SharePoint 2016 and 2019 Are Unsupported. Your Farms Don’t Know That.

Written By Reveille Software

July 20, 2026

SharePoint 2016 & 2019 End of Support: Now What? | Reveille
Microsoft didn’t just stop patching SharePoint 2016 and 2019 on July 14. It stopped watching them. Someone still has to.
— The Reveille Perspective

On July 14, 2026, Microsoft shipped the largest Patch Tuesday in its history — roughly 570 fixes, including CVE-2026-56164, a SharePoint zero-day already being exploited in the wild. The same day, SharePoint Server 2016 and 2019 reached end of support. The farms running them watched the biggest security update ever released go past — and will watch every one that follows.

The consultants are calling it a migration story. It is — eventually. Enterprise SharePoint migrations take quarters, and thousands of organizations will run unsupported farms deep into 2027, holding the contracts, case files, and Enterprise Content Management (ECM) workflows their business runs on. What disappeared on July 14 wasn’t functionality. It was signal: the patches, the advisories, the escalation paths — the early-warning apparatus you never thought of as a monitoring system until the day it retired.

The result is a new and insidious category of risk: the Visibility Cliff — the day the vendor’s watching ends while your platform, and the content it carries, keeps running.

Core Tension

Your SharePoint farms didn’t stop working on July 14 — but every signal you relied on to know they were safe did. The servers will run for years. The watching ended in a day.

Quick answers

When did SharePoint 2016 and 2019 reach end of support?
SharePoint Server 2016 and SharePoint Server 2019 both reached end of support on July 14, 2026. After that date, Microsoft ships no security patches, bug fixes, or assisted support for either version. The supported paths forward are SharePoint Server Subscription Edition or migration to SharePoint Online in Microsoft 365.
Can you still run SharePoint 2016 or 2019 after end of support?
Yes — unsupported SharePoint servers keep running, but every vulnerability discovered after July 14, 2026 remains permanently unpatched. Organizations that must run them through a migration need compensating controls: hardened access, network isolation, and independent observability of the content layer, because Microsoft no longer provides fixes or advisories for these versions.
Will SharePoint 2016 and 2019 get a patch for CVE-2026-56164?
No. CVE-2026-56164, an actively exploited SharePoint Server elevation-of-privilege zero-day, was patched on July 14, 2026 — for supported versions only. SharePoint 2016 and 2019 farms will never receive this fix or any future one, which makes visibility into anomalous behavior on those farms more important than ever.
How do you keep SharePoint content visible during a Microsoft 365 migration?
Through Content Observability — continuous visibility into the documents, libraries, and workflows themselves, not just server health. An independent observability layer such as Reveille watches SharePoint Server and Microsoft 365 from one console, so stalled workflows, missing content, and failed handoffs surface early — before users or auditors find them.

01 — The Cliff

End of Support Doesn’t End Your Farms. It Ends Your Early-Warning System.

What actually disappeared on July 14 — and why “the servers still run” is the wrong comfort.

For a decade, vendor support was a monitoring system you didn’t have to build. Every Patch Tuesday was a diagnosis. Every advisory was a tripwire someone else maintained. Every support case was a safety net under your worst day. On July 14 the apparatus retired — and Microsoft’s lifecycle policy doesn’t taper. One day your farm is a supported product with a global security organization watching its back; the next it is your infrastructure, your risk, your problem. The platform’s behavior didn’t change. Your knowledge of its behavior did.

A SharePoint 2019 farm looks healthy right up until it doesn’t: a w3wp.exe worker process quietly recycling, a search crawl backlog past 200,000 items, an approval workflow retrying every 15 minutes since the 4:00 AM index rebuild — while every dashboard in the building shows green. Under support, those failures eventually met a patch or an engineer. After support, they meet whoever happens to be looking. If anyone is.

THE VISIBILITY CLIFF What ended on July 14, 2026 — and what has to keep going THE UNSUPPORTED YEARS JUL 14, 2026 — END OF SUPPORT Security patches none for 2016 / 2019 — ever Security advisories your own detection now Assisted support no case to open Content-layer visibility was always yours — now it’s the only watch left
End of support removes every signal Microsoft generated about SharePoint 2016 and 2019. The one signal it never generated — what’s happening to your content and workflows — is the one that has to carry you through the unsupported years.

02 — The Evidence

A Zero-Day at the Content Layer, on the Worst Possible Day

July 14 wasn’t a deadline. It was a demonstration.

If unsupported SharePoint sounds like a theoretical risk, Microsoft disproved it the same morning. July’s record Patch Tuesday included CVE-2026-56164 — network-exploitable, rooted in missing authentication, exploited before the fix existed. Note the target. Not a router. Not an endpoint. The platform that holds the documents. Attackers go to the content layer because that’s where the value is — and two entire generations of it are now permanently outside the patch perimeter.

