Systems and records
Exchange Server 2016 and 2019 end of support: archiving old mailboxes
By SourceX Editorial · Updated
Short answer
Exchange Server 2016 and 2019 are past the end of Microsoft support, so they no longer get regular security updates. Companies still running them can upgrade to Exchange Server Subscription Edition, move mailboxes to Exchange Online, or archive and retire the server. On every path, export and verify old mailboxes, public folders and shared mailboxes before shutdown.
Key takeaways
- An unsupported Exchange server keeps running, but it stops receiving regular security fixes, which matters most for anything exposed to the internet.
- Moving active users to the cloud often leaves departed users' mailboxes, public folders and PST files behind on the old server.
- Count items per mailbox and folder before and after export; a migration without counts cannot prove it is complete.
- PST files are a transport format, not an archive: move exported mail into a searchable store with access control.
- Keep the old server intact, powered off and isolated, until the archive has been verified and signed off.
What end of support means for a server you still run#
End of support means Microsoft no longer ships regular security updates, bug fixes or technical help for Exchange Server 2016 and 2019. The server still starts every morning and mail still flows, which is why some companies, plants and smaller sites in particular, keep one running longer than planned. Check Microsoft's lifecycle documentation for exact dates and any remaining options.
The exposure sits mostly in internet-facing services such as Outlook on the web and mobile device access. Cyber insurers and customers' supplier security questionnaires often ask about unsupported systems, so an old Exchange box can become a commercial problem before it becomes a technical one.
Hybrid setups need attention too. Companies that moved mail to Exchange Online years ago sometimes kept an on-premises Exchange server for recipient management or hybrid mail flow, and that server is just as unsupported as a full mail system. Check Microsoft's current hybrid guidance before deciding whether that server must be upgraded or can be removed.
Upgrade, move to the cloud, or archive and retire?#
The right path for an unsupported Exchange 2016 or 2019 server depends on whether you still need mail on premises and how much old history the server holds. Many companies combine paths: active users move to Exchange Online, while departed users, public folders and old shared mailboxes are archived and the server is retired.
| Option | Fits when | What happens to old history | Watch for |
|---|---|---|---|
| Upgrade to Exchange Server Subscription Edition (SE) | Mail must stay on premises for contract, plant network or policy reasons | Stays on premises if moved or upgraded correctly | Upgrade routes differ for 2016 and 2019; check Microsoft's supported path and subscription licensing |
| Move to Exchange Online | You want Microsoft to run the service | Moves only for the mailboxes you migrate | Departed users, public folders and PST files are often left out |
| Archive and retire | No one needs live mail from the server | Exported to an archive store and verified | Needs a searchable target, not a pile of PST files |
| Keep running unsupported | Only as a brief, isolated bridge | Stays in place, at rising risk | Remove internet exposure and set a firm retirement date |
Which mailbox history is easy to leave behind?#
The mailbox history most often left behind in an Exchange migration is the material no current user owns. Migration projects move active people, and nobody claims the mailboxes and folders of people and teams that no longer exist.
For a manufacturer, the quality and order mailboxes deserve special care. They hold customer complaints, corrective action discussions, supplier delays and engineering change requests in the words of the people who handled them, while the ERP usually stores only the outcome.
- Disabled or disconnected mailboxes of former employees, kept on the server instead of being removed.
- Shared mailboxes such as quotes, orders, quality, RMA or purchasing, which often hold years of customer and supplier correspondence.
- Public folders, which in many plants still hold RFQ files, supplier contacts and old project threads.
- Journal mailboxes and in-place archive mailboxes set up long ago.
- PST files on file shares, old laptops and former employees' home drives.
- Mailboxes on litigation hold, whose hold settings do not travel inside a PST.
How to export and verify old mailboxes#
To export and verify old Exchange mailboxes, record item counts and sizes per mailbox and folder before export, export one mailbox at a time, then compare the counts once the data lands in the archive. That comparison is what separates an archive from a copy you hope is complete.
Plan for failures. Corrupt items, oversized attachments and damaged databases are common on servers that have run for many years, so leave room to rerun failed exports and to document items that could not be recovered. Public folders need their own export route, often through Outlook or a migration tool.
