Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Safely updating an on-premises Exchange server starts with confirming its version and cumulative update (CU), then installing the latest security update (SU) made for that CU. Use Microsoft Exchange Health Checker before and after the update, follow Microsoft’s current release instructions, and restart both before and after installation. Microsoft lists Exchange Server 2016 and 2019 as having reached end of support on October 14, 2025, so check the live supportability matrix before planning an update.

1. Check support status and inventory every machine

Record the Exchange version, installed CU, current SU status, and role or topology for each Exchange server. Include computers running only Exchange Management Tools: Microsoft recommends installing SUs on those systems as well as on Exchange servers. Run Microsoft’s Exchange Server Health Checker to help identify installed versions and outstanding updates or manual actions.

Before choosing a package, consult Microsoft’s Exchange Server supportability matrix for the current support picture, including supported operating systems. It records that Exchange Server 2016 and Exchange Server 2019 reached end of support on October 14, 2025. Installing an update does not restore product support; if you operate an out-of-support version, treat migration or support planning as a separate priority.

2. Choose the security update for the installed CU

Security Updates are CU-specific. Use Microsoft’s Exchange Server build numbers and release dates and the linked release documentation to identify the latest SU that applies to the server’s version and installed CU. Check the release page for its KB identifier, prerequisites, vulnerability fixes, known issues, and any required manual actions. Do not rely on an old KB number or assume an update for another CU will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If you have missed earlier SUs, Microsoft says the latest SU for the applicable CU includes the preceding SUs released since that CU; you generally do not need to install every intervening SU individually. If the server has since moved to a different CU, select an SU for the currently installed CU instead.

3. Prepare the maintenance window and sequence

Check Microsoft’s Exchange Server prerequisites and the exact SU’s release instructions before starting. Among the baseline checks, confirm that Active Directory and the operating system meet the requirements, apply current Windows updates, and ensure Remote Registry is set to Automatic rather than Disabled.

Schedule a restart before and after installing the SU. In an organization with front-end and back-end Mailbox servers, Microsoft’s general update guidance is to update front-end servers first, then back-end servers. For a Database Availability Group (DAG) or another high-availability topology, follow the topology-specific Microsoft procedure and your organization’s maintenance and traffic-draining process; the general sequence is not a substitute for those steps.

4. Install the SU from an elevated command prompt

  1. Restart the Exchange server before installation.
  2. Open Command Prompt with administrative elevation.
  3. Run the applicable SU package according to its release instructions. Microsoft’s troubleshooting guidance documents running the full path to the correct .msp file from the elevated prompt.
  4. Wait for installation to finish, then restart the server again—even if the installer does not prompt for a final restart.

Use the instructions for the exact SU, not CU installation steps: Microsoft documents CU and SU as different update types and deployment procedures. Confirm the package matches the installed CU. A CU/SU mismatch is one documented cause of installation failure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

5. Verify the update and check for follow-up actions

After the restart, run Exchange Server Health Checker again. Review its report for the SU status and any manual actions required by that release. Then use your normal operational checks to confirm Exchange services, client access, and mail flow are healthy before closing the maintenance window.

If setup fails, use Microsoft’s Exchange update troubleshooting guidance for the observed error rather than trying an unrelated repair command. Documented failure cases include a CU/SU mismatch, services that do not stop, and invoking the wrong Setup.exe when using a bare executable name from PowerShell. Apply only the guidance that matches the error you actually encounter.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.