Exchange Server 2013 reached the end of extended support on April 11, 2023. If you are still running it in 2026, you are more than three years past the last security update Microsoft will ever ship for it. The server still delivers mail, which is exactly why it is still in production in so many places, but "still working" and "still safe" stopped being the same thing in April 2023.
This guide covers what ended, why 2013 specifically deserves urgency, and, most usefully, the migration options that actually work from this version, because Exchange 2013 sits at an awkward midpoint: too old for some modern conveniences, new enough that you have more routes than a 2010 shop does.
What ended in April 2023
End of extended support means Microsoft stopped providing, permanently:
- Security updates. Vulnerabilities discovered after April 2023 will never be patched on Exchange 2013. Given how heavily Exchange has been targeted, this is the headline risk.
- Bug fixes and time zone updates. No more cumulative updates of any kind.
- Technical support. Microsoft will not take a support case for Exchange 2013, paid or otherwise.
Nothing shut off on the day. Your mail flow, OWA, and mobile sync continued. What changed is that the platform's defenses were frozen while the attacks against it kept evolving.
Why 2013 deserves real urgency
Exchange 2013 shares the core architecture that was hammered by the ProxyLogon and ProxyShell vulnerability classes in 2021. Those were exploited at internet scale: automated scanning found exposed Exchange servers and compromised them indiscriminately, and Exchange 2013 was squarely in scope. It received emergency patches then because it was still supported. It will not receive the equivalent next time, and Exchange research (by both defenders and attackers) has not stopped.
Beyond the direct security exposure:
- The foundation is unsupported too. Exchange 2013 runs on Windows Server 2012 or 2012 R2, both of which have also left extended support. Every layer of the stack is now unpatched.
- Modern authentication limits. Exchange 2013 predates the modern auth ecosystem that Microsoft 365 requires and that current security practice assumes. Basic authentication, which 2013-era clients lean on, is exactly what Microsoft has been eliminating across its cloud.
- Client support is eroding. Current Outlook builds increasingly assume newer server capabilities, and staying compatible means freezing your desktop software in the past along with your server.
- Insurance and compliance questions. Cyber insurance applications now ask about end-of-life software by name. Auditors ask the same question. "We run an unpatched 2013 mail server exposed to the internet" is a difficult sentence in either conversation.
Your migration options from Exchange 2013
For nearly every organization, the destination is Exchange Online in Microsoft 365. The interesting question is the method, and 2013 gives you several.
Option 1: Cutover-style migration (small organizations)
For smaller environments, the simplest approach is to move everyone at once: pre-copy all mailbox data to Microsoft 365 while the old server keeps running, then on a scheduled weekend do a final sync, flip MX records, and reconfigure Outlook and phones. Monday morning, everyone is in the cloud with their history intact. In practice on 2013 this is usually done with migration tooling rather than the classic native cutover mechanism, but the user experience is the same: one clean switch, minimal coexistence complexity.
Option 2: Express or minimal hybrid (move in one pass, keep it simple)
Exchange 2013 supports Microsoft's hybrid configuration, including the lighter-weight minimal and express hybrid modes. Express hybrid uses the hybrid plumbing just long enough to move mailboxes with directory synchronization, so users keep their passwords, then the hybrid relationship is retired. It is a good fit when you want native Microsoft tooling and a short project without signing up for long-term coexistence.
Option 3: Full hybrid migration (larger or phased moves)
A full hybrid ties your 2013 organization and Microsoft 365 into one connected system: shared address book, mail routing between the two, and mailbox moves in scheduled batches with users barely noticing each move. This is the right shape for organizations with hundreds of mailboxes, multiple sites, or a need to phase the move by department. Two honest caveats for 2013 specifically: the hybrid experience on a 2013 server is dated compared to newer versions, and hybrid must be a bridge, not a destination. The old server has to be fully retired at the end, because an unsupported hybrid server is still an unsupported server.
Option 4: Third-party migration tooling
Purpose-built migration platforms copy mailboxes, calendars, contacts, and public folders to Microsoft 365 independent of the old server's native migration machinery. On aging 2013 servers with accumulated database quirks, certificate problems, or half-broken services, this is often the most reliable route, and it handles Microsoft 365 throttling, retries, and delta syncs automatically. It also covers scenarios native tools handle poorly, like merging multiple mail systems into one tenant.
Option 5: Upgrade on-premises (the narrow case)
The current on-premises product is Exchange Server Subscription Edition (SE), licensed by subscription. Reaching it from 2013 is a multi-hop project: 2013 cannot upgrade directly, so you would migrate to an intermediate version first, on new Windows Server, with new hardware or VMs, and then own patching, backups, and certificate renewals indefinitely. Choose this only if a regulatory or data-residency mandate genuinely rules out cloud mail. Otherwise the economics and the risk profile both favor Exchange Online.
Choosing between them
| Method | Fits | Coexistence period | Key advantage |
|---|---|---|---|
| Cutover-style with tooling | Up to ~150 mailboxes | None: one weekend switch | Simplest project, shortest timeline |
| Express / minimal hybrid | Small to mid, single pass | Days | Native tooling, passwords preserved |
| Full hybrid | Hundreds of mailboxes, phased | Weeks, by design | Batch moves, seamless user experience |
| Third-party tooling | Unhealthy servers, complex data, mergers | Flexible | Independent of old server health |
| On-premises Exchange SE | Hard residency mandates only | Not applicable | Data stays on your hardware |
Three questions usually settle the choice: how many mailboxes are moving, whether the business can absorb a single cutover weekend or needs a phased move, and how healthy the 2013 server actually is. The third one is checked, not assumed; discovery on a decade-old server regularly finds surprises that change the method.
The 2013-specific traps
- Public folders. Exchange 2013 introduced modern public folders, which migrate differently than the 2010 style. Either way, they need their own migration plan and a permissions review, because this is where projects stall.
- Basic auth dependencies. Devices and applications authenticating with username and password against the old server (scanners, ticketing systems, backup alerts) must be found and moved to modern authentication or app-specific arrangements, because Microsoft 365 will not accept basic auth.
- Directory hygiene. Duplicate proxy addresses, invalid characters, and stale objects break synchronization to Microsoft 365. Cleaning them up front costs hours; discovering them mid-migration costs days.
- Certificates and endpoints. Hybrid and native moves depend on valid certificates and correctly published endpoints. On long-neglected servers these are frequently expired or misconfigured.
- The decommission. The final step is removing Exchange 2013 from the organization properly, not just powering it off. A half-removed Exchange server leaves directory debris that complicates everything that comes after.
Where this fits in the bigger picture
Exchange 2013 is the middle child of the end-of-life story: not as ancient as Exchange 2010, but out of support years before Exchange 2016 and Exchange 2019, which both reached end of support in October 2025. Whatever the version, the destination and the discipline are the same, and the general case for urgency is laid out in our guide to the risks of unsupported Exchange.
Migration is what we do, not a sideline. We run discovery, pick the method that fits your size and constraints, give you a fixed price and a dated plan, execute the move without losing mail, and retire the old server completely. The routes we run are mapped on the migration paths page, and if you want us to stay on afterward, we manage Microsoft 365 environments month to month.
Three years past the deadline is far enough
Tell us about your Exchange 2013 environment and we will map the cleanest route to Microsoft 365, with a fixed quote and no obligation.
Plan My Migration