Windows Server End-of-Life Dates: the 2012–2025 Timeline and What to Do per Version

All Windows Server end-of-life dates in one timeline: 2012, 2016, 2019, 2022 and 2025, plus ESU costs and your realistic options before January 2027.
Server administrator standing in a data centre aisle reviewing a planning document beside rows of rack servers

On 12 January 2027, Windows Server 2016 runs out of extended support. That sounds comfortably far away until you put it next to a budget cycle: it is one procurement round from now. And it is not even the first deadline on the board. Extended Security Updates for Windows Server 2012 and 2012 R2 terminate permanently on 13 October 2026, the same day Windows Server 2022 exits mainstream support.

Telemetry suggests roughly one in five enterprise servers still runs Windows Server 2016 as its deadline approaches, and a Lansweeper audit of 1.3 million Windows Server installations found 20.94% still on Server 2012/R2 long past its end of life. Legacy servers are not an edge case; they are the norm. This page gives you every date in one table, what each milestone changes, what the Extended Security Update (ESU) programme really costs, and the realistic options per version. We maintain it as a living reference, the same way we track appliance dates in our FortiGate hardware end-of-life timeline.

Mainstream, extended and ESU: what each phase actually means

Windows Server LTSC releases follow Microsoft’s Fixed Lifecycle Policy: ten years of support, split in two.

Mainstream support covers the first five years: security updates, non-security fixes and feature work. Extended support covers the next five: security updates only, no new features, no free assisted support. When extended support ends, the operating system is done; newly discovered vulnerabilities stay unpatched forever on that machine.

Extended Security Updates (ESU) are the paid epilogue: up to three more years of patches, but only those Microsoft rates Critical or Important. No bug fixes, no feature work, no technical support, and a hard stop after year three. ESU is a bridge, not a destination.

One precision note: Microsoft indexes lifecycle dates in Pacific Time, so some non-US documentation shows adjacent dates (12 versus 13 January 2027 for Server 2016). The global servicing cut-off is anchored to 12 January 2027.

The Windows Server end-of-life timeline

Last verified: August 2026.

Version Release Mainstream support end Extended support end ESU window
Windows Server 2012 30 Oct 2012 9 Oct 2018 10 Oct 2023 Ends 13 Oct 2026 (year 3, final)
Windows Server 2012 R2 25 Nov 2013 9 Oct 2018 10 Oct 2023 Ends 13 Oct 2026 (year 3, final)
Windows Server 2016 15 Oct 2016 11 Jan 2022 12 Jan 2027 13 Jan 2027 – 12 Jan 2030 (Azure Arc enrolment opens 3 Aug 2026)
Windows Server 2019 13 Nov 2018 9 Jan 2024 9 Jan 2029 Expected 2029–2032 (not yet formally announced)
Windows Server 2022 18 Aug 2021 13 Oct 2026 14 Oct 2031 Not yet announced
Windows Server 2025 1 Nov 2024 13 Nov 2029 14 Nov 2034 Not yet announced

Source: Microsoft’s official Microsoft Learn lifecycle pages per version. Annual Channel releases follow the Modern Lifecycle Policy with continuous servicing and are not listed. Worth flagging alongside: SQL Server 2016 already reached end of extended support on 14 July 2026, six months ahead of the operating system it often runs on.

What ESU really costs

Server ESU is priced per core, as an escalating percentage of the current licence list price: roughly 75% in year one, 100% in year two, 125% in year three. Three years of ESU therefore costs about 300% of a full licence, for security-only patching. Two rules sharpen the picture further. Coverage is cumulative: enrol in year two and you retroactively pay year one as well. And minimums apply: 8 cores per virtual machine, 16 per physical host.

Deployment profile Year 1 (75%) Year 2 (100%) Year 3 (125%) 3-year total
Standard edition, 16-core physical host ≈€1,290 ($1,400) ≈€1,720 ($1,870) ≈€2,155 ($2,340) ≈€5,160 ($5,610)
Datacenter edition, 16-core physical host ≈€4,815 ($5,232) ≈€6,420 ($6,976) ≈€8,020 ($8,720) ≈€19,250 ($20,928)
Standard VM, 8 vCores via Azure Arc ≈€320 ($350) ≈€430 ($468) ≈€540 ($585) ≈€1,290 ($1,403)
Workload hosted in Azure / Azure Local €0 €0 €0 €0 (ESU included)

Converted from USD list prices at ≈€0.92 per US dollar (August 2026); local EUR pricing may differ.

