Every Windows Server release gets five years of mainstream support and five more of extended support, and when extended support ends the free security updates stop for good.
Windows Server 2022 leaves mainstream support on October 14, 2026, the same day the final paid ESU year for 2012 and 2012 R2 expires. Windows Server 2016 loses extended support on January 13, 2027. Nothing visibly breaks on any of those dates, which is why servers sit unpatched for years past their EOL.
- Mainstream is five years, extended is five more, then nothing
- 2012 and 2012 R2 run out of paid extensions on October 14, 2026
- 2016 is fully out of support on January 13, 2027
- 2019 has until January 10, 2029, and 2022 until October 15, 2031
- Since 2025 an in-place upgrade can jump four versions instead of two
On this page
The datesEvery Windows Server end of life date
| Version | Released | Mainstream ends | Extended ends |
|---|---|---|---|
| Windows Server 2012 | Oct 30, 2012 | Oct 10, 2018 | Oct 11, 2023 |
| Windows Server 2012 R2 | Nov 25, 2013 | Oct 10, 2018 | Oct 11, 2023 |
| Windows Server 2016 | Oct 15, 2016 | Jan 12, 2022 | Jan 13, 2027 |
| Windows Server 2019 | Nov 13, 2018 | Jan 10, 2024 | Jan 10, 2029 |
| Windows Server 2022 | Aug 18, 2021 | Oct 14, 2026 | Oct 15, 2031 |
| Windows Server 2025 | Nov 1, 2024 | Nov 14, 2029 | Nov 15, 2034 |
Every Windows Server end of life date above comes from the Fixed Lifecycle Policy, which is the predictable one: a published date, five years of mainstream support, five years of extended support, and no negotiation.
Every version in the table is a Long-Term Servicing Channel release, and the next subsection covers why that matters. The dates above were read from the Microsoft Lifecycle pages on September 23, 2026, and Microsoft states them in Pacific Time.
Two things in that table are worth reading twice. Windows Server 2016 left mainstream support in January 2022, so a 2016 server has been receiving security updates and nothing else for four years already.
And Windows Server 2022 leaves mainstream support next, which surprises people who think of it as the current release.
LTSC and the Annual Channel, and which one these dates belong to
Microsoft's servicing channels page states that Windows Server has had two primary release channels since September 2023: the Long-Term Servicing Channel, LTSC, and the Annual Channel, AC. Every version in the table above is an LTSC release.
LTSC is the one an on-premises estate runs. Microsoft's page gives it a new major version typically every two to three years, with five years of mainstream support and five years of extended support.
An LTSC release can be installed as Server Core or as Server with Desktop Experience. That five plus five is where every Windows Server end of life date in the table above comes from.
The Annual Channel is for containers. Microsoft describes it as an operating system to host Windows Server containers, released about every twelve months, installable only with the Server Core option and only as a container host.
It is available to volume-licensed customers with Software Assurance and through loyalty programs such as Visual Studio Subscriptions. Each AC release is supported for 24 months from initial release: 18 months of mainstream support plus 6 months of extended support.
Two consequences for planning. Microsoft states that an Annual Channel release is not an update, so moving to one means a clean installation rather than an upgrade.
And an AC release runs out of support roughly four times faster than an LTSC one, so a container host needs a review cycle of its own rather than the ten year rhythm the rest of the estate follows.
One naming detail causes confusion in inventory reports. Microsoft's Windows Server release information page lists Windows Server 2016 under the servicing option Long-Term Servicing Branch, LTSB, which is the older name, while 2019, 2022 and 2025 are listed as LTSC.
The support model behind the two labels is the same, and the dates in the table above are the ones that govern either way.
The phasesWhat mainstream and extended support actually differ on
Mainstream support is the whole product: new features, non-security bug fixes, design change requests, warranty claims and security updates. If a role behaves incorrectly, this is the phase in which Microsoft will fix it.
Extended support is security updates only. A functional bug found in extended support does not get fixed unless it also has a security impact. Free support incidents end, and paid support is available on request. In practice the operating system is frozen and patched.
After extended support there is nothing. No security updates, no fixes, no patches at any price except through a paid Extended Security Updates program where one exists.
The distinction matters commercially because most compliance frameworks and most cyber insurers care about the third state, not the second. A server in extended support is supported. A server past it is an unpatched host on your network, and an auditor will treat it that way.
The day itselfWhat actually happens on the day
Nothing. The server boots, the roles start, the users log in, and no dialog appears. That is the entire problem with an end of life date, and it is why estates carry unsupported servers for years.
What changes is invisible and cumulative. The next vulnerability disclosed in a component that release shares with newer ones gets patched everywhere except on your machine, and the patch itself is the disclosure: anyone can read what changed and work backwards.
An unsupported server does not degrade gradually. It stays exactly as it was while the published attack surface around it grows.
