Home › Insights › Cloud migration
Windows Server 2012 gets its last security fix on 13 October. What to do this fortnight
The paid extended updates run out, and there is no fourth year. The servers keep working, which is exactly why they get forgotten.
- Published
- 28 September 2026
- Reading
- 3 min
- Topic
- Cloud migration
- Last updates
- 13 October 2026no fixes after this
Windows Server 2012 and 2012 R2 left mainstream support years ago and extended support in October 2023. Since then, security fixes have come only through Microsoft’s paid Extended Security Updates, sold for a maximum of three years. The third year ends with the update release of 13 October 2026. After that, nothing: no patches, whatever you pay.
Nothing switches off on the day. The servers boot, the file shares open, the old ERP still posts invoices. That is the problem. Every flaw found in that code after 13 October stays open for good, and the servers that nobody thinks about are the ones still running it.
1 · Find every one of them
The list is always longer than anyone expects. The usual suspects: an old domain controller kept “just in case”, a file server, the box running the accounts package or a line-of-business application whose vendor stopped updating it, a server in a branch office, and virtual machines on an old host that were cloned from a 2012 template years ago.
If you run Active Directory, one query lists the ones that have joined the domain:
Get-ADComputer -Filter 'OperatingSystem -like "*2012*"' -Properties OperatingSystem, LastLogonDate |
Select-Object Name, OperatingSystem, LastLogonDate
Then check what the query cannot see: machines outside the domain, appliances built on Windows, and the virtual machine inventory on every hypervisor. While you are there, note the SQL Server version on each one; older SQL Server releases have their own end dates, and several have already passed.
2 · This fortnight: contain what you cannot move yet
Very few organisations will move every server in two weeks, and they should not try. What can be done in two weeks is to make an unpatched server much harder to reach:
- Nothing exposed to the internet. No Remote Desktop, file sharing or web admin page reachable from outside. If remote access is needed, it goes through the VPN.
- Only the traffic it needs. Put it on its own network segment, and let the firewall allow only the ports its application actually uses, from the machines that actually use it.
- A backup you have restored. Kept off the network, and tested by restoring it, not by reading a green tick in the backup console.
- Somebody watching. Its logs sent somewhere a person or a monitoring service reads, so a break-in on it is noticed rather than discovered.
None of this makes an unsupported server safe. It buys the time to move it properly.
3 · Decide, server by server
For each one, there are four honest answers, and the cheapest is often the first:
- Retire it. A surprising share of old servers run an application nobody uses, or one whose data could be archived and switched off.
- Upgrade in place to a current Windows Server release, where the application and its vendor support it. Quickest on paper, and only as good as the application’s compatibility.
- Rebuild on current hardware, on-premise, when the workload has to stay local: plant systems, low-latency links, or data that must stay on site.
- Move it to the cloud, rebuilt on a current operating system and sized to what it actually uses rather than to the hardware it sat on in 2013.
The deciding question is rarely the operating system. It is the application: whether its vendor still supports it on a newer Windows, whether anyone still has its installation media and licence keys, and who knows how it is configured. Answer those first and the rest is scheduling.
4 · And the desktops
The same date matters for Windows 10. It left support in October 2025, and the one-year extended update option for individual PCs ends on the same 13 October. Businesses can buy further years for their PCs, at a price that rises each year. Either way, it is worth counting how many Windows 10 machines you still have, and whether they can run Windows 11 or need replacing, before the budget for next year is set.
Two weeks is enough to find them all and close the doors. The move itself is a quarter’s work, and it goes better planned than rushed.
Sizing a migration of your own?
We scope what moves, what does not, and what it costs to run afterwards, on a fixed scope agreed before anything starts.


