First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/Windows Server ESU Enrollment through Azure Arc
Implementation

Windows Server ESU Enrollment through Azure Arc

IT Partner enrolls your out-of-support Windows Server 2016 — and, while Microsoft's window is still open, Windows Server 2012 R2 — machines in Extended Security Updates (ESU) through Azure Arc, so they keep receiving Microsoft's Critical and Important security patches after the lifecycle date without being upgraded or moved. Windows Server 2016 leaves extended support on 12 January 2027 per Microsoft's product lifecycle; Microsoft opened Windows Server 2016 ESU configuration in the Azure portal on 3 August 2026, starts billing it on 13 January 2027, and offers up to three years of coverage, to January 2030. Windows Server 2012 and 2012 R2 ESU ends on 13 October 2026 — enrolling those machines now buys weeks, not years, and we say so before you spend anything. In one week we establish each server's eligibility and licensing basis (Software Assurance or an equivalent server subscription; servers running as Azure VMs need no ESU purchase at all), onboard or reuse the Azure Connected Machine agent, provision correctly sized ESU licenses in your own Azure subscription, link and activate them, verify enrollment on every machine, point Azure Update Manager at the estate, and leave you a cost model and a runbook for stopping the charge the day a server is migrated or retired. Pricing is an estimate at $35 per server plus a $1,450 base fee, confirmed in writing once the inventory is agreed; estates above about 100 servers are quoted per estate. Microsoft's ESU charge itself — metered per core and billed monthly by Microsoft to your Azure subscription — is yours and is not part of this fee.

Timeline 1 weekService owner Roman SotnikWindows ServerAzure ArcMicrosoft Azure

What this engagement is

Windows Server 2016 reaches the end of extended support on 12 January 2027 per Microsoft's product lifecycle. After that date Microsoft ships no security updates to it unless the machine is enrolled in Extended Security Updates — a paid, last-resort program that delivers only the updates Microsoft rates Critical and Important, for up to three years, with no new features, no non-security hotfixes and no design changes. Windows Server 2012 and 2012 R2 are already in their third and final ESU year, which ends on 13 October 2026. Most estates we see carry a tail of servers that cannot be upgraded or migrated before the date: an application vendor that certifies nothing newer, a line-of-business box nobody dares touch, a domain controller pair that has been 'next quarter' for three quarters running. ESU is the honest bridge for that tail, and this engagement is the mechanics of getting onto it correctly. There are two ways to buy Windows Server ESU. The classic route is through Volume Licensing, in yearly increments, with Multiple Activation Keys you deploy yourself. The route this service uses is ESU enabled by Azure Arc: the Azure Connected Machine agent connects each server outbound to Azure (version 1.62 or later for Windows Server 2016, 1.34 or later for 2012 R2), you create an ESU license resource in your own Azure subscription — Standard or Datacenter, a core count, and for Windows Server 2016 the physical-or-virtual core type chosen when each server is enabled — and link it to the machines. Delivery is keyless: no product keys to obtain or activate. The security updates themselves still arrive through whatever patching channel you run — Azure Update Manager, WSUS, Microsoft Update or Configuration Manager — and for servers enrolled this way Microsoft currently provides Azure Update Manager, Change Tracking and Inventory, and Azure Policy guest configuration at no additional Azure charge. Billing is monthly and metered per core, it counts toward an Azure consumption commitment if you have one, and it stops within days when you deactivate a license — which is what makes Arc the right channel for an estate that is actively shrinking through migration and upgrades. Microsoft also states that there is no transition from a Volume Licensing ESU into an Arc ESU for Windows Server 2016, so the channel is chosen once. The rules are where estates overspend or fall out of compliance, and encoding them is most of the value here. You must attest to Software Assurance or an equivalent server subscription for every on-premises or hosted server you enroll — SPLA-licensed hosting does not qualify for Windows Server 2016 ESU. Physical-core licenses carry a 16-core minimum per machine; virtual-core licenses an 8-core minimum per VM, and they cannot be used on physical servers. A Standard physical-core license covers up to two VMs on the host, a Datacenter license covers every VM on it, and 'Datacenter virtual cores' is not a valid combination at all — so a 16-node VMware cluster with forty-odd Windows Server 2016 VMs prices very differently as Datacenter physical cores than as Standard virtual cores, and the arithmetic has to be done before the license exists. Billing starts when a license is activated, not when it is linked; licenses provisioned after the end-of-support date are back-billed to that date in a one-time charge that Microsoft says is never waived; deactivating and reactivating bills the gap; adding cores back-bills them too. And a server that runs as an Azure VM or in Azure VMware Solution gets ESU at no additional Microsoft charge and must not be enrolled through Arc at all. Every one of those rules becomes a line in the disposition list and the cost model you sign before we activate anything. This is a one-week enrollment engagement, deliberately narrow. It does not run your monthly patching afterwards, it does not upgrade or migrate the servers, and it does not include Microsoft's ESU charges — those are metered by Microsoft to your Azure subscription and belong to you. If the servers are not in Azure Arc yet, the enrollment includes the agent rollout for the ESU population; for the fuller Arc estate — tagging, policy baselines, Defender for Cloud — our Azure Arc Hybrid Server Management implementation is the broader project, and the two chain cleanly. If you have not yet decided which servers upgrade, which migrate and which bridge on ESU, the Windows Server 2016 End of Support Assessment and Roadmap makes that decision first and hands this engagement a settled list. And because ESU is a bridge with a date on it, the closeout names the exit for every server — upgrade in place, migrate to Azure, or retire — as a recommendation, not a sales pitch.

