Windows Server 2016 to 2025 Upgrade — In Place or Side by Side
Windows Server 2016 to 2025 Upgrade Service moves your Windows Server 2016, 2019 and 2022 hosts to Windows Server 2025 before Microsoft's support runs out — in place where Microsoft's upgrade path, your hardware and your application vendors allow it, and side by side (a new 2025 host, roles and applications moved, cutover, old host decommissioned) where a rebuild is the safer route. IT Partner runs a per-server readiness check against Microsoft's Windows Server 2025 requirements and removed-features list, writes a disposition for every host, executes the upgrades in agreed waves with a restore-tested backup and a written rollback plan behind each one, validates every role and application with its owner, and hands over as-built documentation. $650 per server upgraded in place plus a $1,950 base fee, an estimate confirmed in writing before work begins; a typical wave of up to 25 servers takes about 4 weeks, and side-by-side rebuilds and larger estates are quoted per estate. Windows Server 2016 leaves extended support on 12 January 2027 per Microsoft's product lifecycle. Windows Server 2025 licenses and CALs are yours to buy, and Microsoft's Extended Security Update fees, if a server needs a bridge, are Microsoft's charge to you.
What this engagement is
Windows Server 2016 leaves extended support on 12 January 2027 per Microsoft's product lifecycle — after that date there are no security updates unless you pay Microsoft for Extended Security Updates. The same lifecycle takes Windows Server 2022 out of mainstream support on 13 October 2026 (extended support runs to 14 October 2031) and Windows Server 2019 out of extended support on 9 January 2029, so an estate that upgrades its 2016 hosts alone will be back here within two years. This service takes all three source versions to Windows Server 2025, whose mainstream support runs to 9 October 2029 and extended support to 10 October 2034 per the same lifecycle pages — the longest runway Microsoft currently sells for a server that stays on your own hardware. It is built for infrastructure teams at mid-size and enterprise organizations with dozens to hundreds of servers — on-premises, in a colocation facility or at a hosting provider — that need the estate moved in controlled waves with a rollback behind every one, not one host at a time on a Friday night. Microsoft supports two routes and we use both. An in-place upgrade keeps the server, its applications, settings and data, and replaces the operating system underneath them. Starting with Windows Server 2025, Microsoft lets a non-clustered server jump up to four versions at once, so Windows Server 2016, 2019 and 2022 (and 2012 R2) all upgrade directly to 2025 from installation media, and 2019 and 2022 hosts can also take the upgrade as a feature update through Windows Update once the cumulative update Microsoft names is installed. Microsoft's own prerequisites are the ones we enforce: a full, restore-tested backup of the operating system, applications, data and any virtual machines; a scheduled maintenance window; a valid product key and activation method; hardware that meets the Windows Server 2025 requirements; and, on a Hyper-V host, no virtual machines running during the upgrade. Side by side means a fresh Windows Server 2025 host built to your baseline, roles and data moved across with Microsoft's tools, the application reinstalled by its owner or vendor, a cutover and the old host decommissioned. It is the safer path for role servers and for hosts whose hardware, firmware or application vendor will not carry them through an in-place upgrade — and the readiness check decides per server which path applies, with the reason written down. What decides most of that is not the upgrade mechanics but what changes on the other side. Windows Server 2025 requires SMB signing by default for all outbound SMB connections, removes NTLMv1 and deprecates NTLMv2, turns on an SMB authentication rate limiter, disables TLS 1.0 and 1.1 by default, and has removed Windows PowerShell 2.0, the SMTP Server feature, the IIS 6 management console, Internet Explorer, DES and WordPad, with WSUS, the Windows Internal Database, Network Load Balancing and the WebDAV redirector deprecated — Microsoft's removed-and-deprecated-features list is our checklist. A line-of-business application that authenticates with NTLMv1 to an old appliance, a script that runs under PowerShell 2.0, a NAS that cannot sign SMB, a processor without SSE4.2 or POPCNT support: each of those is found in week one, not on upgrade night, and each gets a fix, a workaround or a side-by-side decision before its wave is scheduled. The same check confirms activation (a KMS host has to be able to issue Windows Server 2025 activations), antivirus, backup and monitoring agent support for the new version, and that Remote Desktop Session Hosts have RDS CALs of a version their license server can hand to a 2025 host. Some hosts are deliberately not upgraded in place by this service, because Microsoft or good practice says otherwise. Domain controllers: Microsoft's guidance for Windows Server 2025 is not to upgrade AD DS servers in place but to promote new domain controllers and demote the old ones, which is the Domain Services and Active Directory Roles Migration. Certificate Services, DHCP, DNS and NPS role holders, AD FS, failover clusters (which Microsoft upgrades one version at a time through a rolling upgrade), Exchange and SQL Server hosts each follow their own product's rules and have their own IT Partner service. And upgrading is not always the right answer: a workload that should leave the datacenter goes through Windows Server Migration to Azure from a Physical Server or VMware to Azure Virtual Machine Migration instead, and a host that cannot be upgraded before 12 January 2027 can be bridged with Microsoft's Extended Security Updates — bought through volume licensing or enabled through Azure Arc and billed by Microsoft per core, to you. We deliver all of those services, which is why the disposition on your inventory says upgrade, rebuild, bridge or move per host — not upgrade for everything.
