Nothing about how much you patch determines what patching costs. The meter reads your licensing posture, whether or not anybody in the room has been told what that posture is. The same estate, on the same schedule against the same content, bills at roughly forty dollars a month or at nothing at all, and the difference is entirely paperwork. I have walked into estates paying this for years while holding the entitlement that waives it, which is the most irritating way to spend money, because nothing is broken and nobody notices.
Half the estate is free and nobody bills you for it
Start with the part that is genuinely simple. Update Manager is available at no extra charge for managing Azure virtual machines, and Microsoft states it in those words in the product’s own pricing FAQ. No meter, no per-core arithmetic, no benefit to claim. The two Azure machines in this estate are free today and would be free if there were two hundred of them, which inverts the intuition people bring to cloud services, where the Azure-resident thing is usually the expensive one.
Everything else is an Arc machine, and Arc machines meter. The list price is five dollars per server per month, charged on a daily prorated basis of roughly sixteen cents, and it has been that number since October 2023. On the invoice the line to look for is the Basic Server meter. What almost nobody knows until they read a bill closely is that waived usage does not vanish from it. It appears as a zero-value Complementary Benefits Server line. So the invoice is also a report on which machines are waived and which are not, machine by machine, month by month. If you take one operational habit out of this article, take that one: read the zero lines.
Eight of Cat Snack Jack’s servers sit on premises and will be Arc-connected by the time any of this matters, though one of those eight is WSUS01 and will not be there for long. The two Azure virtual machines do not meter at all. So the sum is eight machines at five dollars each, and the answer is forty dollars a month: not a number that gets a project cancelled, and exactly the sort of number that gets paid indefinitely. Do the same arithmetic against your own count rather than borrowing mine, because the shape of the answer matters more than this estate’s version of it. Small recurring charges are the ones that survive scrutiny, because scrutiny never arrives.
What counts as a billable day
Microsoft defines the billable day precisely, and the definition rewards a careful reading. An Arc-enabled server is considered managed by Update Manager on days when it meets both of two conditions. The first is that the status for Azure Arc at any time during the day is Connected. The second is that an update operation is triggered on it, patched on demand or through a scheduled job, or assessed on demand or through periodic assessment, or that it is associated with a schedule.
Read the second condition again, because it contains three separate billing triggers and only one of them looks like patching. Installing updates bills. Assessing bills, which is the sharp edge. And association with a schedule bills, with no operation required at all, so a machine sitting in a dynamic scope through a quiet month still meters for every day it was Connected.
The assessment clause catches people through an action that feels like housekeeping rather than spending. Enabling periodic assessment is the first thing anybody does with this product. It is what the built-in policies exist to do, it runs every twenty four hours once turned on, and the recommended way to turn it on is a modify policy with a remediation task that sweeps the machines you already have. That is the correct approach and the article on rings argues for it without reservation. It is also, on an estate with no waiver in place, a billing event on every unwaivered Arc machine from the moment the remediation task completes. Nobody deployed a schedule. Nobody installed anything. Somebody assigned a policy, and the meter started.
The meter does not ask how many updates you installed. It asks whether the machine was reachable and whether anybody looked at it.
The first condition has a mildly perverse corollary that will show up in a variance investigation one day. A machine that is disconnected for a whole day does not bill for that day, so a month that comes in cheaper than expected is a symptom rather than a saving. Cost variance on this meter is an availability signal wearing a finance costume.
Three waivers, and the mechanics that decide them
Microsoft lists exactly three scenarios in which an Arc-enabled server managed through Update Manager is not charged. The machine is enabled for delivery of Extended Security Updates enabled by Azure Arc. Microsoft Defender for Servers Plan 2 is enabled for the subscription that hosts the machine, with the caveat that if you are using Defender through a security connector you are charged. Or your Windows Server licences have active Software Assurance or Windows Server subscription licences, or Windows Server pay-as-you-go enabled by Azure Arc. A grandfather clause also covers machines using Automation Update Management for free as of September 2023, which is not a design input for anybody starting now.
The Defender route needs two corrections, because both directions of the common misunderstanding are wrong. Plan 1 waives nothing; the FAQ is explicit that any other Defender for Servers plan leaves you charged at the daily prorated rate per server. And Plan 2 waives less than people repeat. The documented benefit is that a Plan 2 customer does not pay to remediate the two update recommendations, periodic assessment should be enabled on your machines and system updates should be installed on your machines. That is Update Manager, and only Update Manager. I want to be blunt, because I have seen the wider claim in circulation including in my own earlier writing: current documentation does not state that Plan 2 waives the Azure Machine Configuration charge. Software Assurance attestation covers machine configuration. Plan 2, on the current wording, does not.
