Industry: Industrial & Defense Manufacturing Service Focus: On-Prem Exchange Server Upgrade, Security Hardening & CMMC/DFARS Compliance Engagement Length: 8 Weeks | Downtime: Zero

The Quick Version

A 280-employee industrial equipment manufacturer supplying parts to automotive, aerospace, and defense customers was running Exchange Server 2016 — 18 months behind on security patches — and it nearly cost them an $18M defense contract. We came in as the white-label technical team for their MSP partner, upgraded them to Exchange 2019 with zero downtime, closed 23 critical/high vulnerabilities, and got them through a CMMC Level 2 assessment with zero Exchange-related findings. They kept the contract. Then they won $6.2M more in new business because of it.

Here’s how it actually happened.

The Backstory: When “It Still Works” Isn’t Good Enough

If you support manufacturers in the defense supply chain, you already know the drill: DFARS and CMMC compliance isn’t optional, and “we haven’t had a breach yet” is not an answer auditors accept.

This particular manufacturer was in that exact spot. Defense contract requirements meant they couldn’t lift-and-shift to the cloud — classified workloads and legacy system dependencies kept them on-prem, full stop. That’s a common reality for a lot of manufacturing and defense clients, and it’s exactly the kind of environment where things quietly fall behind because nobody wants to touch a live mail server.

Their in-house IT team — just three people — was already stretched managing day-to-day operations. Exchange patching kept getting pushed. By the time their MSP partner brought us in, the environment looked like this:

  • Exchange Server 2016 CU12, 18 months behind on updates
  • Exposed to ProxyLogon, ProxyShell, and other well-documented CVEs
  • 310 mailboxes, 1.8TB of mail data on aging, 7-year-old physical servers
  • No MFA, weak TLS, no modern authentication
  • Minimal phishing/malware protection
  • DR procedures that had never actually been tested
  • Real DFARS and CMMC Level 2 compliance gaps
  • Sluggish OWA and unreliable mobile mail sync

Then came the letter every manufacturer in the defense supply chain dreads: formal notice from the prime contractor that remediation was required to keep the contract. That’s when the timeline stopped being flexible.

What We Actually Needed to Pull Off

Three things had to be true at the same time, or the project wasn’t a success:

  1. Zero downtime. Production email had to stay live for all 310 users, the entire way through.
  2. Full security hardening, not just a version bump — MFA, encryption, modern auth, phishing protection, the works.
  3. Compliance alignment with CMMC Level 2 and DFARS, backed by documentation an auditor would actually accept.

And it had to happen with a rollback plan in place, because nobody signs off on a mail migration with no safety net.

How We Got It Done

We ran this as an 8-week side-by-side upgrade — meaning Exchange 2019 came up right alongside the existing 2016 environment instead of replacing it in place. That approach is the difference between a stressful cutover weekend and a migration nobody even notices.

1. Modernized the Infrastructure First

Before touching mail flow, we replaced the aging hardware:

  • New Dell PowerEdge R650 servers running Windows Server 2022 with security baselines applied
  • 10GbE networking and NVMe storage for actual performance headroom
  • Upgraded firewalls and tighter network segmentation

2. Migrated Mailboxes in Waves, Not All at Once

We added the new Exchange 2019 servers into the existing Database Availability Group (DAG), then moved mailboxes department by department — IT & Admin first, then Engineering, then Manufacturing. Nobody lost access mid-move. Once everything was validated on the new platform, we decommissioned the old 2016 servers.

3. Locked Down Security End to End

This is where most of the real risk reduction happened:

  • Enforced MFA across OWA, ECP, and ActiveSync
  • Disabled legacy authentication entirely
  • Enforced TLS 1.2 with strong cipher suites
  • Rolled out Microsoft Defender for Office 365 — Safe Links, Safe Attachments, Anti-Phishing
  • Turned on audit logging with SIEM integration
  • Deployed Edge Transport servers in the DMZ
  • Implemented SPF, DKIM, and DMARC
  • Enabled BitLocker for data at rest
  • Rebuilt admin access around role-based, least-privilege accounts

If you want a closer look at how we approach this kind of layered hardening across client environments, it’s the same discipline behind our managed security services.

