Tech News

Exchange Online Will Start Blocking Emails from Unpatched Exchange 2016 and 2019 Servers

Still running an Exchange 2016 or 2019 server in hybrid mode with Microsoft 365? Be careful if you are not keeping up with your mail server updates. Exchange Online will begin rejecting emails sent by servers that have not installed the October 2025 security update.

As shown in this new article published on the official Exchange blog, Microsoft is tightening the rules for those using Microsoft Exchange in a hybrid scenario with Exchange Online (Microsoft 365). In practice, the minimum version accepted by Exchange Online for Exchange 2016 and 2019 servers is about to be raised. While this is not new, these prerequisite changes have so far been made somewhat quietly: "Until now, these changes have been implemented silently", Microsoft admits.

This is also a good reminder that this mechanism is not new. In March 2023, I explained that Exchange Online would block emails coming from vulnerable Exchange servers. The process is based on a three-step system: a report in the Exchange admin center, then throttling, and finally email blocking. Since then, Microsoft has regularly raised the "oldest acceptable version" as new security updates are released.

A threshold aligned with the latest public update

This time, Microsoft has decided to raise the threshold to the latest public update available for Exchange 2016 and 2019, namely the October 2025 release. In fact, these two versions are no longer supported by Microsoft (support for Exchange Server 2016 and 2019 ended on October 14, 2025), so you must be enrolled in the paid ESU program to receive the latest security fixes. According to the official build numbers page, these are the versions in question:

  • Exchange Server 2019 CU15 - KB5066367, build 15.2.1748.39.
  • Exchange Server 2019 CU14 - KB5066368, build 15.2.1544.36.
  • Exchange Server 2016 CU23 - KB5066369, build 15.1.2507.61.

Any server that has not installed at least this KB and sends emails to Exchange Online will be affected. "This update level was released almost a year ago, and every organization should have installed it by now", Microsoft insists.

This security measure applies only to servers that connect to Exchange Online through an inbound OnPremises connector, in other words, the classic hybrid configuration. Servers that use another type of connector are not affected, and the blocking does not currently extend to "all servers in your organization". Microsoft does note, however, that "this could change in the future".

Microsoft is also already warning that, at some point, it will be necessary to migrate to Exchange SE or subscribe to the ESU program. Indeed, the required version will be too high for Exchange 2016 and 2019 if you only rely on the "free" updates.

Take action now: check the installed version if you are unsure, especially since Microsoft will enforce this as early as this week. The easiest way is to run Microsoft’s Exchange HealthChecker script, which displays the build number as well as the detected security update. The Exchange Online admin center also provides a report on on-premises Exchange servers connecting to your tenant.

Your move. But between us, it takes a special kind of confidence to avoid updating an Exchange server for nearly a year.

author avatar
Florian Burnel Co-founder of IT-Connect
Systems and network engineer, co-founder of IT-Connect and Microsoft MVP "Cloud and Datacenter Management". I'd like to share my experience and discoveries through my articles. I'm a generalist with a particular interest in Microsoft solutions and scripting. Enjoy your reading.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.