Windows Server 2016 reaches end of support on January 12, 2027. After that date Microsoft stops issuing security patches for it, and no Extended Security Update program has been announced. This page explains what that means, what your upgrade options actually are, and how long a migration realistically takes — so you can plan one instead of being surprised by it.
Last updated: September 10, 2026 by The Fulcrum Group, a managed IT provider in Keller, Texas.
The date, and what happens on it
| Milestone | Date | Status |
|---|---|---|
| Windows Server 2016 released | October 2016 | Complete |
| Mainstream support ended | January 11, 2022 | Passed |
| Extended support ends | January 12, 2027 | Final security update |
| Extended Security Updates | — | None announced |
Nothing breaks on January 13, 2027. Your servers keep running, your applications keep working, your users notice nothing. That is precisely what makes this deadline dangerous — there is no outage to force the issue.
What changes is that Microsoft stops shipping security patches. Every vulnerability discovered in Windows Server 2016 from that date forward stays open permanently. Given that Server 2016 shares a substantial amount of code with Windows 10 and later server releases, vulnerabilities found in supported products will frequently apply to it too — and will be publicly documented, with the patch for the supported version serving as a roadmap for anyone who wants to exploit the unpatched one.
Is there an ESU program for Windows Server 2016?
No — not as of today, and you should not plan around one appearing.
This is the single most common question we get, and it matters because the last two server deadlines both had an escape hatch. Windows Server 2008 and 2008 R2 got three years of paid Extended Security Updates. Windows Server 2012 and 2012 R2 got the same, and that program ends on October 13, 2026. Many organizations have come to treat ESU as a standing option.
Microsoft has announced nothing equivalent for Server 2016. If a program is announced later it will almost certainly be expensive, escalate in price each year, and cover critical and important vulnerabilities only. Treat any future ESU as a possible emergency fallback, not as a plan.
Your upgrade options
In-place upgrade
Microsoft supports in-place upgrades across a maximum of two versions. From Windows Server 2016 that means:
| From | Direct in-place upgrade to | Supported? |
|---|---|---|
| Server 2016 | Server 2019 | Yes |
| Server 2016 | Server 2022 | Yes |
| Server 2016 | Server 2025 | No — requires two hops |
Two things to weigh before choosing this route. First, Server 2019 reaches its own end of support on January 9, 2029, so upgrading 2016 to 2019 buys you two years and then puts you right back here. If you are going to do the work, go to 2022 or 2025.
Second, in-place upgrades carry over years of accumulated configuration drift, orphaned registry entries, old drivers and half-removed software. On a server that has been running since 2016, that history is usually substantial. In-place upgrades work, but they work best on servers that have been kept clean.
Clean migration to new hardware or a new VM
For most of the Server 2016 machines we see, this is the better answer. You build the new server properly, migrate roles and data deliberately, test, then cut over. You end up with a documented, current environment rather than a decade of inherited decisions.
It is also usually the honest option, because a physical server running Server 2016 is typically running on 2016-era hardware — out of warranty, past its depreciation schedule, and with disks well beyond their expected life. The operating system deadline and the hardware refresh tend to arrive together.
Move the workload and retire the server
Worth asking before you spend anything: does this server still need to exist?
A lot of what Server 2016 was bought to do in 2016 no longer requires a server at all. File shares move to SharePoint or OneDrive. On-premises Exchange moves to Exchange Online — and if you are still running Exchange Server 2016 or 2019, note those reached end of support in October 2025 already. Line-of-business applications increasingly have hosted versions. Domain controllers can move to Azure or stay on-premises on modern hardware depending on how your sites and applications are structured.
The cheapest server migration is the one where you decommission the server instead of replacing it.
Azure
Migrating the workload to Azure is a legitimate path, particularly for organizations that want to stop buying server hardware entirely. It is not automatically cheaper — a lift-and-shift of an over-provisioned physical server into an equivalently sized VM often costs more per year than the hardware it replaced. It becomes cost-effective when you right-size, use reserved instances, and retire workloads you were only running because the server was already there.
How long does this actually take?
Longer than most people budget for. Working backwards from January 12, 2027:
| When | What should be happening |
|---|---|
| September–October 2026 | Inventory. Identify every Server 2016 instance, what roles it holds, what applications depend on it, and who owns those applications. |
| October–November 2026 | Vendor checks. Confirm each line-of-business application is supported on your target OS version. This is the step that most often derails a timeline. |
| November 2026 | Decide and procure. Hardware lead times, licensing, and budget approval all live here. |
| December 2026–January 2027 | Build, migrate, test, cut over. |
That schedule is already tight, and it has an obvious problem: the build-and-cutover window lands over the holidays, when your staff are out, your vendors are slow to respond, and nobody wants to be moving a domain controller. If you are reading this in late 2026, the practical planning window closes around November.
The step that consistently causes overruns is the vendor check. An accounting package, a practice-management system, a CAD licence server or a piece of machinery control software that is only certified against Server 2016 will stop the whole project until someone resolves it — and the resolution is often an application upgrade with its own cost, timeline and testing burden.
What drives the cost
We are not going to quote a price on a web page, because the honest answer depends on things we would need to look at. But the variables that actually move the number are worth knowing before you ask anyone for a quote:
- How many servers, and what roles they hold. A single file server is straightforward. A domain controller carrying FSMO roles, DNS and DHCP is a different conversation.