The second change is contractual. Cyber insurance questionnaires ask whether all systems receive vendor security updates. Frameworks including PCI DSS and HIPAA security rule assessments treat an unsupported operating system as an unmanaged risk requiring compensating controls that have to be documented and defended.
The technical risk is real and gradual. The paperwork risk arrives all at once, usually at renewal.
The compensating controls an assessor will accept are narrower than most people expect. Network segmentation that genuinely isolates the host, firewall rules that restrict it to the few flows it needs, and monitoring that would catch a compromise are the usual three.
All three cost effort every year, which is the argument for spending that effort once on an upgrade instead.
The optionsYour three options
In-place upgrade. Install the newer version over the existing one, keeping roles, settings and data. Fastest, same hardware, one reboot.
Not every role supports it and there is a list of restrictions worth reading before you commit: no 32-bit to 64-bit, no language change, no switch between Server Core and Desktop Experience, and NIC Teaming has to be disabled first.
Microsoft states plainly that you should back up the system and its data first, which means a restorable backup that somebody has actually tested, not the last job that reported success. If the estate does not already follow a backup rule, the upgrade weekend is a bad time to discover it.
Clean install or migration. Stand up the new server alongside the old one, move roles across, decommission. More work and more downtime, and the right answer for any machine carrying a decade of configuration debt, because an in-place upgrade carries that debt forward intact.
Extended Security Updates. Microsoft sells additional years of security patches after a version reaches EOL, priced per core and rising annually. Windows Server 2012 and 2012 R2 had three ESU years, and the third ends October 14, 2026.
Microsoft also names a second route alongside ESU: migrating the on-premises server to an Azure virtual machine and continuing to run it there.
Either way, ESU buys months for a migration that is already planned and funded. It is not a strategy, because the annual price rises and the program itself ends.
Upgrade pathsThe upgrade paths that actually exist
Which version you can jump to depends on which version you are on, and the rule changed with Windows Server 2025.
| From | Can upgrade in place to |
|---|---|
| Windows Server 2012 | 2012 R2, 2016 |
| Windows Server 2012 R2 | 2016, 2019, 2025 |
| Windows Server 2016 | 2019, 2022, 2025 |
| Windows Server 2019 | 2022, 2025 |
| Windows Server 2022 | 2025 |
Starting with Windows Server 2025, a nonclustered system can move up to four versions in one step, which is why 2012 R2 can go straight to 2025. On Windows Server 2022 and earlier the limit is two versions. A cluster performing a rolling upgrade can only advance one version at a time, whatever the target.
The row that traps people is the first one. Windows Server 2012 without R2 cannot reach 2025 in a single step and has to pass through 2016, at which point a clean install is usually the better use of the same weekend.
Two paths are also available through Windows Update rather than installation media, both to Windows Server 2025 and both requiring the current cumulative update first: from Windows Server 2019 and from Windows Server 2022.
PitfallsWhere estates go wrong
Counting servers instead of finding them. The server past its end of life is almost never the one on the inventory. It is the virtual machine running one line of business application that nobody has logged into since the person who installed it left. Query Active Directory for computer objects with an operating system attribute, not the asset register.
Treating extended support as the deadline. Extended support is when the countdown becomes visible, not when it starts. A release entering extended support has already stopped receiving functional fixes, which is when compatibility problems with newer software begin.
Buying ESU without a migration date. The price rises every year and the program ends. ESU with a funded project behind it is insurance. ESU without one is a subscription to the same problem.
Upgrading a domain controller in place without reading the guidance. Domain controllers have their own upgrade sequence and their own restrictions, including the fact that a licensed domain controller cannot be converted to a retail version.
Forgetting the patch process still has to work afterwards. A newly upgraded server that is not in the patching schedule is the same problem with a later date on it.
Assuming the provider is tracking it. Lifecycle tracking is inside almost every managed services agreement and it is rarely the part anyone reads. Ask your provider for the list of servers it is watching and the dates it has for each, and compare that list to the one you built yourself. The gap between the two is the finding.
ComparisonThe four responses, and what each one buys
| Criterion | In-place upgrade | Migrate to new | Buy ESU | Do nothing |
|---|---|---|---|---|
| Effort | Lowest, one reboot | Highest | Lowest | None |
| Downtime | Hours | Planned cutover | None | None |
| Carries old config forward | Yes, all of it | No, fresh build | Yes | Yes |
| Cost | License only | License and hardware | Rises every year | Zero, until it is not |
| Buys you | 5 to 10 years | 5 to 10 years | 1 year at a time | Nothing |
| Right when | Roles support it, config is clean | Config debt, new hardware | Migration is funded and dated | Never |
The last column is on the table because it is what most organizations actually choose, by default rather than by decision. The honest version of that choice is a documented risk acceptance with a date on it, which is also the thing an auditor will ask to see.
