The administration and maintenance of Microsoft Exchange Server to ensure secure, reliable, and efficient email and collaboration services across an organization.
Based on my research that some small businesses prefer keeping their data entirely on premises rather than moving to Microsoft 365, and Exchange Server Subscription Edition (SE) is designed exactly to support organizations that choose to stay on-site.
Because they are migrating from Windows Server 2019 to Windows Server 2025, this requires a Legacy Upgrade (Side-by-Side Migration) path. (While Exchange SE supports a fast in-place upgrade, Windows Server OS changes require a new VM build).
Will I need to install a second signed certificate on the 2025 server?
You do not need to buy or issue a separate, unique certificate. The best practice is to export your existing commercial SSL certificate (including the private key) from the 2019 server as a .pfx file and import it directly into the new Windows Server 2025 environment. Exchange SE will utilize the exact same namespaces (mail.company.com, autodiscover.company.com). During the brief coexistence period, both servers can share the same certificate.
Will I keep the new internal server's name and just re-map public names via the firewall?
Yes, exactly. The new VM will have its own unique internal Active Directory host name (e.g., EXCH2025.domain.local). However, inside Exchange SE, you will configure all the Virtual Directories (OWA, ECP, ActiveSync, Autodiscover, Web Services) to use the exact same external and internal URLs currently pointed at your old server (ex: https://mail.company.com/owa).
During the weekend, you will update your internal DNS records and your external firewall/NAT rules to point the IP target from the old server to the new server's IP address.
Is it safer to run them in parallel for a week or two, or decommission right away?
It is recommended to run them in parallel for at least a week. Even for 35 mailboxes, keeping the old server online but "empty" gives you a safe fallback window.
- It ensures that if any stray devices (like printers, scanners, or legacy applications) are hardcoded to the old server's IP address for SMTP relay, you will catch them in the logs.
- Once you confirm that zero traffic is hitting the old 2019 server, you can safely uninstall Exchange through the Control Panel to gracefully remove it from Active Directory.
Step-by-Step Migration Checklist
Pre-Migration & Prerequisites
- Update Exchange 2019: Ensure the source 2019 server is updated to the latest Cumulative Update (CU14 or CU15) to guarantee Schema compatibility.
- Prepare Windows Server 2025: Build the new VM, join it to the domain, and install the required Exchange SE prerequisites (including .NET Framework 4.8.1, Visual C++ Redistributables, and the IIS URL Rewrite Module).
- Prepare Active Directory: Run the Exchange SE setup with the AD switches:
Setup.exe /PrepareSchema /IAcceptExchangeServerLicenseTerms_DiagnosticDataONfollowed by/PrepareAD. - Install Exchange SE: Run the installer on the Windows Server 2025 VM to establish the Mailbox role.
Configuration & Certificate
- Import SSL Certificate: Import the
.pfxcertificate onto the 2025 server and assign it to the IIS and SMTP services via the Exchange Admin Center (EAC). - Configure Virtual Directories: Match the internal and external URLs on the new server to mirror the old server's configuration.
- Configure Send/Receive Connectors: Recreate any custom anonymous relay connectors on the new server for scanners or local applications.
Mailbox Migration & Cutover
- Create Local Move Requests: Start moving the 35 mailboxes from the old database to the new database. With 35 mailboxes over a local virtual network, this should complete very quickly.
- Update DNS and Firewall: Change internal DNS records for your mail namespace and update external firewall forwarding rules to point to the new server's local IP.
- Test Connectivity: Test external Outlook connection, Autodiscover, OWA, and mobile device mail flow.
Coexistence & Decommissioning
- Monitor Logs: Keep both servers running. Watch for any legacy internal devices attempting to relay mail through the old server's IP.
- Graceful Uninstall: After a week of total silence on the old server, log into the 2019 server and uninstall Exchange via Programs and Features. This cleanly cleans up the Active Directory topology configuration. Decommission the VM afterward.
Note on Licensing: Ensure that the client has an active Software Assurance (SA) plan or eligible cloud licensing subscriptions (like M365 E3/E5 which cover hybrid on-premises rights), as Exchange Server SE utilizes a subscription-based licensing structure rather than traditional fixed perpetual keys.
I hope this information helps. and if you have any further questions, please feel free to ask via comment section!
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.