Windows Server 2016 stops receiving updates on 13 January 2027. Most organisations running it do not know they still are.
An infrastructure audit establishes what you actually run, how much of it is still supported, where the single points of failure are, and which of them would take the business down. It is a factual exercise, and the facts are usually more uncomfortable than the assumptions.

- 13 Jan 2027Windows Server 2016 extended end date
- Full estateServers, storage, network, virtualisation
- Single pointsIdentified and rated by business impact
- Evidence basedDiscovered, not reported from memory
Eight layers, each of which can take the business down on its own.
Compute, and how much of it is still supported
Every physical and virtual server, its operating system, its version, and where that version sits in its lifecycle. Windows Server 2016 has an extended end date of 13 January 2027 under the Fixed Lifecycle Policy, and containers released with it follow the same dates. Estates typically contain more of it than the inventory suggests.
Virtualisation and the concentration it creates
Hypervisor versions, cluster configuration, host capacity and the distribution of workloads across hosts. Virtualisation concentrates risk by design: a host failure that would once have affected one service now affects everything on it, and whether the cluster can absorb that is a capacity question with a specific answer.
Storage, capacity and the failure domain
Array models and firmware, capacity headroom, growth trajectory, RAID or erasure coding configuration, and what a controller or shelf failure would actually affect. Storage is the layer where the single point of failure is most often invisible, because everything above it appears redundant.
Network, and whether the redundancy is real
Core, distribution and access switching, routing, links, and the failure modes. CIS Control 12 is Network Infrastructure Management and Control 13 is Network Monitoring and Defense for a reason. Dual uplinks into one switch, dual switches on one power feed, and dual circuits from one provider are all common and none of them are redundancy.
Configuration currency and hardening
Firmware and operating system patch levels, default credentials, unnecessary services, management interfaces reachable from the wrong places, and configuration drift between devices that were built to be identical. CIS Control 4 is Secure Configuration of Enterprise Assets and Software, and it applies to infrastructure as much as endpoints.
Lifecycle position across the estate
Not only operating systems. Hardware under or out of support, firmware no longer receiving updates, hypervisor versions past end of general support, and network devices whose vendor has published an end of sale date. The audit produces a dated list rather than a general impression that things are getting old.
Facilities, power and environment
Where equipment physically sits, how it is powered, whether uninterruptible power supplies have been tested under load rather than assumed, cooling capacity and headroom, and physical access control. Facilities issues cause outages that look like infrastructure failures and are considerably cheaper to prevent.
Backup and recoverability of the infrastructure itself
CIS Control 11 is Data Recovery, and infrastructure audits repeatedly find that data is backed up while the configuration required to rebuild the platform is not. Switch configurations, hypervisor host builds, firewall rule sets and directory service state are all recovery dependencies, and all are commonly unprotected.
Windows Server 2016 extended support ends 13 January 2027.
Published on the Microsoft lifecycle page for the product, which follows the Fixed Lifecycle Policy. Mainstream support ended 12 January 2022.
- The support dates apply to Datacenter, Essentials, MultiPoint Premium and Standard editions, and containers released with Windows Server 2016 follow the same lifecycle dates. That container note catches organisations who migrated the workload and left the base image behind.
- An operating system past its extended end date does not stop working. It stops receiving security updates, which means every vulnerability published after that date remains open permanently unless the vendor offers a paid extended programme and the organisation buys into it.
- The practical audit question is not whether you run any. It is how many, where, what they do, and whether the applications on them can move. That last one is what determines whether the remaining months are sufficient, and it is the question that takes longest to answer.
- The same exercise applies to hypervisor versions, network device firmware and storage array support status. Compute lifecycle receives attention because it is visible. The other layers reach end of support quietly and are usually discovered during an incident.
Four things that make an infrastructure audit useful.
We discover rather than ask
The existing inventory is an input, not a source. Automated discovery across the network, hypervisor and directory, correlated against records, is what surfaces the assets nobody accounted for. CIS Control 1 exists because the gap between what is recorded and what is running is a real and recurring one.
We attach dates rather than adjectives
Ageing is not a finding. Windows Server 2016 having an extended end date of 13 January 2027 is. Every platform in the estate is dated against its published vendor lifecycle, which turns a general sense that things need refreshing into a schedule with deadlines that can be planned and funded.