The third waiver is the interesting one. It is delivered by a benefit called Windows Server Management enabled by Azure Arc, and its governing sentence is one I would pin above the desk of whoever owns the Azure bill. Customers need to explicitly attest for their Azure Arc-enabled servers or enrol in Windows Server pay-as-you-go. Eligibility is not inferred directly from the enablement to Azure Arc.
Not inferred. Connecting a licensed, Software Assurance covered Windows Server to Arc waives nothing, because Azure has no way to know what is on your licensing statement and does not go looking. Somebody has to tick a box asserting that the entitlement exists. That is honest enough, since Microsoft is asking you to make a statement about a contract it cannot see. It is also exactly where the money goes missing, because the estates most likely to hold Software Assurance and least likely to employ anyone whose job includes attesting to it are the same ones where five dollars a machine quietly accrues.
The conditions are ordinary and worth checking before you promise anybody a saving. The Connected Machine agent has to be at version 1.47 or higher, the operating system has to be Windows Server 2012 or later, Standard or Datacenter, and officially licensed, and the machine has to be Connected, because disconnected and expired servers are not eligible. A machine that has fallen off the management plane loses the waiver at the moment it stops being managed. The benefit is also not offered in US Gov Virginia, US Gov Arizona, China North 2, China North 3 or China East 2. Enrolment is per machine through the Azure Arc licences surface, or at scale by setting softwareAssurance.softwareAssuranceCustomer to true on each machine’s licenseProfiles/default resource.
What attestation buys is much larger than the patching meter, and this is the part that changes how I would argue it internally. Attested machines get Update Manager, Change Tracking and Inventory, Machine Configuration, Windows Admin Center in Azure, Remote Support, Network HUD, Best Practices Assessment, Azure Site Recovery configuration and Azure File Sync at no extra cost beyond networking, storage and log ingestion. Then read the sentence underneath that list, which is the one nobody quotes. Customers who are not attesting and not enrolled in pay-as-you-go can purchase Update Manager, Change Tracking and Inventory, and Machine Configuration. The other six are not available through Azure Arc for them at all.
The waiver is not a discount on something you were going to buy anyway. It is the gate that decides whether you are allowed to buy most of it.
Attestation, then, is not a cost optimisation exercise to be scheduled behind more important work. It is the difference between an Arc estate with nine management capabilities available to it and an Arc estate with three.
Two paths out of the same estate
Cat Snack Jack is small enough that its licensing could plausibly go either of two ways, and the two produce different invoices, different capability sets and different answers to the January 2027 question. Both are worth walking, rather than assuming the one that flatters the tooling.
Path A is the small business estate: Microsoft 365 Business Premium for the people, Windows Server licences bought with the hardware, and no Software Assurance on any of them. This is common and it is not a sign of poor management. Software Assurance is bought by organisations with a volume licensing agreement and a renewal cycle, and plenty of well-run twenty person companies have neither.
For that reader, Business Premium confers nothing here, and I want to be careful about how I know that, because negatives are easy to assert badly. I went looking for a page connecting Microsoft 365 Business Premium to Update Manager, to Arc benefits, or to any waiver on this meter, and there is not one. The waiver list reads as an exhaustive set of three scenarios and Business Premium is not among them. So this is a search that came back empty rather than a Microsoft statement of exclusion. My conclusion is that no such page exists, because Business Premium is user and client licensing and this is a server management charge.
So path A pays. Eight on-premises Arc servers, forty dollars a month from the day periodic assessment is on, the two Azure virtual machines free regardless, and a management plane offering three purchasable capabilities and withholding six. None of that is a scandal. It is the price of the arrangement, and the only real failure would be discovering it after the finance conversation rather than before.
Path B is the same estate with an enterprise-flavoured licensing position: Microsoft 365 E5 for the people and, critically, Microsoft Defender for Servers Plan 2 enabled on the subscription hosting the Arc machines. Every Arc machine is then waived. I would not oversell it. Plan 2 is bought for workload protection, costs considerably more than the meter it waives, and nobody sensible buys it to save forty dollars. But if it is already enabled, and in E5 shops it very often is, the meter has already been paid for, and the remaining task is confirming it is enabled at subscription level rather than arriving through a multicloud security connector, because the connector route is explicitly charged.
