SQL Server 2016 Extended Security Updates (ESU) Enrollment through Azure Arc
SQL Server 2016 left extended support on 14 July 2026 per Microsoft's product lifecycle, and every instance still running it has received no security updates since — unless it is enrolled in Extended Security Updates (ESU). IT Partner enrolls your SQL Server 2016 and 2014 hosts in ESU through Azure Arc in one week: we connect each host with the Azure Connected Machine agent and the Azure extension for SQL Server, set the license type that makes it ESU-eligible, activate the ESU subscription, confirm the update channel can deliver, and hand over an instance inventory with an exit route and exit date for every instance. Pricing is an estimate at $95 per SQL Server host plus a $1,450 tenant fee, confirmed in writing once the host list is agreed; large estates are quoted per estate. The ESU itself is Microsoft's metered charge — billed per core, invoiced monthly to your own Azure subscription, cancellable the day an instance is migrated — and is not part of our fee. This service is the bridge, not the destination: upgrades and migrations are separate engagements, linked below.
What this engagement is
The deadline is behind you. SQL Server 2016 reached the end of extended support on 14 July 2026 per Microsoft's product lifecycle, and SQL Server 2014 did so on 9 July 2024. From those dates Microsoft ships no security fixes for either version except through Extended Security Updates — a paid program that delivers fixes for vulnerabilities Microsoft rates Critical, and nothing else: no new features, no non-security hotfixes, no support incidents. ESU for SQL Server 2016 runs through 17 July 2029; for SQL Server 2014, through 12 July 2027. If you are reading this with three, thirty, or three hundred instances still on 2016 and no realistic way to move them all this quarter, ESU is the honest bridge — and this engagement is how we put you on it in a week. There are two ways to buy SQL Server ESU. Through Volume Licensing you buy it annually, in advance, for licenses with active Software Assurance, and you pay for the whole year whether or not the instance is migrated in month four. Through Azure Arc you subscribe per host: the Azure Connected Machine agent and the Azure extension for SQL Server register each host and its instances in your Azure subscription, the ESU subscription is switched on per host, Microsoft meters it per core by the hour, and the charge stops the moment you unsubscribe — which, for an estate that is migrating in waves, is the difference between paying for the instances you still have and paying for the ones you used to have. Arc is also the only ESU route for organizations without Software Assurance: Microsoft's pay-as-you-go license type makes a host ESU-eligible without an Enterprise Agreement. And the connected host is reusable — it is the same foundation our Azure Arc Hybrid Server Management engagement builds on for patching, inventory and policy, if you want more than ESU from it. We enroll the estate the way a licensing-literate engineer would, not the way the portal's defaults would. The license type set on each host — pay-as-you-go, license with Software Assurance, or license only — is both a billing statement and an ESU eligibility switch, so we set it per host against your actual entitlements and write down why. Hosts that run many virtual machines are evaluated for Microsoft's physical-core ESU license, which covers any number of out-of-support instances on that host, before we default to billing per VM. Passive availability-group and failover-cluster replicas are identified so they are not metered where Microsoft's terms say they should not be. And because ESU is a decision about time, the engagement ends with an instance inventory that names, for every instance, the exit — in-place upgrade, migration to an Azure target, retirement, or a deliberate stay on ESU — and the date by which it happens. That inventory is the document your finance team asks for when the first Azure invoice arrives, and the one your auditors ask for when 2016 shows up in a scan. Two things we say before you sign. ESU is a bridge with a toll that rises every year — Microsoft prices Year 1 at roughly three quarters of the current license price and increases it in Years 2 and 3 — and unlike SQL Server 2014, moving SQL Server 2016 into an Azure VM does not make its ESU free; only a version upgrade, or a move to Azure SQL Managed Instance or Azure SQL Database, ends the charge. If a slice of your estate can be upgraded or migrated to a supported SQL Server on an Azure VM inside the time ESU would buy, we will say so and quote that instead.
Success criteria
What you receive
How the work unfolds
Confirm the host list, core counts, editions, Software Assurance status, network segments, and existing patch tooling. Agree the Azure landing spot and naming. Produce the design memo and the ESU cost model; you approve both before we install anything.
Onboard one representative host — Connected Machine agent, SQL Server extension, license type, ESU subscription — inside a maintenance window. Verify instance discovery, entitlement state, and update-channel visibility on your estate, not in theory, and adjust the runbook.
Roll the agent and extension to the remaining hosts with the scripted method. Bring instances that are behind up to SP3 plus the latest update in your windows. Reconcile discovered instances against the inventory and chase the stragglers.
