First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/Windows Server 2016 to 2025 Upgrade Service
Implementation

Windows Server 2016 to 2025 Upgrade — In Place or Side by Side

Windows Server 2016 to 2025 Upgrade Service moves your Windows Server 2016, 2019 and 2022 hosts to Windows Server 2025 before Microsoft's support runs out — in place where Microsoft's upgrade path, your hardware and your application vendors allow it, and side by side (a new 2025 host, roles and applications moved, cutover, old host decommissioned) where a rebuild is the safer route. IT Partner runs a per-server readiness check against Microsoft's Windows Server 2025 requirements and removed-features list, writes a disposition for every host, executes the upgrades in agreed waves with a restore-tested backup and a written rollback plan behind each one, validates every role and application with its owner, and hands over as-built documentation. $650 per server upgraded in place plus a $1,950 base fee, an estimate confirmed in writing before work begins; a typical wave of up to 25 servers takes about 4 weeks, and side-by-side rebuilds and larger estates are quoted per estate. Windows Server 2016 leaves extended support on 12 January 2027 per Microsoft's product lifecycle. Windows Server 2025 licenses and CALs are yours to buy, and Microsoft's Extended Security Update fees, if a server needs a bridge, are Microsoft's charge to you.

Timeline 4 weeksService owner Roman SotnikWindows ServerHyper-VAzure Arc

What this engagement is

Windows Server 2016 leaves extended support on 12 January 2027 per Microsoft's product lifecycle — after that date there are no security updates unless you pay Microsoft for Extended Security Updates. The same lifecycle takes Windows Server 2022 out of mainstream support on 13 October 2026 (extended support runs to 14 October 2031) and Windows Server 2019 out of extended support on 9 January 2029, so an estate that upgrades its 2016 hosts alone will be back here within two years. This service takes all three source versions to Windows Server 2025, whose mainstream support runs to 9 October 2029 and extended support to 10 October 2034 per the same lifecycle pages — the longest runway Microsoft currently sells for a server that stays on your own hardware. It is built for infrastructure teams at mid-size and enterprise organizations with dozens to hundreds of servers — on-premises, in a colocation facility or at a hosting provider — that need the estate moved in controlled waves with a rollback behind every one, not one host at a time on a Friday night. Microsoft supports two routes and we use both. An in-place upgrade keeps the server, its applications, settings and data, and replaces the operating system underneath them. Starting with Windows Server 2025, Microsoft lets a non-clustered server jump up to four versions at once, so Windows Server 2016, 2019 and 2022 (and 2012 R2) all upgrade directly to 2025 from installation media, and 2019 and 2022 hosts can also take the upgrade as a feature update through Windows Update once the cumulative update Microsoft names is installed. Microsoft's own prerequisites are the ones we enforce: a full, restore-tested backup of the operating system, applications, data and any virtual machines; a scheduled maintenance window; a valid product key and activation method; hardware that meets the Windows Server 2025 requirements; and, on a Hyper-V host, no virtual machines running during the upgrade. Side by side means a fresh Windows Server 2025 host built to your baseline, roles and data moved across with Microsoft's tools, the application reinstalled by its owner or vendor, a cutover and the old host decommissioned. It is the safer path for role servers and for hosts whose hardware, firmware or application vendor will not carry them through an in-place upgrade — and the readiness check decides per server which path applies, with the reason written down. What decides most of that is not the upgrade mechanics but what changes on the other side. Windows Server 2025 requires SMB signing by default for all outbound SMB connections, removes NTLMv1 and deprecates NTLMv2, turns on an SMB authentication rate limiter, disables TLS 1.0 and 1.1 by default, and has removed Windows PowerShell 2.0, the SMTP Server feature, the IIS 6 management console, Internet Explorer, DES and WordPad, with WSUS, the Windows Internal Database, Network Load Balancing and the WebDAV redirector deprecated — Microsoft's removed-and-deprecated-features list is our checklist. A line-of-business application that authenticates with NTLMv1 to an old appliance, a script that runs under PowerShell 2.0, a NAS that cannot sign SMB, a processor without SSE4.2 or POPCNT support: each of those is found in week one, not on upgrade night, and each gets a fix, a workaround or a side-by-side decision before its wave is scheduled. The same check confirms activation (a KMS host has to be able to issue Windows Server 2025 activations), antivirus, backup and monitoring agent support for the new version, and that Remote Desktop Session Hosts have RDS CALs of a version their license server can hand to a 2025 host. Some hosts are deliberately not upgraded in place by this service, because Microsoft or good practice says otherwise. Domain controllers: Microsoft's guidance for Windows Server 2025 is not to upgrade AD DS servers in place but to promote new domain controllers and demote the old ones, which is the Domain Services and Active Directory Roles Migration. Certificate Services, DHCP, DNS and NPS role holders, AD FS, failover clusters (which Microsoft upgrades one version at a time through a rolling upgrade), Exchange and SQL Server hosts each follow their own product's rules and have their own IT Partner service. And upgrading is not always the right answer: a workload that should leave the datacenter goes through Windows Server Migration to Azure from a Physical Server or VMware to Azure Virtual Machine Migration instead, and a host that cannot be upgraded before 12 January 2027 can be bridged with Microsoft's Extended Security Updates — bought through volume licensing or enabled through Azure Arc and billed by Microsoft per core, to you. We deliver all of those services, which is why the disposition on your inventory says upgrade, rebuild, bridge or move per host — not upgrade for everything.

