★ First page of Microsoft's 100,000-partner directory, sorted by responsiveness✓ Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation● Microsoft partner since 2006◆ 1,100+ organizations under management
Microsoft deadlines that change what you should be doing
The end-of-support, retirement and compliance dates that affect Microsoft 365, Windows Server, SQL Server, Exchange and Azure customers — each one verified against Microsoft’s own lifecycle documentation (or the regulator’s own notice) and shown with the source we checked it against. Every date says what happens, who it affects and what your options are. Subscribe and we’ll email you 90, 30 and 7 days before each one.
🗓 Add to calendarSubscribe in any calendar app to keep the dates updated.
Next 90 days
Close enough that the decision is already late if it hasn't started.
24 daysEntra ID
Entra Connect Sync minimum version enforced
What happens
A back-end hardening change means all synchronisation services in Microsoft Entra Connect Sync stop working unless the server is on at least version 2.5.79.0.
Who it affects
Organisations running hybrid identity with Entra Connect Sync (formerly Azure AD Connect) on an older build; directory sync stops until the server is upgraded.
Your options
Upgrade Entra Connect Sync now, preferably to the current release (2.6.84.0) rather than the bare minimum, or move to Entra Cloud Sync.
Version 2.5.79.0 itself reaches end of support on 23 October 2026, so upgrading only to the minimum buys about three weeks. Doc also mirrored at github.com/MicrosoftDocs/entra-docs/blob/main/docs/identity/hybrid/connect/harden-update-ad-fs-pingfederate.md
EWS requests start being blocked in Exchange Online
What happens
Microsoft begins blocking Exchange Web Services requests to Exchange Online; tenants that did not opt in keep EWS disabled by default and only apps on the EWSAllowedAppIDs allow list can still connect.
Who it affects
Any Microsoft 365 tenant with third-party or in-house applications, backup tools, migration tools, signature tools or CRM connectors that still call EWS against Exchange Online.
Your options
Move applications to Microsoft Graph, or set EWSEnabled to True with an EWSAllowedAppIDs allow list as a short bridge while the migration finishes.
EWS was set to EWSEnabled=False by default for tenants that had not opted in during August 2026. This affects Exchange Online only; EWS in Exchange Server is unchanged.
Office LTSC 2021, Office 2021, Visio LTSC 2021 and Project LTSC 2021 stop receiving security updates, bug fixes and technical support; there is no extended support phase and no ESU programme.
Who it affects
Organisations and users on the 2021 perpetual Office family, including isolated or regulated devices deliberately kept off the cloud.
Your options
Move to Microsoft 365 Apps, or to Office LTSC 2024 where a perpetual, device-based build is still required.
Windows 10 Enterprise LTSB/LTSC 2016 end of support
What happens
Windows 10 Enterprise 2016 LTSB reaches the end of its ten-year support window and stops receiving security updates.
Who it affects
Fixed-purpose devices still on the 2016 LTSB build: manufacturing terminals, kiosks, medical and point-of-sale equipment.
Your options
Move to Windows 11 Enterprise LTSC 2024, or to Windows 10 Enterprise LTSC 2021 as a shorter bridge (itself ending 12 January 2027); Microsoft has signalled ESU coverage for the retiring LTSB/LTSC releases.
Not on the candidate list but shares the 13 October 2026 cluster. Windows 10 Enterprise LTSC 2021 ends 12 January 2027, the same day as Windows Server 2016.
Windows 11 version 24H2 Home and Pro end of servicing
What happens
Windows 11 version 24H2 stops receiving monthly security updates on Home, Pro, Pro Education and Pro for Workstations editions after 24 months of servicing.
Who it affects
Any fleet or household device still on Windows 11 24H2 with a Home or Pro edition.
Your options
Install the 25H2 (or later) feature update, which is an enablement package on 24H2 and takes minutes; Enterprise, Education and IoT Enterprise editions of 24H2 get 36 months and run longer.
