We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Audit and compliance
  2. IT infrastructure audit
IT infrastructure audit, Dubai

Windows Server 2016 stops receiving updates on 13 January 2027. Most organisations running it do not know they still are.

An infrastructure audit establishes what you actually run, how much of it is still supported, where the single points of failure are, and which of them would take the business down. It is a factual exercise, and the facts are usually more uncomfortable than the assumptions.

Book an infrastructure auditSee what we examine
IT infrastructure audit for Dubai organisations
  • 13 Jan 2027Windows Server 2016 extended end date
  • Full estateServers, storage, network, virtualisation
  • Single pointsIdentified and rated by business impact
  • Evidence basedDiscovered, not reported from memory
What we examine

Eight layers, each of which can take the business down on its own.

Infrastructure fails at whichever layer is weakest, not at the layer that receives attention. An audit that examines servers thoroughly and the network superficially will produce a confident report and miss the thing most likely to cause an outage.

Compute, and how much of it is still supported

Every physical and virtual server, its operating system, its version, and where that version sits in its lifecycle. Windows Server 2016 has an extended end date of 13 January 2027 under the Fixed Lifecycle Policy, and containers released with it follow the same dates. Estates typically contain more of it than the inventory suggests.

Virtualisation and the concentration it creates

Hypervisor versions, cluster configuration, host capacity and the distribution of workloads across hosts. Virtualisation concentrates risk by design: a host failure that would once have affected one service now affects everything on it, and whether the cluster can absorb that is a capacity question with a specific answer.

Storage, capacity and the failure domain

Array models and firmware, capacity headroom, growth trajectory, RAID or erasure coding configuration, and what a controller or shelf failure would actually affect. Storage is the layer where the single point of failure is most often invisible, because everything above it appears redundant.

Network, and whether the redundancy is real

Core, distribution and access switching, routing, links, and the failure modes. CIS Control 12 is Network Infrastructure Management and Control 13 is Network Monitoring and Defense for a reason. Dual uplinks into one switch, dual switches on one power feed, and dual circuits from one provider are all common and none of them are redundancy.

Configuration currency and hardening

Firmware and operating system patch levels, default credentials, unnecessary services, management interfaces reachable from the wrong places, and configuration drift between devices that were built to be identical. CIS Control 4 is Secure Configuration of Enterprise Assets and Software, and it applies to infrastructure as much as endpoints.

Lifecycle position across the estate

Not only operating systems. Hardware under or out of support, firmware no longer receiving updates, hypervisor versions past end of general support, and network devices whose vendor has published an end of sale date. The audit produces a dated list rather than a general impression that things are getting old.

Facilities, power and environment

Where equipment physically sits, how it is powered, whether uninterruptible power supplies have been tested under load rather than assumed, cooling capacity and headroom, and physical access control. Facilities issues cause outages that look like infrastructure failures and are considerably cheaper to prevent.

Backup and recoverability of the infrastructure itself

CIS Control 11 is Data Recovery, and infrastructure audits repeatedly find that data is backed up while the configuration required to rebuild the platform is not. Switch configurations, hypervisor host builds, firewall rule sets and directory service state are all recovery dependencies, and all are commonly unprotected.

The date on the calendar

Windows Server 2016 extended support ends 13 January 2027.

Published on the Microsoft lifecycle page for the product, which follows the Fixed Lifecycle Policy. Mainstream support ended 12 January 2022.

  • The support dates apply to Datacenter, Essentials, MultiPoint Premium and Standard editions, and containers released with Windows Server 2016 follow the same lifecycle dates. That container note catches organisations who migrated the workload and left the base image behind.
  • An operating system past its extended end date does not stop working. It stops receiving security updates, which means every vulnerability published after that date remains open permanently unless the vendor offers a paid extended programme and the organisation buys into it.
  • The practical audit question is not whether you run any. It is how many, where, what they do, and whether the applications on them can move. That last one is what determines whether the remaining months are sufficient, and it is the question that takes longest to answer.
  • The same exercise applies to hypervisor versions, network device firmware and storage array support status. Compute lifecycle receives attention because it is visible. The other layers reach end of support quietly and are usually discovered during an incident.
Ask us to date your estate
How we approach it

Four things that make an infrastructure audit useful.

An audit that produces a list of everything you own has done inventory. The value is in what it says about dates, failure domains and which findings have a deadline somebody else set.

We discover rather than ask

The existing inventory is an input, not a source. Automated discovery across the network, hypervisor and directory, correlated against records, is what surfaces the assets nobody accounted for. CIS Control 1 exists because the gap between what is recorded and what is running is a real and recurring one.

We attach dates rather than adjectives

Ageing is not a finding. Windows Server 2016 having an extended end date of 13 January 2027 is. Every platform in the estate is dated against its published vendor lifecycle, which turns a general sense that things need refreshing into a schedule with deadlines that can be planned and funded.