Which one applies to you

Every server on your inventory gets one of three dispositions in the readiness check. The first is priced on this page, the second is quoted per server, and the third is routed to the service that owns it.

In-place upgrade (this page)Side-by-side rebuild (quoted per server)Not this page
Best forApplication, file, print, web, utility and standalone Hyper-V hosts whose hardware meets the Windows Server 2025 requirements and whose application vendors support the version on an upgraded host — the majority of a typical estate.Role servers where a clean build is safer; hosts whose hardware or firmware fails the readiness check; Server Core to Desktop Experience (or the reverse) changes; evaluation installs; applications whose vendor supports Windows Server 2025 only on a fresh install.Domain controllers, AD CS, DHCP, DNS, NPS and AD FS role holders, failover clusters, Exchange and SQL Server hosts, Windows Server 2012 R2 and older, and workloads that should move to Azure instead.
How it worksReadiness check, baseline capture, verified backup, Setup from Windows Server 2025 media (or the Windows Update feature update on 2019 and 2022 hosts), post-upgrade validation, cleanup after the rollback window.New Windows Server 2025 host built to your baseline, roles and data moved, application reinstalled by its owner or vendor, parallel run, cutover, old host decommissioned.Each has its own Microsoft-documented path and its own IT Partner service; the readiness report names it and the waves are sequenced around it.
DowntimeOne maintenance window per server, with several restarts; the pilot wave measures it on your estate.Cutover only — the old host keeps serving until the switch.Set by the owning service.
RollbackSetup's go-back option during the days Windows keeps the previous installation (10 by default), or a restore from the verified backup or hypervisor checkpoint.Point users and DNS back at the old host, which is untouched until you sign its decommission.
Price$650 per server plus the $1,950 base fee — an estimate confirmed in writing.Quoted per server once the readiness check sizes the rebuild.Priced on the owning service's page.

Estates above 25 servers, and any wave plan that includes side-by-side rebuilds, are quoted per estate after the readiness check — before any upgrade starts.