Which one applies to you
Every server on your inventory gets one of three dispositions in the readiness check. The first is priced on this page, the second is quoted per server, and the third is routed to the service that owns it.
| In-place upgrade (this page) | Side-by-side rebuild (quoted per server) | Not this page | |
|---|---|---|---|
| Best for | Application, file, print, web, utility and standalone Hyper-V hosts whose hardware meets the Windows Server 2025 requirements and whose application vendors support the version on an upgraded host — the majority of a typical estate. | Role servers where a clean build is safer; hosts whose hardware or firmware fails the readiness check; Server Core to Desktop Experience (or the reverse) changes; evaluation installs; applications whose vendor supports Windows Server 2025 only on a fresh install. | Domain controllers, AD CS, DHCP, DNS, NPS and AD FS role holders, failover clusters, Exchange and SQL Server hosts, Windows Server 2012 R2 and older, and workloads that should move to Azure instead. |
| How it works | Readiness check, baseline capture, verified backup, Setup from Windows Server 2025 media (or the Windows Update feature update on 2019 and 2022 hosts), post-upgrade validation, cleanup after the rollback window. | New Windows Server 2025 host built to your baseline, roles and data moved, application reinstalled by its owner or vendor, parallel run, cutover, old host decommissioned. | Each has its own Microsoft-documented path and its own IT Partner service; the readiness report names it and the waves are sequenced around it. |
| Downtime | One maintenance window per server, with several restarts; the pilot wave measures it on your estate. | Cutover only — the old host keeps serving until the switch. | Set by the owning service. |
| Rollback | Setup's go-back option during the days Windows keeps the previous installation (10 by default), or a restore from the verified backup or hypervisor checkpoint. | Point users and DNS back at the old host, which is untouched until you sign its decommission. | — |
| Price | $650 per server plus the $1,950 base fee — an estimate confirmed in writing. | Quoted per server once the readiness check sizes the rebuild. | Priced on the owning service's page. |
Estates above 25 servers, and any wave plan that includes side-by-side rebuilds, are quoted per estate after the readiness check — before any upgrade starts.
Success criteria
What you receive
How the work unfolds
Kickoff to confirm the server list, owners, maintenance windows and the date driving the work. IT Partner collects the inventory remotely (a read-only script, or your CMDB export), checks each host against Microsoft's Windows Server 2025 requirements and removed-features list, confirms activation and licensing status, and collects application vendor support statements from the owners.
Deliver the readiness report, the per-server disposition, the pilot and production waves, the rollback criteria and the written estimate. You approve the plan; nothing is upgraded before that, and any server that fails the check or belongs to another service is named now.
Two or three representative, lower-risk servers go first: backup verified, baseline captured, upgrade run, validation with the application owner, findings folded into the runbook. The pilot proves the window length, the agent handling and the rollback steps on your estate before anything critical moves.
In-place upgrades run in the agreed windows, wave by wave; side-by-side hosts are built in parallel and cut over with their owners. Each wave closes with its validation record and a go/no-go for the next.
Remaining validation with owners, the post-upgrade hardening notes, confirmation that security, backup and monitoring tools see the new version on every host, and the cleanup schedule for the previous installation once each server's rollback window has passed.
As-built documentation delivered, open items assigned, handover session with your administrators, and delivery approved. Estates above 25 servers repeat the wave cycle on the schedule the written quote states.
Prerequisites
Who does what
IT Partner
- Run the kickoff, collect the inventory, and produce the readiness report, dispositions, wave plan and written estimate.
- Capture the pre-upgrade baseline, confirm backup and rollback readiness, and execute each in-place upgrade in its agreed window.
- Build, migrate, cut over and decommission side-by-side hosts where that disposition was approved.
- Validate every server against its baseline and role, run the owner smoke test with them, and fix upgrade-related issues within scope.
- Document the Windows Server 2025 default changes that touched a connection and what was done, and deliver the as-built documentation and handover.
- Say plainly when a server should not be upgraded in place, and which service or path it belongs to.
