← All blog articles

Windows Server 2016 End of Support: The ESU Costs and Migration Checklist

Kristof Van Stappen
Windows Server 2016 End of Support: The ESU Costs and Migration Checklist

Windows Server 2016 reaches end of extended support on 12 January 2027. After that date Microsoft stops issuing security updates, vulnerability patches, non-security hotfixes and assisted technical support across every edition. That much is on Microsoft’s lifecycle page and in the AI answer above these search results.

What is not there is the part that decides your budget: how Extended Security Updates are actually priced, why enrolling late costs more rather than less, and what you are supposed to do with the servers that genuinely cannot move. This checklist covers those three, in that order.

One date to hold on to before anything else. Sixteen months is not a long runway for an Active Directory migration, and several dependencies expire on the same day or have already gone.

The lifecycle position, in context

Version General availability Mainstream support ended Extended support ends ESU year 1 ESU year 2 ESU year 3
Windows Server 2012 R2 25 Nov 2013 10 Oct 2018 10 Oct 2023 9 Oct 2024 15 Oct 2025 14 Oct 2026
Windows Server 2016 15 Oct 2016 11 Jan 2022 12 Jan 2027 11 Jan 2028 9 Jan 2029 8 Jan 2030
Windows Server 2019 13 Nov 2018 9 Jan 2024 9 Jan 2029 8 Jan 2030 14 Jan 2031 13 Jan 2032
Windows Server 2022 18 Aug 2021 13 Oct 2026 14 Oct 2031 12 Oct 2032 11 Oct 2033 10 Oct 2034
Windows Server 2025 1 Nov 2024 13 Nov 2029 14 Nov 2034 13 Nov 2035 11 Nov 2036 10 Nov 2037

Last verified: September 2026. Source: Microsoft Lifecycle Policy, learn.microsoft.com. For the wider picture across every version, see our Windows Server end-of-life timeline.

Note the row above 2016. Windows Server 2022 leaves mainstream support on 13 October 2026, three months before 2016 leaves extended support. If your migration target is 2022 you are moving onto a version already in its extended phase, which is defensible but worth deciding deliberately rather than by default.

What expires alongside it

The operating system does not retire alone. System Center 2016 reaches end of support on 11 January 2027. Hyper-V Server 2016, IIS 10 on Server 2016, and Windows Server Update Services on Server 2016 go on 12 January 2027. So does .NET Framework 4.6.2, which a great many line-of-business applications still depend on.

Two more have already gone. Exchange Server 2016 left extended support on 14 October 2025. SQL Server 2016 left extended support on 14 July 2026. If you are running either on a 2016 host, the application layer expired before the operating system did.

Extended Security Updates: how the money actually works

This is the section every competing article skips, and it is where the surprises live.

Three procurement routes

Volume Licensing. Through an Enterprise Agreement, Enterprise Agreement Subscription, Server and Cloud Enrolment or Enrolment for Education Solutions, with active Software Assurance or qualifying subscription licences on the covered estate. Coverage is bought in twelve-month blocks and delivered as a Multiple Activation Key retrieved from the Microsoft 365 admin centre, then applied to every host through the Volume Activation Management Tool or a deployment script.

Azure Arc. On-premises physical servers and virtual machines connect to Azure Arc and enrol through the Azure portal, which removes the key deployment work entirely. Billing becomes a monthly operating expense against an Azure subscription and stops when a server is migrated or retired. Portal enrolment opens on 3 August 2026 and active billing begins on 13 January 2027.

Azure native. Workloads inside Azure Virtual Machines, Azure Dedicated Host, Azure VMware Solution and Azure Local have historically received ESU patches at no additional charge, without requiring Software Assurance. Microsoft has introduced a standardised pricing framework intended to align ESU list prices across Azure, on-premises and other clouds for offerings released after 1 April 2026, so confirm with your licensing contact whether that still holds for a 2016 workload rather than assuming it.

What it costs

Channel Licensed on Minimum Published baseline
Azure Arc, Standard edition Virtual or physical core 8 vCores per VM; 16 pCores per physical host ≈€4.79 ($5.21) per core per month; ≈€76.64 ($83.30) per month for a 16-core baseline, roughly €920 ($1,000) a year
Azure Arc, Datacenter edition Physical core only 16 pCores per host ≈€27.58 ($29.98) per core per month; ≈€441.29 ($479.66) per month for 16 cores, roughly €5,295 ($5,755) a year
Volume Licensing, Standard 16-core physical pack 16 physical cores per host 100% of the current Windows Server Standard licence list price, annually
Volume Licensing, Datacenter 16-core physical pack 16 physical cores per host 100% of the current Datacenter list price, annually, which runs five to six times Standard

Converted from USD list prices at approximately €0.92 to the dollar, September 2026; local EUR pricing may differ. Baseline figures published March 2026 and subject to change.