Success criteria

01Every in-scope server has a written disposition — in place, side by side, or routed to another service — with the reason, the target edition and installation option, and the wave it belongs to, approved by you before the first upgrade.
02Each server upgraded in place boots Windows Server 2025, is activated, is current on Microsoft's cumulative updates, and has every role, feature, service and scheduled task recorded in its pre-upgrade baseline present and running afterwards.
03Each server rebuilt side by side carries its roles and data on the new host, users and dependent systems reach it by the agreed names, and the old host is off the network with its decommission recorded.
04The application owner named for each server has run the agreed smoke test on Windows Server 2025 and signed the wave off, and every issue found is fixed within scope or listed with an owner and a path.
05No server was upgraded without a restore-tested backup or a hypervisor checkpoint taken inside its maintenance window, and the rollback plan for every wave was written before the wave started.
06Security, backup, monitoring and patch-management tools see every upgraded server as a Windows Server 2025 host, and the SMB signing, NTLM and TLS changes on each host have been checked against the systems it talks to.
07Your administrators hold the as-built documentation — per-server before-and-after inventory, changes made, open items and the cleanup schedule for the previous installation — the handover session is complete, and you approve delivery.

What you receive

Readiness report per server: operating system, edition and installation option; hardware and firmware against the Windows Server 2025 requirements (64-bit processor with SLAT, NX and DEP, CMPXCHG16b, LAHF/SAHF, PrefetchW, SSE4.2 and POPCNT; at least 32 GB of free disk; UEFI, Secure Boot and TPM 2.0 status); activation method; roles, features, applications and agents installed; and the dependencies Windows Server 2025 changes — NTLMv1, SMB signing, TLS 1.0 and 1.1, Windows PowerShell 2.0, and the removed and deprecated components.
Disposition and wave plan: in place, side by side or routed elsewhere for every server, with the reason; a pilot wave and production waves grouped by dependency and business owner; maintenance windows; go/no-go and rollback criteria per wave; and the estimate confirmed in writing.
Pre-upgrade baseline for each server: exported system information, role and feature list, installed programs, services, scheduled tasks, network configuration, local certificates and the product key or activation record — the document the post-upgrade validation is checked against.
Backup and rollback readiness: confirmation that a restorable backup exists and has been restore-tested for each server (or a hypervisor checkpoint plan for virtual machines), the retention of the previous installation agreed, and the written rollback plan per wave.
In-place upgrades executed in the agreed windows from Windows Server 2025 installation media — or, on Windows Server 2019 and 2022 hosts where you prefer it, the Windows Update feature update — with antivirus and vendor agents handled as their vendors require, the edition kept or moved from Standard to Datacenter as licensed, and the server brought current on Microsoft updates afterwards.
Side-by-side rebuilds where selected: the new Windows Server 2025 host installed and joined to your domain to the agreed baseline, roles and data moved with Microsoft's tools (Robocopy or DFS Replication for file data, Web Deploy for IIS sites, role-native export and import elsewhere), the application reinstalled by its owner or vendor, cutover, and decommission of the old host.
Role-specific validation per server: file and DFS shares and permissions, print queues, IIS sites and application pools, Remote Desktop Session Host connectivity and licensing, standalone Hyper-V guests started and reachable, scheduled tasks, certificates, and the application owner's smoke test — recorded per host.
Post-upgrade hardening notes for the Windows Server 2025 defaults: where SMB signing, NTLM and TLS changes touched a connection and what was done, and which optional protections — SMB NTLM blocking, Hotpatch through Azure Arc — you can turn on next.
As-built documentation and handover: per-server before-and-after inventory, changes made, issues and resolutions, open items with owners, the previous-installation cleanup schedule, and a handover session with your administrators.

How the work unfolds

Week 1, days 1–3 — Kickoff, inventory and readiness check

Kickoff to confirm the server list, owners, maintenance windows and the date driving the work. IT Partner collects the inventory remotely (a read-only script, or your CMDB export), checks each host against Microsoft's Windows Server 2025 requirements and removed-features list, confirms activation and licensing status, and collects application vendor support statements from the owners.

Week 1, days 4–5 — Dispositions, wave plan and written estimate

Deliver the readiness report, the per-server disposition, the pilot and production waves, the rollback criteria and the written estimate. You approve the plan; nothing is upgraded before that, and any server that fails the check or belongs to another service is named now.

Week 2 — Pilot wave

Two or three representative, lower-risk servers go first: backup verified, baseline captured, upgrade run, validation with the application owner, findings folded into the runbook. The pilot proves the window length, the agent handling and the rollback steps on your estate before anything critical moves.

