Databases & HA

SQL Server 2025 Upgrade Checklist: Pre-Checks, Breaking Changes, Rollback

Upgrade SQL Server 2016, 2019 or 2022 to SQL Server 2025 safely: supported paths, OS checks, the OLE DB 19 encryption change for linked servers, full-text and replication fixes, and a rollback plan.

13 min read
On this page

You can upgrade SQL Server 2016 SP3, 2017, 2019 or 2022 to SQL Server 2025 in place, but the risky part isn't Setup itself: it's the switch to Microsoft OLE DB Driver 19, which makes encryption mandatory for linked servers and remote replication distributors, plus the removal of legacy full-text components, Data Quality Services and Master Data Services. Check the operating system (Windows Server 2019 or later), fix certificates or linked server provider strings before cutover, and plan rollback around restoring pre-upgrade backups, because a database upgraded to SQL Server 2025 can't move back to an older version.

Who this is for and what you will have at the end

This checklist is for database administrators upgrading existing SQL Server 2016, 2019 or 2022 instances on Windows to SQL Server 2025 (17.x), either in place, side by side, or as a rolling upgrade of an availability group.

At the end you will have:

  • Confirmed that the version, edition and operating system can be upgraded.
  • Found and fixed the encryption-related breaking changes before they cause an outage.
  • Run the upgrade with Setup or from the command line.
  • Verified the instance and moved databases to the new compatibility level in a controlled way.
  • A rollback plan that matches how SQL Server upgrades actually work.

Supported upgrade paths and editions

SQL Server 2025 supports upgrade from:

Source versionMinimum level
SQL Server 2014SP3 or later
SQL Server 2016SP3 or later
SQL Server 2017Any
SQL Server 2019Any
SQL Server 2022Any

Edition changes to plan for:

  • Web edition is discontinued. Web edition upgrades to Enterprise or Standard.
  • Express with Advanced Services is discontinued. Express now includes those features and its maximum database size is 50 GB.
  • Standard edition limits increased to the lesser of 4 sockets or 32 cores, and 256 GB of buffer pool memory. Resource Governor is now available in Standard.
  • Developer edition is split into Enterprise Developer and Standard Developer. A Developer edition source can upgrade to either.

Pre-upgrade checks

Operating system and hardware

RequirementSQL Server 2025
Operating systemWindows Server 2019 or later; Windows 10 or later
Processorx64 only; Intel and AMD x86-64 with up to 64 cores per NUMA node
Windows Arm64Not supported (listed in the known issues)
.NET Framework4.7.2
DiskAt least 6 GB free, more depending on features
Memory1 GB minimum (512 MB for Express); at least 4 GB recommended

The operating system line is the one that catches people out. A SQL Server 2016 instance running on Windows Server 2016 can't be upgraded in place to SQL Server 2025; you need either an OS upgrade first or a new server and a side-by-side migration. Microsoft's upgrade method guidance points to a new installation when the OS is unsupported or when you want new hardware anyway.

Setup blockers from the known issues list

  • TLS 1.2 disabled. Installation fails if TLS 1.2 is disabled on the machine, including on failover cluster instances. Enable it before you run Setup.
  • Visual C++ Redistributable. Upgrades from SQL Server 2016 and 2017 can fail if the Visual C++ Redistributable for Visual Studio 2022 (version 14.34 at minimum) is missing or older. Install or repair it first.
  • Data Quality Services. If DQS is installed, the upgrade fails at the Feature Rules step. Use /IACCEPTDQUNINSTALL on the command line, which removes DQS during the upgrade.
  • More than 64 logical cores per NUMA node. The instance can fail to start after installation. Limit cores per NUMA node to 64.
  • Pending restart or stopped Windows Installer service. Either blocks the upgrade.
  • SQL Server Agent. Enable Windows Authentication for SQL Server Agent and confirm the Agent service account is a member of the sysadmin role.

Features that are gone or deprecated

ChangeWhat to do
Data Quality Services discontinuedPlan the DQS replacement; remove it during upgrade
Master Data Services discontinuedKeep MDS on SQL Server 2022 or earlier, or replace it
Synapse Link discontinuedUse Mirroring in Fabric
Purview access policies discontinuedUse fixed server roles such as ##MS_ServerPerformanceStateReader## and ##MS_ServerSecurityStateReader##
Reporting ServicesConsolidated under Power BI Report Server from SQL Server 2025
Hot add CPU, lightweight pooling (fiber mode)Deprecated; stop depending on them

You also can't add features during an upgrade. Add them with SQL Server 2025 Setup after the upgrade completes.