Two structural points hide in that table. Azure-hosted workloads get ESU free, which is Microsoft’s not-so-subtle migration incentive. And Azure Arc’s pay-as-you-go route bills monthly and lets Datacenter VMs be covered at the Standard rate under the vCore model, which changes the maths for virtualised estates. Note the contrast with the client side: Windows 10 ESU is flat per device (≈€56/$61 in year one, doubling yearly), a much simpler calculation we covered in our guide to Windows 10 ESU and endpoint isolation.

What actually happens to unpatched servers

The threat data on legacy Windows Server is unambiguous. The 2025 Verizon DBIR puts ransomware in 44% of confirmed breaches, rising to 88% among small and mid-sized organisations, and records a 34% year-on-year surge in vulnerability exploitation: exploited flaws now account for 20% of initial breach vectors, ahead of phishing. Microsoft’s own Digital Defense Report attributes 18% of observed breaches to unpatched web-facing assets and another 12% to exposed remote management services.

History shows exactly how this plays out after a support cut-off. Zerologon (CVE-2020-1472) let an unauthenticated attacker reset a domain controller’s machine password and seize Domain Admin. PrintNightmare turned the Print Spooler into a SYSTEM-level code execution path. BlueKeep (CVE-2019-0708) made unpatched RDP wormable. Supported systems got emergency patches; anything past its date stayed vulnerable permanently. The next flaw of that class to appear after January 2027 will never be fixed on Windows Server 2016.

The blast radius depends on the role. A legacy domain controller or file server is a Tier-0 target: older kernels lack default Credential Guard, so admin-level access yields NTLM hashes and Kerberos tickets straight from LSASS memory, and backward-compatible protocols (SMBv1, NTLMv1) enable relay and pass-the-hash techniques. That is the raw material of the lateral movement playbook, and it is why unpatched servers feature so heavily in the incident patterns our ransomware prevention playbook is built around.

For European organisations, the compliance layer stacks on top: NIS2 Article 21 requires active vulnerability handling, Belgium’s CyFun framework treats unsupported systems without a documented exception as a critical audit finding, and cyber insurers increasingly write EOL exclusions into policies. An unpatched server on a flat network is simultaneously a technical, regulatory and insurance problem.

Your realistic options, per version

Migrate side-by-side. Build fresh Server 2022/2025 instances and move roles across cleanly. The right answer for domain controllers, file clusters and anything Tier-0; predictable, testable, and free of accumulated configuration debt.

Upgrade in place. Windows Server 2025 accepts direct in-place upgrades across up to four generations, so 2012 R2, 2016, 2019 and 2022 can all jump straight to 2025. Low upfront cost, but you carry registry drift and driver risk with you; discouraged for domain controllers. Mind the licensing tail: CALs are backward-compatible but not forward-compatible, so new 2025 servers need new 2025 CALs.

Rehost to Azure. Lift the VM into Azure and ESU comes free. This buys patch coverage, not modernisation: the same OS with the same dependencies now runs in someone else’s datacentre, with cloud hosting costs replacing licence fees.

Buy ESU as a bridge. Legitimate when a migration is funded and dated, and the escalating cost structure (see table) prices in its own urgency. Enrolment via Azure Arc for Server 2016 opens on 3 August 2026.

Keep and isolate. For the servers that genuinely cannot move: vendor-certified ERP and MES stacks, systems welded to production hardware, applications whose vendor no longer exists. The same constraint we described for devices you cannot patch applies to servers you cannot migrate. The defensible route is strict network isolation with identity-gated access and documented compensating controls; a dedicated Jimber guide covers the isolation route in depth.

The four objections, taken seriously

“It’s air-gapped.” Genuine air gaps are rare. Backup agents, monitoring, jump boxes, shared storage and file shares all create bridges, and attackers cross them routinely after landing on an ordinary endpoint. If a human can reach it to administer it, so can malware.

