Edit

Prepare to deliver Extended Security Updates for Windows Server

By using Azure Arc-enabled servers, you can enroll your existing Windows Server machines in Extended Security Updates (ESUs) after they reach end of support. Offering both cost flexibility and an enhanced delivery experience, Azure Arc better positions you to migrate to Azure. Select the version of Windows Server that you're enrolling to see version-specific guidance.

The purpose of this article is to help you understand the benefits and how to prepare to use Arc-enabled servers to enable delivery of ESUs.

Windows Server 2012 and Windows Server 2012 R2 reached end of support on October 10, 2023. Billing for Windows Server 2012 ESUs enabled by Azure Arc starts from October 2023, after end of support.

Note

Azure VMware Solution (AVS) machines and virtual machines on Azure Local are eligible for free ESUs and shouldn't enroll in ESUs enabled through Azure Arc.

Windows Server 2016 reaches end of support on January 12, 2027. Extended Security Updates for Windows Server 2016 provide Critical and Important security updates for up to three years, through 2030. ESUs don't include new features, customer-requested nonsecurity hotfixes, or design change requests.

You can configure Windows Server 2016 ESUs in the Azure portal starting August 3, 2026. Billing for Windows Server 2016 ESUs enabled by Azure Arc begins January 13, 2027.

Key benefits

Delivering ESUs to your Windows Server machines provides the following key benefits:

  • Pay-as-you-go: Flexibility to sign up for a monthly subscription service with the ability to migrate mid-year.

  • Azure billed: You can draw down from your existing Microsoft Azure Consumption Commitment (MACC) and analyze your costs using Microsoft Cost Management and Billing.

  • Built-in inventory: The coverage and enrollment status of ESUs on eligible Arc-enabled servers are identified in the Azure portal, highlighting gaps and status changes.

  • Keyless delivery: The enrollment of ESUs on Azure Arc-enabled machines doesn't require the acquisition or activation of keys.

Access to Azure services

For Azure Arc-enabled servers enrolled in ESUs enabled by Azure Arc, free access is provided to these Azure services for enrolled servers:

  • Azure Update Manager - Unified management and governance of update compliance that includes not only Azure and hybrid machines, but also ESU update compliance for all your Windows Server machines. Enrollment in ESUs does not impact Azure Update Manager. After enrollment in ESUs through Azure Arc, the server becomes eligible for ESU patches. These patches can be delivered through Azure Update Manager or any other patching solution. You'll still need to configure updates from Microsoft Updates or Windows Server Update Services.
  • Change Tracking and Inventory - Track changes in virtual machines hosted in Azure, on-premises, and other cloud environments.
  • Azure Policy Guest Configuration - Audit the configuration settings in a virtual machine. Guest configuration supports Azure VMs natively and non-Azure physical and virtual servers through Azure Arc-enabled servers.

Other Azure services through Azure Arc-enabled servers are available as well, with offerings such as:

Prepare delivery of ESUs

  1. Plan and prepare to connect your machines to Azure Arc-enabled servers by installing the Azure Connected Machine agent to establish a connection to Azure. For Windows Server 2012 ESUs, use agent version 1.34 or higher.

    After establishing this connection, you can enroll your servers to receive Extended Security Updates (ESUs). Both Standard and Datacenter editions are supported. Deploy your machines to Azure Arc so that you have visibility into their ESU coverage and can enroll through the Azure portal or by using Azure Policy.

  2. Download both the licensing package and servicing stack update (SSU) for the Azure Arc-enabled server as documented in the applicable Microsoft Knowledge Base article. For Windows Server 2012, see KB5031043: Procedure to continue receiving security updates after extended support has ended on October 10, 2023.

  1. Plan and prepare to connect your machines to Azure Arc-enabled servers by installing the Azure Connected Machine agent to establish a connection to Azure. For Windows Server 2016 ESUs, use agent version 1.62 or higher.

