First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/SQL Server 2016 ESU Enrollment through Azure Arc
Implementation

SQL Server 2016 Extended Security Updates (ESU) Enrollment through Azure Arc

SQL Server 2016 left extended support on 14 July 2026 per Microsoft's product lifecycle, and every instance still running it has received no security updates since — unless it is enrolled in Extended Security Updates (ESU). IT Partner enrolls your SQL Server 2016 and 2014 hosts in ESU through Azure Arc in one week: we connect each host with the Azure Connected Machine agent and the Azure extension for SQL Server, set the license type that makes it ESU-eligible, activate the ESU subscription, confirm the update channel can deliver, and hand over an instance inventory with an exit route and exit date for every instance. Pricing is an estimate at $95 per SQL Server host plus a $1,450 tenant fee, confirmed in writing once the host list is agreed; large estates are quoted per estate. The ESU itself is Microsoft's metered charge — billed per core, invoiced monthly to your own Azure subscription, cancellable the day an instance is migrated — and is not part of our fee. This service is the bridge, not the destination: upgrades and migrations are separate engagements, linked below.

Timeline 1 weekService owner Mike MackeyMicrosoft AzureAzure ArcSQL Server

What this engagement is

The deadline is behind you. SQL Server 2016 reached the end of extended support on 14 July 2026 per Microsoft's product lifecycle, and SQL Server 2014 did so on 9 July 2024. From those dates Microsoft ships no security fixes for either version except through Extended Security Updates — a paid program that delivers fixes for vulnerabilities Microsoft rates Critical, and nothing else: no new features, no non-security hotfixes, no support incidents. ESU for SQL Server 2016 runs through 17 July 2029; for SQL Server 2014, through 12 July 2027. If you are reading this with three, thirty, or three hundred instances still on 2016 and no realistic way to move them all this quarter, ESU is the honest bridge — and this engagement is how we put you on it in a week. There are two ways to buy SQL Server ESU. Through Volume Licensing you buy it annually, in advance, for licenses with active Software Assurance, and you pay for the whole year whether or not the instance is migrated in month four. Through Azure Arc you subscribe per host: the Azure Connected Machine agent and the Azure extension for SQL Server register each host and its instances in your Azure subscription, the ESU subscription is switched on per host, Microsoft meters it per core by the hour, and the charge stops the moment you unsubscribe — which, for an estate that is migrating in waves, is the difference between paying for the instances you still have and paying for the ones you used to have. Arc is also the only ESU route for organizations without Software Assurance: Microsoft's pay-as-you-go license type makes a host ESU-eligible without an Enterprise Agreement. And the connected host is reusable — it is the same foundation our Azure Arc Hybrid Server Management engagement builds on for patching, inventory and policy, if you want more than ESU from it. We enroll the estate the way a licensing-literate engineer would, not the way the portal's defaults would. The license type set on each host — pay-as-you-go, license with Software Assurance, or license only — is both a billing statement and an ESU eligibility switch, so we set it per host against your actual entitlements and write down why. Hosts that run many virtual machines are evaluated for Microsoft's physical-core ESU license, which covers any number of out-of-support instances on that host, before we default to billing per VM. Passive availability-group and failover-cluster replicas are identified so they are not metered where Microsoft's terms say they should not be. And because ESU is a decision about time, the engagement ends with an instance inventory that names, for every instance, the exit — in-place upgrade, migration to an Azure target, retirement, or a deliberate stay on ESU — and the date by which it happens. That inventory is the document your finance team asks for when the first Azure invoice arrives, and the one your auditors ask for when 2016 shows up in a scan. Two things we say before you sign. ESU is a bridge with a toll that rises every year — Microsoft prices Year 1 at roughly three quarters of the current license price and increases it in Years 2 and 3 — and unlike SQL Server 2014, moving SQL Server 2016 into an Azure VM does not make its ESU free; only a version upgrade, or a move to Azure SQL Managed Instance or Azure SQL Database, ends the charge. If a slice of your estate can be upgraded or migrated to a supported SQL Server on an Azure VM inside the time ESU would buy, we will say so and quote that instead.