We trace failure domains rather than read diagrams
Diagrams show intent. Cables, power feeds and provider paths show reality, and they disagree more often than anyone expects. Dual uplinks into one chassis, dual switches on one feed and dual circuits in one duct are all common, all documented as redundant, and none of them are.
We rate by business impact, not technical severity
A critical technical finding on a system nobody depends on ranks below a moderate one on the platform that carries revenue. Findings are rated by what fails and who notices, which is what allows an executive audience to sequence the work rather than receive a list they cannot prioritise.
Four phases across roughly three to five weeks.
- 01Week 1
Discovery, and it is discovery rather than a questionnaire
Automated discovery across the network, hypervisor and directory, correlated against whatever inventory exists. CIS Control 1 is Inventory and Control of Enterprise Assets and Control 2 is Inventory and Control of Software Assets, and the gap between the two lists is usually the first significant finding.
- Discovered asset inventory across compute, network and storage
- Comparison against the existing inventory
- Operating system, firmware and hypervisor versions captured
- Assets present but unaccounted for identified
- 02Week 2
Lifecycle and configuration assessment
Every discovered version dated against its vendor lifecycle, and configuration examined against a hardening baseline. This is where the estate acquires dates rather than impressions, and where configuration drift between supposedly identical devices becomes visible.
- Lifecycle position with published end dates per platform
- Patch and firmware currency measured
- Configuration compared against a hardening baseline
- Drift between paired or clustered devices identified
- 03Week 3
Resilience and capacity testing
Failure domains traced rather than assumed. Which physical failure affects which services, whether cluster capacity absorbs a host loss, whether power and cooling have headroom, and whether the configuration required to rebuild the platform is protected anywhere.
- Single points of failure identified with business impact
- Cluster and capacity headroom quantified
- Facilities, power and cooling assessed
- Infrastructure configuration backup coverage established
- 04Weeks 4 to 5
Report, prioritise and sequence
Findings rated by business impact rather than technical severity, and sequenced into work that has to happen before a date, work that should happen this year, and work that can be scheduled. The dated items lead, because those are the ones with a deadline set by somebody else.
- Findings rated by business impact
- A dated remediation schedule driven by lifecycle deadlines
- Capacity and refresh planning input
- A walkthrough with technical and executive audiences
Six situations where an infrastructure audit earns its place.
An organisation planning a refresh cycle
Refresh budgets are usually built from age and from whoever argues most persuasively. An audit that dates every platform against its published lifecycle replaces that with a schedule, and it consistently reorders the priorities because the loudest requirement is rarely the one with the nearest deadline.
An operator with sites and operational technology
Plant and remote site infrastructure ages differently because it is harder to touch and the tolerance for downtime is lower. Audits of these estates reliably find network and control equipment several major versions behind, running configurations nobody has reviewed since commissioning.
A business preparing for a cloud migration
Migration planning depends on knowing what exists, what depends on what, and which workloads sit on platforms that cannot move without being rebuilt. That last category determines the timeline more than anything else, and discovering it during migration rather than before is expensive.
A provider whose availability is a clinical matter
Where downtime affects care, single points of failure are not an efficiency question. Tracing which physical failure affects which clinical system, and whether the cluster absorbs a host loss, produces answers that are frequently different from the assumptions the resilience plan is built on.
A company that has just acquired another
The acquired estate is an unknown that becomes your responsibility on completion. An infrastructure audit establishes what was actually bought: how much is supported, what it costs to bring to standard, and which findings need addressing before integration rather than after.
An organisation whose insurer is asking questions
Cyber insurance renewals increasingly require statements about supported operating systems, backup arrangements and network segmentation. Making those statements without evidence is a risk in itself, and the audit produces the evidence that makes the answers defensible.