- Remove the access granted for the work at closeout.
Your team
- Provide the inventory, the owners, hypervisor and out-of-band access, and the administrative credentials before kickoff.
- Buy and hold the Windows Server 2025 licenses, CALs and RDS CALs, and own licensing compliance; Microsoft's Extended Security Update, Azure and pay-as-you-go charges are billed by Microsoft to you.
- Approve the disposition and wave plan and the maintenance windows, and hold the change freeze during each wave.
- Provide application vendor support statements and make application owners available for smoke tests and sign-off in their wave.
- Own application upgrades, reinstallations or vendor engagements the readiness check calls for, or commission them separately.
- Provide replacement hardware where a host fails the readiness check and you choose to rebuild.
- Review the deliverables and approve delivery, or report defects, within the schedule.
What's not included
Limitations & technical notes
Frequently asked questions
Can Windows Server 2016 be upgraded directly to Windows Server 2025?
Yes. Starting with Windows Server 2025, Microsoft lets a non-clustered server upgrade up to four versions at once, so Windows Server 2012 R2, 2016, 2019 and 2022 all have a supported in-place path to 2025 from installation media. Windows Server 2019 and 2022 hosts can additionally take the upgrade as a feature update through Windows Update once the cumulative update Microsoft names is installed; 2016 hosts always use media. Whether a particular server should be upgraded in place is a different question — hardware, firmware, vendor support and the role it holds decide that, which is what the readiness check is for.
What does the service include?
A per-server readiness check against Microsoft's Windows Server 2025 requirements and removed-features list; a disposition and wave plan you approve; a pre-upgrade baseline, a restore-tested backup and a written rollback plan per wave; in-place upgrades executed in agreed windows, or side-by-side rebuilds where that is the safer path; role-specific validation with the application owner; hardening notes on the Windows Server 2025 defaults that touched your connections; and as-built documentation with a handover session. Licenses, hardware and application upgrades are yours; the excluded roles go to their own services.
How much does it cost?
$650 per server upgraded in place plus a $1,950 base fee — an estimate for a wave of up to 25 servers, confirmed as a written quote after the readiness check and before any upgrade starts; you pay after you approve delivery. Ten servers upgraded in place come to $8,450. Side-by-side rebuilds are quoted per server, and estates above 25 servers are quoted per estate. Windows Server 2025 licenses, CALs, hardware, and Microsoft's Extended Security Update or Azure charges are separate and yours.
How long does it take?
About 4 weeks for a typical wave of up to 25 servers: readiness and the plan in week 1, a pilot wave in week 2, production waves in weeks 2 and 3, validation, cleanup and documentation in week 4. Each server's own upgrade is one maintenance window with several restarts. Larger estates run the wave cycle repeatedly on the schedule the quote states, and side-by-side rebuilds add build and cutover time per host. Client-side delays move the completion date, not the scope.
In place or side by side — how do you decide?
Per server, in the readiness check, with the reason written down. In place wins where the hardware meets Microsoft's requirements, the application vendor supports Windows Server 2025 on an upgraded host, the roles are the plain application, file, print, web or utility kind, and the server is not one of the excluded role holders — that is most of a typical estate, and it leaves applications, settings and data where they are. Side by side wins where the hardware or firmware fails the check, the vendor supports the new version only on a clean install, the installation option or edition has to change in a direction Microsoft's upgrade will not allow, or the role is one where a fresh build is simply safer. The table on this page is the short version.
What can break after an upgrade to Windows Server 2025?
Mostly things that talk to the server rather than the server itself. SMB signing is required by default for outbound connections, so a NAS or appliance that cannot sign stops being reachable from the host. NTLMv1 is removed, so an application or device that still authenticates with it fails. TLS 1.0 and 1.1 are disabled by default. Windows PowerShell 2.0 is gone, so scripts pinned to it stop. The SMTP Server feature, the IIS 6 management console, Internet Explorer and WordPad are removed, and WSUS, Network Load Balancing, the Windows Internal Database and the WebDAV redirector are deprecated. Antivirus, backup and monitoring agents may need a supported version. The readiness check exists to find every one of these in week one; the fix is sometimes ours, sometimes a vendor's, and occasionally a side-by-side decision.
Will our existing hardware run Windows Server 2025?
Most hardware from the last several years will; some older hosts will not. Microsoft requires a 1.4 GHz 64-bit processor with SLAT, NX and DEP, CMPXCHG16b, LAHF/SAHF, PrefetchW, SSE4.2 and the POPCNT instruction, at least 2 GB of RAM (4 GB recommended with Desktop Experience) and 32 GB of disk. TPM 2.0, UEFI and Secure Boot are required only for the features that depend on them, but a host still booting legacy BIOS is a rebuild candidate in our book. Vendor driver support for the storage controller and network adapters on that model matters as much as the CPU list, and it is on the readiness check too.