Success criteria

01Every in-scope SQL Server 2016 and 2014 host is connected to Azure Arc with the Azure extension for SQL Server installed, and each instance on it appears as a SQL Server – Azure Arc resource in the agreed subscription and resource group.
02The license type on every host is set to an ESU-eligible value — pay-as-you-go, or license with Software Assurance or a subscription license — chosen against your entitlements and recorded per host with the rationale.
03The ESU subscription shows as active on every in-scope host, or the physical-core ESU license resource covers it, and the activation timestamp is recorded — Microsoft bills from the start of the ESU year regardless of when you enroll, and the invoice needs reconciling.
04Every in-scope instance is at SQL Server 2016 SP3 or SQL Server 2014 SP3 with the latest available update applied before activation, so ESU releases — which Microsoft ships cumulatively with the latest cumulative update — install cleanly.
05The update channel — Azure Update Manager, Microsoft Update, or your existing patch tooling — is configured on each host and confirmed to see SQL Server updates for the enrolled instances.
06Projected monthly ESU charges per host, computed from core counts and edition against Microsoft's current pricing, including the bill-back for months since the ESU year began, are documented and acknowledged by you before any subscription is switched on.
07Passive replicas, Developer-edition hosts, and dev/test subscriptions are identified and configured so they are not metered where Microsoft's terms exempt them.
08The instance inventory names an exit route and exit date for every instance, and your team can enroll a new host and unsubscribe a migrated one unaided after the handover session.

What you receive

Enrollment design memo: Azure subscription and resource group, naming and tagging for Arc-enabled hosts and SQL Server resources, connectivity path per network segment (direct outbound, proxy, or Private Link), and the onboarding identity — approved before anything is installed.
Arc onboarding of every in-scope host: Azure Connected Machine agent and Azure extension for SQL Server deployed with the scripted method that fits your estate, instances discovered and reconciled against the inventory, stragglers named rather than ignored.
Per-host license type decision record: pay-as-you-go, license with Software Assurance, or license only — mapped to your Volume Licensing entitlements, with the billing consequence of each option written in plain English before you choose.
ESU subscription activation per host — or a physical-core ESU license resource for virtualization hosts where Microsoft's unlimited-virtualization structure is cheaper — with activation timestamps and portal evidence for your records.
Servicing-level remediation to SP3 plus the latest available update where instances are behind, scheduled inside your maintenance windows, so the first ESU release installs without surprise.
Update channel configuration and verification: Azure Update Manager assessment, or your existing patch tooling, confirmed to detect SQL Server updates on each host, with the ESU entitlement state visible on the Arc resource.
ESU cost model: per-host core counts, edition, Microsoft's minimums, and the resulting projected monthly charge — including the one-time bill-back since the ESU year began — computed against Microsoft's current pricing at the time of enrollment, not ours.
Instance inventory with per-instance exit date: version, edition, host, cores, databases, the dependencies we could see, the recommended exit route, and a date — the document that turns ESU from an open-ended cost into a plan.
Enrollment and unsubscription runbook: how to add the next host the same way, how to switch ESU off the day an instance is migrated, and how to read the ESU line on your Azure invoice.
Handover session and closeout report: what was enrolled, what was excluded and why, and the recommended next engagement for each exit route.

How the work unfolds

1. Intake and design (day 1)

Confirm the host list, core counts, editions, Software Assurance status, network segments, and existing patch tooling. Agree the Azure landing spot and naming. Produce the design memo and the ESU cost model; you approve both before we install anything.

2. Pilot host (day 2)

Onboard one representative host — Connected Machine agent, SQL Server extension, license type, ESU subscription — inside a maintenance window. Verify instance discovery, entitlement state, and update-channel visibility on your estate, not in theory, and adjust the runbook.

3. Estate onboarding (days 2–3)

Roll the agent and extension to the remaining hosts with the scripted method. Bring instances that are behind up to SP3 plus the latest update in your windows. Reconcile discovered instances against the inventory and chase the stragglers.