Breaking changes to find before you upgrade

Encrypt is now mandatory by default

Starting with SQL Server 2025, the MSOLEDBSQL provider uses Microsoft OLE DB Driver 19. In version 19, the default Encrypt value changed from no to Mandatory, and certificate validation always happens when encryption is used. The same direction was taken earlier in other drivers: ODBC Driver 18 defaults Encrypt to yes/mandatory, and Microsoft.Data.SqlClient 4.0 changed Encrypt to default to true.

The practical effect is that any server-to-server connection made through OLE DB 19 to an instance that only has a self-signed certificate fails with a certificate trust error unless you change the configuration. Inventory linked servers now:

SELECT name, product, provider, data_source, provider_string
FROM sys.servers
WHERE is_linked = 1;

For each linked server, choose a fix, in order of preference:

  1. Install a certificate from a public or internal CA on the target instance and use encrypt=mandatory (or encrypt=strict for TDS 8.0).
  2. Accept the self-signed certificate with encrypt=mandatory;trustservercertificate=yes.
  3. Make encryption optional with encrypt=optional.

The documented sp_addlinkedserver examples look like this:

EXECUTE sp_addlinkedserver
    @server = N'S1_instance1',
    @srvproduct = N'',
    @provider = N'MSOLEDBSQL',
    @provstr = N'encrypt=mandatory;trustservercertificate=yes',
    @datasrc = N'S1\instance1';

To change an existing linked server, update its provider string with sp_serveroption. The value replaces the whole provider string, so include anything that was already in it:

EXECUTE sp_serveroption
    @server = N'S1_instance1',
    @optname = N'provider string',
    @optvalue = N'encrypt=mandatory;trustservercertificate=yes';

If you can't change linked server definitions in time, trace flag 17600 keeps OLE DB version 18 behavior and defaults. Treat it as a temporary bridge, not the end state.

Replication with a remote distributor

Transactional, snapshot, peer-to-peer and merge replication can fail after the upgrade when the publisher uses a remote distributor that doesn't have a trusted certificate, because the publisher talks to the distributor through a linked server. Symptoms include changes to publications failing and Replication Monitor or agent status failing in SSMS. Check whether the instance is a publisher with a remote distributor:

EXECUTE sp_get_distributor;

The recommended fix is a CA-issued certificate on the distributor before you upgrade. The less secure alternative, after upgrade, is to trust the self-signed certificate:

EXECUTE sp_changedistributor_property
    @property = N'trust_distributor_certificate',
    @value = N'yes';

Adding a new remote distributor from a SQL Server 2025 publisher fails the same way, with SSL Provider: The certificate chain was issued by an authority that is not trusted. Use @trust_distributor_certificate = 'yes' on sp_adddistributor only if you can't deploy a certificate.

Log shipping monitor

Log shipping monitoring can break when the monitor is a remote SQL Server 2025 instance while other instances in the topology still run an earlier version. Avoid that combination by upgrading the monitor after the primary and secondary servers, and review Microsoft's TDS 8.0 guidance on certificates.

SQL Server 2025 removes the legacy word breaker and filter binaries. Existing full-text indexes are marked index_version = 1 after upgrade, and queries against them fail with Msg 30010. List them in each database before the upgrade so you can schedule rebuild time (after the upgrade, add WHERE fi.index_version = 1 to see only the ones still on version 1):

SELECT fc.name AS catalog_name,
       OBJECT_SCHEMA_NAME(fi.object_id) AS schema_name,
       OBJECT_NAME(fi.object_id) AS table_name
FROM sys.fulltext_indexes AS fi
JOIN sys.fulltext_catalogs AS fc
  ON fi.fulltext_catalog_id = fc.fulltext_catalog_id;

After the upgrade, confirm FULLTEXT_INDEX_VERSION is 2 and rebuild each catalog with ALTER FULLTEXT CATALOG [FtCatalog] REBUILD;. A catalog rebuild rebuilds every index in it; drop and re-create indexes individually if you need to control order or resource use.

