Windows Server 2016 has only received security updates since early 2022. On 12 January 2027, those stop too, unless you pay for Extended Security Updates (ESU) through Azure Arc, which requires Software Assurance. The server itself keeps running as before. If it handles sign-in, files and printers, that affects your whole office. Here is exactly what ends, when ESU makes sense as a bridge, which three ways forward there are and what to gather before you decide.
What ends on 12 January 2027
Support for Windows Server 2016 runs out in two phases: mainstream support first, then extended support. Three dates matter for your planning:
- End of mainstream support. No new features or bug fixes since then, only security updates.
- Paid ESU available through Azure Arc. Since then, security updates beyond the deadline can be bought for the Standard and Datacenter editions with Software Assurance.
- End of extended support. After that, security updates only come with paid ESU, which requires Software Assurance.

Want to tackle this in your company?
Send me a short message or give me a call. I'll get back to you within 24 hours on weekdays.
ESU as a bridge
Without ESU, newly discovered flaws stay unpatched after the deadline. For a server that handles sign-in and company data, that is the biggest risk on your whole network. Data protection adds to this: Art. 32 GDPR requires safeguards that take the state of the art into account, and cyber insurers often ask whether your systems still receive updates.
ESU buys time, but on clear terms: it is paid for through Azure Arc, the server needs the Standard or Datacenter edition with Software Assurance, and coverage lasts three years at most, until 2030 at the latest. So check first whether your licence includes Software Assurance.
ESU makes sense if the migration can no longer be done properly before the deadline, or if a business application is still waiting for the vendor's approval. In that case, set a date by which the server will be replaced: ESU only extends the security updates, not the life of the hardware, which is often just as old as the system.
Three ways forward for your server
Which way fits depends on what the server does today. Often, a mix of server and cloud works best.
- A current Windows Server: if a business application needs a local server, you'll need a current Windows Server on site, with new licences and, where necessary, new hardware. If you stay with Active Directory, user accounts and passwords stay the same.
- Microsoft 365 with Entra ID: if it's mainly about sign-in and files, Microsoft 365 (licensed per user), Entra ID and SharePoint may be all you need. What central sign-in looks like day to day is covered in my article on Microsoft Entra ID for small businesses.
- ESU as a stopgap: if your server meets the requirements, it buys you time for one of the other two ways. It is not a permanent solution, as it ends in 2030 at the latest.
Inventory checklist
Before you decide, it should be clear what the server does today:
- Roles and services: what does the server do besides sign-in and files? Does it hand out network addresses (DHCP), resolve names (DNS) or run scheduled tasks and scripts?
- Active Directory: which users, groups and computers exist, and which Group Policies roll out settings? Accounts of former staff and old devices are best cleaned up before the move.
- Shares and permissions: which folders are shared, who can access what, and which network drives are mapped on the PCs? Data nobody needs any more doesn't have to move.
- Printers: which printers run through the server? If a multifunction device saves scans to a folder on the server, that path has to work after the move too.
- Business applications: if stock management, accounting or industry software runs on the server, ask the vendor early whether it is supported on a current Windows Server or in the cloud. The answer often decides the way forward.
- Backups: is the server backed up, and has a restore ever been tested?
- Check the basics: the free IT security check shows how your business is doing on updates, backups and access rights.
How I go about it
In the free consultation, we work out what your server does today and which of the three ways could fit. After that, you get a fixed price. Only then does the work start:
- Inventory: I record everything the server does, point by point as in the checklist above.
- Backups first: before anything moves, I check the backup and test a restore. No working backup, no migration.
- Move role by role: outside your core hours where possible, for example in an evening or over a weekend, so your business keeps running.
- Testing and documentation: the next morning, I check sign-in, drives, printers and software. You get documentation that lets someone else understand the setup too.
If you start now, you can plan the move calmly before 12 January 2027. Start late in the year and Christmas and New Year fall right in the middle of the switch. How I plan, migrate and document servers and networks for small offices is described on the Network & Windows Server page.