We trace failure domains rather than read diagrams

Diagrams show intent. Cables, power feeds and provider paths show reality, and they disagree more often than anyone expects. Dual uplinks into one chassis, dual switches on one feed and dual circuits in one duct are all common, all documented as redundant, and none of them are.

We rate by business impact, not technical severity

A critical technical finding on a system nobody depends on ranks below a moderate one on the platform that carries revenue. Findings are rated by what fails and who notices, which is what allows an executive audience to sequence the work rather than receive a list they cannot prioritise.

How the audit runs

Four phases across roughly three to five weeks.

Duration depends on estate size, number of sites and how much is discoverable automatically. Multi-site estates with operational technology take longer because more of the work is physical.
  1. 01
    Week 1

    Discovery, and it is discovery rather than a questionnaire

    Automated discovery across the network, hypervisor and directory, correlated against whatever inventory exists. CIS Control 1 is Inventory and Control of Enterprise Assets and Control 2 is Inventory and Control of Software Assets, and the gap between the two lists is usually the first significant finding.

    • Discovered asset inventory across compute, network and storage
    • Comparison against the existing inventory
    • Operating system, firmware and hypervisor versions captured
    • Assets present but unaccounted for identified
  2. 02
    Week 2

    Lifecycle and configuration assessment

    Every discovered version dated against its vendor lifecycle, and configuration examined against a hardening baseline. This is where the estate acquires dates rather than impressions, and where configuration drift between supposedly identical devices becomes visible.

    • Lifecycle position with published end dates per platform
    • Patch and firmware currency measured
    • Configuration compared against a hardening baseline
    • Drift between paired or clustered devices identified
  3. 03
    Week 3

    Resilience and capacity testing

    Failure domains traced rather than assumed. Which physical failure affects which services, whether cluster capacity absorbs a host loss, whether power and cooling have headroom, and whether the configuration required to rebuild the platform is protected anywhere.

    • Single points of failure identified with business impact
    • Cluster and capacity headroom quantified
    • Facilities, power and cooling assessed
    • Infrastructure configuration backup coverage established
  4. 04
    Weeks 4 to 5

    Report, prioritise and sequence

    Findings rated by business impact rather than technical severity, and sequenced into work that has to happen before a date, work that should happen this year, and work that can be scheduled. The dated items lead, because those are the ones with a deadline set by somebody else.

    • Findings rated by business impact
    • A dated remediation schedule driven by lifecycle deadlines
    • Capacity and refresh planning input
    • A walkthrough with technical and executive audiences
Where this applies

Six situations where an infrastructure audit earns its place.

The common trigger is a decision that needs facts: a refresh budget, a cloud migration, an acquisition, an insurance renewal, or an outage that revealed the diagram was optimistic.

An organisation planning a refresh cycle

Refresh budgets are usually built from age and from whoever argues most persuasively. An audit that dates every platform against its published lifecycle replaces that with a schedule, and it consistently reorders the priorities because the loudest requirement is rarely the one with the nearest deadline.

An operator with sites and operational technology

Plant and remote site infrastructure ages differently because it is harder to touch and the tolerance for downtime is lower. Audits of these estates reliably find network and control equipment several major versions behind, running configurations nobody has reviewed since commissioning.

A business preparing for a cloud migration

Migration planning depends on knowing what exists, what depends on what, and which workloads sit on platforms that cannot move without being rebuilt. That last category determines the timeline more than anything else, and discovering it during migration rather than before is expensive.

A provider whose availability is a clinical matter

Where downtime affects care, single points of failure are not an efficiency question. Tracing which physical failure affects which clinical system, and whether the cluster absorbs a host loss, produces answers that are frequently different from the assumptions the resilience plan is built on.

A company that has just acquired another

The acquired estate is an unknown that becomes your responsibility on completion. An infrastructure audit establishes what was actually bought: how much is supported, what it costs to bring to standard, and which findings need addressing before integration rather than after.

An organisation whose insurer is asking questions

Cyber insurance renewals increasingly require statements about supported operating systems, backup arrangements and network segmentation. Making those statements without evidence is a risk in itself, and the audit produces the evidence that makes the answers defensible.

Three positions

How Dubai organisations understand their infrastructure.

