The End of Grace Periods for On-Premise Exchange
Microsoft has announced a significant shift in its security policy regarding on-premises email infrastructure. Starting in the second week of September 2026, the tech giant will begin blocking or throttling email traffic originating from outdated Exchange Server installations. Specifically, any organization running Exchange Server 2016 or 2019 that attempts to send mail to Exchange Online via an inbound OnPremises connector must be fully patched to the final public update baseline released in October 2025.
This move is part of Microsoft's ongoing effort to secure the Exchange ecosystem against increasingly sophisticated threats. By mandating that on-premises servers meet a specific, high-level security standard, Microsoft is aiming to close vulnerabilities that have historically made older, unpatched servers prime targets for attackers. The company has made it clear that this is not a suggestion; it is a mandatory requirement for maintaining mail flow into the cloud.
Why It Matters
For IT administrators and organizations still maintaining hybrid email environments, this policy change represents a critical operational shift. Many companies rely on on-premises Exchange servers to support legacy applications, specialized workflows, or internal compliance requirements. Under the new rules, these servers effectively become a liability if they are not kept in lockstep with the latest security baseline.
The policy specifically targets the "inbound connector" path. While other methods of delivery remain unaffected for now, Microsoft’s documentation hinted that this could change in the future. The directive serves as a reminder that the company is moving toward a "modern lifecycle" for its software, where failing to apply critical updates results in immediate service degradation rather than simple warnings.
Key Implications for Administrators
- Hard Deadline: Systems must be at the October 2025 update level or they will face delivery issues starting in mid-September 2026.
- Selective Scope: The current policy applies strictly to servers using inbound OnPremises connectors, but the architecture may expand to cover more scenarios later.
- Lifecycle Management: Beyond the 2025 baseline, the only path forward for long-term support remains the Extended Security Update (ESU) program or a full transition to the Exchange Server Subscription Edition.
- Risk Balancing: Administrators are forced to navigate the classic dilemma of ensuring security without risking the stability of legacy business applications that might break during major patch cycles.
As Principal Project Manager Nino Bilic noted, this change is inevitable regardless of whether it is explicitly announced. The overarching message to the IT community is one of urgency: technical debt regarding server updates is no longer a sustainable strategy in a threat landscape that favors automated exploitation of known, unpatched vulnerabilities.


