Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Dark navy graphic with a shield and envelope motif, headline Exchange 2016 and 2019 Updates Stop in October, All IT Services branding

Author: Dan Briggs  |  Published: 27 July 2026  |  Reading time: 15 minutes

Executive summary

On 20 July 2026 the Microsoft Exchange Server team published a blog post confirming that the Extended Security Update (ESU) program for Exchange Server 2016 and Exchange Server 2019 ends in October 2026, and that there will be no third extension. The exact wording was blunt: “There will be no further extension of Exchange 2016/2019 ESU program timeline. Once October 2026 ends, there will be no further updates for Exchange 2016/2019, even if you currently have a Period 2 ESU.”

Exchange Server 2016 and 2019 already reached end of support on 14 October 2025. The ESU program was the safety net. Microsoft has now removed the safety net and named the date. From November 2026, any newly discovered flaw in Exchange 2016 or 2019 stays unfixed forever.

This matters more in Australia than the headline suggests, because the servers most at risk are not the ones businesses think about. They are the leftover hybrid servers that were meant to be decommissioned after a Microsoft 365 migration and never were. Across the client environments we assess in Sydney, the Central West and Brisbane, that single forgotten server is the most common piece of unsupported infrastructure we find still connected to the internet.

Three numbers worth holding onto. Microsoft confirmed active exploitation of an Exchange OWA zero-day, CVE-2026-42897, on 14 May 2026 and only shipped the permanent fix on 9 June 2026 — a 26-day window during which Exchange 2016, 2019 and Subscription Edition were all exposed. The Shadowserver Foundation counted roughly 20,000 to 30,000 end-of-life Exchange servers reachable from the public internet as at late 2025. And under the Cyber Security Act 2024, Australian businesses with turnover above $3 million now face a civil penalty of 60 penalty units — about $19,800 — for failing to report a ransomware payment within 72 hours, with the Department of Home Affairs moving to active enforcement from 1 January 2026.

If you have any Exchange server on-premises, you have roughly 11 weeks to decide between four paths: in-place upgrade to Exchange Server Subscription Edition, full migration to Exchange Online, migration plus a free hybrid management server, or a documented, time-limited risk acceptance. Doing nothing quietly is not one of them.

What Microsoft actually said, and when

The sequence matters, because a lot of Australian businesses have been quietly betting on another reprieve.

Exchange Server 2016 left mainstream support in October 2020. Exchange Server 2019 left mainstream support in January 2024. Both products reached full end of support on 14 October 2025. At that point Microsoft did something it had not done for Exchange before: it created a paid Extended Security Update program, giving customers a way to keep receiving security fixes while they finished migrating.

In April 2026 Microsoft announced a Period 2 ESU program, extending coverage by a further six months to October 2026. That extension is what caused the confusion. The original announcement had said there would be no extensions, and then there was one — so customers reasonably started asking whether a Period 3 would appear.

The 20 July 2026 blog post exists specifically to shut that speculation down. Microsoft acknowledged the questions directly, noted that we are roughly at the midpoint of Period 2, and confirmed there will be no Period 3. Read the original at Reminder: Exchange 2016 and 2019 ESU Program Ends in October 2026 on the Microsoft Community Hub, with independent coverage from BleepingComputer on 22 July 2026.

What “no further updates” means in practice

It is worth being precise, because “end of support” gets used loosely and business owners often assume it means the software stops working. It does not.

Your Exchange server will keep running on 1 November 2026. Mail will keep flowing. Outlook will keep connecting. Nothing breaks on the day.

What stops is the supply of security patches. When a researcher — or an attacker — finds a new flaw in Exchange 2016 or 2019 after October, Microsoft will not fix it. Not for paying customers, not for ESU holders, not for anyone. The vulnerability will be published, proof-of-concept exploit code will circulate within days, and your only options will be network-level mitigations or taking the server offline.

That is a materially different risk profile from the one you have today, and it is permanent. Every month after October, the stack of known-unfixed vulnerabilities on that server grows.

Who this hits in Australia — including the server nobody remembers

There are three groups of Australian businesses affected, and they need very different conversations.

Group one: still fully on-premises

A smaller group than it used to be, but not an empty one. We still see fully on-premises Exchange in professional services firms with long-standing document management integrations, in not-for-profits running donor and case-management systems that were built against on-premises mailboxes, and in businesses that made a deliberate data-sovereignty decision years ago and never revisited it.

For this group the October deadline is a genuine project. Mailbox migration, DNS and mail-flow cutover, client reconfiguration, retraining, and often a licensing conversation that has to reach the board.