FAQFrequently asked questions
When is Windows Server 2016 end of life?
January 13, 2027. Mainstream support ended January 12, 2022, so a 2016 server has been receiving security updates only for four years.
When is Windows Server 2019 end of life?
January 10, 2029. Mainstream support for Windows Server 2019 ended January 10, 2024.
When does Windows Server 2022 end of support happen?
Mainstream support ends October 14, 2026, and extended support runs to October 15, 2031.
Is Windows Server 2012 R2 still supported?
No. Extended support ended October 11, 2023. Three years of paid Extended Security Updates followed, and the third and final year ends October 14, 2026.
What is the difference between mainstream and extended support?
Mainstream includes new features, non-security fixes and security updates. Extended is security updates only. After extended support ends there are no free updates of any kind.
What happens if I keep running a Windows Server past end of life?
It keeps working. It also stops receiving security updates while vulnerabilities in shared components continue to be disclosed and patched elsewhere, and it becomes a documented finding in compliance assessments and cyber insurance questionnaires.
Can I upgrade Windows Server 2016 directly to 2025?
Yes. Since Windows Server 2025 a nonclustered in-place upgrade can jump up to four versions, so 2012 R2, 2016, 2019 and 2022 can all move straight to 2025.
Can Windows Server 2012 upgrade directly to 2025?
No. Windows Server 2012 without R2 can only upgrade in place to 2012 R2 or 2016, so it needs an intermediate step or a clean install.
How long is a Windows Server lifecycle?
Ten years under the Fixed Lifecycle Policy: five years of mainstream support and five years of extended support from the release date. That applies to Long-Term Servicing Channel (LTSC) releases, which is every version in the table above. Annual Channel releases get 24 months.
What are Extended Security Updates?
A paid program that supplies security patches after extended support ends, priced per core and rising each year. Windows Server 2012 and 2012 R2 had three ESU years ending October 14, 2026.
Should I do an in-place upgrade or a clean install?
In-place if the roles support it and the configuration is clean, because it is one reboot on the same hardware. Clean install or migration if the server carries years of accumulated configuration, because an in-place upgrade carries all of that forward.
Can I upgrade a failover cluster the same way?
A cluster OS rolling upgrade advances one version at a time regardless of the four version rule, and it keeps Hyper-V and Scale-Out File Server workloads running while nodes are upgraded one by one.
Do I need a new license to upgrade?
Yes. Unlike Windows client, each Windows Server upgrade requires a separate license and a valid product key for the target version. An upgrade keeps the existing edition by default, and you can move from Standard up to Datacenter during one, but never back down.
Should I back up before an in-place upgrade?
Yes, and Microsoft says so directly in its own upgrade guidance. The backup that matters is one somebody has restored from, because an in-place upgrade that fails halfway leaves a server that boots into neither version cleanly.
How do I find every EOL server we are running?
Query directory computer objects by operating system attribute rather than trusting the asset register, then reconcile against virtualization hosts, because the machines that get missed are almost always virtual and almost always single purpose.
What are the Windows Server EOL dates?
Extended support ended for Windows Server 2012 and 2012 R2 on October 11, 2023. The remaining Windows Server end of life dates are January 13, 2027 for 2016, January 10, 2029 for 2019, and October 15, 2031 for 2022. Microsoft's lifecycle pages are the authority if a date matters to a contract.
What is the Windows Server upgrade path from 2012 R2?
Windows Server 2012 R2 end of life has passed, so the priority is getting off it. The in place Windows Server upgrade path from 2012 R2 goes to 2016 or 2019 first, then onward. A clean install on new hardware or a new virtual machine, followed by moving roles and data, is usually safer than chaining upgrades.
Keep readingRelated concepts
Read next · Directory and identity Active Directory Explained Where to query for the servers nobody put on the asset register, by operating system attribute. Open this next15 min- Hypervisors · 11 min Hyper-V vs VMware The hosts the forgotten servers are almost always running on, and the licensing that decides where they land next.
- Operations · 13 min Patch Management, and Why the Hard Part Is Not the Patching A newly upgraded server that is not in the patching schedule is the same problem with a later date on it.
- Managed IT · 10 min CapEx and OpEx in IT, and Why the Budget Line Shapes the Build Why a fully depreciated server can still be a liability.
- Operations · 10 min What a CMDB Is, and the Question That Justifies One The other inventory question, and why it is not this one.
- Vulnerability management · 10 min The NVD, the CVE and the Score That Does Not Decide Anything Why a scored vulnerability still has nowhere to go on unsupported software.
- Windows · 8 min Reboot Event IDs, and the One That Names the Culprit How to tell which process asked for the restart.
- IT strategy · 10 min Legacy Systems, What the Word Means and Why the Old One Is Still Running The security-patch risk that turns a working legacy system into a liability.