First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/Managed ESU and Legacy Server Lifecycle Service
Managed Services

Managed ESU and Legacy Server Lifecycle Service

Managed ESU and Legacy Server Lifecycle Service is a monthly service for mid-size and enterprise estates that bought Extended Security Updates as a bridge and now need proof that the bridge is holding. For every legacy Windows Server and SQL Server in scope — Windows Server 2016 and 2012 R2, SQL Server 2016, on-premises through Azure Arc or running as Azure VMs — IT Partner delivers a monthly ESU and patch compliance report built from Azure Update Manager, checks Azure Arc agent and extension health, reconciles ESU licenses against the servers that still exist so Microsoft's per-core charges stop when a server goes, triages Microsoft Defender for Servers alerts on the legacy estate where you have it enabled, and runs a quarterly review of migration progress against the written exit plan until the last legacy server is retired. It costs $18 per server plus a $250 tenant fee per 30-day period, with no long-term contract. Microsoft's ESU meters and Azure charges are billed by Microsoft to your own Azure subscription and are not part of this fee. The migrations themselves, 24x7 security operations, and general server support are separate, named services — this one exists to keep the bridge safe, accounted for, and shrinking.

Timeline 30 daysService owner Roman SotnikWindows ServerSQL ServerAzure Arc

What this engagement is

Extended Security Updates were sold to you as time, and time is what they buy: security-only patches for a server whose operating system or database engine Microsoft has stopped supporting, while you finish the work of upgrading, migrating, or retiring it. Per Microsoft's product lifecycle, Windows Server 2012 and 2012 R2 ESU ends on 13 October 2026, with no further updates through any channel; Windows Server 2016 extended support ends on 12 January 2027, and ESU through Azure Arc bills from 13 January 2027 for up to three years, to January 2030; SQL Server 2016 extended support ended on 14 July 2026, with ESU available through 17 July 2029. Those dates are the whole point. An ESU bridge that nobody watches quietly turns into a permanent state: a patch cycle that fails on one server and is never noticed, an Arc agent that dropped offline in March, an ESU license still billing for cores that were decommissioned in April, and an exit plan whose target dates slide a quarter at a time. Meanwhile the people who actually ask about legacy servers — auditors, cyber-insurance underwriters, the board — do not want intent. They want evidence, dated and per server. This service is the evidence, produced monthly. The patch proof comes from Azure Update Manager, which assesses Arc-enabled and Azure machines for pending updates and records what was deployed: for every server in scope, the report shows the ESU and security updates Microsoft published that month, which installed, which are pending or failed, which machines are waiting on a reboot, and when each was last assessed — with every exception carrying a named owner and a reason rather than disappearing into an average. Underneath the patching sits Azure Arc, so the same cycle checks that the Connected Machine agent on each server is connected and on a version inside Microsoft's supported window, and that the extensions the bridge depends on — Update Manager, the ESU license link, SQL Server enabled by Azure Arc where SQL is in scope, Defender for Servers and monitoring agents where you run them — are healthy rather than silently failed. Then the money: ESU through Arc is billed monthly by Microsoft, per core and by edition, and the licenses do not shrink themselves when a server is retired. We reconcile provisioned cores against the servers that actually exist, decrement or deactivate licenses for machines that are gone, watch for the late-enrollment back-billing and the post-deactivation billing tail that Microsoft's terms describe, check the SQL Server ESU hourly meters against the instances still running, and hand you a one-page reconciliation of expected versus invoiced. Where you have Microsoft Defender for Servers on the legacy estate, we triage its alerts during business hours as part of the same cycle — legacy machines are the ones attackers look for first. Every quarter, the review turns from the bridge to the far bank. The exit plan lists each legacy server with its disposition — in-place upgrade, migration to Azure, rebuild on a current Windows Server or SQL Server release, or retirement — an owner, and a target date. The quarterly review measures what moved, what slipped and why, what the next ESU year will cost if a server is still there when it starts (Microsoft's ESU list price rises with each program year), and which dates are hard: nothing survives 13 October 2026 on Windows Server 2012 R2 with patches, and nothing on Windows Server 2016 is patched after 12 January 2027 without ESU. The migrations and upgrades themselves are separate, named engagements — Windows Server to Azure, VMware to Azure, the SQL Server paths to Azure SQL Managed Instance or a current SQL Server on an Azure VM — and the review is where they get scheduled instead of postponed. The service is priced per server plus a flat tenant fee per 30-day period, and the server count is reconciled every cycle, so the fee falls as the estate shrinks; a service that is doing its job ends when the last legacy server is gone. Microsoft's ESU meters, Update Manager, Defender, and log-ingestion charges are Microsoft's, billed to your own Azure subscription, and are never part of this fee. There is no long-term contract: stop any month, and everything the service produced — every report, the reconciliation ledger, the exit plan — stays yours.

