Exchange Server 2016 and 2019 reached end of support in October 2025. If you're still running one on-premises, you're patching an internet-facing server that no longer gets fixes. For most small businesses the answer is Exchange Online, and the real question is how to get there.
Pick the method first
| Method | Best for | How it works | Trade-off |
|---|---|---|---|
| Cutover | Under ~150 mailboxes, no directory sync | Every mailbox is copied, then MX moves in one weekend | Everyone gets new Outlook profiles on the same day |
| Hybrid (minimal or full) | Directory sync in place, or you want staged moves with no profile rebuilds | Exchange on-prem and Exchange Online share one organization. Mailboxes move in batches. | More setup: certificates, connectors, and the Hybrid Configuration Wizard |
| Third-party tool | Unusual sources, or tenant consolidation | The tool copies the data | License cost per mailbox, and one more system to trust |
Before anything moves
- Patch Exchange to the latest cumulative update. The Hybrid Configuration Wizard and migration endpoints expect a current build.
- Check Autodiscover and certificates. A valid public certificate on the Exchange server is required for hybrid and helps every method.
- Clean up the directory. Duplicate proxy addresses, invalid UPNs, and orphaned objects surface as sync and migration errors later. Microsoft's IdFix tool finds most of them.
- Inventory everything that relays through Exchange: scanners, apps, and monitoring systems. They'll need a new path when the server goes away.
- Right-size mailboxes. Very large mailboxes and huge archives slow every batch.
Hybrid in short
- Entra Connect syncs users, with password hash sync as the simplest sign-in method.
- The Hybrid Configuration Wizard sets up the organization relationship, connectors, and the migration endpoint.
- Move mailboxes in batches with remote move migrations. Users keep their Outlook profiles, and Autodiscover redirects them.
- Switch MX to Exchange Online once most mailboxes have moved.
- Move the stragglers, then decide what to do with the on-prem server.
Check batch health from Exchange Online PowerShell:
Connect-ExchangeOnline
Get-MigrationBatch | Format-Table Identity, Status, TotalCount, SyncedCount, FailedCount
Get-MoveRequest | Get-MoveRequestStatistics |
Sort-Object PercentComplete | Format-Table DisplayName, StatusDetail, PercentComplete, TotalMailboxSizeThe "last Exchange server" question
With directory sync, you used to need one Exchange server on-prem forever, just to manage recipient attributes. That's no longer true: once every mailbox is in Exchange Online, you can manage recipients with the Exchange Management Tools and the recipient management PowerShell module, then shut the last server down.
Do it carefully. Removing Exchange incorrectly can strip attributes from your synced users. Shut the server down for a while first, confirm nothing breaks, and only then remove it.
Where these projects go sideways
- Autodiscover pointing at the old server long after cutover, so Outlook keeps prompting for passwords
- Public folders nobody mentioned until week three
- Mail-enabled apps that relay through Exchange with no replacement ready
- Permissions between on-prem and cloud mailboxes during the transition. Delegates and shared mailboxes should move together.
- Removing the last server too early, before recipient management has a new home