Group two: hybrid by design

Mailboxes are in Exchange Online, but an on-premises Exchange server remains in place because Active Directory is still the source of truth for user objects and directory synchronisation writes attributes back on-premises. This is a supported, deliberate architecture. It is also the one most likely to have a 2016 or 2019 server sitting in it.

Group three: the forgotten server

This is the group we care most about, and it is where we spend most of our remediation time.

The pattern is consistent enough that we now check for it on every new client assessment. A business migrated to Microsoft 365 somewhere between 2018 and 2023. The migration went well. The last Exchange server was left running “for a few weeks” to finish recipient management, handle a scan-to-email relay, or keep a line-of-business application posting mail. Then the project closed, the consultant moved on, and the server stayed.

Six years later it is still there. It is not in the patching schedule because nobody classifies it as a production mail server any more. It does not appear on the asset register under “email” because email is “in the cloud”. It survives IT provider changes because nobody wants to be the person who turns it off. And in about a third of the cases we find, it still has Outlook Web Access published to the internet, because that is how it was configured on day one and nothing ever changed.

That server is the one that will be unpatched and internet-facing in November 2026. It is also, in our experience, the most commonly missed item on cyber insurance questionnaires and Essential Eight self-assessments — not through dishonesty, but because the person filling in the form genuinely believes the business has no on-premises mail infrastructure.

Why the Central West sees more of this than Sydney

Here is a regional pattern we do not see written about much. Across Orange, Bathurst and Dubbo, on-premises servers persisted several years longer than in metropolitan Sydney, and for a straightforward reason: connectivity. Businesses that were on fixed wireless, satellite or thin ADSL through the late 2010s had a rational case for keeping mail, files and line-of-business systems local. Cloud migration was not a preference question, it was a bandwidth question.

Connectivity in those centres has improved substantially since, and most of those businesses have moved their mailboxes to Microsoft 365. But the migrations happened later, they were often done in stages, and the on-premises remnants are correspondingly newer and more entrenched. If you run a business in the Central West and you cannot immediately name every server in your comms room, that is where we would start looking.

The same applies to multi-site operations — an accounting practice with an office in Orange and one in Sydney, a not-for-profit with a Brisbane head office and regional service centres. The forgotten server is almost never at head office. It is at the site that got migrated second.

What an unpatched Exchange server actually costs you

Exchange has a specific history that makes this deadline sharper than a generic end-of-support notice.

On-premises Exchange is one of the most consistently attacked pieces of enterprise software in the world. It is internet-facing by design, it authenticates users, it holds every piece of correspondence the business has ever had, and it typically runs with elevated privileges inside Active Directory. Compromise the Exchange server and you very often own the domain.

The 2026 track record makes the point better than any argument. Microsoft confirmed on 14 May 2026 that CVE-2026-42897, a spoofing and cross-site scripting flaw in the Outlook Web Access component, was under active exploitation in the wild. The permanent fix did not ship until the June Patch Tuesday on 9 June 2026, as part of a release addressing around 200 vulnerabilities. Australian organisations running Exchange spent nearly four weeks relying on mitigations rather than a patch — and that was with a supported product and an active ESU subscription.

Run the same scenario in November. Same flaw class, same attacker interest, no patch. Ever.

The scale of the exposed population

The Shadowserver Foundation, which scans the internet daily and publishes vulnerability reporting to national CERTs including Australia’s, estimated roughly 20,000 to 30,000 end-of-life Exchange servers exposed on the public internet as at late 2025. That population has been shrinking, but slowly, and it skews towards exactly the organisations least equipped to detect a compromise: small businesses, regional operations, and sectors where a migration was deferred for budget reasons.

Attackers scan that population continuously. They do not need to find you. They find the software.

What a compromise looks like from the inside

The realistic outcome for an Australian SMB is not a dramatic ransom note on the first day. It is quieter and more expensive than that.

Typically: initial access through the unpatched service, a web shell dropped for persistence, credential harvesting from memory, lateral movement to a file server or domain controller, and then a period of weeks during which the attacker reads mail and exfiltrates data before deploying encryption. By the time you know, they have your client list, your invoices, your banking correspondence and enough context to run a convincing invoice-redirection fraud against your customers.

We have written previously about on-premises Exchange zero-days under active attack, and the pattern in those incidents is consistent. The initial flaw is rarely the expensive part. The two months of undetected access afterwards is.

