Databases & HA

SQL Server 2016 End of Support: ESUs via Azure Arc or Migrate to Azure SQL

SQL Server 2016 left extended support on 14 July 2026. Compare buying Extended Security Updates through Azure Arc, upgrading in place, and migrating to Azure SQL Managed Instance.

12 min read
On this page

SQL Server 2016 is now out of extended support: its Extended Security Update (ESU) Year 1 began on 14 July 2026. You have three ways forward: subscribe to ESUs through Azure Arc (or the SQL IaaS Agent extension on Azure VMs) for up to three more years of critical security fixes, upgrade to a supported SQL Server version, or migrate to Azure SQL Managed Instance or Azure SQL Database, which don't reach end of support. Most estates use ESUs to buy time while they upgrade or migrate, and if you subscribe now you're billed back to 14 July 2026.

Who this is for and what you will have at the end

This guide is for database administrators and IT managers who still run SQL Server 2016 (13.x) on-premises, in another cloud, or on Azure VMs, and need to decide what to do with each instance.

At the end you will have:

  • A clear comparison of the ESU, upgrade and migrate options.
  • An inventory of SQL Server 2016 instances and their ESU status.
  • ESUs enabled through Azure Arc for the instances that need more time, with the right licensing model.
  • An upgrade or migration path for each instance.

What end of support means for SQL Server 2016

Every SQL Server version gets at least ten years of support: five years of mainstream support and five of extended support, which covers security updates only. After that, Microsoft no longer services the product unless you have ESUs.

ESUs are narrow by design:

  • They're released only when the Microsoft Security Response Center rates a vulnerability as Critical, so there's no regular cadence.
  • They don't include new features, functional improvements or customer-requested fixes.
  • ESU licenses don't include support for SQL Server 2016 itself; support is limited to deploying, installing and activating the updates.
  • ESU packages include the most recent cumulative update. If you only applied GDR updates, install and validate the latest CU when you subscribe instead of waiting for the first ESU.

Two changes from the SQL Server 2014 ESU program matter for planning. The SQL Server 2016 ESU price structure is different, and moving SQL Server 2016 to an Azure VM no longer gets you free ESUs.

Compare the options

OptionWhat you getMain considerations
ESUs through Azure ArcCritical security fixes for up to three years, no change to the serverHourly billing, bill-back to 14 July 2026, needs Arc connectivity and SA or pay-as-you-go
ESUs on Azure VMsSame fixes for SQL Server 2016 on Azure VMs via the SQL IaaS Agent extensionNot free for 2016
Upgrade in place or side by sideA current SQL Server version with its own lifecycleOS may also need upgrading; application testing
Azure SQL Managed InstanceFully managed, near full SQL Server compatibility, never reaches end of supportFeature differences, network design, migration effort
Azure SQL Database HyperscaleFully managed database serviceDatabase-scoped; more application change

Microsoft's end-of-support guidance also lists moving as-is to an Azure VM or Azure VMware Solution and subscribing to ESUs there.

Prerequisites for ESUs through Azure Arc

  • Network connectivity from each server to Azure for the Azure Connected Machine agent. Connecting SQL Server to Azure Arc is free.
  • One of these license positions for each instance:
    • Software Assurance or an active SQL Server subscription under an Enterprise Agreement, Enterprise Agreement Subscription, Server and Cloud Enrollment or Enrollment for Education Solutions, or
    • Pay-as-you-go billing for SQL Server enabled in Azure Arc.
  • Perpetual licenses without Software Assurance and Server+CAL licenses don't qualify. You can still connect those instances and set the license type to pay-as-you-go to subscribe.
  • If you can't connect a server to Azure Arc at all, you might be eligible for ESUs through volume licensing; Microsoft directs you to your account team, and you then register the disconnected instance manually in the Azure portal.

