Windows Server 2022 builds on Windows Server 2019 with stronger default security, faster storage repair, better UDP and TCP networking, and leaner containers. Both run on the same minimum hardware, and you can upgrade a 2019 server to 2022 in place. The biggest practical difference today is support: Windows Server 2019 has been on security-only updates since January 2024, and Windows Server 2022 joins it after October 13, 2026.
Key Takeaways
- Support dates: Windows Server 2019 gets security updates until January 9, 2029. Windows Server 2022 gets them until October 14, 2031.
- Biggest upgrades in 2022: Secured-core server, TLS 1.3 on by default, SMB AES-256 encryption, storage bus cache on standalone servers, and twice-as-fast Storage Spaces Direct repairs.
- Choose 2022 over 2019 for any new deployment where 2022 is your target version. Keep 2019 only for apps certified on it, and plan to move before 2029.
- Buying new? Also look at Windows Server 2025, which is supported until 2034 and accepts direct in-place upgrades from 2019.
Windows Server 2022 vs 2019 at a Glance
| Windows Server 2019 | Windows Server 2022 | |
| Released | November 2018 | August 2021 |
| Mainstream support ends | January 9, 2024 | October 13, 2026 |
| Extended (security) support ends | January 9, 2029 | October 14, 2031 |
| Editions | Standard, Datacenter, Essentials | Standard, Datacenter, Datacenter: Azure Edition, Essentials |
| TLS 1.3 enabled by default | No (TLS 1.2) | Yes |
| Secured-core server support | No | Yes, on certified hardware |
| SMB encryption | AES-128 | AES-128 and AES-256 |
| Server Core container RTM layer | 3.47 GB | 2.76 GB |
| gMSA for containers without domain-joined host | No | Yes |
| In-place upgrade to Windows Server 2025 | Yes | Yes |
Lifecycle dates are from Microsoft's Windows Server 2019 and Windows Server 2022 lifecycle pages. Feature details are from Microsoft's What's new in Windows Server 2022.
What Does Windows Server Support Lifecycle Mean for You?
Both versions follow Microsoft's Fixed Lifecycle Policy: five years of mainstream support followed by five years of extended support. During mainstream support you get security fixes plus non-security fixes and new features. Extended support keeps the security updates coming at no extra cost, but nothing else.
For Windows Server 2019, that means security patches only since January 2024. For Windows Server 2022, the same switch happens after October 13, 2026. Neither version is unsafe to run while it's in extended support. The real question is how long you plan to keep the server: a Server 2022 install gives you nearly three more years of security updates than a Server 2019 install.
Key Differences Between Windows Server 2022 and 2019
Security
Security is the largest single change. Windows Server 2022 adds Secured-core server, which combines certified OEM hardware, firmware and drivers with Windows security features:
- Hardware root of trust: A TPM 2.0 chip stores keys and verifies that the server starts with trusted code.
- Firmware protection: Dynamic Root of Trust for Measurement (DRTM) checks the boot process, and DMA protection limits drivers' access to memory.
- UEFI Secure Boot: blocks rootkits by booting only signed firmware and software.
- Virtualization-based security (VBS) and hypervisor-protected code integrity (HVCI). These existed in earlier versions, but Secured-core packages them with hardware that's certified to support them.
Secure connections also improved:
- TLS 1.3 and HTTPS are enabled by default: Windows Server 2019 tops out at TLS 1.2. Applications still need to support TLS 1.3 to use it.
- DNS over HTTPS: encrypts the server's DNS lookups.
- SMB AES-256 encryption: (GCM and CCM) for file sharing, with AES-128 kept for older clients.
- Encryption for SMB Direct and RDMA, and for east-west traffic inside failover clusters.
Windows Server 2019 is still a secure platform. It introduced Microsoft Defender ATP integration and shielded VM improvements. But 2022 turns on stronger protections by default instead of leaving them to you.
Storage
- Storage bus cache on standalone servers: Previously this was limited to Storage Spaces Direct clusters. It pairs fast media (NVMe or SSD) with slower HDDs as a cache tier to speed up reads and writes.
- Adjustable storage repair speed: In Storage Spaces Direct, you choose whether resync work or your running workloads get priority after a disk or node failure.
- Faster repair and resync: Microsoft says repairs after reboots and disk failures are now twice as fast, because only the changed data is moved.
- ReFS file-level snapshot: Read-only snapshots that take the same time regardless of file size, useful for VHDX backups.
- SMB compression: Files compress as they transfer, which helps on slow or congested links.
- Storage Migration Service upgrades: This service first appeared in Windows Server 2019. In 2022 it can also migrate local users and groups, failover clusters, Linux Samba servers and NetApp CIFS servers.
Networking
- UDP Segmentation Offload (USO) moves most of the work of sending UDP packets from the CPU to the network adapter.
