CONTACT

Windows Server 2016 End of Life: What You Need to Do

windows server 2016 end of life

Somewhere in most UK server rooms there’s a box still running Windows Server 2016. It works, nobody has touched it in years, and it quietly holds a file share, a line-of-business app or a print queue. That box now has a deadline.

Windows Server 2016 end of life falls on 12 January 2027. After that date Microsoft stops shipping security updates, and every unpatched flaw found afterwards stays open. You have four realistic moves: upgrade in place, rebuild on a current version, move the workload to Azure, or buy Extended Security Updates as a short bridge.

Windows Server 2016 end of life means the end of security updates on 12 January 2027. Microsoft will sell Extended Security Updates for up to three years, through 2030, but they cover critical and important fixes only. They buy time, not a future.

When Does Windows Server 2016 Support End?

On 12 January 2027. Microsoft’s Extended Security Updates guidance puts the date plainly, and the Windows Server release notes list the same day as the end of updates for build 14393. Mainstream support finished back in January 2022, so Windows Server 2016 end of life is the close of the extended phase rather than a surprise.

That is roughly 15 months from now. It sounds like plenty. It is not, once you allow for dependency mapping, licence purchasing, a test rebuild, a change window that finance and the business will accept, and the applications nobody documented.

The windows server 2016 EOL date matters for one reason above the others: after it, new vulnerabilities in that operating system never get fixed on your hardware unless you pay for them.

What Actually Changes When Support Ends?

The server keeps running. Nothing switches off, no licence expires, and the file share is still there on 13 January. What stops is the supply of security updates, and Windows Server 2016 end of life turns a working server into a liability your auditor, your insurer and your certification body each treat differently.

  • No more patches. Vulnerabilities found after the date stay open unless you buy Extended Security Updates.
  • Compliance exposure. Cyber Essentials requires software in scope to be licensed and supported.
  • Vendor support drift. Application vendors drop support for their software on unsupported operating systems, usually quietly.
  • Insurance questions. Cyber insurance forms ask whether you run unsupported systems, and the answer has to be true.

Transputec sees the same four options play out across UK estates, and the order in which you take them decides the cost.

Still Running Server 2016?

Transputec's cloud migration team runs a three-week discovery sprint: dependency mapping, an application catalogue, 6Rs scoring per workload and a costed plan you keep. Talk to our team about the work behind your server migration.

Get a Strategic Consultation

What Are Your Options for Windows Server 2016 End of Life?

There are four realistic answers to Windows Server 2016 end of life, and most estates use more than one of them. Pick per workload rather than per company, because the file server and the 2009 line-of-business application deserve different treatment. The table sets out what each option actually buys you.

OptionWhat it involvesWatch out forSuits
In-place upgradeUpgrade the existing server to 2019, 2022 or 2025Carries forward old configuration and any old problemsSimple roles on hardware with life left in it
Rebuild on a current versionFresh server, clean build, workload moved acrossNeeds new licences, and someone has to document the appAnything business critical
Move to AzureRehost the workload as an Azure virtual machineRunning costs replace capital costs, so model them firstServers due a hardware refresh anyway
Extended Security UpdatesPay for critical and important fixes, up to three yearsA bridge with an end date of 2030, not a fixWorkloads that genuinely cannot move by January 2027

A fifth option is worth naming: retire the workload. Some 2016 servers exist because nobody ever switched them off.

Can You Upgrade Windows Server 2016 In Place?

Yes. Microsoft’s upgrade guidance supports an in-place upgrade from Windows Server 2016 to 2019, 2022 or 2025, and from Windows Server 2025 onwards non-clustered systems can move up to four versions at a time. So a single hop from 2016 to 2025 is supported, which was not true of older jumps.

If you are weighing Windows Server 2016 to 2022 migration options against a jump straight to 2025, the same three caveats apply before you book the change window:

  • An upgrade inherits everything. The old roles, the old registry tweaks, the certificate somebody installed in 2018. A rebuild costs more time and gives you a cleaner estate.
  • Hardware and drivers. An in-place upgrade keeps you on the same box, so check the vendor supports the newer version on that generation of hardware.
  • Clusters and edition changes. Rolling upgrades and edition conversions follow their own rules, and both need planning rather than a weekend.

Licensing is the other half. Windows Server is licensed per core with client access licences on top, and Microsoft no longer publishes a fixed list price for Standard or Datacenter, so budget from a reseller quote rather than a number you read somewhere.

How Much Do Extended Security Updates Cost?

The cost of Extended Security Updates for Windows Server depends on where the server runs, and Microsoft prices them per core through a partner rather than publishing a list price. What is fixed is the shape: critical and important fixes only, for up to three years after the end of support date, which runs to 2030.

  • Free on Azure. Servers running as Azure virtual machines get Extended Security Updates at no extra cost beyond the virtual machine itself.
  • Pay as you go elsewhere. Through Azure Arc it is a monthly subscription, configurable in the Azure portal from 3 August 2026, with billing starting 13 January 2027.
  • Volume licensing needs Software Assurance. Buying the updates through an Enterprise Agreement or similar programme requires it; the Arc route does not.
  • Standard and Datacenter only. Those are the editions Microsoft covers for 2016.

