Windows Server 2016 End of Support: Migration Plan Before 2027
In short: Windows Server 2016 end of support is 12 January 2027, after which Microsoft releases no new security updates. A migration plan rests on four decisions: an inventory, a target version (usually 2022 or 2025), a method (in-place upgrade or new hardware) and, for late servers, paid ESU through Azure Arc plus network isolation.
When is Windows Server 2016 end of support, and what does it mean?
Extended support for Windows Server 2016 ends on 12 January 2027. Microsoft Learn shows the end as 13 January 2027, 6:59:59 AM Pacific Time, and Microsoft's 2027 end-of-support list as 12 January 2027 (accessed 7 October 2026).
According to Microsoft, end of support means no new security updates, non-security updates, free or paid assisted support options, or online technical content updates. The server keeps running, but later vulnerabilities stay unfixed. Hyper-V Server 2016, IIS 10 on Windows Server 2016, Windows Defender for Windows Server 2016 and WSUS for Windows Server 2016 share the same date.
| Product and phase | End date | What happens next? |
|---|---|---|
| Windows Server 2012 / 2012 R2, ESU year 3 | 13 October 2026 | The final ESU security update is released. |
| Windows Server 2022, mainstream support | 13 October 2026 | Extended support begins: security updates continue at no additional cost, non-security fixes stop. |
| Windows Server 2016, extended support | 12 January 2027 | Security updates only through paid ESU. |
| Windows Server 2016, ESU (Azure Arc) | Up to 3 years, through 2030 | Updates stop completely when ESU ends. |
What migration options exist for Windows Server 2016?
There are five realistic options: in-place upgrade, clean install on a new server with role migration, moving the workload to Azure, paid ESU through Azure Arc, and retirement. NIST SP 800-40 Rev. 4 notes that end-of-life software will never be patched and recommends covering such "unpatchable" assets with isolation or similar measures.
| Option | When it fits | Prerequisites and caveats | Durability |
|---|---|---|---|
| In-place upgrade | Hardware supports the target version, roles are eligible | Tested backup, maintenance window, new licence; not for clusters or domain controllers | Permanent |
| Clean install on new hardware | Hardware is old or out of warranty | Windows Server Migration Tools or Storage Migration Service; short parallel run | Permanent, hardware refreshed too |
| Move to Azure | Workload suits the cloud | Microsoft states ESUs are free for VMs in Azure | Version still needs upgrading |
| ESU (Azure Arc) | Application vendor does not support newer versions, or the schedule slips | Software Assurance or equivalent subscription, Arc agent, Azure connectivity | Temporary bridge |
| Retirement | The workload has moved or is no longer used | Dependency check, data retention and disposal decision | Removes the risk entirely |
Running an unsupported server without safeguards is an unrecorded risk acceptance; if unavoidable, document it with an end date.
How do you build the migration inventory and rank servers?
The inventory puts each Windows Server 2016 instance's role, applications, hardware and network exposure in one table; the migration order follows from it. NIST SP 800-40 Rev. 4 also recommends tracking connectivity, existing controls and business importance.
| What to collect | Why it matters |
|---|---|
| Version, edition, installation option (Server Core / Desktop Experience), language | An in-place upgrade cannot change the installation option or language |
| Physical or virtual | ESU licences are defined by physical or virtual cores |
| Roles, applications, vendor support | Some roles should not be upgraded in place; unsupported applications may need ESU |
| Other Microsoft products on the server | They have their own dates: SQL Server 2016 reached end of support on 14 July 2026; SQL Server 2017 ends on 12 October 2027 |
| Hardware model, warranty, firmware | CPU and driver requirements of the target version |
| Internet-facing services, remote desktop | Highly exposed servers move first |
| Last restore test | Microsoft lists a tested full backup as an upgrade prerequisite |
For ranking, use Priority = Exposure × Business impact, each scored 1–3. Internet-facing or remote desktop servers score 3 for exposure; identity infrastructure and personal-data systems score 3 for impact. On equal scores, finish the easier migration first so the ESU list becomes clear early.
Which version can you upgrade Windows Server 2016 to, and how?
According to Microsoft Learn, Windows Server 2016 can be upgraded in place to Windows Server 2019, 2022 or 2025 using installation media. The feature update in Windows Update only covers 2019 and 2022 to 2025, and clusters (Cluster OS Rolling Upgrade) move one version at a time.
| Target version | End of extended support | Assessment |
|---|---|---|
| Windows Server 2019 | 9 January 2029 | Short runway; only if an application supports nothing newer |
| Windows Server 2022 | 14 October 2031 | Mainstream support ends on 13 October 2026 |
| Windows Server 2025 | 14 November 2034 | Longest runway; mainstream support until 13 November 2029 |
Restrictions matter: language and installation option cannot change, Storage Server cannot be upgraded, NIC Teaming must be disabled first, and each upgrade needs a licence. DHCP, DNS, IIS and WSUS can be upgraded in place; AD FS and Print and Fax Services cannot (printers move with Printbrm.exe). For domain controllers, Microsoft recommends promoting a new server and demoting the old one.
