Skip to content
IT leader reviewing on-premises server infrastructure after SharePoint 2016 and 2019 reached end of support on July 14, 2026.

SharePoint 2016 and 2019 Are Now Unsupported: What to Do After July 14, 2026

On July 14, 2026, Microsoft ended extended support for SharePoint Server 2016 and SharePoint Server 2019 on the same day. Unlike Windows Server and SQL Server, there is no paid Extended Security Update program for SharePoint. You cannot buy more time. If your organization is still running either version, you are past the deadline, not approaching it, and the question has shifted from “when should we plan this” to “how exposed are we right now.”

Your farm did not shut off on July 15. Everything still works this morning, which is exactly why so many organizations are treating this as a non-event. It isn’t one. Here is what actually changed, why the two most common reasons for waiting now cost more than they save, and how to move when you’re starting late.

What End of Support Actually Means

End of support means Microsoft has stopped producing security patches, bug fixes, and support for SharePoint 2016 and 2019 permanently. Any vulnerability discovered from now on will never be fixed on those versions, and Microsoft support cannot open a ticket against them, even under a paid enterprise agreement. The servers keep running, but nobody is standing behind them.

Four things disappeared on July 14:

  • Security updates for newly discovered vulnerabilities
  • Bug fixes and cumulative updates
  • Microsoft technical support, free or paid
  • Maintained official documentation

The third one surprises people most. If your 2019 farm fails on a Saturday night, escalating to Microsoft is no longer an option at any price. Your recourse is whichever consultants still work on these versions, and that pool shrinks every quarter as engineers move to supported platforms.

The vendor ecosystem follows the same clock. Migration tools, backup products, and workflow platforms maintain compatibility with supported Microsoft versions. Expect the connectors and agents your farm depends on to stop receiving updates over the coming months, which means the tooling you would use to migrate also degrades the longer you wait.

The Two Reasons Organizations Waited, and Why Both Cost More Now

In our intake calls with organizations still on 2016 or 2019, the justification for delay is consistent. It comes down to two things: the migration costs too much, and there is custom code that will break. Both were defensible arguments in 2024. After July 14, both point the other direction.

The cost argument flipped on July 15

Delaying a migration used to mean deferring a project cost. Now it means paying to stay. Running an unsupported SharePoint farm carries costs that do not appear on a project quote: cyber insurance questionnaires that ask whether production systems are under vendor support, compliance frameworks like HIPAA, SOC 2, and CMMC that require patchable software, and audit findings that land the moment an assessor sees the version number. The migration quote did not shrink while you waited. The price of not migrating went from zero to real.

There is also recent proof of what the exposure looks like. In July 2025, the ToolShell attack wave compromised on-premises SharePoint farms around the world, and Microsoft responded with emergency patches for supported versions. That response is the part that no longer applies to you. The next actively exploited vulnerability in 2016 or 2019 stays open on your farm forever, and attackers scan for exactly these versions because they know it.

If you want to put numbers against the decision instead of instinct, our migration ROI calculator and our breakdown of what a SharePoint migration costs are the two places to start.

The custom code argument was never a reason to wait

Broken custom code is the other justification we hear, and it deserves a direct answer: the code does not get easier to deal with by waiting. Farm solutions, InfoPath forms, SharePoint Designer workflows, and custom web parts were built for a platform model that no longer exists on any forward path. SharePoint Online will not run them, and SharePoint Server Subscription Edition is the last place they limp along.

Here is what twenty years of these projects has taught us: most custom code in a 2016-era farm automates a process the business changed years ago. When we inventory customizations during discovery, a large share turn out to be dead weight nobody will claim, a portion map cleanly to modern equivalents like Power Automate and SPFx, and only a small remainder needs genuine rebuild work. The custom code you are afraid of is usually smaller than the custom code you have. But you cannot know which is which without the inventory, and the inventory is cheap compared to another year of exposure.

Your Two Realistic Paths Forward

There are two supported destinations: SharePoint Online in Microsoft 365, or SharePoint Server Subscription Edition on-premises. For most organizations, SharePoint Online is the right answer, and Subscription Edition is the exception you choose for a specific, nameable reason.

