Support status · SharePoint Server
Is SharePoint Server 2016 still supported?
SharePoint Server 2016 and 2019 left extended support on 14 July 2026.
Both editions reached the end of their fixed lifecycle on the same day, and InfoPath Forms Services was retired alongside them. Nothing stopped working: the farm serves pages, the forms still open and accept submissions, the workflows still run. What ended is security updates, non-security fixes and technical support. An on-premises farm is now an unpatched application server holding whatever your business put in it, and InfoPath forms keep rendering with no prospect of a fix if something breaks.
- Extended support ended
- 14 July 2026
- Applies to
- SharePoint Server 2016 and 2019
- InfoPath Forms Services
- Retired the same day
- Mainstream support for 2016 ended
- 13 July 2021
Source: Microsoft Lifecycle: search for SharePoint Server. Check it. We would rather you did.
- Dates from Microsoft Lifecycle, linked
- No email needed to read them
- Most of a farm is not our work
What that actually means
The position most estates are in
The forms still open, so nobody has escalated it
An end-of-support date on a server product produces no symptom. Submissions still save, approvals still route, and the only thing that changed is that no fix is coming for whatever surfaces next. There is no error message to attach to a ticket, which is why this sits.
A business process is living inside a form, and it is not owned by anyone
The purchase approval, the onboarding checklist, the safety report: an InfoPath form with rules in it and a Designer workflow behind it is an application. It has no repository, no tests, no documentation and no named owner, because nobody ever called it software.
Power Automate is a supported destination, not a migration
It is genuinely the right answer for a large share of what is on a farm. The parts that do not map are predictable and they are the parts that matter: state machines, long-running approvals with delays, anything tightly coupled to an InfoPath form, and any workflow that quietly encodes a rule nobody wrote down.
Exposure
What breaks, how likely, what it costs
Stated generically here because it is generic until someone looks at your estate. These are the scenarios that actually land, in the columns your risk register already has.
| Scenario | Likelihood | Impact |
|---|---|---|
| A vulnerability is disclosed in SharePoint Server 2016 or 2019 | Certain over time; this product has a history | No patch will be issued. An unpatched on-premises application server is a serious problem |
| An InfoPath form stops rendering after a client or browser change | Unpredictable, and now permanent | The process stops and there is no fix to apply, only a rebuild under pressure |
| A Cyber Essentials or ISO assessment reaches the farm | Annual, if you certify | Unsupported server software in scope is an automatic failure rather than a finding |
| The Windows Server hosting the farm reaches end of support | On a published date | Two unsupported layers, and a SharePoint version that cannot move to a newer Windows |
| The person who built the workflows leaves | Often already happened | A running business process that nobody can explain, modify or safely recreate |
What we do about it
The work itself
The honest triage first, before any rebuild
Document libraries and collaboration sites belong in Microsoft 365, moved with Microsoft's own tooling, and we will say so plainly rather than quote for rebuilding them. Only the parts that are genuinely applications are worth talking to us about.
What the forms and workflows actually do
The rules inside the InfoPath forms, the branches in the Designer workflows, and the business logic in any full-trust solution, read and written down as process a non-SharePoint reader can follow and sign off.
Behaviour pinned before anything moves
Characterisation tests against the running process, submitting the form, following the approval and checking the outcome, so the replacement is verified against what actually happens rather than against what the process document claims.
Replaced one process at a time
One form and its workflow move, in production, while the farm keeps serving everything else. Each process is independently revertible, and the farm is decommissioned only when nothing needs it.
What decides the cost
The three things worth knowing before anyone quotes
- Forms in real use
- Not the number on the farm. The number a person submitted this quarter, which is usually a small fraction and is the only number worth estimating against.
- Workflow shape
- Simple approvals map to Power Automate cleanly. State machines and long-delay workflows do not, and knowing which you have decides the destination.
- Full-trust code
- Farm solutions deployed as WSPs are the part with no supported destination at all. They are also where the real business logic usually turns out to be.
The engagement
How the work runs
You tell us what you have
Roughly how many forms and workflows are genuinely in use, and which process would hurt most if it stopped.
We read what is there
The forms, the workflows, any custom solutions, and the finding that is usually the biggest: how much of the farm nobody has touched in years.
You get the split, plainly
What should go to Microsoft 365 as content, what should become Power Platform, and what is a real application that needs building properly.
The applications are rebuilt in pieces
One process at a time, verified against the old one, with the farm still available until the last dependency is gone.
Questions
Frequently asked
Is SharePoint Server 2016 still supported?
No. SharePoint Server 2016 and SharePoint Server 2019 both reached the end of extended support on 14 July 2026. Mainstream support for 2016 had already ended on 13 July 2021. After the extended date there are no security updates, no non-security fixes and no technical support from Microsoft.
Did InfoPath stop working on 14 July 2026?
No, and this is the most misunderstood part. InfoPath Forms Services was retired on that date, but on-premises forms did not stop rendering. They keep opening and accepting submissions. What ended is patches, compatibility fixes and support. The forms will keep working until something changes around them, and when that happens there is no fix, only an unplanned rebuild.
Is Subscription Edition the answer?
It is the supported on-premises answer and for some organisations it is the right one, particularly with a genuine data-residency or air-gap requirement. It keeps you patched. It does not solve the InfoPath problem, because InfoPath is retired there too, and it does not turn your Designer workflows into something maintainable. If the reason you are on-premises is inertia rather than a requirement, it is worth checking before paying to stay.
Should these forms become Power Platform, or a real application?
Most should be Power Platform, and we will tell you that even though it is not work for us. Power Apps and Power Automate are the intended destination and they fit ordinary forms-and-approval processes well. The ones worth building properly are the processes with real business rules, integrations to other systems, external users, or an audit requirement. They are the ones where you would be uncomfortable if the logic lived somewhere nobody could test.
What about the hundreds of sites and libraries nobody uses?
They are the cheapest part of the problem and the one that makes the estate look frightening. Establishing what has actually been touched in the last year usually shrinks the scope dramatically. Content that is still needed moves to Microsoft 365 with Microsoft's own migration tooling; that is not a rewrite and should not be priced as one.
Will an unsupported farm fail a Cyber Essentials assessment?
If it is in scope, yes. The requirement is that software in scope receives vendor security updates, and after 14 July 2026 SharePoint Server 2016 and 2019 do not. Unsupported software is an automatic failure rather than something to explain, which is why this often surfaces as a blocked certification before it surfaces as a security concern.
Have you migrated SharePoint specifically?
Our deepest delivery experience is ColdFusion, not SharePoint. For the content and collaboration side, a Microsoft 365 migration specialist is straightforwardly the right supplier and we will point you at one rather than compete. Where we are useful is the subset that is really an application: recovering what an undocumented process does, pinning it with tests, and rebuilding it so it can be maintained.
Talk to someone who would read the code
A name, an email, and three optional questions. What comes back is a reply from the engineer who would read the code, and it is either a conversation about rebuilding the parts that are really applications or an honest pointer to a better-suited supplier.
Other platforms