Windows Server 2016 End of Support: January 12, 2027 — How to Plan Your Migration in Time
Microsoft ends Extended Support for Windows Server 2016 on January 12, 2027. Three migration paths compared — with a concrete timeline and cost guidance for SMBs.
On January 12, 2027, Microsoft ends Extended Support for Windows Server 2016. After that date, there will be no more security updates, no bug fixes, and no technical support from Microsoft. The server will keep running — but every vulnerability discovered after that point will remain permanently unpatched.
The date itself is not news. What is new: from today, there are roughly 15 weeks left until the deadline. For a migration that should be properly tested and carried out with minimal risk, that is tight — but sufficient, if you start now.
Note: Licence prices and support terms are subject to change. This article provides an overview based on publicly available Microsoft information as of September 2026 and does not constitute individual licensing or migration advice.
What changes on January 12, 2027?
Windows Server 2016 loses Extended Support on that date — ending all official vendor service. Microsoft publishes security updates monthly on the second Tuesday (Patch Tuesday); after this date, no more will be released for Server 2016. Newly discovered CVEs will still be published — attackers read those disclosures and know exactly which Windows versions will not receive the fix.
Windows Server 2016 has been on the market since October 2016 and carries ten years of production use behind it. In many businesses it is deeply embedded: file servers, domain controllers, ERP backends, internal web services. That makes migration more complex than a desktop upgrade — and makes early planning all the more important. Businesses are familiar with this pattern from the Windows 10 end of support in October 2025; on the server side, the consequences of an unplanned transition are considerably more severe.
Five risks that arise after the deadline
Unpatched security vulnerabilities — permanently. Every vulnerability published after January 12 will remain open for ever. Attackers actively scan for end-of-life systems — the current ransomware threat landscape for 2026 shows that manufacturing and services businesses in the Ruhr region are directly in the crosshairs.
Cyber insurance becomes a liability. Many insurers now require evidence that all production systems run within vendor support. A Server 2016 instance after the deadline can be classified as a contributing factor in a loss event — reducing or voiding the claim. The specific IT requirements cyber insurers demand in 2026 leave little room for interpretation on this point.
Compliance documentation develops gaps. GDPR Article 32, ISO 27001, and NIS2 all require technical measures in line with the state of the art. An unpatched operating system no longer meets that standard at the latest one year after end of life. In the event of an incident or an audit, it must be possible to explain why a system was operated without vendor support.
Software compatibility erodes quietly. Microsoft 365, Azure agents, Entra ID connectors, and many ERP systems periodically raise their minimum system requirements. Windows Server 2016 will fall out of support matrices progressively — often without an explicit warning, only visible when a connector or agent update fails.
Emergency migration after a security incident costs multiples of a planned one. Anyone forced to migrate under time pressure after a ransomware attack has no time for testing, no clean rollback plan, and little negotiating power with service providers. What a single day of IT downtime actually costs your business can be calculated quickly with the downtime cost calculator — the figure almost always exceeds the cost of a planned migration.
Three options from January 2027 onwards
Option 1 — In-place upgrade to Windows Server 2025 (on-premises)
Windows Server 2025 supports a direct in-place upgrade from Windows Server 2016 — something that had not been possible since Server 2012 R2 and has now been reinstated. The infrastructure stays on-premises; roles and configurations are preserved without a fresh installation. Extended Support for Windows Server 2025 runs until October 2034.
Requirements: compatible hardware (TPM 2.0 is mandatory), compatibility check of all installed roles and applications, and a rollback plan in case any services fail post-upgrade. Testing the upgrade on a clone of the production environment is not optional.
Option 2 — Cloud migration (Azure)
Workloads without strict local data-residency requirements benefit from a move to Azure. Microsoft provides Extended Security Updates for Windows Server 2016 free of charge as long as the instance runs on Azure — the time pressure disappears effectively, though the migration work itself remains the same. For file server and collaboration workloads, Microsoft 365 (SharePoint, OneDrive) is often the leaner long-term solution compared with a straight lift-and-shift of the old server structure.