Set the license type per host from the signed decision record. Activate ESU per host, or through the physical-core license resource where that is the chosen structure. Confirm the active state, record timestamps, and configure the exemptions for passive replicas and Developer edition.
Verify the success criteria end to end. Deliver the instance inventory with exit dates, the cost model, the runbook and the closeout report, and run the handover session with your team.
Prerequisites
Who does what
IT Partner
- Design the enrollment: Azure landing spot, connectivity, onboarding identity, naming and tagging.
- Deploy the Connected Machine agent and the Azure extension for SQL Server to every in-scope host, and reconcile discovered instances against the inventory.
- Set the license type per host from the decision record, activate ESU, and configure the exemptions for passive replicas and non-production editions.
- Bring instances that are behind up to the servicing level ESU requires, inside your maintenance windows.
- Produce the cost model, the instance inventory with exit dates, the runbook and the closeout report, and run the handover session.
- Say plainly which instances should not be on ESU at all — because an upgrade or migration is cheaper inside the same window — rather than enrolling everything.
Your team
- Provide the host list, the licensing position, administrative credentials, and maintenance windows.
- Provide the Azure subscription and open the outbound connectivity or proxy path per the design.
- Decide the license type per host and sign the cost model before activation.
- Own Microsoft's ESU charges, any pay-as-you-go SQL Server license charges, and any Azure Update Manager charges for Arc-enabled servers — all billed by Microsoft to your subscription.
- Decide the exit route and date for each instance from the options we lay out.
- Operate enrollment and unsubscription after handover using the runbook, or engage the [Managed ESU and Legacy Server Lifecycle Service](/services/managed-esu-legacy-server-lifecycle) for monthly ESU and patch-compliance evidence as a separate agreement.
What's not included
Limitations & technical notes
Frequently asked questions
SQL Server 2016 support ended in July. How exposed are we right now?
Any SQL Server 2016 instance not enrolled in ESU has received no security updates since 14 July 2026, per Microsoft's product lifecycle. Whether that has bitten yet depends on whether Microsoft has published a Critical fix since — ESU releases appear only when one is needed — but the exposure is structural: the next Critical vulnerability will be patched on enrolled instances and not on yours. And because Arc enrollment bills back to the start of the ESU year, there is no financial reason to wait either.
What exactly does ESU deliver?
Security fixes for vulnerabilities the Microsoft Security Response Center rates Critical, packaged cumulatively with the latest cumulative update, for up to three years after end of support — through 17 July 2029 for SQL Server 2016 and 12 July 2027 for SQL Server 2014. Nothing else: no Important-rated fixes, no new features, no non-security hotfixes, no support incidents. It keeps an unsupported version patched against the worst; it does not make it supported.
Why enroll through Azure Arc instead of buying ESU through our Volume Licensing agreement?
Three reasons. Arc bills per host, metered by the hour and invoiced monthly, and stops the day you unsubscribe — Volume Licensing sells ESU annually, in advance, for the whole year. Arc is available without Software Assurance through Microsoft's pay-as-you-go license type, while the Volume Licensing route requires active SA under an Enterprise Agreement, Enterprise Subscription, Server and Cloud Enrollment, or Enrollment for Education Solutions. And the connected host is reusable: the same agent gives you Azure Update Manager, inventory and policy over the server if you want them. The one case where Volume Licensing wins is a host that cannot reach Azure at all.
We do not have Software Assurance. Can we still get ESU?
Yes, through Arc — by setting the host's license type to pay-as-you-go, which makes it ESU-eligible. The catch is that pay-as-you-go also meters the SQL Server license itself through your Azure subscription, per core, per hour, on top of the ESU charge. For some hosts that is cheaper than buying Software Assurance for a version you are leaving; for others it is not. The cost model shows both numbers per host before you choose, and buying SA or licenses, if that turns out to be the better answer, starts with our Volume Licensing consulting rather than a guess.
What will Microsoft charge us for ESU, and who pays it?
You do, on your own Azure subscription. Microsoft meters ESU per core — with a minimum of four cores per host — reported hourly and invoiced monthly, at a Year 1 price Microsoft sets at roughly 75% of the current license price and raises in Years 2 and 3. We print no rate on this page on purpose, because Microsoft revises them; the cost model in the design carries the current number per host, including the bill-back for the months since the ESU year began, and nothing is activated until you have seen it. Physical hosts running many VMs may be cheaper under Microsoft's physical-core ESU license, which we evaluate rather than defaulting to per-VM billing.
We have been out of support since July. Do we pay for the months we missed?
