October 13, 2020 is four weeks from today. That is the day Exchange 2010 leaves extended support — for real this time, after Microsoft moved the original January 2020 date to give everyone one more year. We wrote about the twelve-month runway in January 2019. The runway is now a runway in the way a driveway is a runway. If you are still on Exchange 2010 this morning, this post is the conversation we are having with clients in your position, written down.
We know the population because they keep calling. In the last six weeks we have fielded assessments for a county government at 2,400 mailboxes, a healthcare-adjacent nonprofit at 600, and a manufacturer at 1,900 — all on Exchange 2010 SP3, all with a reason that sounded good in 2018. Between them and the estates we already moved this year, we have a decent sample of what "still on 2010 in September 2020" actually looks like, and it is rarely laziness. It is a line-of-business app that relays through the CAS array, a records-retention question nobody would sign off on, or a budget cycle that put the project in FY21.
None of those reasons will matter on October 14. So here is the triage.
What October 13 actually means
Unsupported does not mean the servers shut down. Mail flows on October 14 exactly as it did on October 12. What stops is everything that made running it defensible:
- No security updates. Not "fewer" — none. Every Exchange CVE published after October 13 is a permanent, unpatchable hole in your perimeter, because Exchange 2010 CAS is almost always internet-facing for OWA and ActiveSync.
- No time-zone or DST fixes, which sounds trivial until a calendar update lands wrong across 2,400 mailboxes.
- No support cases. When a database won't mount at 2 a.m., Microsoft will not take the call.
The second-order effects bite harder. Office 365 hybrid with Exchange 2010 is already the oldest supported coexistence configuration; expect it to fall off the support matrix quickly. Cyber-insurance questionnaires now ask explicitly about unsupported operating systems and applications, and "Exchange 2010 in production" is a checkbox that changes your premium or voids your coverage. Auditors working from CIS or NIST baselines will flag it in the first hour.
Unsupported is a state you can technically live in. It is not a state you can defend in writing.
The four-week triage matrix
We sort every late estate into one of three buckets, and the sorting takes one day, not one week:
| Bucket | Profile | Play |
|---|---|---|
| Move now | Under ~3,000 mailboxes, healthy directory sync or none yet, no on-prem app entanglement | Minimal hybrid or express migration to Exchange Online before the deadline |
| Move fast, land after | Larger estates, app relay dependencies, compliance holds | Start now, accept two to eight weeks past deadline, mitigate in the gap |
| Contain | Cannot move (air-gapped, contractual, political) | Isolate, restrict, document — and know this is a risk acceptance, not a plan |
The first question is always mailbox data volume and network egress, because physics does not negotiate. A quick sizing pass tells you whether four weeks is arithmetic or fantasy:
Get-Mailbox -ResultSize Unlimited |
Get-MailboxStatistics |
Select-Object DisplayName, ItemCount, TotalItemSize |
Export-Csv .\mbx-sizing.csv -NoTypeInformation
Sum the column, divide by your measured (not rated) upstream throughput, and add 40 percent for throttling and retries. On the 2,400-mailbox county estate that math said eleven days of continuous data movement on their circuit. That is a "move now" answer. We have seen 15,000-mailbox programs where the same math said four months — that estate should have called in 2019, and the honest answer now is bucket two.
Minimal hybrid and express: the fast paths
Full classic hybrid — HCW, federation trust, cross-premises free/busy, MRS moves, long coexistence — is the right architecture for a planned program. It is the wrong tool for a four-week sprint, because you spend the first two weeks on certificates, autodiscover, and namespace decisions.
The fast paths Microsoft actually gives you:
- Minimal hybrid (express migration). The HCW's lighter mode: it configures just enough — MRS endpoint, mail routing — to do native mailbox moves with a one-time directory synchronization, without committing you to permanent AAD Connect and full coexistence. For estates under a few thousand seats that intend to be cloud-only, this is the play. Moves are native MRS, so Outlook profiles reconnect on cutover instead of rebuilding, which is the difference between a quiet Monday and 2,400 helpdesk tickets.
- Cutover migration. Still supported from 2010, still viable under 150 mailboxes in practice (Microsoft says 2,000; do not believe it operationally). Every Outlook profile rebuilds. We use it for the 60-seat stragglers, not the 600-seat ones.
- Third-party movers. MigrationWiz and friends earn their licensing when the source is too fragile to trust — failing databases, no ability to install anything, or a 2010 org so unhealthy the HCW will not complete. We have run enough BitTitan projects to say: it moves data reliably; it does not move your autodiscover problem, your relay problem, or your directory problem. Those are still yours.
One thing we insist on in every fast path: pilot cohort first, even in a sprint. Fifty mailboxes, two days, including at least one executive assistant with delegate access to three calendars. Delegates and shared mailbox permissions are where express migrations go loud.
What we do not attempt in four weeks
Discipline about scope is what makes the sprint survivable. Off the table until after cutover:
- Public folder migration. 2010 public folders to Exchange Online modern public folders is its own project with its own failure modes. We move mailboxes now, keep PF access working through the hybrid plumbing or a scheduled second phase, and refuse to couple the two timelines.
- SMTP relay rationalization. Every 2010 estate has a receive connector accepting anonymous relay from a subnet nobody documented. The scanners, the ERP, the door-badge system. We inventory them (message tracking logs are the source of truth, not tribal knowledge), stand up a hardened relay path, and migrate senders after the mailboxes are safe.
- Archive and journal re-architecture. Journaling rules and third-party archives get an inventory and a continuity plan, not a redesign.
- Directory cleanup. UPN suffix corrections and OU rationalization are real work. In a sprint, we fix only what blocks sync.
The pattern: move the mailbox data behind the deadline; leave the ecosystem work in a numbered, funded phase two. Estates that try to fix everything at once in October are the estates still on 2010 in December.
The compliance conversation
For the clients who land in bucket three — genuinely cannot move in time — we make the risk explicit and written, because unwritten risk acceptance evaporates at the worst moment. The containment checklist we implement and document:
- Remove OWA and ActiveSync from the internet, or front them with a device that is itself supported and can virtual-patch. Unsupported CAS on port 443 to the world is the single worst posture available.
- Enforce TLS and modern client access where the 2010 stack allows; kill anything that cannot manage it.
- Snapshot the patch level, back up like the restore will happen (test it), and put the servers in their own firewall zone with logged, deny-by-default flows.
- Get a dated, signed risk acceptance from someone with budget authority, with a committed exit quarter attached.
That last item is not bureaucracy. It is the artifact that turns "IT never told us" into "leadership deferred with eyes open," and in government engagements it is frequently the document that finally unlocks the migration budget.
Ten years is a long life for a messaging platform, and Exchange 2010 was a genuinely good one — it gave us the DAG, and half of what we like about Exchange Online descends from it. But the decade is over in twenty-eight days.
If you're facing this
If you are reading this with production Exchange 2010 and no signed plan, the honest window for a clean pre-deadline move is closing this week, not next month. We have run this exact sprint several times this year and can tell you within a day which bucket you are in and what the calendar really looks like. Get in touch — the assessment is fast, and the deadline is not moving again.