Retiring the last on-prem Exchange server for a law firm by re-platforming application and device email onto Microsoft 365 High Volume Email and Azure Communication Services.

One server was still standing after the migration.
The firm had already moved its mailboxes to Exchange Online and signed off the migration. A single on-premises Exchange server was still running, still patched every month, still consuming a Windows Server and Exchange licence, and still appearing in every security review and cyber-insurance questionnaire the firm completed.
That carried real risk. On-premises Exchange has been the target of some of the most serious exploits of the last few years, including ProxyLogon and ProxyShell, and an internet-reachable mail server that routes privileged client communication is exactly the kind of asset a firm wants gone once it no longer needs it.
The technical reason it could not be switched off
The server was still acting as an SMTP relay. Across the firm, systems sent mail through it instead of through a mailbox:
Some of that mail stayed inside the firm; some of it went out to clients, courts, and opposing counsel. Microsoft's own guidance is to remove on-premises Exchange once mailboxes are migrated, and hybrid was never designed to be a permanent home. You cannot decommission a relay while live business systems depend on it, and switching it off without a plan would have stopped scanning, invoicing, and new-client intake. Every one of those mail streams needed a new, supported home before the server could go.

BITSUMMIT re-homed each mail stream onto a supported Microsoft service before touching the hybrid configuration, starting from the data on what the relay was actually carrying.
1. Map every connection the server carried, and how it authenticated
Using message-tracking, SMTP protocol, HttpProxy (IIS), and Windows Security logs, BITSUMMIT inventoried every connection still touching the server, not just SMTP relay, working from what the server was actually doing rather than from out-of-date documentation. Each connection type was catalogued with the way it authenticated, so nothing was retired on assumption:
Every real mail stream was then sorted by destination, internal recipients versus external, which decided where each one would go next.
2. Match each sender to the right Exchange Online send path
Once mailboxes are in Exchange Online, Microsoft supports a small set of ways for apps and devices to send, each with its own endpoint, authentication, and limits. Rather than force everything down one path, BITSUMMIT matched each sender to the best fit:
Every sender moved onto a supported, controlled path, and nothing was left relaying anonymously by IP through an on-premises server.
3. Roll out in effort order, easiest senders first
4. Cut over and decommission

Retiring the last Exchange server cut cost, reduced ongoing operational work, shrank the firm's attack surface, and left it running entirely on cloud mail services.
Direct cost removed
Management and operations reduced
Security posture strengthened
Technical end-state
Why it matters for a law firm
Email is both the firm's primary tool and one of its biggest confidentiality liabilities. Removing the last on-premises Exchange server shrinks the surface where privileged communication can be exposed, and moving application mail onto authenticated cloud services makes that mail both more secure and more reliable. The result is a smaller, cheaper, and more defensible environment running entirely on Microsoft 365.
Tell us what you're trying to modernize, secure or migrate. We'll bring a plan and a named senior engineer.
Schedule a call →