Two pricing models circulate and it is worth knowing which you are being quoted. The historical structure escalated by year: 75 per cent of the full licence price in year one, 100 per cent in year two, 125 per cent in year three. Microsoft’s current documentation and Azure Arc commercial baselines describe a standardised model at 100 per cent of the current full licence price in all three years. Ask your reseller which one applies to your agreement, in writing.

The Datacenter row is the one that changes decisions. Three years of ESU on a single 16-core Datacenter host runs to roughly €15,600 to €18,700 ($17,000 to $20,300), which exceeds the capital cost of buying a modern server with a Windows Server 2025 licence on it. ESU makes financial sense as a bridge for isolated machines during an active migration. As a strategy for a fleet, it does not.

The rule that catches people: back-billing

You cannot defer enrolment to save the first year. Under Volume Licensing, enrolling in year two requires buying year one retroactively. Under Azure Arc, provisioning an ESU licence after 12 January 2027 triggers an immediate charge covering every elapsed month back to 13 January 2027.

Arc does give real flexibility in the other direction: billing stops within five business days of deactivating a server, so a machine you retire in March stops costing money in March. But deleting and reprovisioning an Arc ESU resource restarts back-billing across the whole elapsed period, so it is not a gap you can open and close.

What ESU does not cover

Read this before treating ESU as equivalent to support.

Security updates are restricted to vulnerabilities rated Critical or Important by the Microsoft Security Response Center. Moderate and Low are not patched. Non-security updates stop entirely: general bugs, stability fixes, performance improvements, time-zone adjustments. If an unpatched kernel defect degrades database stability without being exploitable, no update is coming. Feature development and hardware enablement end permanently. And assisted support under a Premier or Unified agreement cannot be used for general troubleshooting on the platform; it is limited to ESU activation, update installation problems, and crashes directly caused by an ESU patch.

Upgrade paths, and the workloads that make them painful

Source To Server 2019 To Server 2022 To Server 2025 Recommended approach
Windows Server 2016 Standard Direct Direct Direct, non-clustered Clean install on refreshed compute, side-by-side migration
Windows Server 2016 Datacenter Direct Direct Direct, non-clustered Clean install on refreshed compute, side-by-side migration
Failover cluster, any edition Rolling upgrade Not supported directly Not supported directly Cluster OS rolling upgrade moves one version at a time; a clean rebuild is usually cleaner

Windows Server 2025 widened in-place upgrades to four versions for non-clustered systems, so a direct 2016 to 2025 jump is supported. Supported is not the same as advisable. In-place upgrades carry forward registry bloat, obsolete driver bindings, incompatible filter drivers and damaged component stores, which is why enterprise practice remains a clean install with side-by-side workload migration.

There is a hardware argument too. Servers running Windows Server 2016 typically came from the 2015 to 2018 procurement cycle. That generation often lacks certified driver support for 2022 and 2025 and frequently fails modern security baselines including TPM 2.0 and UEFI Secure Boot. Plan for the compute to move, not just the operating system.

Five workloads generate most of the project time:

Active Directory. A 2016 estate runs at domain and forest functional level 2016. Neither 2019 nor 2022 raised it, so introducing domain controllers on those versions leaves the level where it is; 2025 introduces a new level. Upgrading means building clean servers, promoting them, replicating, transferring FSMO roles and demoting the old ones. In-place upgrades of live domain controllers risk replication failure and are not recommended. Anything still using File Replication Service for SYSVOL must move to DFS-R before 2025 domain controllers can join.

Exchange. Exchange Server does not support in-place upgrades of the underlying operating system, and Exchange 2016 left extended support in October 2025. This is a side-by-side mailbox migration or a move to Exchange Online, not a server upgrade.

SQL Server. SQL Server 2016 left extended support on 14 July 2026, six months ahead of the operating system. Upgrading Windows underneath a live SQL installation risks the master database configuration and the VSS writers. Build clean database hosts and move with backup and restore or availability group cutover.

File and print. Unstructured file data moves cleanly with the Storage Migration Service built into 2019, 2022 and 2025, which carries permissions, shares and network identity across. Print servers are harder: 32-bit third-party print drivers common on 2016 are incompatible with the modern 64-bit spooler, and that remediation is its own project.

Remote Desktop Services. A 2016 licensing server cannot issue client access licences to session hosts running 2019, 2022 or 2025. The licensing infrastructure has to be upgraded before the session hosts, and version-appropriate CALs purchased.

