MICROSOFT is tightening control over outdated on‑premises Exchange servers connecting to Exchange Online, beginning in the second week of September 2026. Inbound emails from Exchange Server 2016 and 2019 via OnPremises connectors will be throttled first and then blocked if those servers have not been updated to at least the final public update baseline published in October 2025. The policy targets hybrid mail workflows in particular, where a local Exchange instance interacts with Microsoft 365.
The rollout marks a sharper threshold than prior steps: Exchange Online will now require a build corresponding to the last publicly released update for 2016 and 2019, with end of support for those lines having occurred on 14 October 2025. Ordinary on‑premises owners are urged to migrate to Exchange Server Subscription Edition or move mail infrastructure to Microsoft 365; ESU (Extended Security Update) support ends in October 2026, after which only Subscription Edition remains fully supported.
The policy comes amid tens of thousands of still‑unpatched servers, with Shadowserver counting around 22,000 systems lacking the fix for CVE-2026-62911, a vulnerability enabling post‑compromise access to mailboxes and for which PoC code has appeared publicly. Initially, affected messages will be delayed (temporary 450 4.7.230 errors) and, if ignored, ultimately return a non‑delivery notification (550 5.7.230). Administrators are urged to update or decommission such servers to retain normal hybrid mail operation.