
SQL Server 2016 reaches the end of Microsoft support on 14 July 2026. The hardest part is rarely the upgrade itself. It is finding every copy your business is still running.
After that date, Microsoft no longer provides standard patches, fixes or assisted support for SQL Server 2016. Extended Security Updates are available for eligible environments from 15 July 2026, but they should be treated as a short-term safety net, not a modernisation plan. The database nobody remembers is exactly the one that will not be assessed, protected or migrated in time.
Databases hide. SQL Server can sit quietly under a line-of-business application, arrive bundled with third-party software as SQL Server Express, or live on a server built years ago by an admin who has since left. It works, so nobody looks at it. Then an audit, supplier check or vulnerability warning reveals that the database is older than anyone thought.
The same unsupported-software exposure that insurers and auditors have lost patience with elsewhere, set out in the lessons from the M&S and Co-op attacks, applies just as much to a forgotten database as to a public-facing web server.
Where forgotten databases tend to live
Picture the finance team’s reporting tool. It works fine, so it sits on a SQL Server 2016 instance nobody has touched for years. The person who built it has left, there is no documentation, and the database may hold payroll figures, customer records or supplier bank details.
| Hiding place | Why it gets missed | How to surface it |
|---|---|---|
| Line-of-business apps | The app is visible, not the database behind it | Check each app’s backend and connection strings |
| SQL Server Express installs | Bundled silently by other software | Scan servers and endpoints for SQL instances |
| Old admin projects | No owner and no documentation | Audit old servers, service accounts and scheduled tasks |
| Dev and test machines | Treated as temporary, then left running | Include non-production systems in the inventory |
| Branch or overseas offices | Out of sight of head office IT | Inventory every site, not just HQ |
Start with discovery, not the upgrade. Azure Migrate can assess discovered SQL Server instances and databases for migration readiness, while SQL Server migration tools can help identify compatibility issues before you move. A structured network penetration test can also uncover exposed services nobody knew were reachable.
If your estate spans more than one location, support for multi-site and international projects keeps the inventory consistent. Where data sits in EU offices, IT support for European offices can help you account for local data and operational requirements at the same time.
Your real options
Once you know what you have, you have 3 honest choices.
First, upgrade to a supported SQL Server version, such as SQL Server 2022 or SQL Server 2025. SQL Server 2019 is still supported, but it gives a shorter runway than newer versions.
Second, move suitable workloads to a cloud database or Azure SQL option. This can fit neatly with wider cloud and Microsoft 365 work already on the roadmap.
Third, use Extended Security Updates where an instance genuinely cannot move in time. ESUs can provide critical security updates for up to 3 years, but they do not give you new features or general product fixes. They are a bridge, not a destination.
A planned database migration turns those options into a sequence rather than a scramble. Start with the instances holding sensitive data, public-facing services, unsupported applications and anything linked to finance, HR or customer records.
Frame it as modernisation, not panic
There is a budget conversation here, and it lands better framed as modernisation than as a grudge purchase. Newer SQL Server versions bring stronger security, better performance and a longer support runway.
Reading the wider Microsoft 365 pricing and security changes alongside your database plan helps you size the whole spend properly. End-of-support deadlines follow a familiar pattern, the same one behind the push to move off older versions of Windows, so treat this as part of one modernisation programme rather than a stray task.
Protect what remains while you migrate
While you migrate, harden anything that stays on SQL Server 2016. Apply network security basics, restrict access, review service accounts and test backups. Keep server endpoints covered with endpoint detection and response, and watch for leaked logins through monitoring for exposed credentials.
Email remains a live route in too, so keep phishing simulation and training running for people with database access.
Frequently asked questions
When does SQL Server 2016 support end?
SQL Server 2016 support ends on 14 July 2026.
Can I keep using SQL Server 2016 after that date?
Yes, it will keep running. The risk is that it becomes unsupported unless you have a valid ESU route in place.
Can I buy Extended Security Updates?
Yes, for eligible environments. They provide critical security updates only and should be treated as temporary.
How do I find every SQL Server instance?
Run discovery across servers, endpoints, non-production systems and remote sites, then map each instance to the application and owner that depends on it.
Find them before July finds them
The businesses that finish this calmly are the ones that start with a full inventory rather than a rushed upgrade. If you would like a clear picture of every SQL Server instance you run, what depends on it, and a realistic path off 2016, talk to Northern Star’s managed IT support team and we will help you surface the forgotten databases before the deadline does.