Blog · 4 min read ·
ShareConfiguration Manager 2503 support ends September 30
Microsoft Configuration Manager version 2503 reaches end of servicing on September 30, 2026. Every Current Branch version is serviced for 18 months from release, and version 2409 already expired on June 6, 2026.
Microsoft Configuration Manager version 2503 reaches end of servicing on September 30, 2026. That is 25 days from the date on this post, and it is the kind of deadline that passes without producing a single alert.
The more useful fact is the one next to it in the same table. Only three versions of Configuration Manager are supported today, and one of the expired ones went quietly three months ago.
The whole supported list, decoded
Microsoft's lifecycle page prints dates in Pacific Time with a 6:59:59 AM stamp, which
is the morning after the last supported day. Decoded, the current picture is short:
| Version | Released | Last supported day | Status |
|---|---|---|---|
| 2603 | May 5, 2026 | November 5, 2027 | Supported |
| 2509 | November 12, 2025 | May 12, 2027 | Supported |
| 2503 | March 31, 2025 | September 30, 2026 | Supported — 25 days left |
| 2409 | December 4, 2024 | June 6, 2026 | Already expired |
| 2403 | April 22, 2024 | October 22, 2025 | Already expired |
Every one of those windows is exactly 18 months from the version's own release date. That is the whole policy, and it is worth internalising because it makes the next date predictable without looking anything up: whatever you are running, it dies eighteen months after it shipped.
⚠️ One decoding note, because it catches people who have learned a useful habit. Many Microsoft lifecycle dates land on a Patch Tuesday, and checking for that is a good way to catch a misread cell. It does not apply here. These dates fall on a Friday, a Wednesday, a Wednesday and a Saturday, because an 18-month clock from an arbitrary release date has no reason to align with a patch cycle. If you apply the Patch Tuesday check to this table you will conclude you have misread it, and you will not have.
2409 is the one worth noticing
Version 2409 left support on June 6, 2026. Three months ago. If a site is still on it, the interesting question is not "when do we upgrade" but "how did a supported-platform expiry pass without anyone raising it".
The answer is usually structural rather than careless. Configuration Manager updates arrive in the console, as an update you choose to install, rather than through the patching channel the rest of the estate uses. So the platform that reports on everyone else's patch compliance is frequently absent from its own report. Nothing external nags. The version number sits in a console nobody opens unless something is wrong.
Why this one is not just another lifecycle row
Most end-of-support dates on this blog are about a workload: a server, a mailbox platform, a database. This one is about a control.
Configuration Manager is, in a lot of mid-market estates, the thing that patches everything else. When it is out of servicing, the statement "we centrally manage and patch our endpoints" is still technically true and materially weaker — because the tool making it true is no longer receiving security updates itself. That distinction reads very differently in three specific documents:
- A cyber-insurance application. Questions about patch management ask what you use and how quickly you deploy. They rarely ask whether the platform itself is supported. That does not mean the answer will not matter after a claim.
- A compliance control narrative. If a control is evidenced by "ConfigMgr enforces it", the supportability of ConfigMgr is inside the scope of that control whether or not the narrative says so.
- An incident timeline. "The management platform was three versions out of support" is a sentence you do not want written by somebody else, afterwards.

What we would do this week
- Open the console and read the version number. Not the documentation, not the inventory system — the console. It takes a minute and it is the only number that settles it.
- If you manage more than one estate, read it without opening consoles. The site
version is available from the registry on the site server under
HKLM\SOFTWARE\Microsoft\SMS\Setup, and through the SMS Provider via WMI, so a fleet-wide version report is a script rather than a morning of logins. For an MSP that is the difference between checking one client and checking all of them. - If you are on 2409 or older, treat it as remediation rather than maintenance. You are not preparing for a deadline; you are past one. That changes who needs to know.
- Check the SQL Server underneath before planning the upgrade. Configuration Manager upgrades have prerequisites, and a site database on an unsupported SQL version turns a change window into two projects. This is the single most common reason a "quick" ConfigMgr upgrade stops being quick.
- Decide whether you are upgrading or leaving. If the estate has drifted toward Intune and ConfigMgr is now maintaining a shrinking set of servers, the eighteen-month clock is a reasonable prompt to ask whether you are upgrading a platform you intend to retire.
- Put the next date in the calendar now. On 2509 that is May 12, 2027; on 2603 it is November 5, 2027. The failure mode here is not difficulty, it is silence.
Sources
Version rows and dates are read directly from
Microsoft's Configuration Manager lifecycle page
(ms.date 2026-06-17), which states that Configuration Manager follows the Modern
Lifecycle Policy and that support dates are shown in Pacific Time. The decoded "last supported day"
column above is our arithmetic on Microsoft's raw cells, not a Microsoft-published column — the raw
cell for 2503 reads 10/1/2026 6:59:59 AM.
This date also appears in our note on the November 10, 2026 cluster, in the context of dated items that are missing from Microsoft's own end-of-support summary page.
If you would rather have the version audit, the prerequisite check and the upgrade window handled as a bounded piece of work, scope it with us.
Questions we get asked
- What is the actual end date for Configuration Manager 2503?
- September 30, 2026. Microsoft's lifecycle table prints the raw cell as '10/1/2026 6:59:59 AM' in Pacific Time, which is the morning after the last supported day — so the last day in support is September 30. It is a Wednesday, and that is not a mistake: Configuration Manager runs an 18-month clock from each release, not a patch-cycle clock, so its end dates land on whatever weekday the arithmetic produces.
- Which versions are actually supported right now?
- Three. Version 2503 until September 30, 2026; version 2509 until May 12, 2027; and version 2603 until November 5, 2027. Everything older is out. Version 2409 left support on June 6, 2026 and version 2403 on October 22, 2025. If your site is on 2409 or earlier it is already unsupported, not approaching it.
- What does 'end of servicing' mean here — does it stop working?
- No. It keeps running, and that is the risk. Configuration Manager follows the Modern Lifecycle Policy, so an out-of-servicing version stops receiving security updates and stops being eligible for support. The console opens, deployments run, and the platform quietly stops being patched. Nothing about the day itself is visible from inside the product.
- Why does this matter more than a normal end-of-support date?
- Because of what the product does. Configuration Manager is frequently the tool that patches everything else — servers, workstations, third-party applications. An unsupported patch-management platform is a different class of finding from an unsupported line-of-business app: it is the control, not the thing being controlled. On a cyber-insurance questionnaire or a compliance narrative, 'we patch centrally' and 'our patching platform is unsupported' cannot both be comfortable.
- How long does an upgrade actually take?
- The in-console update itself is usually a short job on a small estate. What takes the time is what surrounds it: checking that site systems meet the prerequisites for the target version, confirming the SQL Server version underneath is still supported, and scheduling around distribution points. On a single-primary-site mid-market deployment this is typically a change window rather than a project — which is precisely why it tends to be left until it is late.
Related service
Windows Server end of supportWritten by the team at Pro IT NW · Senior-led Microsoft project consultancy · Seattle and the Pacific Northwest, delivered USA-wide.