CIO Brief: When to Finally Leave On-Prem Exchange
Retrospective: this article looks back at events from September 2022, written in 2026 with the benefit of hindsight.
The short version: In late 2022, a third major wave of attacks hit company-run Microsoft Exchange email servers. Microsoft took about six weeks to release patches, leaving organizations relying on workarounds. Companies using Microsoft's cloud email weren't affected.
Three waves in two years
- 2021: ProxyLogon — tens of thousands of servers compromised.
- 2021: ProxyShell — exploited by ransomware groups.
- 2022: ProxyNotShell — weeks of workarounds before a patch.
Each required emergency work, and each created breach risk for organizations that hadn't moved to the cloud.
When to leave on-premises email
Reasons organizations kept Exchange servers included regulatory concerns, application dependencies and recipient management. Many of those reasons have weakened: Microsoft now supports removing the last hybrid server for many customers, and Exchange Online meets most regulatory requirements.
Questions to ask your team
- Why do we still run Exchange servers?
- What did the last three emergencies cost in staff time?
- What would it take to retire the remaining servers?
What good looks like
All mailboxes in Exchange Online, the last server removed, and any remaining on-premises dependencies documented with a plan.
The decision
Set a date to retire your remaining Exchange servers. The recurring emergency cost is usually higher than the migration cost.
- ProxyNotShell (Sept 2022): The Third Major Exchange Zero-Day Wave Incident Teardowns
- How to Decommission the Last Exchange Server in a Hybrid Deployment How-To & Hardening
- Detecting Exchange Zero-Day: Defender XDR and Sentinel Hunting Queries Detection & Response