Step 1: Connect SQL Server 2016 instances to Azure Arc

When a server connected to Azure Arc has SQL Server installed, Azure Arc automatically installs the Azure extension for SQL Server and creates an Azure resource for each instance. For a server that isn't connected yet, generate an onboarding script:

  1. In the Azure portal, go to Azure Arc, then under Data services select SQL servers, and under SQL Server instances select + Add.
  2. Select Connect SQL Server instances, review the prerequisites, and enter the subscription, resource group, region and operating system.
  3. Select the SQL Server edition and license type. Choose Pay-as-you-go or License with Software Assurance if you want ESUs.
  4. Download the generated script and run it on the server from an elevated PowerShell session after signing in to Azure.
& '.\RegisterSqlServerArc.ps1'

The script installs the Azure Connected Machine agent if needed, then the Azure extension for SQL Server. The agent registers the server as a Server - Azure Arc resource, and the extension registers each instance as a SQL Server - Azure Arc resource. Validate the result under Azure Arc > SQL Server.

Step 2: Find your SQL Server 2016 instances and their ESU status

Microsoft publishes an Azure Resource Graph query that lists eligible instances with their license type and ESU status. This version filters for SQL Server 2016:

resources
| where type == 'microsoft.azurearcdata/sqlserverinstances'
| extend Version = properties.version
| extend Edition = properties.edition
| extend containerId = tolower(tostring(properties.containerResourceId))
| where Version in ("SQL Server 2016")
| where Edition in ("Enterprise", "Standard")
| where isnotempty(containerId)
| project containerId, SQL_instance = name, Version, Edition
| join kind=inner (
    resources
    | where type == "microsoft.hybridcompute/machines"
    | extend machineId = tolower(tostring(id))
    | project machineId, Machine_name = name
) on $left.containerId == $right.machineId
| join kind=inner (
    resources
    | where type == "microsoft.hybridcompute/machines/extensions"
    | where properties.type in ("WindowsAgent.SqlServer","LinuxAgent.SqlServer")
    | extend machineIdHasSQLServerExtensionInstalled = tolower(iff(id contains "/extensions/WindowsAgent.SqlServer" or id contains "/extensions/LinuxAgent.SqlServer", substring(id, 0, indexof(id, "/extensions/")), ""))
    | project machineIdHasSQLServerExtensionInstalled,
        Extension_State = properties.provisioningState,
        License_Type = properties.settings.LicenseType,
        ESU = iff(notnull(properties.settings.enableExtendedSecurityUpdates), iff(properties.settings.enableExtendedSecurityUpdates == 'true',"ENABLED","disabled"), "disabled"),
        Extension_Version = properties.instanceView.typeHandlerVersion
) on $left.machineId == $right.machineIdHasSQLServerExtensionInstalled
| project-away machineId, containerId, machineIdHasSQLServerExtensionInstalled

Use the result to tag each instance with its decision: ESU and upgrade, ESU and migrate, or migrate immediately.

Step 3: Choose the ESU licensing model

Azure Arc offers three ways to license ESUs in production. In the documentation's normalized-core model, one Standard core license equals one normalized core and one Enterprise core license equals four.

ModelBilled onBest when
Virtual coresvCPUs of each VM running SQL Server 2016VMs share hosts with other workloads, or you run in a hosted or third-party cloud
Physical cores without VMsAll physical cores of the host, at the highest edition installedSQL Server runs directly on physical servers
Physical cores with unlimited virtualizationA SqlServerEsuLicenses resource covering the physical hosts (Enterprise ESU meter)Many SQL Server 2016 VMs are consolidated on hosts you control

Rules that affect cost:

  • Usage is reported hourly. Each operating system environment is billed for all its cores with a minimum of four.
  • Standard edition ESU subscriptions are capped at 24 virtual or physical cores, even on larger machines.
  • The physical core license resource has a minimum of 16 physical cores. Every VM on those hosts must be connected to Azure Arc, be in the license scope (tenant, subscription or resource group) and have Use physical core ESU license selected.
  • The unlimited virtualization benefit isn't available on infrastructure from the providers Microsoft lists in its licensing documentation; VMs there are billed by virtual cores.
  • Passive replicas in availability groups or failover cluster instances that meet the passivity criteria don't incur ESU charges, and billing follows the active replica after failover.
  • Developer edition instances and machines in Azure dev/test subscriptions report $0 meters, so you can keep non-production on ESUs without charge when production is subscribed.