Weeks 2–3 — Production waves

In-place upgrades run in the agreed windows, wave by wave; side-by-side hosts are built in parallel and cut over with their owners. Each wave closes with its validation record and a go/no-go for the next.

Week 4 — Validation, hardening notes and cleanup

Remaining validation with owners, the post-upgrade hardening notes, confirmation that security, backup and monitoring tools see the new version on every host, and the cleanup schedule for the previous installation once each server's rollback window has passed.

Week 4 — Documentation and handover

As-built documentation delivered, open items assigned, handover session with your administrators, and delivery approved. Estates above 25 servers repeat the wave cycle on the schedule the written quote states.

Prerequisites

An inventory of the servers in scope — hostname, operating system version and edition, physical or virtual (and the hypervisor), roles and applications, hardware model, and a named owner per server — or access for us to collect it remotely in week 1.
Windows Server 2025 licenses for every upgraded host, including CALs and, for Remote Desktop Session Hosts, RDS CALs, in hand before the first wave: through Software Assurance or subscription new-version rights, a CSP perpetual purchase, or Microsoft's pay-as-you-go option for Azure Arc-connected servers. We confirm what you hold in the readiness check and route the purchase to Microsoft Volume Licensing; our Windows Server licensing calculator gives a first count.
A restorable backup of each server, restore-tested within the last quarter or tested in week 1, plus rights to take hypervisor checkpoints of virtual machines. Where no restorable backup exists, Azure Backup for servers can be put in place ahead of this project.
Hardware that meets Microsoft's Windows Server 2025 requirements, and vendor driver support for the storage controllers, network adapters and management agents on that model. Hosts that fail the check are rebuilt on supported hardware you provide, or routed to another path.
A valid activation path for Windows Server 2025: a KMS host able to activate 2025 clients, Active Directory-based activation, or MAK keys.
Windows Server 2025 installation media matching each host's edition and language — or, for the Windows Update path on 2019 and 2022 hosts, the cumulative update Microsoft names installed and the feature update controllable through your patch tooling.
Application vendor support statements for Windows Server 2025 for every line-of-business application on an in-place host, and an application owner available for the smoke test in that host's wave.
Administrative access for IT Partner: a domain account with local administrator rights on the in-scope servers, hypervisor console access for virtual machines, out-of-band management (iDRAC, iLO or equivalent) for physical hosts, and the ability to remove all of it when the work is done.
Agreed maintenance windows per wave with a change freeze on the servers in it, and a change-approval process that can turn the wave plan around within the 4-week schedule.
Windows Server 2016, 2019 or 2022 as the source, non-clustered, activated and current on updates. Windows Server 2012 R2 and older hosts, failover clusters, and servers holding the excluded roles are scoped through their own services.

Who does what

IT Partner

  • Run the kickoff, collect the inventory, and produce the readiness report, dispositions, wave plan and written estimate.
  • Capture the pre-upgrade baseline, confirm backup and rollback readiness, and execute each in-place upgrade in its agreed window.
  • Build, migrate, cut over and decommission side-by-side hosts where that disposition was approved.
  • Validate every server against its baseline and role, run the owner smoke test with them, and fix upgrade-related issues within scope.
  • Document the Windows Server 2025 default changes that touched a connection and what was done, and deliver the as-built documentation and handover.
  • Say plainly when a server should not be upgraded in place, and which service or path it belongs to.
  • Remove the access granted for the work at closeout.

Your team

  • Provide the inventory, the owners, hypervisor and out-of-band access, and the administrative credentials before kickoff.
  • Buy and hold the Windows Server 2025 licenses, CALs and RDS CALs, and own licensing compliance; Microsoft's Extended Security Update, Azure and pay-as-you-go charges are billed by Microsoft to you.
  • Approve the disposition and wave plan and the maintenance windows, and hold the change freeze during each wave.
  • Provide application vendor support statements and make application owners available for smoke tests and sign-off in their wave.
  • Own application upgrades, reinstallations or vendor engagements the readiness check calls for, or commission them separately.
  • Provide replacement hardware where a host fails the readiness check and you choose to rebuild.
  • Review the deliverables and approve delivery, or report defects, within the schedule.

