SQL Server 2016 is now out of extended support: its Extended Security Update (ESU) Year 1 began on 14 July 2026. You have three ways forward: subscribe to ESUs through Azure Arc (or the SQL IaaS Agent extension on Azure VMs) for up to three more years of critical security fixes, upgrade to a supported SQL Server version, or migrate to Azure SQL Managed Instance or Azure SQL Database, which don't reach end of support. Most estates use ESUs to buy time while they upgrade or migrate, and if you subscribe now you're billed back to 14 July 2026.
Who this is for and what you will have at the end
This guide is for database administrators and IT managers who still run SQL Server 2016 (13.x) on-premises, in another cloud, or on Azure VMs, and need to decide what to do with each instance.
At the end you will have:
- A clear comparison of the ESU, upgrade and migrate options.
- An inventory of SQL Server 2016 instances and their ESU status.
- ESUs enabled through Azure Arc for the instances that need more time, with the right licensing model.
- An upgrade or migration path for each instance.
What end of support means for SQL Server 2016
Every SQL Server version gets at least ten years of support: five years of mainstream support and five of extended support, which covers security updates only. After that, Microsoft no longer services the product unless you have ESUs.
ESUs are narrow by design:
- They're released only when the Microsoft Security Response Center rates a vulnerability as Critical, so there's no regular cadence.
- They don't include new features, functional improvements or customer-requested fixes.
- ESU licenses don't include support for SQL Server 2016 itself; support is limited to deploying, installing and activating the updates.
- ESU packages include the most recent cumulative update. If you only applied GDR updates, install and validate the latest CU when you subscribe instead of waiting for the first ESU.
Two changes from the SQL Server 2014 ESU program matter for planning. The SQL Server 2016 ESU price structure is different, and moving SQL Server 2016 to an Azure VM no longer gets you free ESUs.
Compare the options
| Option | What you get | Main considerations |
|---|---|---|
| ESUs through Azure Arc | Critical security fixes for up to three years, no change to the server | Hourly billing, bill-back to 14 July 2026, needs Arc connectivity and SA or pay-as-you-go |
| ESUs on Azure VMs | Same fixes for SQL Server 2016 on Azure VMs via the SQL IaaS Agent extension | Not free for 2016 |
| Upgrade in place or side by side | A current SQL Server version with its own lifecycle | OS may also need upgrading; application testing |
| Azure SQL Managed Instance | Fully managed, near full SQL Server compatibility, never reaches end of support | Feature differences, network design, migration effort |
| Azure SQL Database Hyperscale | Fully managed database service | Database-scoped; more application change |
Microsoft's end-of-support guidance also lists moving as-is to an Azure VM or Azure VMware Solution and subscribing to ESUs there.
Prerequisites for ESUs through Azure Arc
- Network connectivity from each server to Azure for the Azure Connected Machine agent. Connecting SQL Server to Azure Arc is free.
- One of these license positions for each instance:
- Software Assurance or an active SQL Server subscription under an Enterprise Agreement, Enterprise Agreement Subscription, Server and Cloud Enrollment or Enrollment for Education Solutions, or
- Pay-as-you-go billing for SQL Server enabled in Azure Arc.
- Perpetual licenses without Software Assurance and Server+CAL licenses don't qualify. You can still connect those instances and set the license type to pay-as-you-go to subscribe.
- If you can't connect a server to Azure Arc at all, you might be eligible for ESUs through volume licensing; Microsoft directs you to your account team, and you then register the disconnected instance manually in the Azure portal.
Step 1: Connect SQL Server 2016 instances to Azure Arc
When a server connected to Azure Arc has SQL Server installed, Azure Arc automatically installs the Azure extension for SQL Server and creates an Azure resource for each instance. For a server that isn't connected yet, generate an onboarding script:
- In the Azure portal, go to Azure Arc, then under Data services select SQL servers, and under SQL Server instances select + Add.
- Select Connect SQL Server instances, review the prerequisites, and enter the subscription, resource group, region and operating system.
- Select the SQL Server edition and license type. Choose Pay-as-you-go or License with Software Assurance if you want ESUs.
- Download the generated script and run it on the server from an elevated PowerShell session after signing in to Azure.
& '.\RegisterSqlServerArc.ps1'The script installs the Azure Connected Machine agent if needed, then the Azure extension for SQL Server. The agent registers the server as a Server - Azure Arc resource, and the extension registers each instance as a SQL Server - Azure Arc resource. Validate the result under Azure Arc > SQL Server.