4. License type and ESU activation (day 4)

Set the license type per host from the signed decision record. Activate ESU per host, or through the physical-core license resource where that is the chosen structure. Confirm the active state, record timestamps, and configure the exemptions for passive replicas and Developer edition.

5. Verification, inventory and handover (day 5)

Verify the success criteria end to end. Deliver the instance inventory with exit dates, the cost model, the runbook and the closeout report, and run the handover session with your team.

Prerequisites

A list of SQL Server 2016 and 2014 hosts — even a rough one — with core counts and editions; we refine it during intake, and the written estimate follows the agreed list.
Your SQL Server licensing position: the Volume Licensing agreement, and whether the licenses carry active Software Assurance or are subscription licenses. Without either, ESU through Arc requires the pay-as-you-go license type, which meters the SQL Server license itself through Azure — a decision you make with the numbers in front of you, not a default we set.
An Azure subscription in your tenant with rights to register the Azure Arc resource providers, create resource groups, and assign the onboarding role. ESU and any pay-as-you-go license charges land on this subscription. If you would rather it sit under IT Partner's CSP billing, we transact Azure directly with Microsoft as a direct-bill partner and can provision one.
Outbound HTTPS (port 443) from each host to Azure endpoints, directly or through a proxy. No inbound connectivity is required. Fully air-gapped hosts cannot be Arc-enabled — see the limitations for the alternative.
Host operating systems inside the Azure Connected Machine agent's support matrix. We confirm your list against Microsoft's current matrix at intake, and hosts outside it are flagged with an alternative rather than quietly dropped.
Local administrator access on each host for agent and extension installation, and a maintenance window per host for the servicing update where an instance is behind SP3 plus the latest update.
Instances at, or able to be brought to, SQL Server 2016 SP3 or SQL Server 2014 SP3 with the latest available update. ESU releases are cumulative with the latest cumulative update, so an instance still on RTM or SP1 has a remediation step first.
A named decision-maker for license type per host and for the exit route and date per instance. These are your commercial decisions; we bring defensible defaults and the cost of each.
Acknowledgment that ESU is Microsoft's metered charge on your subscription, including the bill-back from the start of the ESU year — presented in the cost model and approved before activation.

Who does what

IT Partner

  • Design the enrollment: Azure landing spot, connectivity, onboarding identity, naming and tagging.
  • Deploy the Connected Machine agent and the Azure extension for SQL Server to every in-scope host, and reconcile discovered instances against the inventory.
  • Set the license type per host from the decision record, activate ESU, and configure the exemptions for passive replicas and non-production editions.
  • Bring instances that are behind up to the servicing level ESU requires, inside your maintenance windows.
  • Produce the cost model, the instance inventory with exit dates, the runbook and the closeout report, and run the handover session.
  • Say plainly which instances should not be on ESU at all — because an upgrade or migration is cheaper inside the same window — rather than enrolling everything.

Your team

  • Provide the host list, the licensing position, administrative credentials, and maintenance windows.
  • Provide the Azure subscription and open the outbound connectivity or proxy path per the design.
  • Decide the license type per host and sign the cost model before activation.
  • Own Microsoft's ESU charges, any pay-as-you-go SQL Server license charges, and any Azure Update Manager charges for Arc-enabled servers — all billed by Microsoft to your subscription.
  • Decide the exit route and date for each instance from the options we lay out.
  • Operate enrollment and unsubscription after handover using the runbook, or engage the [Managed ESU and Legacy Server Lifecycle Service](/services/managed-esu-legacy-server-lifecycle) for monthly ESU and patch-compliance evidence as a separate agreement.