What's not included

Windows Server 2025 licenses, CALs, RDS CALs and Software Assurance or subscription purchases — yours, at Microsoft's or your reseller's price. We route the purchase to Microsoft Volume Licensing and count what you need in the readiness check; the upgrade rights are not inside this fee.
Application upgrades, vendor re-certification, code changes, or reinstallation labor beyond what a side-by-side move needs — application vendors and owners own their products; we tell you what Windows Server 2025 changed and what the vendor has to answer for.
Hardware, firmware and storage replacement — hosts that fail the readiness check are rebuilt on hardware you provide.
Domain controllers and Active Directory roles. Microsoft's guidance is to promote new Windows Server 2025 domain controllers rather than upgrade in place; that work, with FSMO moves and the adprep steps, is the Domain Services and Active Directory Roles Migration, and the health and hardening of the directory before you touch it is the Active Directory Security Assessment and Hardening. Active Directory Certificate Services, DHCP, DNS, NPS and AD FS role moves are separate services as well.
SQL Server upgrades and host moves. A SQL Server version that Microsoft's operating-system support matrix does not list for Windows Server 2025 — SQL Server 2016 among them — has to be upgraded or moved first; see the SQL Server to Azure Migration Assessment and our SQL Server migration services such as SQL Server Migration to Azure VM, or the SQL Server in-place upgrade service where the database stays on your hardware.
Exchange Server. Exchange 2016 and 2019 left support on 14 October 2025 and Exchange Server SE sets its own operating-system rules; the Exchange services, from Hybrid Microsoft 365 Migration from your own Exchange Server to Exchange Server Decommissioning, own those hosts.
Failover clusters, including clustered Hyper-V hosts — Microsoft upgrades clusters one version at a time through Cluster OS Rolling Upgrade, which is a different engagement.
Moving the workload to Azure instead of upgrading it — Windows Server Migration to Azure from a Physical Server, VMware to Azure Virtual Machine Migration, or the Azure Migrate Datacenter Discovery and Assessment when that decision is still open.
Extended Security Updates enrollment and Microsoft's ESU fees. ESU for Windows Server 2016 is bought through volume licensing or enabled through Azure Arc and billed by Microsoft per core, to you; onboarding servers to Arc is the Azure Arc Hybrid Server Management Implementation.
Windows Server 2012 R2 and older hosts, whose Extended Security Updates ended on 13 October 2026 per Microsoft's product lifecycle. Microsoft's four-version rule technically permits a 2012 R2 in-place upgrade, but the hardware and application age on those hosts almost always calls for a rebuild or an exit plan, scoped on request.
Ongoing patching, monitoring and administration after handover, and a patch-management platform. Azure Update Manager schedules and Hotpatch for Windows Server 2025 are set up through the Azure Arc service; organizations that buy their Microsoft licensing through IT Partner get break-fix support during business hours at no extra charge.

