Windows Server 2025 – Part 4 (Services Removed)

Microsoft is removing services or components from Windows Server 2025 or stopped developing them.

Services Removed with Windows Server 2025

FeatureExplanation
IIS 6 Management Console (Web-Lgcy-Mgmt-Console)The console has been removed after being no longer developed in Windows Server 2019. You should also start migration from IIS 6.0 or earlier versions, and move to the latest version of IIS, which is always available in the most recent release of Windows Server.
WordpadWordPad has been removed from Windows Server 2025. We recommend Microsoft Word for rich text documents like .doc and .rtf and Windows Notepad for plain text documents like .txt.
SMTP ServerThe SMTP Server features has been removed from Windows Server 2025. There’s no replacement within the operating systems.
Windows PowerShell 2.0 EngineThe Windows PowerShell 2.0 Engine has been removed, applications, and components should be migrated to PowerShell 5.0+.
Data Encryption Standard (DES)DES, the symmetric-key block encryption cipher, is considered insecure against modern cryptographic attacks, and replaced by more robust encryption algorithms. DES was disabled starting with Windows Server 2008 R2 and is removed from Windows Server 2025 and later releases.
NTLMv1Replace calls to NTLM by calls to Negotiate, which tries to authenticate with Kerberos and only falls back to NTLM when necessary. For more information, see The evolution of Windows authentication.
Services Removed with Windows Server 2025

Services no longer developed with Windows Server 2025

FeatureExplanation
Computer BrowserThe Computer Browser driver and service are deprecated. The browser (browser protocol and service) is a dated and insecure device location protocol. This protocol, service, and driver were first disabled by default in Windows 10 with the removal of the SMB1 service. For more information on Computer Browser, see MS-BRWS Common Internet File System.
NTLMAll versions of NTLM, including LANMAN, NTLMv1, and NTLMv2, are no longer under active feature development and are deprecated. Use of NTLM will continue to work in the next release of Windows Server and the next annual release of Windows. Calls to NTLM should be replaced by calls to Negotiate, which will try to authenticate with Kerberos and only fall back to NTLM when necessary. For more information, see The evolution of Windows authentication.
Remote MailslotsRemote Mailslots are deprecated. The Remote Mailslot protocol, which was initially introduced in MS DOS, is a dated and simple IPC method that is both unreliable and insecure. This protocol was first disabled by default in Windows 11 Insider Preview Build . For more information on Remote Mailslots, see About Mailslots and [MS-MAIL]: Remote Mailslot Protocol.
TLS 1.0
TLS 1.1
TLS versions 1.0 and 1.1 have been deprecated by internet standards and regulatory bodies due to various security concerns. As of the 2024 release of Windows Server Insiders Preview, these versions are disabled by default. For more information on TLS deprecation, see TLS 1.0 and TLS 1.1 deprecation in Windows.
WebDAV Redirector serviceThe WebDAV Redirector service is deprecated. The service isn’t installed by default in Windows Server. For more information on the WebDAV Redirector service, see WebDAV – Win32 apps.
Windows Management Instrumentation Command line (WMIC)WMIC is disabled by default for new installations of Windows Server. It will be removed from Windows in a future release. PowerShell for WMI replaces the WMIC tool. Use PowerShell or programmatically query WMI as a replacement for WMIC. To learn more about WMIC depreciation, see WMI command line (WMIC) utility deprecation: Next steps
VBScriptVBScript is deprecated. In future releases of Windows, VBScript is available as a feature on demand before its removal from the operating system.
Failover Clustering Cluster SetsFailover Clustering Cluster Sets feature is no longer in active feature development and is deprecated.
Network Load Balancing (NLB)NLB is no longer in active feature development and is deprecated. Consider using a Software Load Balancer (SLB) as an alterative. To learn more about SLB, see What is Software Load Balancer (SLB) for SDN?
Windows Internal Database (WID)WID is used by several roles, including ADFS, ADRMS, IPAM, RD Connection Broker, and WSUS. Consider using a free or full version of SQL Server for these roles. WID will be removed from Windows in a future release. To learn more about the different types of SQL Server available, see SQL Server editions.
Windows PowerShell 2.0 EngineThe Windows PowerShell 2.0 Engine is deprecated and isn’t installed by default. Windows PowerShell 2.0 applications, and components should be migrated to PowerShell 5.0+. To learn more about the deprecation, see Windows PowerShell 2.0 Deprecation.
Windows Server Update Services (WSUS)WSUS is no longer actively developed, all the existing capabilities and content continue to be available for your deployments.
Services no longer developed with Windows Server 2025