For context on how this plays out at scale, Australian data-breach notifications reached 1,205 in 2025, an all-time high, with 59 per cent attributed to malicious or criminal attack. We covered the implications of that in our analysis of the record 2025 notification figures. The Office of the Australian Information Commissioner’s most recent published half-year figures, covering January to June 2025, recorded 532 notifications, with malicious or criminal attack accounting for 308 of them, and an average of just over 10,000 individuals affected per cyber incident.

Where this collides with Australian regulation and insurance

The technical argument for acting is strong on its own. The compliance argument closes it.

Privacy Act and Australian Privacy Principle 11

APP 11 requires you to take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. Knowingly running mail infrastructure that can no longer receive security patches, when a supported path exists and you have had twelve months’ notice, is difficult to characterise as reasonable steps.

If a breach occurs and the OAIC investigates, the question will not be whether you were unlucky. It will be what you knew about the end-of-support date and what you did about it. A dated decision record showing you assessed the risk and chose a path — even a path of temporary, mitigated risk acceptance — is a materially better position than nothing.

The Essential Eight, and what replaces it

Both “patch applications” and “patch operating systems” under the Essential Eight require that products no longer supported by vendors are removed from the environment. There is no maturity level at which running unsupported, internet-facing Exchange is compliant. Not Maturity Level One, not any of them.

This is also happening against a moving backdrop. On 24 June 2026 the Australian Signals Directorate confirmed a staged transition away from the Essential Eight towards a new Essentials series, with the current framework to begin deprecation in roughly twelve months and be retired in roughly twenty-four. We set out what that means for planning in our guide to the Essential Eight retirement. The direction of travel is towards outcome-based guidance rather than a control checklist — but “do not run unsupported software exposed to the internet” survives that transition intact.

Ransomware payment reporting

Under the Cyber Security Act 2024, businesses with annual turnover above $3 million, and entities responsible for critical infrastructure assets, must report any ransomware or cyber extortion payment to the Department of Home Affairs within 72 hours of making it. The education-first grace period ran from 30 May 2025 to 31 December 2025. From 1 January 2026 the Department moved to active enforcement, and non-compliance risks regulatory action as a matter of routine. The civil penalty is 60 penalty units, currently around $19,800.

The connection to Exchange is direct: an unpatched mail server is one of the more probable routes to the incident that triggers that obligation, and the 72-hour clock starts at payment, not at discovery.

Cyber insurance

This is the one that catches Australian SMBs off guard most often. Cyber policies increasingly include conditions or exclusions relating to unsupported software, and renewal questionnaires increasingly ask about it explicitly. Two practical consequences:

  • If you answered “no” to a question about unsupported software at your last renewal, and a forgotten Exchange 2016 server was running at the time, you may have a disclosure problem independent of any breach.
  • If you renew after October 2026 with an unpatched Exchange server still in place and you disclose it, expect either an exclusion for incidents originating from that server, or a materially higher premium.

Check the wording before your next renewal date, not after.

Your four options, compared

There are exactly four defensible responses. Pick one deliberately and write down why.

Option Best suited to Typical effort Key considerations Decide by
1. In-place upgrade to Exchange Server Subscription Edition Businesses committed to staying on-premises for regulatory, sovereignty or integration reasons Low to moderate — for Exchange 2019 on CU14 or CU15 the upgrade installs like a cumulative update Requires a subscription licensing model with Software Assurance or qualifying Microsoft 365 subscriptions; Exchange 2016 must go via CU23 legacy upgrade or step through 2019 first; hardware and Windows Server version must meet SE requirements Mid-August 2026
2. Full migration to Exchange Online Most Australian SMBs, especially professional services, hospitality and not-for-profits already licensed for Microsoft 365 Moderate to high, depending on mailbox count, public folders and application dependencies Removes the patching obligation entirely; must resolve scan-to-email, application relay and any remaining directory dependencies; allow time for user communication and training Early August 2026 to finish comfortably
3. Migrate mailboxes, keep a supported management server Businesses with Active Directory as the authoritative directory and ongoing directory synchronisation Moderate A free hybrid licence is available through the Hybrid Configuration Wizard for servers used solely for recipient management, but updates still require active Software Assurance or qualifying cloud subscriptions; consider whether the management server needs any internet exposure at all Mid-August 2026
4. Documented, time-limited risk acceptance Only where a genuine blocker exists — an unsupported line-of-business dependency with a contracted replacement date Low technical effort, high governance effort Requires board or owner sign-off, a hard end date, compensating controls, insurer disclosure, and monitoring; this is a bridge, not a destination Immediately, with review monthly

A note on cost, offered as an observation rather than a quote. In the migrations we have run for Australian SMBs over the past two years, the labour cost of a planned, off-peak Exchange migration has consistently come in well below the cost of a single day of unplanned downtime for the same business, and an order of magnitude below the cost of an incident response engagement. The businesses that end up paying the most are not the ones with the biggest environments. They are the ones that left it until October.

