Windows Server 2016 goes dark January 12, 2027. Azure can buy you three more years, if you start now.

While I was pulling the lifecycle dates together for last week's Windows 10 post, I ended up going down a rabbit hole on Windows Server 2016, and the date I kept landing on was a lot closer than I expected. The October 12, 2027 date that's been floating around is the Windows 10 consumer ESU deadline. Windows Server 2016 reaches end of extended support on January 12, 2027, which is about 108 days from the day I'm writing this.

If the plan in your shop was to start the fleet audit next summer, the calendar already made that decision for you. Between now and January you have budget season, the holidays and at least one change freeze, so realistically you have about 10 working weeks to figure out what you have, who owns it and where each server is going.

The good news is that Microsoft built most of the escape routes through Azure this time, and a few of them cost less than people assume.

What actually ends on January 12, 2027

After that date Windows Server 2016 stops getting security updates, and so does a handful of things that ship with it or run on top of it. Microsoft's 2027 end-of-support list includes:

  • Windows Server 2016 — every edition, including the Datacenter and Standard boxes quietly running line-of-business apps

  • Hyper-V Server 2016 — the free hypervisor, so check your hosts along with the guests

  • WSUS for Windows Server 2016 — if your patch server runs on 2016, the thing delivering your patches is out of support too

  • IIS 10 on Windows Server 2016 and .NET Framework 4.6.2 — web front ends and older in-house apps ride along with the OS

  • Windows Defender for Windows Server 2016 — the built-in antivirus on those servers goes with it

The System Center 2016 products end one day earlier, on January 11, 2027, so if you're still running SCOM 2016 or SCCM-era tooling on those boxes, put them on the same list.

Why next summer is too late

The obvious reason is that next summer is six months past the deadline, however there are a few less obvious ones that matter just as much.

  • Waiting doesn't save money — if you enroll in ESUs through Azure Arc after January 12, Microsoft back-bills the license to January 12. You pay for those months either way, the only difference is whether the servers were patched during them

  • Budgets close before the deadline does — most organizations lock next year's budget in Q4, so if ESU costs or replacement hardware aren't in that number now, you're asking for money mid-year

  • App owners need time to test — an in-place upgrade is quick, getting the vendor or the app owner to sign off on it usually isn't

  • Change freezes eat December — if your environment freezes from mid-December into the new year, your real deadline is closer to Thanksgiving

Where Azure earns its keep

With the 2012 end of support, a lot of shops bought ESU keys and pasted them into each server. For 2016, Azure gives you a cleaner set of options, and this is where it's worth taking a real look at the platform even if you've kept most of your servers on-prem.

  • Azure VMs get ESUs at no extra charge — move a 2016 workload into an Azure VM as-is and the Extended Security Updates come with it, with nothing to configure. The same goes for Azure Local, Azure VMware Solution and Azure Dedicated Host. That buys you up to three years to do the upgrade properly instead of rushing it

  • Azure Arc brings ESUs to the servers that stay put — onboard your on-prem 2016 servers to Azure Arc, create a Windows Server 2016 ESU license in the Azure portal and link it to the machines. Microsoft opened 2016 ESU licensing in the portal on August 3, 2026, and billing doesn't start until January 13, 2027, so you can set all of this up now without paying for it yet

  • Pay monthly and stop when you're done — Arc ESUs are pay-as-you-go through your Azure subscription, so they count against existing Azure commitments and show up in Cost Management. When a server gets upgraded or retired, you reduce the cores on the license and the bill follows within five days

  • No keys on every server — the Azure Connected Machine agent turns on the updates for each enrolled machine, and the updates come through whatever you already patch with, whether that's WSUS, Configuration Manager or Azure Update Manager

  • Management tools come with it — servers enrolled in ESUs through Arc get Azure Update Manager, Change Tracking and Inventory, and Azure Policy guest configuration at no extra cost

  • One place to see coverage — the Eligible resources tab in the portal lists every Arc-connected 2016 server and whether ESUs are enabled on it, which is a lot easier than a spreadsheet of MAK activations

One catch to plan for is that buying ESUs for servers outside Azure requires Software Assurance through a volume licensing agreement, so get your licensing partner involved early.