Success criteria

01Every 30-day period closes with a delivered ESU and patch compliance report covering each in-scope server: updates published, installed, pending, failed, reboot-pending, last assessment time, and every exception with a named owner and reason.
02Arc agent and extension health is verified every cycle: disconnected agents, unsupported agent versions, and failed extensions are named in the report within the cycle in which they appear, with the fix applied or assigned.
03ESU licenses provisioned through Azure Arc reconcile every cycle to the servers that exist; licenses for retired servers are decremented or deactivated in the same cycle the retirement is confirmed, and the expected-versus-invoiced reconciliation is delivered with the report.
04Where SQL Server 2016 ESU is in scope, the hourly ESU meters reconcile to the SQL instances actually running, and subscriptions are terminated when an instance is migrated or retired.
05Where Defender for Servers is enabled on the legacy estate, alerts raised during the cycle are triaged during business hours with a documented disposition and escalation where warranted.
06The exit plan is current at every quarterly review: every legacy server carries a disposition, an owner, and a target date, and the review records what moved, what slipped, and the ESU cost of anything still in place at the next program year.
07When an auditor or cyber-insurer asks for evidence that end-of-support servers are patched and being retired, the monthly reports and the exit plan answer without preparation.
08The service ends cleanly: when the last legacy server is retired, ESU licenses are confirmed deactivated, the final reconciliation is delivered, and the fee stops.

What you receive

Onboarding baseline (first 30-day period): a reconciled inventory of every legacy server in scope — operating system and edition, SQL Server version where present, physical or virtual cores, Arc connection state, ESU license or Azure-VM coverage, Update Manager assessment state, and Defender for Servers coverage — plus the report template agreed with the people who will read it.
Monthly ESU and patch compliance report built from Azure Update Manager assessment and deployment history: per-server status for the ESU and security updates Microsoft published that month, exceptions with owner and reason, and a rolling compliance trend, formatted for auditors, underwriters, and leadership.
Monthly Azure Arc health check: Connected Machine agent status and version on every server, extension state for Update Manager, the ESU license link, SQL Server enabled by Azure Arc, Defender for Servers and monitoring agents where present, with remediation of agent and extension faults inside the cycle or a named escalation where the cause is on the server.
Monthly ESU license and billing reconciliation: cores provisioned per Windows Server ESU license against the servers that exist, SQL Server ESU hourly meters against running instances, decrement or deactivation actions for retired servers executed on your approval, and a one-page expected-versus-invoiced reconciliation against your Azure billing.
Patch cycle coordination: Update Manager maintenance configurations and schedules kept aligned to your approved windows, failed deployments re-run or dispositioned, and reboot-pending servers surfaced to their owners — the mechanism that turns a report of failures into a report of fixes.
Optional Defender for Servers alert triage on the legacy estate, during business hours: classification, first-response guidance, and escalation to your incident process or your MDR provider, documented in the monthly report.
Quarterly exit-plan review: the per-server disposition register (upgrade, migrate, rebuild, retire) with owners and target dates, progress since the last review, slipped items with reasons, the hard-date exposure (13 October 2026, 12 January 2027, 17 July 2029), and the ESU cost forecast for servers still in place at the next program year.
Deadline watch: written notice ahead of each Microsoft program boundary that affects a server in scope — the close of Windows Server 2012 R2 ESU, the start of Windows Server 2016 ESU billing, each ESU year rollover — with the action required from you.
Offboarding of retired servers: ESU license changes, Arc resource cleanup, and removal from the report scope in the same cycle a retirement is confirmed, so the invoice and the inventory stop disagreeing.
Closeout when the estate reaches zero: final reconciliation, confirmation that no ESU license remains active, and a handover of every report and the completed exit plan.