One more timing factor specific to this year: Microsoft 365 prices rose globally on 1 July 2026 across Business Basic, Business Standard, Business Premium, E3, E5 and F3. If you are adding licences as part of a migration, the new rates apply. Budget accordingly rather than working from a quote written in June.

The hybrid trap, and the free licence most businesses miss

Hybrid deployments deserve their own section because the guidance here is genuinely confusing and the money involved is real.

If your organisation synchronises identities from on-premises Active Directory to Microsoft Entra ID, Active Directory remains the source of truth for user attributes. Historically that meant you needed at least one on-premises Exchange server to create and modify mail-enabled recipients in a supported way, even though every mailbox lived in the cloud.

Two things have changed that are worth knowing.

First, Microsoft has made it possible to manage Exchange recipient properties on-premises using the Exchange Management tools with PowerShell, without running a full Exchange server. For some organisations that removes the need for the server entirely.

Second, where a server is still required, Microsoft continues to provide a free licence through the Hybrid Configuration Wizard for a server used exclusively for recipient management. The critical caveat, and the part most businesses miss: the licence is free, but receiving security updates for that server still requires active Software Assurance or qualifying cloud subscriptions. A free hybrid licence does not mean a free ride on patching after October 2026.

Three practical questions to answer about your hybrid server:

  1. Does it need to exist at all? If your only remaining use is occasional attribute edits, the management-tools-only path may close the question permanently.
  2. Does it need to be reachable from the internet? A recipient-management server has no legitimate reason to publish Outlook Web Access or Exchange Web Services externally. Removing that publication removes most of the attack surface immediately, and it is a change you can make this week regardless of which longer-term option you choose.
  3. Is it covered for updates? Confirm the Software Assurance or subscription position before you assume the free licence protects you.

While you are in there, check what else is still relaying mail through that server. Multifunction printers configured for scan-to-email are the usual answer, and they are already on a separate deadline — we covered the authentication changes affecting them in our piece on basic authentication being switched off for scan-to-email. If you are touching mail flow anyway, resolve both at once rather than doing the same discovery work twice.

A realistic timeline from now to October

From the last Monday in July, there are roughly eleven working weeks before the end of October. Here is how we would sequence it.

Period Focus Outcome you should have
Week 1 — late July Discovery A written list of every Exchange server in the environment, its version and cumulative update level, whether it is published to the internet, and what depends on it
Week 2 — early August Immediate risk reduction Unnecessary external publication removed, current ESU coverage confirmed, multi-factor authentication verified on all administrative accounts, backups tested
Weeks 3 to 4 — August Decision Option selected from the four above, budget approved, dependencies documented, decision recorded with a date and a sign-off
Weeks 5 to 8 — late August to September Execution Migration or upgrade performed in stages, with a pilot group first; application and printer relays reconfigured; user communications sent
Weeks 9 to 10 — early October Decommission Legacy server shut down but not yet destroyed, DNS and firewall rules cleaned up, monitoring confirmed
Week 11 — late October Close out Asset register and network diagram updated, insurer questionnaire answers corrected, Essential Eight or Essentials assessment refreshed, server decommissioned permanently after a hold period

Two scheduling realities to build in. Australian SMBs generally cannot cut over mail during the working week, so plan around weekends and expect the end of the financial quarter to compete for the same attention. And if your business is in hospitality or retail, September and October are not quiet months — bring the work forward rather than assuming there will be a gap.

The 12-point checklist to run this week

You can complete most of this in a couple of hours. Do it before you think about budgets or vendors.

  1. Inventory every Exchange server. Include virtual machines that are powered off but not deleted, and servers at branch or regional sites. Do not rely on memory — query Active Directory for Exchange server objects.
  2. Record the exact version and cumulative update level for each. Exchange 2019 on CU14 or CU15 has the easiest upgrade path to Subscription Edition.
  3. Confirm whether you hold Period 2 ESU coverage and when it expires. If you do not, you are already unpatched.
  4. Check what is published to the internet. Test Outlook Web Access, Exchange Web Services and ActiveSync URLs from outside your network. If they respond, they are being scanned.
  5. Identify every dependency. Printers, scanners, CRM and practice management systems, backup software, alerting tools, and any application configured to relay mail.
  6. Verify multi-factor authentication on every account with Exchange administrative rights, and remove standing administrative access that is no longer needed.
  7. Test a mailbox restore from backup. Not a backup report — an actual restore.
  8. Review your cyber insurance policy for unsupported-software conditions or exclusions, and check what you declared at last renewal.
  9. Check your Software Assurance or subscription position if you are considering Exchange Server Subscription Edition or a free hybrid licence.
  10. Look for other end-of-support software in the same wave. SharePoint Server 2016 and 2019 reached end of extended support on 14 July 2026, so if you have one, you may well have the other.
  11. Assign a named owner with a decision deadline in writing. Unowned servers are how this situation happened in the first place.
  12. Record the decision. Whichever path you choose, document what you assessed, when, and who approved it. This is the artefact that protects you if something goes wrong later.