Success criteria

01Every in-scope server has a written disposition: enroll through Arc; entitled to ESU without purchase (Azure VM, Azure VMware Solution or another Microsoft no-charge scenario); better upgraded or migrated instead; or ineligible — with the reason (edition, licensing basis, no outbound connectivity, VDI).
02The licensing basis — Software Assurance or an equivalent server subscription — is documented per server group before any ESU license is created, and the attestation you make in the Azure portal matches it.
03ESU licenses exist in your own Azure subscription with the edition, core type and core counts that Microsoft's licensing rules require for the servers they cover — no fewer than compliant, no more than necessary — and the license-to-server map is documented.
04Every enrolled server shows Connected in Azure Arc on a supported agent version and shows ESU status Enabled in the portal; on Windows Server 2016 a sample verification with azcmagent show reports Extended Security Updates as Active.
05The update delivery channel is proven: Azure Update Manager (or your existing channel) has assessed each enrolled server and installed the current security updates inside an agreed maintenance window, so the first ESU-only release after the lifecycle date has a working path.
06The Microsoft cost model — projected monthly ESU charge per license, any back-billing exposure from your enrollment date, and the no-charge exclusions — is acknowledged in writing before a license is activated.
07The billing-stop procedure has been exercised once — cores decremented or a license deactivated on a test resource, the change visible in the license state — and the runbook records what your team saw.
08Your administrators can enroll a newly discovered server, decrement cores when one is migrated, and read ESU coverage and patch compliance in the portal unaided after the handover session.

What you receive

Eligibility and licensing assessment: per-server inventory of edition, cores, physical or virtual, host and hypervisor, hosting location and licensing program, with the disposition list and the Software Assurance or server-subscription basis for every server group.
ESU licensing model: the compliant and cheapest valid combination per server group — Standard virtual cores, Standard physical cores or Datacenter physical cores — worked against Microsoft's minimums and virtualization rules, in a form you can hand to procurement or your Microsoft representative.
Azure Connected Machine agent onboarding for the ESU population — scripted, Group Policy, a Configuration Manager task sequence, or reuse of an existing Arc estate — including agent upgrades where the installed version is below Microsoft's requirement, and the network path (direct, proxy or private link) confirmed per segment.
ESU license provisioning in your Azure subscription: resource group and naming standard, licenses created in a deactivated state until you approve the cost model, then activated and linked to the right machines, with the core type selected per server at enablement.
Enrollment verification on every server — Connected status, ESU Enabled in the portal, and agent-side confirmation — with an exceptions log for anything that failed to link and its resolution or disposition.
Azure Update Manager configuration for the enrolled estate: periodic assessment, a maintenance configuration with agreed windows and update classifications, a pilot group patched first, and the compliance view your team will use — or, if you keep WSUS or Configuration Manager, confirmation that security classifications flow through it to these servers.
Microsoft cost model: projected monthly charge per license at Microsoft's rate current at engagement time, back-billing exposure from your enrollment date, consumption-commitment treatment, and a reconciliation of the first invoice line once it appears.
Cost-control runbook: how to decrement cores or deactivate a license when a server is migrated, upgraded or retired, how to add a server, how to read the ESU line in Cost Management, and a monthly checklist — because Microsoft does not stop the charge for you.
Optional Azure Policy assignments: audit that eligible Arc-enabled servers are enrolled and, where you want it, a deny on unauthorised ESU license creation or modification — using Microsoft's built-in definitions where they cover your version and custom audit where they do not.
Closeout report and handover session: enrollment reconciliation against the agreed inventory, the per-server exit recommendation — upgrade, migrate or retire — and the as-built documentation.

