The administration and maintenance of Microsoft Exchange Server to ensure secure, reliable, and efficient email and collaboration services across an organization.
Exchange Server Subscription Edition (SE) is treated as the next evolution of Exchange Server 2019, so the move from one SE server on Windows Server 2019 to another SE server on Windows Server 2025 follows the same “legacy upgrade” pattern used when moving to new hardware/OS.
A suitable high‑level approach based on the provided information:
- Plan the migration as a legacy upgrade
Exchange SE supports two upgrade methods: in‑place upgrade (from Exchange 2019 CU14/15) and legacy upgrade. Because the goal is to move to a new Windows Server 2025 VM, this is a legacy upgrade scenario:- Add a new Exchange SE server on Windows Server 2025 to the existing organization.
- Move mailboxes and system mailboxes to the new server.
- Move any remaining services (e.g., mail flow, client access namespaces).
- Decommission the old Exchange SE server on Windows Server 2019.
This is consistent with the guidance that legacy upgrades are used when switching to new hardware or a newer Windows Server version.
- Server naming and namespaces
The new Exchange SE server joins the existing organization with its own server name. The internal and external client access is controlled by namespaces (URLs) and DNS, not by the Windows server name.- Keep the existing namespaces (for example,
mail.contoso.com,autodiscover.contoso.com) and point them to the new server when ready. - Internally, Outlook and other clients continue to use the same URLs; only DNS and load balancer/firewall mappings change.
- There is no requirement that the new server reuse the old server’s name.
- Keep the existing namespaces (for example,
- Certificates
Certificates are bound to namespaces, not to specific servers. For the new Windows Server 2025 Exchange SE server:- Use the same certificate subject/subject alternative names as on the current server (for example,
mail.contoso.com,autodiscover.contoso.com). - Either export the existing certificate (with private key) from the old server and import it on the new server, or request a new certificate from the CA that covers the same names.
- Assign the certificate to the required Exchange services (IIS, SMTP, etc.) on the new server.
A second signed certificate is not strictly required if the existing one can be reused and is still valid, but a new certificate is also acceptable as long as it covers the same namespaces.
- Use the same certificate subject/subject alternative names as on the current server (for example,
- Parallel operation vs. immediate cutover
The documented guidance for legacy upgrades is to add the new server, migrate workloads, and then uninstall the old server. This naturally implies a period of coexistence:- Bring up the new Exchange SE server on Windows Server 2025 and join it to the organization.
- Move all user mailboxes, arbitration/system mailboxes, and any remaining resources to the new server.
- Reconfigure mail flow and client access (DNS/firewall) to point to the new server.
- Once validated, decommission the old server.
Keeping both servers running in parallel for a short period (for example, a week or two) is aligned with the legacy upgrade pattern and provides a safer rollback window than removing the old server immediately after the move.
- Use the Exchange Server Deployment Assistant
For a detailed, step‑by‑step checklist tailored to this scenario (on‑premises Exchange SE moving to new hardware/OS), use the Exchange Server Deployment Assistant. It generates a scenario‑specific plan for adding the new server, moving mailboxes and services, and decommissioning the old server. - General upgrade/maintenance practices
When installing Exchange SE on the new Windows Server 2025 VM, follow the same best practices as for installing/upgrading Exchange 2019 CUs (for example, maintenance windows, backups, and validation steps) as referenced in the cumulative update guidance.
References: