E5, for all users and devices that access Exchange SE.

Where you start decides the route, as Microsoft explains in its guide to upgrading to Exchange Server SE:

  • Exchange 2019 on CU14 or CU15: the servers can be upgraded in place, much like installing a cumulative update.
  • Exchange 2016: there is no in-place route. Mailboxes are migrated to new servers running Exchange SE.

Either way, old and new servers share the same organisation, namespaces and connectors for a while. That overlap is where monitoring earns its place. A fault on a server you have not touched can look like a side effect of the upgrade, and a real side effect can hide behind a server that was already unwell.

What should you record before the first server changes?

Record a baseline: the normal state of each server, measured before anything moves, so that after each step you compare against figures rather than memory. Run these checks on every server and keep the output.

  1. Configuration. HealthChecker.ps1, Microsoft's free script from the CSS-Exchange repository, flags configuration issues known to hurt Exchange performance. Run .\HealthChecker.ps1 -Server MBX1 for one server, or .\HealthChecker.ps1 -BuildHtmlServersReport for an HTML report, as an administrator in the Exchange Management Shell.
  2. Windows services. Test-ServiceHealth checks that every Windows service Exchange needs is running.
  3. Database copies. Get-MailboxDatabaseCopyStatus with -Server MBX1 | Format-List shows every copy on that server, including copy queue length and replay queue length. Without -Server, it lists every copy in the organisation. Add Test-ReplicationHealth for members of a DAG.
  4. Managed Availability. Get-ServerHealth -Identity MBX1 and Get-HealthReport -Identity MBX1 return what Exchange's built-in monitoring has recorded for the server.
  5. Transport queues. Note what Get-Queue shows at a busy hour and at a quiet one, so a growing queue stands out later.
  6. Mail flow timings. Send test messages inside the organisation, to and from the internet and, in hybrid, to and from Exchange Online, and note how long each takes.
  7. Client protocols. List which protocols and namespaces people use, and how many clients still connect through Outlook Anywhere.
  8. Certificates. Write down the expiry date of every certificate on your namespaces and connectors, starting with the Exchange Auth certificate (see below).

On the night of the upgrade, "the copy queue is at 214" means little; "214, when it is usually at zero" tells you where to look.

Which failures should you watch for while old and new servers coexist?

Watch for four kinds of failure: mail waiting in a queue, a database copy falling behind, a service that stops while the server still answers, and one client protocol failing while the others work. Each has its own check.

Mail waits in a queue

When a transport service restarts during an update, or a connector still points at a server you have just removed, messages wait in a transport queue instead of being delivered. Compare Get-Queue with your baseline after each step. Then test mail end to end, in every direction you use. A queue can also look healthy simply because no mail is reaching the server, which only an end-to-end test reveals.

A database copy falls behind

A database availability group (DAG) groups up to 16 Mailbox servers that hold copies of mailbox databases. Copy and replay queue lengths show whether passive copies keep up. During the move, databases are switched between servers and members restart, so check copy status after each step. When the work is done, confirm that each database is mounted on the server you planned, not on whichever one took over last.

A service stops while the server still answers

A server that answers on the network is not necessarily delivering mail. After each restart, run Test-ServiceHealth again and look at what Managed Availability recorded. It is Exchange's built-in monitoring and recovery: probes measure, monitors judge health, responders recover or escalate. To prove that a mailbox store answers, Test-MAPIConnectivity signs in to a mailbox and reads its inbox.

One protocol fails while the others work

Users reach Exchange through several protocols. MAPI over HTTP is the default Outlook connection protocol in current Exchange versions. Outlook on the web and Exchange ActiveSync remain part of Exchange SE. Microsoft plans to remove Outlook Anywhere (RPC over HTTP) from Exchange SE, with no date set, according to its Exchange Server roadmap update.

Load balancer and namespace changes during the move can break one protocol on one namespace while everything else looks fine. Test each protocol on each namespace, and from more than one site: a branch office on a different network path can lose Outlook while head office works. The method is the one we describe for SharePoint Online monitoring, scripted tests from the sites you choose, applied to Outlook.

Checks by phase of the move

Server names are examples. All cmdlets run in the Exchange Management Shell, on-premises.

PhaseCheckTool or cmdlet
Before Configuration issues known to hurt performance HealthChecker.ps1 -Server MBX1
Before Windows services that Exchange needs Test-ServiceHealth
Before Database copies, copy queue and replay queue Get-MailboxDatabaseCopyStatus -Server MBX1, Test-ReplicationHealth
Before Expiry date of the Exchange Auth certificate Get-AuthConfig with Get-ExchangeCertificate, or MonitorExchangeAuthCertificate.ps1
During Transport queues compared with the baseline Get-Queue
During Health recorded by Managed Availability Get-ServerHealth -Identity MBX1, Get-HealthReport -Identity MBX1
During The mailbox store answers Test-MAPIConnectivity
After OAuth between Exchange and Exchange Online Test-OAuthConnectivity -Service EWS, result Success
After Renewed Auth certificate known to the dedicated hybrid app ConfigureExchangeHybridApplication.ps1 -UpdateCertificate
After Databases mounted where you planned Get-MailboxDatabaseCopyStatus

Why does the Exchange Auth certificate need its own watch?

