Starting Position, Product Status and Licensing
- End of support for Exchange 2016 and 2019 since 14 October 2025, ESU programme only until 31 October 2026
- What Exchange Server SE really is: RTM corresponds to the code of Exchange 2019 CU15
- Modern Lifecycle Policy instead of a fixed end of support – consequences for patch and operating processes
- Subscription licensing: Software Assurance or Microsoft 365 entitlement for servers and CALs
- Standard and Enterprise editions, product key required from a future Cumulative Update
Migration Planning and Target Architecture
- Decision tree: in-place upgrade only from Exchange 2019 CU14/CU15, otherwise legacy upgrade
- The window is closing: from SE CU2, coexistence with no-longer-supported versions is blocked
- Platform gap analysis: Windows Server 2019/2022/2025, .NET 4.8.1, Server Core as an option – Windows Server 2016 is no longer supported
- Preparing Active Directory: schema and object versions, PrepareAD, domain controller requirements
- Exercise: create your own migration checklist with the Exchange Server Deployment Assistant
Installation and Upgrade in Practice
- PrepareSchema, PrepareAD and PrepareAllDomains – required permissions and pitfalls
- Exercise: in-place upgrade of an Exchange 2019 organisation to SE
- Exercise: legacy upgrade from an Exchange 2016 organisation – switching coexistence, namespace and Autodiscover
- Migrating mailboxes, public folders and resources: move requests, batch sizes, error handling
- Cleanly uninstalling old servers, cleaning up AD objects and certificates
Operation and Administration
- Exchange Admin Center and Management Shell, recipient and group management
- Databases, metacache database and sizing on modern hardware
- Database Availability Groups: design, failover and search infrastructure
- Mail flow and transport: connectors, transport rules, DLP with DocParser instead of the previous Oracle component
- Client access: MAPI over HTTP, Autodiscover, supported Outlook versions
- Backup and restore, Health Checker after every security update
Security and Hardening
- TLS 1.2 and 1.3 as standard, legacy protocols disabled – effects on multifunction devices and third-party systems
- Windows Extended Protection is active by default: typical breaking points with load balancers
- Locking down Exchange Admin Center and Management Shell from outside
- Modern authentication with OAuth 2.0 purely on-premises via AD FS
- Server Core as a hardening option: operational practice and limits
Hybrid with Exchange Online – the Mandatory Changes for 2025/2026
- Hybrid basics: cloud-based Hybrid Configuration Wizard, Entra Connect, certificates, federation trust
- Dedicated Exchange hybrid app: why the shared service principal has been blocked since 31 October 2025, and which builds are mandatory
- Exercise: create an Entra application, configure Auth Server, verify with Test-OAuthConnectivity
- Remediating CVE-2025-53786: removing old certificates from the first-party service principal
- EWS endgame: shutdown starts October 2026, complete by April 2027 – moving to the Graph workflow and its gaps
- Exit strategies: hybrid licensing via the HCW, or Exchange Management Tools with no running server at all