How the work unfolds

1. Eligibility and licensing (day 1)

Inventory the candidate estate from your CMDB, hypervisor and Active Directory; confirm edition, cores, virtualization and hosting location per server; establish the licensing basis per group; separate out servers that need no purchase (Azure VMs, Azure VMware Solution) and servers that should upgrade or migrate instead. You approve the disposition list and the licensing model before anything is created.

2. Arc onboarding or reuse (days 1–2)

Open the outbound path where needed, deploy or upgrade the Connected Machine agent across the ESU population with the mechanism that fits your estate, and reconcile Connected status against the inventory. The oldest and the most isolated machines go first, so surprises surface on day two rather than day five.

3. Licenses and cost model (day 3)

Create the ESU licenses in a deactivated state, present the cost model — monthly projection, any back-billing exposure, the no-charge exclusions — and activate only on your written acknowledgment. Link licenses to servers with the correct core type per machine.

4. Verification and update delivery (day 4)

Verify ESU status on every server, resolve link failures, configure Azure Update Manager assessment and maintenance windows (or confirm your existing channel), and patch the pilot group inside its window.

5. Controls, runbook and handover (day 5)

Exercise the billing-stop procedure on a test resource, assign the optional Azure Policy audit and deny rules, walk your team through the runbook and the portal views, and deliver the closeout report with the per-server exit recommendation.

Prerequisites

A list of the Windows Server 2016 and 2012 R2 machines you want covered — even a rough one — with, where you have it, edition, core count, physical or virtual, and where each runs; we refine it together on day one.
Windows Server 2016 or 2012 R2 Standard or Datacenter edition on each server — Microsoft offers ESU for no other edition, and we say so per machine rather than discovering it at enablement.
Software Assurance or an equivalent server subscription covering the servers you will enroll — Microsoft requires an attestation at license creation, and SPLA-licensed servers cannot use Windows Server 2016 ESU. If your licensing position is unclear, our Microsoft Volume Licensing advisory settles it first.
An Azure subscription in your tenant to hold the ESU licenses and Arc resources, and the Contributor role (or an equivalent custom role) for the engineer creating and assigning licenses — this is the subscription Microsoft's ESU charge lands on.
Outbound HTTPS (port 443) from each server to the Azure Arc and ESU endpoints — directly, through a proxy, or over private link; no inbound access is needed. Fully air-gapped servers cannot be enrolled through Arc and are flagged for the classic key-based route.
Administrative credentials and a deployment path for the agent: Group Policy, Configuration Manager, your configuration-management tooling, or approval for scripted rollout.
Maintenance windows for the pilot patch cycle, and a named decision-maker for the disposition list, the licensing model and the cost model — the attestation and the spend are yours to sign.
Acknowledgment that Microsoft bills the ESU charge per core, monthly, to your Azure subscription; that it may back-bill to the end-of-support date; and that it is separate from our fee.
For servers that also run SQL Server 2016: awareness that SQL Server ESU is a separate Microsoft program with its own enrollment — we flag those instances in the assessment rather than folding them in quietly.

Who does what

IT Partner

  • Assess eligibility, establish the licensing basis, and produce the disposition list and licensing model.
  • Onboard or upgrade the Connected Machine agent across the ESU population and reconcile Connected status against the inventory.
  • Provision, activate and link ESU licenses to the agreed model — only after the cost model is acknowledged.
  • Verify enrollment on every server, configure Azure Update Manager (or confirm your channel), and run the pilot patch cycle.
  • Deliver the cost-control runbook, optional policy assignments, handover session and closeout report with per-server exit recommendations.
  • Tell you plainly which servers should not be enrolled — because they are entitled without purchase, because they should move or upgrade instead, or because they are ineligible.

Your team

  • Provide the server inventory, licensing evidence, administrative credentials and the deployment mechanism for the agent.
  • Open outbound connectivity or provide proxy details per the design.
  • Make the Software Assurance or server-subscription attestation, and sign off the disposition list, licensing model and cost model.
  • Provide maintenance windows for the pilot patch cycle.
  • Own Microsoft's ESU charges, any back-billing, and the ongoing decrement of cores as servers leave the estate — using the runbook, or a managed service engaged separately.
  • Own the exit: the upgrades, migrations or retirements that end each server's ESU dependency.