Windows Server 2012 / 2012 R2 Extended Security Updates end
What happens
The third and final year of Extended Security Updates for Windows Server 2012 and 2012 R2 ends; no further security updates will be produced at any price, including for VMs running in Azure.
Who it affects
Anyone still running Windows Server 2012 or 2012 R2, on-premises, on Azure VMs, Azure VMware Solution or Azure Stack, where ESU was free.
Your options
Upgrade in place to a supported Windows Server release, rebuild on Windows Server 2022/2025, or move the workload to Azure PaaS; there is no fourth ESU year.
Extended support originally ended 10 October 2023; ESU ran three years from there. Azure-hosted VMs received the ESUs automatically at no extra charge above the VM cost, and that free entitlement ends on the same day.
Windows Server 2022 leaves mainstream support and enters five years of extended support, where it still gets monthly security updates at no extra cost but no new features and no non-security fixes.
Who it affects
Every Windows Server 2022 estate; there is no immediate security impact, but non-security bug fixes and design change requests stop.
Your options
Nothing urgent is required, since extended support runs to 14 October 2031; plan the move to Windows Server 2025 into the normal refresh cycle.
Extended support end date of 14 October 2031 is consistent across sources; the Microsoft lifecycle page is egress-blocked here.
.NET 8 (LTS, 36 months from November 2023) and .NET 9 (STS) both reach end of support; no further servicing updates, security fixes or technical support are shipped.
Who it affects
Teams running applications, container images or Azure App Service/Functions workloads on .NET 8 or .NET 9, and anyone depending on the PowerShell releases built on them.
Your options
Upgrade to .NET 10, which shipped in November 2025 as the current LTS release and is supported through November 2028.
Correction to the candidate list: the same date also retires .NET 9, which was not mentioned. The exact .NET 10 GA day was not confirmed from an authoritative snippet, so only the month is stated.
Windows 11 version 23H2 Enterprise and Education end of servicing
What happens
Windows 11 version 23H2 stops receiving monthly security updates on Enterprise, Education, Enterprise multi-session and IoT Enterprise editions after 36 months.
Who it affects
Managed fleets that pinned 23H2 for application-compatibility reasons.
Your options
Move to Windows 11 25H2 (or 24H2 as a staging step); Home and Pro editions of 23H2 already ended servicing in November 2025.
Far enough out to be a budget line rather than an emergency.
116 daysExchange
SMTP AUTH basic authentication disabled by default in Exchange Online
What happens
At the end of December 2026 Microsoft turns off SMTP AUTH client submission with basic authentication by default for existing tenants; administrators can still re-enable it, and tenants created after that point do not get it at all.
Who it affects
Anyone relaying mail through smtp.office365.com with a username and password: multifunction printers, scanners, line-of-business apps, alerting systems and ERP mail.
Your options
Move devices and apps to OAuth-based SMTP AUTH, to a high-volume email or direct-send path, or to an SMTP relay appliance; re-enabling basic auth per tenant is a temporary measure only.
Microsoft's updated timeline (published 27 January 2026) says 'end of December 2026' without naming a calendar day; 31 December 2026 is used here as the end of that window, not as an announced date. The final removal date is due to be announced in the second half of 2027. This replaces the earlier September 2025 and 1 March 2026 plans.
Businesses using automated decision-making technology to make significant decisions about consumers must give pre-use notice, offer an opt-out unless an exemption applies, and honour access requests explaining how the decision was made.
Who it affects
Businesses subject to the CCPA that use ADMT for decisions about employment, lending, housing, education, healthcare or essential goods and services.
Your options
Inventory ADMT uses, publish pre-use notices, build the opt-out and access workflows, and document whether a human-appeal exemption applies.
Windows Server 2016 reaches the end of its ten-year lifecycle and stops receiving security updates and technical support; servers keep running but are unpatched.