4. Built the Compliance Paper Trail

CMMC and DFARS assessments live and die on documentation, so we treated that as a deliverable, not an afterthought:

  • Access control, auditing, and 7-year log retention
  • Device compliance enforcement for mobile mail access
  • Encryption in transit and at rest
  • Incident monitoring tied into their broader response process
  • Full evidence packages ready for the auditor, not assembled the week before

This is the kind of groundwork that makes security compliance and reporting something you can point to with confidence instead of scrambling to prove after the fact.

5. Tested Everything Before Calling It Done

We didn’t take “it should work” as an answer:

  • DAG failover testing
  • Full backup and restore validation
  • Vulnerability scanning
  • Penetration testing
  • A mock CMMC audit, run before the real one

6. Left Them Better Equipped, Not More Dependent

We wrapped with full architecture and disaster recovery runbooks, hands-on admin training on Exchange 2019 and the new security stack, and documented patch management and incident response procedures — so their three-person team could run this independently going forward, not call us for every routine task.

What Actually Changed

  • Upgraded to Exchange 2019 with zero outages
  • All 310 mailboxes migrated, zero data loss
  • Vulnerability findings dropped from 23 critical/high to zero
  • 140+ phishing attacks blocked in the first 90 days
  • Passed CMMC Level 2 with zero Exchange-related findings
  • The $18M defense contract stayed in place
  • 40% faster Outlook and OWA performance
  • Disaster recovery validated at a 2-hour RTO
  • Mobile email reliability, noticeably better
  • IT team fully trained and running operations independently
  • Avoided roughly $85K in cloud migration costs by staying on-prem
  • Opened the door to new defense contract bids
  • Landed $6.2M in additional contracts tied directly to their improved security posture

That last one is worth sitting with. This didn’t just fix a compliance problem — it became a competitive advantage.

Why This Matters If You’re an MSP With Defense or Manufacturing Clients

If you’re supporting clients under DFARS or CMMC requirements, on-prem Exchange isn’t going away just because the cloud is easier to sell. Classified workloads, legacy dependencies, and contractual requirements keep plenty of manufacturers anchored on-prem — and that means someone still has to patch, harden, and prove compliance on infrastructure most vendors would rather you forget exists.

We built our white-label delivery model around exactly that gap: deep Exchange expertise, a side-by-side migration methodology that doesn’t ask your client to accept downtime, and compliance documentation that holds up when an actual auditor shows up.

FAQ

What is a side-by-side Exchange upgrade, and why use it instead of an in-place upgrade? A side-by-side upgrade runs the new Exchange version alongside the existing one instead of upgrading in place. New servers join the existing DAG, mailboxes move over in controlled waves, and the old environment is decommissioned only after everything’s validated. It’s the approach most experienced Exchange admins prefer specifically because it avoids the all-or-nothing risk of a single cutover window.

Can you pass CMMC Level 2 with Exchange Server still hosted on-prem? Yes. On-prem Exchange doesn’t disqualify you from CMMC Level 2 — but it does mean encryption, access control, audit logging, and retention policies all need to be configured and documented correctly. In this case, proper hardening and evidence documentation resulted in zero Exchange-related findings.

Why would a company keep Exchange on-prem instead of moving to Microsoft 365? Usually it comes down to classified workload requirements, legacy application dependencies, or contractual/regulatory obligations — all common in defense manufacturing. Cloud migration isn’t always the available option, so hardening what’s already on-prem becomes the priority.

How long does an Exchange 2016-to-2019 upgrade like this typically take? This engagement took 8 weeks end to end, covering infrastructure buildout, phased mailbox migration, full security hardening, compliance documentation, and testing — with production email staying online the entire time.

What’s the real risk of falling behind on Exchange Server patching? Unpatched Exchange servers are a direct path to exploits like ProxyLogon and ProxyShell — both actively used in real-world attacks. Beyond the security exposure, falling behind can also trigger compliance failures that put contracts, certifications, and client trust at risk.


TechMonarch provides white-label managed IT services — including on-prem Exchange upgrades, security hardening, and compliance implementations — for MSPs supporting manufacturing and defense organizations across the U.S.