What's not included

Ongoing patch operations after handover — monthly update cycles, compliance chasing, reboots and exceptions are operations work, scoped separately as the Managed ESU and Legacy Server Lifecycle service rather than bundled into an enrollment.
Microsoft's ESU charges — metered per core and billed monthly by Microsoft to your Azure subscription, including any back-billing to the end-of-support date. We model them; we do not carry them.
The upgrades and migrations that end the ESU dependency — in-place upgrades to a supported Windows Server, or moves to Azure, are their own projects. Windows Server to Azure and VMware to Azure cover the migration paths, and the closeout tells you which servers belong on them.
Purchasing or renewing Software Assurance, server subscriptions or classic Volume Licensing ESU — a licensing transaction. The Microsoft Volume Licensing advisory handles the agreement side; as a direct-bill Microsoft CSP we can transact the Azure subscription the ESU charge lands on, and classic ESU where Microsoft makes it available through CSP.
Classic key-based ESU deployment — Volume Licensing ESU with Multiple Activation Keys is the channel for air-gapped servers and the one Microsoft recommends for VDI. It is a different runbook, quoted separately when the assessment shows you need it.
SQL Server ESU — SQL Server 2016 instances on these machines need their own enrollment under a separate Microsoft program; we flag every instance we find and scope it as SQL Server 2016 ESU Enrollment through Azure Arc, on its own.
The broader Azure Arc estate — tagging taxonomy, Azure Policy baselines, Defender for Cloud enrollment across all your servers — is the Azure Arc Hybrid Server Management implementation; this engagement onboards only what ESU needs.
Microsoft Defender for Servers and Microsoft Sentinel for the enrolled machines — available through Arc, metered by Microsoft, and worth a deliberate decision; our Defender for Cloud implementation is the place for it.
Repair of servers that fail to onboard — broken WMI, a corrupted servicing stack, a certificate store that will not trust Azure's issuing CAs — is dispositioned in the exceptions log; fixing them is separate work.
Network engineering beyond confirming the outbound path — new proxies, firewall changes or private-link build-out are scoped separately if the design needs them.
Windows 10 client ESU — a different Microsoft program with different rules; our Windows 11 Migration and Windows 10 ESU Transition service covers the desktop fleet.

Limitations & technical notes

!The $35-per-server plus $1,450 pricing is an estimate for estates of roughly 5 to 100 servers with an existing patching channel and straightforward connectivity. Heavily segmented networks, servers spread across hosting providers, agent rollouts without a deployment mechanism, and estates above about 100 servers are quoted per estate, in writing, before work begins.
!Dates are Microsoft's: Windows Server 2016 extended support ends 12 January 2027 and Windows Server 2012/2012 R2 ESU ends 13 October 2026, per Microsoft's product lifecycle. Enrolling a 2012 R2 server now buys coverage for weeks, not years, and its exit plan matters more than its enrollment — the Windows Server 2012 R2 Post-ESU Isolation and Exit Plan is that plan.
!Windows Server 2016 ESU can be configured from 3 August 2026, but Microsoft publishes no ESU-only updates for it until after 12 January 2027 and starts billing on 13 January 2027. Within an engagement delivered before then, 'verified' means enrollment status Active and a proven delivery channel, not an ESU patch installed — we can schedule a post-January check if you want one.
!ESU delivers only the updates Microsoft rates Critical and Important: no new features, no non-security hotfixes, no design changes, and no general product support. It is a bridge with a date on it, and every enrolled server gets a written exit recommendation.
!Microsoft prices ESU per core and revises those prices; we deliberately print no dollar figure here. The cost model in the engagement carries the rate current at the time, and Microsoft's back-billing rules — to the end-of-support date, never waived, applied on reactivation and on added cores — are applied to your actual enrollment date rather than glossed over.
!Eligibility is Microsoft's rule, not ours: Standard and Datacenter editions only; Software Assurance or an equivalent server subscription attested at license creation; no SPLA for Windows Server 2016; 16-core physical and 8-core virtual minimums; virtual-core licenses only on virtual machines. Servers that fail a rule are named in the disposition list with the alternative.
!Azure VMs and Azure VMware Solution receive ESU without an Arc enrollment, and VMs on Azure Local have for the existing Windows Server 2012 R2 program. Microsoft has announced that ESU offerings introduced from April 2026, Windows Server 2016 included, are treated differently on Azure Local — we confirm the current rule for your platform at engagement time rather than promising it here.
!Arc requires outbound connectivity and a Connected agent, and Microsoft does not recommend Arc-delivered ESU for VDI, which should use Multiple Activation Keys. Air-gapped and VDI machines are routed to the classic channel, not forced through this one.
!Billing follows the license, not the server. Microsoft does not decrement cores or deactivate licenses when a server is migrated or retired, and charges continue for up to five calendar days after you do; the runbook exists precisely because the saving is yours to claim every month.