Who it affects
Every remaining Windows Server 2016 host, including domain controllers, file servers and application servers, plus Windows 10 Enterprise LTSC 2021 devices which share the date.
Your options
Upgrade to Windows Server 2025 (via 2019/2022 if a double hop is needed), rebuild on new hardware, move workloads to Azure, or buy up to three years of Extended Security Updates.
ESU for Windows Server 2016 is confirmed as available for up to three years but Microsoft had not published per-core ESU pricing at the time of checking. Windows Server 2016 mainstream support ended 11 January 2022.
Azure compute reservation exchanges end for new purchases
What happens
Compute reservations purchased on or after this date, for services covered by Azure savings plans, can no longer be exchanged; reservations purchased before it keep the right to one final exchange.
Who it affects
Azure customers and CSP partners holding VM, Dedicated Host or App Service reserved instances and relying on exchanges to re-shape their commitment.
Your options
Use the one final exchange on pre-cutoff reservations, plan future commitments with Azure savings plans (which flex across eligible compute but cannot be cancelled or exchanged), or rely on cancellations within the USD 50,000 rolling 12-month cap per billing scope.
Fetched from the GitHub mirror because learn.microsoft.com is egress-blocked. Instance size flexibility is unaffected, and reservations for products not covered by savings plans (for example Azure VMware Solution) are outside the change. Matches the 1 February 2027 date already cited on the Managed Azure FinOps service page in this repo.
Microsoft-provided SMS and voice MFA retired in Entra ID
What happens
Microsoft stops sending its own SMS and voice-call MFA messages; tenants relying only on those methods will see sign-in failures.
Who it affects
Entra ID tenants where users still register text message or phone call as their MFA method, including shared and frontline accounts.
Your options
Move users to passkeys, Microsoft Authenticator or certificate-based authentication, or contract a telecom provider through the Microsoft Security Store to keep telephony methods.
Announced as MC1426371. Two related milestones: passkeys became the Microsoft-managed default with a registration campaign on 1 September 2026, and third-party telecom providers become selectable in the Microsoft Security Store on 30 October 2026. Microsoft advises completing provider setup at least four weeks before 1 February 2027.
NYDFS Part 500 annual compliance certification due
What happens
Covered entities must electronically file either a certification of material compliance or an acknowledgement of non-compliance with a remediation plan for calendar year 2026, signed by the highest-ranking executive and the CISO.
Who it affects
All NYDFS-licensed covered entities, including those relying on limited exemptions.
Your options
File the certification with supporting evidence, or file the acknowledgement with a documented remediation timeline; the deadline repeats every 15 April.
The 15 April 2026 filing was the first to cover a full calendar year in which every Second Amendment control, including universal MFA and the asset inventory, was in force.
SQL Server 2017 reaches the end of extended support and stops receiving security updates outside the ESU programme.
Who it affects
Anyone running SQL Server 2017 on Windows or Linux, on-premises or on VMs in any cloud.
Your options
Upgrade to SQL Server 2022 or 2025, migrate to Azure SQL Managed Instance or Azure SQL Database (free ESU while migrating), or buy up to three years of ESU through Azure Arc, Azure VMs or volume licensing.
The sql-docs GitHub mirror confirms 2027 as the extended-support year for SQL Server 2017; the exact day of 12 October 2027 comes from search snippets citing the Microsoft lifecycle page. SQL Server 2017 mainstream support ended in 2022.
Windows 10 ESU year 2 ends (consumer and commercial)
What happens
The second year of Windows 10 Extended Security Updates ends. This is also the end of the consumer ESU programme, which Microsoft quietly extended by a year in June 2026.
Who it affects
Consumers enrolled in free consumer ESU, and commercial customers in year 2 of the paid ESU programme.
Your options
Consumers must be on Windows 11 or new hardware by this date, since there is no consumer year 3; commercial customers can buy a third and final ESU year running to 10 October 2028.