- UDP Receive Side Coalescing combines incoming UDP packets to cut CPU use. Together with USO, this matters more now that QUIC runs over UDP.
- TCP HyStart++ reduces packet loss when connections start, and RACK reduces retransmit timeouts. Both are on by default.
- Hyper-V virtual switch Receive Segment Coalescing improves throughput for VM traffic and is on by default for external switches.
Hybrid and Azure Management
Windows Server 2019 can connect to Azure services and Azure Arc. Windows Server 2022 makes this easier: an Azure Arc Setup program is built into the taskbar, so onboarding a server takes a few clicks. Windows Admin Center can also report on and enable Secured-core features.
The Datacenter: Azure Edition (VM-only, running in Azure or on Azure Local) adds features the other editions don't get:
- Hotpatch: security updates without a reboot.
- SMB over QUIC: file access without a VPN.
- Azure Extended Network: VMs keep their on-premises IP addresses after moving to Azure.
Containers and Kubernetes
- Smaller images: The Server Core container RTM layer is 2.76 GB, down from 3.47 GB in 2019 (a 33% reduction). Microsoft says overall container images are up to 40% smaller, with startup times about 30% faster.
- gMSA without a domain-joined host: In 2019, the container host had to join the domain. In 2022 it doesn't.
- HostProcess containers: for Kubernetes node management.
- Direct Server Return (DSR): routing, IPv6 dual stack, and multiple subnets per Windows worker node.
- Virtualized time zones: so a container can use a different time zone from its host.
Hardware Scale
Windows Server 2022 supports up to 48 TB of memory and 2,048 logical cores across 64 sockets on Intel Ice Lake systems. It also adds nested virtualization on AMD processors.
Feature Comparison: Windows Server 2019 vs 2022
| Feature | Windows Server 2019 | Windows Server 2022 |
| Secured-core server | Not available | Available on certified hardware |
| VBS and HVCI | Available | Available, packaged in Secured-core |
| TLS default | TLS 1.2 | TLS 1.3 enabled by default |
| DNS over HTTPS client | Not available | Available |
| SMB encryption | AES-128 | AES-256 and AES-128 |
| SMB over QUIC | Not available | Datacenter: Azure Edition only |
| SMB compression | Not available | Available |
| Storage Migration Service | Introduced | Expanded sources and targets |
| Storage bus cache on standalone servers | Not available | Available |
| Adjustable storage repair speed | Not available | Available |
| UDP Segmentation Offload / UDP RSC | Not available | Available |
| TCP HyStart++ and RACK | Not available | Enabled by default |
| Hotpatch | Not available | Datacenter: Azure Edition only |
| gMSA without domain-joined container host | Not available | Available |
| HostProcess containers | Not available | Available |
| Container virtualized time zone | Mirrors host | Configurable per container |
| Microsoft Edge included | No (Internet Explorer) | Yes |
| Nested virtualization on AMD | Not available | Available |
Windows Server 2022 Editions
Windows Server 2022 comes in four editions:
- Server 2022 Standard: for physical or lightly virtualized servers. Covers two Windows Server VMs per fully licensed host.
- Server 2022 Datacenter: for heavily virtualized datacenters, with unlimited Windows Server VMs on the licensed host.
- Server 2022 Datacenter: Azure Edition: a VM-only edition for Azure and Azure Local, with Hotpatch, SMB over QUIC and Azure Extended Network.
- Server 2022 Essentials: for small businesses with up to 25 users and 50 devices on a single server.
Windows Server 2019 has Standard, Datacenter and Essentials, with no Azure Edition. You can compare prices in our guide to Windows Server 2022 cost.
What Was Removed or Deprecated in Windows Server 2022?
Check these before upgrading a 2019 server, according to Microsoft's removed and deprecated features list:
- Internet Storage Name Service (iSNS): removed. You can still connect to iSNS servers or add iSCSI targets individually.
- Guarded Fabric and Shielded VMs: no longer in development. They're still supported in 2022, but Microsoft is putting its effort into Azure confidential computing instead.
- Windows Deployment Services (WDS) boot.wim deployment: partially deprecated. Workflows that use boot.wim from the 2022 installation media still work, with a warning. PXE boot and custom boot images aren't affected.
- WINS: deprecated. Move name resolution to DNS.
- Hyper-V virtual switch on LBFO teams: no longer supported. Use Switch Embedded Teaming (SET) for Hyper-V instead.
Which One Should You Choose: Windows Server 2022 or 2019?
