SQL Server 2016 is out of support: buy time, upgrade, or move to Azure SQL?
SQL Server 2016 lost security updates on 14 July 2026. What Extended Security Updates cost you, how to upgrade to 2022 or 2025 safely, and when Azure SQL fits.
Vlado Pandžić · Founder · Senior .NET architect
Published · 6 min read
Since 14 July 2026, SQL Server 2016 no longer gets security updates. The database still starts every morning, the applications still work, and nothing looks different. That is exactly the risk: every vulnerability found from now on stays open, on the server that holds your customers, orders and invoices.
You have three ways forward. None of them is hard, but each one has a price and a moment where it fits.
Three ways forward
| Extended Security Updates | Upgrade to SQL Server 2022 or 2025 | Move to Azure SQL | |
|---|---|---|---|
| What you get | Critical security fixes for up to three more years | A current engine, supported for years | No version to manage ever again |
| What it costs | A yearly subscription, on top of your licence | New licences and a few days of work | A monthly Azure bill instead of licences and hardware |
| What it takes | Connecting the server to Azure Arc | A test, a migration window and a check of the slowest queries | Moving the database and adjusting the applications |
| Fits when | You need time, not a solution | You want to keep the servers in-house | You are moving to Azure anyway |
Which versions are affected, and when the next ones run out, is in our SQL Server end of support tool.
Option 1: Extended Security Updates, as a bridge
Microsoft sells Extended Security Updates (ESU) for SQL Server 2016 for up to three years after end of support, so until July 2029. A few things worth knowing:
- They are paid. SQL Server 2014 got free ESUs when moved to an Azure virtual machine. For SQL Server 2016 that no longer applies.
- The server has to be connected to Azure Arc, or run on an Azure virtual machine. If that is not possible, Microsoft points to volume licensing through your account team.
- They cover only critical vulnerabilities. Updates come when the Microsoft Security Response Center rates something as critical, with no regular schedule. No fixes, no new features.
- Install the latest cumulative update first. ESUs build on it, and if you only ever applied security updates, this is the moment to test it.
ESU buys time. It does not solve anything, and the bill grows every year you wait.
Option 2: upgrade to SQL Server 2022 or 2025
SQL Server 2025 can be upgraded in place from SQL Server 2016 with Service Pack 3 or later. In practice, we rarely do that. Many SQL Server 2016 installations run on Windows Server 2016, which itself loses support on 12 January 2027. A new server with a new Windows Server and a new SQL Server solves both at once, and the old server stays untouched until the new one is proven.
The part that worries people most is performance. A newer engine can choose a different plan for an important query, and one report suddenly takes a minute. Microsoft built a safe path for exactly this:
- Keep the old compatibility level. A database moved to a new SQL Server keeps its compatibility level (130 for SQL Server 2016), so the query optimiser behaves as before.
- Turn on Query Store and let the database run under normal load for a week. It records the queries and the plans they use.
- Raise the compatibility level to 160 (SQL Server 2022) or 170 (SQL Server 2025).
- Compare. If a query got slower, Query Store shows it, and you can force the old plan while you fix it.
SELECT name, compatibility_level FROM sys.databases;
ALTER DATABASE Shop SET QUERY_STORE = ON;
-- After a week of normal load on the new server:
ALTER DATABASE Shop SET COMPATIBILITY_LEVEL = 170;
The compatibility level can be set back at any time. The upgrade itself cannot: a database file opened by a newer SQL Server cannot be opened by an older one again, so keep a backup from before the move.
Option 3: Azure SQL
Azure SQL Database and Azure SQL Managed Instance always run on a current engine. Microsoft updates them, and the question “which version are we on” disappears for good.
- Azure SQL Managed Instance is closest to your own SQL Server: SQL Server Agent jobs and queries across databases work as before. The usual choice for an existing application.
- Azure SQL Database is a single database, simpler and often cheaper, but some server-level features are not available. A better fit for applications built or adapted for it.
It makes sense if the rest of your applications are moving to Azure anyway. If they are not, a database in Azure and applications in your own server room usually means slower queries over the network.
The order that works
- Step 1Inventory: versions, jobs, links
- Step 2Test on a copy
- Step 3Move in a planned window
- Step 4Raise the compatibility level
The inventory is quick and saves the most surprises: which databases, which service pack, which Agent jobs, which other servers they talk to, and which applications connect with which accounts. This shows what you have:
SELECT SERVERPROPERTY('ProductVersion') AS Version,
SERVERPROPERTY('ProductLevel') AS ServicePack,
SERVERPROPERTY('Edition') AS Edition;
How long it takes
Rough ranges for moving to a new SQL Server:
- one database behind one application, with few jobs: a few days, including testing
- several databases, Agent jobs, linked servers and reports: two to four weeks
- a server that many applications depend on, with nobody sure who connects to it: longer, and the inventory is half the work
The applications on top usually need no changes for a new SQL Server. If they are old .NET Framework applications, that is a separate decision, covered in our article on migrating from .NET Framework to .NET 10.
How we work
This is exactly what we do. ProCoding is a .NET studio in Split, Croatia, and SQL Server is where we spend much of our time: query performance, migrations and keeping old systems running. We start with the inventory, propose the way forward, move the databases with a test on a copy first, and watch the slowest queries after the switch. When Azure is the destination, our Azure page shows how we approach it. The first step is a free 30-minute call.
Sources
- What are Extended Security Updates?, Microsoft Learn
- Supported version and edition upgrades (SQL Server 2025), Microsoft Learn
- ALTER DATABASE compatibility level, Microsoft Learn
- Change the database compatibility level and use the Query Store, Microsoft Learn
This article is general information only, not legal, tax, financial or other professional advice. Scenarios, examples and calculations are illustrative. Terms of use and disclaimer.