Option 3 — ESU as a bridging measure (maximum 3 years)
Extended Security Updates are available for purchase on-premises via Software Assurance or Volume Licensing. The costs escalate annually: Year 1 costs 75 % of the current annual Software Assurance value of the affected server licence; each subsequent year adds a further cumulative increment. ESU is not a permanent solution — after January 2030 at the latest, this path also closes.
ESU makes sense as a buffer if a specific technical dependency blocks the switch in the short term (custom software development, an ongoing ERP project) — but only with a firm completion date for the actual migration in the following year.
What does waiting cost versus migrating?
A rough orientation for a business with two Windows Server 2016 instances (Standard Edition, 16 physical cores each):
| Scenario | One-off effort | Ongoing costs |
|---|---|---|
| In-place upgrade to WS 2025 | IT services + test time | Licence (one-off); operating overhead unchanged |
| Azure lift-and-shift (2 × D2s_v5) | Migration, network adjustments | Approx. €150–300/month depending on configuration |
| ESU Year 1 on-premises (SA basis) | SA contract review | 75 % of annual SA value; rises every year |
| No action, then security incident | Incalculable | Downtime, data loss, potential insurance shortfall |
The last row is not scaremongering: based on market data, the total cost of a successful ransomware attack on a mid-sized business runs into five to six figures in euros — a planned migration costs a fraction of that.
Which path fits which business?
In-place upgrade is the right choice when hardware and applications are compatible, no cloud migration is planned, and the business intends to stay on-premises long term. Preparation — particularly the test on a cloned environment — determines whether the project succeeds.
Azure migration pays off when workloads need to scale, multiple locations are managed centrally, or the business is already consolidating towards Microsoft 365 infrastructure. The free ESU on Azure provides additional planning headroom without an immediate security gap.
ESU is only justified when a specific technical obstacle prevents the switch in the near term — and only with a fixed completion date for the actual migration. Using ESU as a permanent solution is both more expensive and more risky than a clean upgrade.
What should be done by December 2026?
With 15 weeks until the deadline, time is limited but sufficient — if work begins today.
October 2026 — Inventory: Which servers are running Windows Server 2016? Which roles are installed (AD DS, DNS, DHCP, IIS, Hyper-V, SQL Server)? Which applications and interfaces depend on them?
November 2026 — Testing and compatibility check: Test upgrade candidates on a cloned environment. Evaluate Azure workloads in a staging subscription. Verify backups of all affected systems following the 3-2-1 backup principle — a current full backup immediately before the production migration is non-negotiable.
December 2026 — Production migration: Schedule a migration window (ideally Friday evening to Sunday), take a snapshot before the upgrade, and run 72 hours of monitoring afterwards.
January 2027 — Completion and documentation: Decommission legacy systems (do not delete them immediately), notify vendors and software partners, and document the completed measures for insurers and compliance auditors.
What decision-makers want to know
Do I really have to be finished before January 12? Technically the server keeps running. However, insurance cover, compliance obligations, and the absence of security patches all take effect from that date. Anyone wanting to use ESU also needs to arrange the licence agreement in advance — it is not an ad-hoc purchase.
Can I really upgrade directly from 2016 to 2025 without an intermediate step? Yes. Microsoft has explicitly released the direct upgrade path from Windows Server 2016 to 2025. The full procedure is documented in the Windows Server upgrade guide on Microsoft Learn.
What about SQL Server instances running on these machines? SQL Server has its own end-of-life timeline and must be assessed separately. SQL Server 2016 already lost Extended Support in July 2026. A combined migration project — OS and SQL Server in a single pass — is more efficient than two separate engagements.
We are a small trade business in Recklinghausen — where do we start?
Start with a simple inventory: run winver on each server, note the hostname, main application, and critical interfaces in a short list. That is enough to kick off an initial conversation.
Running Windows Server 2016 past January 12 without a plan is not a neutral decision — it is a deliberate choice to operate without patched infrastructure. If you want to know which migration path fits your business, we are ready to help: IT support and server migrations in the Ruhr region.
Note: The articles on this blog are produced with the help of AI and are editorially reviewed before publication. Editorial responsibility lies with Emre Yurtbay (see the Impressum).