You can upgrade SQL Server 2016 SP3, 2017, 2019 or 2022 to SQL Server 2025 in place, but the risky part isn't Setup itself: it's the switch to Microsoft OLE DB Driver 19, which makes encryption mandatory for linked servers and remote replication distributors, plus the removal of legacy full-text components, Data Quality Services and Master Data Services. Check the operating system (Windows Server 2019 or later), fix certificates or linked server provider strings before cutover, and plan rollback around restoring pre-upgrade backups, because a database upgraded to SQL Server 2025 can't move back to an older version.
Who this is for and what you will have at the end
This checklist is for database administrators upgrading existing SQL Server 2016, 2019 or 2022 instances on Windows to SQL Server 2025 (17.x), either in place, side by side, or as a rolling upgrade of an availability group.
At the end you will have:
- Confirmed that the version, edition and operating system can be upgraded.
- Found and fixed the encryption-related breaking changes before they cause an outage.
- Run the upgrade with Setup or from the command line.
- Verified the instance and moved databases to the new compatibility level in a controlled way.
- A rollback plan that matches how SQL Server upgrades actually work.
Supported upgrade paths and editions
SQL Server 2025 supports upgrade from:
| Source version | Minimum level |
|---|---|
| SQL Server 2014 | SP3 or later |
| SQL Server 2016 | SP3 or later |
| SQL Server 2017 | Any |
| SQL Server 2019 | Any |
| SQL Server 2022 | Any |
Edition changes to plan for:
- Web edition is discontinued. Web edition upgrades to Enterprise or Standard.
- Express with Advanced Services is discontinued. Express now includes those features and its maximum database size is 50 GB.
- Standard edition limits increased to the lesser of 4 sockets or 32 cores, and 256 GB of buffer pool memory. Resource Governor is now available in Standard.
- Developer edition is split into Enterprise Developer and Standard Developer. A Developer edition source can upgrade to either.
Pre-upgrade checks
Operating system and hardware
| Requirement | SQL Server 2025 |
|---|---|
| Operating system | Windows Server 2019 or later; Windows 10 or later |
| Processor | x64 only; Intel and AMD x86-64 with up to 64 cores per NUMA node |
| Windows Arm64 | Not supported (listed in the known issues) |
| .NET Framework | 4.7.2 |
| Disk | At least 6 GB free, more depending on features |
| Memory | 1 GB minimum (512 MB for Express); at least 4 GB recommended |
The operating system line is the one that catches people out. A SQL Server 2016 instance running on Windows Server 2016 can't be upgraded in place to SQL Server 2025; you need either an OS upgrade first or a new server and a side-by-side migration. Microsoft's upgrade method guidance points to a new installation when the OS is unsupported or when you want new hardware anyway.
Setup blockers from the known issues list
- TLS 1.2 disabled. Installation fails if TLS 1.2 is disabled on the machine, including on failover cluster instances. Enable it before you run Setup.
- Visual C++ Redistributable. Upgrades from SQL Server 2016 and 2017 can fail if the Visual C++ Redistributable for Visual Studio 2022 (version 14.34 at minimum) is missing or older. Install or repair it first.
- Data Quality Services. If DQS is installed, the upgrade fails at the Feature Rules step. Use
/IACCEPTDQUNINSTALLon the command line, which removes DQS during the upgrade. - More than 64 logical cores per NUMA node. The instance can fail to start after installation. Limit cores per NUMA node to 64.
- Pending restart or stopped Windows Installer service. Either blocks the upgrade.
- SQL Server Agent. Enable Windows Authentication for SQL Server Agent and confirm the Agent service account is a member of the sysadmin role.