MAJOR CORRECTION to the candidate list: consumer ESU does NOT end on 13 October 2026. Microsoft updated its Windows 10 ESU documentation and added an editor's note dated 25 June 2026 to the Windows Experience Blog extending consumer coverage to 12 October 2027. Commercial ESU year 1 still ended 13 October 2026.
CPPA risk assessment submissions and first cybersecurity audit certifications due
What happens
Businesses must submit information on risk assessments conducted during 2026 and 2027 to the CPPA, and the largest businesses must file their first cybersecurity audit certification.
Who it affects
CCPA-covered businesses conducting risk-assessment-triggering processing, and for the audit certification those with annual revenue above USD 100 million.
Your options
Start risk assessments now (required for new processing from 1 January 2026, with pre-2026 activities documented by 31 December 2027) and scope an independent cybersecurity audit; smaller businesses certify on 1 April 2029 (USD 50-100 million revenue) and 1 April 2030 (under USD 50 million).
Correction to the candidate list: risk assessments themselves became required for processing initiated from 1 January 2026, with a 31 December 2027 deadline to document pre-existing processing; 1 April 2028 is the submission deadline, not the start.
The third and final year of paid Windows 10 Extended Security Updates ends; no further Windows 10 security updates are produced.
Who it affects
Commercial and education customers who bought all three ESU years to keep legacy Windows 10 devices patched.
Your options
Complete the Windows 11 migration, replace non-compliant hardware, or move users to Windows 365 or Azure Virtual Desktop, where Windows 10 ESU is included but also ends here.
ESU years are cumulative: an organisation enrolling in year 3 must also pay for years 1 and 2.
Microsoft ends product enhancements, regulatory and tax updates, and technical support for Dynamics GP; security patches, if needed, continue until 30 April 2031.
Who it affects
Businesses still running Dynamics GP as their ERP, particularly those depending on payroll and tax table updates.
Your options
Migrate to Dynamics 365 Business Central or another ERP; the security-patch tail to April 2031 is a runway, not a supported state.
Correction to the candidate list: the end-of-support date was moved from 30 September 2029 to 31 December 2029, with security updates available to 30 April 2031.
The last 18 months — kept because unsupported estates don't fix themselves on the date.
passedSQL Server
SQL Server 2016 extended support ended
What happens
SQL Server 2016 reached the end of extended support and stopped receiving regular security updates.
Who it affects
Anyone running SQL Server 2016 on-premises, on Azure VMs, on Azure VMware Solution or in another cloud.
Your options
Upgrade to SQL Server 2022 or 2025, migrate to Azure SQL Managed Instance or Azure SQL Database (which carries free ESU while you migrate), or buy Extended Security Updates through Azure Arc, Azure VMs or volume licensing.
SharePoint Server 2016 and 2019 stopped receiving security updates, bug fixes, time-zone updates and paid assisted support, with no paid ESU programme offered.
Who it affects
Organisations running on-premises SharePoint 2016 or 2019 farms, including hybrid farms kept for a single workload.
Your options
Upgrade the farm to SharePoint Server Subscription Edition (Modern Lifecycle Policy, requires a current subscription licence and regular feature updates), or migrate content to SharePoint Online.
SharePoint Designer 2013 and the InfoPath 2013 client reached their final end of support on the same date. The Microsoft lifecycle page could not be fetched directly from this container; the date is consistent across every source checked.
The Department of War/Defense suspended the CMMC Phase 2 requirements that were due to start on 10 November 2026 and launched a 60-day reform review of the programme.
Who it affects
Defense contractors and subcontractors that were preparing for mandatory third-party (C3PAO) assessments at Level 2.
Your options
Phase 1 self-assessment obligations and the underlying DFARS 252.204-7012 and NIST SP 800-171 requirements still apply, so continue remediation work and watch for the reform task force outcome before booking a C3PAO assessment.
Correction to the candidate list: the 10 November 2026 Phase 2 date is no longer in force.