Limitations & technical notes

!The $650 per server plus $1,950 base fee is an estimate for in-place upgrades of Windows Server 2016, 2019 and 2022 hosts in waves of up to 25 servers, confirmed as a written quote after the readiness check and before any upgrade starts. Side-by-side rebuilds are quoted per server, and estates above 25 servers or with mixed dispositions are quoted per estate. Client-side delays — windows missed, licenses not in hand, owners unavailable — move the completion date, not the scope.
!Microsoft's in-place upgrade rules bound what we can do: non-clustered servers only; the same installation option (Server Core stays Server Core, Desktop Experience stays Desktop Experience); the same or a higher edition (Standard can become Datacenter, not the reverse); the same language; and evaluation installs converted to a licensed edition first. Clusters upgrade one version at a time through a rolling upgrade, which is a separate engagement.
!Windows Server 2025 changes defaults that reach beyond the upgraded host. SMB signing is required by default for all outbound SMB connections, NTLMv1 is removed and NTLMv2 deprecated, an SMB authentication rate limiter is on by default, TLS 1.0 and 1.1 are disabled by default, and Windows PowerShell 2.0, the SMTP Server feature, the IIS 6 management console, Internet Explorer, DES and WordPad are gone. Connections to appliances, NAS devices and legacy applications that depend on any of these fail after the upgrade unless the readiness check finds them first — which is what it is for — and the fix may sit with a vendor rather than with us.
!The processor requirements are real: Windows Server 2025 needs a 1.4 GHz 64-bit processor with SLAT, NX and DEP, CMPXCHG16b, LAHF/SAHF, PrefetchW, SSE4.2 and POPCNT, and at least 32 GB of disk. TPM 2.0, UEFI and Secure Boot are required only for the features that use them, such as BitLocker and Secured-core, but a host still booting legacy BIOS gets a rebuild recommendation rather than an upgrade, because the security features a new version is meant to bring need UEFI.
!Microsoft's guidance is not to upgrade domain controllers in place for Windows Server 2025 — an upgraded DC does not receive the Active Directory improvements a freshly promoted one does — and we follow it; the AD service does that work.
!An in-place upgrade preserves what is on the server, including configuration drift, stale drivers and undocumented dependencies. Where those surface after the upgrade, we fix upgrade-related issues within scope and document the rest with an owner; we do not remediate years of accumulated state under this fee.
!Rollback for an in-place upgrade is Setup's go-back option during the days Windows keeps the previous installation (10 by default), or a restore from your backup or hypervisor checkpoint. Both are planned per wave; neither is instant, and a checkpoint of a busy application server taken hours earlier is a recovery point, not a time machine. Side-by-side hosts roll back by pointing users and DNS at the old host.
!Hyper-V hosts: Microsoft requires that no virtual machines run during the upgrade of the host, so guests are shut down or moved off for the window, and their configuration versions are raised only after you confirm you will not roll the host back, because raising them is one-way. The guests themselves are upgraded as servers on their own line of the inventory.
!Activation and licensing are checked, not supplied. A KMS host that cannot issue Windows Server 2025 activations, missing CALs, or RDS CALs older than the session host's version leave the server unactivated or users unlicensed after the upgrade; the readiness check flags each, and the fix is a purchase or an activation change you make.
!The Windows Update feature-update path is offered by Microsoft only to Windows Server 2019 and 2022 hosts with the cumulative update Microsoft names, and it upgrades the host as it finds it — no edition change, no media. It is convenient inside Microsoft's rules; it has also been reported to upgrade servers nobody intended to upgrade when third-party patch tools treated the optional feature update as a security update, so we confirm the update is held in your patch tooling before the waves start and released per wave.
!Lifecycle dates on this page — Windows Server 2016 extended support ending 12 January 2027, 2019 ending 9 January 2029, 2022 mainstream ending 13 October 2026 and extended 14 October 2031, 2025 mainstream to 9 October 2029 and extended to 10 October 2034, Windows Server 2012 R2 ESU ending 13 October 2026 — are Microsoft's product lifecycle dates at the time of writing. ESU terms, prices and Azure Arc billing are Microsoft's, and the charges are yours. Where an upgrade hits a Microsoft product defect, escalation to Microsoft under our Premier Support agreement is available as a paid add-on.
!Technical content reviewed September 2026.

Frequently asked questions

Can Windows Server 2016 be upgraded directly to Windows Server 2025?

Yes. Starting with Windows Server 2025, Microsoft lets a non-clustered server upgrade up to four versions at once, so Windows Server 2012 R2, 2016, 2019 and 2022 all have a supported in-place path to 2025 from installation media. Windows Server 2019 and 2022 hosts can additionally take the upgrade as a feature update through Windows Update once the cumulative update Microsoft names is installed; 2016 hosts always use media. Whether a particular server should be upgraded in place is a different question — hardware, firmware, vendor support and the role it holds decide that, which is what the readiness check is for.

