8 min

How the end of Office 2016 support hits the budget

The end of Office 2016 support raises file, email, and OneDrive risks. See the consequences and calculate the cost of a one-year delay.

How the end of Office 2016 support hits the budget

Office 2016 will continue to launch after support ends. That is exactly why a delay looks harmless: Word opens contracts, Excel recalculates familiar spreadsheets, and Outlook receives email. Yet on October 14, 2025, the product moved from a managed state to one in which Microsoft no longer provides security fixes, bug fixes, or technical updates.

An organization does not lose access to the buttons in Word and Excel. It loses predictable costs, compatibility with the outside world, and the option to escalate a difficult incident to the product developer. Keeping Office 2016 for another year should be treated as a conscious acceptance of risk with an owner and a budget, not as savings on licenses.

After October 14, protection stopped catching up with threats

The end of Office 2016 support means that Microsoft no longer fixes new vulnerabilities in its components. The Microsoft Lifecycle page gives October 14, 2025 as the end of extended support for Office 2016. Microsoft's migration guidance spells out the consequences: no new security fixes, ordinary bug fixes, or help with problems that arise. The applications do not switch off, and the license does not disappear, but that does not make the installation supported.

This distinction is particularly unpleasant for an office suite. Word, Excel, PowerPoint, and Outlook constantly parse data that arrives from outside: supplier documents, candidate résumés, contractor spreadsheets, email attachments, templates, and images. Email filtering and endpoint protection reduce risk, but they do not replace a fix for a vulnerable parser inside the application. If a security product blocks every suspicious document, the business stops normal file exchange. If it allows some of them, the vulnerable code keeps running.

People sometimes tell me that their company blocks macros, so the danger is small. That model is too narrow. A vulnerability can sit in the processing of a font, image, link, OLE object, or the file format itself. Macros create a separate class of risk, but blocking them does not turn an unsupported suite into a safe one.

A vulnerability scanner does not solve the problem either. It can identify a known issue and confirm that no fix exists. The IT team then has only compensating controls: restrict file opening, isolate the workstation, change file associations, disable a component, or accept the risk. Every control needs testing, support, and exceptions. You are already paying, but the bill is hidden in specialist hours.

Two dates must be kept separate. Support for Office 2016 connections to Microsoft 365 services, including Exchange Online, SharePoint Online, and OneDrive, ended on October 10, 2023. Support for the desktop suite itself ended on October 14, 2025. The first date made the cloud connection unsupported, while the second closed the flow of fixes for the applications. If an organization uses both local files and cloud email, both boundaries apply.

A formal exception does not restore technical support

Unsupported Office does not automatically fail every audit, but it changes the evidence an organization must provide. An auditor or risk owner will usually ask how vulnerabilities are found, how quickly they are fixed, and what happens when no fix exists. For Office 2016, an honest answer can no longer be "we will install the vendor's update." You need a limited scope, compensating controls, and approved residual risk.

First identify where people process data whose disclosure or alteration would be unacceptable. A workstation used for public presentations and a computer used to approve a payment register cannot be treated as equal merely because both run the same suite. The business process and access to data set the migration priority, not a department's convenience or the age of the computer.

Then compare the existing vulnerability management rule with reality. If internal policy requires serious issues to be fixed within a defined period, the lack of a patch does not stop the clock. A manager can approve an exception, but it should contain:

  • an exact list of devices and versions;
  • the reason migration is not yet possible;
  • restrictions on files, email, and network access;
  • a risk owner and review date;
  • a testable condition for closing the exception.

The phrase "antivirus is installed" does not describe a compensating control precisely enough. State which rules are enabled, how their status is monitored, who investigates detections, and what happens to a document the protection system could not inspect. The same applies to attachment sandboxing, blocking macros from the internet, and isolating individual workstations. A control matters when the team can prove that it operates on every device covered by the exception.

Review contractual requirements and insurance terms separately. I would not claim that every old version automatically breaches a contract or invalidates a payout, because those conclusions depend on the exact wording. But if a document requires vendor-supported software, regular patching, or compliance with internal policy, Office 2016 creates a fact that cannot be concealed by a broad statement about perimeter security.

