Windows Server 2016 End of Support Assessment and Roadmap
Windows Server 2016 leaves extended support on 12 January 2027, per Microsoft's product lifecycle. This is a fixed-price, two-week assessment that finds every Windows Server 2016 host you run — across sites, hypervisors and physical hardware — maps what each one actually does (AD DS, AD CS, DHCP/DNS/NPS, file and print, IIS, SQL Server, RDS, Hyper-V, third-party applications), checks it against Windows Server 2025's hardware, role and application requirements, and gives every server one of five verdicts: in-place upgrade, side-by-side rebuild, migrate to Azure, Extended Security Updates as a dated bridge, or retire. You get the licensing impact (CALs, Software Assurance, Azure Hybrid Benefit), an ESU-versus-upgrade-versus-Azure cost comparison built on Microsoft's current published pricing, and a dated wave plan that lands before the deadline. $2,950 fixed for up to 25 assessed hosts; larger estates are quoted per estate in writing before we start. Windows Server 2012 R2, 2019 and 2022 hosts can ride along on the same decision matrix. Execution — the upgrades, migrations and ESU enrollment — is separate, quoted per wave from the plan, and the roadmap is yours whoever does the work.
What this engagement is
Windows Server 2016 reaches the end of extended support on 12 January 2027, per Microsoft's product lifecycle. After that date a 2016 host receives no security updates unless it is enrolled in Extended Security Updates, and Microsoft has said 2016 ESU runs for up to three years, is licensed per core, is priced per year with the price stepping up each year, and is cumulative — enroll in year two and you pay for year one as well. Two things make this wave harder than the 2012 R2 one that closes on 13 October 2026. First, the 2016 estate is bigger: it was the default build for the better part of a decade, so it is where the domain controllers, the certificate authority, the file servers, the Hyper-V hosts and the SQL Server instance nobody wants to touch actually live. Second, the cheap escape has narrowed. For 2012 R2, Microsoft included ESU at no extra charge on Azure virtual machines; its 2026 pricing-consistency change gives new ESU offerings one list price wherever the server runs. Whether and how that applies to 2016 hosts you move to Azure is one of the first things we verify against Microsoft's current ESU guidance, because the answer changes the cost comparison — we will not build your roadmap on a benefit that may not exist. The assessment starts with discovery you can trust rather than a spreadsheet someone last updated in 2021. Where an Azure Migrate appliance is practical we deploy it — agentless against vCenter or Hyper-V hosts, standard remote management for physical servers — and where it is not, we run read-only inventory scripts your own staff can execute. Either way the output is the same: every Windows Server host with its edition, build, core count, hypervisor or hardware generation, installed roles and features, installed software, discovered SQL Server instances and the network dependencies that decide what has to move together. Then we reconcile it with what you believe you own. The deltas — the forgotten 2016 VM running the badge system, the 2012 R2 print server everyone assumed was gone — are usually the most useful page in the report. Every server then gets one of five verdicts, and the role decides which. Domain controllers are almost never upgraded in place: Microsoft's own guidance is to promote new 2025 domain controllers and demote the old ones, so a 2016 DC is a rebuild, with functional levels, SYSVOL replication and FSMO placement checked first. A certificate authority is a pinned dependency for every certificate it has ever issued, so it is a planned migration that keeps the CA name and keys, never a casual reinstall. Exchange 2016 on a 2016 host is two ended products at once — Exchange 2016 left support on 14 October 2025, Exchange Server Subscription Edition does not run on Windows Server 2016, and Microsoft does not support upgrading the operating system underneath an installed Exchange server — so the honest verdict is usually Exchange Online, or a new host if mail must stay on-premises. SQL Server 2016 passed its own end of extended support on 14 July 2026, so a SQL host is a two-product decision and the engine version decides whether it can follow an OS upgrade at all. Remote Desktop farms are rebuilt or replaced, and are the first candidates for Azure Virtual Desktop. Hyper-V clusters cannot take the single-hop upgrade a standalone host can, so the roadmap prices the hop sequence or a rebuild. And on physical hardware, Windows Server 2025's processor requirement — SSE4.2 with POPCNT — almost always passes on 2016-era servers; it is the vendor's driver and firmware support statement for 2025 that fails, which is why we check the vendor matrix, not just the CPU flags. What you receive is a decision package: a per-server decision matrix with the reasoning written down, a licensing impact statement (Windows Server 2025 CALs, Software Assurance or subscription position, Azure Hybrid Benefit eligibility, and the pay-as-you-go option through Azure Arc where it fits), a three-way cost comparison — ESU years one to three, upgrade, Azure — with every assumption stated, and a dated wave plan that lands before 12 January 2027 with a named exception list for anything that genuinely needs the ESU bridge and the date it leaves it. This assessment is date-driven and role-driven; if the plan sends a large slice of the estate to Azure, the Azure Migrate Datacenter Discovery and Assessment adds the two-week performance window that right-sizes and prices those workloads properly, and we leave the appliance collecting so it starts with data in hand. Each wave then converts into fixed written quotes — Windows Server to Azure, VMware to Azure, domain controller migration, Azure Arc onboarding for the servers that stay — or into work for your own team or another provider. The report is written to serve all three.