Treat the cost as rent on a decision you have postponed. Three years of updates on a fleet of servers usually buys a migration outright, and at the end of it you still have Windows Server 2016.

Does an Unsupported Server Fail Cyber Essentials?

It fails unless you deal with it. Requirements for IT Infrastructure v3.3 says all software in scope must be licensed and supported, and must be removed from devices when it becomes unsupported, or removed from scope using a defined sub-set that prevents all traffic to or from the internet.

So Windows Server 2016 end of life makes a box still serving internet-connected users in February 2027 a problem at assessment. Segregating it behind a boundary that blocks all internet traffic is the other permitted route, and it is a real design job rather than a firewall rule added on the morning of the audit.

Whether Extended Security Updates keep a server inside the definition of supported is a conversation to have with your certification body before you rely on it. Our guide to the 5 Cyber Essentials controls covers what else the assessor checks.

What Should a Server Migration Plan Look Like?

Start with an inventory, finish with a decommission date. Windows Server 2016 end of life is a programme, not a task. Most server migration projects fail on the middle bit, the dependencies nobody wrote down: the scheduled task feeding the finance report, the licence tied to a MAC address. Find those before you book a cutover.

  1. Inventory every 2016 instance, physical and virtual, including the ones in the DR site.
  2. Map what each one does and who screams if it stops.
  3. Score each workload: upgrade, rebuild, rehost in Azure, retire, or bridge with Extended Security Updates.
  4. Check application vendor support for the target version before you pick it.
  5. Price the licences and the hardware, then compare that with running the same workload in Azure.
  6. Pilot one low-risk server end to end, including the rollback.
  7. Book cutovers in waves, with a parallel run where the business can tolerate one.
  8. Decommission properly, so the old box does not sit powered on “just in case” for another two years.

Transputec runs this as a cloud migration programme when the answer is Azure, and as legacy application migration when an old application is the thing holding everyone hostage.

Your Windows Server 2016 End of Life Checklist

Work through this before the January 2027 deadline turns into a February 2027 incident.

  1. List every Windows Server 2016 instance you own, including virtual machines and DR copies.
  2. Record the roles, applications and users each one supports.
  3. Confirm which applications are supported on Windows Server 2019, 2022 or 2025.
  4. Decide per workload: upgrade, rebuild, rehost, retire or bridge.
  5. Check hardware support for the target version before committing to an in-place upgrade.
  6. Budget licences and client access licences from a current quote.
  7. Compare that budget against running the workload in Azure.
  8. Book a pilot, and test the rollback as well as the upgrade.
  9. Tell your insurer and your assessor what the plan is if anything will still be on 2016 in 2027.
  10. Set a decommission date for every server you replace, and hold it.

Conclusion

The date is fixed and public: 12 January 2027. Everything else is a choice about how much disruption you want, and when you want it. The estates that handle this well start with an inventory now, decide per workload, and keep Extended Security Updates in reserve for the one or two servers that genuinely cannot move.

The ones that handle it badly discover in February 2027 that an application vendor has quietly dropped support, that the insurer asked a question they answered optimistically, and that an assessor wants to know why an unsupported server is still talking to the internet.

Transputec has run 200 plus UK migrations using a 6Rs assessment per workload, and our managed IT services keep the estate patched afterwards. If Windows Server 2016 end of life is still an open item on your risk register, talk to us about the work behind your migration.

FAQs

12 January 2027. Microsoft’s Extended Security Updates guidance names that date for Windows Server 2016 end of life, and the Windows Server release information lists the same day as the end of updates for Windows Server 2016. Mainstream support ended on 12 January 2022, so the product has been receiving security fixes only since then.

Yes. Microsoft supports an in-place upgrade from Windows Server 2016 to 2019, 2022 or 2025, and from 2025 non-clustered systems can jump up to four versions at once. Check application vendor support and hardware compatibility for the target version first, because an upgrade carries the old configuration with it.

Yes, for servers running as Azure virtual machines. Microsoft provides Extended Security Updates at no extra cost beyond the virtual machine itself. Elsewhere they are a paid monthly subscription through Azure Arc, configurable in the Azure portal from 3 August 2026, with billing from 13 January 2027.

Up to three years from end of support, so through 2030 for Windows Server 2016. They cover critical and important security fixes only, on Standard and Datacenter editions. They do not include new features, non-security hotfixes or design change requests, and they are a bridge rather than a long-term position.

Buy time deliberately rather than by accident. Extended Security Updates keep critical fixes coming while you finish the work, and segregating the server so it cannot reach the internet is the other route Cyber Essentials recognises. Both need a documented plan and a date, which is what an assessor or insurer will ask for. Transputec scores each workload before picking either route.

This article was drafted with AI assistance and reviewed by the Transputec team. Featured image: AI-generated.

Ready to experience the Transputec difference?

Turn IT headaches into operational strength. Book a free consultation and see exactly what we can streamline inside your business. 

Get a Strategic Consultation

Sonny Sehgal

CEO & Co-Founder

Since co-founding Transputec, Sonny has guided hundreds of enterprises through every major shift in technology- from the birth of the PC to the rise of Global Cloud and now Generative AI. Known for his "straight-talking" approach to cyber security and IT strategy, he provides the bridge between complex technical infrastructure and boardroom-level business outcomes.

Share Blog »

← Blogs

Contact

Get in Touch