Microsoft's in-place upgrade flow for a non-clustered server:
- Confirm that roles and applications are supported on the target version.
- Take a full backup of the OS, applications, data and VMs, and test the restore.
- Save the output of
Get-ComputerInfo,systeminfoandipconfig /alloff the server. - Shut down or migrate VMs and disable NIC Teaming.
- In the maintenance window, run
setup.exeand choose "Keep files, settings, and apps". - Verify the version with
Get-ComputerInfo -Property WindowsProductNameand test applications; if something fails, analyse theC:\Windows\Pantherlogs with SetupDiag.
Is your current server hardware good enough for the new version?
It usually depends on CPU, memory and firmware. Microsoft Learn lists, for Windows Server 2025, a 1.4 GHz 64-bit processor with SSE4.2, POPCNT, Second Level Address Translation (SLAT) and NX/DEP support, which you can check with Sysinternals Coreinfo. Minimum memory is 2 GB, physical hosts are expected to use ECC memory or similar technology, and 32 GB is the absolute minimum for the system partition. TPM 2.0 and Secure Boot are needed for features such as BitLocker and Secured-core server.
For a refresh decision, ask: is vendor support active, can firmware be updated, does the CPU meet 2025 requirements, is capacity sufficient? We cover vendor versus third-party support after warranty and BIOS, iDRAC and iLO update steps in separate articles. For new hardware, compare Dell PowerEdge and HPE ProLiant models with your workload and see our server CPU guide.
How do you get ESU for Windows Server 2016, and what does it cover?
Microsoft announced Extended Security Updates (ESU) for Windows Server 2016 on 25 February 2026 and delivers them through Azure Arc. ESU provides security updates rated "Critical" and "Important" for up to three years, through 2030; it includes no new features or non-security fixes.
- Scope and timing: Standard and Datacenter; configuration in the Azure portal has been open since 3 August 2026, and billing starts on 13 January 2027.
- Eligibility: on-premises workloads need Software Assurance or an equivalent server subscription; SPLA is not available.
- Missing benefits: no Visual Studio dev/test benefit and no no-cost disaster recovery benefit; DR cores must be licensed.
- Licence unit: at least 16 physical cores per machine, or at least 8 virtual cores per VM.
- Technical prerequisite: Azure Connected Machine agent 1.62 or later and connectivity to Azure via public endpoint, proxy or Private Link.
Microsoft's ESU FAQ calls the programme a "last resort": it does not extend the lifecycle or include technical support beyond security updates. When a server is upgraded to 2019 or later or moved to Azure, reduce licence cores yourself; Microsoft notes this is not automatic. Ask your Microsoft account team or licensing provider for pricing.
How do you protect the old server until migration is complete?
Short-term protection has two goals: make attacks less likely to reach the server, and limit the impact of a compromise. The UK National Cyber Security Centre (NCSC) stresses that such measures reduce rather than remove risk; the only full fix is to stop using the product. The risk is concrete: CISA's Known Exploited Vulnerabilities (KEV) catalogue (version 2026.10.04) lists 172 Microsoft entries with the product "Windows", 42 added since 1 January 2025 (our count; not specific to 2016).
- Segmentation: place the server in its own network zone, restrict traffic to the required source, destination and port with a discrete firewall such as FortiGate, and run the rules through a policy review.
- Reduce services: disable non-essential roles; NCSC advises that obsolete servers should not provide remote desktop facilities.
- Cut untrusted inputs: technically block web browsing, email and removable media, and narrow the server's access to other systems.
- Monitoring: forward events to central log management and define alert rules; NCSC notes that recording events without acting on them is not enough.
- Backup: keep a tested backup in a separate location; ransomware safeguards apply here too.
Host-based intrusion prevention (IPS) adds a layer on the server. According to Trend Micro's documentation, the Intrusion Prevention module of the Server & Workload Protection agent can intercept traffic trying to exploit known vulnerabilities for which no patch is available, and the agent compatibility table lists Windows Server 2016 as supported by the 20.0.3 LTS agent (accessed 7 October 2026). Details are on our Trend Micro Deep Security page. As NCSC warns, such products may be less effective on an unsupported OS; IPS does not replace upgrading.
If you would like to align segmentation, monitoring and server protection with your inventory during the migration, tell us what you need. Get a Quote
In what order should you act before 12 January 2027?
Plan backwards from the inventory and size each phase to your server count and maintenance windows.
- Complete the inventory and assign a business owner to every server.