Other behavior changes worth testing

  • Login CPU. SQL authentication now hashes passwords with PBKDF2 (100,000 iterations of SHA-512). Expect slightly longer logins and higher CPU where connection pooling isn't used.
  • Linked servers using MSDASQL with a provider string can fail with error 7416 for logins outside sysadmin, starting with CU4.
  • Strict encryption. If you plan to force strict encryption, note that SQLPS, the Agent PowerShell subsystem, and Database Mail on Linux don't work with it.
  • Windows Server 2025 with Lock pages in memory. Some configurations produce access violation dumps; the documented workaround is to disable LPIM for the SQL Server service account.

Choose the upgrade method

MethodDowntimeRollbackUse when
In-placeInstance offline during SetupReinstall old version and restore backupsDev/test, or production that tolerates downtime on a supported OS
New installation (side by side)Cutover onlyOld instance stays intactOS or hardware change, unsupported OS, or a cleaner rollback
Rolling (availability groups, FCIs)One manual failoverPossible until you fail over to an upgraded replicaExisting HA topology

For availability groups, upgrade remote secondaries first, then local secondaries, and the primary last. Remove automatic failover from synchronous-commit replicas before you start, fail over only to a synchronized synchronous-commit replica, and set backup preference to the primary because no replicas are readable or available for backups during a version upgrade. An upgraded primary can't ship log to a secondary that's still on the old version.

If you're moving to new servers anyway, the enterprise Azure cloud migration playbook covers sequencing, and the Managed Instance link runbook is an alternative if the target is Azure SQL Managed Instance rather than SQL Server 2025.

Run the upgrade

Before Setup, on the instance being upgraded:

  1. Take full backups of every user database and of master, model and msdb, and test that they restore.
  2. Run DBCC CHECKDB on every database.
  3. Script logins, Agent jobs, linked servers, credentials and server-level objects.
  4. Confirm system databases can autogrow and have disk space.
  5. Disable startup stored procedures. Find them with the query below.
  6. For SQL Server Agent multiserver (MSX/TSX) setups, upgrade target servers before the master server.
  7. Make sure replication is current and then stop it; stop applications that connect to the instance.
USE master;
SELECT name
FROM sys.procedures
WHERE OBJECTPROPERTY(object_id, 'ExecIsStartup') = 1;

Then run Setup from the SQL Server 2025 media as an administrator: select Installation, then Upgrade from... previous versions of SQL Server, select the instance, review the features (they're preselected and can't be changed), choose the full-text upgrade option, and select Install on the Ready to Upgrade page. For an unattended upgrade of a default instance:

.\setup.exe /q /ACTION=upgrade /INSTANCENAME=MSSQLSERVER /INSTANCEID=MSSQLSERVER /IACCEPTSQLSERVERLICENSETERMS /IACCEPTDQUNINSTALL

/INSTANCEID is required when upgrading from SQL Server 2008 or later. Add /FTUPGRADEOPTION (REBUILD, RESET or IMPORT) to control full-text catalogs, and the Integration Services account parameters if SSIS is installed. Leave out /IACCEPTDQUNINSTALL if DQS isn't installed. Add /PID=<product key> unless your installation media already includes the key: the command-line reference states that Evaluation is used when no product key is specified, so check SERVERPROPERTY('Edition') afterwards.

Verification

SELECT @@VERSION AS version,
       SERVERPROPERTY('ProductVersion') AS product_version,
       SERVERPROPERTY('Edition') AS edition;
 
SELECT name, compatibility_level, state_desc
FROM sys.databases;

Then check:

  • The Setup summary log reports success for every feature.
  • Every linked server responds: run a simple query through each one, including from accounts that aren't sysadmin.
  • Replication agents, log shipping jobs and Agent jobs run without errors.
  • Full-text queries return results after catalogs are rebuilt.

Move compatibility levels deliberately

Upgraded databases keep their compatibility level. Query optimizer changes are tied to the latest level (170 for SQL Server 2025), so Microsoft's recommended workflow is:

  1. Upgrade without changing compatibility level.
  2. Enable Query Store and capture a baseline for a full business cycle.
  3. Change to compatibility level 170.
  4. Use Query Store to find plan regressions and force the previous good plan, or revert the compatibility level if needed.
ALTER DATABASE [SalesDb] SET QUERY_STORE = ON;
-- after the baseline period
ALTER DATABASE [SalesDb] SET COMPATIBILITY_LEVEL = 170;

Troubleshooting

SSL Provider: The certificate chain was issued by an authority that is not trusted. A linked server or remote distributor connection now enforces certificate validation. Install a trusted certificate, or set trustservercertificate=yes in the provider string or trust_distributor_certificate for replication.