WSUS – Important Information

Microsoft has announced the deprecation of Windows Server Update Services (WSUS) as part of their vision for simplified Windows management from the cloud. This means that while WSUS will continue to function and receive updates, Microsoft will no longer invest in new capabilities or accept new feature requests for WSUS

Key points to note – See the official statement here. :

  • Current Functionality: WSUS will still work and receive updates, but no new features will be developed.
  • Support: Microsoft will continue to support existing WSUS features and address issues as they arise.
  • Transition Recommendations: Microsoft recommends transitioning to cloud-based tools such as Windows Autopatch and Microsoft Intune for client update management, and Azure Update Manager for server update management.

This deprecation does not impact existing capabilities or support for Microsoft Configuration Manager

However, organizations relying on WSUS should start planning their transition to these cloud-based solutions to ensure continued efficient update management. If you want to learn about modern server management, please check the AdaptiveCloud reddit community or contact me directly.

Conclusion

Most changes shouldn’t have a significant on your environment. In environments that have been created using legacy approaches, you should play attention to the development plan around NTLM. Pay a close look to this documentation and plan your removal of NTLM with Kerberos. Still using NTLM is a technical debt, that you should start to identify, track and pay the debt for as soon as you can afford it.

If you want to setup a Windows Server 2025 journey today and learn how to combine it with Azure Arc and cloud technology, you can start your journey here.

Windows Terminal 2024 on Windows 11 with Azure, Ubuntu, CMD and Powershell to manage Windows Server 2025 with Services removed
Windows Terminal 2024 on Windows 11 with Azure, Ubuntu, CMD and Powershell to manage Windows Server 2025
Spread the knowledge
Avatar for Andreas Hartig
Andreas Hartig - MVP - Cloud and Datacenter Management, Microsoft Azure

Related Posts

Azure Arc Agent 1.54 Stuck IT System Engineer Dragon concerned

Azure Arc Agent 1.54 Stuck? Fixing the WSUS Deadlock and Moving to 1.6x

Is your Azure Arc Agent 1.54 stuck and not updating? If that is the case you are in trouble. Azure Arc enabled servers operate on a strict twelve month support…

Spread the knowledge
Read more
IT operations dragon and the IT System Engineer dragon looking at a whiteboard showing Why Windows Server 2025 and WSUS are fine

Azure Arc – Enable Azure Arc Auto Updates using WSUS and GPOs

While our first part focused on the cloud-native way using Azure Portal and Policy, many IT administrators still prefer or require the reliability of on-premises control. In a traditional IT…

Spread the knowledge
Read more
WSUS Data Flow System Engineer with IT Architect and CISO

Windows Server 2025 – Part 9 (WSUS on Windows Server 2025)

WSUS on Windows Server 2025 continues In the previous parts of my Windows Server 2025 series, where I focused heavily on cloud-native management and the new features of Windows Server…

Spread the knowledge
Read more
Azure Arc Enable Azure Arc Auto Updates using Azure Portal

Azure Arc – Enable Azure Arc Auto Updates using Azure Portal

Azure Arc Auto Updates is key, as the foundation of your hybrid cloud strategy and it’s single contral plane in Azure is the Connected Machine Agent. While we often focus…

Spread the knowledge
Read more
CISO dragon and my IT architecture dragon looking at AGPM replacement

AGPM is End of Life on 14 April 2026

AGPM is End of Life on 14 April 2026. Microsoft’s Advanced Group Policy Management (AGPM) reaches its official End of Life (EOL) on April 14, 2026. After this date, the…

Spread the knowledge
Read more
Winget and IaC SystemEngineerDragon

WinGet and IaC – Take Winget to the next level

WinGet and IaC are maybe your next step to automate your environment. In the past, managing third-party applications on Windows meant 3rd party tools or gathering MSI installers on network…

Spread the knowledge
Read more