Managed ESU and Legacy Server Lifecycle Service
Managed ESU and Legacy Server Lifecycle Service is a monthly service for mid-size and enterprise estates that bought Extended Security Updates as a bridge and now need proof that the bridge is holding. For every legacy Windows Server and SQL Server in scope — Windows Server 2016 and 2012 R2, SQL Server 2016, on-premises through Azure Arc or running as Azure VMs — IT Partner delivers a monthly ESU and patch compliance report built from Azure Update Manager, checks Azure Arc agent and extension health, reconciles ESU licenses against the servers that still exist so Microsoft's per-core charges stop when a server goes, triages Microsoft Defender for Servers alerts on the legacy estate where you have it enabled, and runs a quarterly review of migration progress against the written exit plan until the last legacy server is retired. It costs $18 per server plus a $250 tenant fee per 30-day period, with no long-term contract. Microsoft's ESU meters and Azure charges are billed by Microsoft to your own Azure subscription and are not part of this fee. The migrations themselves, 24x7 security operations, and general server support are separate, named services — this one exists to keep the bridge safe, accounted for, and shrinking.
What this engagement is
Extended Security Updates were sold to you as time, and time is what they buy: security-only patches for a server whose operating system or database engine Microsoft has stopped supporting, while you finish the work of upgrading, migrating, or retiring it. Per Microsoft's product lifecycle, Windows Server 2012 and 2012 R2 ESU ends on 13 October 2026, with no further updates through any channel; Windows Server 2016 extended support ends on 12 January 2027, and ESU through Azure Arc bills from 13 January 2027 for up to three years, to January 2030; SQL Server 2016 extended support ended on 14 July 2026, with ESU available through 17 July 2029. Those dates are the whole point. An ESU bridge that nobody watches quietly turns into a permanent state: a patch cycle that fails on one server and is never noticed, an Arc agent that dropped offline in March, an ESU license still billing for cores that were decommissioned in April, and an exit plan whose target dates slide a quarter at a time. Meanwhile the people who actually ask about legacy servers — auditors, cyber-insurance underwriters, the board — do not want intent. They want evidence, dated and per server. This service is the evidence, produced monthly. The patch proof comes from Azure Update Manager, which assesses Arc-enabled and Azure machines for pending updates and records what was deployed: for every server in scope, the report shows the ESU and security updates Microsoft published that month, which installed, which are pending or failed, which machines are waiting on a reboot, and when each was last assessed — with every exception carrying a named owner and a reason rather than disappearing into an average. Underneath the patching sits Azure Arc, so the same cycle checks that the Connected Machine agent on each server is connected and on a version inside Microsoft's supported window, and that the extensions the bridge depends on — Update Manager, the ESU license link, SQL Server enabled by Azure Arc where SQL is in scope, Defender for Servers and monitoring agents where you run them — are healthy rather than silently failed. Then the money: ESU through Arc is billed monthly by Microsoft, per core and by edition, and the licenses do not shrink themselves when a server is retired. We reconcile provisioned cores against the servers that actually exist, decrement or deactivate licenses for machines that are gone, watch for the late-enrollment back-billing and the post-deactivation billing tail that Microsoft's terms describe, check the SQL Server ESU hourly meters against the instances still running, and hand you a one-page reconciliation of expected versus invoiced. Where you have Microsoft Defender for Servers on the legacy estate, we triage its alerts during business hours as part of the same cycle — legacy machines are the ones attackers look for first. Every quarter, the review turns from the bridge to the far bank. The exit plan lists each legacy server with its disposition — in-place upgrade, migration to Azure, rebuild on a current Windows Server or SQL Server release, or retirement — an owner, and a target date. The quarterly review measures what moved, what slipped and why, what the next ESU year will cost if a server is still there when it starts (Microsoft's ESU list price rises with each program year), and which dates are hard: nothing survives 13 October 2026 on Windows Server 2012 R2 with patches, and nothing on Windows Server 2016 is patched after 12 January 2027 without ESU. The migrations and upgrades themselves are separate, named engagements — Windows Server to Azure, VMware to Azure, the SQL Server paths to Azure SQL Managed Instance or a current SQL Server on an Azure VM — and the review is where they get scheduled instead of postponed. The service is priced per server plus a flat tenant fee per 30-day period, and the server count is reconciled every cycle, so the fee falls as the estate shrinks; a service that is doing its job ends when the last legacy server is gone. Microsoft's ESU meters, Update Manager, Defender, and log-ingestion charges are Microsoft's, billed to your own Azure subscription, and are never part of this fee. There is no long-term contract: stop any month, and everything the service produced — every report, the reconciliation ledger, the exit plan — stays yours.