“The vendor won’t certify anything newer.” A real constraint, and regulators know it. But vendor certification freezes do not suspend your NIS2 duty of care; they shift it from patching to containment. An uncertifiable server can stay, provided it is isolated and the risk is documented.

“ESU buys us three years.” It buys three years of Critical and Important patches at escalating cost, with no bug fixes and a hard end in January 2030. If there is no funded migration or containment plan behind it, ESU only moves the cliff edge.

“Nobody attacks a company our size.” The scanners disagree. Exploitation is automated and indiscriminate, and the DBIR’s 88% ransomware share among SMB breaches reflects precisely the combination of legacy systems and thinner defences.

Put the dates in your budget before they put themselves there

Three deadlines matter now: 13 October 2026 ends the last Server 2012/R2 patches, 12 January 2027 ends Server 2016, and 9 January 2029 is closer than it looks for Server 2019. For every legacy server, pick a lane deliberately: migrate, rehost, bridge with ESU, or isolate what cannot move. The worst plan is the accidental one where the date simply arrives. If part of your estate is going to outlive its support window, Jimber’s EU-sovereign SASE platform isolates those systems behind ZTNA network isolation so nothing unpatched sits exposed on your network, at a predictable flat rate and without new hardware. Book a demo to walk through your server inventory against these dates, or read on about how network isolation works.

Frequently asked questions

When exactly does Windows Server 2016 reach end of life?

Windows Server 2016 reaches end of extended support on 12 January 2027 for Standard, Datacenter and Essentials editions. After that date Microsoft stops all regular security updates, non-security fixes and technical support. A paid three-year ESU programme then runs until 12 January 2030.

What is the difference between mainstream and extended support?

Mainstream support covers the first five years and includes security updates, bug fixes and feature changes. Extended support covers the following five years with security updates only. After extended support ends, no further updates are produced unless the organisation buys Extended Security Updates.

When does Windows Server 2019 reach end of life?

Windows Server 2019 left mainstream support on 9 January 2024 and reaches end of extended support on 9 January 2029. It currently receives security updates only. Microsoft has not yet formally announced its ESU programme, which would be expected to run from 2029 to 2032.

When do Extended Security Updates end for Windows Server 2012 and 2012 R2?

ESU coverage for Windows Server 2012 and 2012 R2 terminates permanently on 13 October 2026, the end of ESU year three. After that date no security updates are available through any commercial channel, and remaining instances must be migrated, rehosted or strictly isolated.

How much do Windows Server 2016 Extended Security Updates cost?

ESU is billed per core at roughly 75% of the current licence list price in year one, 100% in year two and 125% in year three, with minimums of 8 vCores per VM or 16 cores per host. A 16-core Standard host totals about ≈€5,160 ($5,610) over three years; Azure-hosted workloads get ESU free.

Can I upgrade Windows Server 2016 directly to Windows Server 2025?

Yes. Windows Server 2025 supports in-place upgrades across up to four consecutive versions, so 2012 R2, 2016, 2019 and 2022 can upgrade directly. For domain controllers and complex application servers, a side-by-side migration to a fresh install remains the safer route.

Are Windows Server 2025 CALs backward compatible?

Yes. A Windows Server 2025 user or device CAL also grants access to servers running 2022, 2019, 2016 and earlier. The reverse does not hold: older CALs cannot be used against newer server versions, so deploying 2025 servers requires purchasing 2025 CALs.

Does running an unsupported Windows Server violate NIS2?

Not automatically, but NIS2 Article 21 requires appropriate risk management including vulnerability handling. An unsupported server on an open network without compensating controls breaches that duty of care. With documented risk assessment, strict isolation and monitoring, continued operation can remain defensible.

Find out how we can protect your business

In our demo call we’ll show you how our technology works and how it can help you secure your data from cyber threats.

Cybersecurity
Are you an integrator or distributor?

Need an affordable cybersecurity solution for your customers?

We’d love to help you get your customers on board.

checkmark

White glove onboarding

checkmark

Team trainings

checkmark

Dedicated customer service rep

checkmark

Invoices for each client

checkmark

Security and Privacy guaranteed