- Apply the decision matrix: record an upgrade, migrate, ESU or retire decision for each server.
- Settle ESU early: prepare Arc onboarding and licence cores for servers that will not make it before 12 January 2027.
- Run a pilot: test upgrade and rollback on a test server.
- Procure hardware and licences, then migrate in waves by priority.
- Decommission and document: retire old servers with data disposal, and bring new ones under a server maintenance agreement with a regular update schedule.
FAQ
Will Windows Server 2016 keep working after 12 January 2027?
Yes, the server keeps running; end of support is not a shutdown date. However, Microsoft provides no new security updates, non-security fixes or support afterwards. Without ESU, every vulnerability discovered later stays open, so the risk grows over time.
Can Windows Server 2016 be upgraded directly to Windows Server 2025?
Yes. According to Microsoft Learn, a non-clustered Windows Server 2016 server can be upgraded in place directly to 2025 from installation media; the Windows Update route only applies to 2019 and 2022. Clusters move one version at a time, and domain controllers should be replaced with new ones.
Can you buy ESU for Windows Server 2016?
Yes. Microsoft offers 2016 ESU through Azure Arc: Standard and Datacenter are covered, billing starts on 13 January 2027 and coverage lasts up to three years, through 2030. On-premises servers need Software Assurance or an equivalent subscription. ESU is a temporary bridge, not a replacement for an upgrade plan.
Is Windows Server 2019 a sensible target version?
Usually not. Extended support for Windows Server 2019 ends on 9 January 2029, so you would repeat the project in about two years. Windows Server 2022 receives security updates until 14 October 2031 and 2025 until 14 November 2034. Use 2019 only as a stopover when a vendor supports nothing newer.
Will my current server run Windows Server 2025?
Check the CPU first: Windows Server 2025 requires SSE4.2, POPCNT and SLAT support, and Microsoft points to Sysinternals Coreinfo for the check. Then confirm at least 2 GB of memory, a 32 GB system partition and ECC memory on physical hosts, plus the vendor's driver and firmware support for that model.
How do I protect the old server until migration is finished?
Move the server into its own network zone, restrict traffic to required ports with a firewall, disable unneeded services, block internet and email access, and monitor events centrally; host-based intrusion prevention adds a layer. To work out this plan for your environment, contact us through the form.
Conclusion
- Extended support for Windows Server 2016 ends on 12 January 2027; after that, security updates come only through paid ESU.
- Choose the target version by support runway: 14 October 2031 for 2022, 14 November 2034 for 2025.
- A direct upgrade to 2025 is possible; domain controllers, clusters and some roles need another path.
- ESU and isolation are temporary bridges for servers that miss the deadline.
Sora Yazılım, a Türkiye-based technology company, provides selection, procurement, installation and support for Dell and HPE servers and for Trend Micro products; the scope of a server maintenance agreement is defined in the contract.
Get a Quote · WhatsApp: WhatsApp Support · Phone: +90 544 785 21 87 · Email: talep@sorayazilim.com
Sources
- Windows Server 2016, 2019, 2022, 2025 and 2012 R2 lifecycle pages — Microsoft Learn. 2016, 2019, 2022, 2025, 2012 R2 (accessed 7 October 2026)
- Ending Support in 2027 / 2026; Fixed Lifecycle Policy — Microsoft Learn. 2027, 2026, policy (accessed 7 October 2026)
- Planning ahead for Windows Server 2016 end of support — Microsoft Windows Server Blog, 25 February 2026. microsoft.com (accessed 7 October 2026)
- ESU enabled by Azure Arc and the ESU lifecycle FAQ — Microsoft Learn. prepare, licensing, FAQ (accessed 7 October 2026)
- Windows Server upgrade, role migration, domain controller and hardware guides — Microsoft Learn. plan, in-place, roles, DC, hardware (accessed 7 October 2026)
- Obsolete products, version 2.1 — NCSC. ncsc.gov.uk (accessed 7 October 2026)
- SP 800-40 Rev. 4, Guide to Enterprise Patch Management Planning — NIST, April 2022. csrc.nist.gov (accessed 7 October 2026)
- About Intrusion Prevention; Agent platform compatibility — Trend Micro Online Help Center. IPS, compatibility (accessed 7 October 2026)
- Known Exploited Vulnerabilities Catalog data, version 2026.10.04 — CISA. GitHub (accessed 7 October 2026)
How this article was prepared
Prepared by: Sora Yazılım Team. This article was prepared with AI assistance; technical details were checked against the vendor and official sources linked in the text as of 7 October 2026.
Related articles
- What is a server maintenance agreement? — Scope items and a contract checklist.
- Post-warranty server support — Vendor, third-party and hybrid models compared.
- Server firmware, BIOS and iDRAC/iLO updates — Version tracking, order and rollback.
