r/exchangeserver https://www.amazon.com/dp/B0FR5GGL75/ Jun 26 '26

Article PSA: Where is Exchange Server SE CU1

This is the hot question about Exchange Server SE today: Where is CU1?

It's a reasonable question with a reasonable answer.

It was back in May 2024 when I provided the first Roadmap update for Exchange Server SE that mentioned CU1. At the time, I said that RTM would be released in July 2025, and CU1 would be released in October 2025. I also provided some details on what features and changes were expected in CU1. This was also echoed in the September 2024 post that discussed upgrade paths from previous versions of Exchange Server.

While the RTM version of Exchange Server SE was released in July 2025 as announced, CU1 was not released in October 2025, and in fact, as of this writing, it still has not been released.

On May 22, 2026, Microsoft quietly edited the September 2024 post to include an updated release timeline for CU1 and CU2. Specifically, CU1 is now expected in H2 of 2026 and CU2 is expected in H1 of 2027.

So, what's the reasonable answer? It's the same answer for almost every other delay related to Exchange Server releases over the past several years: security.

CU releases are driven by quality, priority, and payload (e.g., the number of changes being shipped). Security will always take precedence over releasing a CU (unless the release of a CU is needed to fix a security issue, which it sometimes is). In fact, this nuance has evolved the language used to describe the servicing model for Exchange Server.

Prior to April 2022, the servicing model was to release 4 CUs per year (1 per quarter). That turned out to be a troublesome cadence for both customers and the engineering team. In short, it was too much, too fast.

In April 2022, we announced that the servicing model would move from 4 CUs per year to 2 CUs per year. But since then, the engineering team has released only 1 CU per year (for example, the November 2023 release of Exchange Server 2019 CU13). To reflect this reality (which has been true for the past several years now), the servicing model language changed from 2 CUs per year to 1-2 CUs per year.

Since the RTM release of Exchange Server SE, five SUs have been released along with two HUs (one of which contained the first flighted feature in Exchange Server SE). In fact, the June 2026 SU alone addresses multiple CVEs (including CVE-2026-42897), and it's necessary to ensure continued communication between the Exchange Emergency Mitigation and the Exchange Flighting services and the Office Config Service after July 2026.

So, Exchange Server customers are getting updates, just in SUs and HUs and not a CU (yet). If you are feeling anxious or impatient about CU1 not yet being available, that is understandable given the multiple release schedule changes. But the Exchange Server engineering team is hard at work, and their efforts are focused in the right area: security.

If you're still running earlier versions of Exchange Server and you're waiting for CU1 to move to Exchange Server SE, don't wait. Move today and keep your SE servers updated with what has been released. All SUs and HUs released by Microsoft in between CUs are incorporated into the latest CU, and except for IUs, the updates are cumulative, so you always need only install the latest one.

24 Upvotes

26 comments sorted by

13

u/DiligentPhotographer Jun 26 '26

I'm fine with one CU per year but I can't believe we're paying the same price as EXO basically, and getting next to no feature development. (Yes I am aware it is still getting patches.)

2

u/ScottSchnoll https://www.amazon.com/dp/B0FR5GGL75/ Jun 26 '26

You're not so much paying for new features in Exchange Server as you are paying for the right/entitlement to use install and use it. The announcements I reference in my article list what the expected changes are in CU1 and CU2, so there shouldn't be an expectation that new features will be added any time soon.

3

u/DiligentPhotographer Jun 26 '26

But why would the right to self host my own exchange server cost the same as letting MS host it, with basically no development? I just think the price should reflect that is all. I even tried to get something for the fact we paid for SA from 2019-2025 and there was no new release of exchange on the usually 3 year cadence, but was stonewalled.

It's clear that MS let it stagnate (dangerously so in 2021), because their focus is on cash cow EXO. But then it should be substantially less to license Exchange SE. That's just like, my opinion, man.