How Dubai organisations understand their infrastructure.
| Feature | Audited and dated | Documented at some point | Known by the people who built it |
|---|---|---|---|
Complete asset inventory | Discovered | Partially accurate | In people |
Lifecycle dates per platform | Documented | Rarely | No |
Single points of failure identified | Yes, rated | Assumed absent | Found in incidents |
Cluster capacity verified | Quantified | Assumed | Assumed |
Configuration drift detected | Yes | No | No |
Infrastructure config backed up | Verified | Partly | Unlikely |
Facilities and power assessed | Yes | No | No |
Refresh planning has a basis | Dated schedule | Budget driven | Reactive |
Key person dependency | Reduced | High | Total |
Surprises during incidents | Few | Several | Routine |
Ten places redundancy is assumed and frequently absent.
| What looks redundant | What the audit checks | |
|---|---|---|
| Dual network uplinks | Whether both terminate in the same switch or the same chassis | |
| Dual switches | Whether both draw from the same power feed or the same rack PDU | |
| Dual internet circuits | Whether both are ultimately delivered by the same provider or the same duct | |
| Clustered hypervisor hosts | Whether remaining hosts have capacity to run everything after a failure | |
| Redundant storage controllers | Whether firmware is current and failover has been tested, not assumed | |
| Multiple domain controllers | Whether they are on separate hosts, sites and storage | |
| Backup infrastructure | Whether a copy exists outside the failure domain being protected | |
| Uninterruptible power supplies | Whether batteries have been load tested within a known period | |
| Cooling | Whether the room stays within tolerance with one unit down | |
| Firewall pairs | Whether configuration is synchronised and failover has ever been exercised |
Five steps, and the first one is deliberately not a meeting.
- 1
Agree scope, access and discovery method
Which sites, which environments, and whether operational technology is included. Then read access to the hypervisor, directory, network management and storage management, plus permission to run network discovery. The scoping conversation is short. The access arrangements usually take longer.
- 2
Discover the estate
Automated discovery correlated with existing records, plus physical verification where sites are in scope. Output is an inventory of compute, storage, network, virtualisation and facilities equipment with versions and firmware levels captured rather than reported.
- 3
Date everything against published lifecycles
Every operating system, hypervisor, firmware and hardware platform positioned against its vendor lifecycle. Windows Server 2016 has a published extended end date of 13 January 2027 and follows the Fixed Lifecycle Policy. Everything else gets the same treatment against its own published dates.
- 4
Trace failure domains and test capacity
Which physical failure affects which service, traced through cables, power and provider paths rather than read from a diagram. Cluster capacity quantified against a host loss. Facilities headroom assessed. Infrastructure configuration backup coverage established, since it is commonly absent.
- 5
Report, sequence and support the plan
Findings rated by business impact, sequenced into deadline-driven work and discretionary work, and presented to both technical and executive audiences. Where the organisation wants it, we stay involved through remediation rather than handing over a document and leaving.
What Dubai organisations ask about infrastructure audits.
Fifteen questions to ask your own infrastructure team.
Currency
- How many Windows Server 2016 instances do we run?Extended support ends 13 January 2027.
- What is our oldest supported operating system?And the oldest unsupported one.
- When was network firmware last updated?Across all devices, not the core.
- Is any hardware out of vendor support?Including storage and UPS.
- What is our hypervisor version and its end date?Check it, do not recall it.
Resilience
- Can the cluster run everything with one host down?With actual numbers.
- Do our dual uplinks reach two separate switches?Trace the cables.
- Are our two circuits on genuinely separate paths?Ask the providers.
- When was firewall failover last exercised?Not configured, exercised.
- When were UPS batteries last load tested?A date, not a schedule.
Recovery
- Are switch configurations backed up?CIS Control 11 is Data Recovery.
- Could we rebuild a hypervisor host from records?Without the person who built it.
- Is the firewall rule set exported anywhere?Outside the firewall.
- Does a backup copy exist outside the failure domain?The same site is not outside.
- Has a full platform rebuild been tested?Data restore is not the same thing.
Count your Windows Server 2016 instances this week.
Extended support ends 13 January 2027 and the number is almost always higher than expected. If nobody can produce it quickly, that is the finding, and the audit will produce considerably more of them.
Related Services
Explore more solutions that work great with this service
Software Asset Management Audit
What is installed against what you own
IT Audit Services Dubai
Assessment, technical test or certification, scoped properly
Disaster Recovery Audit
Measured recovery time, not the stated objective
Firewall Rule Audit
What the rule base permits, and what should go
IT Risk Assessment
A short register with an owner against every risk
Cloud Security Posture Audit
The real inventory, then configuration and identity
IT Due Diligence
What the target runs, what it costs, what integration costs
Server Management
Windows and Linux server administration