The middle column is common and it is not negligence. It is what happens when an estate grows through projects, acquisitions and urgent fixes, and nobody was ever funded to establish the whole picture at once.
Complete asset inventory
Audited and datedDiscovered
Documented at some pointPartially accurate
Known by the people who built itIn people
Lifecycle dates per platform
Audited and datedDocumented
Documented at some pointRarely
Known by the people who built itNo
Single points of failure identified
Audited and datedYes, rated
Documented at some pointAssumed absent
Known by the people who built itFound in incidents
Cluster capacity verified
Audited and datedQuantified
Documented at some pointAssumed
Known by the people who built itAssumed
Configuration drift detected
Audited and datedYes
Documented at some pointNo
Known by the people who built itNo
Infrastructure config backed up
Audited and datedVerified
Documented at some pointPartly
Known by the people who built itUnlikely
Facilities and power assessed
Audited and datedYes
Documented at some pointNo
Known by the people who built itNo
Refresh planning has a basis
Audited and datedDated schedule
Documented at some pointBudget driven
Known by the people who built itReactive
Key person dependency
Audited and datedReduced
Documented at some pointHigh
Known by the people who built itTotal
Surprises during incidents
Audited and datedFew
Documented at some pointSeveral
Known by the people who built itRoutine
Feature
Audited and dated
Documented at some point
Known by the people who built it
Complete asset inventory
DiscoveredPartially accurateIn people
Lifecycle dates per platform
DocumentedRarelyNo
Single points of failure identified
Yes, ratedAssumed absentFound in incidents
Cluster capacity verified
QuantifiedAssumedAssumed
Configuration drift detected
YesNoNo
Infrastructure config backed up
VerifiedPartlyUnlikely
Facilities and power assessed
YesNoNo
Refresh planning has a basis
Dated scheduleBudget drivenReactive
Key person dependency
ReducedHighTotal
Surprises during incidents
FewSeveralRoutine
Single points of failure

Ten places redundancy is assumed and frequently absent.

Each of these appears redundant on a diagram. Each has caused outages in estates whose owners believed the layer was covered. The audit tests them rather than reading the diagram.
What looks redundantWhat the audit checks
Dual network uplinksWhether both terminate in the same switch or the same chassis
Dual switchesWhether both draw from the same power feed or the same rack PDU
Dual internet circuitsWhether both are ultimately delivered by the same provider or the same duct
Clustered hypervisor hostsWhether remaining hosts have capacity to run everything after a failure
Redundant storage controllersWhether firmware is current and failover has been tested, not assumed
Multiple domain controllersWhether they are on separate hosts, sites and storage
Backup infrastructureWhether a copy exists outside the failure domain being protected
Uninterruptible power suppliesWhether batteries have been load tested within a known period
CoolingWhether the room stays within tolerance with one unit down
Firewall pairsWhether configuration is synchronised and failover has ever been exercised
How an engagement runs

Five steps, and the first one is deliberately not a meeting.

Discovery before discussion, because discussion about an estate that has not been discovered tends to describe the estate as it was intended rather than as it is.
  1. 1

    Agree scope, access and discovery method

    Which sites, which environments, and whether operational technology is included. Then read access to the hypervisor, directory, network management and storage management, plus permission to run network discovery. The scoping conversation is short. The access arrangements usually take longer.

  2. 2

    Discover the estate

    Automated discovery correlated with existing records, plus physical verification where sites are in scope. Output is an inventory of compute, storage, network, virtualisation and facilities equipment with versions and firmware levels captured rather than reported.

  3. 3

    Date everything against published lifecycles

    Every operating system, hypervisor, firmware and hardware platform positioned against its vendor lifecycle. Windows Server 2016 has a published extended end date of 13 January 2027 and follows the Fixed Lifecycle Policy. Everything else gets the same treatment against its own published dates.

  4. 4

    Trace failure domains and test capacity

    Which physical failure affects which service, traced through cables, power and provider paths rather than read from a diagram. Cluster capacity quantified against a host loss. Facilities headroom assessed. Infrastructure configuration backup coverage established, since it is commonly absent.

  5. 5

    Report, sequence and support the plan

    Findings rated by business impact, sequenced into deadline-driven work and discretionary work, and presented to both technical and executive audiences. Where the organisation wants it, we stay involved through remediation rather than handing over a document and leaving.

Straight answers

What Dubai organisations ask about infrastructure audits.

Assets nobody accounted for. The discovered inventory and the recorded inventory disagree in almost every engagement, and the difference is usually servers built for a project that never got decommissioned, network devices added during a fit-out, and virtual machines nobody claims. That gap is why CIS Control 1 is Control 1.

Because it has a published extended end date of 13 January 2027 under the Fixed Lifecycle Policy, mainstream support ended on 12 January 2022, and estates contain more of it than their owners believe. The lifecycle note that containers released with Windows Server 2016 follow the same dates catches organisations who moved the workload and kept the base image.

No, and that is precisely the problem. It continues running and stops receiving security updates, so every vulnerability published after the end date remains open permanently. Nothing visible changes on the date, which is why these systems persist for years after anybody intended them to.

Typically three to five weeks depending on estate size, number of sites and how much is discoverable automatically. Multi-site estates and anything including operational technology take longer, because a larger proportion of the work has to be done physically rather than from a management console.