Five mistakes we keep seeing in Australian migrations

Turning the server off without decommissioning it properly

Shutting down an Exchange server is not the same as removing it. An improperly removed server leaves Active Directory objects, DNS records, firewall rules and autodiscover entries behind. Those artefacts cause support problems for years and can mask the fact that the server still exists. Follow the supported uninstall process.

Forgetting the printers until cutover night

Scan-to-email is the most common cause of a migration weekend running long. Every multifunction device relaying through the old server needs new configuration, and in a practice with devices across several floors or sites, that is a half-day of work on its own. Discover them in week one, not at 11pm on a Saturday.

Migrating mailboxes but not archives or public folders

Public folders in particular tend to be forgotten because nobody has looked at them since 2014, right up until the moment someone needs the contents. Audit them early and decide explicitly whether to migrate, export or discard.

Assuming a cloud mailbox means the compliance work is done

Moving to Exchange Online changes where mail lives, not what your obligations are. Retention, legal hold, mailbox auditing and data-loss prevention all need to be configured deliberately in the new environment. The defaults are not your policy.

Leaving no controls on the decommissioned host

If you retain the server in a powered-off state during a hold period, make sure it cannot be started and reconnected by someone doing housekeeping six months later. We have seen exactly that happen, and a server that reappears on the network after its patching stopped is worse than one that never left.

Where to start, and how we can help

If you take one thing from this, make it the discovery step. Most Australian businesses we speak to are confident they have no on-premises Exchange, and a meaningful minority turn out to be wrong. The cost of checking is an hour. The cost of being wrong in November is measured in weeks of disruption and a conversation with the OAIC.

All IT Services works with businesses across Sydney and the Northern Beaches, the Central West of New South Wales including Orange, Bathurst and Dubbo, Brisbane and Melbourne. We run Exchange discovery assessments, in-place upgrades to Exchange Server Subscription Edition, full migrations to Exchange Online, and supported decommissioning of legacy servers — including the ones that were meant to be switched off years ago.

If you are not sure what is running in your comms room, or you want a second opinion on which of the four options fits your business, call us on 1300 425 548 or get in touch through our contact page. An initial discovery conversation takes about twenty minutes and will tell you whether you have a project on your hands or nothing to worry about.

Frequently asked questions

Will our email stop working in November 2026?

No. Exchange Server 2016 and 2019 will keep running and mail will keep flowing after October 2026. What stops is the supply of security updates. Any vulnerability discovered from November onwards will never be patched by Microsoft, so the server becomes progressively more exposed each month it stays online.

We moved to Microsoft 365 years ago. Does this affect us?

Possibly, and it is worth ten minutes to check. Many businesses that migrated to Microsoft 365 left one on-premises Exchange server running for recipient management, mail relay or a line-of-business application, and never removed it. Query Active Directory for Exchange server objects rather than relying on memory, and check whether anything is still published to the internet.

Is Exchange Server Subscription Edition just another version we will have to replace?

Not in the same way. Subscription Edition follows a continuous servicing model rather than a fixed end-of-support date, so as long as your subscription and Software Assurance position stays current, you keep receiving updates. It became generally available on 1 July 2025 and can be installed as an in-place upgrade from Exchange Server 2019 CU14 or CU15.

Can we just buy another year of extended security updates?

No. Microsoft stated on 20 July 2026 that there will be no further extension of the Exchange 2016 and 2019 ESU program, and that no updates will be issued after October 2026 even for customers who hold a Period 2 ESU. There is no Period 3 to purchase.

What happens to our cyber insurance if we miss the deadline?

That depends on your policy wording, so read it before your renewal date. Many cyber policies now carry conditions or exclusions relating to unsupported software, and renewal questionnaires commonly ask about it. If you keep an unpatched Exchange server past October 2026, expect either an exclusion covering incidents that originate from it or a higher premium, and make sure your disclosures are accurate either way.