For a new server, choose Windows Server 2022 over 2019. It has the same hardware requirements, stronger security out of the box, and nearly three more years of security updates. Only choose 2019 when something specific holds you to it.
| If you… | Choose |
| Are deploying a new server and standardizing on 2022 | Windows Server 2022 |
| Need TLS 1.3 by default, Secured-core or SMB AES-256 for compliance | Windows Server 2022 |
| Run Windows containers or Kubernetes nodes | Windows Server 2022 (smaller images, gMSA without domain join) |
| Have an application only certified on 2019 | Windows Server 2019, with a plan to migrate before January 2029 |
| Need to match an existing 2019 cluster | Windows Server 2019 for now. Cluster rolling upgrades move one version at a time, so 2019 to 2022 is a supported next step |
| Want the longest support from a new purchase | Consider Windows Server 2025, which is supported until November 2034 |
If you're buying today, it's worth comparing Windows Server 2025 too. You can upgrade a 2019 Server in place directly to 2025, through installation media or Windows Update. See our Windows Server 2025 Standard and Windows Server 2025 Datacenter guides.
Is Windows Server 2022 Worth the Upgrade from 2019?
Yes, if you want to stay on a 2022-generation platform. You get stronger default security, faster storage recovery and better network throughput, and the support clock moves from 2029 to 2031.
The case for stopping at 2022 is weaker than it was in 2021, though. Windows Server 2025 is supported for three years longer, and 2019 can upgrade straight to it. If you're going to plan downtime and buy new licenses anyway, check whether Server 2025 fits your applications before settling on 2022.
How to Upgrade from Windows Server 2019 to 2022
Windows Server 2019 vs 2022 hardware requirements
The minimum requirements are the same for both versions, according to Microsoft's hardware requirements:
| Component | Minimum |
| Processor | 1.4 GHz 64-bit, with NX, DEP and SLAT support |
| RAM | 1 GB (Server Core), 2 GB (Desktop Experience), ECC for physical hosts |
| Disk | 32 GB (absolute minimum) |
| Network | Gigabit (1 Gbps) Ethernet adapter |
| Firmware | UEFI 2.3.1c with Secure Boot, needed only for certain features |
| TPM | TPM 2.0, needed for features like BitLocker and Secured-core |
| Display | Super VGA (1024 x 768) or higher, for Desktop Experience |
A virtual machine with only the minimum RAM can fail during setup. Give it at least 800 MB while installing, then reduce it afterwards if you need to.
Upgrading Steps
- Back up the server, or take a VM snapshot, and confirm you can restore it.
- Check your roles and apps. Confirm that every role and third-party application supports Windows Server 2022. Microsoft's role migration matrix lists which roles upgrade in place.
- Get a Windows Server 2022 license. Each Windows Server upgrade needs its own license, and CALs must be for the same version or newer.
- Disable NIC Teaming if you use it. You can turn it back on after the upgrade.
- Mount the Windows Server 2022 ISO and run setup.exe.
- Choose the same edition and installation type. You can move from Standard to Datacenter during the upgrade, but not downgrade. You can't switch between Server Core and Desktop Experience.
- Select "Keep files, settings, and apps" and let setup finish. The server restarts several times.
- Activate Windows Server 2022 and install the latest cumulative update.
A few restrictions apply. You can't change the system language, and you can't upgrade into an evaluation copy. Domain controllers have their own upgrade guidance. For a fresh install instead, follow our guide to download, install and activate Windows Server 2022 Standard.
Frequently Asked Questions
When does support end for Windows Server 2019 and 2022?
Windows Server 2019 left mainstream support on January 9, 2024, and gets security updates until January 9, 2029. Windows Server 2022 mainstream support runs until October 13, 2026, with security updates continuing until October 14, 2031.
Can I upgrade directly from Windows Server 2019 to 2022?
Yes. Microsoft supports in-place upgrades from Windows Server 2019 to 2022 using installation media. Windows Server 2019 can also upgrade directly to Windows Server 2025, including through Windows Update.
Do I need a new license to upgrade from 2019 to 2022?
Yes. Unlike Windows client upgrades, every Windows Server version upgrade needs its own license. Your CALs also need to be for Windows Server 2022 or newer.
Are the system requirements different between 2019 and 2022?
The minimums are the same: a 1.4 GHz 64-bit processor, 1 GB of RAM for Server Core (2 GB for Desktop Experience) and 32 GB of disk. Secured-core features need certified hardware with TPM 2.0.
Is Windows Server 2022 still worth buying in 2026?
Yes, if your applications or existing estate are built around 2022. It keeps getting security updates until October 2031. For the longest support from a new purchase, compare it with Windows Server 2025.
Final Thoughts
Windows Server 2022 is the better choice over 2019 for almost every new deployment. It has the same hardware needs, safer defaults and more years of updates. Keep 2019 only where an application requires it, and plan to move off it before January 2029. If you're ready to buy, browse Windows Server licenses at Mscdkeys.
Leave a comment