Windows Server 2016 End of Support: Options for MSPs
Windows Server 2016 end of support is 12 January 2027. How MSPs can classify customer workloads and plan file server replacement before the deadline.
Windows Server 2016 End of Support: File Server Replacement Options for MSPs
Windows Server 2016 end of support is on 12 January 2027. For most MSPs, it affects customer servers that have taken on more roles than anyone documented. Some only hold shared folders. Others also run a line-of-business database, a scan-to-folder target, a print server or a domain controller. This article explains what the deadline changes and how to choose a replacement for each workload.
Quick answer: what MSPs need to know
Windows Server 2016 reaches the end of extended support on 12 January 2027. After that date, Microsoft stops providing regular security updates and support for the product, although the servers will keep running. MSPs should inventory every affected customer environment before choosing a destination, because a single Windows Server 2016 installation often combines file shares, applications, databases, identity services and device dependencies. No single replacement fits every Windows Server workload. Shared files, SMB-dependent applications and domain controllers usually need different destinations, and the migration plan should be built around that classification.
What ends when Windows Server 2016 support ends?
On 12 January 2027, Windows Server 2016 leaves extended support, the final phase of Microsoft's Fixed Lifecycle Policy. The Microsoft Windows Server 2016 lifecycle page lists the date for the Datacenter, Essentials, MultiPoint Premium and Standard editions. What changes is maintenance: regular security updates and standard technical support end. What does not change is the running server, which will still boot, serve files and run applications after the deadline.
That gap is where the risk sits. An unpatched server becomes harder to defend over time and can raise issues in security reviews, cyber insurance questionnaires and compliance audits. The MSP is also left supporting a platform without the vendor behind it.
Where Extended Security Updates fit
Extended Security Updates (ESU) is Microsoft's paid programme that provides critical and important security updates for certain products after the end of extended support. Microsoft's Extended Security Updates FAQ describes ESU as a last-resort option and a temporary bridge while customers migrate, not a long-term solution. If a customer needs more time, confirm with Microsoft or your licensing distributor whether an ESU offer applies to Windows Server 2016 and whether the customer is eligible. Treat any ESU period as fixed migration time.
Why a Windows Server 2016 inventory must come before the migration decision
The inventory determines the destination, so it must come first. Choosing a platform before you know what a server does is a frequent reason a file server migration overruns or breaks a workflow at cutover. Before selecting any Windows Server 2016 migration option, record for each server:
- The roles and features actually installed and in use
- Shared folders, their size, file counts and growth
- Users, security groups and who needs access to what
- Existing access requirements, including folders with restricted or inherited permissions
- Applications, scripts and devices that read from or write to the server
- Remote access and offline working patterns
- Backup, retention and recovery requirements
- Business-critical dependencies and the people who own them
Separate the file shares from the server-dependent workloads
Classify each workload before assigning a destination. These categories behave differently during migration and should be planned separately.
Ordinary shared-file workloads
Ordinary shared files are documents, spreadsheets, drawings and project folders that people open, edit and save through a desktop client or browser. These workloads are often suitable for a managed file-sharing platform, provided the access model, file sizes and editing patterns are confirmed during the pilot.
SMB and UNC-dependent applications
Server Message Block (SMB) is the network file-sharing protocol behind Windows shares. A Universal Naming Convention (UNC) path is the \\server\share address that software uses to reach them. Applications, macros, linked documents and scripts that store hard-coded SMB or UNC paths need separate technical validation. If the software cannot use the target platform's access method, it needs a destination that provides SMB access.
Databases and server-side applications
Databases and applications that run services on the server are not ordinary file-sharing workloads. Many line-of-business applications keep live data files on a share and expect file locking, low latency and a consistent path. These need a supported application platform, such as a newer Windows Server, a hosted version of the application or a vendor-approved cloud service.
Identity, print, scan and scheduled-task dependencies
Domain controller and identity functions, print queues, scan-to-folder targets and scheduled tasks each need their own migration or replacement plan. Active Directory Domain Services roles require their own supported migration plan. Entra ID can cover some cloud identity scenarios, but it is not a direct replacement for every AD DS function. Print services, scan-to-folder workflows and scheduled tasks must also be assessed separately.
Windows Server 2016 replacement options
The right way to replace Windows Server 2016 is to select a destination per workload, not per server. The table summarises the common file server replacement options and where each fits.
One customer may need more than one destination: department folders on a managed file platform, Teams documents in SharePoint, a line-of-business application on a new Windows Server and identity in Entra ID. For a broader view of how MSPs combine these platforms, see our article on what MSPs are using instead of traditional Windows file servers. If you need the underlying concept first, our guide explains what a cloud file server is and how MSPs deploy it.
Where RushFiles fits in a Windows file server replacement
RushFiles fits the shared-file part of a Windows file server replacement: the folders people work in daily and share inside and outside the organisation.
Users work through File Explorer on Windows and Finder on macOS, so day-to-day file handling stays familiar. The same files are available through the web application and the iOS and Android apps for remote access.