Success criteria
What you receive
How the work unfolds
Scope is agreed in writing: which sites, hypervisors and physical hosts are in, whether 2012 R2, 2019 and 2022 hosts ride along, and the access method — an Azure Migrate appliance where practical, read-only inventory scripts your staff can run where it is not. Credentials are read-only wherever the platform allows, and discovery is verified healthy before we leave the call.
Inventory, installed software, SQL instances and network dependencies are collected across the scope while your estate runs normally. We reconcile the result against your own records and chase the deltas with your team — the servers nobody listed are the ones that hurt on 13 January.
Each host's roles are examined the way an upgrade engineer would: FSMO placement and SYSVOL replication on the domain controllers, CA hierarchy and template dependencies, DHCP scopes and NPS policies, IIS application pool frameworks, SQL Server versions and editions, RDS deployment topology, Hyper-V cluster membership. Dependencies are corroborated with your application owners, because the tool sees connections and your people know why they exist.
Physical hosts are checked against Windows Server 2025's processor and firmware requirements and the hardware vendor's support matrix; roles against Microsoft's current upgrade guidance; applications against the vendor statements you supply. Your license position — CALs, Software Assurance or subscription, Azure Hybrid Benefit eligibility — is mapped to what each path would require.
Every server gets its verdict and its reasoning. The three-way comparison is built at Microsoft's published pricing on the delivery date: ESU per core for years one to three under the enrollment terms that apply to you, upgrade licensing and effort, and Azure run-rate with Azure Hybrid Benefit where your licensing qualifies. Assumptions are written down, not buried.
Findings become a dated plan that lands before 12 January 2027: what moves first and why, what needs remediation, what genuinely needs the ESU bridge and when it leaves it, what should be retired. We present it to leadership, walk your engineers through the detail, and issue per-wave fixed quotes if you want them — a decision that is entirely yours.
Prerequisites
Who does what
IT Partner
- Deploy discovery — appliance or scripts — with read-only access, and verify it is healthy within the first days rather than at the deadline.
- Inventory every in-scope host, reconcile against your records, and chase the deltas with you.
- Analyze roles, dependencies, compatibility and licensing against Microsoft's current documentation and the hardware vendor's published support matrix, checked at assessment time rather than from memory.
- Assign each server a verdict with the reasoning written down, including retire and stay-put verdicts that earn us nothing.
- Build the ESU, upgrade and Azure cost comparison at Microsoft's published pricing on the delivery date, with assumptions stated and the Azure-hosted ESU treatment verified rather than assumed.
- Deliver a dated wave plan that lands before 12 January 2027, present it to leadership, and walk your engineers through the findings.
- Remove the appliance and our access cleanly at the end if you choose, and treat everything discovered as confidential.
Your team
- Provide the named technical contact, discovery placement, credentials and outbound connectivity.
- Provide licensing details and any vendor support statements you already hold.
- Make application owners available to corroborate dependencies and answer context questions promptly.
- Confirm scope before discovery starts, including which non-2016 hosts ride along.
- Attend the leadership presentation and the engineering walkthrough.
- Decide what happens next — execute with us, with your own team, or with someone else; the roadmap serves all three.
What's not included
Limitations & technical notes
Frequently asked questions
When exactly does Windows Server 2016 support end, and what actually happens after?
Extended support ends on 12 January 2027, per Microsoft's product lifecycle. From the next patch cycle a 2016 host gets no security updates, no non-security fixes and no Microsoft support unless it is enrolled in Extended Security Updates — and ESU covers critical and important security updates only. Nothing stops working on the day; that silence is the problem, because every month after it is unpatched exposure that your cyber-insurer, your auditor and your attackers all treat the same way.
Is ESU available for Windows Server 2016, and what does it cost?
Yes. Microsoft has said Extended Security Updates for Windows Server 2016 run for up to three years after end of support, are licensed per core in line with how the server is licensed, are priced per year with the price stepping up each year, and are cumulative — enroll in year two and you pay for year one as well. Enrollment is through volume licensing or through Azure Arc, where Microsoft bills the ESU meter monthly per core to your Azure subscription. We do not print Microsoft's ESU list prices on this page because Microsoft revises them; the report models years one to three at the published price on its delivery date and states the source. ESU fees are Microsoft's charge, not part of our fee.
If we move the 2016 servers to Azure, do we get ESU for free?
Do not assume it. For Windows Server 2012 R2, Microsoft included ESU at no extra charge on Azure virtual machines. In 2026 Microsoft announced a pricing-consistency change that gives new ESU offerings the same list price wherever the server runs — Azure, on-premises or another cloud — and Windows Server 2016 ESU begins after that change. Exactly how that lands for Azure-hosted 2016 servers is one of the first things we verify against Microsoft's current ESU guidance during the assessment, and the cost comparison uses whatever the verified terms are. Moving to Azure can still be the right verdict for other reasons — Azure Hybrid Benefit, no CAL requirement for access to Azure-hosted Windows Server, retiring the hardware — but 'free patches' is a claim we check, not one we make.
Can we just upgrade Windows Server 2016 to 2025 in place?
Often, yes — Microsoft supports in-place upgrade to Windows Server 2025 from Windows Server 2012 R2, 2016, 2019 and 2022, up to four versions in a single hop for non-clustered systems. The catch is the role, not the operating system: domain controllers are rebuilt rather than upgraded, Exchange cannot be upgraded underneath, SQL Server has its own version support matrix, clustered hosts follow a different path, and every third-party application needs a vendor statement for 2025. That is why the matrix is per server. Where in-place upgrade is the right answer we say so plainly, because it is the cheapest path and pretending otherwise would be selling.
What about our domain controllers?
Microsoft's recommended path is a clean install: promote new Windows Server 2025 domain controllers, move the FSMO roles, and demote the 2016 ones — an in-place upgrade of a DC is supported but is the worse option. Before any of that we check the forest and domain functional levels, that SYSVOL replication is on DFS-R rather than the retired FRS engine, and where the roles sit. A DC rebuild is also the natural moment to fix the things the Active Directory Security Assessment finds, and the roadmap says so where it applies. Executing the move is the domain controller migration service, quoted per wave.
We run Hyper-V on 2016 hosts. Is that an upgrade or a migration?
It depends on whether the hosts are clustered and where the guests should live afterwards. A standalone 2016 Hyper-V host can be upgraded in place once its hardware passes the 2025 checks; a 2016 failover cluster cannot take the single-hop upgrade a standalone host can, so the plan prices the supported hop sequence or a rebuild alongside. The guests themselves are a separate question — some belong on new on-premises hosts, some belong in Azure, and the same dependency data tells us which. The matrix states a verdict for each host and each guest, not one blanket answer for the cluster.
There is SQL Server on some of these hosts. Does that change things?