What's not included

Upgrades and migrations — ESU buys time; using it is separate work. An in-place upgrade to a supported version, or a migration to SQL Server on an Azure VM, Azure SQL Managed Instance or Azure SQL Database, is its own engagement, and the SQL Server to Azure Migration Assessment is the honest first step when the target is not yet decided. Smaller single-instance moves have their own fixed-price pages: database migration to a current SQL Server on an Azure VM and replication-based migration to an Azure VM.
Microsoft's ESU charges — metered per core by the hour, invoiced monthly by Microsoft to your Azure subscription, including the one-time bill-back for the months since the ESU year began. We model them; we do not carry them.
SQL Server license fees under the pay-as-you-go license type, and Azure Update Manager charges for Arc-enabled servers where Microsoft meters them — likewise Microsoft's, modeled in the design, outside our fee.
Windows Server ESU for the host operating system. Windows Server 2016 leaves extended support on 12 January 2027 per Microsoft's product lifecycle, and its ESU is a separate enrollment on the same Arc-connected host with its own per-core charge — our Windows Server ESU Enrollment through Azure Arc covers it; ask at intake and we scope the two together.
Performance tuning, index work, query rewrites, or capacity fixes — an ESU-enrolled instance is exactly as fast, and exactly as fragile, as it was the day before.
SQL Server licensing true-ups, Software Assurance purchases, or Enterprise Agreement negotiations. We document which license type each host needs and what it costs; buying licenses or SA is a separate conversation, and our Microsoft Volume Licensing consulting is where it starts.
Broader Azure Arc management — Azure Policy baselines, Update Manager schedules across the estate, Defender for Cloud — is the Azure Arc Hybrid Server Management Implementation; the hosts enrolled here are ready for it.
SQL Server 2012 and earlier. Microsoft's ESU program for SQL Server 2012 ended in July 2025 per Microsoft's product lifecycle, so those instances have no patch path at any price; they are named in the inventory with the only honest options — isolate, migrate, or retire — and that work is scoped separately.
Instances hosted on Azure VMs. Those enroll in ESU through the SQL IaaS Agent extension rather than Azure Arc; tell us at intake and we can usually fold them into the same engagement and quote.
Remediation of hosts that fail to onboard because of OS corruption, broken WMI, or unsupported operating systems — dispositioned in the closeout, repaired as separate work.

Limitations & technical notes

!Pricing is an estimate: $95 per SQL Server host plus a $1,450 tenant fee, where a host is one physical machine or virtual machine regardless of how many instances it runs — confirmed in writing after the host list is agreed. Heavily segmented networks, proxy-only egress, many instances behind on servicing, or Private Link requirements move effort, and large estates are quoted per estate rather than by the per-host rate.
!ESU covers what Microsoft says it covers: fixes for vulnerabilities the Microsoft Security Response Center rates Critical, cumulative with the latest cumulative update, released only when such a vulnerability exists. It is not a support contract, brings no new features or non-security fixes, and does not extend the product's life beyond 17 July 2029 for SQL Server 2016 or 12 July 2027 for SQL Server 2014, per Microsoft's product lifecycle.
!The ESU charge is Microsoft's, and it runs on Microsoft's clock: under the Arc terms, enrolling after the ESU year began triggers a one-time bill-back from the start of the year to the activation timestamp, so waiting costs more, not less. Charges are metered per core by the hour with a four-core minimum per host and stop when you unsubscribe. We deliberately print none of Microsoft's rates here — they change — and the cost model carries the current ones.
!Eligibility is a licensing fact, not a portal setting. Hosts whose SQL Server licenses have no Software Assurance and are not subscription licenses cannot take ESU through Arc on the license-only type. The alternative is the pay-as-you-go license type, which meters the SQL Server license itself through Azure on top of ESU — a real cost the model shows before you choose.
!Moving SQL Server 2016 into an Azure VM does not make its ESU free. Under Microsoft's current terms that exemption applies to SQL Server 2014, not to 2016; a 2016 instance on an Azure VM subscribes and pays. Verify against Microsoft's lifecycle pages before you commit — the terms are Microsoft's to change.
!Microsoft prices ESU Year 1 at roughly 75% of the current license price and increases it in Years 2 and 3, per Microsoft's ESU guidance at the time of writing. Three years on ESU can cost more than the upgrade would have; the inventory's exit dates exist so that does not happen by inertia.
!Arc enrollment requires a supported host operating system and an outbound path to Azure. Air-gapped hosts and operating systems outside the Connected Machine agent's support matrix cannot be Arc-enabled; for those, ESU is available only annually through Volume Licensing with Software Assurance, and the closeout names every host excluded and why.
!Verifying ESU delivery at handover means verifying entitlement and the channel — the subscription state on the Arc resource and the host's ability to see and apply SQL Server updates — not installing an ESU patch, because Microsoft releases one only when a Critical vulnerability requires it. The runbook covers what to check when the first one ships.
!The Windows Server under your SQL Server has its own clock. Windows Server 2016 leaves extended support on 12 January 2027 per Microsoft's product lifecycle, after which the operating system needs its own ESU. This engagement enrolls SQL Server; the Windows Server enrollment is a separate item — Windows Server ESU Enrollment through Azure Arc — that we can run in the same week.
!Microsoft's ESU terms, license types, meters and exemptions are current as of the engagement and verified during design, not promised from this page.

