Extended support for Windows Server 2016 ends on January 12, 2027. The server will not automatically shut down on that date, but security updates provided under extended support will end. Prepare to migrate the services you still need, or check eligibility for temporary coverage through Extended Security Updates (ESUs). Microsoft lifecycle dates.
Start with what people use: shared files, accounting, staff sign-ins and printing. New hardware will not fix an incompatible application. Upgrading Windows does not always require replacing the hardware either.
For the business owner: identify essential services, acceptable downtime and the person who will confirm that work can resume. For your IT provider: verify supported versions, licences, recovery and the migration method. The expandable technical notes below cover upgrade paths and Active Directory.
This guide helps you work through those decisions with your provider. The preparation worksheet records the inventory, evidence and cutover conditions.
In this guide
1. Identify what actually needs to migrate
Ask for one inventory entry per physical server or virtual machine, including hosted systems: Windows version and edition, applications, database engine, dependencies and business owner. Moving a virtual machine to another hosting provider does not change its operating system.
Identify what stops working if the server becomes unavailable, and the last successful restore. An essential service without a tested recovery path needs early attention. Contact vendors whose compatibility position is still unknown at the same time: their lead time may determine the schedule.
Fictional example: a small business has a file server and an accounting server. The file service is ready for testing; the accounting application needs an update, and its export to the sales system must be tested. The two projects have different prerequisites and may need different migration dates.
Check less visible jobs: monthly exports, scheduled tasks and service accounts. A machine without user sessions on inventory day is not necessarily unused. Windows Server 2012 and 2012 R2 have a different deadline.
2. Choose between migration, retirement and ESUs
One decision per service
Start with use, then compatibility.
- Unused servicePrepare retirement
Check dependencies, retained data and scheduled or periodic jobs.
- Compatible target confirmedTest the migration
Prepare the target and business tests. Validate recovery before the cutover.
- Blocked applicationGet the vendor’s plan
If it extends beyond the deadline, check ESU eligibility, cost and the exit date.
Replace it only if its condition, capacity or compatibility requires it.
An abandoned service can be retired after checking its uses and the data that must be kept. A service still in use needs a compatible target. Decide on hardware replacement separately, considering vendor support, condition and capacity. Microsoft minimum requirements do not size your business application.
For hosting location and future costs, see the on-premises server or cloud comparison.
If an application cannot migrate in time
ESUs can provide Critical and Important security updates for up to three additional years. They do not add new features or full product support. They do not, by themselves, extend support for your business application either.
For the Azure Arc option, Microsoft lists Standard and Datacenter, with billing starting on January 13, 2027. Eligibility depends on the licence agreement and hosting arrangement. Ask your licensing provider to confirm your case, then arrange enrolment and update delivery. Installing Arc alone is not sufficient. The worksheet includes the conditions to check. Microsoft requirements.
The proposal should state the transition cost, its owner and the target exit date. Use the detailed conditions to assess the offer, not to postpone the project indefinitely.
3. Verify three things before choosing the target
The Windows version, application compatibility and migration method all need validation. A Microsoft-supported upgrade path does not prove that your business application is supported on the target.
| Target | Extended support | What to consider |
|---|---|---|
| Windows Server 2022 | Until October 2031 | Application supported on 2022 but not yet on 2025 |
| Windows Server 2025 | Until November 2034 | Applications, backup and infrastructure are compatible |
The end of mainstream support for 2022 in October 2026 does not end its extended support. 2022 lifecycle, 2025 lifecycle.
Ask the vendor for confirmation covering the exact application, Windows and database engine versions. Check SQL separately: extended support for SQL Server 2016 ended on July 14, 2026. Upgrading Windows does not upgrade SQL. SQL Server dates.
Connections that are easy to miss
Test exchanges with other equipment too. Microsoft removed NTLMv1, an older authentication method, from Windows Server 2025. Identify components that depend on it before migrating. Removed features.
During testing, reproduce these four tasks where they apply:
- Open the older application from a user's workstation, not only on the server.
- Send a scanned document to its usual folder.
- Read and edit a file on the NAS using the intended account.
- Run the automated script or export with its service account.
Investigate failures with the software or equipment vendor rather than automatically attributing them to NTLMv1.
For your IT provider: migration method and Active Directory
Direct upgrade or separate installation?
Microsoft supports a direct 2016-to-2025 upgrade using installation media for nonclustered systems, subject to restrictions. That path is not available through Windows Update for 2016. Upgrade paths.
A separate installation lets you prepare and test the target before transfer. An in-place upgrade retains part of the installation but depends on the supported roles. Both approaches still need testing and a recoverable backup.
For Active Directory, the account directory, Microsoft recommends new domain controllers on clean installations. A 2025 domain controller also requires domain and forest functional levels of at least 2016, which must be checked separately from the Windows version. AD approach, prerequisites.