SharePoint Online

This is Microsoft’s recommended path and where all new investment goes, including Copilot, modern search, and the integration surface with Teams. You stop patching servers entirely, and the platform stays current without another end-of-support cliff in your future. It is also the path that forces the useful conversation: a move to SharePoint Online done properly is a restructuring of how your content is organized and governed, which is the reason it works better afterward. Our guide to SharePoint Server to SharePoint Online migration covers what that path involves, and the complete guide to SharePoint Online migrations goes deeper on planning the move itself.

SharePoint Server Subscription Edition

Subscription Edition is the evergreen on-premises product, and it exists for organizations with hard constraints: data sovereignty requirements, air-gapped environments, or regulatory language that genuinely prohibits cloud storage for specific workloads. It runs on a subscription model, so the days of buying a version and sitting on it for a decade are over either way. Be honest about whether your constraint is real or inherited. In our experience, most “we can’t go to the cloud” positions trace back to a policy written before Microsoft 365 had the compliance certifications it holds now, and a hybrid design covers the workloads that truly must stay on-premises.

How to Start When You Are Already Late

Being past the deadline changes the sequence, and the first move is an exposure assessment, not a migration kickoff. Before anyone debates destinations, you need to know what you are running, what is customized, what is actually used, and what your compliance obligations say about unsupported software. That assessment typically takes weeks, and it shrinks the migration itself because it tells you what not to move.

The working order looks like this:

  1. Inventory the farm: sites, databases, customizations, integrations, and the last-accessed dates that reveal how much of it is dead
  2. Document your exposure: which compliance frameworks apply, what your cyber insurance requires, and what an auditor will flag
  3. Decide the destination with real constraints, not inherited ones
  4. Build the plan, working from a migration project plan with named content owners, because the content decisions stall projects far more often than the technical moves do
  5. Move in waves, highest-risk and highest-value content first

If you want a structured starting point, our migration readiness assessment is built for exactly this situation, and our SharePoint migration services page explains how we run the full engagement.

Frequently Asked Questions

Did SharePoint 2016 and 2019 stop working on July 14, 2026?

No. The servers continue to run. What ended is every form of Microsoft support: security patches, bug fixes, technical assistance, and documentation maintenance. The risk is not an outage on a known date. It is an unpatched vulnerability on an unknown one.

Can we buy Extended Security Updates for SharePoint like we did for Windows Server?

No. Microsoft has not offered an ESU program for SharePoint Server 2016 or 2019. There is no paid option to extend patching. The only supported paths are migrating to SharePoint Online or upgrading to SharePoint Server Subscription Edition.

Can we upgrade directly from SharePoint 2016 to Subscription Edition?

There is no in-place upgrade from 2016. The supported route is a database-attach upgrade through SharePoint 2019 or a direct content migration, and for 2016 farms a migration is usually cleaner than a two-hop upgrade. This is one of the reasons many 2016 organizations land on SharePoint Online instead: if you have to move the content anyway, move it once to the platform without the next deadline.

Is it safe to run unsupported SharePoint for another year while we plan?

Every month adds risk you cannot patch away. If a year of planning is genuinely necessary, spend the first month on the exposure assessment and interim hardening: restrict external access to the farm, tighten the accounts that can reach it, and confirm your backups actually restore. Treat that as triage, not a strategy.

Reviewed By

Justin Daniluck
Justin DaniluckSenior SharePoint / M365 Specialist
Justin has more than 21 years of hands-on SharePoint experience and 24 years in information technology. He has planned and executed SharePoint migrations across every major version of the platform from SharePoint Portal through SharePoint Online.

Author

  • Andrea Skinner Bio Square

    Andrea leads operations at dataBridge and plays a key role in keeping complex SharePoint and Microsoft 365 engagements organized, efficient, and well managed. She brings a strong blend of project leadership, platform knowledge, and operational discipline that helps clients move forward with confidence.

SHARE ON SOCIAL MEDIA