What does the service include?

A per-server readiness check against Microsoft's Windows Server 2025 requirements and removed-features list; a disposition and wave plan you approve; a pre-upgrade baseline, a restore-tested backup and a written rollback plan per wave; in-place upgrades executed in agreed windows, or side-by-side rebuilds where that is the safer path; role-specific validation with the application owner; hardening notes on the Windows Server 2025 defaults that touched your connections; and as-built documentation with a handover session. Licenses, hardware and application upgrades are yours; the excluded roles go to their own services.

How much does it cost?

$650 per server upgraded in place plus a $1,950 base fee — an estimate for a wave of up to 25 servers, confirmed as a written quote after the readiness check and before any upgrade starts; you pay after you approve delivery. Ten servers upgraded in place come to $8,450. Side-by-side rebuilds are quoted per server, and estates above 25 servers are quoted per estate. Windows Server 2025 licenses, CALs, hardware, and Microsoft's Extended Security Update or Azure charges are separate and yours.

How long does it take?

About 4 weeks for a typical wave of up to 25 servers: readiness and the plan in week 1, a pilot wave in week 2, production waves in weeks 2 and 3, validation, cleanup and documentation in week 4. Each server's own upgrade is one maintenance window with several restarts. Larger estates run the wave cycle repeatedly on the schedule the quote states, and side-by-side rebuilds add build and cutover time per host. Client-side delays move the completion date, not the scope.

In place or side by side — how do you decide?

Per server, in the readiness check, with the reason written down. In place wins where the hardware meets Microsoft's requirements, the application vendor supports Windows Server 2025 on an upgraded host, the roles are the plain application, file, print, web or utility kind, and the server is not one of the excluded role holders — that is most of a typical estate, and it leaves applications, settings and data where they are. Side by side wins where the hardware or firmware fails the check, the vendor supports the new version only on a clean install, the installation option or edition has to change in a direction Microsoft's upgrade will not allow, or the role is one where a fresh build is simply safer. The table on this page is the short version.

What can break after an upgrade to Windows Server 2025?

Mostly things that talk to the server rather than the server itself. SMB signing is required by default for outbound connections, so a NAS or appliance that cannot sign stops being reachable from the host. NTLMv1 is removed, so an application or device that still authenticates with it fails. TLS 1.0 and 1.1 are disabled by default. Windows PowerShell 2.0 is gone, so scripts pinned to it stop. The SMTP Server feature, the IIS 6 management console, Internet Explorer and WordPad are removed, and WSUS, Network Load Balancing, the Windows Internal Database and the WebDAV redirector are deprecated. Antivirus, backup and monitoring agents may need a supported version. The readiness check exists to find every one of these in week one; the fix is sometimes ours, sometimes a vendor's, and occasionally a side-by-side decision.

Will our existing hardware run Windows Server 2025?

Most hardware from the last several years will; some older hosts will not. Microsoft requires a 1.4 GHz 64-bit processor with SLAT, NX and DEP, CMPXCHG16b, LAHF/SAHF, PrefetchW, SSE4.2 and the POPCNT instruction, at least 2 GB of RAM (4 GB recommended with Desktop Experience) and 32 GB of disk. TPM 2.0, UEFI and Secure Boot are required only for the features that depend on them, but a host still booting legacy BIOS is a rebuild candidate in our book. Vendor driver support for the storage controller and network adapters on that model matters as much as the CPU list, and it is on the readiness check too.

Do we need new licenses or CALs?

Yes, and they are yours to buy. Windows Server 2025 is licensed per core — Microsoft's licensing guide sets a minimum of 8 core licenses per processor and 16 per server — with CALs for every user or device that accesses the servers, and RDS CALs of a compatible version for Remote Desktop Session Hosts. Software Assurance or subscription licenses carry new-version rights; otherwise the licenses are bought as CSP perpetual products or, for Windows Server 2025 hosts connected to Azure Arc, through Microsoft's pay-as-you-go option billed to your Azure subscription. Our Windows Server licensing calculator gives a first count and Microsoft Volume Licensing handles the purchase; neither is part of this fee.