The Exchange Auth certificate is what Exchange uses for server-to-server authentication (OAuth) and for several of its security features, and in hybrid the dedicated hybrid app relies on it too. Microsoft asks you to rotate it before it expires and, if it has already expired or is missing, to replace it immediately.

Microsoft documents how to maintain the Auth certificate. To read its expiry date, run:

(Get-AuthConfig).CurrentCertificateThumbprint | Get-ExchangeCertificate | Format-List Subject, Thumbprint, NotAfter, NotBefore

NotAfter is the expiry date.

Rotate the certificate at least two days before it expires. Create the new certificate with New-ExchangeCertificate, using the parameters on Microsoft's page and answering No when asked to replace the default SMTP certificate, then declare it with Set-AuthConfig -NewCertificateThumbprint and an effective date at least 48 hours ahead with -NewCertificateEffectiveDate. Exchange switches to the new certificate once that date is reached.

Microsoft also publishes MonitorExchangeAuthCertificate.ps1 in the CSS-Exchange repository. It checks the Auth certificate, stages a new one when the current one expires within 60 days, and can run as a scheduled task with -ConfigureScriptToRunViaScheduledTask. When it detects a hybrid configuration, it does not renew unless you add -IgnoreHybridConfig, so in hybrid, plan the renewal and the step below together.

In hybrid, one more step follows a renewal: upload the renewed certificate to the dedicated hybrid app with .\ConfigureExchangeHybridApplication.ps1 -UpdateCertificate, as Microsoft's dedicated hybrid app guide describes.

What changes for Exchange hybrid in 2026 and 2027?

Rich coexistence (free/busy, MailTips, photos) runs through a dedicated hybrid app and is moving to Microsoft Graph, while Exchange Online retires Exchange Web Services (EWS). Four changes matter.

  • Dedicated hybrid app. Since 31 October 2025, rich coexistence needs a dedicated hybrid app in Microsoft Entra ID, tied to the Exchange Auth certificate, which must be renewed before it expires.
  • Microsoft Graph. Hybrid organisations must move rich coexistence to Graph, which requires Exchange SE with the May 2026 Hotfix Update or later. Microsoft's Graph migration post gives April 2027 as the latest date. Exchange 2016 and 2019 will not receive this update, and Microsoft states that their rich coexistence will stop working in April 2027.
  • EWS in Exchange Online. Exchange Online began retiring EWS on 1 October 2026. From 10 October 2026, in the worldwide cloud, a tenant that keeps EWS enabled must list the apps allowed to use it in EWSAllowedAppIDs, and a change to that list can take 24 hours to apply. A later phase turns EWS off for tenants that never set EWSEnabled and have no allow list, with seven days' notice in Message center (EWS deprecation post).
  • Gaps in Graph. As of October 2026, Graph covers free/busy and photos in hybrid, in the Global cloud only, MailTips only partly (automatic replies), and not moving items to an online archive. Hybrid organisations whose on-premises mailboxes have archives in Exchange Online must keep EWS allowed for their dedicated hybrid app until Graph covers that case (impact on hybrid).

Hybrid changes to track

Dates as published by Microsoft. Check the linked posts before each change, as these timelines can move.

ChangeKey dateWhat to check
Dedicated hybrid app in Microsoft Entra ID Required since 31 October 2025 The app exists and holds the current Auth certificate
Allow list for EWS in Exchange Online From 10 October 2026, for tenants that keep EWS enabled Every app that still needs EWS is listed, including the hybrid app if you use online archives
Rich coexistence through Microsoft Graph April 2027 at the latest Every server runs Exchange SE with the May 2026 Hotfix Update or later
Throttling of out-of-date servers Minimum raised from the second week of September 2026, further increase announced Every server behind an OnPremises connector is up to date

After each hybrid change, check the link itself. Test-OAuthConnectivity -Service EWS -TargetUri https://outlook.office365.com -Mailbox followed by an on-premises mailbox should return a ResultType of Success. Then look up free/busy in both directions and send mail both ways. If something fails on the Exchange Online side, Service health lists the incidents and advisories Microsoft is working on for your tenant; our article on Microsoft 365 Service health during an outage explains how to read it.

What we see in the field

Over 15 years of monitoring projects with large enterprises, first on-premises and then in the cloud, a few patterns keep coming back with mail.