Every 2016 server should end up on one of these paths on purpose:

Path Security updates after Jan 12, 2027 What to know
Upgrade in place Full support on the new version Windows Server 2025 supports nonclustered in-place upgrades from 2016, so test the apps and go.
Move to an Azure VM ESUs included at no extra charge Lift and shift as-is, then upgrade on your own schedule. Azure Hybrid Benefit lets you bring existing licenses.
Stay on-prem, enroll through Azure Arc ESUs billed monthly through Azure Needs Software Assurance. Billing starts January 13, 2027, and late enrollment is back-billed to January 12.
Do nothing None The server stops getting security fixes and every new CVE stays open.

Your fleet audit checklist

Here's the order I'd work through it. Most of this can be done in a week if you block the time for it.

1. Pull every Windows Server 2016 machine out of Active Directory. This gets you the list along with the last logon date, which helps you spot stale objects:

Get-ADComputer -Filter 'OperatingSystem -like "Windows Server 2016*"' `
-Properties OperatingSystem, OperatingSystemVersion, LastLogonDate |
Select-Object Name, OperatingSystem, LastLogonDate |
Export-Csv .\ws2016-fleet.csv -NoTypeInformation

If some of your servers are already connected to Azure Arc, this Azure Resource Graph query lists the 2016 machines there:

resources
| where type == "microsoft.hybridcompute/machines"
| where properties.osSku contains "2016"
| project name, resourceGroup, properties.osSku, properties.status

2. Go looking for the ones AD doesn't know about. Workgroup servers in the DMZ, vendor appliances running 2016 under the hood, lab machines and anything a contractor stood up years ago. Your RMM, vulnerability scanner and hypervisor inventory will catch most of them.

3. Check the infrastructure servers first. Domain controllers, WSUS, Hyper-V hosts, file servers and SQL boxes on 2016 carry more risk than a single app server, and they usually take longer to move.

4. Put an owner and an application next to every server. If nobody can tell you what a server does, that's your first retirement candidate.

5. Assign each server a path. Upgrade, move to an Azure VM, enroll in Arc ESUs or retire. Nothing should end up in the ESU bucket just because nobody looked at it.

6. Onboard the ESU candidates to Azure Arc now. Create the 2016 ESU license, link the servers, then run azcmagent show on each one and confirm the Extended Security Updates status shows Active. Doing this in October means you're not troubleshooting agent connectivity on January 11.

7. Price it and get it into the budget. ESU billing depends on the edition (Standard or Datacenter) and the core count, physical or virtual, so pull those numbers from the inventory before you talk to finance.

8. Schedule the upgrades before your change freeze. Anything on the upgrade path should have a date on it that lands before the holidays.

What to tell leadership

Keep it short and bring the plan with you. Something like this works:

Windows Server 2016 stops getting security updates on January 12, 2027. We have [number] servers on it. Here's the plan for each one, which ones we're upgrading, which ones we're moving to Azure where the security updates are included, and which ones need paid extended updates while we finish. Waiting past January doesn't save money, because Microsoft bills back to that date anyway.

That conversation is a lot easier in October than it is the week after a critical CVE drops for a server you can't patch.

If Azure Arc is new in your environment, the free Azure Arc Pre-Flight Checklist on OpStacks.net covers the network and agent prerequisites, and the Azure Arc Onboarding Pack has the scripts I use to get Windows servers connected.

If you're working through this for your own fleet or your clients and run into something this post didn't cover, let me know at opstacks@outlook.com.

Sources

Previous
Previous

AZ-104 vs. SAA-C03: One Exam Asks How You’d Run It, The Other Asks What You’d Build

Next
Next

The free Windows 10 Extension Doesn’t Cover Your Clients