First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/Windows Server 2016 End of Support Assessment and Roadmap
AssessmentConsulting

Windows Server 2016 End of Support Assessment and Roadmap

Windows Server 2016 leaves extended support on 12 January 2027, per Microsoft's product lifecycle. This is a fixed-price, two-week assessment that finds every Windows Server 2016 host you run — across sites, hypervisors and physical hardware — maps what each one actually does (AD DS, AD CS, DHCP/DNS/NPS, file and print, IIS, SQL Server, RDS, Hyper-V, third-party applications), checks it against Windows Server 2025's hardware, role and application requirements, and gives every server one of five verdicts: in-place upgrade, side-by-side rebuild, migrate to Azure, Extended Security Updates as a dated bridge, or retire. You get the licensing impact (CALs, Software Assurance, Azure Hybrid Benefit), an ESU-versus-upgrade-versus-Azure cost comparison built on Microsoft's current published pricing, and a dated wave plan that lands before the deadline. $2,950 fixed for up to 25 assessed hosts; larger estates are quoted per estate in writing before we start. Windows Server 2012 R2, 2019 and 2022 hosts can ride along on the same decision matrix. Execution — the upgrades, migrations and ESU enrollment — is separate, quoted per wave from the plan, and the roadmap is yours whoever does the work.

Timeline 2 weeksService owner Roman SotnikWindows ServerWindows Server 2025Microsoft Azure

What this engagement is

Windows Server 2016 reaches the end of extended support on 12 January 2027, per Microsoft's product lifecycle. After that date a 2016 host receives no security updates unless it is enrolled in Extended Security Updates, and Microsoft has said 2016 ESU runs for up to three years, is licensed per core, is priced per year with the price stepping up each year, and is cumulative — enroll in year two and you pay for year one as well. Two things make this wave harder than the 2012 R2 one that closes on 13 October 2026. First, the 2016 estate is bigger: it was the default build for the better part of a decade, so it is where the domain controllers, the certificate authority, the file servers, the Hyper-V hosts and the SQL Server instance nobody wants to touch actually live. Second, the cheap escape has narrowed. For 2012 R2, Microsoft included ESU at no extra charge on Azure virtual machines; its 2026 pricing-consistency change gives new ESU offerings one list price wherever the server runs. Whether and how that applies to 2016 hosts you move to Azure is one of the first things we verify against Microsoft's current ESU guidance, because the answer changes the cost comparison — we will not build your roadmap on a benefit that may not exist. The assessment starts with discovery you can trust rather than a spreadsheet someone last updated in 2021. Where an Azure Migrate appliance is practical we deploy it — agentless against vCenter or Hyper-V hosts, standard remote management for physical servers — and where it is not, we run read-only inventory scripts your own staff can execute. Either way the output is the same: every Windows Server host with its edition, build, core count, hypervisor or hardware generation, installed roles and features, installed software, discovered SQL Server instances and the network dependencies that decide what has to move together. Then we reconcile it with what you believe you own. The deltas — the forgotten 2016 VM running the badge system, the 2012 R2 print server everyone assumed was gone — are usually the most useful page in the report. Every server then gets one of five verdicts, and the role decides which. Domain controllers are almost never upgraded in place: Microsoft's own guidance is to promote new 2025 domain controllers and demote the old ones, so a 2016 DC is a rebuild, with functional levels, SYSVOL replication and FSMO placement checked first. A certificate authority is a pinned dependency for every certificate it has ever issued, so it is a planned migration that keeps the CA name and keys, never a casual reinstall. Exchange 2016 on a 2016 host is two ended products at once — Exchange 2016 left support on 14 October 2025, Exchange Server Subscription Edition does not run on Windows Server 2016, and Microsoft does not support upgrading the operating system underneath an installed Exchange server — so the honest verdict is usually Exchange Online, or a new host if mail must stay on-premises. SQL Server 2016 passed its own end of extended support on 14 July 2026, so a SQL host is a two-product decision and the engine version decides whether it can follow an OS upgrade at all. Remote Desktop farms are rebuilt or replaced, and are the first candidates for Azure Virtual Desktop. Hyper-V clusters cannot take the single-hop upgrade a standalone host can, so the roadmap prices the hop sequence or a rebuild. And on physical hardware, Windows Server 2025's processor requirement — SSE4.2 with POPCNT — almost always passes on 2016-era servers; it is the vendor's driver and firmware support statement for 2025 that fails, which is why we check the vendor matrix, not just the CPU flags. What you receive is a decision package: a per-server decision matrix with the reasoning written down, a licensing impact statement (Windows Server 2025 CALs, Software Assurance or subscription position, Azure Hybrid Benefit eligibility, and the pay-as-you-go option through Azure Arc where it fits), a three-way cost comparison — ESU years one to three, upgrade, Azure — with every assumption stated, and a dated wave plan that lands before 12 January 2027 with a named exception list for anything that genuinely needs the ESU bridge and the date it leaves it. This assessment is date-driven and role-driven; if the plan sends a large slice of the estate to Azure, the Azure Migrate Datacenter Discovery and Assessment adds the two-week performance window that right-sizes and prices those workloads properly, and we leave the appliance collecting so it starts with data in hand. Each wave then converts into fixed written quotes — Windows Server to Azure, VMware to Azure, domain controller migration, Azure Arc onboarding for the servers that stay — or into work for your own team or another provider. The report is written to serve all three.

