Windows Server 2016 extended support ends on 12 January 2027. Mainstream support ended on 12 January 2022, so this is the last stage. (Source: Microsoft lifecycle page for Windows Server 2016)
Your server won't stop working on 13 January. That's the problem. Nothing breaks, nobody gets an alert, and the file shares keep opening. It just stops getting security fixes. So the deadline is easy to ignore until something goes wrong.
If you run an office server with file shares, a domain controller, an accounting or job-management database, or remote desktop, there are 14 weeks left. Here's a calm way to use them.
What the paid extension does, and doesn't do
Microsoft offers Extended Security Updates (ESU) for Server 2016. It covers Critical and Important security updates only, for up to three years, through 2030. Setup through the Azure portal opened on 3 August 2026, and Azure Arc billing starts on 13 January 2027. For on-premises servers, it needs Software Assurance or an equivalent server subscription. (Source: Microsoft Azure Arc ESU preparation guide)
Microsoft's own description is that ESU is "a last resort paid option" and "a temporary bridge… while one migrates to a newer, supported platform". (Source: Microsoft ESU FAQ)
So ESU is useful if you need more time. It isn't a plan. The plan is the work below.
Why it matters beyond patching
The Australian Signals Directorate's Essential Eight says that "operating systems that are no longer supported by vendors are replaced", at all maturity levels. Maturity level 1 also expects restore testing in disaster recovery exercises. (Source: ASD Essential Eight maturity model)
The ASD's 2024-25 Annual Cyber Threat Report says the average self-reported cost of cybercrime for a small business was $56,571, up from $49,615. (Source: ASD Annual Cyber Threat Report 2024-2025)
We're not here to scare anyone. The point is that an unsupported server is a risk worth a plan, not a panic.
A dated checklist
These dates are a suggested calendar counting back from 12 January. Adjust them for your own busy periods, especially the Christmas shutdown.
Weeks 1-2 (5 and 12 October): find out what's on the box
- List every server, physical or hosted, and its operating system version.
- For each one, write down its roles: file shares, domain controller, database, remote desktop, print, anything else.
- Note the line-of-business apps, the scheduled jobs, and who or what connects to it.
- Check whether any ESU or Software Assurance licensing already exists.
Weeks 3-4 (19 and 26 October): decide what happens to each workload
- Retire it, because nobody uses it.
- Move it to a service that's already supported.
- Rebuild it on a new, supported server.
- Bridge it, with ESU, only where you truly need more time.
Weeks 5-8 (2 to 23 November): build the replacement and test the restore
- Build or buy the new environment.
- Set up backups that include a copy that can't be changed or deleted.
- Do a real restore test, not just a "backup succeeded" message.
Weeks 9-12 (30 November to 21 December): move over and run both in parallel
- Run old and new side by side with a tested way to roll back.
- Cut over the workloads in a quiet period, not the week before Christmas.
Weeks 13-14 (4 and 11 January): lock it in
- Decommission or isolate the old server.
- Confirm patches are applying on the new one.
- Write down how to restore it, and who does it.
The part most checklists skip: what the server is really doing
The server itself is rarely the hard part. The hard part is the thing living on it that nobody wants to touch. An Access or Excel job tracker only one person understands. A nightly CSV export that someone re-keys into Xero or MYOB. A scheduled task that nobody remembers setting up. Move the box and those quietly break.
That's why the discovery step comes first and takes more care than people expect.
How OrionX can help
We work with Adelaide and South Australian businesses whose systems haven't kept up with how much they've grown. For a Server 2016 situation, we'd typically build three things:
- Discovery and a risk register. We use scripts to inventory every server: its roles, SQL and line-of-business apps, file shares, scheduled jobs, and who connects to it. You get a one-page dashboard tagging each workload as retire, move, rebuild or bridge. This is the free tailored demo, run on your own environment after we've talked.
- Replacing the fragile app or process on the box. For example, an Access or Excel job tracker, or a nightly CSV export into Xero or MYOB, becomes a small web app or an API integration, with the data moved to a managed database, so nobody is re-keying anymore.
- A scripted rebuild, backups and cutover. The new server is built from code, with an immutable backup copy and an automated restore test that emails you pass or fail. We run both servers in parallel with a tested rollback, then give you a patch-compliance dashboard.
The offer is simple: a free 20 to 30 minute chat about where your systems are slowing you down, and then one free demo built around your business. There's no obligation, and we don't promise savings or timeframes. Get in touch through the OrionX website to book the chat.
Related reading:
- Legacy system modernisation for Australian business
- BizTalk, Azure Service Bus and SBMP retirement in 2026
- Cyber security for Australian small business
This post is general information only and isn't legal, financial or technical advice. Licensing and support terms change, so check Microsoft's current pages and speak with your IT provider about your own situation.