Data is organised into Company Shares, private Shares and subfolder Shares. Administrators assign users and groups to Shares with read, write or owner access. RushFiles integrates with Active Directory and Entra ID for user and group administration. Existing NTFS (New Technology File System) permissions are not migrated automatically, so current access requirements need to be reviewed and mapped to RushFiles users, groups, Shares and access levels.
Each customer runs as a separate RushFiles company with its own users, data, capacity and configuration, managed through central reseller administration. RushFiles SaaS is hosted in EU-based infrastructure, while RushFiles On-Premise runs on provider-controlled infrastructure. The service can be presented under the MSP's brand, with the available branding scope depending on the deployment model. If a customer is deciding between Microsoft 365 storage and a dedicated file layer, our comparison of RushFiles with OneDrive and SharePoint covers the trade-offs.
The scope, migration approach and technical controls are described on the file server replacement with RushFiles page.
A practical action plan for MSPs
These five steps turn a customer list into a controlled file server migration.
Identify affected customer environments. Pull every Windows Server 2016 instance from your RMM and documentation, including virtual machines and servers at branch sites. Record customer, hardware age and contract status, then rank environments by risk and complexity.
Inventory server roles, data and dependencies. For each server, document installed roles, shares, data volume, users and groups, current access requirements and every application, script or device that connects to it. Confirm findings with key users, because some dependencies only appear at month-end.
Classify each workload and select its destination. Assign each workload to a category, such as shared files, SMB-dependent, database, identity or device dependency, and choose a destination for each. Record every blocker and its owner.
Run a representative pilot. Select representative users, including heavy and remote users. Apply real permissions and check Windows and macOS access where both are used. Test frequently edited and large files, remote and offline workflows, external sharing and file recovery. Include at least one workflow that could prevent the migration, such as a scanner, a linked spreadsheet or an application that expects a mapped drive, and define acceptance criteria before the pilot starts.
Plan cutover, validation and rollback. Schedule a final synchronisation and freeze window and inform users in advance. Validate access, file counts and key workflows after cutover. Keep the source server read-only for an agreed period, with a documented rollback trigger, before decommissioning.
Use the File Server Exit Plan 2027 Workbook
The File Server Exit Plan 2027 Workbook gives MSPs a structured way to run the steps above for each customer. It helps you:
- Inventory the current environment
- Classify workloads
- Identify dependencies and migration blockers
- Compare replacement options
- Define pilot acceptance criteria
- Plan cutover and rollback
Frequently asked questions
When does Windows Server 2016 support end?
Windows Server 2016 reaches the end of extended support on 12 January 2027, according to Microsoft's lifecycle information. The date applies to the Datacenter, Essentials, MultiPoint Premium and Standard editions, which follow Microsoft's Fixed Lifecycle Policy. After 12 January 2027, Microsoft no longer provides regular security updates or standard technical support for the product.
Can Windows Server 2016 still be used after January 2027?
Yes. Windows Server 2016 does not stop working when support ends, and servers continue to run their roles and applications. However, without regular security updates, newly discovered vulnerabilities remain unpatched unless the customer is covered by an eligible post-support programme. This increases security exposure and can cause issues in audits and insurance reviews.
Is Extended Security Updates a replacement for migration?
No. Microsoft describes Extended Security Updates as a last-resort paid option and a temporary bridge while organisations move to a supported platform. ESU provides critical and important security updates only, without new features or standard technical support. Confirm with Microsoft or your licensing partner whether an ESU offer applies to Windows Server 2016 and whether the customer is eligible, and use any ESU period as fixed migration time.
Can SharePoint replace a Windows file server?
SharePoint and OneDrive can replace a Windows file server for workloads centred on Microsoft 365 collaboration, Teams and Office co-authoring. They are less suitable where users expect drive-style access to deep folder structures, very large files or complex permissions, and workflows often need redesign. A mixed approach, with SharePoint for some workloads and another platform for the rest, is often a practical outcome.
Which workloads need Azure Files or another server?
Workloads that depend on SMB or UNC paths usually need Azure Files, a newer Windows Server or a NAS. This includes applications with live data files on a share, scripts that write to a network path and scanners that save to a Windows folder. Databases, server-side applications and domain controller roles need a supported application or identity platform rather than a file-sharing service.
Can RushFiles replace every Windows file server?
No. RushFiles is designed for suitable shared-file workloads that need File Explorer and Finder access, web and mobile access, remote access, internal and external sharing and central MSP administration. It does not replace domain controllers, databases, server-side applications or workloads that require SMB or UNC paths. Existing NTFS permissions are not migrated automatically and must be mapped to RushFiles users, groups and Shares.
Next step
Windows Server 2016 end of support is a fixed date, but the work varies by customer. Start with one documented customer environment, classify every workload on its servers and validate the chosen destination with a representative pilot before scaling the approach to other customers. The File Server Exit Plan 2027 Workbook provides the structure for that first assessment, and the RushFiles migration-planning guidance explains how shared-file workloads move from assessment to cutover.