- Step 1: inventory every mailbox type with Get-Mailbox and Get-MailboxStatistics, including disabled and shared mailboxes.
- Step 2: record item counts per mailbox and per folder with Get-MailboxFolderStatistics, and save the output as your baseline.
- Step 3: export with New-MailboxExportRequest to a UNC network share, or with a migration tool, one mailbox at a time, and log each request's result; the export cmdlet needs the Mailbox Import Export role assigned.
- Step 4: import into the archive target and compare counts against the saved baseline.
- Step 5: record a hash of each exported file and keep the files in two separate locations.
- Step 6: spot-check old threads by opening a sample from each mailbox in the target system.
What to keep besides the mail itself#
Besides the mail itself, keep the context records that make an Exchange archive usable years later: who each mailbox belonged to, who received group mail, which retention and hold rules applied, and how the export was done. They disappear when Active Directory and the server are decommissioned, and without them a mailbox is a list of messages from addresses no one can place.
| Record | Why keep it | Where it lives |
|---|---|---|
| Mailbox-to-person map with job titles and departments | Tells a future reviewer who the sender was and what role they held | Active Directory and HR records |
| Distribution list memberships | Explains who received group mail such as order or quality alerts | Exchange and Active Directory |
| Retention tags, journaling rules and hold settings | Shows what was supposed to be kept and why | Exchange configuration |
| Public folder structure and permissions | Preserves how teams organized shared threads and files | Public folder hierarchy |
| Export logs, counts and hashes | Proves the archive is complete and unaltered | Your migration records |
Illustrative: a machining company retires its last Exchange 2016 server#
Illustrative: a fictional contract machining company runs Exchange 2016 on premises, Epicor for quoting and orders, and a separate quality system for nonconformance reports. Active users move to Exchange Online, and the IT lead plans to switch the old server off once the cutover is done.
The inventory shows what the migration skipped: disabled mailboxes for retired estimators and quality engineers, a quality shared mailbox with years of customer complaint threads, and a public folder of RFQs whose file names carry Epicor quote numbers. The team exports each one, matches counts to the baseline, and imports the results into a searchable archive with read access limited to quality and sales leadership.
The server stays powered off but intact until the archive is signed off. Because the RFQ threads carry quote numbers, they can later be linked to Epicor records, turning a pile of old mail into a connected history of how quotes were won, lost and revised.
Why archived mailboxes can matter beyond compliance#
Archived engineering, quality and supplier email can record how decisions were made, which is the part of operations that systems of record rarely capture. That history has value for internal knowledge and, with the right rights review and preparation, for licensing to AI developers building models for manufacturing and operations work.
Rights come first. Customer-owned designs, drawings received under NDA and export-controlled technical data are typically excluded, and personal details are removed during preparation. Within the SourceX five-step transaction (Supply, Rights, Preparation, Approval, Delivery), those carve-outs happen at the Rights step, after a fit check that looks only at metadata such as mailbox counts and years covered. For archives that proceed, a SourceX Evidence Packet documents where each mailbox came from and what release was approved.
Frequently asked questions
Can we keep the old Exchange server running just for search?
Some companies do for a brief bridge period, but only with internet access removed, no mail flow and few admin accounts. An isolated server still needs its Windows host patched and a dated retirement plan. A verified archive in a supported store is the safer long-term home for the history.
Is a PST export enough for a legal hold?
Usually not on its own. A PST is a file anyone with access can alter, and hold settings do not travel with it. If a hold applies, document the chain of custody, keep hashes of the exported files, and recreate the hold in the target system. Counsel should confirm the approach.
Do mailboxes already moved to Exchange Online need anything else?
Check that their on-premises archive mailboxes and any PST files they used moved with them. Departed users in the cloud also need a hold or retention policy before their accounts are deleted, or their mail is removed after a short recovery window.
What about Exchange 2013 or older servers?
Those versions have been out of support for longer, so the same steps apply with more urgency. Older servers are also more likely to have corrupt databases and awkward export paths, so start with an inventory and a test export of a few mailboxes before committing to a schedule.
Who should approve switching the old server off?
The IT lead should confirm export counts and hashes, and an owner of the records, often the controller, quality manager or general counsel, should sign off that nothing still needed lives only on the server. Keep that sign-off with the export logs.
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.