Success criteria

01Every Windows Server 2016 host in the agreed scope is discovered, inventoried and reconciled against your own records, with the unexplained deltas listed.
02Each in-scope host has a documented role and dependency profile: what it runs, what talks to it, and what breaks if it goes away.
03Each host has a Windows Server 2025 compatibility finding — hardware, roles, and application vendor support as supplied — with blockers named individually.
04Each host carries exactly one verdict — in-place upgrade, side-by-side rebuild, migrate to Azure, ESU bridge, or retire — with the reason written down and the alternatives noted.
05The licensing impact is stated: Windows Server 2025 CAL exposure, Software Assurance or subscription position, Azure Hybrid Benefit eligibility, and where Arc pay-as-you-go licensing fits.
06A three-way cost comparison — ESU years one to three, upgrade, Azure — is built on Microsoft's published pricing at the delivery date with every assumption stated.
07A dated wave plan exists that completes before 12 January 2027, with a named ESU exception list and an exit date for each server on it.
08Leadership has seen the roadmap presentation, the engineer has walked your team through the findings, and per-wave fixed quotes are available on request.

What you receive

Windows Server inventory workbook — every discovered host with edition, build, physical or virtual, hypervisor or hardware generation, core count (the unit ESU and Windows Server licensing are measured in), installed roles and features, installed software and discovered SQL Server instances.
Role and dependency map — AD DS (FSMO roles, functional levels, SYSVOL replication method), AD CS, DHCP/DNS/NPS, file and print, IIS sites and application pools, SQL Server, RDS, Hyper-V, and third-party applications, with the observed network dependencies grouped into move groups.
Windows Server 2025 compatibility register — processor and firmware findings per physical host, role upgrade support per Microsoft's current upgrade matrix, and application vendor support statements as you supply them, with blockers and their remediation listed.
Per-server decision matrix — one verdict per host (in-place upgrade, side-by-side rebuild, migrate to Azure, ESU bridge, retire) with rationale, risk rating, effort class and prerequisites.
Licensing impact statement — Windows Server 2025 CAL requirements, Software Assurance or subscription status and what it entitles, Azure Hybrid Benefit eligibility, Standard versus Datacenter virtualization rights, and the Azure Arc pay-as-you-go option where it fits. Pre-check your own core counts with our Windows Server licensing calculator.
ESU cost estimate — per-core, per-year, cumulative, for years one to three, at Microsoft's current published pricing and enrollment terms (volume licensing or Azure Arc), with the Azure-hosted treatment verified rather than assumed.
Three-way cost comparison — ESU bridge versus upgrade versus Azure, per server and for the estate, with the assumptions written down so your finance team can challenge them.
Dated wave plan — sequenced move groups that complete before 12 January 2027, prerequisites per wave, the ESU exception list with exit dates, and the retire list with reasons.
Roadmap presentation for leadership, a findings walkthrough with the assessing engineer, and — on request — fixed written quotes per wave.