Jul 14
The day SharePoint 2016 and 2019 reached end of support — and Microsoft’s largest-ever Patch Tuesday shipped
~570
Vulnerabilities fixed in that single July 2026 update, per BleepingComputer
1
Actively exploited SharePoint zero-day (CVE-2026-56164) patched that day — for supported versions only
0
Future security patches for SharePoint 2016 and 2019 farms, no matter what is discovered next

And the exposure isn’t only adversarial. The unsupported years coincide with the most turbulent thing you can do to a content platform: migrate it. Four failure modes, none of them visible on an infrastructure dashboard.

01

The Quiet Farm

An unsupported 2016 farm hums along untouched — until access patterns shift at 2:00 AM on a service account nobody remembers creating. There’s no advisory coming to tell you what that means. “Server up” was the only check anyone kept.

02

The Frozen Workflow

A department’s library moves to Microsoft 365 mid-migration. The approval workflow feeding accounts payable keeps firing against the old path — and stalls. Both platforms report healthy. The invoices report nothing at all.

03

The Half-Moved Library

40,000 documents leave the farm; 38,900 arrive. No error, no alert — just 1,100 records that exist in last month’s audit and nowhere else. Nobody reconciles content the platform didn’t flag. The auditor will.

04

The Copilot Blind Spot

The M365 tenant goes live and Copilot ships on top of the freshly migrated corpus — including the stale halves and missing libraries. The model is fine. The pipeline feeding it wasn’t. Now the wrong answers have confidence scores.

03 — The Reframe

When the Vendor Stops Watching, You Have To

Content Observability is the compensating control for the unsupported years.

Content Observability — the continuous visibility, assurance, and optimization of the content and document workflows that drive business outcomes and feed AI — is the compensating control for exactly this. It watches what infrastructure tools structurally can’t: whether documents committed, workflows advanced, queues drained, and whether the right people — and only the right people — touched the content. Your APM tells you the code ran; it doesn’t know that a library’s access pattern just broke character on a farm that can no longer be patched. Platform SLA is not workflow SLA — and on an unsupported farm, the gap between them is where the incidents will live.

SignalBefore July 14, 2026After July 14, 2026Where it comes from now
Security patchesMonthly, from MicrosoftNone for 2016 / 2019 — permanentlySubscription Edition or Microsoft 365 only
Security advisoriesMicrosoft-issued tripwiresSilence for these versionsYour own anomaly detection
Assisted support & hotfixesOpen a case, get an engineerRetiredInternal expertise and partners
Platform telemetryULS logs, health analyzerStill exists — watched by no one but youYour operations team
Content-layer visibilityNever Microsoft’s jobStill yours — now the only watch leftContent Observability

Forward Principle

End of support is not an infrastructure deadline. It’s a visibility deadline — the day your early-warning system retires before your platform does.

04 — The Hidden Engine, Part Two

The Migration Your AI Strategy Was Already Demanding

The road off the cliff runs straight through the engine room of Microsoft 365.

We’ve argued before that SharePoint is the hidden engine of Microsoft 365 — the content layer beneath Teams, OneDrive, and every Copilot answer worth trusting. End of support just converted that argument from strategy into deadline: the migration your AI ambitions were quietly demanding is now the one your risk register requires. One move, correctly watched, retires your security exposure and builds your AI foundation at the same time. And “correctly watched” is the part that gets skipped. A migration is a content-layer event wearing an infrastructure costume — content in motion, workflows re-homed, permissions rebuilt, and Copilot waiting at the destination to treat whatever arrives as the truth. You can’t feed AI from an estate you can’t see into. The organizations that get this right run one watch across both sides for the whole journey: the unsupported farm before, the moving content during, the Microsoft 365 tenant after.

Reveille for SharePoint

Reveille is the independent observability layer for the entire SharePoint estate — SharePoint Server on-premises and SharePoint Online in Microsoft 365, from one console. Over 95 out-of-the-box M365-specific tests and more than 90 M365 dashboard metrics at the content layer, passive user analytics that never capture user passwords, self-healing that resolves issues before the ticket queue, and an audit record the platform vendor doesn’t author. Cloud-native by design, deployment-agnostic by choice — which is exactly what a multi-year migration requires. See Reveille for SharePoint →

05 — The Point

Two Versions of 2028

Same deadline, same platforms, very different memories of it.

In one version of 2028, the organization treated July 14 as a visibility event: farms inventoried that week, an independent watch on the content layer, a migration that ran on its own schedule with every move verified. Copilot launched on a corpus the organization could prove was complete. The unsupported window closed without a story to tell — which was the entire point.

In the other, the farms ran quiet because the servers were up and the budget was elsewhere. The migration started after the incident — content moved in a panic, unreconciled — and the questions came later, from people outside IT, with answers that all began with “we believe.”

The difference isn’t the migration timeline — it’s whether the organization treated visibility as a first-class citizen for the unsupported years, or an afterthought.

Your farms stopped being watched on July 14. They’ll keep running — that was never the question. The question is whether anyone will see what happens next.

Support ended. Visibility doesn’t have to.

You may also like…

Get the signal on what’s shaping IDP, ECM, RPA, and intelligent automation.