Frequently asked questions

What is Windows Server ESU, and why enroll through Azure Arc rather than Volume Licensing?

Extended Security Updates is Microsoft's paid program for Windows Server versions past the end of extended support: Critical and Important security updates only, for up to three years, no features or non-security fixes. You can buy it the classic way — through Volume Licensing in yearly increments, with Multiple Activation Keys you deploy — or as ESU enabled by Azure Arc, where the entitlement follows an Azure license resource linked to the Arc-connected server, keyless, billed monthly per core to your Azure subscription, and stopped within days when you deactivate it. Arc also gives you the enrollment inventory in the portal and Azure Update Manager, Change Tracking and Inventory, and Azure Policy guest configuration at no additional Azure charge for enrolled servers. For an estate that will shrink as you migrate and upgrade, monthly beats annual. Microsoft states there is no transition from a Volume Licensing ESU into an Arc ESU for Windows Server 2016, so we help you pick once — and if annual through your Microsoft representative is genuinely right for you, we say so.

When do we need to have this done?

For Windows Server 2016: before 12 January 2027, the end of extended support per Microsoft's product lifecycle. Enrollment has been possible in the Azure portal since 3 August 2026, and Microsoft's published billing rules start the charge on 13 January 2027 — so enrolling in the autumn costs nothing until then and avoids a January scramble, while enrolling after the date is back-billed to it. For Windows Server 2012 and 2012 R2, ESU ends on 13 October 2026; those machines need an exit far more than an enrollment, and we say that on the call — the 2012 R2 Post-ESU Isolation and Exit Plan is the service for it.

How much does Microsoft charge for ESU through Azure Arc?

Per core, monthly, at a rate that depends on edition — Standard or Datacenter — and is subject to a 16-core minimum per physical machine or an 8-core minimum per virtual machine. Microsoft sets and revises the rate, so we deliberately print no dollar figure on this page; the cost model you approve on day three carries the rate current at the time, per license, with any back-billing shown as the one-time line it will be. The charge is Azure consumption on your own subscription — it counts toward a Microsoft Azure Consumption Commitment if you have one — and it is entirely separate from our $35-per-server plus $1,450 fee.

Do we need Software Assurance?

For on-premises and hosted servers, yes — Microsoft requires you to attest to Software Assurance or an equivalent server subscription when the ESU license is created, through programs such as an Enterprise Agreement, Server and Cloud Enrollment, or Open Value. Windows Server 2016 ESU is not available for SPLA-licensed servers. Servers running as Azure VMs need neither Software Assurance nor an ESU purchase to receive the updates. If your licensing position is uncertain, our Microsoft Volume Licensing advisory establishes it before you attest to anything.

Our servers already run as Azure VMs — do we need this at all?

No. Windows Server VMs in Azure receive ESU at no additional Microsoft charge and must not be enrolled through Arc; the same applies to machines in Azure VMware Solution. What those servers do need is a working update channel — Azure Update Manager or Windows Update — so the ESU-classified updates actually install, and we can confirm that as part of the disposition. The engagement exists for the servers that are not in Azure: your datacenter, a hosting provider, or another cloud.

We have around 40 Windows Server 2016 VMs on a VMware cluster — how does the licensing work?

Two valid ways, and the arithmetic decides. You can license the whole cluster with Datacenter physical cores — every physical core on every host — which covers unlimited VMs, or license each Windows Server 2016 VM with Standard virtual cores at the greater of eight or its actual vCPU count. When 2016 is a minority of what runs on the hosts, virtual cores are usually far cheaper; when the hosts are mostly 2016, Datacenter physical cores can win. Either way each VM is onboarded to Arc and linked to the license, and the model is worked out in writing before the license exists — because edition and core type cannot be changed afterwards, only cores added or removed.

