Microsoft 365CIO BriefingsRetrospectives

CIO Brief: When to Finally Leave On-Prem Exchange

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from September 2022, written in 2026 with the benefit of hindsight.

The short version: In late 2022, a third major wave of attacks hit company-run Microsoft Exchange email servers. Microsoft took about six weeks to release patches, leaving organizations relying on workarounds. Companies using Microsoft's cloud email weren't affected.

Three waves in two years

  • 2021: ProxyLogon — tens of thousands of servers compromised.
  • 2021: ProxyShell — exploited by ransomware groups.
  • 2022: ProxyNotShell — weeks of workarounds before a patch.

Each required emergency work, and each created breach risk for organizations that hadn't moved to the cloud.

When to leave on-premises email

Reasons organizations kept Exchange servers included regulatory concerns, application dependencies and recipient management. Many of those reasons have weakened: Microsoft now supports removing the last hybrid server for many customers, and Exchange Online meets most regulatory requirements.

Questions to ask your team

  • Why do we still run Exchange servers?
  • What did the last three emergencies cost in staff time?
  • What would it take to retire the remaining servers?

What good looks like

All mailboxes in Exchange Online, the last server removed, and any remaining on-premises dependencies documented with a plan.

The decision

Set a date to retire your remaining Exchange servers. The recurring emergency cost is usually higher than the migration cost.

proxynotshell impactProxyNotShell2022

More on this story