Another mistake is extending an exception indefinitely. A quarter later, the device list has changed, the owner of an old add-in has left, a new counterparty has appeared, and the document still points to last year's inventory. Set a short review cycle and automatically end permission for devices missing from the current list. The exception should shrink as migration proceeds. Otherwise, it has become permanent architecture without a budget.

File compatibility does not stop at the DOCX extension

The same file extension does not guarantee identical document behavior. DOCX, XLSX, and PPTX files remain readable, but application features, calculation models, and collaboration mechanisms have continued to develop since Office 2016 was released. A file may therefore open without an obvious error and still show an old-version user a different result from the one its author saw.

Excel provides the clearest example. Microsoft documentation states directly that XLOOKUP is unavailable in Excel 2016. A user of a newer version can send a workbook in which XLOOKUP calculates a price, delivery status, or payment reconciliation. A recipient with Office 2016 may see an unknown function or a previously saved value, but cannot reliably recalculate the workbook. The _xlfn prefix in a formula is not a cosmetic warning. It means the current Excel version does not know the function.

Dynamic arrays create a less obvious gap. Modern Excel can spill a formula's result into adjacent cells and resize the range when the data changes. Microsoft warns that older versions may display these formulas as legacy array formulas, cannot resize them, and require compatibility checks. The error may appear only after someone adds rows to a register or refreshes the source data, rather than when the file first opens.

In Word and PowerPoint, editing accuracy tends to suffer more than calculation. A counterparty uses a newer feature, cloud font, modern comment, or design element, while the old version converts it, simplifies it, or prevents full editing. PDF hides part of the problem only when the document is final and read-only. It does not help when a contract needs tracked revisions, a financial model needs recalculation, or a presentation needs to be adapted for a meeting.

The price of incompatibility rarely appears in the Office budget. Employees pay it when they ask someone to save a file again, replace formulas with values, maintain two template versions, and compare the output manually. A silent error is worse: the workbook opened, someone dismissed the warning, and a number went into a report. Tests must therefore cover more than whether a file opens. They should cover four operations:

  • recalculation after source data changes;
  • saving and reopening without losing functions;
  • coauthoring and version history;
  • printing or PDF export with the same result.

Use real files exchanged with outside parties, not demonstration documents. The test set should include a contract with tracked changes, a large workbook with external links, a presentation using the corporate template, and a file edited by several people at once. This set quickly reveals where Office 2016 already forces partners to accommodate your internal delay.

Outlook works until the service side changes

Outlook 2016 may continue to connect to a mail server, but a connection that works today is not the same as a supported configuration. Microsoft stopped supporting Office 2016 connections to Microsoft 365 services on October 10, 2023. Its documentation uses careful language: older versions may still connect, but they might not use the newest service features and may eventually experience performance or reliability issues.

That changes how an incident is investigated. When a supported Outlook client loses its Exchange Online connection, an administrator checks the network, service health, access policy, profile, and client version. Office 2016 adds another branch: does the problem reproduce on a supported client? If it does not, the cloud provider is not obliged to fix the old Outlook client. The team must find its own workaround or urgently move the user to the web interface or a newer version.

Check authentication and mail add-ins separately. Exchange Online disabled Basic authentication for several protocols, while modern sign-in policies, multifactor verification, and conditional access change independently of the Office 2016 lifecycle. You cannot conclude that "email connects, so we are ready" from one test mailbox. An executive may have a delegated mailbox, accounting may use a shared mailbox, legal may depend on an archive, and an assistant may use several calendars and a correspondence registration add-in.

The email pilot should cover daily operations: creating a profile from scratch, signing in after a password change, repeating identity verification, searching a large mailbox, shared calendars, delegation, sending on behalf of a department, archives, and opening a protected attachment. Record more than "successful." Capture the operation time, error messages, and reliance on the local cache.

