Microsoft stops supporting Windows Server 2016 on January 12, 2027. From today, that is about fifteen weeks, and two of those weeks are the holidays, when nobody is touching production.
If you have a server closet, there is a reasonable chance something in it is running Server 2016. It was a good release. It has been quietly doing its job since the year it shipped, which is exactly why nobody has thought about it.
Here is the part that tends to surprise people. If you are running Server 2016, you are often also running SQL Server 2016 on top of it, and that one already ended support on July 14 of this year. So the database holding your line of business application may have been out of support for two months already, and the operating system underneath it is next.
End of support does not mean it stops working
This is the trap in every end of support deadline, and it is worth being precise about.
On January 13, your server will boot normally. Users will log in. Applications will run. Nothing visible will change, which is what makes the date so easy to ignore.
What changes is that Microsoft stops shipping security updates for it. Every vulnerability discovered after that date stays open on that machine permanently. And those vulnerabilities do get discovered, and they do get published, and attackers read the same advisories your vendors do. An unsupported server is not a server that breaks. It is a server that slowly turns into a liability while continuing to look perfectly healthy.
There is a second cost that shows up sooner than most owners expect. Your cyber insurance application asks whether you run unsupported operating systems. Your customers' vendor security questionnaires ask the same question. Increasingly the answer changes your premium or your eligibility, and that bill arrives well before anything gets exploited.
The upgrade itself got easier
Some genuinely good news, because this used to be worse.
You can now upgrade Windows Server 2016 directly to Server 2025 in place. Microsoft supports jumping up to four versions at once on standalone servers, so you no longer have to step through 2019 and 2022 to get current. That removes two full maintenance windows and a lot of risk from the typical project.
The exception is clusters. Cluster rolling upgrades still move one version at a time, so a 2016 cluster has to walk the whole path. If you are running clustered workloads, your timeline is materially longer than your neighbor's, and that is worth knowing in September rather than in December.
The part that eats the schedule
If the only thing on the box is file shares or a line of business application, this is a manageable project. Plan it, test it, schedule a window, done.
What turns a weekend into a quarter is certificate services.
If any of your 2016 servers is running Active Directory Certificate Services, that is where the project will get stuck. Certificate authority databases do not move casually. In most environments the CA was configured once, years ago, by someone who has since left, and has received almost no maintenance since, which means nobody currently on staff knows exactly what depends on it.
NDES servers are worse. The configuration is a delicate combination of specialized IIS settings, Active Directory service accounts, custom certificate templates, and CA permissions, and small changes break it in ways that are difficult to diagnose. If you issue device certificates through Intune, that connector is in the same fragile category.
The practical consequence is that certificate services should be the first thing you look at, not the last. It is the item most likely to extend your timeline, and the only way to know how far is to go look now. The upside is that a migration is the natural moment to modernize certificate templates and cryptography that have not been touched in a decade, and to get the CA off a domain controller if that is where it ended up.
Extended Security Updates buy time, not a solution
Microsoft offers Extended Security Updates for Server 2016, up to three years past end of support. If your timeline genuinely does not fit, they are a legitimate bridge and better than running exposed.
Understand how they are priced, though, because the structure is designed to discourage exactly what most people do with them. The cost roughly doubles each year. They are also cumulative, so an organization that decides to enroll in year two has to buy year one as well. Waiting does not defer the cost. It increases it, and you still own the same migration at the end.
ESUs make sense when you have a defined plan and need a few extra months to execute it safely. They are an expensive mistake when they are used as a way to avoid making the decision.
What to do between now and January
You do not need a full project plan this week. You need to know the size of the problem, and that takes an afternoon.
Find every 2016 machine. Servers, yes, but also the virtual machines nobody logs into and the appliance somebody stood up for one application in 2019.
Write down what each one actually does. Domain controller, certificate authority, SQL host, file server, application server. The role determines the difficulty, not the hardware.
Flag the certificate authority and anything clustered immediately. Those two set your real timeline. Everything else can be scheduled around them.
Check your SQL versions while you are in there. If SQL Server 2016 is in the environment, that clock already expired and should be part of the same conversation.
Decide what is actually worth migrating. Some of these workloads should move to a current server. Some should move to a cloud service. Some should be retired, because the application they support has not been used in two years and nobody noticed.
Fifteen weeks
The organizations that handle this well will spend the fall doing it deliberately, in scheduled windows, with rollback plans. The ones that do not will spend February doing it under pressure, after an insurance questionnaire or an auditor forces the issue, and they will pay more for a worse outcome.
If you are not sure what you are running or what it would take, we can inventory it with you and tell you honestly which pieces are urgent and which can wait until spring. That conversation is a lot cheaper in September than it is in January.
Want this reviewed against your environment?
We'll walk your stack with you and tell you plainly what we'd change first.