Frequently asked questions

SQL Server 2016 support ended in July. How exposed are we right now?

Any SQL Server 2016 instance not enrolled in ESU has received no security updates since 14 July 2026, per Microsoft's product lifecycle. Whether that has bitten yet depends on whether Microsoft has published a Critical fix since — ESU releases appear only when one is needed — but the exposure is structural: the next Critical vulnerability will be patched on enrolled instances and not on yours. And because Arc enrollment bills back to the start of the ESU year, there is no financial reason to wait either.

What exactly does ESU deliver?

Security fixes for vulnerabilities the Microsoft Security Response Center rates Critical, packaged cumulatively with the latest cumulative update, for up to three years after end of support — through 17 July 2029 for SQL Server 2016 and 12 July 2027 for SQL Server 2014. Nothing else: no Important-rated fixes, no new features, no non-security hotfixes, no support incidents. It keeps an unsupported version patched against the worst; it does not make it supported.

Why enroll through Azure Arc instead of buying ESU through our Volume Licensing agreement?

Three reasons. Arc bills per host, metered by the hour and invoiced monthly, and stops the day you unsubscribe — Volume Licensing sells ESU annually, in advance, for the whole year. Arc is available without Software Assurance through Microsoft's pay-as-you-go license type, while the Volume Licensing route requires active SA under an Enterprise Agreement, Enterprise Subscription, Server and Cloud Enrollment, or Enrollment for Education Solutions. And the connected host is reusable: the same agent gives you Azure Update Manager, inventory and policy over the server if you want them. The one case where Volume Licensing wins is a host that cannot reach Azure at all.

We do not have Software Assurance. Can we still get ESU?

Yes, through Arc — by setting the host's license type to pay-as-you-go, which makes it ESU-eligible. The catch is that pay-as-you-go also meters the SQL Server license itself through your Azure subscription, per core, per hour, on top of the ESU charge. For some hosts that is cheaper than buying Software Assurance for a version you are leaving; for others it is not. The cost model shows both numbers per host before you choose, and buying SA or licenses, if that turns out to be the better answer, starts with our Volume Licensing consulting rather than a guess.

What will Microsoft charge us for ESU, and who pays it?

You do, on your own Azure subscription. Microsoft meters ESU per core — with a minimum of four cores per host — reported hourly and invoiced monthly, at a Year 1 price Microsoft sets at roughly 75% of the current license price and raises in Years 2 and 3. We print no rate on this page on purpose, because Microsoft revises them; the cost model in the design carries the current number per host, including the bill-back for the months since the ESU year began, and nothing is activated until you have seen it. Physical hosts running many VMs may be cheaper under Microsoft's physical-core ESU license, which we evaluate rather than defaulting to per-VM billing.

We have been out of support since July. Do we pay for the months we missed?

Yes. Under Microsoft's Arc ESU terms, subscribing after the ESU year began adds a one-time bill-back from the start of that year to the activation timestamp. It is the same money whether you enroll this week or in three months — the difference is how many of those months you were unpatched. We record the activation timestamp per host so the first invoice can be reconciled line by line.

Can we stop paying once an instance is migrated?