Success criteria
What you receive
How the work unfolds
Least-privilege Azure access is granted through Azure Lighthouse or scoped role assignments you approve on the subscriptions and resource groups that hold the Arc resources, ESU licenses, and billing data. We reconcile the legacy inventory server by server, confirm Update Manager periodic assessment is on and schedules match your windows, verify every ESU license against Microsoft's edition and core rules, capture or draft the exit plan with a disposition per server, and agree the report format with its readers.
After each month's Microsoft release, Update Manager deployments run in your approved windows; we read the assessment and deployment history for every server, chase failures and reboot-pending machines with their owners, and produce the compliance report with exceptions named.
Agent connectivity, agent version, and extension health are checked and faults fixed or escalated. ESU cores and SQL ESU meters are reconciled to the servers and instances that exist; decrements and deactivations you approve are executed, and the expected-versus-invoiced page is delivered with the report.
Defender for Servers alerts on the legacy estate are triaged during business hours, dispositioned, and escalated to your incident process or MDR provider where warranted; the month's alert summary is appended to the report.
Every third cycle closes with the review: progress against each server's disposition and date, slips with reasons, the hard-date exposure, the ESU cost of anything still standing at the next program year, and the decisions needed from you — which is where the separate migration and upgrade engagements get scheduled.
When the last legacy server is retired, we confirm every ESU license is deactivated, deliver the final reconciliation and the completed exit plan, and the fee stops.
Prerequisites
Who does what
IT Partner
- Deliver the monthly ESU and patch compliance report on schedule, with every exception named and owned.
- Check Arc agent and extension health every cycle and fix or escalate faults inside the cycle.
- Reconcile ESU licenses and SQL ESU meters to the live estate, execute approved decrements and deactivations, and deliver the expected-versus-invoiced page.
- Keep Update Manager schedules aligned to your windows and chase failed and reboot-pending deployments with their owners.
- Triage Defender for Servers alerts on the legacy estate during business hours where the option is in scope, and escalate per the agreed path.
- Run the quarterly exit-plan review, issue deadline notices ahead of every Microsoft program boundary, and say plainly when a server's date has slipped past what the bridge can cover.
- Treat all collected data as confidential and delete it on request when the service ends.
Your team
- Approve the Azure access, maintenance windows, and ESU license changes, and keep a named contact current for approvals.
- Send the retirement signal when a server is decommissioned, and tell us early about migrations, rebuilds, and new legacy servers entering scope.
- Reboot or allow reboots of servers in the approved windows — a patch that is installed but waiting on a reboot is not protection.
- Provide billing visibility for the subscription that carries the ESU meters.
- Own the exit-plan decisions and the separate migration, upgrade, and retirement projects; we measure progress and schedule the work with you, you decide the dates.
- Own Microsoft's charges for ESU, Update Manager, Defender, and log ingestion on your subscription.
What's not included
Limitations & technical notes
Frequently asked questions
What is the Managed ESU and Legacy Server Lifecycle Service?
A monthly service that keeps end-of-support Windows Server and SQL Server machines on an ESU bridge safe and accounted for until they are retired: a per-server ESU and patch compliance report from Azure Update Manager, Azure Arc agent and extension health checks, reconciliation of ESU licenses and SQL ESU meters so Microsoft's charges stop when a server goes, optional business-hours triage of Defender for Servers alerts, and a quarterly review of migration progress against the exit plan. It is $18 per server plus a $250 tenant fee per 30-day period, with no long-term contract, and Microsoft's ESU and Azure meters are billed to your own subscription outside this fee.
