The End of On-Prem Exchange: Subscription Edition or a Move to the Cloud?

TL;DR: An out-of-support Exchange server is the most dangerous legacy system a business can run, because a mail server is internet-facing by definition. Two exits exist: staying on-premises with the new Exchange Server Subscription Edition, or migrating to Exchange Online. For most SMBs the economic and operational answer is the cloud; staying on-prem now needs a specific justification, not inertia.
For businesses hosting their own Exchange, the calendar has run out: Exchange Server 2016 and 2019 stopped receiving security updates in October 2025 — the same day as Windows 10, but the two events do not carry the same weight. An office PC sits behind the firewall; a mail server is internet-facing by definition, because accepting email from the entire world is its job. The mass-exploitation waves that targeted Exchange in past years showed painfully how an unpatched mail server sits at the top of attackers' target lists. Running Exchange without support is therefore not "risky" — it is indefensible.
The Fork: Two Options Remain
Microsoft has ended Exchange's perpetual-licence era; the on-prem successor to 2016/2019 ships as Exchange Server Subscription Edition (SE) under a subscription model. The decision is no longer "buy a licence and run it for a decade" versus cloud — it is between two subscriptions: do you operate the subscription on your own hardware, or in Microsoft's data centre?
Option 1: Exchange Online (Microsoft 365)
Mailboxes move to Microsoft's infrastructure; server maintenance, patch schedules, disk growth and version migrations cease to be your problems. Security patching stops being your night shift. At SMB scale the total cost usually lands below on-prem operation, because the honest calculation includes not just licences but server hardware, backup, power and cooling — and the most expensive line of all, specialist time.
Option 2: Staying On-Prem with Exchange SE
Estates with data-residency obligations, integrations that cannot move, or very specific compliance requirements can continue on-premises. The move from 2019 to SE is technically smooth (in-place upgrade logic); coming from 2016 requires an intermediate step. But it must be a conscious choice: patch discipline, hardening of internet-facing services and mail backup responsibility remain entirely yours.
The Decision Table
| Criterion | Exchange Online | Exchange SE (on-prem) |
|---|---|---|
| Patching and security responsibility | Microsoft's | Yours — a critical load on an internet-facing server |
| Hardware/infrastructure cost | None | Server + storage + backup continue |
| Data-residency control | Limited to region selection | Full control — the main reason for those who need it |
| Downtime/version-migration burden | Invisible, in the background | Planned off-hours work, on you |
| Economy of scale (5–100 mailboxes) | Strong | Weak — fixed costs divided by few mailboxes |
| Custom integrations / legacy application ties | Sometimes a constraint | Flexible |
If Migration Is the Decision: the Healthy Sequence
- 1. Mailbox inventory: mailbox counts and sizes, shared mailboxes, distribution groups, and the systems that send mail from applications (scanners, ERP notifications, web forms) — these machine accounts are migration's most forgotten line.
- 2. Domain and DNS records: plan the MX cutover; re-verify SPF/DKIM/DMARC against the new infrastructure — your sending reputation on migration day depends on those records.
- 3. Staged moves: start with pilot mailboxes; schedule move waves off-hours and manage the coexistence period where old and new run side by side.
- 4. Retiring the old server: when migration completes, decommission the on-prem Exchange properly — not "switch off and forget"; leaving no internet-facing remnant services is part of the security work.
What "Carrying On Without Support" Really Means
We do not pretend the "let's stretch it a little longer" option is off the table; it exists in the field, and its picture is precise: an internet-facing, unpatched server holding the entirety of your corporate correspondence. A large share of ransomware incidents begin with email; when the target is the mail server itself, the attacker's path shortens by a full step. Operating with that picture is not an IT decision — it is a board-level risk acceptance, and it should not continue without one in writing.
Yamanlar Bilişim's Role in This Transition
Exchange projects start with a photograph of the current estate: version, mailbox inventory, internet-facing services, integrations. The decision meeting receives a cost-and-risk table for both scenarios specific to you; if migration wins, the move waves, record changes and the old server's safe retirement run as a single project. Where staying on-prem has a genuine justification, the SE transition and hardening are planned instead. Email infrastructure is a standing checklist item in our maintenance agreements.
FAQ
Frequently Asked Questions
Exchange 2019 runs fine — why touch it?
Because looking fine is the inheritance of the years it received patches. With support ended, every vulnerability discovered from now on stays open permanently — and Exchange vulnerabilities have historically turned into mass exploitation within days. On a mail server, the gap between "runs" and "safe" is wider than on any other system.
Do we lose our old email if we move to Exchange Online?
No; mailboxes migrate with their full history. In a properly planned migration, users open their computers in the morning to the same emails, folders and calendars on the new infrastructure.
Our printers and ERP send email — what happens to them?
Those "application accounts" are the critical rows of the migration inventory. Each one gets a new sending method (an authenticated account or a relay rule) and is tested individually on migration day. Skip them and invoice notifications, scan-to-email and form mails stop silently — most migration complaints originate exactly here.
Instead of an SE subscription, can we keep 2019 on an isolated network?
A mail server has no business on an isolated network; an Exchange that receives no email has lost its purpose. A fully isolated archival copy can be kept briefly — but for production mail flow, "isolated network" is not an option.
How long does the migration take?
A typical SMB project runs a few weeks including inventory and preparation, and per-user downtime approaches zero with the right plan. Duration is driven less by mailbox count than by data volume, integration diversity and what the pilot uncovers.
Author
Serdar YAMAN
Yamanlar Bilişim Expert
Writes content on IT infrastructure, cybersecurity, and digital transformation at Yamanlar Bilişim. Get in touch for any questions.
Professional Support
Get help on this topic
Let's design the Email and Messaging solution you need together. Our experts get back to you within 1 business day.
support@yamanlarbilisim.com · Response time: 1 business day
Keep Reading
Related Articles

Starting a Company from Zero: the Domain and Business Email Setup Guide
A new company's digital identity starts with two stones: a properly registered domain and business email built right on day one. Ownership traps, platform choice, mailbox structure and the authentication records — one guide for all of it.

Keep Your Email Out of the Spam Folder with DMARC, SPF, and DKIM
When a proposal you send to a customer lands in the spam folder, it means a lost sale. When DMARC, SPF, and DKIM records are configured correctly, email delivery rates improve markedly.

Microsoft 365 or Google Workspace? An SME Comparison
The two major cloud office suites offer similar functions with different experiences. Price, ecosystem, integration, and team habits determine the right choice. This guide lists practical decision criteria for SMEs.