Microsoft to bounce mail from outdated Exchange servers
Microsoft is tightening security enforcement for on-premises Exchange Server, warning administrators that outdated installations will soon be prevented from delivering email to Exchange Online. From the second week of September, Exchange Server 2016 and 2019 systems sending mail via an inbound "OnPremises" connector must be updated to the final public update baseline released in October 2025, or their messages risk being throttled or blocked entirely. The move is part of an ongoing push by Microsoft to ensure hybrid deployments run on patched, secure software, though it has caused frustration among some administrators.
Microsoft says the required update level has been available for almost a year and that all organisations should already have applied it, noting that any future baseline increase would effectively require enrolment in Extended Security Updates or migration to Exchange Server Subscription Edition. The restriction applies specifically to servers using the OnPremises inbound connector type, so other mail delivery routes remain unaffected, though Microsoft has hinted the scope "might change in the future". Microsoft Principal Project Manager Nino Bilic stressed that such changes would have occurred regardless of the advance announcement, adding that administrators must ensure Exchange updates are applied on schedule.
- Unpatched Exchange 2016/2019 servers will be blocked from reaching Exchange Online
- Servers must meet the October 2025 update baseline from mid-September
- Only OnPremises inbound connector mail flow is affected, for now