Microsoft end of support timeline

Last updated: September 10, 2026.

If your business is still running Windows Server 2012 R2, the clock runs out in about a month. Extended Security Updates for Windows Server 2012 and 2012 R2 — the paid extension that has kept those servers patched since October 2023 — stop for good on October 13, 2026. There is no year four. After that date, those servers never receive another security patch from Microsoft.

Four months later, Windows Server 2016 reaches end of support on January 12, 2027, and unlike 2012 R2 it has no announced ESU program at all.

Below is every Microsoft end-of-life date a North Texas business needs on its radar, what each one actually means in practice, and what your options are if one of them applies to you.

Microsoft end-of-life dates at a glance

Already past end of support

Product End of support Where it stands now
Windows 7 January 14, 2020 ESU ended January 10, 2023. No further patches.
Windows Server 2008 / 2008 R2 January 14, 2020 ESU ended January 10, 2023 on-premises. No further patches.
Windows 8.1 January 10, 2023 No ESU was offered. No further patches.
Windows Server 2012 / 2012 R2 October 10, 2023 Final ESU year ends October 13, 2026.
Windows 10 October 14, 2025 ESU available for commercial editions through October 2028.
Office 2016 and Office 2019 October 14, 2025 No ESU. No further patches.
Exchange Server 2016 and 2019 October 14, 2025 No ESU. Migration to Exchange SE or Microsoft 365 required.
SQL Server 2016 July 14, 2026 Extended support has ended. ESU available via Azure Arc.

Coming up

Product Date What happens
Windows Server 2012 / 2012 R2 October 13, 2026 Final ESU year ends. Nothing after this.
Windows 10 ESU (Year 1) October 13, 2026 Year 1 ends. Renewal decision for Year 2.
Windows 11 version 24H2 October 13, 2026 End of servicing for Home and Pro. Feature update required.
Windows Server 2022 October 13, 2026 Mainstream support ends. Moves to extended support.
Windows Server 2016 January 12, 2027 End of extended support. No ESU program announced.
Windows 11 version 25H2 October 13, 2027 End of servicing for Home and Pro.
Windows 10 ESU (Year 2) October 12, 2027 Year 2 ends.
Windows 10 ESU (Year 3, final) October 10, 2028 Last possible Windows 10 security update.
Windows Server 2019 January 9, 2029 End of extended support.
Windows Server 2022 October 14, 2031 End of extended support.
Windows Server 2025 November 2034 End of extended support.

Microsoft publishes these as Pacific Time cutoffs, which is why you will sometimes see the following calendar day quoted. The dates above are the final Patch Tuesday — the last day a security update actually ships.

Windows Server 2016 end of life: January 12, 2027

This is the one most North Texas businesses are not ready for. Server 2016 has been quietly reliable for nearly a decade, and reliable servers do not generate the kind of complaints that get them onto a budget — which is exactly why so many are still running.

Unlike Server 2012 R2 it has no announced ESU program, there is no single-step upgrade path to Server 2025, and the hardware underneath is usually the same vintage as the operating system. We have covered the deadline, the upgrade options and a realistic migration timeline in full here: Windows Server 2016 end of life: January 12, 2027.

Windows Server 2012 and 2012 R2: the extension runs out October 13, 2026

Windows Server 2012 and 2012 R2 reached end of support back in October 2023. Since then, organizations that bought Extended Security Updates have kept receiving critical and important patches. That program was always three years long, and the third year ends on October 13, 2026.

If you are on ESU today, that is roughly a month of runway. If you are not on ESU and still running 2012 R2, those servers have been unpatched for nearly three years already.

The one exception worth knowing: Windows Server 2012 R2 running in Azure receives ESU at no additional cost, and Azure Arc extends a similar arrangement to on-premises machines. That is a bridge, not a destination — but if you are genuinely stuck, it is a bridge worth knowing about.

Windows 10: end of support was October 2025

Windows 10 reached end of support on October 14, 2025, with version 22H2 as the final release. Extended Security Updates are available for Enterprise, Education and Pro editions in commercial use, in three one-year increments ending October 13 2026, October 12 2027 and October 10 2028.

Year 1 ends in a month, which makes this a live decision for a lot of DFW businesses right now: pay for another year of ESU, or move those machines to Windows 11. If a machine meets the Windows 11 hardware requirements, upgrading is almost always the better use of the money. If it does not — usually a TPM 2.0 or CPU generation issue — ESU buys you time to schedule the replacement rather than time to avoid it.

Still running Windows 7 or Windows Server 2008?

We wrote the original version of this article the week Windows 7 and Windows Server 2008 reached end of support, back in January 2020. Some organizations are still running both, usually because a single piece of equipment or software will not run on anything newer.

Here is where those platforms stand today. Windows 7 and Windows Server 2008 / 2008 R2 both reached end of support on January 14, 2020. The Extended Security Update program for both ended on January 10, 2023. There is no paid option left, no exception process, and no path to getting these machines patched. Every vulnerability discovered since January 2023 remains open on them permanently, and vulnerabilities in these platforms are extremely well documented and actively exploited.