And underneath all of it, .NET Framework 4.6.2 expires on the same day. Applications depending on it need testing against 4.8 or modernising before the host they run on can move.

The servers that cannot move

Some machines are pinned: certified medical or industrial appliances, hardcoded 32-bit dependencies, software whose vendor no longer exists. Pretending otherwise is not a plan. What is defensible is a documented set of compensating controls, and being honest about what they do and do not achieve.

Control What it mitigates What it does not cover
Network micro-segmentation Lateral movement to and from the pinned host; uninspected internal traffic Anything an attacker can do once already on the host
Strict egress filtering Command-and-control callbacks and data exfiltration from the host Inbound exploitation through an approved application port
Identity-based access instead of network VPN Network-level visibility; unauthorised endpoints can no longer see the host at all A compromised authorised account with legitimate access
Protocol isolation and jump hosts Direct RDP and SMB exposure from general client subnets Compromise of the jump host itself
Reverse proxy and virtual patching Exploitation of exposed legacy web interfaces; obsolete cipher suites Vulnerabilities not reachable over HTTP
Host hardening and application control Unauthorised binary and script execution; in-memory payloads Exploitation of a kernel flaw by an allowlisted process

Aligned with NIST SP 800-40 and SP 800-207, CISA Cross-Sector Cybersecurity Performance Goals, and CIS Critical Security Controls v8.

The third column is the honest part and it is worth stating plainly rather than in a footnote. Compensating controls address delivery and lateral movement. They do not repair the operating system. If an attacker gets an internal foothold through stolen credentials, a compromised jump host or an uninspected service account, an unpatched local privilege escalation flaw in the 2016 kernel is still there and still works. Isolation reduces blast radius. It does not secure the host.

We go through the isolation architecture in depth, including what it changes about the attack surface, in running Windows Server 2016 past end of support. The mechanics of what an attacker does once inside are covered in lateral movement attack techniques, and the shift from VLAN-based to identity-based segmentation in network segmentation in 2026.

Where an auditor and an insurer draw the line

Under NIS2, running an operating system that no longer receives vendor updates without an active ESU agreement is a visible failure of Article 21(2)(e) on vulnerability handling and 21(2)(g) on basic cyber hygiene, and keeping an unpatched server on a routable corporate subnet sits badly against 21(2)(j) on segmentation. Article 20 puts personal responsibility on management bodies for approving and supervising these measures. Administrative fines reach €10 million or 2 per cent of worldwide turnover for essential entities, and €7 million or 1.4 per cent for important entities.

Belgium transposed NIS2 through the Law of 26 April 2024 and designated the CCB as supervisory authority, with CyberFundamentals as the conformity benchmark. CyFun maintenance controls require that operating systems, hypervisors and enterprise software are actively maintained by the vendor or covered by a contract guaranteeing timely security updates. An unsupported operating system without active ESU coverage is an audit failure rather than a finding to negotiate. Verification at Basic or Important level from an accredited conformity assessment body was required by 18 April 2026, so most Belgian organisations will be showing an assessor a documented migration roadmap for these servers rather than starting the conversation.

What auditors accept in practice is narrower than what vendors imply. Compensating controls are accepted alongside a formal risk acceptance document, an active ESU contract and a funded migration plan with a target date. On their own they are not accepted as a permanent substitute for a supported operating system, and the unpatched privilege escalation exposure stays on the risk register either way.

On insurance, the useful question is not whether your policy excludes end-of-life software. It is what you attested to at renewal. Policies increasingly carry minimum security control warranties: if the application stated that production operating systems receive security updates within a defined window, and an incident traces back to an unpatched 2016 host, the carrier has grounds to void coverage for breach of warranty before the merits of the loss are reached. Typical exclusion wording also requires both an active written ESU agreement and compensating controls accepted by the insurer in writing beforehand. Pull the questionnaire out now, not in January.

The case for buying ESU and deferring

A system administrator with a frozen capital budget will point out that ESU exists precisely for this, that the servers keep running on 13 January 2027 exactly as they did the day before, and that a rushed migration breaks more than a deferred one. All three are true.

Two things temper it. The first is the arithmetic above: on Datacenter hosts, three years of ESU costs more than the hardware and licence you were deferring, so the deferral is only economical on Standard edition or on a small number of isolated machines. The second is that ESU does not stop the compliance clock. From 13 January 2027, internal vulnerability scanners flag every 2016 instance, and February’s Patch Tuesday will ship updates for 2019, 2022 and 2025 while 2016 receives nothing. ESU keeps the security fixes coming; it does not make the estate compliant or the audit conversation easier.

