Sounds to me like you let Exchange live as a zombie because you can't really kill the on-premise version. This means that the local exchange will become less and less important over time, as it will probably no longer be able to keep up with Exchange Online within a few years.
To make it less noticeable, you provide a few alibi functions such as tls1.3 or certificate handling in the gui. And the rest is probably simply backported or reportable “waste” from Exchange online at some point. 😉 There doesn't seem to be anything halfway useful anymore, such as:
1. DKIM agent for outbound mail
2. Dmarc filtering and reporting
3. Modern auth for active sync
etc. etc.