How the work unfolds

1. Onboarding and baseline (first 30-day period)

Least-privilege Azure access is granted through Azure Lighthouse or scoped role assignments you approve on the subscriptions and resource groups that hold the Arc resources, ESU licenses, and billing data. We reconcile the legacy inventory server by server, confirm Update Manager periodic assessment is on and schedules match your windows, verify every ESU license against Microsoft's edition and core rules, capture or draft the exit plan with a disposition per server, and agree the report format with its readers.

2. Monthly cycle — patch proof

After each month's Microsoft release, Update Manager deployments run in your approved windows; we read the assessment and deployment history for every server, chase failures and reboot-pending machines with their owners, and produce the compliance report with exceptions named.

3. Monthly cycle — Arc health and billing reconciliation

Agent connectivity, agent version, and extension health are checked and faults fixed or escalated. ESU cores and SQL ESU meters are reconciled to the servers and instances that exist; decrements and deactivations you approve are executed, and the expected-versus-invoiced page is delivered with the report.

4. Monthly cycle — Defender triage (where enabled)

Defender for Servers alerts on the legacy estate are triaged during business hours, dispositioned, and escalated to your incident process or MDR provider where warranted; the month's alert summary is appended to the report.

5. Quarterly exit-plan review

Every third cycle closes with the review: progress against each server's disposition and date, slips with reasons, the hard-date exposure, the ESU cost of anything still standing at the next program year, and the decisions needed from you — which is where the separate migration and upgrade engagements get scheduled.

6. Closeout

When the last legacy server is retired, we confirm every ESU license is deactivated, deliver the final reconciliation and the completed exit plan, and the fee stops.

Prerequisites

A legacy server estate of mid-size to enterprise scale — Windows Server 2016 or 2012 R2, SQL Server 2016, or a mix — already connected to Azure Arc (or running as Azure VMs) and already enrolled in ESU where the deadline has passed. Arc onboarding is the one-time Azure Arc Hybrid Server Management Implementation; ESU enrollment is scoped separately and can run immediately before this service starts.
Least-privilege Azure access you approve — through Azure Lighthouse or scoped role assignments — with read access to the Arc resources, Update Manager data, and Cost Management for the subscription carrying the ESU meters, and change rights limited to Update Manager schedules and ESU license resources for the actions you approve. Never standing Owner.
Azure Update Manager in use on the in-scope servers with periodic assessment enabled and patch orchestration under customer-managed schedules; where it is not yet configured, the onboarding period sets it up and the WSUS-to-Update-Manager transition is scoped separately if a WSUS estate is still in the path.
Billing visibility for the Azure subscription that carries the ESU and Update Manager meters — invoices or Cost Management access — so the reconciliation compares expected charges with what Microsoft actually billed.
A written exit plan, even a rough one, with a disposition per server; if none exists, the onboarding period drafts it from the inventory and your decisions, and our Azure Migrate discovery and assessment supplies the dependency and sizing evidence where a migration path is undecided.
A named contact authorized to approve maintenance windows, ESU license decrements, and server retirements, plus a defined retirement signal (ticket or change record) so licenses are released on fact, not discovered on the invoice.
For the optional Defender triage: Microsoft Defender for Servers enabled on the legacy estate through Defender for Cloud, with an agreed escalation path to your incident process or MDR provider.
Acknowledgment that ESU, Update Manager, Defender, and log-ingestion charges are Microsoft's, billed to your subscription under Microsoft's terms — including that Windows Server 2016 ESU through Arc lists Software Assurance or an equivalent server subscription as a requirement for on-premises workloads in Microsoft's provisioning guidance at the time of writing.

