Exchange Server Subscription Edition (SE) is the on-premises Exchange version that follows Exchange 2016 and 2019, which reached end of support on 14 October 2025. Getting there means an in-place upgrade or a mailbox migration, and old and new servers run side by side for a while. Monitoring tells you whether mail still flows after each step.
Mail rarely fails, so it is tempting to stop watching it. An upgrade is when problems are easiest to miss, which is why our Exchange monitoring approach treats the move as something to watch closely from start to finish.
Is Exchange 2016 or 2019 still supported?
No. Exchange Server 2016 and 2019 reached end of support on 14 October 2025, as Microsoft's lifecycle page for Exchange Server 2019 shows. Microsoft then offered a paid Extended Security Update (ESU) programme, in two periods, with security fixes only.
Paid extended security updates for Exchange 2016 and 2019 cover updates released up to the end of October 2026, and Microsoft has said there will be no further extension. After October 2026, no more updates are released for these versions, even for organisations enrolled in the second ESU period (Exchange Team reminder).
Staying put also has a mail cost in hybrid. Exchange Online throttles, then blocks, mail from out-of-date Exchange 2016 and 2019 servers that connect over an inbound connector of the OnPremises type. On 2 September 2026, Microsoft announced that from the second week of September 2026 the oldest version accepted on that connector would be the October 2025 update level, the last public one, and that at the following increase only ESU customers and Exchange SE servers would meet the bar (throttling and blocking announcement). Servers that send to Exchange Online through other connector types are outside this rule.
What is Exchange Server Subscription Edition, and which route applies to you?
Exchange SE has been available since 1 July 2025 and follows Microsoft's Modern Lifecycle Policy: there is no fixed end date as long as you stay current. It needs subscription licences or Software Assurance: on top of the server licences and CALs, either Software Assurance on them or cloud subscription licences, such as Microsoft 365 E3 or E5, for all users and devices that access Exchange SE.
Where you start decides the route, as Microsoft explains in its guide to upgrading to Exchange Server SE:
- Exchange 2019 on CU14 or CU15: the servers can be upgraded in place, much like installing a cumulative update.
- Exchange 2016: there is no in-place route. Mailboxes are migrated to new servers running Exchange SE.
Either way, old and new servers share the same organisation, namespaces and connectors for a while. That overlap is where monitoring earns its place. A fault on a server you have not touched can look like a side effect of the upgrade, and a real side effect can hide behind a server that was already unwell.
What should you record before the first server changes?
Record a baseline: the normal state of each server, measured before anything moves, so that after each step you compare against figures rather than memory. Run these checks on every server and keep the output.
- Configuration. HealthChecker.ps1, Microsoft's free script from the CSS-Exchange repository, flags configuration issues known to hurt Exchange performance. Run
.\HealthChecker.ps1 -Server MBX1for one server, or.\HealthChecker.ps1 -BuildHtmlServersReportfor an HTML report, as an administrator in the Exchange Management Shell. - Windows services. Test-ServiceHealth checks that every Windows service Exchange needs is running.
- Database copies. Get-MailboxDatabaseCopyStatus with
-Server MBX1 | Format-Listshows every copy on that server, including copy queue length and replay queue length. Without-Server, it lists every copy in the organisation. AddTest-ReplicationHealthfor members of a DAG. - Managed Availability.
Get-ServerHealth -Identity MBX1andGet-HealthReport -Identity MBX1return what Exchange's built-in monitoring has recorded for the server. - Transport queues. Note what
Get-Queueshows at a busy hour and at a quiet one, so a growing queue stands out later. - Mail flow timings. Send test messages inside the organisation, to and from the internet and, in hybrid, to and from Exchange Online, and note how long each takes.
- Client protocols. List which protocols and namespaces people use, and how many clients still connect through Outlook Anywhere.
- Certificates. Write down the expiry date of every certificate on your namespaces and connectors, starting with the Exchange Auth certificate (see below).
On the night of the upgrade, "the copy queue is at 214" means little; "214, when it is usually at zero" tells you where to look.
Which failures should you watch for while old and new servers coexist?
Watch for four kinds of failure: mail waiting in a queue, a database copy falling behind, a service that stops while the server still answers, and one client protocol failing while the others work. Each has its own check.
Mail waits in a queue
When a transport service restarts during an update, or a connector still points at a server you have just removed, messages wait in a transport queue instead of being delivered. Compare Get-Queue with your baseline after each step. Then test mail end to end, in every direction you use. A queue can also look healthy simply because no mail is reaching the server, which only an end-to-end test reveals.
A database copy falls behind
A database availability group (DAG) groups up to 16 Mailbox servers that hold copies of mailbox databases. Copy and replay queue lengths show whether passive copies keep up. During the move, databases are switched between servers and members restart, so check copy status after each step. When the work is done, confirm that each database is mounted on the server you planned, not on whichever one took over last.