Which servers does it cover, and what counts as legacy?
Windows Server 2016 and 2012 R2, and SQL Server 2016 instances, whether on-premises or in another cloud through Azure Arc or running as Azure VMs. Legacy means a version that has passed, or is about to pass, Microsoft's end of extended support and is being kept alive on Extended Security Updates: per Microsoft's product lifecycle, Windows Server 2012 R2 ESU ends 13 October 2026, Windows Server 2016 extended support ends 12 January 2027 with ESU through Arc running to January 2030, and SQL Server 2016 ESU runs to 17 July 2029. A current-version server with a broken patch process is a support problem, not a lifecycle one, and belongs in a different service.
What is in the monthly report, and will it satisfy our auditor or cyber-insurer?
Per server: the ESU and security updates Microsoft published that month, what installed, what is pending or failed, what is waiting on a reboot, the last Update Manager assessment time, Arc agent and extension health, and every exception with a named owner and reason — plus the ESU license reconciliation and, where enabled, the Defender alert summary. It is written for the person who has to attach it to an insurance renewal or hand it to an auditor, and it documents what was not fixed as honestly as what was, because that is what those readers respect. We do not promise any specific insurer's or auditor's verdict; those are their decisions.
What does the ESU billing reconciliation actually catch?
ESU through Azure Arc is billed monthly by Microsoft per provisioned core and edition, and the licenses do not shrink themselves: Microsoft's guidance is explicit that adjusting them is the customer's responsibility. So the reconciliation compares provisioned cores to the servers that exist and finds licenses still billing for machines that were decommissioned, over-provisioned core counts, edition or core-type mismatches that cannot be fixed after creation, SQL ESU meters still running for instances that migrated, and Arc ESU licenses provisioned for Azure VMs that already receive ESU at no additional cost. Each finding becomes a decrement or deactivation you approve, executed in the cycle, with Microsoft's up-to-five-day post-deactivation billing tail noted so the next invoice is not a surprise.
We still have Windows Server 2012 R2 — what happens after 13 October 2026?
Per Microsoft's product lifecycle, that is the end of the 2012 and 2012 R2 ESU program, and there is no fourth year to buy through any channel. Until then the service proves the ESU patches are landing; after it, there are no updates to prove, and any 2012 R2 server still in scope is carried for isolation and retirement tracking with a report line that says exactly that. The quarterly review treats it as a hard date, and a server whose exit slips past it needs containment work that is scoped separately — we say so in writing before the date, not after.
Our estate is mostly Windows Server 2016 — when does ESU start and what does it need?
Windows Server 2016 extended support ends 12 January 2027 per Microsoft's product lifecycle, and Microsoft states that ESU enabled by Azure Arc bills from 13 January 2027 for up to three years. To use it, each server must be connected to Azure Arc and linked to an ESU license of the matching edition with Microsoft's core minimums, and Microsoft's provisioning guidance at the time of writing lists Software Assurance or an equivalent server subscription as a requirement for on-premises workloads. Licenses provisioned after the date carry back-billing to it. The enrollment itself is a one-time engagement; this service starts once the servers are enrolled — or beforehand, so the baseline and exit plan are in place before the billing clock starts.
How is SQL Server 2016 ESU billed, and how do you reconcile it?
Through SQL Server enabled by Azure Arc, Microsoft bills SQL ESU on an hourly per-core meter with its own minimums, available to licenses covered by Software Assurance, a SQL Server subscription, or pay-as-you-go through Arc, and running to 17 July 2029 per Microsoft's lifecycle. Subscribing after an ESU year starts triggers bill-back to the start of the year; terminating the subscription when an instance is migrated stops the meter. Each cycle we reconcile the running instances and their core counts against the meters, and the quarterly review carries the cost of any instance still in place at the next ESU year — the moment when moving it to a current SQL Server or to Azure SQL usually starts paying for itself.