Yes. Under Microsoft's Arc ESU terms, subscribing after the ESU year began adds a one-time bill-back from the start of that year to the activation timestamp. It is the same money whether you enroll this week or in three months — the difference is how many of those months you were unpatched. We record the activation timestamp per host so the first invoice can be reconciled line by line.
Can we stop paying once an instance is migrated?
Yes — that is the point of the Arc route. Unsubscribing a host stops its ESU charges immediately; you lose access to future ESU releases for that host, which no longer matters once the instance is gone. The runbook covers the exact steps, and the instance inventory's exit dates tell you when each host should come off. One rule to know: if a virtualization host is covered by a physical-core ESU license, its VMs must be unsubscribed before that license resource is removed, or they revert to per-VM billing.
If we move SQL Server 2016 into an Azure VM, is ESU free?
No. Under Microsoft's current terms the free-in-Azure ESU applies to SQL Server 2014, not to SQL Server 2016 — a 2016 instance on an Azure VM subscribes to ESU through the SQL IaaS Agent extension and pays. The only ways off the charge are a version upgrade or a move to a platform without a version to support, Azure SQL Managed Instance or Azure SQL Database. That is why the inventory names an exit route per instance rather than assuming a lift-and-shift ends the problem. Verify against Microsoft's lifecycle pages before committing; the terms are Microsoft's.
We also have SQL Server 2014 and a couple of 2012 instances. Can they be enrolled?
SQL Server 2014, yes — the same Arc enrollment, with ESU available through 12 July 2027 per Microsoft's product lifecycle, so its exit date is closer. SQL Server 2012, no: Microsoft's ESU program for it ended in July 2025, and there is no patch path at any price. Those instances are named in the inventory with the only honest options — isolate, migrate, or retire — and we scope that work separately.
Our SQL Server 2016 runs on Windows Server 2016. What about the operating system?
It has its own clock. Windows Server 2016 leaves extended support on 12 January 2027 per Microsoft's product lifecycle, after which the operating system under your database needs Windows Server ESU — also available through Azure Arc, on the same connected host, as a separate enrollment with its own per-core charge. This engagement enrolls SQL Server; the Windows Server ESU Enrollment through Azure Arc is the matching service for the operating system, and when both are in scope we run them in the same week on the same hosts.
Does onboarding to Arc restart SQL Server or change anything on the host?
Installing the Connected Machine agent and the Azure extension for SQL Server adds two services that connect outbound to Azure and read instance metadata. Neither install is designed to restart SQL Server or reboot the host, and we run the pilot host inside a maintenance window to prove that on your estate before touching the rest. The one change with real impact is deliberate: bringing an instance that is behind on servicing up to SP3 plus the latest update, which does restart SQL Server and is scheduled in your window.
What does 'per server' mean in your pricing?
One host — a physical machine or a virtual machine — regardless of how many SQL Server instances it runs; named instances on the same host count once. It matches how Microsoft meters ESU (by the host's cores) and how Arc onboarding works (per machine). Ten hosts is $950 plus the $1,450 tenant fee, $2,400 in total as an estimate; large estates are quoted per estate.
How do we know the ESU patches are actually arriving?
Three checks, all handed over. The Arc resource for each host shows the ESU subscription state — active, with a timestamp. Azure Update Manager, or your existing patch tooling, is confirmed to see SQL Server updates on the host. And the runbook tells you what to check when Microsoft releases the first ESU after enrollment, because ESU updates ship only when a Critical vulnerability requires one — there may be nothing to install on handover day, and that is normal. If you would rather have that checked every month with evidence you can hand an auditor, the Managed ESU and Legacy Server Lifecycle Service does exactly that, as a separate monthly agreement.
What is the 'exit date' in the instance inventory, and who decides it?
For every instance: the recommended exit route — in-place upgrade to a supported version, migration to SQL Server on an Azure VM, Azure SQL Managed Instance or Azure SQL Database, retirement, or a deliberate stay on ESU to a named date — and the date it should happen, chosen against Microsoft's ESU price steps and your project calendar. We propose; you decide. It is the document that keeps ESU a plan rather than a habit, and it is written so the migration engagement can pick it up without re-discovery.
Do you need sysadmin on our SQL Server instances?
Not to enroll ESU. We need local administrator on each host to install the agent and extension; the extension runs under the host's system account to discover instances and report their state. Some optional Arc features for SQL Server need a login inside the instance, and we ask for those separately only if you want them — we do not take sysadmin by default, and everything we do is recorded on the host and in Azure's activity log.