A service stops while the server still answers
A server that answers on the network is not necessarily delivering mail. After each restart, run Test-ServiceHealth again and look at what Managed Availability recorded. It is Exchange's built-in monitoring and recovery: probes measure, monitors judge health, responders recover or escalate. To prove that a mailbox store answers, Test-MAPIConnectivity signs in to a mailbox and reads its inbox.
One protocol fails while the others work
Users reach Exchange through several protocols. MAPI over HTTP is the default Outlook connection protocol in current Exchange versions. Outlook on the web and Exchange ActiveSync remain part of Exchange SE. Microsoft plans to remove Outlook Anywhere (RPC over HTTP) from Exchange SE, with no date set, according to its Exchange Server roadmap update.
Load balancer and namespace changes during the move can break one protocol on one namespace while everything else looks fine. Test each protocol on each namespace, and from more than one site: a branch office on a different network path can lose Outlook while head office works. The method is the one we describe for SharePoint Online monitoring, scripted tests from the sites you choose, applied to Outlook.
Checks by phase of the move
Server names are examples. All cmdlets run in the Exchange Management Shell, on-premises.
| Phase | Check | Tool or cmdlet |
|---|---|---|
| Before | Configuration issues known to hurt performance | HealthChecker.ps1 -Server MBX1 |
| Before | Windows services that Exchange needs | Test-ServiceHealth |
| Before | Database copies, copy queue and replay queue | Get-MailboxDatabaseCopyStatus -Server MBX1, Test-ReplicationHealth |
| Before | Expiry date of the Exchange Auth certificate | Get-AuthConfig with Get-ExchangeCertificate, or MonitorExchangeAuthCertificate.ps1 |
| During | Transport queues compared with the baseline | Get-Queue |
| During | Health recorded by Managed Availability | Get-ServerHealth -Identity MBX1, Get-HealthReport -Identity MBX1 |
| During | The mailbox store answers | Test-MAPIConnectivity |
| After | OAuth between Exchange and Exchange Online | Test-OAuthConnectivity -Service EWS, result Success |
| After | Renewed Auth certificate known to the dedicated hybrid app | ConfigureExchangeHybridApplication.ps1 -UpdateCertificate |
| After | Databases mounted where you planned | Get-MailboxDatabaseCopyStatus |
Why does the Exchange Auth certificate need its own watch?
The Exchange Auth certificate is what Exchange uses for server-to-server authentication (OAuth) and for several of its security features, and in hybrid the dedicated hybrid app relies on it too. Microsoft asks you to rotate it before it expires and, if it has already expired or is missing, to replace it immediately.
Microsoft documents how to maintain the Auth certificate. To read its expiry date, run:
(Get-AuthConfig).CurrentCertificateThumbprint | Get-ExchangeCertificate | Format-List Subject, Thumbprint, NotAfter, NotBefore
NotAfter is the expiry date.
Rotate the certificate at least two days before it expires. Create the new certificate with New-ExchangeCertificate, using the parameters on Microsoft's page and answering No when asked to replace the default SMTP certificate, then declare it with Set-AuthConfig -NewCertificateThumbprint and an effective date at least 48 hours ahead with -NewCertificateEffectiveDate. Exchange switches to the new certificate once that date is reached.
Microsoft also publishes MonitorExchangeAuthCertificate.ps1 in the CSS-Exchange repository. It checks the Auth certificate, stages a new one when the current one expires within 60 days, and can run as a scheduled task with -ConfigureScriptToRunViaScheduledTask. When it detects a hybrid configuration, it does not renew unless you add -IgnoreHybridConfig, so in hybrid, plan the renewal and the step below together.
In hybrid, one more step follows a renewal: upload the renewed certificate to the dedicated hybrid app with .\ConfigureExchangeHybridApplication.ps1 -UpdateCertificate, as Microsoft's dedicated hybrid app guide describes.
What changes for Exchange hybrid in 2026 and 2027?
Rich coexistence (free/busy, MailTips, photos) runs through a dedicated hybrid app and is moving to Microsoft Graph, while Exchange Online retires Exchange Web Services (EWS). Four changes matter.
- Dedicated hybrid app. Since 31 October 2025, rich coexistence needs a dedicated hybrid app in Microsoft Entra ID, tied to the Exchange Auth certificate, which must be renewed before it expires.
- Microsoft Graph. Hybrid organisations must move rich coexistence to Graph, which requires Exchange SE with the May 2026 Hotfix Update or later. Microsoft's Graph migration post gives April 2027 as the latest date. Exchange 2016 and 2019 will not receive this update, and Microsoft states that their rich coexistence will stop working in April 2027.