Backup web access is useful, but it does not make the delay free. The user changes a familiar process, some add-ins disappear, local archives behave differently, and support has to explain two interfaces instead of one. If the web version has already been accepted as the full workplace for a specific role, it is a sound decision. If it is remembered only after Outlook fails, it is an emergency workaround.

OneDrive does not update Office itself

Support after the Office update
GSE's Kazakhstan service network provides technical support around the clock.
Discuss the move

The current OneDrive sync client and Office 2016 have separate lifecycles. An up-to-date OneDrive client may keep moving files between a computer and the cloud while the Word or Excel application that opens them remains unsupported. A green sync check confirms delivery of the bytes, not formula compatibility, coauthoring support, or application security.

Version history is not a replacement for a newer Office release either. Microsoft says that Microsoft 365 version history works for files stored in OneDrive or SharePoint. It can restore an earlier copy after a bad edit or corruption. But restoration treats the outcome. It does not close a vulnerability, add XLOOKUP to Excel 2016, or guarantee identical calculations for two participants.

In practice, an old client pushes people toward copies. One employee opens a cloud document in the desktop application, another edits it in the browser, and a third emails an attachment because they do not trust conflict handling. Files named "final," "final2," and "really final" appear, and the process owner can no longer tell which version was approved. The cloud storage is functioning normally. The agreement about where and with which client the original gets edited has broken down.

Test scenarios, not the OneDrive icon, before approving a delay:

  • simultaneous Word and Excel editing by several people;
  • restoring an earlier version after a conflicting change;
  • working offline and synchronizing afterward;
  • opening a link as an external counterparty with permitted access;
  • applying protection labels and policies if the organization uses them.

If some operations work only in the browser, the organization can accept that as a target rule. It must then formalize the rule for the relevant file types and train employees. It cannot promise full desktop work while assuming that the browser will quietly cover the old suite's gaps.

A year of delay costs more than support for old installations

The cost of one more year on Office 2016 consists of extra spending caused specifically by the delay. The entire purchase price of a future license should not be counted as a loss. If migration will still happen a year later, the main payment merely moves in time. The calculation should include exception support, lost time, repeated work, expected risk loss, and any change in the migration price.

I use this model:

Стоимость отсрочки =
  поддержка Office 2016
+ потери времени на несовместимость
+ дополнительные обращения в поддержку
+ повторная инвентаризация и тестирование
+ ожидаемый ущерб от инцидентов
+ удорожание лицензий и проекта
- финансовый эффект от переноса платежа

The final line keeps the model honest. If the organization retains the money for another year, the postponement has a financial effect. People often overestimate that effect and compare it only with the license price, ignoring labor hours and risk. Finance should apply its own cost-of-capital rate, while IT supplies the other inputs.

Consider a hypothetical organization with 500 users. This is not an industry benchmark or a forecast, but an example that must be replaced with your own data. Suppose each user loses an average of 12 minutes per month to saving files again, working around an incompatible function, or finding the correct file version. At a fully loaded employee cost of 7,000 tenge per hour, the result is:

500 × 0,2 часа × 12 месяцев × 7 000 тенге = 8 400 000 тенге

Now add 20 extra support requests per month, each taking 45 minutes of a specialist's time at 8,000 tenge per hour. That adds 1,440,000 tenge. Repeating the inventory, add-in validation, and pilot a year later might take 120 hours at 10,000 tenge, or 1,200,000 tenge.

Security risk must not be presented as a guaranteed loss. Calculate it as an expected value across scenarios. If the internal risk owner estimates a 5 percent annual probability for a specific incident and an agreed financial impact of 80,000,000 tenge, the model includes 4,000,000 tenge. Do not take those numbers from this article. Security, finance, and process owners must approve them using your architecture, protections, and downtime consequences.

In the hypothetical example, the measurable sum already reaches 15,040,000 tenge before any license or project price increase and before the financial effect of postponing payment. If time loss is 3 minutes rather than 12, enter 3. If email runs on premises and there are no cloud connections, remove the related workload. A sound model does not prove a predetermined answer. It lets management see which assumptions change the decision.

