Microsoft 365How-To & HardeningRetrospectives

How to Decommission the Last Exchange Server in a Hybrid Deployment

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from September 2022, written in 2026 with the benefit of hindsight.

Many organizations moved all mailboxes to Exchange Online but kept one Exchange server for recipient management. Microsoft now supports removing it in many scenarios. Here is how to decommission the last Exchange server safely.

Step 1: Confirm you're eligible

You can remove the last Exchange server if:

  • All mailboxes (including shared and resource mailboxes) and public folders are in Exchange Online.
  • You use Entra Connect or cloud sync for directory synchronization.
  • No on-premises applications need to relay mail through Exchange (or you've moved relay elsewhere).
  • You don't need hybrid features such as cross-premises free/busy with remaining on-prem mailboxes.

Step 2: Plan SMTP relay

Devices and applications sending mail through the Exchange server need a new path: Exchange Online connectors, direct send, SMTP client submission with modern authentication, or a dedicated relay service.

Step 3: Install the management tools

Install the Exchange Server Management Tools (from the latest Exchange Server version) on a domain-joined management machine. They provide the PowerShell snap-in to manage Exchange attributes in Active Directory without a running server.

Step 4: Switch recipient management

Update processes and scripts to use the management tools to create remote mailboxes and edit attributes. Restrict access with the provided RBAC model.

Step 5: Shut down and monitor

Shut down the Exchange server (don't uninstall yet). Monitor for broken mail flow, application failures and management issues for a few weeks.

Step 6: Decommission

Follow Microsoft's guidance for removing the server permanently. Don't uninstall Exchange in a way that removes Exchange attributes from Active Directory.

Step 7: Clean up

Remove DNS records, firewall rules and certificates associated with the server.

decommission last exchange serverProxyNotShell2022

More on this story