As of October 14, 2025, every traditionally licensed version of on-premises Exchange Server is out of support. Exchange 2010 fell out in October 2020, Exchange 2013 in April 2023, and Exchange 2016 and 2019 together in October 2025. The only supported ways to run Exchange today are Exchange Online in Microsoft 365 and the subscription-licensed Exchange Server Subscription Edition on-premises.
Plenty of businesses are still running one of the retired versions anyway, usually on the reasoning that it works fine and has for years. This article is for the owner or IT lead who needs to evaluate that reasoning honestly. Not scare copy: a sober inventory of what the risk actually is, where it shows up first, and why "it has been fine so far" is not the evidence it appears to be.
Risk 1: You are running a proven target with a frozen defense
The core problem with unsupported software is simple: vulnerabilities keep being discovered, and patches stop being written. For most software that is a theoretical concern. For Exchange it is not, because the last five years supplied a live demonstration of what Exchange exploitation at scale looks like.
In 2021, the vulnerability classes commonly called ProxyLogon and ProxyShell hit on-premises Exchange. Attackers automated the whole chain: scan the internet for Exchange servers, exploit them, plant web shells for persistent access. Compromise was not targeted at valuable victims; it was applied to essentially everything reachable, from global enterprises to ten-person firms, within days of the flaws becoming known. Microsoft shipped emergency patches, and even published mitigations for some already-retired versions because the situation was that severe. That episode is the template, not the exception: Exchange remains one of the most studied attack surfaces in enterprise software.
A supported server closes those windows within days of each discovery. An unsupported server never closes another one. The number of known, unpatched, forever-open flaws on your server only moves in one direction, and attackers specifically catalog end-of-life products because exploits against them never expire.
Why an Exchange compromise is worse than most
- It is exposed by design. Mail servers accept connections from the internet; that is their job. You cannot firewall the problem away without breaking mobile and remote mail.
- It holds the crown jewels. Years of contracts, financials, HR matters, and customer correspondence, all searchable. Email archives are the single richest data store most small businesses own.
- It is a bridge to everything else. Exchange integrates deeply with Active Directory, historically with elevated privileges. Compromising the mail server is a classic route to compromising the whole domain, at which point ransomware operators can encrypt everything, not just mail.
- It enables quiet fraud. An attacker with mailbox access does not have to be loud. Reading invoices in transit and inserting altered banking details, or impersonating executives from their real mailboxes, is how business email compromise losses happen.
Risk 2: Your cyber insurance may quietly stop protecting you
Cyber insurers learned from the Exchange mass-exploitation era, and their applications now show it. It is standard for questionnaires to ask directly whether the organization runs end-of-life or unsupported software, and sometimes to ask about internet-facing servers specifically. That creates three bad outcomes and no good ones:
- Answer accurately, and you may face higher premiums, an exclusion carved around the unsupported system, or a declined application.
- Answer inaccurately, and you risk a denied claim after an incident, exactly when the coverage was the point.
- Say nothing and hope, and the post-incident forensic report names the unpatched Exchange server as the entry point anyway.
The uncomfortable math is that a migration frequently costs less than a single year's premium increase, and incomparably less than an uncovered incident.
Risk 3: Compliance findings and awkward customer questions
Most security and compliance frameworks require, in some form, that systems be supported and patched. Whether your obligation comes from HIPAA, PCI DSS, CMMC, SOC 2, state privacy law, or simply a large customer's vendor security questionnaire, an unsupported internet-facing mail server is a finding, and vendor questionnaires increasingly ask about it outright. Deals have stalled on exactly this answer. The regulatory exposure compounds after a breach: demonstrating that you knowingly ran unpatched end-of-life software handling personal data is not a position any counsel wants to defend.
Risk 4: The slow decay nobody announces
Security is the sharp risk. The dull one is that the ecosystem moves on and your server does not:
- Client compatibility erodes. New Outlook builds and mobile OS releases are tested against supported servers. Old Exchange versions gradually lose the ability to connect to current clients, which pins you to old Office versions with their own expired support.
- Modern authentication passes you by. Microsoft 365 requires modern auth, and the broader ecosystem now assumes it. Legacy Exchange lives on basic authentication and old protocols, which are precisely what credential-stuffing attacks feed on and what modern tooling refuses to speak.
- Deliverability degrades. The internet keeps raising TLS and mail authentication standards. Aging servers fall behind them, and the symptom is your quotes and invoices landing in spam folders, or bouncing, with no error on your side.
- The stack underneath expires too. Old Exchange runs on old Windows Server, often on old hardware. Each layer out of support multiplies both the risk and the difficulty of recovery when something finally fails.
- Recovery knowledge evaporates. When a fifteen-year-old server has a bad day, there is no vendor to call and shrinking real-world expertise to hire. Some failures on ancient Exchange are effectively unrecoverable without heroics, and the backup that was never test-restored is part of the same gamble.
"It has been fine for years" is survivorship, not safety
The absence of a visible incident is weak evidence, for two reasons. First, mail server compromises are frequently silent by design: the attacker's goal is to read, not to announce. Second, risk that grows monotonically does not reward past luck. Every month adds newly discovered, never-to-be-patched flaws to the pile while your defense stays exactly where it was on the day support ended. The bet does not stay the same bet; it gets worse on a schedule you cannot see.
What the deadlines look like side by side
| Version | Extended support ended | Unsupported for | Detailed guide |
|---|---|---|---|
| Exchange 2010 | October 13, 2020 | Nearly 6 years | Exchange 2010 five years on |
| Exchange 2013 | April 11, 2023 | Over 3 years | Exchange 2013 migration options |
| Exchange 2016 | October 14, 2025 | Almost 1 year | Exchange 2016: what now |
| Exchange 2019 | October 14, 2025 | Almost 1 year | Exchange 2019 paths compared |
Closing the risk for good
Every risk in this article has the same single remediation: get mail onto a supported platform. For most organizations that means Exchange Online in Microsoft 365, where patching, uptime, and modern authentication are Microsoft's job. For the minority with hard data-residency mandates, it means Exchange Server Subscription Edition on-premises, kept current. Partial mitigations (VPN-only access, stricter firewalling, extra monitoring) buy time and are worth doing while you plan, but they narrow the exposure rather than ending it.
Getting there is a well-understood project when it is run by people who do it constantly. Ours follow the same shape regardless of version: a discovery that inventories everything touching mail, a fixed-price plan with dates, a staged or cutover move matched to your size and version, verification that nothing was lost, and a proper decommission of the old server so the risk actually ends rather than idling in a closet. The routes are mapped on our migration paths page, and we can stay on to manage the Microsoft 365 environment after cutover.
Unsupported Exchange is not a technology problem waiting for a convenient budget cycle. It is an open business risk with a known fix, a fixed price, and a short timeline. The only variable left is the date.
End the risk, not just the worry
Tell us what version you are running and how many mailboxes, and we will send back a fixed-price migration plan within one business day.
Plan My Migration