- EWS in Exchange Online. Exchange Online began retiring EWS on 1 October 2026. From 10 October 2026, in the worldwide cloud, a tenant that keeps EWS enabled must list the apps allowed to use it in
EWSAllowedAppIDs, and a change to that list can take 24 hours to apply. A later phase turns EWS off for tenants that never set EWSEnabled and have no allow list, with seven days' notice in Message center (EWS deprecation post). - Gaps in Graph. As of October 2026, Graph covers free/busy and photos in hybrid, in the Global cloud only, MailTips only partly (automatic replies), and not moving items to an online archive. Hybrid organisations whose on-premises mailboxes have archives in Exchange Online must keep EWS allowed for their dedicated hybrid app until Graph covers that case (impact on hybrid).
Hybrid changes to track
Dates as published by Microsoft. Check the linked posts before each change, as these timelines can move.
| Change | Key date | What to check |
|---|---|---|
| Dedicated hybrid app in Microsoft Entra ID | Required since 31 October 2025 | The app exists and holds the current Auth certificate |
| Allow list for EWS in Exchange Online | From 10 October 2026, for tenants that keep EWS enabled | Every app that still needs EWS is listed, including the hybrid app if you use online archives |
| Rich coexistence through Microsoft Graph | April 2027 at the latest | Every server runs Exchange SE with the May 2026 Hotfix Update or later |
| Throttling of out-of-date servers | Minimum raised from the second week of September 2026, further increase announced | Every server behind an OnPremises connector is up to date |
After each hybrid change, check the link itself. Test-OAuthConnectivity -Service EWS -TargetUri https://outlook.office365.com -Mailbox followed by an on-premises mailbox should return a ResultType of Success. Then look up free/busy in both directions and send mail both ways. If something fails on the Exchange Online side, Service health lists the incidents and advisories Microsoft is working on for your tenant; our article on Microsoft 365 Service health during an outage explains how to read it.
What we see in the field
Over 15 years of monitoring projects with large enterprises, first on-premises and then in the cloud, a few patterns keep coming back with mail.
Low probability, very high impact. Many teams stop watching Exchange because it is stable. Then the day mail stops arriving, nothing else matters: email is still how organisations talk to each other, and an outage is felt far beyond IT.
Delay is a failure too. One company in the financial sector, running Exchange hybrid, handled some of its operations by email. Delays in delivery could change the outcome of some orders sent that way, so the link between mail monitoring and money was direct. It had suffered mail outages with a heavy financial impact and, outside those outages, delivery times that went past a minute.
Agree what "on time" means. As a rule of thumb, we expect internal mail to arrive within a few seconds and mail to or from the internet in under a minute. These are reference points from our experience, not a Microsoft standard. Agree your own targets with the business, then measure against them end to end.
The problem moves, it does not disappear. Moving from Exchange 2019 to SE, or from on-premises to hybrid, changes where mail can fail. It does not remove the need to watch it.
IT is often the last to know. Without end-to-end tests, the first sign of a mail problem is usually a user asking where a message went.
How Neptune helps
Neptune is an integrator. We select the monitoring tool that fits your Exchange environment, implement it with your messaging team, train your admins to read and act on it, and support you afterwards: professional services during the engagement, then customer success. We monitor the Exchange Server versions you run, on-premises and hybrid.
- Synthetic tests check internal, internet and cloud mail flow, replication and client access around the clock.
- Mailbox servers are watched for disk capacity, database health and system load.
- Client access is tested protocol by protocol and namespace by namespace.
- For database availability groups, we follow replication health and check that each database runs where it should.
- Probes on remote workstations replay common Outlook actions, so a slow site shows up in the results, not only in tickets.
- Hybrid components such as AD FS, pass-through authentication and Exchange hybrid are watched, with a warning before certificates expire.
- Reports show patch levels per server, mailbox growth, unused mailboxes and which Outlook versions still connect. Before a migration, they list unused distribution lists and public folders nobody opens, so you know what to clean up first.
- Dashboards are set up for each audience, from the helpdesk and the messaging team to the NOC and management.
We agree thresholds with your messaging team, starting from tested defaults, and check the hybrid links with you before and after each change. See our Exchange monitoring approach, or how it fits into Microsoft 365 monitoring.
Sources
- Exchange Server 2016 lifecycle
- Exchange Server 2019 lifecycle
- Exchange Server Subscription Edition lifecycle
- Reminder: Exchange 2016 and 2019 ESU program ends in October 2026
- Exchange 2016/2019: Throttling and Blocking up to the Final Public Update Baseline
- Upgrading your organization from current versions to Exchange Server SE
- Exchange Server Health Checker
- Test-ServiceHealth
- Get-MailboxDatabaseCopyStatus
- Database availability groups
- Managed Availability
- MAPI over HTTP in Exchange Server
- Exchange Server roadmap update
- Maintain the Auth certificate
- MonitorExchangeAuthCertificate.ps1
- Deploy a dedicated Exchange hybrid app
- Update your Exchange SE hybrid on-premises rich coexistence to Graph
- EWS deprecation is here: what this means to you
- Impact of Exchange Online EWS deprecation on hybrid rich coexistence and cross-org sharing