On 20 July 2026 the Exchange Server team answered a question a lot of IT departments had been quietly hoping to hear a different answer to. There will be no Period 3.
Extended Security Updates for Exchange Server 2016 and 2019 end on 31 October 2026. Period 2 was the final window. It cannot be renewed or extended, and enrolled organizations get no further patches after that date, including for a critical vulnerability disclosed on 1 November. Roughly eight weeks from today.
What Does the Period 2 ESU Actually Cover?
Less than most people assume.
Extended Security Updates deliver only the patches that the Microsoft Security Response Center rates Critical or Important. They are not a restoration of product support, and the word support is doing a lot of misleading work in most internal conversations about this. 
You cannot open a general support case for Exchange Server 2016 or 2019. The single exception is a problem caused by an ESU update itself. No bug fixes outside security, no performance help, no feature requests. Period 2 also had to be purchased separately through an Enterprise Agreement, and Period 1 enrollment did not carry over, which caught out a fair number of organizations in May.
Both products left the standard lifecycle on 14 October 2025. Everything since has been a bridge with the expiry date printed on it.
The Part That Is Not an IT Problem
Exchange will keep delivering mail on 1 November. Nothing breaks, no alert fires, and that is exactly what makes this easy to defer for a third time.
The exposure is regulatory. For an organization under GDPR, HIPAA, or SEC oversight, a breach traced to an unpatched server running a version that left support more than a year earlier does not read as bad luck. It reads as evidence of inadequate technical and organizational measures, which carries its own enforcement consequences separate from the breach. We went through that dynamic at length in our work on the compliance risks of legacy email systems.
Ransomware crews read lifecycle calendars too.
A rushed cutover is where governance quietly disappears. Legacy archives left on a server nobody decommissions. Retention policies never rebuilt for the new platform. Legal holds that lapse somewhere mid-project and surface a year later, in response to an eDiscovery request nobody saw coming. Our guidance on cybersecurity controls during Office 365 migration covers what belongs in the plan before the first mailbox moves.
Questions We Keep Getting
Q: When exactly do Exchange 2016 and 2019 stop receiving security updates?
A: 31 October 2026. Microsoft confirmed on 20 July 2026 that no Period 3 will follow, and Period 2 cannot be renewed or extended.
Q: Will Exchange stop working on 1 November?
A: No. Mail flow continues normally. The risk is that a newly disclosed vulnerability will never be patched, and no compensating control repairs the underlying code.
Q: Does the ESU cover every Exchange server we run?
A: Only servers on Exchange Server 2016 CU23 or Exchange Server 2019 CU14 or CU15. Older cumulative updates receive nothing even if the ESU was purchased. Edge Transport servers, management tools, and hybrid components share the same deadline.
Q: Can we upgrade straight to Exchange Server SE?
A: From Exchange 2019, yes, in place, through a process identical to installing a cumulative update. From Exchange 2016 or 2013, either go directly to SE or install 2019 first. Exchange Online is the third route.
Q: What if we cannot finish before 31 October?
A: Reduce exposure with segmentation and tightened firewall rules, then keep going. Treat legal holds and legacy archives as part of the project rather than cleanup, because those are the pieces a rushed cutover loses.
How Messaging Architects Can Help
We have moved organizations off GroupWise, legacy Exchange, and proprietary archives for more than two decades. Before cutover we map what data exists, what retention governs it, and what sits under hold. More on how we work sits on the Messaging Architects blog and at our parent company, eMazzanti Technologies.
October is not a planning deadline. It is the last month anybody patches these servers.