Can you upgrade our domain controllers, DHCP, DNS or certificate servers in the same waves?

Not under this service, on purpose. Microsoft's guidance for Windows Server 2025 is not to upgrade a domain controller in place but to promote new 2025 domain controllers and demote the old ones — an upgraded DC misses the Active Directory improvements a fresh one gets — and that work, with the FSMO moves and adprep steps, is the Domain Services and Active Directory Roles Migration. Certificate Services, DHCP, DNS, NPS and AD FS have their own migration steps and their own services. The readiness check still inventories those hosts so the whole estate has one plan; the work runs through the owning service, sequenced with these waves.

What about SQL Server or Exchange running on a host?

Those hosts are dispositioned to their own services. Microsoft publishes an operating-system support matrix for SQL Server, and older versions — SQL Server 2016 among them — are not listed for Windows Server 2025, so upgrading the host underneath a SQL Server 2016 instance leaves you unsupported twice over; the database is upgraded or moved first. Exchange 2016 and 2019 left support on 14 October 2025, and Exchange Server SE decides its own operating-system requirements, so Exchange hosts follow the Exchange services. We tell you which host is which in the readiness report rather than discover it on upgrade night.

We will not get everything done by 12 January 2027. What then?

Three honest options, per server. Bridge with Microsoft's Extended Security Updates for Windows Server 2016 — Microsoft's published guidance at the time of writing makes them available for up to three years after end of support, bought through volume licensing or enabled through Azure Arc and billed by Microsoft per core, to you. Move the workload to Azure, where the migration itself changes the support picture. Or isolate the server and plan its exit. We deliver all three paths; the wave plan puts the 2016 hosts first so the bridge is as small as possible, and the readiness report says which servers need it.

Should we upgrade, or move these servers to Azure instead?

It depends on the server, and we will say so rather than sell the upgrade. A host whose application is staying on your hardware for years is an upgrade. A host at the end of its hardware life, or one whose workload the business wants out of the datacenter, is usually a migration — Windows Server Migration to Azure from a Physical Server for standalone hosts, VMware to Azure Virtual Machine Migration for a virtual estate — and the Azure Migrate Datacenter Discovery and Assessment prices that alternative from real utilization data when the decision is still open. Many estates do both: upgrade what stays, migrate what leaves, and the readiness report is the same document either way.

How much downtime, and what is the rollback?

In place: one maintenance window per server, with several restarts; the length depends on the host and its applications, and the pilot wave measures it on your estate before production waves are scheduled. Rollback is Setup's go-back option during the days Windows keeps the previous installation (10 by default), or a restore from the verified backup or hypervisor checkpoint — both written into the wave plan before the wave starts. Side by side: no downtime until the cutover, and rollback is pointing users and DNS back at the old host, which stays untouched until you sign its decommission.

What happens after the upgrade — patching, hotpatching, support?

You leave with as-built documentation and a current, activated Windows Server 2025 estate. Two things worth doing next: connecting the hosts to Azure Arc, which is where Microsoft delivers Hotpatch for Windows Server 2025 — security updates with far fewer restarts, made available at no extra cost in mid-2026 — along with Azure Update Manager patching schedules, through the Azure Arc Hybrid Server Management Implementation; and working through the hardening notes to turn on the protections Windows Server 2025 makes available, such as SMB NTLM blocking. Organizations that buy their Microsoft licensing through IT Partner get unlimited break-fix support during business hours at no extra charge; 24/7 coverage is a separate paid agreement.

Who owns this service at IT Partner?

Roman Sotnik is the service owner. IT Partner has been a Microsoft partner since 2006 and holds the Solutions Partner for Infrastructure designation; this service sits beside our Active Directory, SQL Server, Exchange and Azure migration practices, which is why a host that should not be upgraded in place is routed to the right team instead of forced through.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$650 per server + $1,950 tenant fee
4 weeks
Book a server upgrade scoping call