Msg 30010 ... If recently performed in-place upgrade to SQL2025, For help please see https://aka.ms/sqlfulltext. The full-text index is still version 1. Rebuild the catalog with version 2 components.

This application requires Microsoft Visual C++ Redistributable for Visual Studio 2022 (x64/x86, version 14.34 at minimum). Install or repair the redistributable and rerun Setup.

Upgrade stops at Feature Rules. Data Quality Services is installed. Rerun from the command line with /IACCEPTDQUNINSTALL.

Msg 7416 ... Access to the remote server is denied because no login-mapping exists. A linked server uses MSDASQL with a provider string. See the SQL Server 2025 known issues article for the affected builds.

Msg 15129 ... '3' is not a valid value for configuration option 'backup compression algorithm'. Setting ZSTD as the server default fails; specify the algorithm in the BACKUP statement instead.

Rollback plan

  • In-place: Setup overwrites the previous version, and no SQL Server backup can be restored to an earlier version. Rollback means reinstalling the old version, restoring the pre-upgrade backups and re-creating server-level objects from your scripts. Any data written after the upgrade is lost unless you reapply it, so decide the go/no-go window in advance.
  • Side by side: Keep the old instance read-only and untouched until acceptance criteria pass. Rollback is pointing clients back.
  • Rolling AG upgrade: Your rollback point is before you fail over to an upgraded replica. After that failover the databases are upgraded and can't return to the old version replicas.

Checklist

  • Source on SQL Server 2016 SP3, 2017, 2019 or 2022; OS on Windows Server 2019 or later.
  • TLS 1.2 enabled; Visual C++ 2022 redistributable current; no pending restart.
  • DQS, MDS, Synapse Link, Purview policies and SSRS dependencies resolved.
  • Linked servers inventoried and fixed for OLE DB 19 encryption; certificates deployed where possible.
  • Remote distributors and log shipping monitors checked for trusted certificates.
  • Full-text indexes listed and rebuild time scheduled.
  • Backups taken and test-restored; DBCC CHECKDB clean; server objects scripted.
  • Upgrade method and rollback point agreed; Query Store baseline before compatibility level 170.

References

Questions people ask

Can I upgrade SQL Server 2016 directly to SQL Server 2025?

Yes, if the instance runs SQL Server 2016 SP3 or later. SQL Server 2025 also supports in-place upgrade from SQL Server 2014 SP3, 2017, 2019 and 2022. The operating system must be supported by SQL Server 2025, which means Windows Server 2019 or later on servers.

Why do my linked servers fail after upgrading to SQL Server 2025?

In SQL Server 2025 the MSOLEDBSQL provider uses Microsoft OLE DB Driver 19, which defaults to mandatory encryption and validates the server certificate. Linked servers to instances with self-signed certificates fail until you install a trusted certificate, set encrypt=optional or trustservercertificate=yes in the provider string, or enable trace flag 17600 to keep OLE DB 18 behavior.

Can I roll back an in-place upgrade to SQL Server 2025?

Not in place. Setup overwrites the previous version, and no SQL Server backup can be restored to an earlier version than the one that created it. Rolling back means reinstalling the old version and restoring the backups you took before the upgrade, losing later changes, which is why side-by-side and rolling upgrades are safer for production.

Does upgrading change my database compatibility level?

No. Upgraded databases keep their existing compatibility level as long as it is supported. Microsoft recommends enabling Query Store, capturing a baseline at the old level, and only then moving to compatibility level 170.

SQL Server 2025SQL ServerWindows ServerTLS
  1. Azure SQL Managed Instance Link: Near-Zero Downtime Migration Runbook

    Migrate a SQL Server database to Azure SQL Managed Instance with the Managed Instance link: prepare SQL Server and the network, seed with SSMS, check lag, then fail over and cut over.

    Databases & HA12 min read
  2. SQL Server Always On Availability Groups on Azure VMs: Setup Guide

    Build a SQL Server Always On availability group on Azure VMs in multiple subnets: IP plan, Windows failover cluster, cloud witness quorum, Azure tuned thresholds, listener and failover testing.

    Databases & HA14 min read
  3. SQL Server Error 1205 Deadlock Victim: Capture, Read and Fix Deadlocks

    Capture deadlock graphs with Extended Events in SQL Server and Azure SQL Database, read the victim, process and resource lists, and stop error 1205 with indexing, access order, row versioning and retries.

    Databases & HA14 min read