Exchange 2016 End of Support: The 3 Risks of the 'Do Nothing' Strategy
Exchange 2016 and SharePoint 2016 reach end of support in October 2026. This post breaks down the four real risks of staying on unsupported infrastructure: unpatched security vulnerabilities, escalating ESU costs, a shrinking talent pool, and automatic compliance failures.
Planning a migration?
Get a free 30-min call with our engineers. We'll review your setup and map out a custom migration plan — no obligation.
Schedule a free call- 1,500+ migrations completed
- Zero downtime guaranteed
- Transparent, fixed pricing
- Project success responsibility
- Post-migration support included
In every migration consultation I run, there is a moment where the client pauses and looks at the budget. Then they ask the question that every engineer dreads.
"Raaj, honestly, what if we just don't move? What if we just keep the servers running? They work fine right now."
I understand why you ask this. You have a SharePoint 2016 farm that has been stable for a decade. You have an Exchange 2016 server that delivers email perfectly. Why spend money to fix something that isn't broken?
Here is the answer: Because "working" is not the same as "secure."
The 2026 End-of-Support Deadline is not just a marketing event. When Microsoft ends support, your servers stop receiving security patches, bug fixes, and technical support. If you choose to keep your data on those servers after the support date, you aren't saving money. You are accepting a growing set of engineering, financial, and compliance risks that compound every month.
In this post, I am going to walk you through the four specific risks of staying on unsupported on-premise infrastructure.
A note on Exchange 2016 vs. SharePoint 2016: While both products reach end of support in October 2026, they have different risk profiles and different migration paths. Exchange 2016 is internet-facing and directly exposed to external attack. SharePoint 2016 is typically internal-facing, which changes the threat model. I will call out product-specific differences where they matter.
1. The Security Risk: Unpatched Servers Are Open Targets
Do you remember the HAFNIUM Exchange Server attacks of 2021?
Attackers exploited zero-day vulnerabilities in on-premise Exchange servers. Within days, thousands of organizations were breached worldwide. Microsoft released an emergency patch quickly. If you applied it, you survived.
The HAFNIUM incident demonstrated a specific pattern: attackers actively scan the internet for on-premise Exchange servers running known-vulnerable versions. Exchange 2016 is particularly exposed because it is internet-facing by design — it must accept inbound email connections.
After October 2026, when a new vulnerability is discovered in Exchange 2016, Microsoft will not release a security patch through normal support channels. Your server will remain vulnerable for as long as it runs.
What "unsupported" actually means in practice:
- No security patches. Vulnerabilities discovered after end-of-support go unpatched indefinitely.
- No bug fixes. Known issues will not be resolved.
- No technical support. You cannot open support cases with Microsoft for Exchange 2016 or SharePoint 2016 issues.
Exchange 2016 vs. SharePoint 2016 — different exposure levels:
- Exchange 2016 is internet-facing. It accepts inbound SMTP, provides Outlook Web Access, and exposes ActiveSync endpoints. Every one of these is an attack surface that will stop receiving patches.
- SharePoint 2016 is typically deployed behind a firewall. The attack surface is smaller, but if it stores contracts, PII, or regulated data, a single unpatched vulnerability can still lead to a serious data breach.
You cannot secure a system that the vendor has stopped patching.
2. The Financial Trap: Extended Security Updates Are Not a Long-Term Strategy
You might think that paying for Extended Security Updates (ESU) is a smart way to buy time.
It is worth understanding how Microsoft structures ESU pricing. The program is designed to be a short-term bridge, not a permanent solution. Microsoft prices ESU to incentivize migration, not to make staying comfortable.
How ESU pricing typically works:
- ESU is priced as a percentage of your original license cost, and that percentage increases each year.
- The cost escalates year over year — what starts as a manageable line item in Year 1 becomes significantly more expensive by Year 3.
- ESU covers security patches only. No new features, no performance improvements, no technical support beyond the patches themselves.
Important: ESU availability and pricing differ by product. Windows Server ESU is a well-established program with published pricing. Exchange 2016 and SharePoint 2016 ESU details should be confirmed against Microsoft's official lifecycle documentation for your specific SKU and licensing agreement. Do not assume the same terms apply across products.
Every dollar you spend on ESU is a dollar you didn't spend on modernizing. And at the end of the ESU period, you still have to migrate. The cost was not avoided — it was deferred and inflated.
The alternative: Take that ESU budget and invest it in a migration. You stop paying escalating annual fees. You stop worrying about the next zero-day disclosure. You gain access to modern capabilities — like Copilot, modern authentication, and automated compliance tooling — that do not exist on-premise.
See our breakdown of Real Migration Costs to understand how the numbers compare.
3. The Talent Risk: The Expertise You Depend On Is Disappearing
This is the operational risk that rarely appears on a spreadsheet but can stop your business cold.
Who manages your Exchange 2016 server right now? In most organizations, it is one or two senior engineers who have been with the company for over a decade. They know the PowerShell scripts, the custom transport rules, the specific quirks of your environment.