    After establishing this connection, you can enroll your servers to receive Extended Security Updates (ESUs). Both Standard and Datacenter editions are supported. Deploy your machines to Azure Arc so that you have visibility into their ESU coverage and can enroll through the Azure portal or by using Azure Policy.

Review the version-specific eligibility and licensing requirements before you enroll.

Windows Server 2012 Extended Security Updates support Windows Server 2012 and 2012 R2 Standard and Datacenter editions. Windows Server 2012 Storage isn't supported. Billing for this service starts from October 2023 (that is, after Windows Server 2012 end of support).

Note

To purchase ESUs, you must have Software Assurance through Volume Licensing Programs such as an Enterprise Agreement (EA), Enterprise Agreement Subscription (EAS), Enrollment for Education Solutions (EES), Server and Cloud Enrollment (SCE), or through Microsoft Open Value Programs. Alternatively, if your Windows Server 2012/2012 R2 machines are licensed through SPLA or with a Server Subscription, Software Assurance isn't required to purchase ESUs.

Windows Server 2016 Extended Security Updates support Windows Server 2016 Standard and Datacenter editions. You can configure Windows Server 2016 ESUs in the Azure portal starting August 3, 2026, and billing begins January 13, 2027.

Note

To purchase ESUs, you must have Software Assurance through Volume Licensing Programs such as an Enterprise Agreement (EA), Enterprise Agreement Subscription (EAS), Enrollment for Education Solutions (EES), Server and Cloud Enrollment (SCE), or through Microsoft Open Value Programs, or an equivalent Server Subscription. Software Assurance is required for on-premises workloads. The Services Provider License Agreement (SPLA) isn't available for Windows Server 2016 ESUs.

Deployment options

There are several at-scale onboarding options for Azure Arc-enabled servers:

Note

Delivery of ESUs through Azure Arc to virtual machines running on Virtual Desktop Infrastructure (VDI) is not recommended. VDI systems should use Multiple Activation Keys (MAK) to apply ESUs. See Access your Multiple Activation Key from the Microsoft 365 Admin Center to learn more.

Networking

Ensure your machines have the necessary network connectivity to Azure Arc. Connectivity options include:

  • Public endpoint
  • Proxy server
  • Private link or Azure Express Route.

Review the networking prerequisites to prepare non-Azure environments for deployment to Azure Arc.

If you use Azure Arc-enabled servers only for Extended Security Updates for one or more of the following products:

  • Windows Server 2012
  • Windows Server 2016
  • SQL Server 2012

You can enable the following subset of endpoints.

Agent resource Description When required Endpoint used with private link
download.microsoft.com Used to download the Windows installation package. Only at installation time.1 Public.
login.windows.net Microsoft Entra ID. Always. Public.
login.microsoftonline.com Microsoft Entra ID. Always. Public.
*.login.microsoft.com Microsoft Entra ID. Always. Public.
management.azure.com Azure Resource Manager is used to create or delete the Azure Arc server resource. Only when you connect or disconnect a server. Public, unless a resource management private link is also configured.
*.his.arc.azure.com Metadata and hybrid identity services. Always. Private.
*.guestconfiguration.azure.com Extension management and guest configuration services. Always. Private.
www.microsoft.com/pkiops/certs Intermediate certificate updates for Extended Security Updates (uses HTTP/TCP 80 and HTTPS/TCP 443). Always for automatic updates or temporarily if you download certificates manually. Public.
*.<region>.arcdataservices.com Azure Arc data processing service and service telemetry. SQL Server Extended Security Updates. Public.

1 Access to this URL is also needed when you perform updates automatically.

Tip

To take advantage of the full range of offerings for Arc-enabled servers, such as extensions and remote connectivity, ensure that you allow the additional URLs that apply to your scenario. For more information, see Connected machine agent networking requirements.

Required Certificate Authorities

The following Certificate Authorities are required for Extended Security Updates:

If necessary, you can manually download and install these Certificate Authorities.

Next steps