What happens to the ESU charge when we migrate or retire a server?

Nothing, automatically — and that is the trap. Billing is tied to the activated license and its core count, not to whether a server still exists. When a server is migrated to Azure, upgraded or decommissioned, someone has to decrement the cores or deactivate the license; the reduced rate applies within about five days of the change. The runbook we leave you covers exactly that, with a monthly checklist, and the handover includes doing it once on a test resource so it is not theoretical.

What is back-billing?

Microsoft's rule that a license provisioned after the end-of-support date is charged, in a one-time line item, for the time elapsed since that date — for Windows Server 2016, back to 12 January 2027. Microsoft states there are no cases in which it is waived: deactivating a license and reactivating it bills the gap, deleting and recreating one does not escape it, adding cores back-bills the new cores, and moving a license to another region or tenant triggers it too. The cost model shows your exposure against your real enrollment date so the first invoice is not a surprise.

Do the ESU patches come through Azure, or through our WSUS?

Arc provides the entitlement, keyless — it does not become your patch pipe. Once a server is linked to an activated license, the ESU-classified updates flow through whatever channel you already run: Azure Update Manager, WSUS, Microsoft Update, Configuration Manager, or a third-party tool. Azure Update Manager is provided at no additional Azure charge for servers enrolled in ESU through Arc, so it is the natural choice if you have no channel or want to retire one, and we configure it with assessment, maintenance windows and a pilot group. If you keep WSUS or Configuration Manager, we confirm the security classifications reach these servers instead.

Which servers cannot be enrolled through Azure Arc?

Anything other than Windows Server 2016 or 2012/2012 R2 Standard or Datacenter; servers without Software Assurance or an equivalent server subscription (or licensed under SPLA, for Windows Server 2016); servers with no outbound path to Azure; and VDI workloads, where Microsoft recommends Multiple Activation Keys instead. Windows Server 2012 Storage edition is also excluded. Each of these is named in the disposition list with the alternative — classic key-based ESU, upgrade, migration or retirement — rather than discovered when a link fails.

Does ESU make an old server safe?

Safer, not safe. ESU delivers only the updates Microsoft rates Critical and Important; lower-rated vulnerabilities are not fixed, there is no product support, and everything else on the machine — the application stack, the drivers, the configuration — is as old as it was. That is why the closeout gives every server an exit recommendation, and why it is worth a deliberate decision about Defender for Servers through Arc for the ones staying longest.

What about SQL Server 2016 on these machines?

SQL Server ESU is a separate Microsoft program with its own enrollment, and SQL Server 2016 reached the end of extended support on 14 July 2026 per Microsoft's product lifecycle. Enrolling the operating system does nothing for the database engine. We flag every SQL Server instance the assessment finds and scope its enrollment through SQL Server 2016 ESU Enrollment through Azure Arc — or its move to Azure, which the SQL Server to Azure migration assessment evaluates — as its own piece of work rather than quietly folding it in.

Can you run the patching for us after enrollment?

Not inside this engagement — it is an enrollment, and we keep it that way so the price stays honest. The runbook and handover make your team self-sufficient: enrolling a new server, decrementing cores, reading compliance. If you would rather have the monthly cycle operated for you, that is the Managed ESU and Legacy Server Lifecycle service — its own terms, scoped explicitly rather than bundled as a retainer into a one-week project.

How does this relate to your Azure Arc Hybrid Server Management service?

This engagement onboards only what ESU needs — the 2016 and 2012 R2 population — and does the licensing, linking and update-channel work. The Azure Arc Hybrid Server Management implementation is the estate-wide project: every server, a tagging taxonomy, an Azure Policy baseline, Update Manager schedules across Windows and Linux, and optional Defender for Cloud. If you already have Arc, this service is a licensing and enrollment exercise on top of it; if you do not, it is a clean first step, and the agent rollout carries straight into the broader project.

How does your pricing work?

An estimate of $35 per in-scope server plus a $1,450 base fee, confirmed as a written quote once the inventory is agreed on day one — and you pay after you approve delivery. The per-server fee covers every server we assess and disposition, whether it ends up enrolled, entitled without purchase, or routed elsewhere. Estates above about 100 servers are quoted per estate. Microsoft's ESU charges are metered to your Azure subscription and are never part of our fee.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$35 per server + $1,450 tenant fee
1 week
Book an ESU scoping call