Yes, because SQL Server 2016 passed its own end of extended support on 14 July 2026, so a 2016 SQL host is two ended products. Which SQL Server versions are supported on Windows Server 2025 is decided by Microsoft's support matrix, checked on the day, and it decides whether the engine can follow an OS upgrade or has to move first — to a supported version on a new host, to an Azure VM, or off the version treadmill entirely with Azure SQL Managed Instance. We inventory instances, versions and editions here; where a real database estate emerges, the SQL Server to Azure Migration Assessment does the engine-level work.
Exchange 2016 is on one of the 2016 servers. What is the verdict?
Almost always Exchange Online, or a new host if mail must stay on-premises. Exchange 2016 left support on 14 October 2025; its successor, Exchange Server Subscription Edition, runs on Windows Server 2019 and later, not 2016; and Microsoft does not support upgrading the operating system underneath an installed Exchange server. So there is no in-place path for that host at all. The assessment states the verdict; the mailbox migration and the last server's decommissioning are separate, separately quoted engagements.
What licenses do we need for the upgrade paths?
Three things decide it. Windows Server 2025 server licenses — covered by Software Assurance or a subscription if you have it, a purchase if you do not. Client Access Licenses — Windows Server 2025 CALs permit access to 2025 and earlier servers, but older CALs do not permit access to a 2025 server, so an upgrade wave usually carries a CAL true-up with it. And Azure Hybrid Benefit for the Azure path, which needs licenses with active Software Assurance or qualifying subscriptions; access to Windows Server running in Azure does not require CALs. Microsoft also offers pay-as-you-go Windows Server 2025 licensing through Azure Arc for organizations that want off the licensing cycle. The report maps all of this to your actual position; the purchase itself is separate.
How is this different from the Azure Migrate Datacenter Discovery and Assessment?
That engagement answers 'what should move to Azure and what will it cost to run there' for a whole estate, using two weeks of observed utilization to right-size and price it. This one answers 'what do we do with each Windows Server 2016 host before 12 January 2027' — role by role, with upgrade, rebuild, ESU and retire on the table alongside Azure — and it is what an infrastructure lead needs when the driver is a date rather than a datacenter exit. Estates that need both usually run this first; if the verdicts send a large slice to Azure, the Azure Migrate assessment picks up with the appliance already collecting.
Do you install agents on our servers?
No persistent agents. On VMware, discovery and dependency data come through vCenter APIs; on Hyper-V, through the hosts; on physical servers, through standard remote management. Where your policy rules out an appliance altogether, your own staff run our read-only inventory scripts and return the output. Every credential is agreed in writing and read-only wherever the platform allows, and we ask for the least access the job needs — never Domain Admin for an assessment.
We have more than 25 servers, and some are 2012 R2 or 2019. What then?
The fixed fee covers up to 25 assessed hosts of whatever version you put in scope — 2012 R2 hosts facing the 13 October 2026 ESU end and 2019 or 2022 hosts you want on the same matrix can all ride along. Above 25, or across several datacenters, we quote per estate in writing before anything starts, and the price is fixed once agreed. Discovery itself sees whatever it can reach; the fee is about how many servers get the full role, compatibility and verdict treatment.
Is two weeks really enough?
For up to 25 hosts, yes — provided discovery starts in the first two days and your application owners answer questions in days, not weeks. Discovery and reconciliation take the first week; role analysis, compatibility, licensing and the cost comparison the second; the wave plan and presentation close it out. Where an estate's vendor answers arrive late, the report ships on time with those items marked 'unconfirmed' and named, rather than the whole roadmap waiting on one vendor.
What happens after the assessment — and can we take the roadmap elsewhere?
You decide, from evidence. Most organizations convert wave one into fixed per-wave quotes with us; some hand the plan to their own engineers; some take it to another provider. All three are legitimate, and the inventory, matrix, cost comparison and wave plan are working files delivered to you with nothing proprietary holding them. We price execution in fixed, written, per-wave quotes so comparison is easy — and we would rather you left with an honest roadmap than stayed with a flattering one.