- Whether the hardware is being replaced too. Usually it is, and that is often the largest line item.
- Windows Server licensing and CALs. Core-based licensing changed how this is priced, and organizations that last bought in 2016 are frequently surprised.
- Application dependencies. One application that needs upgrading to run on a supported OS can exceed the cost of the server work itself.
- Acceptable downtime. A cutover you can do over a weekend costs less than one that has to happen with zero interruption.
What it costs to do nothing
The security exposure is obvious. The consequences that catch business owners off guard are the commercial ones.
Cyber insurance. Cyber liability applications now routinely ask whether you operate any unsupported operating systems. Answering yes raises your premium or gets the application declined. Answering no when the answer is yes hands your carrier grounds to deny a claim at the moment you most need it paid. For most SMBs, this — not regulation — is what finally forces the upgrade.
Compliance. PCI DSS requires that systems handling cardholder data receive security patches, which an unsupported OS cannot do by definition. HIPAA’s Security Rule requires reasonable and appropriate safeguards. For Texas municipalities, police departments and their vendors, CJIS makes unsupported operating systems a straightforward audit finding.
The Texas safe harbor. Texas SB 2610 gives businesses with fewer than 250 employees a measure of protection from punitive damages in a breach lawsuit, provided they maintain a cybersecurity program that reasonably conforms to a recognized framework such as CIS Controls or NIST CSF. Every one of those frameworks requires supported, patched software. An unsupported server undercuts the claim.
Your own software vendors. Vendors follow Microsoft’s lifecycle. First they stop testing against an unsupported OS, then stop supporting it, then ship a version that will not install. Businesses are frequently forced off an old server not by Microsoft but by their accounting or practice-management provider.
Windows Server 2016 migration for DFW businesses
The Fulcrum Group has been handling server migrations for North Texas businesses since 2002, through every Microsoft end-of-support deadline from Server 2003 onward. We are based in Keller and work across Fort Worth, Dallas, Plano, Arlington and the wider DFW area, with clients in professional services, healthcare, manufacturing, and municipal and water-district government.
A Server 2016 engagement with us normally runs in this order:
- Inventory and assessment. We identify every Server 2016 instance you have, what each one does, what depends on it, and what condition the underlying hardware is in.
- Application dependency review. We contact your software vendors and confirm what each application supports, before you commit to a target version.
- A written plan with dates and costs. Target OS, hardware or cloud decision, licensing, migration sequence, downtime windows, and a budget you can take to whoever approves it.
- Migration and cutover. Built, tested, and moved on a schedule that fits around your operations rather than through them.
- Ongoing management, if you want it. Most clients move onto our SPOT managed IT service afterwards so the next deadline is handled before it becomes urgent.
If you would rather just find out where you stand, we offer a free end-of-life readiness assessment. We inventory your Windows servers and workstations, map each against Microsoft’s lifecycle dates, and flag what is already unsupported and what expires in the next twelve months. You get the inventory and the dated replacement plan whether or not you work with us.
Schedule a discovery call or call 817-337-0300.
Frequently asked questions
When exactly does Windows Server 2016 reach end of life?
January 12, 2027. That is the final Patch Tuesday on which Microsoft issues security updates for it. Microsoft’s lifecycle page lists the following calendar day because the cutoff is recorded in Pacific Time.
Will Microsoft offer Extended Security Updates for Server 2016?
Nothing has been announced. Server 2008 and Server 2012 both received three-year paid ESU programs, so it is possible, but you should not build a plan around it. If one appears it will be costly and will escalate annually.
Can I upgrade Windows Server 2016 straight to Server 2025?
No. Microsoft supports in-place upgrades across two versions, so 2016 to 2019 or 2016 to 2022 is supported, but 2016 to 2025 is not a single step. Reaching 2025 requires two sequential upgrades or a clean migration — and for most businesses the clean migration is the better use of the same downtime.
Should I upgrade to Server 2019 or Server 2022?
Server 2022 or 2025 in almost every case. Server 2019 reaches end of support on January 9, 2029, so moving 2016 to 2019 buys roughly two years before you repeat the exercise.
What happens to my server on January 13, 2027?
Nothing visible. It boots, runs and serves users exactly as before. It simply stops receiving security patches, permanently, and every vulnerability found from that point on remains open.
Can I keep running Server 2016 if I isolate it?
If a legacy application genuinely cannot move, network isolation reduces risk: segment the machine, remove its internet access, restrict who can reach it, and monitor it closely. Understand what that is and is not. It is a containment measure. It does not make you compliant, and it will not satisfy a cyber insurance carrier.
How long does a Windows Server 2016 migration take?
For a single straightforward server, a few weeks from assessment to cutover. For a multi-server environment with line-of-business application dependencies, three to six months is realistic — and the vendor compatibility checks, not the technical work, are usually what set the pace.
What if we are also still running Server 2012 R2?
Then you have a more urgent problem. Extended Security Updates for Server 2012 and 2012 R2 end on October 13, 2026, and that is the final year of that program. Those servers should be at the front of the queue.
See also: Microsoft end-of-life dates: what DFW businesses need to know · Managed cybersecurity services for DFW SMBs · fCIO strategic technology planning