The version of this that does hold up is narrow and worth naming: ESU on Azure Arc, applied per node, for a specific pinned machine, alongside a funded plan with a date on it. Arc makes that possible in a way Volume Licensing historically did not, because you can license one isolated host rather than the whole agreement.

What to do in the next fortnight

Three things, and none of them requires budget approval.

First, inventory by role rather than by hostname. For every 2016 instance, record what it does, what depends on it, and whether Exchange, SQL Server, RDS licensing, .NET 4.6.2 or a 32-bit print driver is in the path. That list sorts itself into “migrate”, “rebuild” and “cannot move” faster than any tooling will.

Second, get a written answer from your reseller on which ESU pricing model applies to your agreement, and on whether Azure-hosted 2016 workloads remain covered without charge under the post-April 2026 framework. Those two answers can move the budget by a factor of five.

Third, for anything on the “cannot move” list, write the risk acceptance now and put the compensating controls next to it. Under CyFun that document is the difference between a documented exception and an audit failure, and it takes an afternoon in September against a much worse January.

Where isolation is the answer, we can help you scope it: Jimber’s platform puts identity-based access and network isolation in front of hosts that cannot be patched, so an unsupported server stops being reachable from the general network without rebuilding your segmentation from scratch. Book a demo or get in touch, and if the isolation route is where you are heading, end-of-life systems under NIS2 covers what that has to look like on paper.

Frequently asked questions

When does Windows Server 2016 reach end of support?

Windows Server 2016 reaches end of extended support on 12 January 2027. Mainstream support ended on 11 January 2022. After January 2027 Microsoft stops all security patches, bug fixes and assisted technical support unless you have purchased Extended Security Updates, which run for a maximum of three further years to 8 January 2030.

How much do Windows Server 2016 Extended Security Updates cost?

Under Microsoft’s standardised model ESU costs 100 per cent of the current full licence price annually. Through Azure Arc that works out at roughly €4.79 ($5.21) per core per month for Standard and €27.58 ($29.98) for Datacenter, with minimums of 8 virtual cores per VM or 16 physical cores per host.

Can I buy ESU later if my migration runs late?

Yes, but not more cheaply. ESU is cumulative back to 13 January 2027. Under Volume Licensing, enrolling in year two requires purchasing year one retroactively. Under Azure Arc, provisioning after the deadline triggers an immediate charge covering every elapsed month since billing began.

Can I upgrade directly from Windows Server 2016 to Windows Server 2025?

Yes for non-clustered servers. Windows Server 2025 supports in-place upgrades across up to four versions. Failover clusters are restricted to single-version rolling increments. Enterprise practice still favours a clean installation with side-by-side workload migration, because in-place upgrades carry forward driver and component-store debt.

What happens to my servers the day after end of support?

Nothing immediately. The operating system keeps running and workloads keep processing. What changes is that February 2027’s Patch Tuesday delivers updates for Server 2019, 2022 and 2025 and nothing for 2016, internal vulnerability scanners flag every instance, and compliance reporting shows non-conformity from that date.

Does running Windows Server 2016 after January 2027 breach NIS2?

Running an unpatched operating system without active ESU coverage conflicts with Article 21(2)(e) on vulnerability handling and 21(2)(g) on cyber hygiene, and Article 20 places responsibility on the management body. In Belgium, CyFun maintenance controls treat an unsupported operating system without ESU as an audit failure.

Will my cyber insurance pay a claim involving a Windows Server 2016 host?

It depends on what you declared at renewal. Policies increasingly include end-of-life exclusions and minimum security control warranties. If you attested that production systems are patched within a defined window and an incident traces to an unpatched 2016 host, the carrier can decline for breach of warranty regardless of the loss itself.

Can I license ESU for one server rather than the whole estate?

Through Azure Arc, yes. Deploy the Connected Machine agent to an individual host or virtual machine and activate an ESU licence for that node alone, subject to the 8 virtual core or 16 physical core minimum. Classic Volume Licensing historically required coverage across the server agreement.

Can I keep running Active Directory domain controllers on Windows Server 2016?

Not safely past January 2027. Migrating requires building clean domain controllers, replicating, transferring FSMO roles and demoting the old ones, because in-place upgrades of live domain controllers risk replication failure. Environments still using File Replication Service for SYSVOL must move to DFS-R first.

Will auditors accept network segmentation instead of upgrading?

Only as part of a package. Compensating controls are accepted alongside a formal risk acceptance document, an active ESU contract and a funded migration plan with a target date. On their own they are not accepted as a permanent substitute, and unpatched privilege escalation exposure remains an open item on the risk register.