TechNewsReel
Live

Microsoft blocks mail from outdated Exchange 2016 and 2019 servers

Organizations failing to install the October 2025 security update face throttled or bounced emails to Exchange Online.

TechNewsReel Newsroom · September 4, 2026

Microsoft began enforcing a new security baseline for on-premises Exchange Server 2016 and 2019 installations during the second week of September 2026. The move targets outdated servers that communicate with cloud-hosted inboxes, potentially disrupting business-critical mail flow for unpatched environments.

Under the new policy, any server using an inbound connector of type 'OnPremises' to send mail to Exchange Online must have the October 2025 public security update installed. Servers that do not meet this specific baseline will have their messages throttled or blocked entirely, resulting in bounced emails when attempting to reach Microsoft 365 users.

The shift to extended support

This enforcement follows the end of mainstream Microsoft support for Exchange 2016 and 2019, which occurred in October 2025. Since that milestone, these versions have moved into the Extended Security Update (ESU) phase. Microsoft has a documented history of incrementally raising the minimum acceptable version of Exchange servers allowed to communicate with Exchange Online to maintain the security integrity of the cloud ecosystem.

By establishing the final public update as the absolute minimum requirement for connectivity, Microsoft is effectively forcing administrators to either patch their systems to the final public baseline or migrate their infrastructure to newer versions or fully cloud-based services.

Industry implications

This transition creates a hard deadline for organizations still relying on legacy on-premises mail servers. The move is designed to mitigate the dangers associated with running outdated software. The primary consequence for the average administrator is the immediate loss of mail delivery to the cloud if the October 2025 update is missing.

For many enterprises, the interruption of mail flow to Microsoft 365 users represents a significant operational risk. The policy underscores a broader industry trend of deprecating legacy on-premises dependencies in favor of standardized, cloud-native security baselines.

What to watch

Administrators should immediately verify that their Exchange 2016 and 2019 servers are updated to at least the October 2025 public security baseline to avoid service interruptions. Organizations that cannot patch due to legacy constraints must accelerate their migration plans to avoid permanent mail blocking. It remains to be seen if Microsoft will introduce further baseline requirements for ESU customers in the coming months.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.