What happens when those engineers leave, retire, or are unavailable?
The pool of engineers with deep Exchange 2016 and SharePoint 2016 operational expertise is shrinking every year. New engineers entering the workforce are learning Azure, Power Platform, and modern cloud infrastructure. They are not learning how to manage IIS application pools on Windows Server 2012 R2.
The practical consequences:
- Finding replacement staff with legacy Exchange or SharePoint expertise becomes harder and more expensive each year.
- When your environment has an outage and your primary admin is unavailable, your recovery depends on finding someone who understands a platform that has been out of support for months or years.
- You become operationally dependent on a shrinking number of people with a shrinking skill set.
Moving to a supported cloud environment changes this equation. You gain access to a large, actively growing pool of engineers with current Microsoft 365 and Azure skills. Your environment is maintained on an evergreen platform that new hires already understand.
4. The Compliance Risk: Unsupported Software Fails Audits
I touched on this in my Security & Data Sovereignty Guide, but it is critical for regulated industries.
If you are in Healthcare, Finance, or Government, your compliance obligations are tied to running supported, actively patched software.
- PCI-DSS (Requirement 6.3.3): Requires that all system components are protected from known vulnerabilities by installing applicable security patches. Running software that no longer receives patches makes this requirement impossible to satisfy.
- HIPAA (Security Rule § 164.308(a)(5)): Requires implementation of security measures sufficient to reduce risks to electronic protected health information. Running end-of-life software with known, unpatched vulnerabilities is a failure of this requirement.
Running End-of-Life software is an automatic finding in many compliance frameworks. Telling an auditor "We plan to migrate soon" is not an acceptable remediation.
The path forward: Migrate to a supported environment before your next audit cycle. Land in a compliant, evergreen Microsoft Cloud environment where patches are applied automatically and your compliance posture is maintained by default.
What Are Your Actual Options?
The "Do Nothing" path feels safe because it requires zero effort today. But in engineering terms, it accumulates risk on every dimension — security, financial, operational, and compliance — and that risk compounds month over month.
Here is an honest look at the paths available:
| Stay on Exchange/SharePoint 2016 | Upgrade to Exchange 2019 | Migrate to Microsoft 365 | Hybrid Deployment | |
|---|---|---|---|---|
| Security | No patches after Oct 2026 | Supported until Oct 2025 (extended to 2029 with ESU) | Evergreen, always patched | Partially patched (on-prem component still needs management) |
| Cost trajectory | ESU fees escalate annually | New license + hardware costs | Predictable per-user subscription | Split costs: cloud subscription + on-prem maintenance |
| Compliance | Fails most frameworks post-EOL | Passes while supported | Passes; built-in compliance tooling | Passes if on-prem component stays supported |
| Talent availability | Shrinking pool | Somewhat larger but still legacy skills | Large, actively growing talent pool | Requires both legacy and cloud skills |
| Timeline | No effort now, high effort later | Medium effort, buys time | Full migration effort, permanent solution | Phased effort, flexible timeline |
Exchange 2019 as a stepping stone: Upgrading to Exchange 2019 is a legitimate intermediate option, especially if you need more time to plan a full cloud migration. It buys you supported infrastructure with a known end-of-support date. It is not a permanent solution, but it is a defensible one.
Hybrid deployments: Exchange Hybrid is a supported architecture that lets you maintain some mailboxes on-premise while moving others to Exchange Online. This can be a practical approach for organizations with regulatory constraints on data residency or complex routing requirements. It does add architectural complexity — you are maintaining two environments instead of one.
Frequently Asked Questions
- When does Exchange 2016 reach end of support?
- Exchange 2016 reaches end of support on October 13, 2026. After that date, Microsoft will no longer provide security patches, bug fixes, or technical support.
- What is the difference between Exchange 2016 and SharePoint 2016 end-of-support risks?
- Exchange 2016 is internet-facing by design, making it directly exposed to external attacks once patches stop. SharePoint 2016 is typically deployed behind a firewall with a smaller attack surface, but still carries data breach risk if it stores sensitive information.
- Are Extended Security Updates (ESU) available for Exchange 2016?
- ESU availability and pricing differ by product and licensing agreement. Check Microsoft's official lifecycle documentation for your specific SKU, as Exchange 2016 ESU terms may differ from Windows Server ESU terms.
- Can I upgrade to Exchange 2019 instead of migrating to the cloud?
- Yes. Exchange 2019 is a supported intermediate option that buys additional time while you plan a full migration. It is not a permanent solution, but it is a defensible stepping stone.
- Will running Exchange 2016 after end of support fail a compliance audit?
- In most regulated frameworks, yes. PCI-DSS Requirement 6.3.3 requires systems to be protected with current security patches, and HIPAA Security Rule § 164.308(a)(5) requires active risk mitigation. Unsupported software with known unpatched vulnerabilities fails both.