Who does what

IT Partner

  • Deliver the monthly ESU and patch compliance report on schedule, with every exception named and owned.
  • Check Arc agent and extension health every cycle and fix or escalate faults inside the cycle.
  • Reconcile ESU licenses and SQL ESU meters to the live estate, execute approved decrements and deactivations, and deliver the expected-versus-invoiced page.
  • Keep Update Manager schedules aligned to your windows and chase failed and reboot-pending deployments with their owners.
  • Triage Defender for Servers alerts on the legacy estate during business hours where the option is in scope, and escalate per the agreed path.
  • Run the quarterly exit-plan review, issue deadline notices ahead of every Microsoft program boundary, and say plainly when a server's date has slipped past what the bridge can cover.
  • Treat all collected data as confidential and delete it on request when the service ends.

Your team

  • Approve the Azure access, maintenance windows, and ESU license changes, and keep a named contact current for approvals.
  • Send the retirement signal when a server is decommissioned, and tell us early about migrations, rebuilds, and new legacy servers entering scope.
  • Reboot or allow reboots of servers in the approved windows — a patch that is installed but waiting on a reboot is not protection.
  • Provide billing visibility for the subscription that carries the ESU meters.
  • Own the exit-plan decisions and the separate migration, upgrade, and retirement projects; we measure progress and schedule the work with you, you decide the dates.
  • Own Microsoft's charges for ESU, Update Manager, Defender, and log ingestion on your subscription.

What's not included

The migrations, upgrades, and rebuilds themselves. Moving a server is a named project — Windows Server to Azure, VMware to Azure, SQL Server to Azure SQL Managed Instance, SQL Server to an Azure VM — quoted separately in writing. This service tracks the exit plan; it does not execute it.
Microsoft's charges. ESU through Azure Arc, SQL Server ESU hourly meters, Azure Update Manager where Microsoft meters it, Defender for Servers plans, and log ingestion are billed by Microsoft to your Azure subscription under Microsoft's terms and are never part of this fee. We reconcile them; we do not pay them.
Azure Arc onboarding and initial ESU enrollment. Connecting servers to Arc is the one-time Azure Arc Hybrid Server Management Implementation; provisioning and linking ESU licenses for Windows Server and subscribing SQL Server instances to ESU are separately scoped one-time engagements that finish before this service starts.
24x7 security operations and incident response. The optional Defender triage is business-hours classification and escalation; around-the-clock detection and response is Multi-Platform Managed Detection and Response.
General server administration and break-fix — capacity, application issues, hardware faults, backup operation, and everything else a server needs beyond patch proof and lifecycle tracking — is IT Infrastructure Monitoring and Support, and broader Azure estate monitoring is Azure Resource Monitoring and Maintenance.
Application and third-party patching, firmware, and hardware. The report proves Microsoft's ESU and security updates; line-of-business applications, database application code, drivers, and firmware on legacy hosts are outside it and named as such when they block a disposition.
Servers Arc cannot reach. Air-gapped segments and operating systems outside the Connected Machine agent's support matrix cannot be assessed by Update Manager; they are listed in the inventory with their disposition, and any containment work for them is scoped separately.
Exchange Server. Exchange 2016 and 2019 left support on 14 October 2025 per Microsoft's product lifecycle, with Exchange Server SE as the supported successor and no ESU program to bridge with; retiring an on-premises Exchange server is Exchange Server Decommissioning, and Exchange SE operations are a separate managed service.
Windows 10 client ESU — a different program on a different fleet, handled inside Windows 11 Migration and Windows 10 ESU Transition.
ESU purchased through Volume Licensing. Annual ESU bought under an agreement rather than through Arc is recorded in the inventory and its keys tracked, but the purchase, renewal, and agreement negotiation belong to Microsoft Volume Licensing consulting.
Guaranteed audit or insurance outcomes. The reports are built for auditors and underwriters and we do not promise any specific verdict; those decisions belong to the third parties making them.