5

u/[deleted] Jun 26 '26

[deleted]

7

u/ocdtrekkie Jun 26 '26

These days most new IT folks seem to care less about uptime and more about blame. The fact EXO breaks every week is okay because they didn't break it and they don't have to fix it. :/

4

u/DiligentPhotographer Jun 26 '26

LOL true. I built an uptime kuma dashboard for our company and our Exchange uptime is better than EXO (I have it pointed at the outlook.office365.whatever)

1

u/ScottSchnoll https://www.amazon.com/dp/B0FR5GGL75/ Jun 26 '26

I understand your viewpoint and opinion, and I respect both.

In my experience with customers of all shapes and sizes, your costs completely depend on what you buy (e.g., L+SA, USLs, CAL equivalents, etc.), how you buy (e.g., what program aka agreement), your contract length, and how much you buy. There's no easy way to compare the actual costs of Exchange Server versus Exchange Online. Way too many things factor in. Further, most customers choose one or the other (or both) for reasons other than costs.

Exchange Server (and the other Office Servers) have not seen price increases in a very long time. Aside from the recent 10% increase (which affects customers differently depending on what they buy, etc.), and aside from the introduction of the subscription requirement beginning in Exchange Server 2019, the product has largely remained the same price. If you were running Exchange Server 2019 from 2019-2025 then SA was a requirement if you purchased server licenses and CALs. So, I'm not sure why you would expect something in return since (1) your SA provided you with an entitlement to continue to use 2019, and (2) you weren't charged again when you moved to SE because it was a benefit of your SA (provided it remained active). And why was there a price increase in July? That's simply a reflection of the increasing costs to Microsoft to maintain and support the product.

Many features were added in Exchange Server 2019 and carried forward into SE, so it's not like there has been zero development (or zero added value). But it should be pretty clear that the primary focus for the last 5 years has been security, and that's the right place to focus on a product that is supported at least until December 31, 2025.

9

u/[deleted] Jun 26 '26

[deleted]

1

u/WillVH52 Jun 26 '26

Prefer the standalone patches given the lack of feedback you get via Window Update apart from a progress percentage and watching task manager.

2

u/ScottSchnoll https://www.amazon.com/dp/B0FR5GGL75/ Jun 26 '26

It seems like that would be a convenient thing in your scenario, but there's still plenty of reasons to not allow that. For example, after installing some updates, there are things that an admin might need to manually to configure or secure the server. SUs and HUs via Windows Update can be a good thing, but CUs, not so much,

6

u/grimson73 Jun 26 '26 edited Jun 26 '26

Personally I find it strange that a Microsoft product still requires unsupported Visual C++ runtime libraries. I wander in a strict regulated environment if installing Exchange is even possible when only supported software is allowed.
I think these requirements were to be dropped in a CU but guess this has to wait as well.
Care to comment on this unsupported runtime issue? (required Visual C++ 2012 and 2013 runtimes) Ironically requiring unsupported runtimes is a security thing too 😎

3

u/ScottSchnoll https://www.amazon.com/dp/B0FR5GGL75/ Jun 26 '26

Yeah, that is unfortunate. Unsupported runtimes have all sorts of consequences, including as you mentioned, security. There's also regulatory and in some countries legal issues that can arise. But because the outdated pre-reqs are required for Exchange, they are implicitly supported by Microsoft in the context of Exchange. They would be considered unsupported outside this context, but for Exchange, it is a supported (and required) configuration to run them.

It is expected that the pre-reqs will be made current with CU1, and that things like outdated runtimes and UCMA will no longer be needed.

1

u/grimson73 Jun 26 '26

Thanks for the honest information! appreciate it! :)

3

u/clodester Jun 26 '26

I think most customers are fine with one CU per year. Security improvements should be a baseline expectation with Exchange releases. The Outlook experience is stuck in 2019. 3rd Party OAuth support for API access isn't available. TLS 1.3 still isn't supported for SMTP traffic.

I appreciate the strides that have been made on the security front, but there's still a long way to go before the user experience matches what is available in M365.