Step 2: Find your SQL Server 2016 instances and their ESU status
Microsoft publishes an Azure Resource Graph query that lists eligible instances with their license type and ESU status. This version filters for SQL Server 2016:
resources
| where type == 'microsoft.azurearcdata/sqlserverinstances'
| extend Version = properties.version
| extend Edition = properties.edition
| extend containerId = tolower(tostring(properties.containerResourceId))
| where Version in ("SQL Server 2016")
| where Edition in ("Enterprise", "Standard")
| where isnotempty(containerId)
| project containerId, SQL_instance = name, Version, Edition
| join kind=inner (
resources
| where type == "microsoft.hybridcompute/machines"
| extend machineId = tolower(tostring(id))
| project machineId, Machine_name = name
) on $left.containerId == $right.machineId
| join kind=inner (
resources
| where type == "microsoft.hybridcompute/machines/extensions"
| where properties.type in ("WindowsAgent.SqlServer","LinuxAgent.SqlServer")
| extend machineIdHasSQLServerExtensionInstalled = tolower(iff(id contains "/extensions/WindowsAgent.SqlServer" or id contains "/extensions/LinuxAgent.SqlServer", substring(id, 0, indexof(id, "/extensions/")), ""))
| project machineIdHasSQLServerExtensionInstalled,
Extension_State = properties.provisioningState,
License_Type = properties.settings.LicenseType,
ESU = iff(notnull(properties.settings.enableExtendedSecurityUpdates), iff(properties.settings.enableExtendedSecurityUpdates == 'true',"ENABLED","disabled"), "disabled"),
Extension_Version = properties.instanceView.typeHandlerVersion
) on $left.machineId == $right.machineIdHasSQLServerExtensionInstalled
| project-away machineId, containerId, machineIdHasSQLServerExtensionInstalledUse the result to tag each instance with its decision: ESU and upgrade, ESU and migrate, or migrate immediately.
Step 3: Choose the ESU licensing model
Azure Arc offers three ways to license ESUs in production. In the documentation's normalized-core model, one Standard core license equals one normalized core and one Enterprise core license equals four.
| Model | Billed on | Best when |
|---|---|---|
| Virtual cores | vCPUs of each VM running SQL Server 2016 | VMs share hosts with other workloads, or you run in a hosted or third-party cloud |
| Physical cores without VMs | All physical cores of the host, at the highest edition installed | SQL Server runs directly on physical servers |
| Physical cores with unlimited virtualization | A SqlServerEsuLicenses resource covering the physical hosts (Enterprise ESU meter) | Many SQL Server 2016 VMs are consolidated on hosts you control |
Rules that affect cost:
- Usage is reported hourly. Each operating system environment is billed for all its cores with a minimum of four.
- Standard edition ESU subscriptions are capped at 24 virtual or physical cores, even on larger machines.
- The physical core license resource has a minimum of 16 physical cores. Every VM on those hosts must be connected to Azure Arc, be in the license scope (tenant, subscription or resource group) and have Use physical core ESU license selected.
- The unlimited virtualization benefit isn't available on infrastructure from the providers Microsoft lists in its licensing documentation; VMs there are billed by virtual cores.
- Passive replicas in availability groups or failover cluster instances that meet the passivity criteria don't incur ESU charges, and billing follows the active replica after failover.
- Developer edition instances and machines in Azure dev/test subscriptions report $0 meters, so you can keep non-production on ESUs without charge when production is subscribed.
Step 4: Subscribe to ESUs
In the Azure portal
- Open the Azure Arc-enabled SQL Server resource and select SQL Server Configuration (from the machine, it's under Operations on the Azure Arc | Machines page).
- Set License type to Pay-as-you-go or License with Software Assurance.
- Select Subscribe to Extended Security Updates. If you're using a physical core ESU license, also select Use physical core ESU license.
- Select Save.
With PowerShell
The documented approach updates the extension settings with New-AzConnectedMachineExtension. Replace the placeholders with your values:
$Settings = @{
SqlManagement = @{ IsEnabled = $true };
LicenseType = "PAYG";
enableExtendedSecurityUpdates = $True;
esuLastUpdatedTimestamp = [DateTime]::UtcNow.ToString('yyyy-MM-ddTHH:mm:ss.fffZ')
}
New-AzConnectedMachineExtension -Name "WindowsAgent.SqlServer" `
-ResourceGroupName "rg-sql-legacy" `
-MachineName "sql2016-01" `
-Location "eastus" `
-Publisher "Microsoft.AzureData" `
-ExtensionType "WindowsAgent.SqlServer" `
-Settings $SettingsThe update overwrites all extension settings, so include any instance exclusion list you already use.
At scale with Azure Policy
Assign the built-in definition Subscribe eligible Arc-enabled SQL Servers instances to Extended Security Updates to a subscription or resource group. It enables ESUs on every Arc-enabled machine in scope that has the Azure extension for SQL Server, and activates the subscription immediately for qualifying instances. Scope it carefully, because every qualifying instance starts billing.
How billing works if you subscribe now
The SQL Server 2016 ESU subscription is available from Year 1 of the extended support period, which started on 14 July 2026. If you enable it after that date, the next month's bill includes a bill-back charge from the start of the current ESU year, based on the timestamp when ESU was enabled. After that, billing is hourly.
The subscription is canceled automatically when you upgrade the instance to a supported version or migrate it to Azure. When you migrate to Azure SQL, ESU charges stop. You can also cancel at any time by selecting Unsubscribe from Extended Security Updates and saving; charges stop immediately. Once ESUs are enabled, you can't change the license type to License only until you cancel.
If you previously bought ESUs through volume licensing, the transition to an Azure subscription happens automatically when you already have coverage for all prior ESU years.
Verification
- Rerun the Resource Graph query: every instance you intended to cover should show
ENABLEDand a license type ofPAYGorPaid. - In the instance's Extended Security Updates pane in the portal, confirm the subscription status. Instances with automatic updates enabled install ESUs automatically; for others, download the packages from that pane.
- Confirm the patch channel you use (Microsoft Update, Windows Update, Configuration Manager or Azure Update Manager) can reach the server, since ESUs are delivered through the same channels as regular updates.
- Check Cost Management after the first billing cycle for the expected ESU meters (named like "Std edition - ESU 2016" and "Ent edition - ESU 2016", plus the back-billing meters).
Plan the exit: upgrade or migrate
ESUs buy up to three years. Use them to execute one of these exits.
Upgrade to a current SQL Server version
SQL Server 2016 SP3 or later can be upgraded directly to SQL Server 2025. SQL Server 2025 requires Windows Server 2019 or later, so a SQL Server 2016 instance on Windows Server 2016 needs an OS upgrade or a new server. Pay particular attention to linked servers and replication, because SQL Server 2025 makes encryption mandatory for server-to-server OLE DB connections. The SQL Server 2025 upgrade checklist covers the pre-checks and rollback plan.
Migrate to Azure SQL Managed Instance
Managed Instance closely resembles an on-premises instance, supporting cross-database queries, SQL Agent jobs, CLR and transactional replication, so it suits most lift-and-shift migrations. For SQL Server 2016, the Managed Instance link supports one-way replication from SQL Server 2016 SP3 with the matching Azure Connect pack, on Windows Server, which gives a near-zero downtime cutover. After cutover the link is removed and you can't fail back to SQL Server 2016. The Managed Instance link migration runbook walks through it. Microsoft's end-of-support guidance also lists SQL Server migration in Azure Arc, Azure Database Migration Service and the migration component in SQL Server Management Studio as migration tools.
Other targets
- Azure SQL Database Hyperscale for applications that can work with a single-database model.
- SQL Server on Azure VMs, either upgraded during the move or moved as-is with paid ESUs.
For the broader sequencing of moving many workloads to Azure, see the enterprise Azure cloud migration playbook.
Troubleshooting
You can't subscribe an instance to ESUs. ESUs require the host's license type to be Pay-as-you-go or License with Software Assurance. If it's set to License only, change it first, then subscribe.
Billed for more cores than expected on a VM. Billing covers all cores visible to the operating system environment, with a minimum of four. Check the VM size, or use a physical core ESU license if the host qualifies for unlimited virtualization.
Charges continue after moving to a physical core license. VMs in scope must have Use physical core ESU license selected; otherwise they're billed individually.
Server+CAL instance can't subscribe. ESUs through Azure Arc aren't available for Server+CAL licensing. Set the instance's license type to pay-as-you-go, then enable ESUs.
The extension settings were lost after a CLI update. az connectedmachine extension update --settings overwrites all settings. Reapply the full settings object, including exclusions and ESU flags.
Checklist
- Every SQL Server 2016 instance inventoried, with edition, host type and core count.
- Decision recorded per instance: ESU plus upgrade, ESU plus migrate, or migrate now.
- Instances connected to Azure Arc with the Azure extension for SQL Server.
- License type set to pay-as-you-go or Software Assurance; ESU licensing model chosen.
- ESUs enabled and verified; bill-back from 14 July 2026 budgeted.
- Latest SQL Server 2016 CU installed and patch channel working.
- Upgrade or migration project scheduled well inside the three-year ESU window.
References
- What are Extended Security Updates for SQL Server?
- SQL Server Extended Security Updates enabled by Azure Arc
- SQL Server end of support options
- Connect your SQL Server to Azure Arc
- Configure SQL Server enabled by Azure Arc
- Supported version and edition upgrades (SQL Server 2025)
- Hardware and software requirements for SQL Server 2025
- Overview of the Managed Instance link