Microsoft 365 and Entra pricing update took effect
What happens
New global list prices took effect for a wide set of commercial SKUs, including Entra ID P1 and P2, EMS E3/E5, Windows E3/E5, Microsoft 365 Apps and the per-device SKUs, alongside packaging changes that added Defender for Office 365 P1 and several Intune capabilities into the suites.
Who it affects
Commercial and government customers buying or renewing Microsoft 365, Entra or Windows subscriptions, and CSP partners repricing their own offers.
Your options
Existing customers see the new prices at their first renewal after 1 July 2026; review suite composition before renewal because some standalone add-ons are now included and may be removable.
Packaging changes began rolling out in June 2026 with completion of the Defender for Office 365 P1 and Intune additions by 1 August 2026; tenants receive at least 30 days notice in Message Center. Entra ID P1 was reported to rise by roughly 16 percent, but percentage figures come from third-party licensing analysts rather than the Microsoft page.
Teams live events, and the Microsoft Graph APIs used to create them, were retired; new live events can no longer be scheduled.
Who it affects
Organisations that ran large broadcasts through Teams live events, including via Viva Engage, Dynamics 365 or custom Graph integrations.
Your options
Move broadcasts to Teams town halls or Teams webinars, and rework any Graph automation that created live events.
Events created before the cut-off remain supported until 28 February 2027. Separately, Teams Together Mode and the legacy third-party meeting and call control APIs were also retired in June 2026.
Windows Server 2025 hotpatch became free via Azure Arc
What happens
Microsoft removed the hotpatch subscription charge for Azure Arc-connected Windows Server 2025 Standard and Datacenter machines and stopped billing servers already enrolled.
Who it affects
Anyone running Windows Server 2025 on-premises or in another cloud who wants restart-free monthly security updates.
Your options
Connect the server to Azure Arc and enable hotpatch; there is no longer a per-core meter to budget for.
Reverses the $1.50 per core per month subscription that had applied from 16 July 2025. Correction to the candidate assumption that hotpatch billing is still live.
Microsoft 365 E7 went on sale, bundling Microsoft 365 E5, Microsoft 365 Copilot, Agent 365 and the Microsoft Entra Suite.
Who it affects
Enterprise customers evaluating Copilot and agent licensing alongside their E5 estate.
Your options
Buy E7 as a bundle, or keep E5 and add Copilot, Agent 365 and the Entra Suite separately and compare the two positions at renewal.
Availability date and the $99 per user per month list price come from secondary licensing analysts citing the Microsoft licensing news page; E7 pricing was not changed by the July 2026 update, but E5 packaging changes flow through to E7.
The last tranche of the Second Amendment to 23 NYCRR Part 500 took effect: MFA for all individuals accessing any information system of a covered entity, plus written policies and procedures for maintaining an asset inventory.
Who it affects
Covered entities licensed by the New York Department of Financial Services, unless they qualify for one of the limited exemptions.
Your options
Deploy MFA across all users and remote/third-party access paths, document an asset inventory process, and evidence both for the annual certification.
Windows 10 stopped receiving security updates, feature updates and technical support outside the Extended Security Updates programme.
Who it affects
Every organisation and consumer still running Windows 10 (all editions except the Enterprise LTSC releases, which have their own dates).
Your options
Upgrade eligible devices to Windows 11, replace hardware that fails the Windows 11 requirements, move users to Windows 365 or Azure Virtual Desktop, or enrol devices in ESU.
Skype for Business Server 2015 and 2019 end of support
What happens
Skype for Business Server 2015 and 2019 stopped receiving security fixes, stability fixes, time-zone updates and technical support.
Who it affects
Organisations still running on-premises Skype for Business Server, including hybrid deployments kept for enterprise voice.
Your options
Move users to Microsoft Teams (with Teams Phone or Direct Routing for voice), or upgrade to Skype for Business Server Subscription Edition, which shipped in Q3 2025.