How the work unfolds

Days 1–2 — Scope and discovery setup

Scope is agreed in writing: which sites, hypervisors and physical hosts are in, whether 2012 R2, 2019 and 2022 hosts ride along, and the access method — an Azure Migrate appliance where practical, read-only inventory scripts your staff can run where it is not. Credentials are read-only wherever the platform allows, and discovery is verified healthy before we leave the call.

Days 2–6 — Discovery and reconciliation

Inventory, installed software, SQL instances and network dependencies are collected across the scope while your estate runs normally. We reconcile the result against your own records and chase the deltas with your team — the servers nobody listed are the ones that hurt on 13 January.

Days 5–8 — Role and dependency analysis

Each host's roles are examined the way an upgrade engineer would: FSMO placement and SYSVOL replication on the domain controllers, CA hierarchy and template dependencies, DHCP scopes and NPS policies, IIS application pool frameworks, SQL Server versions and editions, RDS deployment topology, Hyper-V cluster membership. Dependencies are corroborated with your application owners, because the tool sees connections and your people know why they exist.

Days 7–9 — Compatibility and licensing

Physical hosts are checked against Windows Server 2025's processor and firmware requirements and the hardware vendor's support matrix; roles against Microsoft's current upgrade guidance; applications against the vendor statements you supply. Your license position — CALs, Software Assurance or subscription, Azure Hybrid Benefit eligibility — is mapped to what each path would require.

Days 9–11 — Decision matrix and cost comparison

Every server gets its verdict and its reasoning. The three-way comparison is built at Microsoft's published pricing on the delivery date: ESU per core for years one to three under the enrollment terms that apply to you, upgrade licensing and effort, and Azure run-rate with Azure Hybrid Benefit where your licensing qualifies. Assumptions are written down, not buried.

Days 11–14 — Wave plan, presentation and walkthrough

Findings become a dated plan that lands before 12 January 2027: what moves first and why, what needs remediation, what genuinely needs the ESU bridge and when it leaves it, what should be retired. We present it to leadership, walk your engineers through the detail, and issue per-wave fixed quotes if you want them — a decision that is entirely yours.

Prerequisites

A named technical contact who knows the estate and can reach the application owners — two weeks is enough for the analysis only if questions get answered in days, not weeks.
Somewhere to run discovery: a VM for the Azure Migrate appliance on VMware or Hyper-V with outbound HTTPS to Azure, or a Windows host for physical-estate discovery — or, if your policy rules out an appliance, staff who can run our read-only inventory scripts and return the output.
Read-only credentials: vCenter read access for VMware, host access for Hyper-V, and standard remote management (WinRM) for Windows hosts we poll directly. We do not need Domain Admin for an assessment and will say so if anyone offers it.
An Azure subscription to host the Azure Migrate project if the appliance route is used — Microsoft provides the discovery tooling at no additional charge; any supporting resources that run in your subscription are billed by Microsoft to you.
Your licensing facts: Windows Server and SQL Server licenses with their Software Assurance or subscription status, existing CAL counts and versions, and any Enterprise Agreement or CSP arrangement in force.
Application vendor support statements for Windows Server 2025 where you already have them; where you do not, we tell you exactly which vendors to ask and what to ask them.
The standard fixed fee covers up to 25 assessed hosts. Larger or multi-datacenter estates are scoped and quoted per estate in writing before anything starts.

Who does what

IT Partner

  • Deploy discovery — appliance or scripts — with read-only access, and verify it is healthy within the first days rather than at the deadline.
  • Inventory every in-scope host, reconcile against your records, and chase the deltas with you.
  • Analyze roles, dependencies, compatibility and licensing against Microsoft's current documentation and the hardware vendor's published support matrix, checked at assessment time rather than from memory.
  • Assign each server a verdict with the reasoning written down, including retire and stay-put verdicts that earn us nothing.
  • Build the ESU, upgrade and Azure cost comparison at Microsoft's published pricing on the delivery date, with assumptions stated and the Azure-hosted ESU treatment verified rather than assumed.
  • Deliver a dated wave plan that lands before 12 January 2027, present it to leadership, and walk your engineers through the findings.
  • Remove the appliance and our access cleanly at the end if you choose, and treat everything discovered as confidential.

