Organizations can maintain security coverage for legacy servers without migrating workloads to Azure VMs.
Key Takeaways:
Microsoft is giving businesses more time to protect their Windows Server 2016 workloads as the platform moves closer to the end of support. With Azure Arc-enabled Extended Security Updates (ESUs) now generally available, organizations can continue receiving critical security patches without moving their legacy servers to Azure.
Microsoft plans to end extended support for Windows Server 2016 on January 12, 2017. After this date, these servers will stop receiving security patches that protect against new security threats. Organizations that can’t upgrade before the end of support date can purchase Extended Security Updates (ESUs) to continue receiving security protection through January 2030.
“Extended Security Updates give you access to Critical and Important security updates for Windows Server 2016 for up to three years after end of support, covering January 12, 2027 through January 2030. They provide a supported bridge for business-critical applications that need more time to migrate, without new features or non-security fixes, and without leaving systems exposed while you plan your move,” Microsoft explained.
This new offering allows organizations to enroll Windows Server 2016 instances connected via Azure Arc and receive ESUs without migrating workloads to Azure virtual machines. It supports servers running on-premises, at the edge as well as in other cloud environments. This capability allows administrators to extend security coverage for legacy workloads while planning modernization within their organizations.
Microsoft highlighted that this service offers a simplified, cloud-based experience, including direct enrollment through Azure, centralized administration, and the removal of traditional activation-key requirements. Moreover, flexible pay-as-you-go pricing allows organizations to purchase coverage as needed rather than committing to a long-term upfront contract.
Organizations that enroll servers in ESUs through Azure Arc also gain access to Azure management capabilities, including Azure Update Manager, Change Tracking and Inventory, and Azure Policy Guest Configuration. These services help improve visibility, compliance, and operational management across hybrid and multicloud environments.
To prepare for delivering Extended Security Updates (ESUs) through Azure Arc, IT admins should first identify eligible Windows Server systems that are approaching or have reached end of support and connect them to Azure Arc. Once onboarded, Azure Arc provides a centralized way to enroll servers in ESUs, track coverage, and manage update compliance without relying on traditional activation keys. Microsoft also recommends ensuring that servers can receive updates through Windows Update, Windows Server Update Services (WSUS), or Azure Update Manager.
Microsoft’s recommendation is to view ESUs as a temporary bridge rather than a long-term strategy. Businesses should use this extended period to modernize applications and plan migrations to supported platforms.