EOSL Alerts

Exchange 2016 CU23 SU22 EOL Oct 14, 2025 – Act Now

Updated 3rd Party Support Team

Microsoft Exchange 2016 CU23 SU22 End of Life: Last-Call Action Plan

Only three months remain until Microsoft Exchange 2016 Cumulative Update 23 with Security Update 22 reaches end of life on October 14, 2025. If your organization still runs this version, a full migration to Exchange Online or a newer on-premises build before that date is simply no longer realistic for most estates. That's not a reason to panic — but it is a reason to act now with a clear, structured checklist.

Here's what changes on October 14:

  • No more security patches or hotfixes from Microsoft.
  • No updates for known or zero-day vulnerabilities — every CVE from that day forward will remain unpatched.
  • No vendor SLA or support escalations for break-fix, crashes, or data integrity issues.
  • Compliance frameworks (PCI-DSS, SOC2, HIPAA, ISO 27001) will flag the product as unsupported.

Your audit and cyber insurance teams will want documented evidence of risk mitigation before that date. Use the weeks ahead productively.

Week 1–2: Full Inventory and Exposure Assessment

  • Identify every server running Exchange 2016 CU23 SU22 (build 15.1.2507.69). Do not forget passive DAG members, edge transport servers, or hybrid servers.
  • Confirm whether any servers are still receiving active directory–based updates or are already orphaned.
  • Document:
    • Number of mailboxes hosted on each server.
    • External-facing protocols (OWA, ECP, ActiveSync, Autodiscover).
    • Any public folders or third-party integrations tied to this version.
  • Share the inventory with your IT security, compliance, and procurement teams.

Week 3–4: Isolation and Hardening

  • Remove unnecessary exposure: If you can stop OWA or ActiveSync access from the internet, do it. If the server is used only for internal mail flow, block all inbound HTTP/HTTPS from outside your network.
  • Restrict authentication methods: Disable legacy protocols (Basic Auth for POP3, IMAP, SMTP) unless absolutely required. Document any exceptions.
  • Harden the OS and network: Apply all remaining Windows updates before October 14. Review firewall rules — limit source IP ranges to only what's necessary.
  • Enable logging and monitoring: Ensure that security logs, mailbox audit logging, and IIS logs are all turned on and forwarded to your SIEM.

Week 5–6: Document Risk for Auditors and Insurers

  • Write a formal risk acceptance memo that states:
    • Product name, version, and end-of-life date.
    • What controls are in place (isolation, reduced attack surface, monitoring).
    • Migration timeline (even if estimated: Q1 or Q2 2026).
    • Manager or executive sign-off.
  • Share this with your internal audit team and cyber insurance provider. Most insurers require documentation of known unsupported software exposures.
  • If your insurer demands compensating controls, be ready to show the hardening steps above.

Week 7–8: Secure a Third-Party Support Contract

  • By the end of week 8, have a signed support agreement in place for day one after October 14. Without this, any critical vulnerability discovered the week after EOL will have no vendor fix available.
  • The right third-party support provider will deliver:
    • Security patches and hotfixes for zero-day vulnerabilities.
    • Break-fix support for crashes, corruption, or performance issues.
    • Coexistence and migration assistance as you move to a fully supported environment.
  • Start the procurement process now — legal review, security review, and contract signing take time.

Week 9–10: Final Pre-EOL Runbook and Communication

  • Create a one-page runbook for your IT operations team. Include:
    • Who to call if a new vulnerability is disclosed (your support provider's contact).
    • Steps to isolate a compromised server.
    • Where to find the risk acceptance memo and hardening documentation.
  • Communicate the plan to all stakeholders: your CISO, IT director, and compliance officer. Make sure everyone understands the deadline and the ongoing risk.

Week 11–12: Dry Run the Day-After Scenario

  • On a test server or a non-production environment, simulate a post-EOL scenario:
    • Attempt to download or install an Exchange update — confirm it fails.
    • Test your third-party support provider's emergency contact process.
    • Validate that your monitoring and alerting still work without updates.
  • Review your backup and disaster recovery procedures. MAKE SURE THEY WORK.

What Third-Party Support Can Do for You

Once October 14 passes, Microsoft Exchange 2016 CU23 SU22 will receive no further updates or fixes from the vendor. Third-party support keeps that environment safe: you get security patches tailored to new CVEs, break-fix support for operational issues, and migration assistance when you're ready to move on. It's not a permanent solution — but it buys you the time to plan and execute a proper migration without rushing.

Next Steps

Don't wait until October 13. Contact our team today to start the procurement process for third-party support and get your documentation in order. The deadline is fixed; your response doesn't have to be a scramble.

Lifecycle source: endoflife.date/msexchange and vendor lifecycle details available on our Microsoft software page.

How we can help

Keep it supported after end of life

The vendor's date doesn't have to be yours. Our engineers keep Microsoft Exchange 2016 CU23 SU22 running after official support ends — independent third-party support that covers most operational issues, typically at 40-70% below the last renewal quote.

Microsoft software support →

Migration services

When you do decide to move, we plan and execute the migration. Your current environment stays under vendor support while your contract is active — and if the renewal lapses mid-move, our third-party support covers most issues until the last workload is off it.

Migration & hybrid cloud services →

24×7 remote administration

Short on hands to run it day to day? Our NOC engineers monitor, patch and administer your environment around the clock — incident response included, at a fraction of the cost of an in-house night shift.

24/7 operations & remote administration →

Talk to a support specialist

Speak with an engineer, not a sales rep. We respond within 24 hours.

Your quote will be sent to this address.

By submitting this form, you agree to our Privacy Policy.