4. Price the whole project
Ask for five separate items: preparation, licences and capacity, business application updates, cutover and rollback, and ongoing operation. Clarify vendor involvement, working hours and support when users restart work.
For each uncertainty, the quote should state what is included and what needs pricing after investigation. For example, is conversion of the accounting database included? Who handles an incompatibility discovered in testing? Comparing totals without those answers can hide a difference in scope.
If staff use Remote Desktop Services, check the RDS access licences and the licensing server. RDS 2022 licences do not cover a Windows Server 2025 session host. Microsoft RDS compatibility.
Compare costs over the same period. A temporary ESU option must include the future migration in the budget; it does not replace that cost.
5. Agree on start and rollback conditions
Prepare the date before booking downtime
Some investigations can run in parallel. Commit to the cutover date once blocking issues have been resolved.
| Stage | What allows the next step |
|---|---|
| Inventory and vendor responses | Services, dependencies and compatible versions identified |
| Quote and required resources | Scope, licences, capacity and people confirmed |
| Representative trial | Business tasks and restoration verified; durations recorded |
| Fixing gaps | Blocking tests rerun successfully |
| Scheduling cutover | Window, rollback, user communication and decision-maker agreed |
If a vendor response is missing, record who will follow up and when. Preparation time depends on these steps; it cannot be inferred from the two-hour example below.
Before stopping the service, obtain business test results, evidence of restoration and a rollback procedure. Name the people performing the work and the person authorising reopening. A box marked "backup OK" without a restore report leaves an essential question unanswered.
Recover a document or restore the whole service?
Retrieving an invoice verifies recovery of a file. Restarting accounting also requires a usable database, the application, its configuration and the necessary access. Establish which elements are backed up and how the rest will be recovered.
For an in-place upgrade, Microsoft requires a full server backup and a restore test. Microsoft prerequisites.
Useful evidence records the restored point, test environment, observed duration and successful business operation. A readable folder does not replace that trial. Backup access must also remain available if the usual server is stopped.
Validate reopening
Agree on the results needed to resume work:
| Use | Essential check |
|---|---|
| Files | Documents present and editable; prohibited access is refused |
| Accounting or business system | Complete fictional operation with the correct result in the connected application |
| Directory and remote desktop | Ordinary user sign-in, technical checks, applications and printing |
| Jobs and backup | Export runs under its service account; restore an item from the target and verify it |
Isolate tests to prevent conflicts and real outgoing messages. The restore test kit exercises fictional files; it does not validate the whole application.
Fictional example: a service required by 20:00
Assume an 18:00 start: 10 minutes to block writes, 30 for the final transfer and 20 for testing. Rollback, its validation and the agreed buffer need 60 minutes together. The decision deadline is therefore 19:00: 20:00 minus that reserve. These durations illustrate the method; replace them with those assessed in your trials.
Two hours. One deadline.
Fictional example. Replace these durations with your trial results.
- 18:00Block writes
10 minutes to prepare the transfer
- 18:10Transfer the changes
30 minutes for the final copy
- 18:40Check business use
20 minutes of business tests
Have all essential tests passed?
Authorise reopening. Users can write to the target again.
Start the rollback. 60 minutes reserved, validate before 20:00.
Any rollback must preserve the new data. Restarting the old server alone is not enough.
At the deadline, a failed or incomplete essential test triggers the agreed rollback. Continuing to test would consume the reserve. Writes remain blocked until reopening is authorised.
After reopening, rollback changes. New documents or invoices created on the target do not reappear by restarting the old server. Plan how to preserve those changes and which copy will be authoritative. The original time allowance no longer necessarily applies; use a role-appropriate procedure for a database or directory.
6. Close the project with usable evidence
After reopening, check actual use, backups and deferred jobs. Test a monthly export or keep it tracked with a date and an owner. Request the deployed versions, access changes, test results and restore procedure.
Decide what happens to the old system too: required retention, any isolation and retirement. Avoid leaving two writable copies of the same service in circulation.
The editable worksheet and printable version bring together these decisions, a filled example and a message for your provider. Start by recording the affected services, their business impact and the next action with its owner.
Use this worksheet
Your Windows Server 2016 preparation
One worksheet per service. Record decisions and their evidence; the printable pack above provides detailed tables and a filled example.
Complete the worksheet
Nothing is sent or saved automatically. Download your answers before leaving the page.
A checked status does not replace a restore test or approval by the person responsible for the cutover.
Would you like Initial Infra to scope this migration? Prepare that inventory, the essential applications and the acceptable downtime windows. Discuss the project.
Sources checked on September 26, 2026. Examples are fictional; compatibility, licences and timings must be confirmed for your environment.