Accurate data starts with an inventory

Email, files, and new applications
GSE integrates Microsoft software within the organization's wider IT system.
Discuss the move

Before selecting a license, find out where Office 2016 is actually installed and what depends on it. A purchasing ledger shows how many licenses were bought at some point. It does not reveal laptops outside the domain, old virtual machine images, 32-bit add-ins, terminal servers, or Project and Visio installations that live alongside Office.

For an initial local check, PowerShell can collect Click-to-Run and MSI installations without the slow and risky Win32_Product query. The command below does not delete or change anything:

$c2r = @(
  'HKLM:\SOFTWARE\Microsoft\Office\ClickToRun\Configuration',
  'HKLM:\SOFTWARE\WOW6432Node\Microsoft\Office\ClickToRun\Configuration'
)

$msi = @(
  'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*',
  'HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\*'
)

$result = @()

$result += Get-ItemProperty $c2r -ErrorAction SilentlyContinue |
  Select-Object @{n='Computer';e={$env:COMPUTERNAME}},
    @{n='Type';e={'ClickToRun'}},
    @{n='Product';e={$_.ProductReleaseIds}},
    @{n='Version';e={$_.ClientVersionToReport}},
    @{n='Platform';e={$_.Platform}},
    @{n='Channel';e={$_.UpdateChannel}}

$result += Get-ItemProperty $msi -ErrorAction SilentlyContinue |
  Where-Object {
    $_.DisplayName -match 'Microsoft (Office|Project|Visio).*2016'
  } |
  Select-Object @{n='Computer';e={$env:COMPUTERNAME}},
    @{n='Type';e={'MSI'}},
    @{n='Product';e={$_.DisplayName}},
    @{n='Version';e={$_.DisplayVersion}},
    @{n='Platform';e={if ($_.PSPath -match 'WOW6432Node') {'x86'} else {'x64'}}},
    @{n='Channel';e={''}}

$result | Sort-Object Product -Unique |
  Export-Csv "$env:TEMP\office-inventory.csv" -NoTypeInformation -Encoding UTF8

The output contains the columns Computer, Type, Product, Version, Platform, and Channel. Deploy the check through the standard device management system instead of collecting a file manually from each computer. Then link each installation to a user, department, operating system, and device model.

The version alone is not enough. For every group, record macros, COM add-ins, templates, fonts, Excel data sources, email archives, shared mailboxes, and document management integrations. A business process must own each dependency, not an anonymous IT department. Otherwise, everyone says an add-in is unnecessary during the pilot, only to discover on migration day that it approves payments.

The inventory should produce four groups: ready to update unchanged, validation required, dependency replacement required, and temporarily unable to migrate. For the last group, record the reason, risk owner, compensating controls, and next decision date. "Not ready yet" does not support a cost calculation or a finished project.

The choice between Microsoft 365 Apps and Office LTSC 2024 depends on the operating model

New software on local computers
GSE manufactures computers in Kazakhstan and integrates Microsoft software.
Choose a solution

The supported replacement does not have to be identical for every workstation. Microsoft 365 Apps receives feature and security updates through the selected channel. Office LTSC 2024 is intended for organizations and devices that need a fixed feature set, including regulated or restricted environments that cannot accept regular feature changes. According to Microsoft documentation, LTSC 2024 receives five years of mainstream support and no new features after release.

For ordinary connected workplaces that use Exchange Online, OneDrive, and coauthoring, Microsoft 365 Apps is the more logical option to assess. The organization chooses an update channel and commits to keeping builds supported. Monthly Enterprise Channel provides a predictable monthly release, while Semi-Annual Enterprise Channel suits only selected devices with specialized workloads that need extended testing. The channel name does not remove the need for monthly security updates.

LTSC 2024 fits where fixed functionality matters more than cloud features: an isolated workstation, a production environment, or a device beside an application certified for a specific Office version. But "we do not like subscriptions" is not enough for an architecture decision. Check operating system support, cloud service connectivity, activation, security updating, and the date of the next migration. LTSC also has an end-of-support date.