Skype consumer was retired separately in May 2025.
Office 2016 and Office 2019 stopped receiving security updates, bug fixes and support; there is no extended support phase and no paid ESU for these releases.
Who it affects
Users of perpetual Office 2016 or Office 2019, including the matching Visio and Project versions.
Your options
Move to Microsoft 365 Apps, or to Office LTSC 2024 if a perpetual, disconnected build is required.
Date corroborated by several sources reporting the 14 October 2025 cluster; the Microsoft lifecycle page itself is egress-blocked from this container.
Exchange Server 2016 and Exchange Server 2019 stopped receiving public security updates, bug fixes and technical support; the October 2025 updates (Exchange 2019 CU15 SU5 / Exchange 2016 CU23 SU19) were the last public ones.
Who it affects
Anyone running on-premises Exchange 2016 or 2019, including hybrid organisations keeping a server only for recipient management.
Your options
Migrate mailboxes to Exchange Online, or in-place upgrade Exchange 2019 CU14/CU15 to Exchange Server Subscription Edition (SE), which needs an active subscription licence and follows the Modern Lifecycle Policy.
Exchange Online also applies transport enforcement against persistently vulnerable on-premises servers: from the second week of September 2026 the minimum accepted build for Exchange 2016/2019 servers using an OnPremises inbound connector rises to the October 2025 security updates, after which mail is throttled and then blocked. Microsoft has not published an exact calendar day for that change, so it is recorded here as a note rather than a dated entry.
The separate legacy multifactor authentication and self-service password reset policies in Microsoft Entra ID were retired and all authentication method management moved to the unified Authentication Methods policy.
Who it affects
Entra ID tenants that had never run the combined authentication methods policy migration.
Your options
Tenants that had not migrated were moved automatically; administrators should now manage every method (Authenticator, FIDO2/passkeys, TAP, certificate-based auth) in the Authentication Methods policy.
Candidate date of 30 September 2025 confirmed by multiple sources; no extension was found.
Azure Local (formerly Azure Stack HCI) version 22H2 stopped receiving updates, and from around 23 February 2026 Microsoft began degrading features on clusters still running it.
Who it affects
Organisations running Azure Stack HCI 22H2 clusters that have not upgraded to the 23H2 or 24H2 solution.
Your options
Upgrade the cluster to Azure Local 23H2 and then 24H2, or move the workloads to Azure or to new hardware.
Related: the Azure Local solution on the 23H2 OS (build 25398.xxxx) received its final monthly security and quality update on 31 October 2025 (release 11.2510), and support for the 23H2 OS outside the Azure Local solution ran to April 2026. Azure Local releases carry six months of support each, so the current supported baseline moves roughly every six months.
PCI DSS v4.x future-dated requirements became mandatory
What happens
The 51 future-dated requirements in PCI DSS v4.0/v4.0.1 stopped being best practice and became fully assessable, including 6.4.3 and 11.6.1 payment page script controls and 12.3.1 targeted risk analyses.
Who it affects
Every merchant and service provider that stores, processes or transmits cardholder data, including small merchants validating with a SAQ.
Your options
There is no further grace period; organisations either evidence the controls at their next assessment or work through their acquirer on a remediation plan.
Confirmed: there is no 2026 or 2027 PCI DSS deadline. The SAQ A published January 2025 took effect on the same 31 March 2025 date; it removed 6.4.3, 11.6.1 and 12.3.1 for SAQ A merchants but added an eligibility condition covering the whole website, not just the payment page. PCI DSS v5.0 is in development (RFC cycles closed December 2025 and July 2026) with no announced release date.
Dates are checked against the vendor’s or regulator’s own page, and the date of that check is printed on every entry. Microsoft moves lifecycle dates from time to time — where a date is not yet confirmed against a primary source it is tagged “date to confirm”. Spotted one that has moved, or one we’re missing? Tell usand we’ll correct it.