Features that are gone or deprecated
| Change | What to do |
|---|---|
| Data Quality Services discontinued | Plan the DQS replacement; remove it during upgrade |
| Master Data Services discontinued | Keep MDS on SQL Server 2022 or earlier, or replace it |
| Synapse Link discontinued | Use Mirroring in Fabric |
| Purview access policies discontinued | Use fixed server roles such as ##MS_ServerPerformanceStateReader## and ##MS_ServerSecurityStateReader## |
| Reporting Services | Consolidated under Power BI Report Server from SQL Server 2025 |
| Hot add CPU, lightweight pooling (fiber mode) | Deprecated; stop depending on them |
You also can't add features during an upgrade. Add them with SQL Server 2025 Setup after the upgrade completes.
Breaking changes to find before you upgrade
Encrypt is now mandatory by default
Starting with SQL Server 2025, the MSOLEDBSQL provider uses Microsoft OLE DB Driver 19. In version 19, the default Encrypt value changed from no to Mandatory, and certificate validation always happens when encryption is used. The same direction was taken earlier in other drivers: ODBC Driver 18 defaults Encrypt to yes/mandatory, and Microsoft.Data.SqlClient 4.0 changed Encrypt to default to true.
The practical effect is that any server-to-server connection made through OLE DB 19 to an instance that only has a self-signed certificate fails with a certificate trust error unless you change the configuration. Inventory linked servers now:
SELECT name, product, provider, data_source, provider_string
FROM sys.servers
WHERE is_linked = 1;For each linked server, choose a fix, in order of preference:
- Install a certificate from a public or internal CA on the target instance and use
encrypt=mandatory(orencrypt=strictfor TDS 8.0). - Accept the self-signed certificate with
encrypt=mandatory;trustservercertificate=yes. - Make encryption optional with
encrypt=optional.
The documented sp_addlinkedserver examples look like this:
EXECUTE sp_addlinkedserver
@server = N'S1_instance1',
@srvproduct = N'',
@provider = N'MSOLEDBSQL',
@provstr = N'encrypt=mandatory;trustservercertificate=yes',
@datasrc = N'S1\instance1';To change an existing linked server, update its provider string with sp_serveroption. The value replaces the whole provider string, so include anything that was already in it:
EXECUTE sp_serveroption
@server = N'S1_instance1',
@optname = N'provider string',
@optvalue = N'encrypt=mandatory;trustservercertificate=yes';If you can't change linked server definitions in time, trace flag 17600 keeps OLE DB version 18 behavior and defaults. Treat it as a temporary bridge, not the end state.
Replication with a remote distributor
Transactional, snapshot, peer-to-peer and merge replication can fail after the upgrade when the publisher uses a remote distributor that doesn't have a trusted certificate, because the publisher talks to the distributor through a linked server. Symptoms include changes to publications failing and Replication Monitor or agent status failing in SSMS. Check whether the instance is a publisher with a remote distributor:
EXECUTE sp_get_distributor;The recommended fix is a CA-issued certificate on the distributor before you upgrade. The less secure alternative, after upgrade, is to trust the self-signed certificate:
EXECUTE sp_changedistributor_property
@property = N'trust_distributor_certificate',
@value = N'yes';Adding a new remote distributor from a SQL Server 2025 publisher fails the same way, with SSL Provider: The certificate chain was issued by an authority that is not trusted. Use @trust_distributor_certificate = 'yes' on sp_adddistributor only if you can't deploy a certificate.
Log shipping monitor
Log shipping monitoring can break when the monitor is a remote SQL Server 2025 instance while other instances in the topology still run an earlier version. Avoid that combination by upgrading the monitor after the primary and secondary servers, and review Microsoft's TDS 8.0 guidance on certificates.
Full-text search
SQL Server 2025 removes the legacy word breaker and filter binaries. Existing full-text indexes are marked index_version = 1 after upgrade, and queries against them fail with Msg 30010. List them in each database before the upgrade so you can schedule rebuild time (after the upgrade, add WHERE fi.index_version = 1 to see only the ones still on version 1):
SELECT fc.name AS catalog_name,
OBJECT_SCHEMA_NAME(fi.object_id) AS schema_name,
OBJECT_NAME(fi.object_id) AS table_name
FROM sys.fulltext_indexes AS fi
JOIN sys.fulltext_catalogs AS fc
ON fi.fulltext_catalog_id = fc.fulltext_catalog_id;After the upgrade, confirm FULLTEXT_INDEX_VERSION is 2 and rebuild each catalog with ALTER FULLTEXT CATALOG [FtCatalog] REBUILD;. A catalog rebuild rebuilds every index in it; drop and re-create indexes individually if you need to control order or resource use.
