The Webex directory sync runs on a Windows server somewhere in your estate, and on many estates nobody has looked at that server in years. Cisco does not list Windows Server 2012 as a supported host for it, and Microsoft stopped supporting Windows Server 2012 on 10 October 2023. The last year of paid Extended Security Updates for that operating system ends on 13 October 2026. After that date there is no paid option left.

This is a small machine running a small application, and it is easy to fix. It is also easy to miss, because when it fails nothing goes down and nobody files a ticket.

What the Sync Does, and Why the Server Matters

Webex keeps its own record of your people in the cloud. It does not read your staff directory live. Cisco Directory Connector sits on one of your own Windows servers and, on a schedule, copies changes out of Active Directory up to the Webex identity service. Cisco describes it as "an on-premises application for identity synchronization in to the cloud" that you "download from Control Hub and install on a trusted Windows server."

That is the whole mechanism, and it is worth understanding only to the depth of one sentence: your staff list in Webex is accurate because a piece of software on a server you own keeps pushing changes to it. Which makes that server part of your identity plumbing rather than a spare box in a rack, and the version of Windows underneath it a supportability question rather than a housekeeping one.

The Dates, in One Table

Windows Server lifecycle milestones relevant to a Directory Connector host, as published by Microsoft
MilestoneDate
Windows Server 2012 and 2012 R2, end of support10 October 2023
Extended Security Updates for Windows Server 2012 and 2012 R2, final year ends13 October 2026
Windows Server 2016, mainstream support ended12 January 2022
Windows Server 2016, extended support ends13 January 2027
Windows Server 2019, extended support ends9 January 2029
Windows Server 2022, moves to extended support13 October 2026
Windows Server 2022, extended support ends15 October 2031

Microsoft's own wording on the Extended Security Updates program for Windows Server 2012 is that they "will continue for three years, renewable on an annual basis, until October 13, 2026." Three years was the whole program. There is no fourth year to buy.

The Distinction That Decides Whether This Is a Two-Hour Job or a Project

The advice going around is to upgrade your Windows Server. Read that carefully, because Cisco's documentation separates two things that people routinely merge, and merging them turns a small piece of work into a domain project that nobody budgeted for.

Cisco lists the supported host operating systems for Directory Connector as Windows Server 2025, Windows Server 2022, Windows Server 2019 and Windows Server 2016. Windows Server 2012 is not on that list.

Cisco separately lists the supported Active Directory services as Active Directory 2025, Active Directory 2016, Active Directory 2012, Active Directory 2008 R2 and Active Directory 2008.

So the thing that has to move is the member server the connector application runs on. Your domain controllers are a separate question with a separate answer, and Cisco still lists older directory levels as supported. You do not have to raise a forest functional level to get your Webex directory sync back onto supported ground.

That said, treat Cisco listing Active Directory 2008 in 2026 as a table that has not been pruned rather than as an endorsement. It means Cisco has not removed it. It does not mean anyone should be running it.

It Fails Quietly, Which Is the Real Problem

If the connector stops, Webex does not go down. Your people keep meeting and messaging, because the cloud already holds their accounts. What stops is the flow of changes, and it stops without an alarm.

The symptoms arrive over weeks and do not look related to each other. New hires are missing from Webex while every other system provisions them normally, so the service desk fixes them by hand, one at a time, without anyone connecting the tickets. The directory drifts as name changes, moves and new numbers fail to reach it, and people stop trusting what it tells them.

The one that matters is leavers. Removing somebody from Active Directory is normally how you remove them from Webex. With the connector dead, that removal is never pushed, and the Webex identity persists. How serious that is depends on how your tenant authenticates: with an external identity provider, disabling the Active Directory account still blocks sign-in and what you are left with is a license count and an audit finding; if Webex holds its own credentials, the position is worse. Establish which of the two you are in before somebody asks you.

Cisco does not document what happens when synchronization stops, so treat the three symptoms above as reasoning from how the connector is described rather than as a Cisco statement. Control Hub does show synchronization status and the next scheduled run. Somebody should be looking at it.

Do Not Stop at Windows Server 2016

Cisco's supported list starts at Windows Server 2016, and that is where a lot of remediation plans land, because it is the lowest version that satisfies the requirement.