Step 4: Subscribe to ESUs

In the Azure portal

  1. Open the Azure Arc-enabled SQL Server resource and select SQL Server Configuration (from the machine, it's under Operations on the Azure Arc | Machines page).
  2. Set License type to Pay-as-you-go or License with Software Assurance.
  3. Select Subscribe to Extended Security Updates. If you're using a physical core ESU license, also select Use physical core ESU license.
  4. Select Save.

With PowerShell

The documented approach updates the extension settings with New-AzConnectedMachineExtension. Replace the placeholders with your values:

$Settings = @{
    SqlManagement = @{ IsEnabled = $true };
    LicenseType = "PAYG";
    enableExtendedSecurityUpdates = $True;
    esuLastUpdatedTimestamp = [DateTime]::UtcNow.ToString('yyyy-MM-ddTHH:mm:ss.fffZ')
}
 
New-AzConnectedMachineExtension -Name "WindowsAgent.SqlServer" `
    -ResourceGroupName "rg-sql-legacy" `
    -MachineName "sql2016-01" `
    -Location "eastus" `
    -Publisher "Microsoft.AzureData" `
    -ExtensionType "WindowsAgent.SqlServer" `
    -Settings $Settings

The update overwrites all extension settings, so include any instance exclusion list you already use.

At scale with Azure Policy

Assign the built-in definition Subscribe eligible Arc-enabled SQL Servers instances to Extended Security Updates to a subscription or resource group. It enables ESUs on every Arc-enabled machine in scope that has the Azure extension for SQL Server, and activates the subscription immediately for qualifying instances. Scope it carefully, because every qualifying instance starts billing.

How billing works if you subscribe now

The SQL Server 2016 ESU subscription is available from Year 1 of the extended support period, which started on 14 July 2026. If you enable it after that date, the next month's bill includes a bill-back charge from the start of the current ESU year, based on the timestamp when ESU was enabled. After that, billing is hourly.

The subscription is canceled automatically when you upgrade the instance to a supported version or migrate it to Azure. When you migrate to Azure SQL, ESU charges stop. You can also cancel at any time by selecting Unsubscribe from Extended Security Updates and saving; charges stop immediately. Once ESUs are enabled, you can't change the license type to License only until you cancel.

If you previously bought ESUs through volume licensing, the transition to an Azure subscription happens automatically when you already have coverage for all prior ESU years.

Verification

  • Rerun the Resource Graph query: every instance you intended to cover should show ENABLED and a license type of PAYG or Paid.
  • In the instance's Extended Security Updates pane in the portal, confirm the subscription status. Instances with automatic updates enabled install ESUs automatically; for others, download the packages from that pane.
  • Confirm the patch channel you use (Microsoft Update, Windows Update, Configuration Manager or Azure Update Manager) can reach the server, since ESUs are delivered through the same channels as regular updates.
  • Check Cost Management after the first billing cycle for the expected ESU meters (named like "Std edition - ESU 2016" and "Ent edition - ESU 2016", plus the back-billing meters).

Plan the exit: upgrade or migrate

ESUs buy up to three years. Use them to execute one of these exits.

Upgrade to a current SQL Server version

SQL Server 2016 SP3 or later can be upgraded directly to SQL Server 2025. SQL Server 2025 requires Windows Server 2019 or later, so a SQL Server 2016 instance on Windows Server 2016 needs an OS upgrade or a new server. Pay particular attention to linked servers and replication, because SQL Server 2025 makes encryption mandatory for server-to-server OLE DB connections. The SQL Server 2025 upgrade checklist covers the pre-checks and rollback plan.

Migrate to Azure SQL Managed Instance

Managed Instance closely resembles an on-premises instance, supporting cross-database queries, SQL Agent jobs, CLR and transactional replication, so it suits most lift-and-shift migrations. For SQL Server 2016, the Managed Instance link supports one-way replication from SQL Server 2016 SP3 with the matching Azure Connect pack, on Windows Server, which gives a near-zero downtime cutover. After cutover the link is removed and you can't fail back to SQL Server 2016. The Managed Instance link migration runbook walks through it. Microsoft's end-of-support guidance also lists SQL Server migration in Azure Arc, Azure Database Migration Service and the migration component in SQL Server Management Studio as migration tools.

Other targets

  • Azure SQL Database Hyperscale for applications that can work with a single-database model.
  • SQL Server on Azure VMs, either upgraded during the move or moved as-is with paid ESUs.

For the broader sequencing of moving many workloads to Azure, see the enterprise Azure cloud migration playbook.

Troubleshooting

You can't subscribe an instance to ESUs. ESUs require the host's license type to be Pay-as-you-go or License with Software Assurance. If it's set to License only, change it first, then subscribe.

Billed for more cores than expected on a VM. Billing covers all cores visible to the operating system environment, with a minimum of four. Check the VM size, or use a physical core ESU license if the host qualifies for unlimited virtualization.

Charges continue after moving to a physical core license. VMs in scope must have Use physical core ESU license selected; otherwise they're billed individually.

Server+CAL instance can't subscribe. ESUs through Azure Arc aren't available for Server+CAL licensing. Set the instance's license type to pay-as-you-go, then enable ESUs.

The extension settings were lost after a CLI update. az connectedmachine extension update --settings overwrites all settings. Reapply the full settings object, including exclusions and ESU flags.

Checklist

  • Every SQL Server 2016 instance inventoried, with edition, host type and core count.
  • Decision recorded per instance: ESU plus upgrade, ESU plus migrate, or migrate now.
  • Instances connected to Azure Arc with the Azure extension for SQL Server.
  • License type set to pay-as-you-go or Software Assurance; ESU licensing model chosen.
  • ESUs enabled and verified; bill-back from 14 July 2026 budgeted.
  • Latest SQL Server 2016 CU installed and patch channel working.
  • Upgrade or migration project scheduled well inside the three-year ESU window.

References

Questions people ask

When did SQL Server 2016 extended support end?

Extended support has ended, and Year 1 of the SQL Server 2016 Extended Security Update period started on 14 July 2026. From then on, security fixes are only available to instances covered by an ESU subscription, for up to three years.

Are SQL Server 2016 ESUs free on Azure virtual machines?

No. Unlike SQL Server 2014, moving SQL Server 2016 to an Azure VM no longer gives free ESUs. You can subscribe through the SQL IaaS Agent extension on Azure VMs, or through Azure Arc for servers outside Azure.

What happens if I subscribe to ESUs after July 2026?

Your next monthly bill includes a bill-back charge from the start of the current ESU year, which for SQL Server 2016 began on 14 July 2026. After that the subscription is billed hourly and can be canceled at any time without penalty.

Do I need Software Assurance to get ESUs through Azure Arc?

You need either Software Assurance or an active SQL Server subscription under a qualifying agreement, or you can set the instance's license type to pay-as-you-go in Azure Arc. Perpetual licenses without Software Assurance and Server+CAL licenses aren't eligible unless you switch the instance to pay-as-you-go.

SQL Server 2016Azure ArcExtended Security UpdatesAzure SQL Managed Instance
  1. Azure SQL Database Backups: Point-in-Time Restore, LTR and Geo-Restore

    Set PITR retention and backup redundancy, add a long-term retention policy, and run point-in-time, deleted-database, LTR and geo-restores for Azure SQL Database and Managed Instance.

    Databases & HA13 min read
  2. Azure SQL Database vs Managed Instance vs SQL Server VM: How to Choose

    Compare Azure SQL Database, Azure SQL Managed Instance and SQL Server on Azure VMs on compatibility, high availability, limits, cost model and management, then pick one with a repeatable assessment.

    Databases & HA14 min read
  3. Azure SQL Entra Authentication: Entra-Only Mode and Managed Identity

    Replace SQL logins on Azure SQL Database and Managed Instance with Microsoft Entra ID: set the Entra admin, create users for groups and managed identities, then enable Entra-only authentication.

    Databases & HA11 min read