Limitations & technical notes

!ESU is security-only. Per Microsoft, Extended Security Updates deliver critical and important security updates and no new features, non-security fixes, or general support requests; the monthly report proves those updates landed and nothing more. A server on ESU is safer than one without, and still a server that has to go.
!After 13 October 2026 there are no Windows Server 2012 or 2012 R2 updates to prove, through any channel. Servers on that version still in scope after the date are carried in the inventory and the exit plan for isolation and retirement tracking only, and the report says so plainly rather than showing a green tick.
!ESU billing rules are Microsoft's, stated here per Microsoft's Azure Arc guidance at the time of writing: licenses are billed monthly by cores and edition; decrementing, deactivating, or deleting a license keeps billing for up to five more calendar days; licenses provisioned after the end-of-support date carry back-billing to that date as a separate invoice line; license edition and core type cannot be changed once created; and Windows Server 2016 ESU through Arc lists Software Assurance or an equivalent server subscription as a requirement for on-premises workloads. Reconciliation prevents waste going forward; it cannot rewrite an invoice Microsoft has already issued.
!SQL Server 2016 ESU through Azure Arc runs on an hourly meter with Microsoft's per-core minimums, is available to licenses with Software Assurance, a SQL Server subscription, or pay-as-you-go through Arc, and is not available to perpetual licenses without Software Assurance. Enrolling after the ESU year starts triggers bill-back to the start of that year. We state these as Microsoft's terms at the time of writing and confirm them against Microsoft's documentation during onboarding.
!Windows Server and SQL Server running as Azure VMs receive ESU at no additional license cost per Microsoft's lifecycle policy; for those machines the service delivers patch proof, health, and exit tracking, and the billing reconciliation confirms no Arc ESU license was provisioned for them by mistake.
!Visibility equals Arc and Update Manager visibility. A server whose agent is disconnected reports nothing until it is reconnected, which is why agent health is checked before the patch report is written, and why a disconnected agent is an exception with an owner rather than a blank line.
!Patching throughput depends on your maintenance windows and reboots. Update Manager installs inside the windows you approve; a server whose owner never releases it for a reboot appears in the report as reboot-pending every month until they do.
!Defender triage covers alerts on the legacy estate during IT Partner's business hours and is classification, first-response guidance, and escalation — not containment, forensics, or around-the-clock monitoring.
!Billing is per in-scope server per 30-day period plus the tenant fee, reconciled at each cycle as servers retire or enter scope; large estates are quoted per estate in writing. Requests through the service intake receive first response within IT Partner's published SLA of 1 business hour, with monthly support statistics published openly since December 2023.

Frequently asked questions

What is the Managed ESU and Legacy Server Lifecycle Service?

A monthly service that keeps end-of-support Windows Server and SQL Server machines on an ESU bridge safe and accounted for until they are retired: a per-server ESU and patch compliance report from Azure Update Manager, Azure Arc agent and extension health checks, reconciliation of ESU licenses and SQL ESU meters so Microsoft's charges stop when a server goes, optional business-hours triage of Defender for Servers alerts, and a quarterly review of migration progress against the exit plan. It is $18 per server plus a $250 tenant fee per 30-day period, with no long-term contract, and Microsoft's ESU and Azure meters are billed to your own subscription outside this fee.

Which servers does it cover, and what counts as legacy?

