EOSL Alerts

SQL Server 2016 SP3 Azure Connect Pack EOL July 14, 2026

Updated 3rd Party Support Team

The Clock Is the Only Certainty

Microsoft SQL Server 2016 SP3 Azure Connect Pack reaches end of life (EOL) on July 14, 2026. This is not an LTS release, and after that date there will be no more patches, security fixes, or vendor SLAs from Microsoft. With roughly three months to go, a full migration to a supported version before the deadline is no longer realistic for most estates. The task now is to contain the risk, document the exposure, and secure a continuity path for the systems that must remain on this version past July.

This guide gives you a week-by-week action checklist to get ready for the EOL date.

What Changes on July 14, 2026

From that day forward:

  • No new security patches. Any CVE discovered after July 14, 2026 will remain unpatched by Microsoft for this product.
  • No bug fixes or hotfixes. Microsoft will not release fixes for functional or performance issues specific to this version.
  • No vendor technical support. You will not be able to open a case with Microsoft for this product.
  • Compliance clock starts. Audit frameworks (PCI DSS, SOX, HIPAA) typically require unpatched or unsupported software to be explicitly documented, risk-assessed, and controlled.

Systems running this version will continue to function exactly as they do today — there is no built-in kill switch. But every day past July 14, the security and compliance risk grows without vendor protection.

Week-by-Week Action Checklist

Weeks 1–2: Full Inventory

  • Find every instance. Use your CMDB (or run a query against all SQL Servers) to identify every SQL Server 2016 instance, then confirm which are on SP3 with the Azure Connect Pack. Latest build in this line is 13.0.7085.1 Azure Connect pack+GDR. Any instance with that version or earlier is in scope.
  • Tag and classify. Mark each instance with its business owner, application dependency, and risk tier (critical, important, low).
  • Document dependencies. Which line-of-business apps, reporting systems, or integrations connect to these instances? You will need that map for isolation planning.

Weeks 3–4: Harden and Isolate

  • Remove from the internet. If any instance has public-facing endpoints, move them behind a firewall or VPN immediately. No inbound RDP or SQL Server Browser service should be exposed.
  • Apply the latest patch. If you have not yet installed the last GDR update (13.0.7085.1), do so now while vendor support is still active. This is your final opportunity for a certified patch.
  • Lock down network access. Create explicit firewall rules so only known application servers can reach the SQL port (default 1433). Block all other traffic.
  • Enable logging and alerting. Turn on SQL Server audit, Windows event logging, and integrate with your SIEM. After EOL, you will rely on detection rather than prevention.
  • Review service accounts. Ensure service accounts have the minimal privileges needed (no domain admin, no local admin). Rotate any shared or default passwords.

Weeks 5–6: Document for Auditors and Insurers

  • Write a risk acceptance memo. For each instance that will remain on this version past July 14, draft a risk acceptance document signed by the business owner. Include:
    • Reason for remaining (e.g., app vendor hasn't certified a newer SQL version, migration project delayed)
    • Compensating controls (isolation, logging, network restrictions, third-party support)
    • Planned migration date (even if TBD)
  • Contact your cyber insurer. Many policies require notification when software goes out of vendor support. Ask your underwriter whether they require active third-party support or specific compensating controls to maintain coverage.
  • Update your BCP/DR plans. If an unpatched CVE triggers an incident, your business continuity plan should include the option to take the database offline or fail over to a temporary replacement.

Weeks 7–8: Secure a Support Contract

  • Line up third-party support. The only way to maintain a support contract after July 14 is through a third-party maintenance provider like 3rd Party Support. We cover the 2016 Azure Connect Pack version and can provide patches (where available), security guidance, and technical support for as long as you need to run this version.
  • Review any existing support agreements. If you already have a partner or reseller support package, check if it continues past July 14. Most vendor-branded support stops exactly on the EOL date.
  • Negotiate your transition plan. Third-party support gives you breathing room while you plan migration to a supported version (SQL Server 2019 or 2022, or Azure SQL Managed Instance). You do not need to rush the migration — just ensure you are covered for incidents.

Weeks 9–12: Final Checks

  • Run a full backup. Before July 14, take a verified full backup of every in-scope database. Store it in a secure, offline location.
  • Test your restore process. The worst time to discover your backup is corrupt is after vendor support has ended.
  • Brief your team. Ensure on-call DBAs and sysadmins know they cannot call Microsoft after July 14. Provide them with the new third-party support contact details.
  • Set a calendar reminder. On July 14, 2026, your team should re-verify that all compensating controls are in place and that the third-party support contract is active.

What Third-Party Support Can Do for You

Third-party maintenance keeps your systems running safely after the vendor stops. For SQL Server 2016 SP3 Azure Connect Pack, that means:

  • Technical support for issues like crashes, performance problems, or configuration questions.
  • Patch guidance — we track CVEs and can advise on workarounds or custom patches where feasible.
  • Security advisory — you get early warning and remediation steps for critical vulnerabilities.
  • Coverage for as long as you need — no artificial deadline to migrate.

We cannot reverse the EOL date, but we can make sure you are not left alone on July 15.

Final Word: Do Not Ignore the Date

Pretending July 14, 2026 does not apply is the riskiest option. A single critical CVE after that date could force an emergency migration under pressure, or worse, a breach. The three months you have left are enough to get your inventory right, apply compensating controls, and secure third-party support. Do that now, and you can manage the transition on your own timeline.

Contact us to discuss third-party support for your SQL Server 2016 estate.

How we can help

Keep it supported after end of life

The vendor's date doesn't have to be yours. Our engineers keep Microsoft SQL Server 2016 SP3 Azure Connect Pack running after official support ends — independent third-party support that covers most operational issues, typically at 40-70% below the last renewal quote.

Microsoft software support →

Migration services

When you do decide to move, we plan and execute the migration. Your current environment stays under vendor support while your contract is active — and if the renewal lapses mid-move, our third-party support covers most issues until the last workload is off it.

Migration & hybrid cloud services →

24×7 remote administration

Short on hands to run it day to day? Our NOC engineers monitor, patch and administer your environment around the clock — incident response included, at a fraction of the cost of an in-house night shift.

24/7 operations & remote administration →

Talk to a support specialist

Speak with an engineer, not a sales rep. We respond within 24 hours.

Your quote will be sent to this address.

By submitting this form, you agree to our Privacy Policy.