Other behavior changes worth testing
- Login CPU. SQL authentication now hashes passwords with PBKDF2 (100,000 iterations of SHA-512). Expect slightly longer logins and higher CPU where connection pooling isn't used.
- Linked servers using MSDASQL with a provider string can fail with error 7416 for logins outside sysadmin, starting with CU4.
- Strict encryption. If you plan to force strict encryption, note that SQLPS, the Agent PowerShell subsystem, and Database Mail on Linux don't work with it.
- Windows Server 2025 with Lock pages in memory. Some configurations produce access violation dumps; the documented workaround is to disable LPIM for the SQL Server service account.
Choose the upgrade method
| Method | Downtime | Rollback | Use when |
|---|---|---|---|
| In-place | Instance offline during Setup | Reinstall old version and restore backups | Dev/test, or production that tolerates downtime on a supported OS |
| New installation (side by side) | Cutover only | Old instance stays intact | OS or hardware change, unsupported OS, or a cleaner rollback |
| Rolling (availability groups, FCIs) | One manual failover | Possible until you fail over to an upgraded replica | Existing HA topology |
For availability groups, upgrade remote secondaries first, then local secondaries, and the primary last. Remove automatic failover from synchronous-commit replicas before you start, fail over only to a synchronized synchronous-commit replica, and set backup preference to the primary because no replicas are readable or available for backups during a version upgrade. An upgraded primary can't ship log to a secondary that's still on the old version.
If you're moving to new servers anyway, the enterprise Azure cloud migration playbook covers sequencing, and the Managed Instance link runbook is an alternative if the target is Azure SQL Managed Instance rather than SQL Server 2025.
Run the upgrade
Before Setup, on the instance being upgraded:
- Take full backups of every user database and of
master,modelandmsdb, and test that they restore. - Run
DBCC CHECKDBon every database. - Script logins, Agent jobs, linked servers, credentials and server-level objects.
- Confirm system databases can autogrow and have disk space.
- Disable startup stored procedures. Find them with the query below.
- For SQL Server Agent multiserver (MSX/TSX) setups, upgrade target servers before the master server.
- Make sure replication is current and then stop it; stop applications that connect to the instance.
USE master;
SELECT name
FROM sys.procedures
WHERE OBJECTPROPERTY(object_id, 'ExecIsStartup') = 1;Then run Setup from the SQL Server 2025 media as an administrator: select Installation, then Upgrade from... previous versions of SQL Server, select the instance, review the features (they're preselected and can't be changed), choose the full-text upgrade option, and select Install on the Ready to Upgrade page. For an unattended upgrade of a default instance:
.\setup.exe /q /ACTION=upgrade /INSTANCENAME=MSSQLSERVER /INSTANCEID=MSSQLSERVER /IACCEPTSQLSERVERLICENSETERMS /IACCEPTDQUNINSTALL/INSTANCEID is required when upgrading from SQL Server 2008 or later. Add /FTUPGRADEOPTION (REBUILD, RESET or IMPORT) to control full-text catalogs, and the Integration Services account parameters if SSIS is installed. Leave out /IACCEPTDQUNINSTALL if DQS isn't installed. Add /PID=<product key> unless your installation media already includes the key: the command-line reference states that Evaluation is used when no product key is specified, so check SERVERPROPERTY('Edition') afterwards.
Verification
SELECT @@VERSION AS version,
SERVERPROPERTY('ProductVersion') AS product_version,
SERVERPROPERTY('Edition') AS edition;
SELECT name, compatibility_level, state_desc
FROM sys.databases;Then check:
- The Setup summary log reports success for every feature.
- Every linked server responds: run a simple query through each one, including from accounts that aren't sysadmin.
- Replication agents, log shipping jobs and Agent jobs run without errors.
- Full-text queries return results after catalogs are rebuilt.
Move compatibility levels deliberately
Upgraded databases keep their compatibility level. Query optimizer changes are tied to the latest level (170 for SQL Server 2025), so Microsoft's recommended workflow is:
- Upgrade without changing compatibility level.
- Enable Query Store and capture a baseline for a full business cycle.
- Change to compatibility level 170.
- Use Query Store to find plan regressions and force the previous good plan, or revert the compatibility level if needed.
ALTER DATABASE [SalesDb] SET QUERY_STORE = ON;
-- after the baseline period
ALTER DATABASE [SalesDb] SET COMPATIBILITY_LEVEL = 170;Troubleshooting
SSL Provider: The certificate chain was issued by an authority that is not trusted. A linked server or remote distributor connection now enforces certificate validation. Install a trusted certificate, or set trustservercertificate=yes in the provider string or trust_distributor_certificate for replication.
Msg 30010 ... If recently performed in-place upgrade to SQL2025, For help please see https://aka.ms/sqlfulltext. The full-text index is still version 1. Rebuild the catalog with version 2 components.
This application requires Microsoft Visual C++ Redistributable for Visual Studio 2022 (x64/x86, version 14.34 at minimum). Install or repair the redistributable and rerun Setup.
Upgrade stops at Feature Rules. Data Quality Services is installed. Rerun from the command line with /IACCEPTDQUNINSTALL.
Msg 7416 ... Access to the remote server is denied because no login-mapping exists. A linked server uses MSDASQL with a provider string. See the SQL Server 2025 known issues article for the affected builds.
Msg 15129 ... '3' is not a valid value for configuration option 'backup compression algorithm'. Setting ZSTD as the server default fails; specify the algorithm in the BACKUP statement instead.
Rollback plan
- In-place: Setup overwrites the previous version, and no SQL Server backup can be restored to an earlier version. Rollback means reinstalling the old version, restoring the pre-upgrade backups and re-creating server-level objects from your scripts. Any data written after the upgrade is lost unless you reapply it, so decide the go/no-go window in advance.
- Side by side: Keep the old instance read-only and untouched until acceptance criteria pass. Rollback is pointing clients back.
- Rolling AG upgrade: Your rollback point is before you fail over to an upgraded replica. After that failover the databases are upgraded and can't return to the old version replicas.
Checklist
- Source on SQL Server 2016 SP3, 2017, 2019 or 2022; OS on Windows Server 2019 or later.
- TLS 1.2 enabled; Visual C++ 2022 redistributable current; no pending restart.
- DQS, MDS, Synapse Link, Purview policies and SSRS dependencies resolved.
- Linked servers inventoried and fixed for OLE DB 19 encryption; certificates deployed where possible.
- Remote distributors and log shipping monitors checked for trusted certificates.
- Full-text indexes listed and rebuild time scheduled.
- Backups taken and test-restored;
DBCC CHECKDBclean; server objects scripted. - Upgrade method and rollback point agreed; Query Store baseline before compatibility level 170.
References
- Supported version and edition upgrades (SQL Server 2025)
- Breaking changes to Database Engine features in SQL Server 2025
- What's new in SQL Server 2025
- SQL Server 2025 known issues
- Hardware and software requirements for SQL Server 2025
- sp_addlinkedserver
- sp_serveroption
- Major version differences in MSOLEDBSQL
- Release notes for the Microsoft ODBC Driver for SQL Server on Windows
- Introduction to Microsoft.Data.SqlClient namespace
- Full-text index version upgrade
- Choose a Database Engine upgrade method
- Plan and test the Database Engine upgrade plan
- Upgrade SQL Server using the Installation Wizard
- Install SQL Server from the command prompt
- Upgrade availability group replicas
- ALTER DATABASE compatibility level
- Query Store usage scenarios
- RESTORE statements