Then there is the third path, which is the one I find most often and the one almost nobody is claiming. Software Assurance or Windows Server subscription licences on the server estate, plus attestation. No Defender plan, no Extended Security Updates, no argument with finance. The entitlement already exists, was already paid for, and sits unclaimed behind a checkbox and a version check on the Connected Machine agent. It waives Update Manager, it waives Machine Configuration, and it unlocks the six capabilities the unattested estate cannot buy at any price. If you do nothing else after reading this, find out whether your server licences carry Software Assurance, because the answer decides both this month’s invoice and the next section of this article.
January 2027 is not the same date for both readers
Four of these ten servers run Windows Server 2016, whose extended support ends on 12 January 2027. Extended Security Updates for it were announced in late February 2026, delivered through Azure Arc in the same shape as the 2012 programme before it. They became configurable in the Azure portal on 3 August 2026 and billing begins on 13 January 2027, the day after support ends. Enrolled machines get the Update Manager waiver as a side effect, since the first item on the waiver list is exactly this.
What it costs is published nowhere. Not on the Arc pricing page, not in the announcement, not in the licence provisioning guidance. I will not estimate it by analogy to the 2012 programme, and I would treat any circulating figure with suspicion until it appears on a Microsoft price surface, because the April 2026 pricing consistency update changed the rules for new Extended Security Updates offerings. The most load-bearing of the old assumptions is the one about Azure. Free Extended Security Updates for machines running in Azure was a 2012 era benefit scoped to that era, and the shipped precedent for the new model is SQL Server 2016, which is paid in Azure.
What is published, and what settles this estate’s question, is the eligibility rule. Licences are provisioned as Azure resources, specified as Standard or Datacenter and as physical or virtual cores, with a minimum of sixteen physical cores per machine or eight virtual cores per virtual machine, then linked to Arc-enabled servers. In every case you must attest to conformance with Software Assurance or an equivalent Server Subscription for on-premises workloads. And the Services Provider License Agreement route that existed for Windows Server 2012 is not available for Windows Server 2016 Extended Security Updates at all.
Which means path A cannot buy them. Not cannot afford them. Cannot buy them. The Business Premium estate with no Software Assurance on its server licences has no route to Extended Security Updates for Windows Server 2016 through Arc, and I will not soften that by presenting it as one option among several. For that reader, 12 January 2027 is an exit rather than a decision point. The 2016 machines are upgraded in place, replatformed onto something newer, or they run unsupported, and the third of those should be a choice made deliberately and in writing rather than by drift.
There is one mercy in the timing. One of the four is the WSUS server, which this series is retiring anyway, so its deadline resolves as a consequence of work already planned. The other three are two domain controllers and the legacy application server, and each is a longer conversation than a patching project. On path A the 2016 exit is the larger piece of work and this migration should be sequenced so the two do not collide. The mechanics of enrolling machines that do qualify sit in the Arc series, in [ARC 6] and its build sheet [ARC 6.1].
Where the meter is heading
One thing to keep in peripheral vision rather than in the plan. A preview capability called Essential Machine Management bundles Azure Monitor, Update Manager, Machine Configuration and Change Tracking and Inventory into a single enrolment. It is free during preview, the documentation states it will be priced at nine dollars per server per month once billing is enabled at a future date, and the same waiver families apply, so an attested or pay-as-you-go or Extended Security Updates covered machine stays at zero. I am not recommending it and I would not build a plan around a preview with an unstated billing date. What it tells you is the direction of travel: the five dollar line looks like it is becoming one component of a bundled per-server management charge, and the positions that waive the component are the ones that waive the bundle.
What this changes about the plan
Two things move as a result of this article, and neither is a patching decision. The first is that the licensing check belongs in front of the Arc onboarding rather than behind it. Not because the meter is large, but because the answer determines which management capabilities exist for this estate at all, and because attestation is trivially cheap at onboarding and becomes archaeology eighteen months later. Ask the question while somebody still has the purchase order.
The second is that the 2016 endgame is a licensing-dependent fork rather than a shared deadline, and it belongs in the same risk register as the WSUS retirement rather than in one of its own. The estate that can attest has an option in January. The estate that cannot has a date.
Next is operations, the part of this product nobody costs and everybody builds. Update Manager keeps seven days of assessment history and thirty days of installation history, its alerting has been in preview for the better part of three years, and every estate that runs this seriously ends up assembling the same small pile of queries, exports and event handlers around it. Knowing what that pile looks like in advance is the difference between planning an afternoon and discovering a gap during an audit.
Azure Update Manager
‹ Previous: [AUM 5.2] Build Sheet: Decommissioning WSUS01
Next: [AUM 7] Operating Update Manager: The Loop After the Rings ›