Windows Server 2016 and 2012 R2, and SQL Server 2016 instances, whether on-premises or in another cloud through Azure Arc or running as Azure VMs. Legacy means a version that has passed, or is about to pass, Microsoft's end of extended support and is being kept alive on Extended Security Updates: per Microsoft's product lifecycle, Windows Server 2012 R2 ESU ends 13 October 2026, Windows Server 2016 extended support ends 12 January 2027 with ESU through Arc running to January 2030, and SQL Server 2016 ESU runs to 17 July 2029. A current-version server with a broken patch process is a support problem, not a lifecycle one, and belongs in a different service.

What is in the monthly report, and will it satisfy our auditor or cyber-insurer?

Per server: the ESU and security updates Microsoft published that month, what installed, what is pending or failed, what is waiting on a reboot, the last Update Manager assessment time, Arc agent and extension health, and every exception with a named owner and reason — plus the ESU license reconciliation and, where enabled, the Defender alert summary. It is written for the person who has to attach it to an insurance renewal or hand it to an auditor, and it documents what was not fixed as honestly as what was, because that is what those readers respect. We do not promise any specific insurer's or auditor's verdict; those are their decisions.

What does the ESU billing reconciliation actually catch?

ESU through Azure Arc is billed monthly by Microsoft per provisioned core and edition, and the licenses do not shrink themselves: Microsoft's guidance is explicit that adjusting them is the customer's responsibility. So the reconciliation compares provisioned cores to the servers that exist and finds licenses still billing for machines that were decommissioned, over-provisioned core counts, edition or core-type mismatches that cannot be fixed after creation, SQL ESU meters still running for instances that migrated, and Arc ESU licenses provisioned for Azure VMs that already receive ESU at no additional cost. Each finding becomes a decrement or deactivation you approve, executed in the cycle, with Microsoft's up-to-five-day post-deactivation billing tail noted so the next invoice is not a surprise.

We still have Windows Server 2012 R2 — what happens after 13 October 2026?

Per Microsoft's product lifecycle, that is the end of the 2012 and 2012 R2 ESU program, and there is no fourth year to buy through any channel. Until then the service proves the ESU patches are landing; after it, there are no updates to prove, and any 2012 R2 server still in scope is carried for isolation and retirement tracking with a report line that says exactly that. The quarterly review treats it as a hard date, and a server whose exit slips past it needs containment work that is scoped separately — we say so in writing before the date, not after.

Our estate is mostly Windows Server 2016 — when does ESU start and what does it need?

Windows Server 2016 extended support ends 12 January 2027 per Microsoft's product lifecycle, and Microsoft states that ESU enabled by Azure Arc bills from 13 January 2027 for up to three years. To use it, each server must be connected to Azure Arc and linked to an ESU license of the matching edition with Microsoft's core minimums, and Microsoft's provisioning guidance at the time of writing lists Software Assurance or an equivalent server subscription as a requirement for on-premises workloads. Licenses provisioned after the date carry back-billing to it. The enrollment itself is a one-time engagement; this service starts once the servers are enrolled — or beforehand, so the baseline and exit plan are in place before the billing clock starts.

How is SQL Server 2016 ESU billed, and how do you reconcile it?

Through SQL Server enabled by Azure Arc, Microsoft bills SQL ESU on an hourly per-core meter with its own minimums, available to licenses covered by Software Assurance, a SQL Server subscription, or pay-as-you-go through Arc, and running to 17 July 2029 per Microsoft's lifecycle. Subscribing after an ESU year starts triggers bill-back to the start of the year; terminating the subscription when an instance is migrated stops the meter. Each cycle we reconcile the running instances and their core counts against the meters, and the quarterly review carries the cost of any instance still in place at the next ESU year — the moment when moving it to a current SQL Server or to Azure SQL usually starts paying for itself.

Do you onboard servers to Azure Arc or enroll them in ESU as part of this?

