On 14 October 2025, Microsoft ended support for Office 2016 and 2019, Exchange Server 2016 and 2019, Outlook, Skype for Business, and Windows 10 — all on the same day. The software still runs. It just doesn’t get fixed anymore. If you’re still on it, this isn’t a deadline approaching. It’s a gap already open.
This wasn’t a single product sunsetting. It was a lifecycle convergence — which is why so many Philippine organizations are carrying more exposure than they realize.
End of support. No more security fixes, bug fixes, technical support, or time zone updates for any of the products below.
Nothing breaks on day one — which is why this risk gets deferred. But the protections quietly stopped, and the exposure compounds every month you stay.
Any vulnerability discovered from now on stays open in your environment permanently. Attackers know exactly which versions are unpatched, and mail servers are among the most actively targeted assets in any organization.
Stability and usability issues that surface will not be resolved. You're running software that has been formally frozen.
If something fails, Microsoft will not help you fix it. Your options narrow to your internal team and whatever your partner can improvise.
A quiet one with real operational bite: calendars and scheduling drift as time zone rules change — a genuine problem for teams working across ASEAN and with global clients.
Outlook 2016 is no longer supported for connecting to Microsoft 365 services — so even partially cloud-migrated organizations are exposed on the client side.
Every month adds newly disclosed vulnerabilities that will never be closed. The gap between "supported" and "what you're running" widens on its own, without you doing anything.
The Data Privacy Act (RA 10173) requires personal information controllers to implement reasonable and appropriate organizational, physical, and technical measures to protect personal data against unauthorized access.
Now apply that standard to a mail server that Microsoft has publicly confirmed will receive no further security fixes. If a breach occurs and the National Privacy Commission asks what technical measures were in place, “we were running software the vendor stopped patching nine months ago” is not a defensible answer. This is the exposure that turns an IT deferral into a board-level issue.
Microsoft's own guidance is unambiguous: installations continue to run after the end-of-support date, but continuing to use them invites potential security risk — and organizations should act now.
— Microsoft, Exchange Server end of support guidanceWe’ll give you the honest version, including where our recommendation doesn’t apply.
Move mailboxes to Exchange Online and desktop apps to Microsoft 365 Apps. You exit the patch cycle problem permanently.
Microsoft's supported on-premises path. A subscription model rather than perpetual licensing.
Where available, ESU buys time on unsupported software. It is explicitly a bridge, not a destination.
Organizations on Office 2019 and Exchange Server 2019 aren’t one version behind — they’re an architecture behind. Migrating doesn’t restore parity, it changes what your business can do.
Microsoft 365 updates continuously. You never do this migration again.
Defender, Entra ID, MFA and Conditional Access — no separate purchase, no separate vendor.
Exchange Online removes your most-targeted on-prem asset from the equation entirely.
Purview DLP, sensitivity labels, retention and audit logs mapped to Data Privacy Act obligations.
Chat, calls, meetings, and files converge — the platform Skype's retirement was pushing you toward anyway.
Microsoft 365 Copilot works on your data inside the apps — impossible on a perpetual, on-prem stack.
Once you’re on Microsoft 365, the next question is which plan. Most organizations coming off legacy land on Business Premium — it carries the security and device management the old on-prem stack was doing manually.
Legacy migrations carry more variables than a cloud-to-cloud move — hybrid identity, mail flow, line-of-business integrations. That’s exactly why they need a partner who has done it repeatedly, not a first attempt.
We inventory every unsupported product you're running, map mailbox sizes, identity, and integrations — and quantify the risk in writing.
We stand up hybrid configuration, validate mail flow and authentication, and migrate a pilot group before touching anyone else.
Mailboxes migrate in batches around your business hours. Desktop apps move to Microsoft 365 Apps. Nothing cuts over blind.
Legacy servers are retired once migration is verified, security baselines are configured, and your people are trained on what's changed.
Typical range for 50–500 mailboxes. Complex hybrid or heavily integrated environments take longer — we’ll tell you that up front rather than discover it midway.
Legacy migrations go wrong in the details: hybrid identity, mail flow, the line-of-business app nobody documented. Technical depth isn’t a nice-to-have here — it’s the whole job.
Recognized four times for technical excellence and business impact delivering Microsoft solutions in the Philippines — backed by our Microsoft Solutions Partner designations and Advanced Specializations across Modern Work and Security.
We inventory every unsupported product in your estate, quantify the security and compliance exposure in writing, and right-size the Microsoft 365 licensing you'll actually need.
→Certified engineers configure hybrid, migrate mailboxes in staged batches, move desktop apps, harden your security baseline, and decommission the legacy estate cleanly.
→Teams instead of Skype, Outlook in the cloud, new security prompts — real change for your users. Role-based training and hypercare make sure it lands as an upgrade, not a disruption.
Exchange Server 2016 and 2019, Microsoft Office 2016 and 2019, Outlook 2016 and 2019, Skype for Business 2016 and 2019, Skype for Business Server 2015 and 2019, and Windows 10 — all on the same date. That convergence is why many organizations are carrying more exposure than a single-product sunset would suggest.
It works, and it will keep working — that’s what makes it dangerous. What stopped is the patching. Any vulnerability disclosed from October 2025 onward remains permanently open in your environment, and mail servers are among the most actively targeted assets an organization runs. The system’s uptime tells you nothing about its exposure.
It’s a serious question for your compliance officer. RA 10173 requires reasonable and appropriate technical measures to protect personal data. Running mail infrastructure that the vendor has publicly confirmed will receive no further security fixes is difficult to characterize as reasonable — particularly after a breach, when the question is asked in retrospect.
Where ESU is available it’s a legitimate bridge, but it’s priced per device, escalates in cost each year, and delivers security updates only — no bug fixes, no features, no roadmap. You pay to stand still, and you still have to migrate afterward. If a migration genuinely can’t happen this quarter, ESU buys you a window. It doesn’t buy you a strategy.
Not necessarily, but it’s a real question worth answering properly rather than assuming. For organizations with genuine residency or regulatory constraints, Exchange Server Subscription Edition is Microsoft’s supported on-premises path. We assess your actual obligations first — plenty of organizations believe they’re residency-bound when they aren’t, and some genuinely are.
Most organizations of 50–500 mailboxes complete in two to six weeks including discovery, hybrid setup, staged migration, and cut-over. Mail history, contacts, and calendars migrate intact, and mailboxes move in batches around your business hours — so no one loses a working day.
It reached end of support on the same date. Microsoft’s strategic path has been Teams for years, and Teams is included in Microsoft 365 — so for most organizations, retiring Skype for Business isn’t a separate project. It happens as part of the same migration.
Book a free exposure assessment. We’ll inventory every unsupported Microsoft product in your environment, quantify the security and compliance risk in writing, and give you a costed migration path you can take to your board.