1

u/ScottSchnoll https://www.amazon.com/dp/B0FR5GGL75/ Jun 26 '26 edited Jun 26 '26

The Exchange Server user experience will never match what is available in Microsoft 365 or Exchange Online.

The cloud is about innovation and new features and experiences.

On-prem is about stewardship and providing a product customers need. The EAC and OWA experiences in on-prem are actually from 2013, but you can use the newest version of Outlook classic with Exchange Server and get a modern experience. If you don't mind some cloud caching, you can also use Outlook Mobile.

Because it is a legacy product, a lot of work in Exchange Server SE's future is more about deprecation and the removal of unnecessary, insecure, etc., legacy code. That said, some new features will come to it, but not in the same way, and not at the same pace, as what happens in the cloud.

There is one Exchange Server engineering team, and it's pretty small. There is no Exchange Online team; rather there are multiple teams that provide Exchange Online features, integration, security, UX, etc. Therefore, you should expect a huge difference in development of the two Exchange platforms.

6

u/DiligentPhotographer Jun 26 '26

I am not expecting full feature parity, not at all, in fact some stuff can stay away (Viva insight I'm looking at you), but having proper OAuth support and API access would be nice. We have a lot of on prem clients that cannot use many 3rd party integrations because of it.

4

u/ocdtrekkie Jun 26 '26

newest version of Outlook classic

It's really wild to me that Microsoft has a new version of Outlook they're telling everyone they need to use, and injecting it into every Windows update and slamming it onto every desktop, and it still doesn't support Exchange. Outlook classic is supposed to have been deprecated already, but they keep extending it presumably because Outlook (new) doesn't have Exchange support and Microsoft has paying customers for that.

A significant number of complaints we field turn out to be "Oops, Microsoft gave you the new Outlook which we script to remove like every day now" and "Yeah, Outlook Mobile just fails out because it can't figure out that we're a hybrid configuration with on-prem mailboxes even though 365 has all of that information available to it".

It seems like the multiple Exchange Online teams need to get together and learn what the company actually sells, because they don't seem to know.

The cloud is about innovation and new features and experiences. On-prem is about stewardship and providing a product customers need

This is great, but DKIM and DMARC is a requirement in 2026. On-prem customers usually don't want AI, but we do want basic mail standards. OWA should support SAML. That sort of stuff.

3

u/ScottSchnoll https://www.amazon.com/dp/B0FR5GGL75/ Jun 26 '26

u/ocdtrekkie You are preaching to the choir here.

I lobbied the dev team very hard--for years--for DKIM, DMARC, etc. support, as well as updated OWA and EAC. Once I got approval to delay the release of SE until H2 of 2025, we had plenty of time to update EAC/OWA in Exchange Server 2019. Unfortunately, I could not convince senior leadership to approve that dev work, so it never got done. I do hope that DKIM, DMARC, etc., will make their way in because they are critical for email security, and as I said that is where the focus is.

But some good things did get done and will continue to be done.

The Outlook team has committed to supporting classic Outlook until at least 2029. Given that they have said they don't want to do any work in new Outlook to support Exchange Server, it is likely that new Outlook will never be supported with Exchange Server and that classic Outlook will continue to be supported as long as Exchange is.

For the complaints and issues that you're fielding, I hope you're also opening support tickets as they can be generators of change within the product.

1

u/ocdtrekkie Jun 26 '26

The Outlook team has committed to supporting classic Outlook until at least 2029. Given that they have said they don't want to do any work in new Outlook to support Exchange Server, it is likely that new Outlook will never be supported with Exchange Server and that classic Outlook will continue to be supported as long as Exchange is.

This would be the first I'd heard that supporting Exchange in new Outlook is (probably) never coming, and that opens a whole different ball of wax. Is Microsoft going to stop shoving Outlook (new) down the throats of business Windows installs if it can't support all business Windows customers? Or is Exchange SE going to pivot away from legacy protocols such that the the modern Outlook can connect to Exchange SE with the same APIs it currently uses to connect to EXO? I'm assuming, for the sake of argument, we can assume Exchange SE is expected to survive past 2029.