No — both are one-time projects that finish before the monthly rhythm starts. Arc onboarding is the Azure Arc Hybrid Server Management Implementation, and ESU enrollment for Windows Server and SQL Server is scoped separately. Keeping them out of a per-server monthly fee is deliberate: an enrollment project has a defined end, and folding it into a subscription hides its cost. What this service does do is confirm every month that the enrollment is still intact — licenses linked, agents connected, extensions healthy.

What does the Arc agent and extension health check cover?

Whether each server's Connected Machine agent is connected rather than disconnected or expired, whether the agent version is inside Microsoft's supported window, and whether the extensions the bridge depends on are provisioned and healthy: Azure Update Manager, the ESU license link, SQL Server enabled by Azure Arc where SQL is in scope, and Defender for Servers and monitoring agents where you run them. Faults we can fix from the Azure side are fixed in the cycle; faults on the server itself — broken WMI, a proxy change, a firewall rule — are escalated to their owner as a named exception, because a disconnected agent is a server nobody is patching.

What is the optional Defender for Servers alert triage, and how is it different from MDR?

Where you have Microsoft Defender for Servers enabled on the legacy estate through Defender for Cloud, we review the alerts it raises on those machines during business hours, classify them, give first-response guidance, and escalate to your incident process or MDR provider when an alert warrants it, with the month's summary in the report. It is included for in-scope servers when you turn the option on. It is not around-the-clock monitoring, containment, or forensics — that is Multi-Platform Managed Detection and Response, and the two are complementary: MDR watches for the attack, this service shrinks the number of unpatched legacy targets the attack needs.

What happens at the quarterly exit-plan review?

Every legacy server carries a disposition — in-place upgrade to a current Windows Server or SQL Server release, migration to Azure, rebuild, or retirement — with an owner and a target date. The review measures what moved since last quarter, what slipped and why, the exposure against the hard Microsoft dates, and what each server still standing at the next ESU program year will cost, since Microsoft's ESU price rises each year. Its output is decisions: which migration or upgrade engagements to schedule next, which retirements to approve, and which dates to move honestly rather than silently. The projects themselves are separate, quoted work; the review is what keeps them from being postponed a quarter at a time.

What access do you need, and is it read-only?

Reading is read-only: Arc resources, Update Manager assessment and deployment data, ESU license resources, and Cost Management for the subscription that carries the meters. Acting needs two narrow change rights — Update Manager schedules and maintenance configurations, and the ESU license resources for the decrements and deactivations you approve. We request it through Azure Lighthouse or scoped role assignments you approve on the relevant subscriptions and resource groups, consistent with our published least-privilege access policy, and never standing Owner.

Our legacy servers are Azure VMs and get ESU free — do we still need this?

Microsoft provides ESU at no additional license cost for Windows Server and SQL Server running in Azure, which removes the billing problem but not the other three: the patches still have to land and be proven, the exit plan still has to move, and the auditor still asks. For Azure-VM estates the service delivers the patch proof, health, and quarterly review, and the reconciliation's job is simply to confirm no Arc ESU license was provisioned for a machine that never needed one. If the estate is small and the exit is weeks away, we will tell you the service is not worth starting.

How does billing work, and can we stop?

Per in-scope server plus the tenant fee, invoiced per 30-day period, with the server count reconciled every cycle — so the fee falls as servers retire, and it stops when the last one is gone. Large estates are quoted per estate in writing. There is no long-term contract: stop any month, and all we ask is payment of previously approved invoices. Every report, the reconciliation ledger, and the exit plan stay yours.

Can you do the migrations too?

Yes, as separate engagements, which is why this page does not price them: Windows Server migration to Azure, VMware to Azure, the SQL Server paths to Azure SQL Managed Instance or a current SQL Server on an Azure VM, and Azure Migrate discovery where the disposition is undecided. The quarterly review is where they get scheduled. Keeping the migration out of the monthly fee keeps the monthly fee honest, and keeps us from having an incentive to let the bridge last longer than it should.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$18 per server + $250 tenant fee
30 days
Start ESU management