Do we need new licenses or CALs?
Yes, and they are yours to buy. Windows Server 2025 is licensed per core — Microsoft's licensing guide sets a minimum of 8 core licenses per processor and 16 per server — with CALs for every user or device that accesses the servers, and RDS CALs of a compatible version for Remote Desktop Session Hosts. Software Assurance or subscription licenses carry new-version rights; otherwise the licenses are bought as CSP perpetual products or, for Windows Server 2025 hosts connected to Azure Arc, through Microsoft's pay-as-you-go option billed to your Azure subscription. Our Windows Server licensing calculator gives a first count and Microsoft Volume Licensing handles the purchase; neither is part of this fee.
Can you upgrade our domain controllers, DHCP, DNS or certificate servers in the same waves?
Not under this service, on purpose. Microsoft's guidance for Windows Server 2025 is not to upgrade a domain controller in place but to promote new 2025 domain controllers and demote the old ones — an upgraded DC misses the Active Directory improvements a fresh one gets — and that work, with the FSMO moves and adprep steps, is the Domain Services and Active Directory Roles Migration. Certificate Services, DHCP, DNS, NPS and AD FS have their own migration steps and their own services. The readiness check still inventories those hosts so the whole estate has one plan; the work runs through the owning service, sequenced with these waves.
What about SQL Server or Exchange running on a host?
Those hosts are dispositioned to their own services. Microsoft publishes an operating-system support matrix for SQL Server, and older versions — SQL Server 2016 among them — are not listed for Windows Server 2025, so upgrading the host underneath a SQL Server 2016 instance leaves you unsupported twice over; the database is upgraded or moved first. Exchange 2016 and 2019 left support on 14 October 2025, and Exchange Server SE decides its own operating-system requirements, so Exchange hosts follow the Exchange services. We tell you which host is which in the readiness report rather than discover it on upgrade night.
We will not get everything done by 12 January 2027. What then?
Three honest options, per server. Bridge with Microsoft's Extended Security Updates for Windows Server 2016 — Microsoft's published guidance at the time of writing makes them available for up to three years after end of support, bought through volume licensing or enabled through Azure Arc and billed by Microsoft per core, to you. Move the workload to Azure, where the migration itself changes the support picture. Or isolate the server and plan its exit. We deliver all three paths; the wave plan puts the 2016 hosts first so the bridge is as small as possible, and the readiness report says which servers need it.
Should we upgrade, or move these servers to Azure instead?
It depends on the server, and we will say so rather than sell the upgrade. A host whose application is staying on your hardware for years is an upgrade. A host at the end of its hardware life, or one whose workload the business wants out of the datacenter, is usually a migration — Windows Server Migration to Azure from a Physical Server for standalone hosts, VMware to Azure Virtual Machine Migration for a virtual estate — and the Azure Migrate Datacenter Discovery and Assessment prices that alternative from real utilization data when the decision is still open. Many estates do both: upgrade what stays, migrate what leaves, and the readiness report is the same document either way.
How much downtime, and what is the rollback?
In place: one maintenance window per server, with several restarts; the length depends on the host and its applications, and the pilot wave measures it on your estate before production waves are scheduled. Rollback is Setup's go-back option during the days Windows keeps the previous installation (10 by default), or a restore from the verified backup or hypervisor checkpoint — both written into the wave plan before the wave starts. Side by side: no downtime until the cutover, and rollback is pointing users and DNS back at the old host, which stays untouched until you sign its decommission.
What happens after the upgrade — patching, hotpatching, support?
You leave with as-built documentation and a current, activated Windows Server 2025 estate. Two things worth doing next: connecting the hosts to Azure Arc, which is where Microsoft delivers Hotpatch for Windows Server 2025 — security updates with far fewer restarts, made available at no extra cost in mid-2026 — along with Azure Update Manager patching schedules, through the Azure Arc Hybrid Server Management Implementation; and working through the hardening notes to turn on the protections Windows Server 2025 makes available, such as SMB NTLM blocking. Organizations that buy their Microsoft licensing through IT Partner get unlimited break-fix support during business hours at no extra charge; 24/7 coverage is a separate paid agreement.
Who owns this service at IT Partner?
Roman Sotnik is the service owner. IT Partner has been a Microsoft partner since 2006 and holds the Solutions Partner for Infrastructure designation; this service sits beside our Active Directory, SQL Server, Exchange and Azure migration practices, which is why a host that should not be upgraded in place is routed to the right team instead of forced through.