Do you onboard servers to Azure Arc or enroll them in ESU as part of this?
No — both are one-time projects that finish before the monthly rhythm starts. Arc onboarding is the Azure Arc Hybrid Server Management Implementation, and ESU enrollment for Windows Server and SQL Server is scoped separately. Keeping them out of a per-server monthly fee is deliberate: an enrollment project has a defined end, and folding it into a subscription hides its cost. What this service does do is confirm every month that the enrollment is still intact — licenses linked, agents connected, extensions healthy.
What does the Arc agent and extension health check cover?
Whether each server's Connected Machine agent is connected rather than disconnected or expired, whether the agent version is inside Microsoft's supported window, and whether the extensions the bridge depends on are provisioned and healthy: Azure Update Manager, the ESU license link, SQL Server enabled by Azure Arc where SQL is in scope, and Defender for Servers and monitoring agents where you run them. Faults we can fix from the Azure side are fixed in the cycle; faults on the server itself — broken WMI, a proxy change, a firewall rule — are escalated to their owner as a named exception, because a disconnected agent is a server nobody is patching.
What is the optional Defender for Servers alert triage, and how is it different from MDR?
Where you have Microsoft Defender for Servers enabled on the legacy estate through Defender for Cloud, we review the alerts it raises on those machines during business hours, classify them, give first-response guidance, and escalate to your incident process or MDR provider when an alert warrants it, with the month's summary in the report. It is included for in-scope servers when you turn the option on. It is not around-the-clock monitoring, containment, or forensics — that is Multi-Platform Managed Detection and Response, and the two are complementary: MDR watches for the attack, this service shrinks the number of unpatched legacy targets the attack needs.
What happens at the quarterly exit-plan review?
Every legacy server carries a disposition — in-place upgrade to a current Windows Server or SQL Server release, migration to Azure, rebuild, or retirement — with an owner and a target date. The review measures what moved since last quarter, what slipped and why, the exposure against the hard Microsoft dates, and what each server still standing at the next ESU program year will cost, since Microsoft's ESU price rises each year. Its output is decisions: which migration or upgrade engagements to schedule next, which retirements to approve, and which dates to move honestly rather than silently. The projects themselves are separate, quoted work; the review is what keeps them from being postponed a quarter at a time.
What access do you need, and is it read-only?
Reading is read-only: Arc resources, Update Manager assessment and deployment data, ESU license resources, and Cost Management for the subscription that carries the meters. Acting needs two narrow change rights — Update Manager schedules and maintenance configurations, and the ESU license resources for the decrements and deactivations you approve. We request it through Azure Lighthouse or scoped role assignments you approve on the relevant subscriptions and resource groups, consistent with our published least-privilege access policy, and never standing Owner.
Our legacy servers are Azure VMs and get ESU free — do we still need this?
Microsoft provides ESU at no additional license cost for Windows Server and SQL Server running in Azure, which removes the billing problem but not the other three: the patches still have to land and be proven, the exit plan still has to move, and the auditor still asks. For Azure-VM estates the service delivers the patch proof, health, and quarterly review, and the reconciliation's job is simply to confirm no Arc ESU license was provisioned for a machine that never needed one. If the estate is small and the exit is weeks away, we will tell you the service is not worth starting.
How does billing work, and can we stop?
Per in-scope server plus the tenant fee, invoiced per 30-day period, with the server count reconciled every cycle — so the fee falls as servers retire, and it stops when the last one is gone. Large estates are quoted per estate in writing. There is no long-term contract: stop any month, and all we ask is payment of previously approved invoices. Every report, the reconciliation ledger, and the exit plan stay yours.
Can you do the migrations too?
Yes, as separate engagements, which is why this page does not price them: Windows Server migration to Azure, VMware to Azure, the SQL Server paths to Azure SQL Managed Instance or a current SQL Server on an Azure VM, and Azure Migrate discovery where the disposition is undecided. The quarterly review is where they get scheduled. Keeping the migration out of the monthly fee keeps the monthly fee honest, and keeps us from having an incentive to let the bridge last longer than it should.