Sign in with Microsoft
Sign in or create an account.
Select a different account.
You have multiple accounts
Choose the account you want to sign in with.


This article applies to customers who purchase extended security updates (ESUs) for the following versions and editions of Windows Server 2012:

  • Windows Server 2012 R2 Standard, Datacenter, and Embedded Systems

  • Windows Server 2012 Standard, Datacenter, and Embedded Systems


To continue receiving security updates after October 10, 2023, follow these steps:

  1. For all Windows Server 2012 and Windows Server 2012 R2 servers, you must have the following updates installed. If you use Windows Update, these updates will be offered automatically as needed. 

    IMPORTANT You must restart your device after you install the following required updates.

  2. Download and install the Extended Security Updates (ESU) Licensing Preparation Package. For more information, see the following articles in the Microsoft Knowledge Base:

    IMPORTANT If you are not being offered the latest cumulative updates (security updates), you must install the following update.

    • For Windows Server 2012 R2, see the Extended Security Updates (ESU) Licensing Preparation Package that is dated August 10, 2022 (KB5017220).

    • For Windows Server 2012, see the Extended Security Updates (ESU) Licensing Preparation Package that is dated August 10, 2022 (KB5017221).

  3. For Windows Servers that run on-premises without Azure Arc:

    1. Download the ESU MAK add-on key from the VLSC portal.

    2. Deploy and activate the ESU MAK add-on key by using Slmgr.vbs or VAMT tool.

    3. The steps to install, activate, and deploy ESUs for Windows Server 2012 and Windows Server 2012 R2 are the same as for Windows Server 2008 and Windows Server 2008 R2.

  4. For Windows Servers that run on-premises with Azure Arc.

    • Deploying a MAK key is not required if the Windows Servers are running in virtual machines (VMs) on Azure or Azure Stack HCI or devices that are Azure-Arc enabled and signed-up for keyless Pay-As-You-Go Service.

    • To deploy Extended Security Updates enabled by Azure Arc, you must onboard your devices to Azure Arc-enabled servers by deploying the Connected Machine agent. You can then provision and link Extended Security Update licenses to your Azure Arc-enabled servers, offering the flexibility of a Pay-as-you-Go, monthly Azure billed service.

    • Azure Arc-enabled servers enrolled for Windows Server 2012 ESUs receive Azure Update Management, Machine Configuration, and Change Tracking and Inventory capabilities at no additional cost. For more information, see Prepare to deliver Extended Security Updates for Windows Server 2012 through Azure Arc.

After you successfully complete these procedures, you can continue to download the monthly updates through the usual channels of Windows Update, WSUS and Microsoft Update Catalog. You can continue to deploy the updates by using your preferred update management solution.

More information

If you use Windows Update, the latest SSU will be offered to you automatically if you are an ESU customer. To get the standalone package for the latest SSU, search for it in the Microsoft Update Catalog. For general information about SSUs, see Servicing stack updates and Servicing Stack Updates (SSU): Frequently Asked Questions.

  • For other Azure products such as Azure VMWare, Azure Nutanix Solution, Azure Stack (Hub, Edge), or for bring-your-own images on Azure for Windows Server 2012 or Windows Server 2012 R2, you have to deploy the ESU key.

  • Azure resources require up to date SSL/TLS certificates to make sure endpoints are available and are updated.

  • Azure resources require connectivity with Azure instance MetaData Service (IMDS).


Need more help?

Want more options?

Explore subscription benefits, browse training courses, learn how to secure your device, and more.

Communities help you ask and answer questions, give feedback, and hear from experts with rich knowledge.

Was this information helpful?

What affected your experience?
By pressing submit, your feedback will be used to improve Microsoft products and services. Your IT admin will be able to collect this data. Privacy Statement.

Thank you for your feedback!