Your team

  • Provide the named technical contact, discovery placement, credentials and outbound connectivity.
  • Provide licensing details and any vendor support statements you already hold.
  • Make application owners available to corroborate dependencies and answer context questions promptly.
  • Confirm scope before discovery starts, including which non-2016 hosts ride along.
  • Attend the leadership presentation and the engineering walkthrough.
  • Decide what happens next — execute with us, with your own team, or with someone else; the roadmap serves all three.

What's not included

Executing the roadmap — every upgrade, rebuild, migration and ESU enrollment is a separately quoted, fixed-price engagement: Windows Server migration to Azure from a physical server, VMware to Azure VM migration, domain controller and AD role migration, Azure Arc onboarding for the servers that stay on-premises.
Application-vendor remediation — where a vendor does not support Windows Server 2025, we name the blocker and what it takes to clear it; negotiating with the vendor, re-platforming or rewriting the application is not part of the fee.
License purchase — we state exactly what Windows Server 2025 licenses, CALs, Software Assurance or subscriptions each path needs; buying them is a separate transaction through your agreement or our CSP relationship, and choosing the right program is the Microsoft Volume Licensing consultation.
Microsoft's ESU fees — Extended Security Updates are Microsoft's product, licensed per core and billed by Microsoft through volume licensing or, through Azure Arc, to your Azure subscription. We estimate them; we do not sell or subsidize them.
Azure consumption — anything that runs in your subscription during or after the assessment is billed by Microsoft to you.
Performance-based right-sizing of the Azure candidates — the two-week utilization window, dependency-based move groups and the reservation-versus-pay-as-you-go cost model are the Azure Migrate Datacenter Discovery and Assessment. This assessment tells you which servers should go to Azure; that one tells you what size and what it costs to run them there.
Engine-level SQL Server analysis — feature compatibility, migration method and cutover window for a database estate are the SQL Server to Azure Migration Assessment. We inventory instances and versions here and tell you when that deeper step is warranted.
Active Directory security hardening — attack paths, privileged-group sprawl and legacy authentication are the Active Directory Security Assessment; a domain controller rebuild is the natural moment to fix them, and the roadmap says so where it applies.
Exchange Server work — mailbox moves to Exchange Online are the hybrid Microsoft 365 migration and the last server's removal is Exchange Server Decommissioning; this assessment states the verdict for the host, not the migration plan for the mailboxes.
Backup and disaster-recovery design — if a server's real verdict is 'protect it, don't move it yet', Azure Backup and Azure Site Recovery are separate implementations.
Non-Windows servers, network appliances and end-user devices — Linux hosts appear in the inventory if discovery sees them, but they receive no verdict.

Limitations & technical notes

!End-of-support and ESU dates are Microsoft's: Windows Server 2016 extended support ends 12 January 2027, Windows Server 2012 R2 ESU ends 13 October 2026, SQL Server 2016 extended support ended 14 July 2026 and Exchange 2016 support ended 14 October 2025, all per Microsoft's product lifecycle at the time of writing. The report cites Microsoft's lifecycle pages on its delivery date; confirm against them before a licensing decision.
!ESU terms — per-core licensing, year-by-year pricing, the cumulative rule, availability through volume licensing or Azure Arc, and how Azure-hosted servers are treated under Microsoft's 2026 pricing-consistency change — are Microsoft's and move over time. We verify what applies to your estate during the assessment and state the source and date in the report; we do not promise on this page that ESU is free anywhere.
!Discovery is read-only and finds what access allows. If a site, host or credential is withheld, the report says what was not examined and what risk that leaves open.
!Compatibility findings for applications rest on vendor support statements. Where a vendor has not published one, the report says 'unconfirmed' and names the vendor — it does not guess.
!The cost comparison is decision-grade input built on Microsoft's published pricing on the delivery date, with every assumption written down. It is not a quote for Microsoft's charges and not a guarantee of your future bill; those meters are Microsoft's.
!Windows Server 2025 upgrade support per role, hardware requirements and cluster upgrade paths are checked against Microsoft's current documentation and the hardware vendor's matrix at assessment time, and the report records the date. Microsoft revises these pages.
!The wave plan's dates are engineering estimates built around the 12 January 2027 deadline; the pace of execution depends on your change windows, vendor responses and approvals. Where the plan honestly cannot land everything in time, it says so and names what goes on the ESU bridge and for how long.
!$2,950 covers up to 25 assessed hosts across the sites and hypervisors agreed at kickoff. Larger estates receive a fixed written quote per estate before work starts.

Frequently asked questions

When exactly does Windows Server 2016 support end, and what actually happens after?

Extended support ends on 12 January 2027, per Microsoft's product lifecycle. From the next patch cycle a 2016 host gets no security updates, no non-security fixes and no Microsoft support unless it is enrolled in Extended Security Updates — and ESU covers critical and important security updates only. Nothing stops working on the day; that silence is the problem, because every month after it is unpatched exposure that your cyber-insurer, your auditor and your attackers all treat the same way.

Is ESU available for Windows Server 2016, and what does it cost?

Yes. Microsoft has said Extended Security Updates for Windows Server 2016 run for up to three years after end of support, are licensed per core in line with how the server is licensed, are priced per year with the price stepping up each year, and are cumulative — enroll in year two and you pay for year one as well. Enrollment is through volume licensing or through Azure Arc, where Microsoft bills the ESU meter monthly per core to your Azure subscription. We do not print Microsoft's ESU list prices on this page because Microsoft revises them; the report models years one to three at the published price on its delivery date and states the source. ESU fees are Microsoft's charge, not part of our fee.

If we move the 2016 servers to Azure, do we get ESU for free?

Do not assume it. For Windows Server 2012 R2, Microsoft included ESU at no extra charge on Azure virtual machines. In 2026 Microsoft announced a pricing-consistency change that gives new ESU offerings the same list price wherever the server runs — Azure, on-premises or another cloud — and Windows Server 2016 ESU begins after that change. Exactly how that lands for Azure-hosted 2016 servers is one of the first things we verify against Microsoft's current ESU guidance during the assessment, and the cost comparison uses whatever the verified terms are. Moving to Azure can still be the right verdict for other reasons — Azure Hybrid Benefit, no CAL requirement for access to Azure-hosted Windows Server, retiring the hardware — but 'free patches' is a claim we check, not one we make.

Can we just upgrade Windows Server 2016 to 2025 in place?

Often, yes — Microsoft supports in-place upgrade to Windows Server 2025 from Windows Server 2012 R2, 2016, 2019 and 2022, up to four versions in a single hop for non-clustered systems. The catch is the role, not the operating system: domain controllers are rebuilt rather than upgraded, Exchange cannot be upgraded underneath, SQL Server has its own version support matrix, clustered hosts follow a different path, and every third-party application needs a vendor statement for 2025. That is why the matrix is per server. Where in-place upgrade is the right answer we say so plainly, because it is the cheapest path and pretending otherwise would be selling.

What about our domain controllers?

Microsoft's recommended path is a clean install: promote new Windows Server 2025 domain controllers, move the FSMO roles, and demote the 2016 ones — an in-place upgrade of a DC is supported but is the worse option. Before any of that we check the forest and domain functional levels, that SYSVOL replication is on DFS-R rather than the retired FRS engine, and where the roles sit. A DC rebuild is also the natural moment to fix the things the Active Directory Security Assessment finds, and the roadmap says so where it applies. Executing the move is the domain controller migration service, quoted per wave.

We run Hyper-V on 2016 hosts. Is that an upgrade or a migration?

It depends on whether the hosts are clustered and where the guests should live afterwards. A standalone 2016 Hyper-V host can be upgraded in place once its hardware passes the 2025 checks; a 2016 failover cluster cannot take the single-hop upgrade a standalone host can, so the plan prices the supported hop sequence or a rebuild alongside. The guests themselves are a separate question — some belong on new on-premises hosts, some belong in Azure, and the same dependency data tells us which. The matrix states a verdict for each host and each guest, not one blanket answer for the cluster.

There is SQL Server on some of these hosts. Does that change things?

Yes, because SQL Server 2016 passed its own end of extended support on 14 July 2026, so a 2016 SQL host is two ended products. Which SQL Server versions are supported on Windows Server 2025 is decided by Microsoft's support matrix, checked on the day, and it decides whether the engine can follow an OS upgrade or has to move first — to a supported version on a new host, to an Azure VM, or off the version treadmill entirely with Azure SQL Managed Instance. We inventory instances, versions and editions here; where a real database estate emerges, the SQL Server to Azure Migration Assessment does the engine-level work.

Exchange 2016 is on one of the 2016 servers. What is the verdict?

Almost always Exchange Online, or a new host if mail must stay on-premises. Exchange 2016 left support on 14 October 2025; its successor, Exchange Server Subscription Edition, runs on Windows Server 2019 and later, not 2016; and Microsoft does not support upgrading the operating system underneath an installed Exchange server. So there is no in-place path for that host at all. The assessment states the verdict; the mailbox migration and the last server's decommissioning are separate, separately quoted engagements.

What licenses do we need for the upgrade paths?

Three things decide it. Windows Server 2025 server licenses — covered by Software Assurance or a subscription if you have it, a purchase if you do not. Client Access Licenses — Windows Server 2025 CALs permit access to 2025 and earlier servers, but older CALs do not permit access to a 2025 server, so an upgrade wave usually carries a CAL true-up with it. And Azure Hybrid Benefit for the Azure path, which needs licenses with active Software Assurance or qualifying subscriptions; access to Windows Server running in Azure does not require CALs. Microsoft also offers pay-as-you-go Windows Server 2025 licensing through Azure Arc for organizations that want off the licensing cycle. The report maps all of this to your actual position; the purchase itself is separate.

How is this different from the Azure Migrate Datacenter Discovery and Assessment?

That engagement answers 'what should move to Azure and what will it cost to run there' for a whole estate, using two weeks of observed utilization to right-size and price it. This one answers 'what do we do with each Windows Server 2016 host before 12 January 2027' — role by role, with upgrade, rebuild, ESU and retire on the table alongside Azure — and it is what an infrastructure lead needs when the driver is a date rather than a datacenter exit. Estates that need both usually run this first; if the verdicts send a large slice to Azure, the Azure Migrate assessment picks up with the appliance already collecting.

Do you install agents on our servers?

No persistent agents. On VMware, discovery and dependency data come through vCenter APIs; on Hyper-V, through the hosts; on physical servers, through standard remote management. Where your policy rules out an appliance altogether, your own staff run our read-only inventory scripts and return the output. Every credential is agreed in writing and read-only wherever the platform allows, and we ask for the least access the job needs — never Domain Admin for an assessment.

We have more than 25 servers, and some are 2012 R2 or 2019. What then?

The fixed fee covers up to 25 assessed hosts of whatever version you put in scope — 2012 R2 hosts facing the 13 October 2026 ESU end and 2019 or 2022 hosts you want on the same matrix can all ride along. Above 25, or across several datacenters, we quote per estate in writing before anything starts, and the price is fixed once agreed. Discovery itself sees whatever it can reach; the fee is about how many servers get the full role, compatibility and verdict treatment.

Is two weeks really enough?

For up to 25 hosts, yes — provided discovery starts in the first two days and your application owners answer questions in days, not weeks. Discovery and reconciliation take the first week; role analysis, compatibility, licensing and the cost comparison the second; the wave plan and presentation close it out. Where an estate's vendor answers arrive late, the report ships on time with those items marked 'unconfirmed' and named, rather than the whole roadmap waiting on one vendor.

What happens after the assessment — and can we take the roadmap elsewhere?

You decide, from evidence. Most organizations convert wave one into fixed per-wave quotes with us; some hand the plan to their own engineers; some take it to another provider. All three are legitimate, and the inventory, matrix, cost comparison and wave plan are working files delivered to you with nothing proprietary holding them. We price execution in fixed, written, per-wave quotes so comparison is easy — and we would rather you left with an honest roadmap than stayed with a flattering one.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$2,950 per project
2 weeks
Book the 2016 assessment