If a legacy application is the reason a Windows 7 machine or a Server 2008 box is still running, the answer is almost never “keep it patched” — that option no longer exists. It is isolation: pull the machine off the general network, restrict it to the one function it exists to perform, remove internet access, and treat it as a known-compromised device that happens to be useful. That is a containment strategy, and it should come with a dated plan to retire the underlying application.

What running past end of life actually costs you

The security exposure is the obvious part. The parts that surprise business owners are the other three.

Cyber insurance

This is the one that bites hardest and soonest. Cyber liability applications now routinely ask whether you run any unsupported operating systems. Answering yes raises your premium or gets the application declined. Answering no when the answer is yes gives your carrier grounds to deny a claim at exactly the moment you need it paid. For most small and mid-sized businesses in DFW, cyber insurance requirements — not regulators — are what actually forces the upgrade conversation.

Compliance frameworks

PCI DSS requires that systems handling cardholder data receive security patches. An unsupported OS cannot, by definition, meet that requirement. HIPAA’s Security Rule requires reasonable and appropriate safeguards, and running software the vendor no longer patches is difficult to defend as either. If you handle CJIS data — which applies to Texas municipalities, police departments and their vendors — unsupported operating systems are a straightforward finding.

The Texas safe harbor

Texas SB 2610 offers businesses with fewer than 250 employees a degree of protection from punitive damages in a breach lawsuit, provided they maintain a cybersecurity program that reasonably conforms to a recognized framework such as CIS Controls or NIST CSF. Every one of those frameworks requires supported, patched software. An unsupported server undercuts the claim that you conform to any of them.

Third-party software support

Software vendors follow Microsoft’s lifecycle. Once an OS goes out of support, your line-of-business vendor typically stops testing against it, then stops supporting it, then ships a version that will not install on it. Businesses are often forced off an old server not by Microsoft but by their own accounting or practice-management software.

Your options, honestly assessed

  1. Upgrade or migrate. The right answer in nearly every case. It costs the most up front and the least over three years, and it is the only option that ends with you in a supported position. For most SMBs the destination is Windows Server 2022 or 2025, or moving the workload to Microsoft 365 or Azure entirely and retiring the server.
  2. Buy Extended Security Updates where they exist. A legitimate bridge when a migration genuinely cannot happen before the deadline. Available for Windows 10 and, until October 13, 2026, Windows Server 2012 R2. Not available for Server 2016, Office 2016/2019, or Exchange 2016/2019. Price it before you assume it is the cheap option.
  3. Isolate and contain. For a machine that exists only to run one legacy application: segment it off the network, strip its internet access, restrict who can reach it, and monitor it closely. This reduces risk. It does not make you compliant and it will not satisfy an insurance carrier.
  4. Do nothing. Cheapest today, most expensive the day something happens. We mention it because it is what most organizations do by default rather than by decision — and a default is not a decision.

Frequently asked questions

When does Windows Server 2016 reach end of life?

January 12, 2027. Extended support ends on that date and Microsoft has not announced an Extended Security Update program for it.

Is Windows Server 2008 still supported?

No. Windows Server 2008 and 2008 R2 reached end of support on January 14, 2020, and the Extended Security Update program for them ended on January 10, 2023. They receive no security updates of any kind.

When does Windows Server 2012 R2 support really end?

Mainstream and extended support ended October 10, 2023. The three-year Extended Security Update program ends October 13, 2026, which is the genuine final date for patches.

Can I still get security updates for Windows 10?

Yes, through the Extended Security Updates program, for Enterprise, Education and Pro editions in commercial use. It runs in one-year increments through October 10, 2028. It covers critical and important security updates only.

Can I upgrade Windows Server 2016 directly to Server 2025?

Not in a single step. Microsoft supports in-place upgrades across two versions, so 2016 to 2022 is supported. Reaching 2025 requires a second upgrade or a clean migration, and for most businesses a clean migration is the better use of the same downtime.

What happens if we just keep running an unsupported server?

It keeps working. It also stops receiving security patches permanently, is likely to breach your cyber insurance conditions and any compliance framework you are subject to, and will eventually be dropped by your own software vendors.

Not sure what you are running?

Most businesses we talk to are surprised by at least one thing on this list — usually a server everybody forgot about, or a handful of Windows 10 machines that cannot take Windows 11.

The Fulcrum Group offers a free end-of-life readiness assessment for businesses in Keller, Fort Worth, Dallas and across North Texas. We inventory every Windows machine and server you have, map each one against the dates above, flag what is already exposed and what expires within twelve months, and give you a dated replacement plan you can put in a budget. No obligation, and you keep the inventory whether or not you work with us.

Schedule a discovery call or call us at 817-337-0300.

Related reading: Managed cybersecurity services for DFW SMBs · Cloud computing services in Dallas and DFW · fCIO strategic technology planning