Cyber One Solutions logo.
Get Support

Cloud

Windows Server 2016 Support Ends in January 2027

September 29, 2026 ·

Microsoft stops security updates for Windows Server 2016 on January 12, 2027. Compare upgrading, moving to Azure, and paying for Extended Security Updates. It also explains why moving to Azure should no longer be assumed to make those extra updates free.

Microsoft stops releasing security updates for Windows Server 2016 on January 12, 2027. A server still running it will keep working, but vulnerabilities found after that date will stay unpatched unless it is covered by Extended Security Updates. Most businesses have three realistic paths: upgrade to a supported version, move the workload to Azure, or pay for Extended Security Updates to buy time. One detail has changed since the last round of server retirements: moving to Azure should no longer be assumed to make those extra updates free.

What Actually Ends on January 12, 2027

Microsoft's Windows Server 2016 lifecycle page covers the Datacenter, Essentials, MultiPoint Premium, and Standard editions, with mainstream support already over and extended support ending in January 2027. Microsoft's 2027 end-of-support list puts Windows Server 2016, Hyper-V Server 2016, and Windows Storage Server 2016 on the same date: January 12, 2027.

After that date, Microsoft's Extended Security Updates overview is direct about the result: the end of support means the end of security updates, which can cause security or compliance issues and put business applications at risk.

There is a second clock for servers that host Microsoft 365 desktop apps, such as a Remote Desktop server staff log into. Microsoft's Windows Server and Microsoft 365 Apps support page says support for Microsoft 365 Apps on Windows Server 2016 already ended on October 14, 2025, with security updates for those apps continuing until October 10, 2028.

Who This Affects

Any business that still runs an on-site or hosted server for file shares, a domain controller, an accounting or practice-management database, or a Remote Desktop environment should check its version now. These are often the machines nobody has touched in years, precisely because they still work. If your business answers to HIPAA, the FTC Safeguards Rule, or a cyber insurance application, an unsupported server is exactly the kind of gap your risk assessment should record and resolve.

Option 1: Upgrade to a Supported Version

Microsoft's upgrade planning guide says that starting with Windows Server 2025, nonclustered systems can upgrade up to four versions at a time, and its supported-path table shows Windows Server 2016 upgrading directly to 2019, 2022, or 2025 from installation media. The same guide adds two cautions: not every server role supports an in-place upgrade, and unlike Windows on a PC, each Windows Server upgrade requires its own license.

Pick the target version carefully. The Microsoft 365 Apps support page above says Microsoft 365 Apps is supported on Windows Server 2022 only while it is in Mainstream Support, which ends in October 2026, while Mainstream Support for Windows Server 2025 runs to October 2029. For a Remote Desktop server, that makes Windows Server 2025 the more durable choice.

Also check the hardware. A server old enough to run 2016 may be due for replacement anyway, which can make a clean build on new hardware, with data migrated across, the simpler path.

Option 2: Move the Workload to Azure

Moving a server into Azure removes the hardware question. Microsoft's in-place upgrade guide for Azure virtual machines lists Windows Server 2016 among the versions that can be upgraded to Windows Server 2025 once the workload is running there.

Here is what changed. For Windows Server 2012 and 2012 R2, Microsoft's ESU FAQ says workloads migrated to Azure get Extended Security Updates for three years at no additional charge above the cost of running the virtual machine. In a March 27, 2026 licensing update, Microsoft announced standardized Extended Security Update pricing for Windows and SQL Server offerings starting April 1, 2026, so customers pay the same list price regardless of whether they deploy in Azure, on-premises, or in other public clouds. Existing offerings such as Windows Server 2012 are not affected, and Microsoft's Azure Local documentation names Windows Server 2016 among the offerings subject to the new pricing. Move to Azure because it fits how you want to run the workload, not to avoid paying for security updates.

Option 3: Buy Time With Extended Security Updates

Extended Security Updates (ESUs) are a paid program that keeps delivering Critical and Important security fixes after support ends. According to Microsoft's Azure Arc ESU preparation guide, Windows Server 2016 ESUs run for up to three years, through 2030. They can be configured in the Azure portal starting August 3, 2026, with billing for ESUs enabled by Azure Arc beginning January 13, 2027.

The same guide lists requirements worth checking early:

The Azure Connected Machine agent must be version 1.62 or higher.

Windows Server 2016 ESUs support the Standard and Datacenter editions. If a small office server runs the Essentials edition, confirm eligibility before counting on this path.

Software Assurance, or an equivalent Server Subscription, is required for on-premises workloads, and the Services Provider License Agreement (SPLA) is not available for Windows Server 2016 ESUs.

The same ESU FAQ calls the program "a last resort paid option" and a temporary bridge. ESUs do not include new features or customer-requested non-security fixes, so treat them as a way to finish a migration safely, not a reason to postpone one.

A Practical Checklist Before January

  1. 1. Inventory every server running Windows Server 2016, including Hyper-V hosts and virtual machines.
  2. 2. Record what each one does: its roles, the applications on it, and who depends on it.
  3. 3. Ask each software vendor which Windows Server versions they support for their current release.
  4. 4. Confirm the edition and licensing of each server, including whether Software Assurance is active.
  5. 5. Choose upgrade, Azure, or ESU for each server, and schedule the work with a tested backup taken first.
  6. 6. For any server that will miss the deadline, set up ESU enrollment before January 12, 2027.

How Cyber One Solutions Can Help

Cyber One Solutions' Managed Cloud services cover Azure infrastructure, cloud migration, and cost management, so moving a server workload is planned against what it will actually cost to run. For servers that stay on-site, our Managed IT services cover server patching and track hardware and software end-of-life dates. If you are comparing cloud providers, our cloud buyer's guide covers what to ask about migrations and cost governance. If you are not sure how many 2016 servers you have or which path fits each one, contact us and we will help you build the plan before the deadline.

Frequently Asked Questions

Will a Windows Server 2016 machine stop working on January 12, 2027?

No. It will keep running, but Microsoft will stop releasing security updates for it unless it is enrolled in Extended Security Updates.

Are Extended Security Updates free if we move the server to Azure?

Do not plan on it. Microsoft's pricing update for Extended Security Update offerings released from April 1, 2026 sets the same list price across Azure, on-premises, and other clouds, and Microsoft's documentation names Windows Server 2016 among the offerings subject to that pricing. The free-in-Azure model applied to earlier offerings such as Windows Server 2012.

Does this affect Microsoft 365 Apps on our Remote Desktop server?

It already has. Support for Microsoft 365 Apps on Windows Server 2016 ended on October 14, 2025, and security updates for those apps continue only until October 10, 2028.