Check that against Microsoft's lifecycle page before you commit to it. Windows Server 2016 left mainstream support on 12 January 2022 and leaves extended support on 13 January 2027. A plan that moves a Directory Connector host from 2012 to 2016 buys about fifteen months and then repeats the same exercise, in the same budget cycle, for the same server.

Windows Server 2019 runs to 9 January 2029. Windows Server 2022 moves to extended support on 13 October 2026 and runs to 15 October 2031. Microsoft's own guidance for customers leaving Windows Server 2012 names Windows Server 2022 as the upgrade target. Windows Server 2022 or 2025 is the destination worth building a plan around.

What Extended Security Updates Do and Do Not Buy You

Extended Security Updates are a real option and they have been the right answer for plenty of estates. Microsoft states that "customers needing to stay on-premises can upgrade to Windows Server 2022 or purchase Extended Security Updates (ESUs) for Windows Server 2012 — providing up to three years of security updates only," and that "customers can use Azure Arc to automatically deploy the purchased ESUs on-premises." Workloads migrated into Azure receive them without charge for three years.

None of that extends past 13 October 2026. The program ends on that date wherever the server sits, so Extended Security Updates are not a way out of this particular decision. They were a way of scheduling it, and the schedule has run out.

Note also what Extended Security Updates never covered. They are security updates for the operating system. They do not make an operating system supported by an application vendor, and Windows Server 2012 was absent from Cisco's supported host list independently of what Microsoft was still shipping.

What to Check This Week

This is a short list and most of it is inventory rather than engineering.

Find the connector host. Open Control Hub, look at directory synchronization, and establish which server is running it and what operating system that server is on. If you run more than one Active Directory domain, expect more than one of these servers.

Check when the last sync ran. If the last successful run is not recent, the symptoms above are already in progress and nobody has escalated them.

Establish your authentication posture. Find out whether Webex sign-in goes through your identity provider or through Webex-managed credentials. That single fact decides how serious the leaver problem is for you, and it is worth knowing before an auditor asks.

Look wider than the connector. A Windows Server 2012 machine hosting the Directory Connector is rarely the only Windows Server 2012 machine in the building. Management platforms, recording and analytics tools, attendant consoles and reporting applications tend to live on servers of the same vintage, installed in the same project. The connector is worth treating as the thing that surfaced the question rather than as the whole answer.

Decide the destination once. Whatever you move the connector onto, move the rest of that group onto the same supported build. Doing it as one exercise costs less than doing it five times, and it stops the 2016 problem repeating in fifteen months.

Common Questions

Do we have to upgrade our domain controllers? Not for this. Cisco's supported list covers the server the Directory Connector application runs on. Cisco separately lists Active Directory 2012, 2008 R2 and 2008 among the supported directory services. Your domain controller strategy is a real question, and it is a different question with a different timeline.

Can we just move the connector to another existing server? Usually. It is a modest application and it does not need a dedicated machine. What it does need is a supported operating system, domain membership and a reliable path out to the Webex identity service. Plan the cutover rather than running two connectors against one domain.

What happens to our existing Webex users while this is sorted out? Their accounts already exist in the Webex cloud and the connector is a one-way push rather than a live authentication path, so existing users are not expected to lose access. Cisco does not document the behavior when synchronization stops, so that is reasoning from the architecture rather than a vendor statement, and it is not a reason to leave the connector on an unsupported host.

Is Windows Server 2016 acceptable? Cisco lists it as supported. Microsoft has it leaving extended support on 13 January 2027. Both statements are true, which is why 2016 is a requirement that a plan can satisfy and still be the wrong plan.

We are already past 13 October 2026 when we read this. What changed? The operating system stopped receiving security updates through any paid route. The connector may well still be running. An application continuing to function is not the same as an application being supported, and neither is the same as the host underneath it being patched.

Sources

Find the servers your collaboration stack still depends on

Trybus Solutions inventories the on-premises components behind your cloud collaboration services, establishes which operating systems they run on and which are outside vendor support, and returns the list with the constraints written down.

Or call 423-633-1817 · info@trybussolutions.com