Do not confuse product selection with deployment method. A subscription or perpetual license answers the question of usage model and lifecycle. Office Deployment Tool, the device management system, local sources, and pilot groups answer how the package gets delivered. Microsoft recommends removing old MSI versions when installing Microsoft 365 Apps to avoid conflicts. Keeping the old and new suites side by side as a permanent arrangement usually just doubles the number of cases support must handle.

Rare dependencies may need a separate transition group. For example, 480 users move in the main wave while 20 remain on isolated devices until an add-in is replaced. That is better than keeping 500 people on the old version because of one application. The exception should be technically constrained and have an end date.

A delay requires the same management decisions as a migration

If an organization consciously keeps Office 2016 for another year, it still needs a project. It must appoint a risk owner, define permitted file types, restrict unsupported cloud scenarios, control exceptions, prepare web access to email, verify protection systems, and set an exit date. Without this work, "change nothing" merely means refusing to see the cost.

Run the migration in waves based on dependencies. IT and template owners first validate deployment, rollback, macros, and updates. Departments with standard documents come next. Then move groups with complex Excel workbooks, Outlook archives, and industry add-ins. A wave is complete when the business process works, not when the installer reports success on a number of computers.

Keep the original test set and pilot results. In a month, they will help validate updates. In a year, they will support an audit of the decision. In a dispute with a counterparty, they will show which version changed the file and after which action. That costs less than reconstructing events from user email.

GSE.kz can supply and integrate Microsoft software, select compatible hardware, and support the migration through its service network, while licensing and architecture should still follow the inventory results. A contractor helps when it takes responsibility for a testable outcome instead of simply passing on licenses.

By October 14, 2025, the product lifecycle had already settled the question of whether to leave Office 2016. Other questions remain open: which workplaces move first, which dependencies need isolation, and who signs off on the cost of residual risk. If the final item has no name and no amount, the organization has not delayed migration by a year. It has agreed to pay an undefined bill as problems appear.

FAQ

Can we continue using Office 2016 after October 14, 2025?

The applications will not switch off, and existing licenses will keep working. Microsoft no longer provides security or bug fixes, so the organization must accept and manage the resulting risk itself.

Will Office 2016 receive any more security updates?

No. Microsoft ended support on October 14, 2025 and does not offer an Extended Security Updates program for Office 2016. Antivirus and Windows updates do not replace fixes for Office itself.

Will Outlook 2016 stop connecting to Exchange Online?

Not necessarily on a specific day, but the connection has been unsupported since October 10, 2023. It may work until a service, sign-in policy, or client change exposes an incompatibility, after which there is no guaranteed fix for Outlook 2016.

Does OneDrive work with Office 2016 after support ends?

The OneDrive client may continue to synchronize files because it has a separate lifecycle. That does not give Office 2016 security fixes or guarantee support for newer coauthoring features.

Can Excel 2016 open files from newer Excel versions?

Many files will open, but that does not prove that they recalculate correctly. XLOOKUP is unavailable in Excel 2016, and dynamic arrays have limitations, so test data changes, recalculation, saving, and reopening.

Can blocking macros reduce the risk?

Blocking macros removes one attack path and usually makes sense where macros are unnecessary. Vulnerabilities can exist in the processing of other document elements, so the block does not return the product to a supported state.

Which costs less, Microsoft 365 Apps or Office LTSC 2024?

The answer depends on the calculation period, number of devices, cloud services, and update costs. Compare total spending over the same period, including deployment, dependency testing, support, and the next migration.

Do we need to replace Office 2016 on every computer at once?

No. Waves based on dependency groups reduce risk and allow complex add-ins to be handled separately. Every temporary exception still needs an owner, compensating controls, and an end date.

How do we calculate the cost of delaying migration for a year?

Add extra support, lost time, service requests, repeated testing, expected incident loss, and any increase in project cost. Subtract the financial effect of postponing payment, and do not count the entire future license as a loss if it will still be purchased next year.

Where should an Office 2016 migration begin?

Start with a factual inventory of installations and dependencies, then assemble a test set of real documents and email scenarios. Choosing a license before this work often moves old problems into the new suite.