Yes — that is the point of the Arc route. Unsubscribing a host stops its ESU charges immediately; you lose access to future ESU releases for that host, which no longer matters once the instance is gone. The runbook covers the exact steps, and the instance inventory's exit dates tell you when each host should come off. One rule to know: if a virtualization host is covered by a physical-core ESU license, its VMs must be unsubscribed before that license resource is removed, or they revert to per-VM billing.

If we move SQL Server 2016 into an Azure VM, is ESU free?

No. Under Microsoft's current terms the free-in-Azure ESU applies to SQL Server 2014, not to SQL Server 2016 — a 2016 instance on an Azure VM subscribes to ESU through the SQL IaaS Agent extension and pays. The only ways off the charge are a version upgrade or a move to a platform without a version to support, Azure SQL Managed Instance or Azure SQL Database. That is why the inventory names an exit route per instance rather than assuming a lift-and-shift ends the problem. Verify against Microsoft's lifecycle pages before committing; the terms are Microsoft's.

We also have SQL Server 2014 and a couple of 2012 instances. Can they be enrolled?

SQL Server 2014, yes — the same Arc enrollment, with ESU available through 12 July 2027 per Microsoft's product lifecycle, so its exit date is closer. SQL Server 2012, no: Microsoft's ESU program for it ended in July 2025, and there is no patch path at any price. Those instances are named in the inventory with the only honest options — isolate, migrate, or retire — and we scope that work separately.

Our SQL Server 2016 runs on Windows Server 2016. What about the operating system?

It has its own clock. Windows Server 2016 leaves extended support on 12 January 2027 per Microsoft's product lifecycle, after which the operating system under your database needs Windows Server ESU — also available through Azure Arc, on the same connected host, as a separate enrollment with its own per-core charge. This engagement enrolls SQL Server; the Windows Server ESU Enrollment through Azure Arc is the matching service for the operating system, and when both are in scope we run them in the same week on the same hosts.

Does onboarding to Arc restart SQL Server or change anything on the host?

Installing the Connected Machine agent and the Azure extension for SQL Server adds two services that connect outbound to Azure and read instance metadata. Neither install is designed to restart SQL Server or reboot the host, and we run the pilot host inside a maintenance window to prove that on your estate before touching the rest. The one change with real impact is deliberate: bringing an instance that is behind on servicing up to SP3 plus the latest update, which does restart SQL Server and is scheduled in your window.

What does 'per server' mean in your pricing?

One host — a physical machine or a virtual machine — regardless of how many SQL Server instances it runs; named instances on the same host count once. It matches how Microsoft meters ESU (by the host's cores) and how Arc onboarding works (per machine). Ten hosts is $950 plus the $1,450 tenant fee, $2,400 in total as an estimate; large estates are quoted per estate.

How do we know the ESU patches are actually arriving?

Three checks, all handed over. The Arc resource for each host shows the ESU subscription state — active, with a timestamp. Azure Update Manager, or your existing patch tooling, is confirmed to see SQL Server updates on the host. And the runbook tells you what to check when Microsoft releases the first ESU after enrollment, because ESU updates ship only when a Critical vulnerability requires one — there may be nothing to install on handover day, and that is normal. If you would rather have that checked every month with evidence you can hand an auditor, the Managed ESU and Legacy Server Lifecycle Service does exactly that, as a separate monthly agreement.

What is the 'exit date' in the instance inventory, and who decides it?

For every instance: the recommended exit route — in-place upgrade to a supported version, migration to SQL Server on an Azure VM, Azure SQL Managed Instance or Azure SQL Database, retirement, or a deliberate stay on ESU to a named date — and the date it should happen, chosen against Microsoft's ESU price steps and your project calendar. We propose; you decide. It is the document that keeps ESU a plan rather than a habit, and it is written so the migration engagement can pick it up without re-discovery.

Do you need sysadmin on our SQL Server instances?

Not to enroll ESU. We need local administrator on each host to install the agent and extension; the extension runs under the host's system account to discover instances and report their state. Some optional Arc features for SQL Server need a login inside the instance, and we ask for those separately only if you want them — we do not take sysadmin by default, and everything we do is recorded on the host and in Azure's activity log.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$95 per server + $1,450 tenant fee
1 week
Book an ESU enrollment call