I have a similar setup with an email security appliance, but I still allow users to access OWA/ActiveSync, etc.
All interactions for email are handled by your security mail gateway, and Exchange is only used as a backing store? Without OWA/ActiveSync, when users send/receive email, does it do some sort of IMAP/POP3 passthrough to Exchange? (Or maybe users can't access email off-prem?)
I won't be much help, since I'm not sure how that works, but given your scenario, you could consider continuing to use your perpetual 2016/2019 licenses even after October's EOL. But there would still be security concerns as it ages without patches.
If you're using Exchange ONLY as a backing store then you could also consider an alternate product, many of them are free. Additionally, many email security appliances can act like/as an email server.