Discovery is read-only and scheduled around change windows where the environment is sensitive. Where operational technology is in scope we use passive methods rather than active scanning, since active scanning of industrial control equipment has caused outages and there is no reason to accept that risk for an audit.

Read access to hypervisor, directory, network management and storage management platforms, plus permission to run network discovery. No administrative changes are made. Where the organisation prefers, discovery can be run by their own team with our tooling and instructions and the output shared with us.

Yes, where sites are in scope. Power and cooling cause outages that look like infrastructure failures, and they are considerably cheaper to prevent. Uninterruptible power supply batteries that have never been load tested, and cooling with no headroom for a unit failure, are both routine findings.

It is one of the most reliable findings. Data is backed up and the configuration needed to rebuild the platform is not: switch configurations, hypervisor host builds, firewall rule sets, directory state. CIS Control 11 is Data Recovery, and a recovery that restores data onto a platform nobody can rebuild is not a recovery.

By business impact rather than technical severity. A critical finding on a system nobody depends on ranks below a moderate one on the platform that carries revenue. That rating is what lets an executive audience sequence and fund the work, rather than receive a list of severities they have no basis to prioritise.

They overlap and the emphasis differs. A security audit asks whether the estate is defended. An infrastructure audit asks whether it is supported, resilient and recoverable, and picks up security findings such as default credentials, exposed management interfaces and configuration drift along the way because they are infrastructure facts.

Yes, and hybrid is the usual case. The questions shift rather than disappear: instead of hardware lifecycle, it is service tier, region resilience and dependency between cloud services and remaining on-premises components. That dependency is where hybrid estates most often turn out to be less resilient than either half suggests.

A discovered inventory, a dated lifecycle position for every platform, an identified list of single points of failure rated by business impact, capacity and facilities findings, and a remediation schedule split into deadline-driven and discretionary work. Plus a walkthrough for technical and executive audiences separately, since they need different things from it.

A full audit every two to three years, with the inventory and lifecycle position maintained continuously in between. The lifecycle element in particular goes stale quickly, because vendors publish end dates that move closer without anything in the estate changing at all.

Yes. Some organisations want the audit independent of the delivery and we respect that. Where you would rather one party carry it through, we can plan and execute the refresh, migration and hardening work, and the audit findings become the project plan rather than a document that ages on a shared drive.

We scope by estate size, number of sites and whether operational technology is included. The useful first step is free and quick: count your Windows Server 2016 instances and check their planned migration dates against 13 January 2027. If that number is unknown, the audit will pay for itself on that finding alone.
Before you engage anyone

Fifteen questions to ask your own infrastructure team.

These are answerable in an afternoon if the estate is well managed. The ones that take a week to answer are telling you where the audit will find something.

Currency

  • How many Windows Server 2016 instances do we run?
    Extended support ends 13 January 2027.
  • What is our oldest supported operating system?
    And the oldest unsupported one.
  • When was network firmware last updated?
    Across all devices, not the core.
  • Is any hardware out of vendor support?
    Including storage and UPS.
  • What is our hypervisor version and its end date?
    Check it, do not recall it.

Resilience

  • Can the cluster run everything with one host down?
    With actual numbers.
  • Do our dual uplinks reach two separate switches?
    Trace the cables.
  • Are our two circuits on genuinely separate paths?
    Ask the providers.
  • When was firewall failover last exercised?
    Not configured, exercised.
  • When were UPS batteries last load tested?
    A date, not a schedule.

Recovery

  • Are switch configurations backed up?
    CIS Control 11 is Data Recovery.
  • Could we rebuild a hypervisor host from records?
    Without the person who built it.
  • Is the firewall rule set exported anywhere?
    Outside the firewall.
  • Does a backup copy exist outside the failure domain?
    The same site is not outside.
  • Has a full platform rebuild been tested?
    Data restore is not the same thing.
Related reading

The pages around this one.

IT audit services

The parent audit practice, and the other audit types within it.

Learn more

Disaster recovery audit

Recovery capability tested rather than documented.

Learn more

Firewall rule audit

The network layer examined rule by rule.

Learn more
Next step

Count your Windows Server 2016 instances this week.

Extended support ends 13 January 2027 and the number is almost always higher than expected. If nobody can produce it quickly, that is the finding, and the audit will produce considerably more of them.

Book an infrastructure auditCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

Software Asset Management Audit

What is installed against what you own

Learn more

IT Audit Services Dubai

Assessment, technical test or certification, scoped properly

Learn more

Disaster Recovery Audit

Measured recovery time, not the stated objective

Learn more

Firewall Rule Audit

What the rule base permits, and what should go

Learn more

IT Risk Assessment

A short register with an owner against every risk

Learn more

Cloud Security Posture Audit

The real inventory, then configuration and identity

Learn more

IT Due Diligence

What the target runs, what it costs, what integration costs

Learn more

Server Management

Windows and Linux server administration

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy