Flamingo Raises $4.5M Seed Round

Skip to content

Windows Server 2016 sits under file shares, domain controllers and line-of-business apps that nobody has touched in years. When its support date passes, those servers keep booting, but Patch Tuesday stops shipping anything for them. Here's what the server 2016 end of life changes, what Microsoft has and hasn't published about extended updates, and how to pick a path for each workload before January.

TL;DR

  • Extended support for Windows Server 2016 ends on January 12, 2027. Mainstream support already ended on January 11, 2022.
  • After that date, Microsoft stops releasing security updates for 2016, and support incidents for it close. The servers keep running.
  • As of late September 2026, Microsoft has not announced an Extended Security Update (ESU) program for Server 2016. Plan as if there won't be one.
  • Server 2016 can upgrade in place to 2019, 2022 or 2025. Failover clusters move one version at a time.
  • Pick the target with the calendar in mind: Server 2022 leaves mainstream support in October 2026, and Server 2025 is supported until November 2034.
  • Start with an inventory by role, not by hostname. The role decides the path.

Windows Server 2016 Lifecycle Dates

Server 2016 follows Microsoft's Fixed Lifecycle Policy: five years of mainstream support, then five years of extended support. The dates below come from the Server 2016 lifecycle page on Microsoft Learn.

MilestoneDate
General availabilityOctober 15, 2016
Mainstream support endedJanuary 11, 2022
Extended support endsJanuary 12, 2027
Editions coveredDatacenter, Standard, Essentials, MultiPoint Premium

Microsoft Learn shows the end timestamps in UTC, so you'll see January 13 on some pages and third-party trackers. The last day of coverage is Tuesday, January 12, 2027, which is also the final Patch Tuesday that includes Server 2016. Container base images released with Server 2016 follow the same dates.

Mainstream support ending in 2022 already cut new features and non-security fixes. What's left today is security updates, and that's what January takes away.

What Stops on January 12, 2027

Nothing switches off. Windows Server 2016 doesn't expire, deactivate or refuse to boot after end of support. Three things change.

Security updates stop. The February 2027 Patch Tuesday won't include Server 2016. Any vulnerability disclosed after January stays open on those machines for good, including ones in shared components like SMB, RDP, Print Spooler and the TCP/IP stack that newer versions get fixes for.

Microsoft support stops. You can't open a support case for Server 2016 after the date, even with a paid support plan. Microsoft's ESU FAQ says the same held for Server 2012 once its support ended without ESU coverage.

Everyone else starts leaving. Software vendors tie their own support to the OS lifecycle. Backup agents, security tools, database engines and line-of-business apps drop 2016 from their compatibility lists, often quietly, in the release notes of a version you haven't installed yet.

Some of the stack under Server 2016 is already gone. SQL Server 2016 left extended support on July 14, 2026, and Exchange Server 2016 on October 14, 2025. If either still runs on your 2016 boxes, the OS date is the second deadline, not the first.

Then there's compliance. Cyber insurance questionnaires and frameworks like PCI DSS and CIS Controls expect supported, patched systems. An unsupported server becomes an exception you have to document and defend at every renewal.

Is There ESU for Windows Server 2016?

Not yet, and possibly not at all. As of September 30, 2026, Microsoft's ESU lifecycle FAQ (last updated August 24, 2026) lists two products with active ESU programs: Windows Server 2012 and 2012 R2, and Windows 10. The Server 2012 R2 lifecycle page lists three ESU years. The Server 2016 page lists none.

That can change. But a migration plan that depends on an unannounced program is a plan with a hole in it. Budget and schedule as if January 12 is the end.

If Microsoft does announce Server 2016 ESU, the Server 2012 program is the only published model to go on. Here's how that one worked, per the same FAQ:

  • In Azure: ESU was free for eligible VMs, including Azure VMs, Dedicated Host, Azure VMware Solution, Nutanix Cloud Clusters on Azure and the Azure Stack portfolio. Updates applied automatically.
  • On-premises through Azure Arc: Servers connected to Azure Arc could enroll and pay monthly, billed through Azure, licensed per virtual or physical core with no keys to manage. Late enrollment triggered back-billing for the missed months.
  • On-premises through volume licensing: Yearly ESU licenses bought through commercial licensing, one year at a time, and Year 2 required Year 1.

Eligibility outside Azure required active Software Assurance, subscription licenses, or "License-Included" licensing from an SPLA hoster. Microsoft priced on-premises Server 2012 ESU at 100% of the full license price per year, per the FAQ as of August 2026. ESU also never included technical support beyond ESU installation and regressions it caused.

The 2012 R2 program itself ends on October 13, 2026. If you still carry 2012 R2 servers on ESU, they fall off three months before your 2016 fleet does. Handle both in the same project.

Migration Paths Out of Server 2016

You have four ways out: an in-place upgrade, a clean install with role migration, a cluster rolling upgrade, or moving the workload somewhere else entirely, such as Azure or a SaaS replacement.

In-Place Upgrade Paths

Microsoft's upgrade path table (updated April 2026) supports in-place upgrades from Server 2016 to 2019, 2022 or 2025 using installation media. Starting with Server 2025, non-clustered servers can jump up to four versions at a time, so 2016 goes straight to 2025. The Windows Update feature-update route to 2025 only covers 2019 and 2022, so 2016 needs the ISO.

The restrictions matter more than the matrix. You can't switch between Server Core and Desktop Experience during an upgrade. You can't change language or downgrade edition, though Standard can move up to Datacenter. NIC Teaming has to be disabled first. Servers that boot from VHD and Storage Server editions can't upgrade in place. Each target version also needs its own license; Windows Server upgrades aren't free the way client upgrades were.

In-place upgrades suit servers where the role supports it, the hardware is still under warranty, and rebuilding would cost more than the risk. Take a backup and a snapshot first, and test the same build on a clone if you can.

Clusters, Clean Installs and Azure

Failover clusters are the exception to the four-version jump. A Cluster OS Rolling Upgrade moves one version at a time, so a 2016 Hyper-V or Scale-Out File Server cluster takes three passes to reach 2025. For older hardware that's often the argument for building a new cluster and live-migrating VMs across instead.

A clean install with role migration takes longer but leaves you with a fresh OS, no inherited registry clutter, and hardware you picked on purpose. Storage Migration Service in Windows Admin Center moves file servers, shares and permissions and can take over the old server's identity. We covered where that tool helps and where it stops in our Windows Admin Center guide.

Moving a VM to Azure doesn't extend Server 2016 support by itself. Azure's free ESU only helps once an ESU program exists for the product. If the workload is moving to Azure, upgrade the guest OS on the way.

Upgrading in place is where surprises show up. This r/sysadmin post asks what breaks when RD Gateway boxes go from 2016 to 2022:

Which Version to Target

The target version decides when you do this again.

  • Server 2019: extended support ends January 9, 2029. That's two years of runway. Only pick it when an application vendor certifies nothing newer.
  • Server 2022: mainstream support ends October 13, 2026, so it arrives already in extended support. Security updates run to October 14, 2031.
  • Server 2025: mainstream support runs to November 13, 2029 and extended support to November 14, 2034.

For a fleet leaving 2016 in the next three months, 2025 is the default. Use 2022 where an application is certified for it and not yet for 2025.

This walkthrough shows a Server 2016 to 2025 in-place upgrade from installation media:

Inventory Your Server 2016 Machines First

You can't plan a migration from a hostname list. You need four facts per server: the roles it runs, the application and its owner, the hardware and its warranty, and how it's licensed.

Start with Active Directory. Server 2016 reports build 14393:

powershell
Get-ADComputer -Filter 'OperatingSystem -like "*Server 2016*"' `
  -Properties OperatingSystem, OperatingSystemVersion, LastLogonDate, IPv4Address |
  Select-Object Name, OperatingSystem, OperatingSystemVersion, LastLogonDate, IPv4Address |
  Sort-Object LastLogonDate -Descending

AD only knows about domain-joined machines. Workgroup servers, appliances and VMs in a hoster's tenant won't show up, so cross-check against your hypervisor inventory and your RMM.

Then run a role check on each server:

powershell
$os = Get-CimInstance Win32_OperatingSystem
Get-WindowsFeature | Where-Object Installed |
  Select-Object @{n='Server';e={$env:COMPUTERNAME}}, @{n='Build';e={$os.BuildNumber}}, Name, DisplayName

Add the installed software list, the last reboot time, and whether the box is physical or virtual. In OpenFrame, the open, AI-native infrastructure layer for IT and security, you can run that script across a client's devices and collect the output in one place.

For physical servers, note the firmware and warranty date too. An in-place upgrade on hardware that's out of vendor support trades one unsupported layer for another, and a BIOS update is often a prerequisite for a newer OS to install cleanly.

The inventory also shows you what nobody owns. The server labelled "APP01" with no documentation tends to be the one tied to a vendor that stopped answering email. Find those early, because they take the longest.

Licensing Checks Before You Upgrade

Licensing is where upgrade budgets go wrong, because the OS license is only one line.

Server licenses. Each Windows Server version needs its own license. If the server is covered by Software Assurance or a subscription, the new version is usually included in that agreement; OEM licenses that shipped with the hardware don't carry forward. Windows Server is licensed per core, with a minimum of 8 cores per processor and 16 per server.

Edition and virtualization rights. Standard covers two VMs per fully licensed host, and Datacenter covers unlimited VMs on the host. A 2016 Hyper-V host with a growing VM count is a good moment to recheck which edition the new host needs.

Client access licenses. Users and devices connecting to a 2025 server need CALs at the 2025 level or newer. The same applies to RDS CALs for session hosts. Existing 2016 CALs don't cover a newer server.

Activation. If you run a KMS host, it needs a key for the new version before it can activate Server 2025 machines. Update the KMS host before the first upgrade, or new servers will sit in the grace period.

Line these up per server in the inventory, next to the role and hardware. A server that's cheap to upgrade technically can still be expensive to license, and that changes which path is cheaper.

Decision Table by Workload

The role decides the path. This is the default we'd start from, then adjust for hardware and vendor constraints.

Workload on Server 2016Default pathWatch for
Domain controllerBuild a new 2025 DC, move FSMO roles, demote the old oneRaise functional levels only after every DC is upgraded; update DNS and DHCP pointers
File serverStorage Migration Service to a new server, or in-place upgradeShare permissions, DFS namespaces, mapped drives in scripts
Hyper-V host or clusterNew cluster on 2025 with live migration, or rolling upgrade one version per passGuest OS versions, cluster functional level, backup agent support
RDS, RD Gateway, RD WebIn-place upgrade after a clone test, or a fresh deploymentRDS CALs must match or exceed the new version; certificates and gateway policies
SQL Server 2016 on 2016Move to a new server with a supported SQL versionSQL Server 2016 has been out of extended support since July 2026
Exchange Server 2016Move mailboxes to Exchange Server SE or Microsoft 365Exchange 2016 support ended October 2025; don't upgrade the OS under it
Line-of-business appAsk the vendor for a certified version, then rebuildUnsupported vendor combos, license keys tied to hardware
Print serverMigrate queues to a new server or cloud printDriver packages and Point and Print settings
App nobody can migrate yetIsolate: dedicated VLAN, no internet, tight firewall rules, extra loggingDocument the exception with a retirement date

Isolation buys time for the one server that can't move by January. Give it an owner and a retirement date.

A Timeline From Now to January 2027

If you're starting in October 2026, you have roughly 15 weeks. Here's a schedule that fits.

Early October: inventory and triage. Run the AD query and the role script. Tag each server with a path from the table above. Flag anything with no owner.

October 13, 2026: two deadlines land at once. Server 2012 R2 ESU Year 3 ends and Server 2022 leaves mainstream support. Clear any 2012 R2 stragglers in the same wave.

Late October to November: pilot and easy wins. Upgrade or rebuild the low-risk servers first: file servers, print servers, standalone utility boxes. Use them to test your backup, rollback and licensing steps.

November to mid-December: the hard ones. Domain controllers, Hyper-V clusters, RDS and vendor applications. Book vendor time now; December calendars fill fast.

Mid-December to January 12: freeze and stragglers. Leave change windows for rollbacks. Isolate anything that can't move and write down its retirement date.

After January 12: prove it. Re-run the inventory query. The count of Server 2016 machines should be zero, or equal to the list of documented, isolated exceptions.

The Short Version

Windows Server 2016 extended support ends on January 12, 2027, and no ESU program has been announced for it. The servers keep running, but security updates and Microsoft support stop, and vendors follow. Inventory by role, pick a path per workload, and target Server 2025 unless an application pins you to 2022. Upgrade clusters one version at a time, rebuild domain controllers rather than upgrading them in place, and isolate whatever can't move with a named owner and a date.

Conrad Lunderstedt

Conrad Lunderstedt

Solution Architect

I'm Conrad, Solution Architect at Flamingo. I've spent about 26 years in IT, roughly half of it inside MSPs and the rest in enterprise environments, so I've watched vendor decisions get made on both sides of that line. Now I spend my days talking with MSPs about the stack they already run, and helping them work through the requests and issues that come with it.

Related Content

Blog Posts

Product Releases

Podcasts

Webinars

Case Studies

Events

Onboarding Guides

Frequently Asked Questions

Windows Server 2016 End of Life

Extended support for Windows Server 2016 ends on January 12, 2027, the final Patch Tuesday that includes it. Mainstream support already ended on January 11, 2022. Microsoft Learn lists the end timestamp in UTC, so some trackers show January 13.
As of September 30, 2026, Microsoft has not announced an ESU program for Windows Server 2016. Its ESU lifecycle FAQ, last updated August 24, 2026, lists only Windows Server 2012/2012 R2 and Windows 10. Plan the migration as if January 12, 2027 is the end.
The servers keep booting and stay activated, and their roles keep working. Microsoft stops releasing security updates for them, support cases for Server 2016 are closed, and software vendors drop it from their compatibility lists.
Yes. Microsoft supports in-place upgrades from Server 2016 to 2019, 2022 or 2025 using installation media, because Server 2025 allows non-clustered servers to jump up to four versions. Failover clusters using a rolling upgrade move one version at a time, so they need three passes.
Server 2025 is the default target: mainstream support runs to November 13, 2029 and extended support to November 14, 2034. Server 2022 leaves mainstream support on October 13, 2026 and gets security updates until October 14, 2031, so choose it only when an application is certified for 2022 and not yet for 2025.

About OpenFrame

In the cloud, on US soil. Your data stays stateside.
OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
Most platforms give you one piece and expect you to bolt the rest on. OpenFrame unifies the whole stack in one place, with AI copilots built in. Fewer logins, fewer bills, less duct tape.
Both. It's built for MSPs and MSSPs alike.

MSP AI Agents

Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.