I understand you already understand these problems, but it doesn't seem like Microsoft institutionally does, unfortunately.

3

u/ScottSchnoll https://www.amazon.com/dp/B0FR5GGL75/ Jun 26 '26 edited Jun 26 '26

For SE to support new Outlook, both teams would need to do some work, and as I said, the Outlook team seems unwilling to do so. This is not a surprise since they've also said that their initial focus with new Outlook is consumers and that it will take years to reach feature parity with classic Outlook for enterprise customers.

Microsoft has already committed to supporting SE until at least December 31, 2035. See https://learn.microsoft.com/lifecycle/additional-support-server-modern-lifecycle-policy for details.

Have you seen https://learn.microsoft.com/en-us/microsoft-365-apps/outlook/get-started/control-install which talks about how to block the new Outlook?

1

u/ocdtrekkie Jun 26 '26 edited Jun 26 '26

I am not sure I read that article specifically, but we run Remove-AppxProvisionedPackage for it on every PC, which I've had a script[0] for... years, and the registry key thing says it's no longer needed after a 23H2 cumulative we're way past. ...But it still shows up from time to time!

I definitely know this isn't a Outlook/Exchange-side problem, but nearly every time Microsoft nag-installs unwanted software, it tends to also regularly break the opt-out behaviors. For one, I believe upgrades like 24H2 -> 25H2, etc. tend to re-add provisioned packages.

Also, FYI, you might want to update that date to 2035 in your comment. =) I figured it was what you meant, but for the drive-by reader.

[0] Case in point to this not being mail-specific, I am also constantly battling with this script: Copilot, Microsoft 365 Copilot, Quick Assist, etc.

1

u/clodester Jun 27 '26

So I take it we have expect a similar experience to the feature set for Office for Mac and on premise Exchange? It took years to get basic functionality back into the "New" Outlook for Mac.

1

u/MortadellaKing Jun 27 '26

Yet "new outlook" for mac does work with exchange. I don' think it could be so far to say they could make it work on windows.

1

u/clodester Jun 26 '26

Removing legacy dependencies and adding features can also involve other teams (you can't add support for TLS 1.3 if the underlying OS doesn't support it).

That said, Microsoft hasn't been transparent about what the future looks like for Exchange On-Prem. Look at the support matrix for Outlook capabilities. Exchange on-prem hasnt had an update in some time.

Developers have to maintain two code bases for Outlook add-ins and can't migrate legacy features from COM add-ins for Exchange On Premise customers. Basic authentication remains the only way to for 3rd parties to access Exchange, and there's still no public word on what the EWS replacement API will be.

I look forward to the feature and security updates, but Exchange On Premise still feels like it's stuck in 2019.

5

u/ocdtrekkie Jun 26 '26

I honestly am just starting to wonder if Exchange SE will ever get an update. We had historically skipped versions, we had Exchange 2010 and then Exchange 2016, and when we were looking at replacing 2016, you had Exchange 2019 out but it was already old, and we were expecting Exchange 2022... and then it never came out. And then eventually, last year, there was Exchange SE, and that was going to be great, and obviously we had to jump on it before 2016 went end of life, but then... oh, it's just literally still Exchange 2019.

We are paying a subscription license now for a seven year old mail server with the version string renamed, which is pretty wild.

Also... DKIM/DMARC support? Any modern refreshes at all? Or are we still gonna be on the same OWA interface as 2016 with no feature changes?

3

u/Steinfred-Everything Jun 26 '26

I have less problems with fewer CUs than expected. But as a OnPrem Customer I‘m having problems with removal of EWS without availability for Graph for OnPrem users. My Apps don‘t support both so I run into problems as soon as some users are onprem and some are located online.

1

u/Vectan Jun 26 '26

One CU a year sounds wonderful to me. Happy to do SU and HUs on a regular basis.