Low probability, very high impact. Many teams stop watching Exchange because it is stable. Then the day mail stops arriving, nothing else matters: email is still how organisations talk to each other, and an outage is felt far beyond IT.

Delay is a failure too. One company in the financial sector, running Exchange hybrid, handled some of its operations by email. Delays in delivery could change the outcome of some orders sent that way, so the link between mail monitoring and money was direct. It had suffered mail outages with a heavy financial impact and, outside those outages, delivery times that went past a minute.

Agree what "on time" means. As a rule of thumb, we expect internal mail to arrive within a few seconds and mail to or from the internet in under a minute. These are reference points from our experience, not a Microsoft standard. Agree your own targets with the business, then measure against them end to end.

The problem moves, it does not disappear. Moving from Exchange 2019 to SE, or from on-premises to hybrid, changes where mail can fail. It does not remove the need to watch it.

IT is often the last to know. Without end-to-end tests, the first sign of a mail problem is usually a user asking where a message went.

How Neptune helps

Neptune is an integrator. We select the monitoring tool that fits your Exchange environment, implement it with your messaging team, train your admins to read and act on it, and support you afterwards: professional services during the engagement, then customer success. We monitor the Exchange Server versions you run, on-premises and hybrid.

  • Synthetic tests check internal, internet and cloud mail flow, replication and client access around the clock.
  • Mailbox servers are watched for disk capacity, database health and system load.
  • Client access is tested protocol by protocol and namespace by namespace.
  • For database availability groups, we follow replication health and check that each database runs where it should.
  • Probes on remote workstations replay common Outlook actions, so a slow site shows up in the results, not only in tickets.
  • Hybrid components such as AD FS, pass-through authentication and Exchange hybrid are watched, with a warning before certificates expire.
  • Reports show patch levels per server, mailbox growth, unused mailboxes and which Outlook versions still connect. Before a migration, they list unused distribution lists and public folders nobody opens, so you know what to clean up first.
  • Dashboards are set up for each audience, from the helpdesk and the messaging team to the NOC and management.

We agree thresholds with your messaging team, starting from tested defaults, and check the hybrid links with you before and after each change. See our Exchange monitoring approach, or how it fits into Microsoft 365 monitoring.

Sources

Moving to Exchange SE, or running Exchange hybrid? See how we monitor Exchange on-premises and hybrid.

FAQ

Questions on this topic

Is Exchange Server 2019 still supported?

No. Exchange Server 2016 and 2019 reached end of support on 14 October 2025. Paid extended security updates for both cover updates released up to the end of October 2026, with no further extension, so no updates are released for them after October 2026. Exchange Server Subscription Edition (SE), available since 1 July 2025, is the version to move to.

Can I upgrade Exchange 2019 to Exchange SE in place?

Yes, if your Exchange 2019 servers run CU14 or CU15: the upgrade installs much like a cumulative update. Exchange 2016 has no in-place route, so its mailboxes move to new servers running Exchange SE. In both cases, take a baseline first with HealthChecker.ps1 and the usual cmdlets, and watch queues and database copies after each step.

Do I need new licences for Exchange Server Subscription Edition?

Exchange SE needs subscription licences or Software Assurance. On top of server licences and client access licences, you need either active Software Assurance on them or cloud subscription licences for all users and devices that access Exchange SE. It follows Microsoft's Modern Lifecycle Policy, so it has no fixed end date as long as you keep it up to date. Check your current agreement with your licensing partner before you plan the upgrade.

What happens to Exchange hybrid if we stay on Exchange 2016 or 2019?

Rich coexistence is moving to Microsoft Graph, which requires Exchange SE, and Microsoft states that rich coexistence for Exchange 2016 and 2019 will stop working in April 2027. Exchange Online also throttles, then blocks, mail from out-of-date Exchange 2016 and 2019 servers on OnPremises connectors, and Microsoft announced on 2 September 2026 that, after the following increase of the minimum version, only ESU customers and Exchange SE would meet it.

What does HealthChecker.ps1 check?

HealthChecker.ps1 is Microsoft's free script from the CSS-Exchange repository. It flags configuration issues known to hurt Exchange performance. Run it as an administrator in the Exchange Management Shell, with -Server for one server or -BuildHtmlServersReport for an HTML report across servers. Run it before an upgrade to fix known issues first, and keep the output as part of your baseline.

How do I check when the Exchange Auth certificate expires?

Pipe the thumbprint from Get-AuthConfig into Get-ExchangeCertificate and read the NotAfter value, which is the expiry date. Renew it at least two days ahead, because the new certificate only takes over on an effective date set at least 48 hours later. Microsoft's MonitorExchangeAuthCertificate.ps1 can run the check and the renewal as a scheduled task; in hybrid, it renews only with -IgnoreHybridConfig.

Have a question about your own tenant?

Tell us what you are working on and we will tell you where we would start.